Terms of Service (TOS) Under Scrutiny - Part XIII - RealVNC and What It Does in Practice
We're soon entering the part of the series where we more closely examine the doom and gloom of TOS, illuminating to people the sorts of terms they "agree" to without ever bothering to read (i.e. without understanding what they are consenting to).
One reader has looked into the TOS of RealVNC. "Here's the RealVNC one I wrote up a few months ago," she said. "After I wrote it up, I saw Raspberry Pi was announcing Connect and I asked on linkedin, if it did data collection and mentioned an analysis of RealVNC on my blog. The CIO asked me for a link. LOL. Image attached [above]."
By the way, we obscure names because Microsofters have been harassing and extorting people who participated - a subject we shall tackle separately some other day. They're viscerally hateful and vicious against women in particular.
Here is what she wrote down about her findings:
TOS – Real VNCApril 6, 2024
I only started reading the RealVNC ToS – and wow. I was only at 2.3 when I saw this: 2.3 You are only permitted to use the Software for educational and non-commercial purposes.
who knew?
And then this…
Where is this Data Agreement+ of which they speak? Separate document.
TOS - a PDF: https://www.realvnc.com/wp-content/uploads/2022/06/VNC-Connect-Raspberry-Pi-EULA-DP-Update-18-May-2022.pdf
Data Agreement: https://help.realvnc.com/hc/en-us/articles/5438412949405-Data-Processing-Agreement-DPA
10.1 If REALVNC acts as a processor of your personal data in accordance with applicable data protection law the terms of the Data Processing Agreement which is hereby incorporated by reference shall apply. In the event of a direct conflict between this Agreement and the Data Processing Agreement, the Data Processing Agreement will govern.
Gets a little more dark as you read the Data Processing agreement!
2.1 Customer will share Data with RealVNC and hereby appoints RealVNC as a Processor to Process the Data in connection with the provision of the Services (the “Permitted Purpose”).
I will? No. I will not!
14.8 Categories of personal data transferred: first name, last name, User Principal Name (UPN) (only if SSO is in use), country, phone number (if provided), email address, computer name (hostname), team name, device name, screenshots taken during the connection (only if enabled), labels, IP address, Mac addresses, product usage data and chat transcripts.
But why do you need to collect this data?!
While there were sections stating RealVNC would protect privacy laws, the mere fact they are collecting data such as usage and transcripts is a bit disconcerting as there was not full transparency of this when using the free version on Raspberry Pi OS or previously Raspbian.
Try another remote desktop app.
Again… if the product is free, you are the product.
Word Count: 5445 words
Average wpm: 240
Estimated read time: 22 minutes
We'll get back to it and examine similar TOS "doom" some other day later in this series. How many (Real)VNC users or Raspberry Pi customers are even aware of this? Some of these companies have financial objectives and they view users' behaviour/data as an "asset" they can sell for profit; do you wish to becoming their "client"? █