Legal

Acceptable Use Policy

Last updated: 2 September 2026

RDesk exists so that a technician can help someone with their computer. This policy sets out what that does and does not permit. It applies to everyone who uses the Service and forms part of our Terms of Service.

One rule underpins all of the others: consent. Every RDesk session must be one the owner of the computer has agreed to. Using RDesk to reach a machine without the informed permission of the person who owns or lawfully controls it is unauthorised access — it is prohibited here, and it is a criminal offence under the Digital Security Act and equivalent computer-misuse laws elsewhere.

01What RDesk is for

Legitimate uses include:

  • An IT team or managed service provider supporting computers belonging to their own organisation or to clients who have engaged them.
  • A help desk assisting a colleague or customer who has asked for help and clicks Allow at their machine.
  • An administrator reaching their own servers, kiosks or unattended workstations.
  • An individual reaching their own computers — a work machine from home, or a home machine while travelling.
  • Remote training and demonstrations where the person at the machine has agreed to share it.

02Prohibited uses

You must not use RDesk, or the RDesk agent, to do any of the following.

Access without authorisation

  • Connect to any computer you do not own and have not been given permission to access.
  • Install the Agent on a computer without the knowledge and permission of its owner.
  • Enable unattended access on a machine whose owner has not agreed to it.
  • Retain access to a machine after permission has been withdrawn, or after the support engagement has ended.
  • Use credentials, session IDs or unattended passwords obtained from someone other than the machine's owner.

Concealment and tampering

The consent prompt, the on-screen session banner, the tray icon and the End-session control are safety features. Any attempt to defeat them converts a support tool into spyware, and is grounds for immediate and permanent termination.
  • Modify, patch, repackage, rebrand or rebuild the Agent so that it suppresses or hides the Allow/Deny prompt, the “Remote control active” banner, the tray icon, or the session-ending control.
  • Hide the Agent's process, service, window, installation folder or uninstaller from the person using the machine.
  • Obscure, cover, move off-screen or otherwise defeat the on-screen session indicator.
  • Bundle the Agent inside another installer, or install it silently, so that the machine's user is unaware it is present.
  • Apply packing, obfuscation, or any technique intended to evade anti-virus or endpoint-detection software.
  • Deploy the Agent at scale to machines whose owners have not agreed to be supported.

Surveillance and harassment

  • Monitor a partner, family member, employee or any other person covertly.
  • Capture keystrokes, screen content, clipboard data, camera or microphone input outside an approved, visible session.
  • Stalk, harass, intimidate, threaten or defame anyone.
  • Access, collect or exfiltrate personal data, credentials, financial records or private files without a lawful basis and the owner's permission.

Fraud and social engineering

  • Run technical-support scams — contacting people with fabricated warnings about their computer in order to obtain remote access.
  • Impersonate a bank, a government body, a manufacturer, a courier, or any organisation you do not represent, in order to persuade someone to install the Agent or approve a session.
  • Pressure, mislead or rush anyone into granting access, or coach them into approving a prompt they do not understand.
  • Use remote access to induce a payment, a transfer, a purchase of gift cards, or the disclosure of a one-time passcode.

Malicious and unlawful activity

  • Distribute malware, ransomware, spyware or unwanted software, or use a session to deploy any of them.
  • Encrypt, destroy, damage or hold to ransom data on any machine.
  • Conduct penetration testing, vulnerability scanning or red-team activity against systems you have not been authorised in writing to test.
  • Attack, probe or attempt to gain unauthorised access to RDesk's own infrastructure, or to circumvent authentication, quotas or account boundaries.
  • Store, transmit or access material that is unlawful, including child sexual abuse material, or content that infringes intellectual property rights.
  • Use the Service to send spam, or as a proxy, relay or exit point to disguise the origin of other traffic.

Service abuse

  • Resell, sublicense or white-label the Service without a written agreement with us.
  • Share one account among multiple technicians in order to avoid per-seat pricing or to obscure who connected.
  • Place disproportionate load on the relay infrastructure, or use automation that degrades the Service for others.
  • Circumvent plan limits, or create accounts to evade a suspension.

03If you are the person being supported

You are in control of your machine. You should:

  • Only approve a session when you initiated contact with a technician you trust. A legitimate support provider will not cold-call you about a problem with your computer.
  • Read the name shown on the Allow prompt before approving, and deny anything you did not expect.
  • Remember that approving the screen does not approve file access — that is a second, separate prompt.
  • Watch for the on-screen banner during the session; it lists who is connected, and you can end the session from it at any time.
  • Uninstall the Agent when the support engagement is over, and change any unattended password you shared.
If someone pressured you into granting access, end the session using the control on the banner, uninstall the Agent, and contact your bank if any financial detail was visible. Then report it to us at abuse@rdesk.bd — the report helps us remove the account.

04Reporting abuse

If you believe RDesk is being used against this policy, report it to abuse@rdesk.bd. Where you can, include the Display ID of the machine involved, the approximate date and time, and any account name or contact details the other party used. Reports are treated confidentially.

Suspected security vulnerabilities in RDesk itself should go to security@rdesk.bd rather than being disclosed publicly, so that we can fix them before they are exploited.

05Enforcement

We investigate credible reports. Depending on what we find we may warn the account holder, require evidence that access was authorised, suspend the account, terminate it permanently, or refer the matter to law enforcement.

For unauthorised access, concealment of the Agent, technical-support scams, or the deployment of malware, suspension is immediate and permanent, without notice. We may preserve and disclose account and connection records where we are legally required to do so, or where it is necessary to investigate abuse or protect people from harm.

We do not monitor the content of sessions. Enforcement is driven by reports and by operational signals such as connection metadata — not by watching what you do on a machine.

06Changes

This policy may be updated as new forms of abuse appear. The “last updated” date above will change, and material changes will be notified through the console or by email. Continuing to use the Service means you accept the updated policy.

07Contact

Abuse reports: abuse@rdesk.bd
Security reports: security@rdesk.bd
Everything else: support@rdesk.bd

See also our Terms of Service and Privacy Policy.