Beveiliging van je account

Wij nemen de beveiliging van je account serieus. Als je inlogt met een e-mailadres en wachtwoord, vereisen wij dat je een tweede verificatiestap (tweefactorauthenticatie, 2FA) instelt. Voor deze 2FA-functie gebruiken wij tijdgebaseerde eenmalige codes (TOTP, conform RFC 6238). Je TOTP-sleutel wordt versleuteld opgeslagen op onze server met AES-256-GCM encryptie. De sleutel verlaat onze server nooit in leesbare vorm.

Eenmalige herstelcodes worden eenmalig aan jou getoond bij het instellen en daarna nooit meer opgeslagen in leesbare vorm. Sla deze codes veilig op.

Ter bescherming van je account leggen wij beveiligingsgebeurtenissen vast (zoals inlogpogingen, gebruik van herstelcodes en het resetten van 2FA). Bij deze logging bewaren wij je IP-adres en het type apparaat/browser (user-agent): 12 maanden voor gebeurtenissen rond tweefactorauthenticatie (2FA) en voor alle inlogpogingen, ook de geslaagde. Gegevens van een afgebroken inlog in de app verwijderen wij al na 7 dagen. Na afloop van deze termijnen verwijderen wij de gegevens automatisch.

GRIP Mobiele App

Gegevens die wij verwerken in de mobiele app

Wanneer je de GRIP Mobile-app gebruikt, verwerken wij de volgende gegevens:

Gegeven Doel Bewaartermijn
E-mailadres Identificatie bij inloggen Zolang account actief is
Wachtwoord Verificatie bij inloggen (nooit opgeslagen; alleen gecontroleerd) Niet bewaard (transit only)
Toegangstoken Autorisatie van app-verzoeken aan de server Korte termijn (sessieduur)
Verversingstoken Automatisch verlengen van je sessie Tot afmelding of inactiviteit
IP-adres (bij 2FA- en inlogregistratie) Beveiliging en fraudedetectie 12 maanden
User-agent (bij 2FA- en inlogregistratie) Beveiliging en fraudedetectie 12 maanden

Opslag op je apparaat

De GRIP Mobile-app slaat toegangs- en verversingstokens op in de beveiligde opslagfaciliteit van je apparaat (iOS Keychain of Android Keystore). Deze gegevens zijn versleuteld en zijn niet toegankelijk voor andere apps.

Camera

De app vraagt om toegang tot je camera voor het scannen van QR-codes en barcodes van apparaten, en voor het maken van foto's van patchkasten en netwerkruimten. Camera-beelden worden niet opgeslagen of doorgestuurd zonder jouw expliciete actie.

Fotobibliotheek

De app kan toegang vragen tot je fotobibliotheek om bestaande afbeeldingen te kiezen voor OCR-tekstherkenning of voor uploads naar netwerkmedia (bijvoorbeeld patchkast-documentatie). De app leest alleen de afbeelding die jij selecteert; er wordt geen overige fotobibliotheek-inhoud verwerkt.

Je rechten

Je hebt het recht op inzage, correctie en verwijdering van je persoonsgegevens. Voor verwijdering van je account en alle bijbehorende gegevens kun je contact opnemen met je systeembeheerder of een verzoek indienen via de account-verwijder-pagina. Na verwijdering van je account worden al je gegevens, inclusief 2FA-instellingen en audit-logs, automatisch verwijderd.

Wie je gegevens ontvangt — en waar GRIP gegevens vandaan haalt

GRIP verkoopt je gegevens niet en gebruikt ze niet voor reclame. Hieronder staan twee verschillende dingen, omdat ze vaak door elkaar lopen: partijen die gegevens van ons ontvangen, en partijen waar GRIP gegevens ophaalt.

Partijen die gegevens van ons ontvangen

Bronnen waar GRIP gegevens ophaalt

Gebruikt jouw school Intune of Google Workspace voor apparaatbeheer, dan haalt GRIP daar apparaatgegevens op. Dat verkeer gaat maar één kant op: GRIP leest, en schrijft er niets terug. De toegang loopt via een koppeling die je school zelf in haar eigen omgeving aanmaakt, met uitsluitend leesrechten.

Voor deze twee koppelingen heeft je school zelf de overeenkomst met Microsoft respectievelijk Google, niet EduNexus. Vindt daarbij verwerking buiten de Europese Economische Ruimte plaats, dan berust die op de afspraken die je school met die partij heeft gemaakt.

Verder verstrekken wij gegevens alleen aan politie, justitie of een toezichthouder als de wet ons daartoe verplicht.

Gegevens uit Google Workspace

GRIP leest per Chromebook onder meer het serienummer, het model, het MAC-adres, de versie van het besturingssysteem, de organisatie-eenheid, de einddatum van de ondersteuning, de tijdstippen van inschrijving en laatste synchronisatie, en de labels die je school zelf invult (Asset-ID en Locatie). GRIP vraagt niet op wie er op een Chromebook heeft ingelogd, en leest geen mail, Drive of agenda. Het leesrecht geeft Google technisch wel toegang tot meer velden. GRIP vraagt die niet op en bewaart ze niet.

Om de koppeling te laten werken, bewaart GRIP per school een toegangssleutel van Google (een refresh token), versleuteld en apart beveiligd. Die sleutel bewaren we zolang de koppeling actief is, samen met het e-mailadres van het koppelaccount. Koppelt je school los, dan trekken we de sleutel in bij Google en wissen we hem direct. Moet de koppeling al 30 dagen opnieuw worden verbonden (de sleutel werkt dan niet meer), dan wissen we hem automatisch. Een onvoltooide poging om te verbinden verloopt na een uur en wordt daarna automatisch gewist. Het synchronisatielogboek bewaren we standaard 30 dagen (je stichting kan dat tussen 14 en 90 dagen instellen), zonder e-mailadressen.

Het gebruik door GRIP van gegevens uit Google-API's, en het doorgeven daarvan aan een andere app, voldoet aan het Google API Services User Data Policy, inclusief de eisen voor beperkt gebruik (Limited Use).

Verwerkingsverantwoordelijke en verwerker

Verwerkingsverantwoordelijke: uw stichting, school of werkgever (de klant van GRIP). Zij bepaalt het doel en de middelen van de verwerking van persoonsgegevens binnen deze applicatie.

Verwerker: EduNexus B.V., uitgever van het GRIP-platform en de mobiele app. EduNexus verwerkt persoonsgegevens uitsluitend in opdracht van uw stichting, conform de tussen partijen gesloten verwerkersovereenkomst.
EduNexus B.V., Buitendijklaan 128, 2353 VR Leiderdorp, Nederland. KvK 42042075. Voor privacyvragen: privacy@edunexus.nl.

Voor vragen over de verwerking van jouw persoonsgegevens neem je in eerste instantie contact op met de beheerder van jouw stichting of organisatie. Algemene vragen over GRIP kun je richten aan privacy@edunexus.nl.

Account Security

We take the security of your account seriously. If you sign in using an email address and password, we require you to set up a second verification step (two-factor authentication, 2FA). For this 2FA feature, we use time-based one-time codes (TOTP, as per RFC 6238). Your TOTP key is stored on our server in encrypted form using AES-256-GCM encryption and never leaves our server in readable form.

One-time recovery codes are shown to you once during setup and are never stored in readable form thereafter. Please store these codes in a safe place.

To protect your account, we log security events (such as sign-in attempts, use of recovery codes, and 2FA resets). For these logs, we retain your IP address and device/browser type (user-agent) for 12 months for two-factor authentication (2FA) events and for all sign-in attempts, including successful ones. Data from an interrupted sign-in in the app is deleted after 7 days. When these periods end, we delete the data automatically.

GRIP Mobile App

Data we process in the mobile app

When you use the GRIP Mobile app, we process the following data:

Data Purpose Retention
Email address Account identification for sign-in For the duration of your account
Password Sign-in verification (never stored; verified only) Not retained (transit only)
Access token Authorization of app requests to the server Short-term (session duration)
Refresh token Automatic session renewal Until logout or inactivity
IP address (at 2FA and sign-in logging) Security and fraud detection 12 months
User-agent (at 2FA and sign-in logging) Security and fraud detection 12 months

Storage on your device

The GRIP Mobile app stores access and refresh tokens in your device's secure storage facility (iOS Keychain or Android Keystore). This data is encrypted and inaccessible to other apps.

Camera

The app requests access to your camera to scan QR codes and barcodes on devices, and to take photos of network rooms and patch panels. Camera images are not stored or transmitted without your explicit action.

Photo Library

The app may request access to your photo library to pick existing images for OCR text recognition or for uploads to network media (for example, patch-panel documentation). The app only reads the image you select; no other photo-library content is processed.

Your rights

You have the right to access, rectify, and delete your personal data. To delete your account and all associated data, please contact your system administrator or submit a request via the account deletion page. Upon account deletion, all your data — including 2FA settings and audit logs — will be automatically deleted.

Who receives your data — and where GRIP reads data from

GRIP does not sell your data and does not use it for advertising. The section below separates two things that are often conflated: parties that receive data from us, and parties that GRIP reads data from.

Parties that receive data from us

Sources GRIP reads data from

If your school uses Intune or Google Workspace for device management, GRIP retrieves device data from there. That traffic goes one way only: GRIP reads, and writes nothing back. Access runs through a connection your school creates in its own environment, with read-only permissions.

For these two connections, your school holds the agreement with Microsoft or Google respectively, not EduNexus. Where processing takes place outside the European Economic Area, it rests on the arrangements your school has made with that party.

Beyond this, we only provide data to police, judicial authorities or a supervisory authority where the law obliges us to.

Data from Google Workspace

For each Chromebook, GRIP reads details such as the serial number, model, MAC address, operating system version, organizational unit, end-of-support date, enrolment and last sync times, and the labels your school fills in itself (Asset ID and Location). GRIP does not request who has signed in to a Chromebook, and does not read mail, Drive or Calendar. The read permission technically gives access to more fields; GRIP does not request or store them.

To keep the connection working, GRIP stores one Google access credential per school (a refresh token), encrypted and separately secured. We keep it for as long as the connection is active, together with the email address of the connection account. If your school disconnects, we revoke the credential with Google and delete it immediately. If the connection has needed reconnecting for 30 days (the credential no longer works), we delete it automatically. An unfinished connection attempt expires after one hour and is then deleted automatically. The sync log is kept for 30 days by default (your foundation can set this between 14 and 90 days), without email addresses.

GRIP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Data Controller and Data Processor

Data Controller: your foundation, school, or employer (the GRIP customer). They determine the purpose and means of processing personal data within this application.

Data Processor: EduNexus B.V., publisher of the GRIP platform and mobile app. EduNexus processes personal data solely on behalf of your foundation, in accordance with the data processing agreement signed between the parties.
EduNexus B.V., Buitendijklaan 128, 2353 VR Leiderdorp, the Netherlands. Chamber of Commerce 42042075. For privacy questions: privacy@edunexus.nl.

For questions about the processing of your personal data, please first contact the administrator of your foundation or organisation. General questions about GRIP can be sent to privacy@edunexus.nl.