9a13683116
Initial set of documents
4.8 KiB
4.8 KiB
EasyLogon Privacy Policy
Last update: 26-Dec-21 (View change history)
1. General terms
- EasyLogon Privacy Policy (hereinafter "Policy") is applied to software developers, system administrators, internet-service maintainers, etc. (hereinafter "Customers") who implement EasyLogon solutions (like QR code authorization) to their software (hereinafter "Service").
- End-users (persons, who utilize EasyLogon mobile application and use EasyLogon QR code authorization to access their personal data) can find EasyLogon Privacy Policy for end-users at https://ezlog.app/privacy.
- By using our Service (by implementing it in software or accessing https://easylogon.foxdev.studio/ website) Customers agree to this Policy and EasyLogon Terms of Use.
- Policy is a complimentary document to EasyLogon Terms of Service which can be found on https://easylogon.foxdev.studio/terms.
- Up-to-date version of Policy can be found on https://easylogon.foxdev.studio/privacy.
- New versions of Policy are automatically applied to Customers as soon as they were published.
- Other versions of Policy, including outdated and upcoming versions presented in official EasyLogon documentation repository on GitHub (https://github.com/foxdev-studio/easylogon-docs) have no effect.
- FoxDev Studio LLC (hereinafter "Company") is obliged to notify Customer only about significant changes of the Policy.
- Significant changes are changes which include, but not limited to:
- Alterations in process of sharing Customer's personal data with Third-parties.
- Insignificant changes are changes which include, but not limited to:
- Extension or reduction of personal data, collected by the Service, described in paragraph 2.1;
- Alterations in the list of employees which have access to the data, described in paragraph 3.1;
- Timings of personal data retention, described in paragraphs 2.3 and 3.6.
- Significant changes are changes which include, but not limited to:
2. Personal data
- By using Service Customers delegate rights to the Company store, alter, process, delete and share their personal data on Company servers. This data includes:
- Account name;
- E-mail address;
- E-mail address verificaiton status;
- Password hash;
- One-time password generator secret key;
- List of domain names, connected to the Service;
- Statistics which includes number of sign-ins via the Service on connected domains;
- Technical support conversation history.
- Company does not store any other personal data, unless it is stated in paragraph 2.1. of the Policy
- Customers can revoke their approval by stopping using the Service and deleting their account on https://easylogon.foxdev.studio/editProfile. Approval will be revoked in 30 (thirty) calendar days after request has been issued.
3. Data protection
- Customers allow certain number of Company employees access and review their personal data stored on Company servers. Number of employees includes, but not limited to:
- Chief Security Officer;
- Chief Executing Officer;
- GDPR Compliance Officer;
- Database administrators;
- Technical Support Service members.
- All Company employees which have an access to Customer's data are obliged to sign a life-time non-disclosure agreement related to Customer's personal data
- All Customers' passwords stored on Company servers are encrypted using one-way hashing algorithms and cannot be revealed to anyone.
- Company may share your personal data with government authorities if there is any order issued.
- Company doesn't share your personal data with thrid-parties in any way (excluding the case described in paragraph 3.3 of the Policy)
- Following the General Data Protection Regulations (GDPR) Customers may request to access all data stored on Company servers. To do so, Customer should go to https://easylogon.foxdev.studio/editProfile, click "Download data" button.
- Customers can request data deletion by submitting EasyLogon acount deletion request. To do so, Customer should go to https://easylogon.foxdev.studio/editProfile, click "Delete account" button and fill out a form. All personal data will be deleted in 30 (thirty) calendar days.
- Company may use depersonalized data in its internal and external reports. Depersonalized data cannot include any data which can compromise Customers' account security on the Service, account names, domain names or conversation mailchains.
- Company is obliged to notify Customers about all data leaks or potential data leaks which can involve Customer's personal data within 3 days since the incident.