Privacy notice - BSI Service tool app

This Privacy Notice is concerned only with the data collected and processed where ASSA ABLOY Entrance Systems AB acts as the controller.

ASSA ABLOY Entrance Systems AB is committed to protecting your personal data. This Privacy Notice describes how ASSA ABLOY Entrance Systems processes the personal data (your "Data") that we receive from you in connection with your use of the App. 

This privacy notice describes

  • The types of personal data we collect from you in connection with the BSI Service Tool app.
  • How we collect personal data from you.
  • How we use that information and why.
  • Who we share data with and where.
  • How long we store data for.
  • How we can make changes to this notice.

 

ASSA ABLOY Entrance Systems AB of Lodjursgatan 10, Landskrona, Sweden, as "data controller" is responsible for the processing of your personal data in this Privacy Notice. 

What personal data will we collect? 

We collect the following Data, which can be considered personal data according to applicable laws and regulations:

  • Android ID “IAM data”
  • Control Unit Change log based on your use of the App
  • Crash tracers and their associated identifiers

How we obtain data

We obtain personal data from Google Firebase Crashlytics when the App for some reason crashes.

Purpose and legal basis for collecting and processing your Data

What is the legal basis for such processing?

Crash tracers and their associated identifiers are stored to capture any bugs in the BSI Service Tool app

It is in our legitimate interest to store Crash tracers and their associated identifiers for us to improve the BSI Service Tool App. The personal data being processed is non-sensitive and the processing is limited, consequently we have concluded that our legitimate interest to improve the BSI Service Tool App takes precedence over your privacy interest.

IAM data is processed to verify your identity for security purposes.

It is in our legitimate interest to ensure the identity of App users for security reasons. The personal data being processed is non-sensitive and the processing is limited, consequently we have concluded that our legitimate interest to ensure security takes precedence over your privacy interest.

Control Unit change logs are processed to improve the App and help our customers with troubleshooting.

It is in our legitimate interest to store activity logs for us to improve the BSI Service Tool App and help our customers with troubleshooting. The personal data being processed is non-sensitive and the processing is limited, consequently we have concluded that our legitimate interest to improve the BSI Service Tool App takes precedence over your privacy interest.

 

Who we may disclose data to

We may disclose your personal data for the purposes set out above to:

  • ASSA ABLOY Entrance System AB support run by a third party (see below).

A third party that provides remote 2nd line support is a recipient of your personal data and is in Sweden, inside the EU/European Economic Area (EEA). 

The personal data may only be processed to provide the support services and we remain responsible for the lawfulness of the service provider’s processing.  

We may use Google Firebase Crashlytics when obtaining the data for the purposes set out above. In the Google Firebase Crashlytics we are only using the feature of Crash Reporting. Please read more about the processing carried out by the Google Firebase App at   https://firebase.google.com/support/privacy.

Transfer

We may share your information with our trusted subcontractor to analyze crash tracers for the purposes set out in this Privacy Notice. Processing of data may therefore take place in a country other than your home country.

 

For how long will we store your personal data? 

Crash tracers and their associated identifiers are kept for 90 days.

Your rights

Below follows a description of the rights you have regarding our processing of your personal data. You are welcome to contact us to exercise your rights (see contact information below).

Right to withdraw your consent and object to the processing
You may at any time withdraw any consent you have given us with effect from the day of the withdrawal. You may object to our processing of your personal data for marketing purposes. We will then cease to process your personal data. You also have the right to object to the processing of your personal data performed based on our legitimate interest.

Right to access
You are entitled to request information about which personal data we process about you and how the personal data is being processed. You also have the right to request a copy of the personal data we process about you. 

Right to rectification
You have the right to without unnecessary delay get inaccurate information corrected and to get incomplete information completed by providing us with correct information.  

Right to erasure (right to be forgotten) and limitation
You have the right to at any time request that your data is erased, for example if the processing is no longer relevant in relation to the purpose the information was collected for, or if you object to processing which is based on our legitimate interests (marketing). You may also request to have certain processing of your personal data restricted, for example if you object to the accuracy of the data. 

Right to data portability
If you have given your consent to the processing or if the legal basis for processing is to fulfil an agreement with you, you have the right to obtain the personal data you have provided us with in a structured, commonly used and machine-readable format and have the right to transmit such to another controller or get our assistance to transmit the data to another controller when technically feasible. 

Right to object
If you have a complaint regarding our processing of your personal data you are entitled to lodge a complaint to the Supervisor Authority in your country. Please check this site (https://edpb.europa.eu/about-edpb/board/members_en) at the European Data Protection Board for a list of Supervisor Authorities per country.

We would like to take this opportunity to remind you that you can also find our internal privacy notice on the corporate website.

If you want to make a request in relation to the processing of your personal data, please let us know by sending an email to privacy.entrance@assaabloy.com. Please note that we may contact you and ask you to confirm your identity to ensure that we do not disclose your personal data to any unauthorized person, and that we may ask you to specify your request before we perform any actions. Once we have confirmed your identity, we will handle the request in accordance with applicable law. 

How can we make changes to this privacy notice? 

We may update this privacy notice from time to time in response to changing legal, regulatory or operational requirements. We will notify you of any such changes (including when they will take effect). 

Contact

Requests to exercise your rights should be addressed to “Attn.: ASSA ABLOY Data Protection Manager” at ASSA ABLOY Entrance Systems AB or privacy.entrance@assaabloy.com.

Privacy Policy Date: 2022-10-10