Privacy & Terms of Use
SlHash Privacy
This policy describes the methods used to process the personal data of users who use the Unipd4Me Application. Pursuant to art. 13 and 14 of Regulation (EU) 2016/679, containing provisions on data protection, to those who interact with the Application, we provide the following information and which we invite you to read carefully. In the paragraphs below, the following names will be used:
- Application: the mobile client, iOS and Android, by Unipd4Me
- Backend of the University: the service mediation system between SlHash and UniWeb.
Holder
The Data Controller of the Unipd4Me Application is the University of Padova.
Security of the request exchange channel
The Unipd4Me application is the application of the University of Padova, developed by the University in collaboration with Ennova Research srl. Currently, the Unipd4Me Application and the system that supports it, SlHash, developed by Ennova, use the private university channel that does not expose any message or request to other channels. The private channel, exposed by the SlHash service, is protected by end-to-end encryption, allowing a secure exchange of data between the parties.
Security of the student's credentials for access to the University's services
To access the backend information services and devices, you need to go through an authentication process, providing your university email and password. To avoid requiring credentials at each login or when the validity of the login expires, the Application stores the authentication information on the mobile device, in a protected area accessible only to the Application.
The authentication information entered is communicated to the backend, using a secure channel (https), which in turn forwards it on behalf of the student to the university backend (UniWeb) to obtain a session token that is valid until the student logs out through the Application or until the natural expiration of the same (session time to live).
The time to live of the session is established by the University's backend (UniWeb).
The session can be closed for different reasons, some technical (e.g. inactivity timeout or expiration of the authentication cookie of the university backend [UniWeb]). If necessary, the backend requests the forwarding of credentials to the university backend (UniWeb) and opens a new session without requiring user intervention.
Again, none of the credentials are stored in any of the systems traversed by the request (SlHash system and university backend).
To delete the credentials stored on your smartphone, simply uninstall the App.
If the student changes his/her credentials through the university website (e.g. password change), he/she must provide the new credentials when he/she logs in to the Application again.
Credentials, tracking and information stored on SlHash
SlHash reserves the right to save on the server side all possible generic information that may be useful to create services that meet the expressed needs of SlHash users, whether they are "owner" or "end-user".
The storage of such information requires the explicit consent of the user, without which no information or data can be stored.
Among the data that SlHash can store is location and placement data. Depending on the type of service, the sending of coordinates takes place on request and requires specific authorizations and actions from the user. Once the positioning is activated, it can remain active even when the application is in the background (see the relevant platform of the App, iOS and Android). Where possible, messages are sent with geo-location.
All collected data is stored in association with an anonymous profile that is created on SlHash.
Contact details of the Data Protection Officer
It is possible to contact the Data Protection Officer of the University of Padova at the email address: privacy@unipd.it
Last updated: 25 May 2018