Services

SlHash Privacy

This notice describes how the personal data of users who use the Unipd4Me Application are processed. Pursuant to Articles 13 and 14 of Regulation (EU) 2016/679, laying down provisions on data protection, we provide those who interact with the Application with the following information, which we invite you to read carefully. In the paragraphs below, the following names will be used:

  • Application: the Unipd4Me mobile client for iOS and Android
  • University backend: the service mediation system between SlHash and UniWeb.

Data Controller

The Data Controller for the data processed through the Unipd4Me Application is the University of Padua.

Security of the request exchange channel

The Unipd4Me application is the application of the University of Padua, developed by the University in collaboration with Ennova Research srl. At present, the Unipd4Me Application and the supporting system SlHash, developed by Ennova, use the private University channel, which does not expose any message or any request to other channels. The private channel, made available by the SlHash service, is protected by end-to-end encryption, allowing secure data exchange between the parties.

Security of student credentials for access to University services

To access information services and backend devices, it is necessary to complete an authentication process by providing a University email address and password. To avoid requesting credentials at every login or when this expires, the Application stores authentication information on the mobile device, in a protected area accessible only to the Application.

The authentication information entered is sent to the backend using a secure channel (https), which in turn forwards it on the student's behalf to the University backend (UniWeb) in order to obtain a session token that remains valid until the student logs out through the Application or until its natural expiry (session time to live).

The session time to live is established by the University backend (UniWeb).

The session may close for various reasons, some technical (e.g. inactivity timeout or expiry of the authentication cookie of the University backend [UniWeb]). If necessary, the backend requests the forwarding of credentials to the University backend (UniWeb) and opens a new session without requiring any action by the user.

Once again, none of the credentials is stored in any of the systems crossed by the request (SlHash system and University backend).

To delete the credentials stored on the smartphone, it is sufficient to uninstall the App.

If the student changes their credentials through the University website (e.g. password change), it is necessary to provide the new credentials the next time they access the Application.

Credentials, tracking and information stored on SlHash

SlHash may reserve the right to save on the server side all possible generic information that may be useful for creating services that respond to the needs expressed by SlHash users, whether they are "owner" or "end-user".

The storage of such information requires the user's explicit consent, without which no information or data may be stored.

Among the data that SlHash may store are location and positioning data. Depending on the type of service, the sending of coordinates takes place on request and requires specific authorisations and actions by the user. Once positioning has been activated, it may remain active even when the application is running in the background (see the relevant App platform, iOS and Android). Where possible, messages are sent with geo-location.

All collected data are stored in association with an anonymous profile created on SlHash. 

Contact details of the Data Protection Officer

You can contact the Data Protection Officer of the University of Padua at the following email address: privacy@unipd.it

 

Last updated: 25 May 2018