Beveiliging van je account
Wij nemen de beveiliging van je account serieus. Als je inlogt met een e-mailadres en wachtwoord, vereisen wij dat je een tweede verificatiestap (tweefactorauthenticatie, 2FA) instelt. Voor deze 2FA-functie gebruiken wij tijdgebaseerde eenmalige codes (TOTP, conform RFC 6238). Je TOTP-sleutel wordt versleuteld opgeslagen op onze server met AES-256-GCM encryptie. De sleutel verlaat onze server nooit in leesbare vorm.
Eenmalige herstelcodes worden eenmalig aan jou getoond bij het instellen en daarna nooit meer opgeslagen in leesbare vorm. Sla deze codes veilig op.
Ter bescherming van je account leggen wij beveiligingsgebeurtenissen vast (zoals inlogpogingen, gebruik van herstelcodes en het resetten van 2FA). Bij deze logging bewaren wij je IP-adres en het type apparaat/browser (user-agent): 12 maanden voor gebeurtenissen rond tweefactorauthenticatie (2FA) en voor alle inlogpogingen, ook de geslaagde. Gegevens van een afgebroken inlog in de app verwijderen wij al na 7 dagen. Na afloop van deze termijnen verwijderen wij de gegevens automatisch.
GRIP Mobiele App
Gegevens die wij verwerken in de mobiele app
Wanneer je de GRIP Mobile-app gebruikt, verwerken wij de volgende gegevens:
| Gegeven | Doel | Bewaartermijn |
|---|---|---|
| E-mailadres | Identificatie bij inloggen | Zolang account actief is |
| Wachtwoord | Verificatie bij inloggen (nooit opgeslagen; alleen gecontroleerd) | Niet bewaard (transit only) |
| Toegangstoken | Autorisatie van app-verzoeken aan de server | Korte termijn (sessieduur) |
| Verversingstoken | Automatisch verlengen van je sessie | Tot afmelding of inactiviteit |
| IP-adres (bij 2FA- en inlogregistratie) | Beveiliging en fraudedetectie | 12 maanden |
| User-agent (bij 2FA- en inlogregistratie) | Beveiliging en fraudedetectie | 12 maanden |
Opslag op je apparaat
De GRIP Mobile-app slaat toegangs- en verversingstokens op in de beveiligde opslagfaciliteit van je apparaat (iOS Keychain of Android Keystore). Deze gegevens zijn versleuteld en zijn niet toegankelijk voor andere apps.
Camera
De app vraagt om toegang tot je camera voor het scannen van QR-codes en barcodes van apparaten, en voor het maken van foto's van patchkasten en netwerkruimten. Camera-beelden worden niet opgeslagen of doorgestuurd zonder jouw expliciete actie.
Fotobibliotheek
De app kan toegang vragen tot je fotobibliotheek om bestaande afbeeldingen te kiezen voor OCR-tekstherkenning of voor uploads naar netwerkmedia (bijvoorbeeld patchkast-documentatie). De app leest alleen de afbeelding die jij selecteert; er wordt geen overige fotobibliotheek-inhoud verwerkt.
Je rechten
Je hebt het recht op inzage, correctie en verwijdering van je persoonsgegevens. Voor verwijdering van je account en alle bijbehorende gegevens kun je contact opnemen met je systeembeheerder of een verzoek indienen via de account-verwijder-pagina. Na verwijdering van je account worden al je gegevens, inclusief 2FA-instellingen en audit-logs, automatisch verwijderd.
Wie je gegevens ontvangt — en waar GRIP gegevens vandaan haalt
GRIP verkoopt je gegevens niet en gebruikt ze niet voor reclame. Hieronder staan twee verschillende dingen, omdat ze vaak door elkaar lopen: partijen die gegevens van ons ontvangen, en partijen waar GRIP gegevens ophaalt.
Partijen die gegevens van ons ontvangen
- Hetzner Online GmbH (Duitsland) — levert de servers en de database waarop GRIP draait. Alles staat binnen de Europese Unie. Hetzner is een subverwerker van EduNexus.
- EduNexus Mijn Leeromgeving (MLS) — de inlogvoorziening van EduNexus zelf. Sinds 20 juli 2026 is dit de standaard-inlogroute voor GRIP. Bij het inloggen worden je e-mailadres, naam en de organisatie waartoe je behoort uitgewisseld. MLS wordt beheerd door EduNexus B.V. en draait op servers binnen de Europese Unie.
- Microsoft — log je in met je Microsoft-account, dan verloopt die stap via Microsoft Entra ID. Microsoft ziet daarbij dat je op dat moment op GRIP inlogt. Meer stuurt GRIP niet naar Microsoft.
Bronnen waar GRIP gegevens ophaalt
Gebruikt jouw school Intune of Google Workspace voor apparaatbeheer, dan haalt GRIP daar apparaatgegevens op. Dat verkeer gaat maar één kant op: GRIP leest, en schrijft er niets terug. De toegang loopt via een koppeling die je school zelf in haar eigen omgeving aanmaakt, met uitsluitend leesrechten.
- Microsoft Intune — in de eigen Microsoft-omgeving van je school, met een app-registratie die je school zelf aanmaakt.
- Google Workspace — in de eigen Google-omgeving van je school. Je school geeft GRIP één keer toestemming met een vast koppelaccount met alleen leesrechten (Chromebooks, organisatie-eenheden en klantgegevens). Bij het verbinden krijgt GRIP van Google ook het e-mailadres van dat koppelaccount, zodat zichtbaar is met welk account je school verbonden is. Je school kan die toestemming op elk moment intrekken, in GRIP of in de Google Admin-console. Heeft je school nog een oudere koppeling met een serviceaccount dat ze zelf heeft aangemaakt, dan gelden daarvoor dezelfde drie leesrechten.
Voor deze twee koppelingen heeft je school zelf de overeenkomst met Microsoft respectievelijk Google, niet EduNexus. Vindt daarbij verwerking buiten de Europese Economische Ruimte plaats, dan berust die op de afspraken die je school met die partij heeft gemaakt.
Verder verstrekken wij gegevens alleen aan politie, justitie of een toezichthouder als de wet ons daartoe verplicht.
Gegevens uit Google Workspace
GRIP leest per Chromebook onder meer het serienummer, het model, het MAC-adres, de versie van het besturingssysteem, de organisatie-eenheid, de einddatum van de ondersteuning, de tijdstippen van inschrijving en laatste synchronisatie, en de labels die je school zelf invult (Asset-ID en Locatie). GRIP vraagt niet op wie er op een Chromebook heeft ingelogd, en leest geen mail, Drive of agenda. Het leesrecht geeft Google technisch wel toegang tot meer velden. GRIP vraagt die niet op en bewaart ze niet.
Om de koppeling te laten werken, bewaart GRIP per school een toegangssleutel van Google (een refresh token), versleuteld en apart beveiligd. Die sleutel bewaren we zolang de koppeling actief is, samen met het e-mailadres van het koppelaccount. Koppelt je school los, dan trekken we de sleutel in bij Google en wissen we hem direct. Moet de koppeling al 30 dagen opnieuw worden verbonden (de sleutel werkt dan niet meer), dan wissen we hem automatisch. Een onvoltooide poging om te verbinden verloopt na een uur en wordt daarna automatisch gewist. Het synchronisatielogboek bewaren we standaard 30 dagen (je stichting kan dat tussen 14 en 90 dagen instellen), zonder e-mailadressen.
Het gebruik door GRIP van gegevens uit Google-API's, en het doorgeven daarvan aan een andere app, voldoet aan het Google API Services User Data Policy, inclusief de eisen voor beperkt gebruik (Limited Use).
Verwerkingsverantwoordelijke en verwerker
Verwerkingsverantwoordelijke: uw stichting, school of werkgever (de klant van GRIP). Zij bepaalt het doel en de middelen van de verwerking van persoonsgegevens binnen deze applicatie.
Verwerker: EduNexus B.V., uitgever van het
GRIP-platform en de mobiele app. EduNexus verwerkt
persoonsgegevens uitsluitend in opdracht van uw stichting,
conform de tussen partijen gesloten verwerkersovereenkomst.
EduNexus B.V., Buitendijklaan 128, 2353 VR Leiderdorp, Nederland.
KvK 42042075. Voor privacyvragen: privacy@edunexus.nl.
Voor vragen over de verwerking van jouw persoonsgegevens neem je in eerste instantie contact op met de beheerder van jouw stichting of organisatie. Algemene vragen over GRIP kun je richten aan privacy@edunexus.nl.
Account Security
We take the security of your account seriously. If you sign in using an email address and password, we require you to set up a second verification step (two-factor authentication, 2FA). For this 2FA feature, we use time-based one-time codes (TOTP, as per RFC 6238). Your TOTP key is stored on our server in encrypted form using AES-256-GCM encryption and never leaves our server in readable form.
One-time recovery codes are shown to you once during setup and are never stored in readable form thereafter. Please store these codes in a safe place.
To protect your account, we log security events (such as sign-in attempts, use of recovery codes, and 2FA resets). For these logs, we retain your IP address and device/browser type (user-agent) for 12 months for two-factor authentication (2FA) events and for all sign-in attempts, including successful ones. Data from an interrupted sign-in in the app is deleted after 7 days. When these periods end, we delete the data automatically.
GRIP Mobile App
Data we process in the mobile app
When you use the GRIP Mobile app, we process the following data:
| Data | Purpose | Retention |
|---|---|---|
| Email address | Account identification for sign-in | For the duration of your account |
| Password | Sign-in verification (never stored; verified only) | Not retained (transit only) |
| Access token | Authorization of app requests to the server | Short-term (session duration) |
| Refresh token | Automatic session renewal | Until logout or inactivity |
| IP address (at 2FA and sign-in logging) | Security and fraud detection | 12 months |
| User-agent (at 2FA and sign-in logging) | Security and fraud detection | 12 months |
Storage on your device
The GRIP Mobile app stores access and refresh tokens in your device's secure storage facility (iOS Keychain or Android Keystore). This data is encrypted and inaccessible to other apps.
Camera
The app requests access to your camera to scan QR codes and barcodes on devices, and to take photos of network rooms and patch panels. Camera images are not stored or transmitted without your explicit action.
Photo Library
The app may request access to your photo library to pick existing images for OCR text recognition or for uploads to network media (for example, patch-panel documentation). The app only reads the image you select; no other photo-library content is processed.
Your rights
You have the right to access, rectify, and delete your personal data. To delete your account and all associated data, please contact your system administrator or submit a request via the account deletion page. Upon account deletion, all your data — including 2FA settings and audit logs — will be automatically deleted.
Who receives your data — and where GRIP reads data from
GRIP does not sell your data and does not use it for advertising. The section below separates two things that are often conflated: parties that receive data from us, and parties that GRIP reads data from.
Parties that receive data from us
- Hetzner Online GmbH (Germany) — provides the servers and database GRIP runs on. Everything stays within the European Union. Hetzner is a sub-processor of EduNexus.
- EduNexus Mijn Leeromgeving (MLS) — EduNexus's own sign-in service. Since 20 July 2026 this is the standard sign-in route for GRIP. Signing in exchanges your email address, name and the organisation you belong to. MLS is operated by EduNexus B.V. and runs on servers within the European Union.
- Microsoft — if you sign in with your Microsoft account, that step goes through Microsoft Entra ID. Microsoft therefore sees that you are signing in to GRIP at that moment. GRIP sends nothing further to Microsoft.
Sources GRIP reads data from
If your school uses Intune or Google Workspace for device management, GRIP retrieves device data from there. That traffic goes one way only: GRIP reads, and writes nothing back. Access runs through a connection your school creates in its own environment, with read-only permissions.
- Microsoft Intune — in your school's own Microsoft environment, using an app registration your school creates itself.
- Google Workspace — in your school's own Google environment. Your school grants GRIP access once, using a dedicated connection account with read-only permissions (Chromebooks, organizational units and customer details). When connecting, Google also gives GRIP the email address of that connection account, so that it is clear which account your school used to connect. Your school can withdraw that access at any time, in GRIP or in the Google Admin console. If your school still has an older connection using a service account it created itself, the same three read-only permissions apply to it.
For these two connections, your school holds the agreement with Microsoft or Google respectively, not EduNexus. Where processing takes place outside the European Economic Area, it rests on the arrangements your school has made with that party.
Beyond this, we only provide data to police, judicial authorities or a supervisory authority where the law obliges us to.
Data from Google Workspace
For each Chromebook, GRIP reads details such as the serial number, model, MAC address, operating system version, organizational unit, end-of-support date, enrolment and last sync times, and the labels your school fills in itself (Asset ID and Location). GRIP does not request who has signed in to a Chromebook, and does not read mail, Drive or Calendar. The read permission technically gives access to more fields; GRIP does not request or store them.
To keep the connection working, GRIP stores one Google access credential per school (a refresh token), encrypted and separately secured. We keep it for as long as the connection is active, together with the email address of the connection account. If your school disconnects, we revoke the credential with Google and delete it immediately. If the connection has needed reconnecting for 30 days (the credential no longer works), we delete it automatically. An unfinished connection attempt expires after one hour and is then deleted automatically. The sync log is kept for 30 days by default (your foundation can set this between 14 and 90 days), without email addresses.
GRIP's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Data Controller and Data Processor
Data Controller: your foundation, school, or employer (the GRIP customer). They determine the purpose and means of processing personal data within this application.
Data Processor: EduNexus B.V., publisher of
the GRIP platform and mobile app. EduNexus processes personal
data solely on behalf of your foundation, in accordance with
the data processing agreement signed between the parties.
EduNexus B.V., Buitendijklaan 128, 2353 VR Leiderdorp, the Netherlands.
Chamber of Commerce 42042075. For privacy questions:
privacy@edunexus.nl.
For questions about the processing of your personal data, please first contact the administrator of your foundation or organisation. General questions about GRIP can be sent to privacy@edunexus.nl.