This document describes the methods and logic of the processing of personal data of data subjects following the use of the Workplace Explorer. This information is provided pursuant to Articles 13 and 14 of EU Reg. 2016/679, respectively, to the Principal and to all interested parties who may interact with Synapses Srls by providing their personal data directly and/or indirectly.
The data controller of the data collected is Synapses Srls, located in Via Madre Geltrude Comensoli 5 26833 Comazzo, Italy
The Data Protection Officer is Stefania Pusateri, who can be contacted at dpo@synapseslab.com.
Synapses Srls provides its customers with Workplace Explorer, which can be installed either in the cloud or on premises. It is an RTLS middleware whose primary function is to manage positional information from one or more RTLS (Real-Time Location System) systems. The platform also enables the management of information from third-party systems, such as IoT sensors.
Workplace Explorer can be interconnected to RTLS systems of various types. In general, such systems can be classified into the following categories:
In general, Workplace Explorer is able to handle incoming information in different ways:
Workplace Explorer can be interconnected with the following systems in order to implement specific use cases:
The Workplace Explorer framework can be provided with the following interfaces involving end users:
Workplace Explorer can be supplied with the following modules and/or functions involving end users:
Integration with the SSO of third-party systems (e.g. Microsoft SSO) allows the user to log in to both mobile APP and WEB Booking without the user having to perform any registration process. The configuration of the SSO module can be done by defining in detail what user information will be sent to Workplace Explorer. In general, only the e-mail address, first name and last name are required. Other information such as department, working groups etc. can be used for specific use cases (e.g. generating aggregated statistics for departments).
When this module is enabled, the system is able to know and historicise the position of the individual user
in
accordance with the logics defined with the DPO of the Client/Purchaser.
If the user's location is calculated on the basis of information generated through the APP, the user will
have
the option of not granting location use privileges or disabling Bluetooth and GPS by preventing the APP from
generating information to locate the user.
If, on the other hand, the user is tracked by means of a badge, it will not be possible to inhibit the
information on the user's location, but only to intervene on the use the system can make of it.
The RTLS module usually enables the following basic functionalities for the end user of the APP:
This module allows the user to control from the mobile APP or devices that can be managed by the BMS itself (lights, temperature, blinds, etc.). In general, control can also take place remotely, but only if such privileges have been assigned to the user. Workplace Explorer allows the user to define authorisations to control items in individual rooms at the individual user and individual room level.
This module allows the user to make reservations for Meeting Rooms, Desks, Parking lots or Assets. In
general
Workplace Explorer provides internal management of bookings by storing all relevant information.
In combination with the SSO and the integration with Microsoft Calendar O365, it will also be possible to
book
resources defined on the latter. Only with regard to these resources, Workplace Explorer will not store any
information, but will ask the O365 system for the necessary information from time to time (e.g. list of
commitments of the individual user, list of availability of a bookable resource, etc.).
From a system perspective, aggregate statistics can be generated at various levels, but never on an
individual
user basis.
Other possible functions in combination with other modules are:
This module allows the user to book and unlock a locker. In combination with other modules, the following functions will also be possible:
This module allows the user to clock in or out, as well as to view the list of his or her clockings via APP.
Integration with access control systems involves only the generation of a call that emulates the passing of
a
physical badge in the vicinity of an opening head. All opening authorisation management will be handled by
the
access control system.
In combination with other modules, the following functions will also be possible:
This module allows the user to make a lift call, optionally also indicating the destination floor. In combination with other modules, the following functions will also be possible:
The information collected by Workplace Explorer mainly concerns the position of mobile devices and
transponders,
but may also include other personal information such as the user's identity, phone number and
e-mail.
If required by the customer, other information, such as department and/or working groups etc., can be
included
to be used for specific use cases (e.g. to generate aggregate statistics for departments).
The data categories can be summarised as follows: personal, identification, location
The purposes of the above data processing are the localisation of mobile devices and transponders, access management, opening a ticket or booking a desk or meeting room.
The legal basis for the processing of data are pre-contractual and contractual obligations with the Client/Purchaser, in compliance with the GDPR.
All data are processed using automated IT tools and not by staff specifically authorised by the data
controller.
These authorised personnel in a suitable number to ensure the service (with regard to operational
continuity)
and minimisation of the operating subjects (with regard to the basic concept of "need to know"), access the
data
by means of a two-factor authentication system, on the basis of the appropriate authorisations.
For these IT tools, there is also the possibility of tracking access or attempted access, in accordance with
the
GDPR, for greater data protection.
Workplace Explorer offers several functionalities to ensure the protection of users' personal data, such as
the
possibility of activating the 'privacy' function in order not to be searched within the platform by
administrators or other users, if not allowed by the DPO or the user himself.
Workplace Explorer takes appropriate security measures to prevent the loss, theft, unauthorised access,
disclosure, modification or destruction of users' personal data. For example, the platform uses advanced
security protocols to protect communications between the device and the server, and data is stored in an
encrypted format.
The technique of anonymisation of geolocation data is also applied, which allows a policy of permanent
storage:
this data is anonymised for statistical and analysis purposes, such as the creation of heatmaps or other
data
aggregations, to improve the service.
The data contained within Workplace Explorer are made available to the Customer/Purchaser in accordance with the contract and in compliance with the GDPR. Under no circumstances shall they be sold or transferred to third parties.
The data are acquired through communication by service users directly or through the Customer/Purchaser.
Whenever the processing of data includes as a legal basis pre-contractual and/or contractual obligations
and/or
fulfilment of tax law obligations and/or receiving answers to one's questions, the provision of the data is
necessary in order to fulfil the requirements. Failure to provide such data will affect the customer's
ability
to use the service.
At any time, the user will have the option of not granting location use privileges or disabling Bluetooth
and
GPS, preventing the APP from generating location information.
Whenever the processing of data includes pre-contractual and/or contractual obligations and/or fulfilment of
tax
law obligations as a legal basis, the data will be retained for the time necessary to ensure the lawfulness
of
the processing in accordance with the law, and, alternatively, in accordance with contractual
provisions.
Should the user request the deletion of his or her personal data, such as user name and password, Workplace
Explorer promptly carries out the deletion from the system.
It is possible to customise the data anonymisation time according to the needs of the Customer/Purchaser. In
addition, Workplace Explorer offers the option of either not saving any positioning data, if requested by
the
Customer/Purchaser, or anonymising them in real time, provided this has been previously contracted (given
the
increased complexity and cost of the project, as it requires a more advanced real-time anonymisation
system).
To date, the organisation has no plans to transfer the data of European citizens to a third country. All data of registered users are stored within the European Union and in accordance with European data protection legislation.
At any time, the data subject may exercise, pursuant to Articles 15 to 22 of EU Regulation No. 2016/679, the right to: