App Policy

APP PRIVACY AND SECURITY POLICY

Dazzle Technologies Ltd, trading as Waizu and providing the KOERBER EMM APP, is a private limited company established under the laws of England and Wales, with company number 12570292 with registered address of 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ.
This Privacy and Security Policy describes the privacy and security practices for Dazzle Technologies Ltd products and the website www.koerberemm.com
We take user privacy and security very seriously. This document provides an overview of our privacy and security policies and technology. We are happy to discuss any of these points in more detail with concerned customers. We can be contacted by email at legal@koerberemm.com


Security Policies


Authentication
Our product offers two authentication capabilities: email and password based, or Google federated identity provider.
The email and password-based authentication let users authenticate with their email addresses and passwords. The password is always hashed before being stored in our database, so that we never have access to our user’s passwords.
We may offer integration with the Google federated identity provider which lets users authenticate with a Google Account or a Gmail address. This authentication method relies on the OAuth 2.0 industry standard. We never have access to our users' Google Account or Gmail passwords.

Access to Systems and Hosting
We have built the Application in Microsoft .NET, running on Microsoft SQL and hosted in Microsoft Azure – therefore enjoy the Microsoft terms of services which can be found here - https://azure.microsoft.com/en-gb/support/legal/  
Some links to specialist device management software may be granted as part of this policy and if so this service is hosted on the Google Cloud Platform, and therefore enjoy GoogleCloud Platform ToS (https://cloud.google.com/terms) as well as Security and Confidentiality (https://cloud.google.com/security/overview/whitepaper)  

All interaction between your browser and our application occurs over a secure HTTPS connection. All web reports and account management activities are likewise performed over a secure HTTPS connection

  • We use the Android Management API to connect with the Android devices of your fleet.
  • We use the Android Device Provisioning Partner API to manage Zero Touch devices assigned by a Zero Touch reseller.
  • We use the Managed Google Play as your managed application store. The security screening application Google Play Protect guarantees a high-level security screening of all applications

Location Data / Location Permissions

The application requires background location data permissions and consent.
The application collects Location Data in the background to enable location data to be sent back to the web interface of “Koerber EMM” The application has several functions, one being to provide vital data to the managed mobility operator. This includes data such as location and device status. The application also acts as a central point of contact for IT admins or managers to get in touch with device users. The app also includes a simple view of device-specific information. The application also can display usage information to the user and the IT admin. (e.g Applications used)

Location-based features need access to location in the background. - The application provides location information back to the company administration console. The location of the device can be viewed in the web console by the company administrator. An administrator can check the user's location and send them job-specific information in the form of the messaging system. This job-specific information would be based on the user's location. The application is aimed at corporately owned environments and not personal device environments.  

Technical Support, Incident Response

We monitor our systems permanently. Our team is notified as soon as problems are detected, and the issues are immediately investigated. Whenever a significant downtime happens, we notify you via Email. Every user has access to our support platform to log support. Contact legal@koerberemm.com to find out more. We provide 24x5 email support to every end user with an average first response time of 6 hours. Our Enterprise support offering includes Video and Phone support.

Data Access & Confidentiality

Access to user's account and all data associated with that account by Dazzle Technologies Ltd employees is limited to an as-needed basis (e.g., to resolve customer issues, support). When such access is required, only personnel with a direct need will access the data, and such access will be limited as much as possible. Breach of this policy by a Dazzle Technologies Ltd employee is a serious matter which can lead to contract termination as well as legal action. When requested, we will destroy a user's account, removing all data associated with that account. As customers use Dazzle Technologies Ltd, our server collects telemetry data about the features being used. We use this data to generate reports, to assist us in debugging and customer service, and to update system status and capacity planning. Dazzle Technologies Ltd does not rent, sell, trade or disclose users Personal Information to third parties.

Why do we keep some of your information?

Dazzle Technologies Ltd products are web based; because of this they require the use of first and last names, billing contact information, as well as login and password. Therefore, at a minimum, we may require such necessary information in order to establish your account with us.

Do we access, use, store, or share users data during application usage?


Personal Information: We collect personal information from users including (at minimum) first and last names, and an email address to be used as a login. When a user registers online to use products, Dazzle Technologies Ltd will take steps to verify the email address supplied to us to ensure it is accurate. Your email address may be used to send you periodic product newsletters, offers and usage tips from Dazzle Technologies Ltd. You can opt out of promotional emails at any time, but will still receive communications such as receipts, confirmation emails and customer service updates that are considered necessary to provide the service to you. We use the information collected to deliver services, update our records, communicate with you about products and services, and generally maintain your accounts with us. We will retain your information for as long as your account is active, as needed to provide you services, to comply with our legal obligations, resolve disputes, and enforce our agreements. If you wish to cancel your account or request that we no longer use your information to provide you services, contact us at legal@koerberemm.com

Business Information: Information that is collected by our products is considered confidential. We will not view Business Information except as necessary to appropriately support the service or as required by law. (Business Information includes app data, documents, files, configuration settings and any other business information stored on Dazzle Technologies Ltd products). We will not view Business Information, except as necessary to appropriately support the service, for the purpose of anticipating, diagnosing, supporting or resolving any problems that might limit or disrupt the quality of our customers’ service experience or as required by law.  

Session Records: To maintain our quality of service and to assist in the analysis of product performance, we may also gather data on connection information. The gathered information is used only to ensure the highest quality experience possible when using Dazzle Technologies Ltd products.  

Security Information: Dazzle Technologies Ltd also collects certain standard information about your computer for security and identification purposes. This information may include: IP addresses, domain names, access times, cookies and other unique identifying information of machines that have our software downloaded and installed on them. This information is used for the operation of the service, to identify and protect our customers and to control unauthorized use or abuse of our services. All information is encrypted during transmission and is stored securely within our servers.  

Web Analytics: We continuously improve our websites and utilize different web analytic tools to help us do so. We are interested in how visitors use our websites, what they like and dislike, and where they have problems. We also use web analytic tools on our mobile applications to help gather non-personally identifiable data about download and application usage. In our use of web analytics, we do collect Geo Location data, but it is only on an aggregate basis and not tied to any individual. The web beacons used in connection with our web analytics services do not share any personally identifiable information about our website and application visitors with third parties. Our tools may gather data such as what browser a person uses, what operating systems are used, what is downloaded, and what content, products and services are reviewed when visiting or registering for services at one of our websites or mobile applications. This information is used solely to assist Dazzle Technologies Ltd in maintaining a more effective and useful website for our customers. We track aggregate traffic patterns throughout our site but we do not correlate this information with personally identifiable data about individual users. We track domain names and browser types. Such information will not be passed to third parties without your prior consent unless where required by applicable law.  

With whom do we share this information?

Ensuring your privacy is important to us. We do not sell, trade or rent your personal information to third parties. Dazzle Technologies Ltd products and services by necessity require us to provide some of your information to third parties. We use a number of third parties to process personal data on our behalf. These third parties have been carefully chosen and all of them comply with the EU General Data Protection Regulation 2018 (GDPR) and EU-U.SPrivacy Shield. We currently use the following third parties: Google, Microsoft, Fresh Service, Zendesk, Hubspot, Intercom, Auth0.

How do we protect information from loss, misuse, or alternations?

Dazzle Technologies Ltd has implemented commercially reasonable precautions designed to protect the websites and applications it hosts and the information it collects from loss, misuse, and unauthorized access, disclosure, alteration, and destruction. Nevertheless, we remind you that no security measure is perfect. Dazzle Technologies Ltd is not liable for loss of passwords due to user carelessness. If you lose control over your credentials, you may lose control over your personally identifiable information. If you believe your account credentials have been compromised, we recommend that you immediately change your password or activate Google 2 step authentication.  

Data retention policy, Data controller and data protection officer

Dazzle Technologies Ltd is compliant with the EU General Data Protection Regulation 2018 (GDPR). Dazzle Technologies Ltd currently retains all user and business data while you are user of Dazzle Technologies Ltd online services. We keep your data for a period of 12 months after you stop using any of our services.  

You can request an immediate deletion of all your data by contacting our Data Protection Officer by email.

Data Controller: legal@koerberemm.com

Data Protection Officer: Data Protection Officer: Adrian Lawson, Director, Dazzle Technologies Ltd, email legal@koerberemm.com  

Data breaches

We will report any unlawful data breach of this website’s database or the database(s) of any of our third-party data processors to any and all relevant persons and authorities within 72 hours of the breach if it is apparent that personal data stored in an identifiable manner has been stolen