Skip to main content
Privacy Policy · Ver 5.0 · Update and Effective Date 2026-07-31

Privacy Policy.

How to collect, use and protect the data involved in the process of using EasyOps and Asset Sonar is explained here clearly.

core commitment:We adhere to the "local first" principle. Except for the synchronization targets that you actively configure, core business data is not uploaded to the servers controlled by us by default.

EasyOps (mobile terminal)

focuses on network diagnosis, knowledge base and field tools, and defaults to local processing.

Asset Sonar (desktop)

focuses on asset scanning, field mapping, Snipe-IT synchronization and export archiving.

1. Scope and definition of application

This policy applies to all versions of EasyOps and Asset Sonar, official website experience applications, documents and update services. The personal information processor isJianxiu Tech (Hangzhou) Co., Ltd.. This policy explains what information we process, why we process it, how it is stored and how you can exercise your rights.

This Policy also covers Asset Sonar commercial licensing, activation validation, operational metrics and software updates. The licensing service processes only information necessary to provide entitlements, compatibility support, security and releases; it does not receive the complete endpoint inventory collected by a scan.

2. Data classification and collection scope (key color distinction)

2.1 EasyOps collection item (blue area)

  • network diagnostic data:Target IP/domain name, port, delay, connectivity, LAN Scan results.
  • User input data:Collection commands, history records, and quick tool configuration.
  • operating environment data:Device model, system version, and App version (for compatibility troubleshooting).

2.2 Asset Sonar collection item (purple area)

  • Hardware asset field:host name, model, serial number, CPU/memory/disk/network card/monitor, etc.
  • configure mapping fields:ActiveProfileCATEGORY_ID_MAPCOMPONENT_CATEGORY_ID_MAPACCESSORY_CATEGORY_ID_MAPCATEGORY_CODE_MAP
  • Synchronization process data:HTTP status code, failure object, batch number, retry record, export information.
  • License and customer data: license or activation identifier, licensed customer name, entitlement status and term, first activation and latest validation time.
  • Authorized media data: device label, hardware identification attributes of the USB drive or approved medium (such as serial identifiers, vendor/product identifiers, model and capacity), installation identifier and a derived device identifier used for license validation.
  • Necessary operational data: Asset Sonar version, Modern/Legacy mode, architecture, operating-system family and version, validation or usage-report time, source IP and necessary request security logs.
  • Clear boundary: employee-computer scan results, Snipe-IT API credentials, field mappings, exports and synchronized business content remain on customer-controlled media, endpoints or the customer-configured target system and are not uploaded to the Jianxiu licensing service, unless you actively submit them for support.

2.3 Website experience application information

  • Contact information:The email or mobile phone number you actively submitted.
  • application platform:iOS or Android / HarmonyOS.
  • EasyOps application information:Name, individual or corporate application type, unit or team, position or identity, team size, main usage scenarios and experience requirements. Individual applications are not required to fill in the unit and team size.
  • Asset Sonar Application information:Name, unit or team, position, asset scale, current asset system and usage scenarios.
  • processing purpose:Review experience qualifications, send test notifications and communicate with necessary applications.
  • Anti-abuse information:The server performs HMAC hashing of the source IP of the submitted request and a random key, which is only used to implement the frequency limit of "the same IP once every five minutes"; the current limit record is cleared after about five minutes.
  • processing link:application materials will be written to the restricted directory of our server and sent to our Alibaba corporate email for review, contact and leaving traces.

2.4 Sensitive field processing (yellow emphasis)

  • ApiKeyAssignPassword should not be used for public logs, screenshots, or clear text dissemination of work orders.
  • It is recommended to enable system security storage (such as Keychain/DPAPI) and rotate credentials regularly.
  • Before exporting a report for external collaboration, it is recommended to perform field masking first.

3. Permission description and shutdown impact

3.1 EasyOps

3.2 Asset Sonar

4. Purpose and legal basis of processing

5. Storage, encryption and retention policy

storage policy (green)

is stored locally by default, and whether it is sent out is determined by the target system you configure. We do not host the full business library by default.

6. Entrusted processing, sharing and third-party boundaries

7. Cross-border, minors, automated decision-making

8. Your rights and request channels

9. Field-level data list table (field name/source/purpose/whether it is sensitive/retention period)

field name Source Purpose sensitive? retention period (recommended)
ApiKeyUser configuration (Asset Sonar)Call asset system APIYes (high), the old value will be cleared immediately after rotation.
AssignPasswordUser configuration (Asset Sonar)Automatic assignment/authentication processYes (high)is within the validity period and will be cleaned immediately after rotation.
InternalUrl/ExternalUrluser configurationInterface connection and routingMediumUpdate when configuration changes, clean up within 30 days after deactivation
CATEGORY_ID_MAPAdministrator configurationAsset Classification MappingNois reserved for a long time and will be iterated according to versions.
COMPONENT_CATEGORY_ID_MAPAdministrator configurationcomponent mappingNois reserved for a long time and will be iterated according to versions.
ACCESSORY_CATEGORY_ID_MAPAdministrator configurationaccessory mappingNois reserved for a long time and will be iterated according to versions.
device serial number/host name/modelsystem scan (Asset Sonar)Asset identification, deduplication and reconciliationMediumrecommends 180 days (can be extended if audit needs)
IP / domain name / port / delaynetwork diagnosis (EasyOps)Network troubleshooting and connectivity verificationMediumrecommended 30~90 days
Collection command/historyUser active entry (EasyOps)Improve on-site operation efficiencylowis controlled by the user and can be deleted at any time
error code/failure object/retry recordsystem operation logProblem location and reviewMediumrecommended 90 days
Application contact information/name/application type/unit/position/team or asset size/scenario and demandEasyOps, Asset Sonar official website application formQualification review, product adaptation assessment, contact and application tracesMediumup to 180 days
IPofficial website application interfaceFive-minute frequency limit and abuse preventionlowabout 5 minutes
protocol version/confirmation timeofficial website application formCertification notification and confirmation statuslowwith application materials, up to 180 days
License/activation identifier, customer name, entitlement status and term, authorized-media attributesAsset Sonar activation and periodic validationProvide the commercial license, validate authorized media and process renewalsMedium to highActive licensing relationship plus any necessary post-termination period
App version, runtime mode, architecture, OS version, latest IP and usage timeAsset Sonar licensing and operations serviceCompatibility support, security audit, aggregate usage and troubleshootingMediumShortest period necessary for the purpose, cleared periodically

10. Role Responsibility Matrix (Responsibility Boundary)

role Main Responsibilities Safety Responsibility compliance boundary
user (end user) Use functions according to authorization; input and export business data; handle on-site troubleshooting tasks. Do not leak accounts, keys, or export files; avoid spreading sensitive screenshots in public channels. is responsible for the authenticity and necessity of the data entered and exported by himself.
Administrator (Enterprise/IT Management) Maintenance Profiles, classification mapping, permission policy, log retention policy. implements least privileges, key rotation, desensitization specifications, backup and recovery strategies. is responsible for the compliance configuration and cross-border evaluation of target systems (such as Snipe-IT).
developer (Jianxiu Tech) provides software capabilities, fixes vulnerabilities, and continuously optimizes stability and security. provides recommendations for safe default settings, vulnerability response mechanisms, and version security updates. does not host your complete business library by default; cooperate with compliance requests within legal obligations.

11. Security measures and incident response

We adopt measures such as access control, minimum permissions, transmission encryption, credential protection, log auditing, backup and regular cleaning based on the scale of processing. When personal information is or may be leaked, tampered with, or lost, we will immediately take remedial measures and report to the competent authorities in accordance with the law; when it is necessary to notify individuals, we will inform individuals of the type of incident, possible impact, measures taken, preventive measures that individuals can take, and contact information. If measures can be taken to effectively avoid harm, we do not need to notify each case one by one in accordance with the law; if the regulatory authorities believe that harm may be caused and require notification, we will notify as required.

12. Policy update and effectiveness

General text, formatting or contact details adjustments will be posted via the page. For major changes involving the purpose of processing, processing methods, types of personal information, retention period, recipients or cross-border arrangements, we will re-inform you through pop-up windows, prominent page prompts or product notifications; if consent is required by law, consent will be obtained again before the change takes effect. The old version will still apply to processing activities that occurred during the period of validity of the new version before it becomes effective.

13. Contact us

If you have any questions about this policy, data processing practices or security issues, you can contact us:

Jianxiu Tech (Hangzhou) Co., Ltd. · Privacy and Compliance Contact

Email:axuan@bigbabol.xyz

It is recommended to indicate "Personal Information Rights Request" or "Privacy Complaint" in the subject of the email. We generally respond within 15 working days after receiving a complete request.