EasyOps (mobile terminal)
focuses on network diagnosis, knowledge base and field tools, and defaults to local processing.
Asset Sonar (desktop)
focuses on asset scanning, field mapping, Snipe-IT synchronization and export archiving.
1. Scope and definition of application
This policy applies to all versions of EasyOps and Asset Sonar, official website experience applications, documents and update services. The personal information processor isJianxiu Tech (Hangzhou) Co., Ltd.. This policy explains what information we process, why we process it, how it is stored and how you can exercise your rights.
This Policy also covers Asset Sonar commercial licensing, activation validation, operational metrics and software updates. The licensing service processes only information necessary to provide entitlements, compatibility support, security and releases; it does not receive the complete endpoint inventory collected by a scan.
- Personal information:Information that can identify a natural person.
- business data:asset list, network scan, synchronization log, report file, etc.
- Sensitive Credentials:API Key, login password and other security credentials. Whether it constitutes personal information depends on whether it can be associated with or identified a specific natural person, but it is protected at a high sensitivity level.
- local processing:information is only read, calculated or stored in your device, and we cannot access this information.
- server-side processing:information is sent to servers, corporate mailboxes and other systems controlled or entrusted by us.
2. Data classification and collection scope (key color distinction)
2.1 EasyOps collection item (blue area)
- network diagnostic data:Target IP/domain name, port, delay, connectivity, LAN Scan results.
- User input data:Collection commands, history records, and quick tool configuration.
- operating environment data:Device model, system version, and App version (for compatibility troubleshooting).
2.2 Asset Sonar collection item (purple area)
- Hardware asset field:host name, model, serial number, CPU/memory/disk/network card/monitor, etc.
- configure mapping fields:
ActiveProfile、CATEGORY_ID_MAP、COMPONENT_CATEGORY_ID_MAP、ACCESSORY_CATEGORY_ID_MAP、CATEGORY_CODE_MAP。 - Synchronization process data:HTTP status code, failure object, batch number, retry record, export information.
- License and customer data: license or activation identifier, licensed customer name, entitlement status and term, first activation and latest validation time.
- Authorized media data: device label, hardware identification attributes of the USB drive or approved medium (such as serial identifiers, vendor/product identifiers, model and capacity), installation identifier and a derived device identifier used for license validation.
- Necessary operational data: Asset Sonar version, Modern/Legacy mode, architecture, operating-system family and version, validation or usage-report time, source IP and necessary request security logs.
- Clear boundary: employee-computer scan results, Snipe-IT API credentials, field mappings, exports and synchronized business content remain on customer-controlled media, endpoints or the customer-configured target system and are not uploaded to the Jianxiu licensing service, unless you actively submit them for support.
2.3 Website experience application information
- Contact information:The email or mobile phone number you actively submitted.
- application platform:iOS or Android / HarmonyOS.
- EasyOps application information:Name, individual or corporate application type, unit or team, position or identity, team size, main usage scenarios and experience requirements. Individual applications are not required to fill in the unit and team size.
- Asset Sonar Application information:Name, unit or team, position, asset scale, current asset system and usage scenarios.
- processing purpose:Review experience qualifications, send test notifications and communicate with necessary applications.
- Anti-abuse information:The server performs HMAC hashing of the source IP of the submitted request and a random key, which is only used to implement the frequency limit of "the same IP once every five minutes"; the current limit record is cleared after about five minutes.
- processing link:application materials will be written to the restricted directory of our server and sent to our Alibaba corporate email for review, contact and leaving traces.
2.4 Sensitive field processing (yellow emphasis)
ApiKey、AssignPasswordshould not be used for public logs, screenshots, or clear text dissemination of work orders.- It is recommended to enable system security storage (such as Keychain/DPAPI) and rotate credentials regularly.
- Before exporting a report for external collaboration, it is recommended to perform field masking first.
3. Permission description and shutdown impact
3.1 EasyOps
- Local network permissions:is used to discover and diagnose LAN devices; the LAN tool is unavailable when closed.
- Location permission (Android):is used to read Wi-Fi identification capabilities; after it is turned off, some network identification capabilities are limited.
- Camera permissions:is used for scanning code entry; after closing, the label information needs to be entered manually.
3.2 Asset Sonar
- system read permission:is used to collect hardware fields; insufficient permissions will cause the model/serial number to be missing.
- Network access rights:is used to call the asset interface you configured; it cannot be synchronized after it is closed.
- local file reading and writing:is used to read configuration and export reports; the results cannot be saved after closing.
- Licensing and update connectivity: network access is also used for initial activation, periodic validation, renewal of offline eligibility, update checks or downloads, and necessary operational reporting. Without connectivity, continued local scanning depends on the currently valid offline entitlement; activation, revalidation and online updates are unavailable.
4. Purpose and legal basis of processing
- performs product functions:Completes the scanning, troubleshooting, synchronization and export initiated by you. The processing done only locally is controlled by you; it involves the functions of our server and is based on what is necessary to enter into or perform the service agreement.
- Processing experience application:will process contact information and Asset Sonar application information based on your consent after checking and confirming; you can withdraw your consent, but it will not affect the legality of the processing activities before the withdrawal.
- Security and Abuse Prevention:In order to ensure the security of the website and application interface, the IP hash is not directly identifiable and recorded for a short period of time, which is a necessary security measure.
- Fulfill legal obligations:Make necessary disclosures, retain or cooperate with regulatory and judicial authorities as required by laws and regulations.
- purpose change:If there are substantial changes in the purpose, method or type of information, we will inform you again; if consent is required by law, consent will be obtained again.
- Licensing and service operation: we process necessary media and operational data to perform the commercial license, confirm entitlement status, deliver updates, protect service interfaces, troubleshoot compatibility and produce aggregate operational statistics that are not used for marketing profiles.
5. Storage, encryption and retention policy
storage policy (green)
is stored locally by default, and whether it is sent out is determined by the target system you configure. We do not host the full business library by default.
- encryption:Keychain is available for iOS, and DPAPI/system security mechanism is available for Windows.
- experience application:Server application records and application emails in corporate mailboxes will be retained for a maximum of 180 days from the date of submission, and will be cleared on a periodic basis after expiration; if the law otherwise requires or the dispute handling needs to be extended, they will only be retained for the necessary period.
- current limit record:IP hashes and timestamps are usually cleared after the five-minute window and are not used in conjunction with user portraits other than application data.
- Reserved:It is recommended that the administrator cleans logs and snapshots regularly according to the 30/90/180 day policy.
- Minimize:only processes the fields required to implement functions to avoid long-term retention of irrelevant information.
- Licensing-service data: customer, license and activation records are generally retained while the licensing relationship remains active. After it ends, data is retained only for the shortest period necessary for settlement, support, audit, dispute handling or legal obligations. Usage events, source IPs and request security logs are periodically cleared on the shortest cycle needed for security and operations. When the purpose is complete or a valid deletion request is accepted, we delete or anonymize the data within a reasonable processing cycle, unless law or a valid contract requires otherwise.
6. Entrusted processing, sharing and third-party boundaries
- does not sell personal information.
- corporate email service:We use Alibaba corporate email to receive application notifications. Application data may therefore be stored, transmitted and secured by an email service provider in accordance with our instructions.
- website infrastructure:Website servers, domain name resolution, certificates and network protection service providers may process IP, request time, User-Agent and security logs necessary to provide network services. We prioritize front-end fonts, styles and icon resources on our own sites to reduce unnecessary third-party page requests.
- Third-party system that you actively configured:As in Snipe-IT/Gateway/Agent, your organization is responsible for target system compliance.
- issuance and payment channels:App Store handles transactions and distribution, and its independent privacy policy applies.
- Legal obligations:Necessary provision in accordance with legal regulatory/judicial requirements.
- Company Transaction:In the event of a merger, division, reorganization or asset transfer, we will inform the recipient of the information and contact information, and require it to continue to be bound by this policy; obtain necessary consent again when the purpose or method of processing changes.
7. Cross-border, minors, automated decision-making
- Cross-border:We do not actively transmit official website application materials and local product data overseas. If cross-border provision led by us occurs due to service needs in the future, we will perform notification, separate consent and applicable data export procedures in accordance with the law. If you configure the synchronization target as an overseas system, your organization should also evaluate its own data export obligations.
- Minors:product is intended for enterprise technicians and does not target minors under the age of 14. Those under the age of 14 should not submit applications by themselves; if guardians find that we have mistakenly received relevant information, they can contact us to delete it.
- Automated decision-making:currently does not make automated marketing decisions based on personal portraits.
8. Your rights and request channels
- Access, correction, deletion, export, authorization withdrawal, complaints and feedback.
- You can achieve local data control through system settings, configuration files, log cleaning and uninstallation.
- If you need to process the application information in the server or corporate email, please submit a request through the email at the end of this policy. To prevent fraudulent use, we may verify the application number, original contact information or other necessary information, but will not ask for materials unrelated to verification.
- In principle, we will respond within 15 working days after receiving a complete request. If the request cannot be fulfilled, the reasons and complaint channels will be explained; if laws and regulations provide otherwise, such provisions shall prevail.
- The withdrawal of consent does not affect the legality of the processing activities before the withdrawal. After the deletion request is completed, the backup copy will be deleted or rendered unretrievable during the normal overwrite cycle.
9. Field-level data list table (field name/source/purpose/whether it is sensitive/retention period)
| field name | Source | Purpose | sensitive? | retention period (recommended) |
|---|---|---|---|---|
ApiKey | User configuration (Asset Sonar) | Call asset system API | Yes (high) | , the old value will be cleared immediately after rotation. |
AssignPassword | User configuration (Asset Sonar) | Automatic assignment/authentication process | Yes (high) | is within the validity period and will be cleaned immediately after rotation. |
InternalUrl/ExternalUrl | user configuration | Interface connection and routing | Medium | Update when configuration changes, clean up within 30 days after deactivation |
CATEGORY_ID_MAP | Administrator configuration | Asset Classification Mapping | No | is reserved for a long time and will be iterated according to versions. |
COMPONENT_CATEGORY_ID_MAP | Administrator configuration | component mapping | No | is reserved for a long time and will be iterated according to versions. |
ACCESSORY_CATEGORY_ID_MAP | Administrator configuration | accessory mapping | No | is reserved for a long time and will be iterated according to versions. |
| device serial number/host name/model | system scan (Asset Sonar) | Asset identification, deduplication and reconciliation | Medium | recommends 180 days (can be extended if audit needs) |
| IP / domain name / port / delay | network diagnosis (EasyOps) | Network troubleshooting and connectivity verification | Medium | recommended 30~90 days |
| Collection command/history | User active entry (EasyOps) | Improve on-site operation efficiency | low | is controlled by the user and can be deleted at any time |
| error code/failure object/retry record | system operation log | Problem location and review | Medium | recommended 90 days |
| Application contact information/name/application type/unit/position/team or asset size/scenario and demand | EasyOps, Asset Sonar official website application form | Qualification review, product adaptation assessment, contact and application traces | Medium | up to 180 days |
| IP | official website application interface | Five-minute frequency limit and abuse prevention | low | about 5 minutes |
| protocol version/confirmation time | official website application form | Certification notification and confirmation status | low | with application materials, up to 180 days |
| License/activation identifier, customer name, entitlement status and term, authorized-media attributes | Asset Sonar activation and periodic validation | Provide the commercial license, validate authorized media and process renewals | Medium to high | Active licensing relationship plus any necessary post-termination period |
| App version, runtime mode, architecture, OS version, latest IP and usage time | Asset Sonar licensing and operations service | Compatibility support, security audit, aggregate usage and troubleshooting | Medium | Shortest period necessary for the purpose, cleared periodically |
10. Role Responsibility Matrix (Responsibility Boundary)
| role | Main Responsibilities | Safety Responsibility | compliance boundary |
|---|---|---|---|
| user (end user) | Use functions according to authorization; input and export business data; handle on-site troubleshooting tasks. | Do not leak accounts, keys, or export files; avoid spreading sensitive screenshots in public channels. | is responsible for the authenticity and necessity of the data entered and exported by himself. |
| Administrator (Enterprise/IT Management) | Maintenance Profiles, classification mapping, permission policy, log retention policy. |
implements least privileges, key rotation, desensitization specifications, backup and recovery strategies. | is responsible for the compliance configuration and cross-border evaluation of target systems (such as Snipe-IT). |
| developer (Jianxiu Tech) | provides software capabilities, fixes vulnerabilities, and continuously optimizes stability and security. | provides recommendations for safe default settings, vulnerability response mechanisms, and version security updates. | does not host your complete business library by default; cooperate with compliance requests within legal obligations. |
11. Security measures and incident response
We adopt measures such as access control, minimum permissions, transmission encryption, credential protection, log auditing, backup and regular cleaning based on the scale of processing. When personal information is or may be leaked, tampered with, or lost, we will immediately take remedial measures and report to the competent authorities in accordance with the law; when it is necessary to notify individuals, we will inform individuals of the type of incident, possible impact, measures taken, preventive measures that individuals can take, and contact information. If measures can be taken to effectively avoid harm, we do not need to notify each case one by one in accordance with the law; if the regulatory authorities believe that harm may be caused and require notification, we will notify as required.
12. Policy update and effectiveness
General text, formatting or contact details adjustments will be posted via the page. For major changes involving the purpose of processing, processing methods, types of personal information, retention period, recipients or cross-border arrangements, we will re-inform you through pop-up windows, prominent page prompts or product notifications; if consent is required by law, consent will be obtained again before the change takes effect. The old version will still apply to processing activities that occurred during the period of validity of the new version before it becomes effective.
13. Contact us
If you have any questions about this policy, data processing practices or security issues, you can contact us:
Jianxiu Tech (Hangzhou) Co., Ltd. · Privacy and Compliance Contact
Email:axuan@bigbabol.xyz
It is recommended to indicate "Personal Information Rights Request" or "Privacy Complaint" in the subject of the email. We generally respond within 15 working days after receiving a complete request.