Skip to content

Instantly share code, notes, and snippets.

Embed
What would you like to do?

Graylog test - Privacy Policy

Description of Graylog test

Graylog test is a test service setup to test login to a Graylog instance via SWAMID.

Processing of personal data

Transfer of personal data

Personal data are transferred from the identity provider (your login service) to Graylog test to login to a Graylog instance. The attribute values, that contains personal data, are not stored.

When logging in to these test services, the following personal data are requested from the identity provider you use:

Personal data Purpose Technical representation
Unique identifiers To match user against a pre-configured Graylog user ID. eduPersonPrincipalName
Assurance level To allow restriction of logins to assurance level AL2. eduPersonAssurance

In addition to direct personal data, indirect personal data are also transferred, such as which organisation the user belongs to and which identity provider that has been used when logging in. In combination with the above personal data, these can be used to uniquely identify a person.

Other processing of personal data within the service

Graylog test stores technical logs for debugging purposes and security related incidents. These technical logs contain information regarding all authentications made to the test services and the personal data transferred.

Transfer of personal data to third parties

No personal data are transferred to third parties.

Lawful basis

Personal data are processed on the basis of internal testing for development. The only intended user of Graylog test is myself. Personal data must be transferred in order for me to ensure that integration with Graylog is working as intended.

Right of access, right of rectification and right of erasure of personal data

No personal data are stored in the service except in technical logs for debugging purposes and security related incidents.

For access and erasure of your personal data, contact the Personal data controller.

Purging of personal data

No personal data are stored in the service except in technical logs. The technical logs are not automatically purged.

Personal data controller

Personal data controller for the processing of personal data is Ernst Widerberg. If you have questions about how personal data are processed within the service, please contact ernst@sunet.se.

GÉANT Data Protection Code of Conduct

This service complies with the international framework GÉANT Data Protection Code of Conduct (http://www.geant.net/uri/dataprotection-code-of-conduct/v1) for the transfer of personal data from identity providers to the service. This framework is intended for services in Sweden, the EU and the EEA that are used in research and higher education.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment