
10
ISSUE APRIL 2019
GRAINSENSE USER MANUAL
2.2 GrainSense cloud services
Grainsense gathers data of all registered users to:
• Provide calibration and other data to users and their devices
• Verify account status and level
• Store all measured data to provide an access to it from different
devices and backup
• Communicate any issues, guidance or other important messages
Grainsense gathers the following information:
• User details: email, address, phone number, profession
• Measurement results with user id, GPS location, time and date, and
notes
2.2.1 GDPR Guidance
GDPR is active after 25.5.2018 and involves all companies handling data
from EU citizens. Data controllers (i.e. company) and data processors
(company or subcontractor) are required to comply and give more power
to a person regarding his data, that includes to:
• Ask explicit consent for all different data types (GPS, email marketing,
etc), describe how to data is used and for what purpose
• Allow users to control the data (delete and export)
Companies must also have an internal guidance (this chapter of the
User Manual) on GDPR.
Note! GrainSense is fully compliant with GDPR.
2.2.2 Data infrastructure and protection
Grainsense acts as a data controller and processor, but for processing,
it uses outsourced infrastructure (Amazon AWS). Graisense has taken
measures to protect user data by:
• Applying standard encrypted HTTPS (TLS) communication
• Using proper authorization and authentication methods
• Using enterprise level framework (Java Spring)
• Taking nightly backups of the data (last 30 days)
• Limiting admin rights to the databases (two key persons have access
to user’s personal data)
2.2.3 User registration
The user registers to Grainsense cloud via the web registration wizard
(www.grainsense.com/register). The user is asked to fill personal details,
which some are optional, in the end, the user is asked to consent to:
Terms of use*, Privacy policy*, Location data use, Marketing use.
*Terms of use and privacy policy are compliant to GDPR