Version 1.2 of 19 October 2022
Thank you for taking the time to read the privacy statement of the SURF edubadges service! We have devoted a great deal of attention to the protection of your personal data and you can read all about this in this privacy statement. If you have any questions, comments or concerns after reading this privacy statement, please feel free to send an e-mail to [email protected] or contact your own educational institution.
We are SURF, located at 48 Moreelsepark, 3511 EP Utrecht, the Netherlands. You can call us on 31-887873000
. SURF is a cooperative: the collaborative organisation for ICT in Dutch education and research. More than 100 education and research institutions in the Netherlands work together within the SURF cooperative to fully utilise the opportunities of digital transformation. More about the SURF cooperative.
An edubadge is a digital badge (image) which shows that the holder has certain knowledge or skills. The recipient of an edubadge can share it with others, for example on social media, on a digital CV, or with an educational institution or (potential) employer.
A technical infrastructure is required in order to create and award edubadges. SURF has developed the infrastructure for issuing edubadges; the edubadges are stored securely and can be validated within SURF's systems. More information about edubadges can be found on SURF's website.
Can't find what you're looking for? Take a look at Getting started with edubadges.
The edubadges service is divided into two parts:
- Account/backpack (1)
- Creating and maintaining an account
- Storing edubadges in the backpack
- Validating edubadges
- Issuing edubadges (2)
- Registering for edubadges
- Creating an edubadge
- Issuing an edubadge
SURF is the data controller for the processing of data in the user account, storing edubadges and validating edubadges (1). This privacy statement primarily relates to this data processing. If you have any questions about this data processing, please contact [email protected]. De edubadge 'Edubadge account complete' will be awarded automatically after user account creation. With this edubadge, the functionality of edubadges.nl can be explored. This edubadge can be rejected by clicking 'Reject this edubadge' inside the edubadge's page.
For the issuing of edubadges (2), your educational institution is the data controller and SURF is the data processor. When applying for an edubadge, the educational institution in question will present you its privacy policy. If you have any questions about this processing, please contact your own educational institution. Contact information can be found in the table below.
Instelling | Contactgegevens |
---|---|
Albeda | [email protected] |
Avans Hogeschool | [email protected] |
Deltion | [email protected] |
Erasmus Universiteit Rotterdam | [email protected] |
Fontys | [email protected] |
HAN University of Applied Sciences | [email protected] |
Hanzehogeschool Groningen | [email protected] |
Hogeschool Saxion | [email protected] |
Hogeschool Utrecht | [email protected] |
Maastricht University | [email protected] |
mboRijnland | [email protected] |
NHL Stenden Hogeschool | [email protected] |
Rijksuniversiteit Groningen | [email protected] |
Rotterdam University of Applied Sciences | [email protected] |
Tilburg University | [email protected] |
University of Twente | [email protected] |
Universiteit Utrecht | [email protected] |
VISTA college | [email protected] |
Vrije Universiteit Amsterdam | [email protected] |
Wageningen University & Research | [email protected] |
Below is the privacy statement for the data processing operations associated with 'Account/backpack' (1).
In order for the edubadges platform to function, it is necessary to process personal data. The legal basis for the creation of the user account is the 'performance of an agreement'. The applicable Terms of Use will be displayed when an user account is created.
Two groups of users are distinguished during data processing operations:
- Edubadge recipients: Natural persons having a user account.
- Guests: Natural persons viewing edubadges without an account.
The table below shows the personal data processed for edubadge recipients (along with the purpose and the legal basis). This personal data is obtained by means of a link to the user's eduID account.
Personal data | Purpose | Legal basis |
---|---|---|
Given name(s) | User identification | Performance of an agreement |
Surname | User identification | Performance of an agreement |
E-mail address | Notify user | Performance of an agreement |
Educational institution | Showing the right edubadges | Performance of an agreement |
eduID | Pseudonymous identifier in edubadge | Performance of an agreement |
Privacy Interaction | Whether the Terms of Use have been accepted | Performance of an agreement |
Edubadges | Storage of edubadges | Performance of an agreement |
Backups | Recovery of edubadges service in case of catastrophic event | Performance of an agreement |
An edubadge contains your eduID. The edubadge also contains information such as the time of issue, the issuer (your institution) and information about grades, the educational module and/or learning outcomes. Edubadges essentially last for a lifetime. This is why we keep edubadges until you delete the edubadge or your user account with us (plus a period of one month for backups).
As the owner of an edubadge, you can make the edubadge publicly available in your account/backpack. This allows the edubadge to be verified, for example, by a potential employer or an educational institution.
Guests are viewers of edubadges that have not logged in. No personal data of guests will be processed.
Employees of your educational institution have access to given name(s), surname and e-mail address once you have requested an edubadge. SURF and its parent entity have access to all personal data. Personal data will not be disclosed to other third parties.
Security measures, including the following, have been taken to protect personal data:
- Only the personal data associated with the eduID is stored in the edubadge.
- Communication between systems is encrypted in accordance with the state of the art and best practices.
- An extensive independent security audit (code review and penetration testing) took place before the systems went live.
- The edubadges service will be audited regularly.
- Access to servers is secured in accordance with the state of the art in security technology, standards and best practices.
- All physical and virtual servers and data are located in SURF's data centres in the Netherlands. The edubadges service is hosted redundantly at SURF's Nikhef and InterXion locations.
- All operating systems and software are kept up-to-date.
- Access to the administration side of the edubadges service is shielded by VPN and a hardened configuration for the access itself.
- Backups of the production environment are made daily.
- Servers, operating systems and applications are protected by a restrictive firewall.
- Actions in the operating system and actions taken to issue edubadges are all logged.
- The web server uses a hardened configuration and security headers in accordance with best practices.
- Employee account roles access in edubadges is limited to only the personal data that is relevant to them.
You have the following rights with regard to your own personal data:
- You may submit a request to modify, supplement or delete your data if it is incorrect or no longer relevant.
- You may submit a request to access the data about you that we process.
- You may object to the processing of your data if we process your data on the legal basis of a legitimate interest or the performance of a task in the public interest.
- You may submit a request to limit the processing of your data in relation to the processing of data which you have objected to, which you consider to be unlawful, whose accuracy you have disputed, or where we no longer need the personal data, but you need it in the context of legal action.
- You may request an export of the data we process on you, in a structured and common format, and you have the right to portability of this data to another service provider.
- You may withdraw your consent for the processing of your personal data. However, the withdrawal of your consent does not affect the lawfulness of any processing based on your consent prior to its withdrawal.
- If you believe that SURF has not handled your personal data properly, you may submit a complaint to SURF.
However, if you and SURF disagree and SURF's response to your complaint does not lead to an acceptable outcome, you have the right to submit a complaint about SURF to the Dutch Data Protection Authority. More information on the Dutch Data Protection Authority and the procedure for submitting complaints can be found on the website of the Dutch Data Protection Authority.
To exercise these rights, please contact [email protected] or your own educational institution.
We may amend this privacy statement from time to time. We therefore advise you to consult our privacy statement regularly.