Privacy Policy — GtinSpector
Effective date: 2026-05-13 · Last updated: 2026-05-22 · Version: 1.1
1. Who we are
This policy explains how GS1 Belgium & Luxembourg VZW/ASBL ("GS1 Belgilux", "we", "us") processes personal data through the GtinSpector mobile application (the "app").
- Controller: GS1 Belgium & Luxembourg VZW/ASBL — company number BE 0418 233 415
- Registered office: Ravensteingalerij 4 bus 10, 1000 Brussels, Belgium
- Privacy contact: support@gs1belu.org
This notice sits alongside the general GS1 Belgilux privacy policy and covers only the GtinSpector iOS and Android apps and the Microsoft Dataverse backend they talk to directly. Other GS1 Belgilux products and websites have their own privacy notices.
2. Scope
GtinSpector is a professional tool used internally at GS1 Belgilux (and by authorised partner organisations) to verify product master-data quality by scanning GTIN barcodes, recording validation results, and attaching photographic evidence ("proof photos"). Use of the app requires authentication against a GS1 Belgilux Microsoft Entra ID account.
3. Personal data we process
| Category | Examples | Source |
|---|---|---|
| Identity | Entra ID object ID, email address, display name | Microsoft Entra ID at sign-in |
| Authentication tokens | Access and refresh tokens used to call Microsoft Dataverse on your behalf | Microsoft Entra ID; stored on device only (refresh token in OS-level secure storage) |
| Scans and validation results | The scanned barcode, the GTIN, the validation outcome, timestamp, and the user who performed the scan | Created by you when using the app |
| Proof photos | Photos you take or select from the gallery to evidence a scan or reset a validation | Created by you when using the app |
| Push notification token | A device-specific identifier used to deliver push notifications | Generated by Expo + the platform push service (APNs / FCM), persisted in Dataverse against your user record |
| Diagnostic data | Crash reports, error stack traces, app version, OS version, device model | Captured automatically by Sentry, only on error and only if Sentry is enabled in the build |
We do not collect precise location, contacts, calendar entries, microphone recordings, advertising identifiers, or browsing history. The app contains no advertising and is not used to profile users. We do not engage in automated decision-making or profiling within the meaning of Article 22 of the GDPR.
4. Why we process this data
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Authenticating you against a GS1 Belgilux Entra ID account so you can use the app | Performance of a contract (Art. 6(1)(b)) |
| Storing scans, validation results, and proof photos to verify product master data | Performance of a contract (Art. 6(1)(b)) |
| Delivering push notifications about scans, validation outcomes, and gamification events | Legitimate interest (Art. 6(1)(f)); you can disable notifications in your device settings |
| Diagnosing crashes and errors to improve app stability | Legitimate interest (Art. 6(1)(f)) |
5. Device permissions
| Permission | Used for | Requested |
|---|---|---|
| Camera | Scanning GTIN barcodes; capturing proof photos | First scanner / proof-photo use |
| Photo library | Attaching an existing photo from your gallery as proof | First "from gallery" use |
| Notifications | Delivering push notifications you have opted into | First app start (or first feature that needs them) |
Declining a permission disables only the corresponding feature.
6. Where data lives and who processes it
- Microsoft (processor) — Microsoft Entra ID for authentication and Microsoft Dataverse / Dynamics 365 for scans, proof photos, and the push-token registry. The Dataverse environment is hosted by Microsoft in the European Union (Western Europe geo).
- Expo / Expo Application Services (processor) — registers your push token and routes notifications to APNs / FCM. Notification payload content is generated by GS1 Belgilux from Dataverse; Expo sees only routing metadata and the payload in transit.
- Apple (APNs) and Google (FCM) — deliver push notifications to your device.
- Sentry GmbH (processor) — receives crash reports (stack trace, app version, OS version, device model) only when an error occurs in a build that has Sentry configured.
International transfers. Microsoft, Apple, Google, Expo, and Sentry are established outside the EU and may process limited data (push routing metadata, crash reports) in the United States. Such transfers are covered by the EU Standard Contractual Clauses and the EU–US Data Privacy Framework where applicable. We also refer to the standard data processing agreements (DPAs) of these processors.
We do not sell personal data, share it for advertising, or transfer it to third parties for any purpose other than running the service.
7. Retention
- Scans, validation results, and proof photos are kept for as long as needed for the GS1 product-verification purpose and any related record-keeping obligations. When product-related data are no longer required for providing the service and product verification, they may be retained in archived form to document the services delivered and to comply with legal, regulatory, or record-keeping obligations.
- Authentication and push tokens on your device are cleared when you log out, when the app is uninstalled, or when the token expires.
- Crash reports in Sentry are retained per Sentry's standard retention policy (ninety days).
8. Your rights
Under the EU General Data Protection Regulation (GDPR) and Belgian / Luxembourg implementing legislation you have the right to access, rectify, erase, restrict processing of, port, or object to processing of your personal data, and to withdraw consent where processing is based on consent. To exercise any of these rights, email support@gs1belu.org. We respond within 30 days of verifying your identity.
If you have concerns about how we process your personal data and they persist after you have contacted us, you have the right to lodge a complaint with the Belgian Data Protection Authority (Gegevensbeschermingsautoriteit), the supervisory authority responsible for enforcing data-protection legislation in Belgium. You can contact the Authority via www.gegevensbeschermingsautoriteit.be or at Rue de la Presse 35, 1000 Brussels, Belgium.
9. Security
- All communication between the app and Dataverse is over HTTPS (TLS 1.2+).
- Authentication uses Microsoft Entra ID with PKCE; refresh tokens are held only in iOS Keychain / Android Keystore.
- Microsoft Dataverse encrypts data at rest with Microsoft-managed keys.
- Only authenticated GS1 Belgilux accounts (or explicitly invited partner accounts) can access the app; row-level security in Dataverse limits which records each user can see.
Keep your device locked and your operating system up to date.
10. Children
GtinSpector is a professional tool. It is not directed at children, and we do not knowingly collect personal data from anyone under the age of 16.
11. Changes to this policy
We may update this policy from time to time. Substantive changes will be communicated in the app at least 30 days before they take effect. The "Last updated" date above always reflects the most recent change.
12. Contact
- Email: support@gs1belu.org
- Post: GS1 Belgium & Luxembourg VZW/ASBL — Ravensteingalerij 4 bus 10, 1000 Brussels, Belgium