harmony mobile privacy data sheet.pdf
Privacy Data Sheet Mobile
About Harmony Mobile
Harmony Mobile is an innovative security solution designed to protect mobile devices from advanced threats such as malware, spyware, phishing, malicious or risky networks, targeted attacks, and other malicious technologies that may gather information from mobile devices or the organizations they access. It provides comprehensive protection across multiple layers, including app protection, file and web threat prevention, network protection, and device-level security.
Key features of Harmony Mobile include:
- App Protection: Prevents malware from infiltrating devices by detecting and blocking the download of malicious apps.
- Network Protection: Offers a broad range of network security capabilities, including anti-phishing safe browsing and Wi-Fi network security.
- Device-Level Security: Assesses device risk, detects OS vulnerabilities, and detects advanced rooting and jailbreak devices.
- File Protection: Detects malicious files whether they might pose a risk for mobile devices or for other endpoints (computers & servers).
How Does Check Point Comply with Applicable Data Protection Regulations?
At Check Point, ensuring customer privacy and security remains our foremost concern, with the trust our customers place in our services being one of our most valued assets.
Security. As a leading AI-powered, cloud-delivered cybersecurity platform provider over the past decades, we acknowledge the significance of implementing rigorous security measures to safeguard our customers’ information. For more details, visit our Information Security Measures Policy.
Privacy by Design. We operate under the principle of privacy by design. This means that we prioritize the protection of personal data and privacy throughout the entire lifecycle of our products and services. We treat personal data with the utmost care. Our commitment to privacy is reflected in our policies, procedures, and the way we do business. For more details, visit our Privacy Policy and our Trust Point.
Disaster Recovery. We maintain comprehensive plans and procedures for disaster recovery and business continuity.
Transfers. In order to regulate the transfer of personal data between the Check Point entities, Check Point has adopted an intercompany agreement for transfers of data between its various Check Point entities, including the EU Standard Contractual Clauses and UK International Data Transfer Addendum to the EU Standard Contractual Clauses. Check Point’s US subsidiary, Check Point Software Technologies, Inc. (and its subsidiaries) has self-certified its compliance with the EU-U.S. Data Privacy Framework, the UK Extension to the EU-U.S. Data Privacy Framework, and the Swiss-U.S. Data Privacy Framework (DPF).
What Types of Personal Data Does Harmony Mobile Process?
Harmony Mobile requires the user’s email address, typically their work email address provided by their enterprise organization, or a phone number to register a device. If Harmony Mobile is integrated with the organization’s Unified Endpoint Management (UEM) solution, a unique device identifier (assigned by the UEM) can be used instead.
When a user device is created within the organization’s Harmony Mobile admin management console, a unique identifier (Check Point device ID) is generated and used as the ‘pseudonymized’ method of identifying a user’s device within Harmony Mobile.
Harmony Mobile collects the following personal data:
- Information provided by the admin, during registration: unique device identifier, email address and/or phone number.
- Personal data provided by the organization: The organization’s administrator may provide a user’s full name or organization identifier, email address, and telephone number.
- Personal data voluntarily provided by the user: App users may provide Check Point with certain troubleshooting information using the “issue report” text box in the App, such as personal details while reporting an issue or debugging information of an issue.
- Phone content – such as installed applications and downloaded files content and metadata.
- Personal data the user allowed access to - geolocation data, storage data. Geolocation data may be used when a threat is detected according to organizational access rules, provided that user permission has been granted.
Harmony Mobile does not inspect data exchanges with financial or health domains.
Why Does Harmony Mobile Process Personal Data?
Harmony Mobile processes information to provide real-time prevention for mobile-based threats, as well as for threats found in collaboration tools and shared files.
For more information on the purposes for which we process personal data, please visit our Privacy Policy.
What Is the Duration and Frequency of Processing?
Personal data is shared with Harmony Mobile throughout the subscription term.
Retention
| DATA TYPE | RETENTION PERIOD |
|---|---|
| Data that was added by the organization's administrator:Emails,Phone number,other | Duration of subscription term + 3 months following the end of subscription term, for the purpose of allowing the customer to renew the service. |
| Scanned ("verified") content, including files, websites, and applications* | The files are removed following the completion of the scan and once a verdict is available, typically within 10 minutes. |
- Harmony Mobile transmits hashed data to ThreadCloud AI for analysis. ThreatCloud AI processes the data in accordance with its Privacy Data Sheet.
If a malicious file, domain, or application is identified, it is sent to Infinity Events and stored for 90 days.
Where Is Personal Information Stored?
Personal information is stored on AWS Cloud Hosting Service. The hosting locations available are: United States, Europe, Australia, India, Canada, United Kingdom and United Arab Emirates. The location is selected per customer’s choice during the onboarding process.
Sub-Processors
Check Point engages third-party Sub-processors in connection with the provision of the Check Point’s products and services. The list of Sub-processors is available at our Sub-Processors Page.
Privacy Options
We provide the following configurations, empowering our customers to select their data and privacy preferences:
- Personal Data Access Restriction – Harmony Mobile allows organization administrators to select the users’ data they wish to import from their UEM.
- Personal data obfuscation – Organization administrators can use Harmony Mobile Connector to obscure personal data in the cloud, which can only be accessed through network connectivity to the Connector.
- Scoping the protected user data – Organization administrators can adjust their policy (rules) to control the inspection of transmitted user data at granular levels such as domain name, server, or IP address.
- UEM Configuration – Organization administrators can set up the organization’s UEM to assign a unique device identifier to a user, which is used instead of their work email address or phone number when registering a device.
The organization sets rules that determine which URLs, applications, or websites will be blocked.
Authorized Access to Personal Data
Information contained in this data sheet is for awareness only, may be modified, and does not constitute legal or professional advice or warranty of fitness for a particular purpose.
All access and action by administrators and authorized users are fully logged.
This Privacy Data Sheet is a supplement to Check Point’s Privacy Policy. Please visit it for more information on how Check Point collects and uses personal data.