Assetnix · Technix AB · Annex A
This annex sets out the categories of personal data processed in Assetnix, the source systems from which the data is retrieved, and the data that is expressly not processed. The field lists have been compiled from the service's implemented data collection and cover the personal data actually retrieved, processed and stored within the service.
Controller
The customer organisation
Processor
Technix AB — Assetnix service
Hosting
swedencentral
Microsoft Azure SQL Database and App Service. No transfer outside the EU/EEA by the service.
Flow direction
Read-only
Assetnix never writes back to any source system.
Assetnix retrieves data from eight different source systems. What is decisive for assessing the processing of personal data is who is the controller for each source. Source systems 1–3 and 8 relate to the Customer's own directory and require the Customer's Entra ID administrator to grant the necessary admin consent. Source systems 4–7 are integrations with Technix's own systems and do not process personal data from the Customer's directory.
| Source system | Owned by | Transport | Frequency | Personal data | |
|---|---|---|---|---|---|
| 1 | Microsoft Entra ID | Customer | Microsoft Graph API (HTTPS) | Interval in hours | Yes |
| 2 | Microsoft Intune | Customer | Microsoft Graph API (HTTPS) | Interval in hours | Yes |
| 3 | Microsoft 365 licensing | Customer | Microsoft Graph API (HTTPS) | Interval in hours | Yes Pseudonymous |
| 4 | NinjaOne RMM | Technix | NinjaOne REST API (HTTPS, OAuth2) | Interval in hours Online-status poll every 3 hours | No |
| 5 | ACMP subscriptions | Technix | ACMP REST API (HTTPS) | Interval in hours | No |
| 6 | Netset order data | Technix | Authenticated retrieval over HTTPS | Interval in hours | No Delivery city only |
| 7 | Visma.net ERP | Technix | Visma.net Service API (HTTPS, OAuth2) | Interval in hours | No Organisation address only |
| 8 | Sign-in (OpenID Connect) | Customer | Entra ID identity token | Per sign-in | Yes |
A scheduler evaluates due syncs every 15 minutes. The interval for each source is configured in hours and can differ between sources and between customers.
Graph permissions · application · admin consent required
The customer determines the scope. The customer's administrator can designate a security group in Entra ID, in which case only the members of that group are synchronised; if no group is selected, the synchronisation covers all Member accounts in the directory. The selection is made by the customer within the service and can be changed or removed at any time.
| Graph field | Stored as | Category |
|---|---|---|
| id Object ID | User.Id | Identifier |
| displayName | User.DisplayName | Identity |
| mail / userPrincipalName | User.Email | Contact details |
| jobTitle | User.JobTitle | Employment |
| department | Department lookup | Employment |
| city | Office lookup | Work location |
| streetAddress | Office resolution only | Work location |
| userType | Filter only — not stored | — |
Assetnix only processes user accounts classified as Member in the source system. Accounts of type Guest, or equivalent external users, are excluded from synchronisation and processing. When a user is removed or no longer exists in the source directory, the data is retained in Assetnix in an inactive state. It is then used solely for historical, audit and reporting purposes and is not automatically deleted from the system.
Not read
Phone numbers · personal or home addresses · manager chains · photographs · employee IDs · dates of birth · group memberships beyond the configured sync-scope group · any special-category data.
Graph permissions · application · admin consent required
The customer determines the scope. The customer's administrator can designate a separate Entra group of devices, in which case only the managed devices in that group are synchronised; if no group is selected, the synchronisation covers all managed devices. The selection is made by the customer within the service and can be changed or removed at any time.
| Graph field | Stored as | Category |
|---|---|---|
| id | Device.Id | Identifier |
| deviceName | Device.DeviceName | Device identity Frequently embeds a username in practice |
| serialNumber | Device.SerialNumber | Device identifier |
| imei | Device.Imei | Device identifier |
| azureADDeviceId | Device.AzureAdDeviceId | Identifier |
| operatingSystem, osVersion | Device.OperatingSystem, OsVersion | Technical |
| manufacturer, model | Device.Manufacturer, Model | Technical |
| complianceState | Device.ComplianceState | Compliance status |
| managedDeviceOwnerType | Device.OwnerType | Company or personal |
| userId | Device.AssignedUserId | Identifier Links a device to a person |
| userDisplayName | Device.AssignedUserDisplayName | Identity |
| userPrincipalName | Device.AssignedUserEmail | Contact details |
| lastSyncDateTime | Device.LastSyncDateTime | Last device check-in |
Devices removed upstream are marked not-synced and inactive rather than deleted, so the asset history remains auditable.
Not read
Device location or GPS · installed application inventory · browsing and usage telemetry · network addresses (IP or MAC) · disk-encryption keys · file contents · configuration-profile payloads.
subscribedSkus — skuId, skuPartNumber, prepaidUnits, consumedUnits. Subscription volumes; no personal data.
users — id, assignedLicenses. Links a directory object ID to the licences assigned to it, forming a licence-entitlement record per person.
Not read
Licence usage, activity, or consumption telemetry of any kind.
The scope per customer is the configured Ninja organisation.
Devices
id, organizationId, systemName, nodeClass, offline, lastContact
Computer system
deviceId, serialNumber, biosSerialNumber, manufacturer, model
Stored against the asset as device reference, online state and last-seen timestamp, plus serial and model matching. No user identity, no logged-in-user data, and no monitoring or telemetry content is read.
Commercial subscription and price data at organisation level:
AccountId, CompanyName, AccountState, ServiceName, ServiceDisplayName, VendorDisplayName, ContractEndDate, BillingStartDate, SalesPrice, ChargeType
No personal data is processed from this source.
The data is retrieved over an authenticated, encrypted connection.
Data retrieved: order number, order date, customer number, quantity, product description, sale price, product category and sub-category, serial numbers, delivery city.
This provides purchase and warranty provenance for assets. The delivery city is the only address element taken — no named recipient and no street address.
| Record | Fields read |
|---|---|
| Shipment | Shipment number, type, status, date and last-modified timestamp |
| Customer | Internal reference, customer number, company name |
| Delivery address | Address line, postal code, city |
| Shipment lines | Article number, description, warehouse, location, quantity, serial numbers |
| Sales-order lines | unitPrice, extPrice Sets the asset purchase price |
The customer name and delivery address relate to the Customer's organisation and its delivery locations. The data is used to link devices, orders and deliveries to the correct customer organisation and is not normally attributable to an identified or identifiable natural person.
The following is not synced from a source system but is created and processed by the service, and is therefore in scope for this annex.
| Record | Contents | Purpose |
|---|---|---|
| Sign-in record | Directory tenant and object identifiers, name claims, and the last-login timestamp | Authentication, customer separation |
| System audit log | Timestamp, actor name, actor IP address, record type and name, action, and field-level changes | Security audit, traceability |
| Asset history | Timestamp, changed by, event type, field name, previous and new value, notes | Asset lifecycle traceability |
| Asset assignment | Which user holds which asset, with assignment and return dates | Core service function |
| Licence assignment | Which user holds which licence | Core service function |
| Feedback | Title, description, submitter identifier, name, email address, and the page it was sent from | Support |
| Application logs | Azure Application Insights and Log Analytics Device and user identifiers may appear in diagnostic entries | Operations, troubleshooting |
No local passwords exist — authentication is delegated to Entra ID in full. Integration credentials are held in Azure Key Vault or encrypted at rest. Customer API keys are stored only as irreversible hashes; the key itself is shown once at creation and is never logged.
Every customer-scoped table carries a customer identifier and is protected by a global filter in the data layer, so a query cannot return another customer's records.
Technix staff access to a customer environment runs through an audited flow that records the acting user and their organisation.
Deletions are soft deletes, and records removed in a source system are deactivated rather than erased, to preserve the audit trail.
Active data is retained while the organisation is a customer of Technix. Audit records are retained for the subscription term plus a 90-day window after the agreement ends.
Erasure requests from data subjects are handled through the offboarding process initiated by the controller.
Assetnix processes no special-category data within the meaning of Article 9 GDPR, no payment or financial data relating to data subjects, no health data, and performs no location tracking of individuals.
For data protection questions, a signed copy of the data processing agreement, or a record of processing activities, contact Technix.
The field lists in this annex were compiled from the service's implemented queries rather than from product documentation. Sync frequency is configurable per source and per customer, so any specific interval should be confirmed for your own environment.
Last updated: September 2026 · Technix AB