This app, NetRecon (Android package
be.casavait.netrecon), is published by:
| Controller | Casava-IT |
|---|---|
| Address | Sint-Bertinusstraat 156, 8970 Poperinge, Belgium |
| Registration / VAT | BE1040050133 |
| Contact | info@casava-it.be |
For the purposes of the EU General Data Protection Regulation (GDPR) and the UK GDPR, Casava-IT is the “data controller” for the limited personal data described here.
NetRecon is a defensive network-auditing utility. It discovers devices on the private local network (LAN) your phone is connected to, identifies them, and flags weak or exposed services so you can secure a network you own or administer. Scanning is limited to the private network the device is attached to.
All discovery results — hostnames, MAC addresses, IP addresses, open ports, service banners — are stored only on your device and are used only to display the results to you. NetRecon has no backend server and transmits none of this discovery data to us or to any third party. Two optional checks do contact outside services in order to work at all — see section 3.6 — but neither of them receives anything about your network or the devices on it.
This information is held in the app’s private storage, is excluded from cloud backup and device-to-device transfer, and is deleted when you uninstall the app. Because it never leaves your device, we have no access to it.
The free version of NetRecon displays ads through Google AdMob. To serve ads, Google’s Mobile Ads SDK processes an advertising identifier and related device information, plus coarse signals used for ad delivery, frequency capping and fraud prevention. This is carried out by Google under its own terms — see Google’s Privacy & Terms and the AdMob data disclosures. If you buy the one-time “NetRecon Pro” upgrade, ads are removed and the ads SDK is no longer used.
In the EU/EEA and UK, NetRecon uses Google’s User Messaging Platform (UMP), a certified consent-management platform, to ask for your consent before any personalised or non-personalised ad loads. Your choice is stored on your device and can be changed at any time from Settings → Ad privacy options. No ad is requested until this choice has been made.
The optional “NetRecon Pro” upgrade is a one-time purchase processed by the Google Play (or, on Apple devices, App Store) billing system. We never see your payment-card details; the store confirms only whether the entitlement is owned. Refunds and receipts are handled by the store.
If you use the built-in password-strength check, NetRecon queries the Have I Been Pwned breach database using k-anonymity: only the first five characters of a SHA-1 hash of the password are sent, never the password itself. Nothing you type is transmitted in full or stored. See the HIBP privacy policy.
Two checks contact external services to work at all: the internet-exposure check asks api.ipify.org for your public IP address, and the bandwidth test downloads sample data from speed.cloudflare.com. Both reveal your public IP address to those services, as any internet request does. Neither receives any information about your network or the devices on it. See the ipify and Cloudflare privacy information.
| Permission | Why NetRecon needs it |
|---|---|
| Location (approximate & precise) | Android requires location permission to return nearby Wi-Fi scan results. NetRecon uses it only to enable Wi-Fi scanning. Your location is never collected, stored, or shared, and is not used for tracking or advertising. |
| Nearby Wi-Fi devices | Same purpose on newer Android versions, to list Wi-Fi networks without location. |
| Bluetooth scan / connect | To discover nearby Bluetooth devices as part of the network inventory. Processed on-device only. |
| Network / Wi-Fi state | To detect the current network and perform the LAN scan. |
| Notifications & foreground service | For the optional background monitor that alerts you when a new device joins your network. Runs only if you enable it. |
| Processing | Legal basis |
|---|---|
| Running the scan and storing results on your device | Performance of the service you requested / our legitimate interest in providing the app’s core function (Art. 6(1)(b)/(f)). |
| Personalised or non-personalised advertising | Your consent (Art. 6(1)(a)), collected via the UMP consent form in the EU/EEA/UK. You may withdraw it at any time. |
| Fraud prevention and securing the ad system | Legitimate interests of us and Google (Art. 6(1)(f)). |
| Processing a purchase | Performance of a contract (Art. 6(1)(b)), handled by the app store. |
We do not sell your personal data. The only third parties involved are the service providers named above — Google (advertising, consent, Play billing), Apple (App Store billing on iOS), Have I Been Pwned (only if you use the password check), ipify (only for the internet-exposure check) and Cloudflare (only for the bandwidth test). Where these providers process data outside your country (including in the United States), they do so under their own safeguards, such as the EU Standard Contractual Clauses and applicable adequacy frameworks.
Under the GDPR/UK GDPR you have the right to access, rectify, or erase your personal data; restrict or object to processing; data portability; and to withdraw consent for advertising at any time (Settings → Ad privacy options), without affecting past processing.
Because NetRecon stores its data only on your device and we operate no user database, the most direct way to exercise erasure is to clear the app’s data or uninstall it. For the advertising identifier, you can also reset or delete it in your device’s system settings. For anything else, contact us at info@casava-it.be and we will respond within the statutory time limits.
You also have the right to lodge a complaint with your data-protection supervisory authority — in our case the Belgian Data Protection Authority (www.dataprotectionauthority.be).
NetRecon is a general-audience technical utility and is not directed at children. We do not knowingly collect personal data from children. The app is not enrolled in child-directed ad programmes.
On-device settings that include secrets (such as TV pre-shared keys) are held in the Android encrypted key store. Advertising, consent and billing traffic uses encrypted HTTPS connections. Note that when NetRecon audits other devices on your network it may connect to plaintext services (for example an HTTP admin page) — that is a deliberate part of auditing those devices, not a transmission of your personal data.
We may update this policy as the app evolves. Material changes will be reflected by a new “Last updated” date, and, where required, surfaced in the app or store listing. Continued use after an update constitutes acceptance of the revised policy.
Questions about this policy or your data: info@casava-it.be.
Deze app, NetRecon (Android-pakket
be.casavait.netrecon), wordt uitgegeven door:
| Verwerkingsverantwoordelijke | Casava-IT |
|---|---|
| Adres | Sint-Bertinusstraat 156, 8970 Poperinge, België |
| Onderneming / btw | BE1040050133 |
| Contact | info@casava-it.be |
Voor de toepassing van de Algemene Verordening Gegevensbescherming (AVG/GDPR) is Casava-IT de “verwerkingsverantwoordelijke” voor de beperkte persoonsgegevens die hier worden beschreven.
NetRecon is een defensief hulpprogramma voor netwerkaudits. Het ontdekt apparaten op het private lokale netwerk (LAN) waarmee uw telefoon verbonden is, identificeert ze en signaleert zwakke of blootgestelde diensten, zodat u een netwerk dat u bezit of beheert kunt beveiligen. Het scannen blijft beperkt tot het private netwerk waarmee het toestel verbonden is.
Alle resultaten — hostnamen, MAC-adressen, IP-adressen, open poorten, dienstbanners — worden uitsluitend op uw toestel opgeslagen en dienen enkel om de resultaten aan u te tonen. NetRecon heeft geen backend-server en zendt deze scangegevens niet naar ons of naar derden. Twee optionele controles nemen wél contact op met externe diensten om überhaupt te kunnen werken — zie punt 3.6 — maar geen van beide ontvangt iets over uw netwerk of de apparaten daarop.
Deze informatie staat in de privéopslag van de app, is uitgesloten van cloudback-up en toestel-naar-toestel-overdracht, en wordt verwijderd wanneer u de app deïnstalleert. Omdat ze uw toestel nooit verlaat, hebben wij er geen toegang toe.
De gratis versie van NetRecon toont advertenties via Google AdMob. Om advertenties te tonen verwerkt de Mobile Ads SDK van Google een advertentie-identificator en gerelateerde apparaatinformatie, plus globale signalen voor advertentielevering, frequentiebeperking en fraudepreventie. Dit gebeurt door Google onder haar eigen voorwaarden — zie Privacy & Voorwaarden van Google en de AdMob-gegevensinformatie. Als u de eenmalige upgrade “NetRecon Pro” koopt, worden advertenties verwijderd en wordt de advertentie-SDK niet langer gebruikt.
In de EU/EER en het VK gebruikt NetRecon het User Messaging Platform (UMP) van Google, een gecertificeerd toestemmingsbeheerplatform, om uw toestemming te vragen voordat een gepersonaliseerde of niet-gepersonaliseerde advertentie wordt geladen. Uw keuze wordt op uw toestel opgeslagen en kan op elk moment worden gewijzigd via Instellingen → Advertentie-privacyopties. Er wordt geen advertentie opgevraagd voordat deze keuze is gemaakt.
De optionele upgrade “NetRecon Pro” is een eenmalige aankoop die wordt verwerkt door het betaalsysteem van Google Play (of op Apple-toestellen de App Store). Wij zien uw kaartgegevens nooit; de store bevestigt enkel of het recht in bezit is. Terugbetalingen en bonnetjes worden door de store afgehandeld.
Als u de ingebouwde wachtwoordsterktecontrole gebruikt, bevraagt NetRecon de inbreukendatabank Have I Been Pwned met k-anonimiteit: enkel de eerste vijf tekens van een SHA-1-hash van het wachtwoord worden verzonden, nooit het wachtwoord zelf. Niets van wat u typt wordt volledig verzonden of opgeslagen. Zie het HIBP-privacybeleid.
Twee controles nemen contact op met externe diensten om te kunnen werken: de controle op blootstelling aan internet vraagt uw publieke IP-adres op bij api.ipify.org, en de bandbreedtetest downloadt voorbeelddata van speed.cloudflare.com. Beide onthullen uw publieke IP-adres aan die diensten, zoals elk internetverzoek dat doet. Geen van beide ontvangt informatie over uw netwerk of de apparaten daarop. Zie de privacy-informatie van ipify en Cloudflare.
| Machtiging | Waarom NetRecon ze nodig heeft |
|---|---|
| Locatie (bij benadering & precies) | Android vereist locatietoestemming om Wi-Fi-scanresultaten in de buurt te geven. NetRecon gebruikt ze uitsluitend om Wi-Fi-scannen mogelijk te maken. Uw locatie wordt nooit verzameld, opgeslagen of gedeeld, en wordt niet gebruikt voor tracking of advertenties. |
| Wi-Fi-apparaten in de buurt | Zelfde doel op nieuwere Android-versies, om Wi-Fi-netwerken te tonen zonder locatie. |
| Bluetooth scannen / verbinden | Om Bluetooth-apparaten in de buurt te ontdekken als deel van de netwerkinventaris. Uitsluitend op het toestel verwerkt. |
| Netwerk-/Wi-Fi-status | Om het huidige netwerk te detecteren en de LAN-scan uit te voeren. |
| Meldingen & voorgrondservice | Voor de optionele achtergrondmonitor die u waarschuwt wanneer een nieuw apparaat op uw netwerk verschijnt. Werkt enkel als u dit inschakelt. |
| Verwerking | Rechtsgrond |
|---|---|
| De scan uitvoeren en resultaten op uw toestel opslaan | Uitvoering van de door u gevraagde dienst / ons gerechtvaardigd belang om de kernfunctie van de app te leveren (art. 6(1)(b)/(f)). |
| Gepersonaliseerde of niet-gepersonaliseerde advertenties | Uw toestemming (art. 6(1)(a)), verzameld via het UMP-toestemmingsformulier in de EU/EER/VK. U kunt ze op elk moment intrekken. |
| Fraudepreventie en beveiliging van het advertentiesysteem | Gerechtvaardigde belangen van ons en Google (art. 6(1)(f)). |
| Een aankoop verwerken | Uitvoering van een overeenkomst (art. 6(1)(b)), afgehandeld door de app store. |
Wij verkopen uw persoonsgegevens niet. De enige betrokken derden zijn de hierboven genoemde dienstverleners — Google (advertenties, toestemming, Play-betaling), Apple (App Store-betaling op iOS), Have I Been Pwned (enkel als u de wachtwoordcontrole gebruikt), ipify (enkel voor de controle op blootstelling aan internet) en Cloudflare (enkel voor de bandbreedtetest). Waar deze dienstverleners gegevens buiten uw land verwerken (waaronder de Verenigde Staten), doen zij dat onder hun eigen waarborgen, zoals de EU-modelcontractbepalingen en toepasselijke adequaatheidskaders.
Onder de AVG hebt u het recht op inzage, rectificatie of wissing van uw persoonsgegevens; beperking van of bezwaar tegen de verwerking; overdraagbaarheid van gegevens; en om uw toestemming voor advertenties op elk moment in te trekken (Instellingen → Advertentie-privacyopties), zonder dat dit de eerdere verwerking aantast.
Omdat NetRecon zijn gegevens uitsluitend op uw toestel opslaat en wij geen gebruikersdatabank hebben, is de meest directe manier om wissing uit te oefenen het wissen van de appgegevens of het deïnstalleren van de app. Voor de advertentie-identificator kunt u deze ook resetten of verwijderen in de systeeminstellingen van uw toestel. Voor al het overige kunt u ons contacteren op info@casava-it.be; wij antwoorden binnen de wettelijke termijnen.
U hebt ook het recht om een klacht in te dienen bij uw gegevensbeschermingsautoriteit — in ons geval de Gegevensbeschermingsautoriteit (www.gegevensbeschermingsautoriteit.be).
NetRecon is een technisch hulpprogramma voor een algemeen publiek en is niet gericht op kinderen. Wij verzamelen niet bewust persoonsgegevens van kinderen. De app neemt niet deel aan advertentieprogramma’s gericht op kinderen.
Instellingen op het toestel die geheimen bevatten (zoals tv pre-shared keys) worden bewaard in de versleutelde sleutelopslag van Android. Advertentie-, toestemmings- en betaalverkeer verloopt via versleutelde HTTPS-verbindingen. Merk op dat wanneer NetRecon andere apparaten op uw netwerk auditeert, het verbinding kan maken met onversleutelde diensten (bijvoorbeeld een HTTP-beheerpagina) — dat is een bewust onderdeel van het auditen van die apparaten, geen doorgifte van uw persoonsgegevens.
Wij kunnen dit beleid bijwerken naarmate de app evolueert. Wezenlijke wijzigingen worden weergegeven door een nieuwe datum “Laatst bijgewerkt” en, waar vereist, in de app of de store-vermelding getoond. Voortgezet gebruik na een update geldt als aanvaarding van het herziene beleid.
Vragen over dit beleid of uw gegevens: info@casava-it.be.
Cette application, NetRecon (paquet Android
be.casavait.netrecon), est éditée par :
| Responsable du traitement | Casava-IT |
|---|---|
| Adresse | Sint-Bertinusstraat 156, 8970 Poperinge, Belgique |
| Entreprise / TVA | BE1040050133 |
| Contact | info@casava-it.be |
Aux fins du Règlement général sur la protection des données (RGPD), [LEGAL ENTITY] est le « responsable du traitement » des données à caractère personnel limitées décrites ici.
NetRecon est un utilitaire défensif d’audit de réseau. Il découvre les appareils présents sur le réseau local privé (LAN) auquel votre téléphone est connecté, les identifie et signale les services faibles ou exposés, afin que vous puissiez sécuriser un réseau que vous possédez ou administrez. L’analyse se limite au réseau privé auquel l’appareil est rattaché.
Tous les résultats — noms d’hôtes, adresses MAC, adresses IP, ports ouverts, bannières de service — sont stockés uniquement sur votre appareil et servent seulement à vous afficher les résultats. NetRecon n’a pas de serveur dorsal et ne transmet aucune de ces données d’analyse, ni à nous ni à des tiers. Deux vérifications facultatives contactent bien des services externes pour pouvoir fonctionner — voir le point 3.6 — mais aucune des deux ne reçoit d’information sur votre réseau ni sur les appareils qui s’y trouvent.
Ces informations résident dans le stockage privé de l’application, sont exclues de la sauvegarde cloud et du transfert d’appareil à appareil, et sont supprimées lorsque vous désinstallez l’application. Comme elles ne quittent jamais votre appareil, nous n’y avons aucun accès.
La version gratuite de NetRecon affiche des publicités via Google AdMob. Pour diffuser des publicités, le SDK Mobile Ads de Google traite un identifiant publicitaire et des informations d’appareil associées, ainsi que des signaux généraux servant à la diffusion, au plafonnement de fréquence et à la prévention de la fraude. Cela est effectué par Google selon ses propres conditions — voir les Règles de confidentialité de Google et les informations sur les données AdMob. Si vous achetez la mise à niveau unique « NetRecon Pro », les publicités sont supprimées et le SDK publicitaire n’est plus utilisé.
Dans l’UE/EEE et au Royaume-Uni, NetRecon utilise la plateforme User Messaging Platform (UMP) de Google, une plateforme de gestion du consentement certifiée, pour recueillir votre consentement avant tout chargement d’une publicité personnalisée ou non personnalisée. Votre choix est stocké sur votre appareil et peut être modifié à tout moment via Paramètres → Options de confidentialité publicitaire. Aucune publicité n’est demandée avant que ce choix ait été fait.
La mise à niveau facultative « NetRecon Pro » est un achat unique traité par le système de paiement de Google Play (ou, sur les appareils Apple, l’App Store). Nous ne voyons jamais vos données de carte ; la boutique confirme seulement si le droit est détenu. Les remboursements et reçus sont gérés par la boutique.
Si vous utilisez la vérification intégrée de robustesse de mot de passe, NetRecon interroge la base de fuites Have I Been Pwned selon le principe de k-anonymat : seuls les cinq premiers caractères d’un condensé SHA-1 du mot de passe sont envoyés, jamais le mot de passe lui-même. Rien de ce que vous saisissez n’est transmis en entier ni stocké. Voir la politique de confidentialité de HIBP.
Deux vérifications contactent des services externes pour pouvoir fonctionner : la vérification d’exposition à Internet demande votre adresse IP publique à api.ipify.org, et le test de débit télécharge des données d’exemple depuis speed.cloudflare.com. Toutes deux révèlent votre adresse IP publique à ces services, comme le fait toute requête Internet. Aucune ne reçoit d’information sur votre réseau ni sur les appareils qui s’y trouvent. Voir les informations de confidentialité d’ ipify et de Cloudflare.
| Autorisation | Pourquoi NetRecon en a besoin |
|---|---|
| Localisation (approximative & précise) | Android exige l’autorisation de localisation pour renvoyer les résultats d’analyse Wi-Fi à proximité. NetRecon l’utilise uniquement pour permettre l’analyse Wi-Fi. Votre position n’est jamais collectée, stockée ni partagée, et n’est pas utilisée à des fins de suivi ou de publicité. |
| Appareils Wi-Fi à proximité | Même finalité sur les versions récentes d’Android, pour lister les réseaux Wi-Fi sans localisation. |
| Analyse / connexion Bluetooth | Pour découvrir les appareils Bluetooth à proximité dans le cadre de l’inventaire réseau. Traité uniquement sur l’appareil. |
| État réseau / Wi-Fi | Pour détecter le réseau actuel et effectuer l’analyse LAN. |
| Notifications & service de premier plan | Pour le moniteur d’arrière-plan facultatif qui vous alerte lorsqu’un nouvel appareil rejoint votre réseau. Ne fonctionne que si vous l’activez. |
| Traitement | Base légale |
|---|---|
| Exécuter l’analyse et stocker les résultats sur votre appareil | Exécution du service que vous avez demandé / notre intérêt légitime à fournir la fonction principale de l’application (art. 6(1)(b)/(f)). |
| Publicité personnalisée ou non personnalisée | Votre consentement (art. 6(1)(a)), recueilli via le formulaire de consentement UMP dans l’UE/EEE/RU. Vous pouvez le retirer à tout moment. |
| Prévention de la fraude et sécurisation du système publicitaire | Intérêts légitimes de nous et de Google (art. 6(1)(f)). |
| Traiter un achat | Exécution d’un contrat (art. 6(1)(b)), géré par la boutique d’applications. |
Nous ne vendons pas vos données à caractère personnel. Les seuls tiers concernés sont les prestataires nommés ci-dessus — Google (publicité, consentement, paiement Play), Apple (paiement App Store sur iOS), Have I Been Pwned (uniquement si vous utilisez la vérification de mot de passe), ipify (uniquement pour la vérification d’exposition à Internet) et Cloudflare (uniquement pour le test de débit). Lorsque ces prestataires traitent des données hors de votre pays (y compris aux États-Unis), ils le font sous leurs propres garanties, telles que les clauses contractuelles types de l’UE et les cadres d’adéquation applicables.
En vertu du RGPD, vous avez le droit d’accéder à vos données à caractère personnel, de les rectifier ou de les effacer ; de limiter le traitement ou de vous y opposer ; à la portabilité des données ; et de retirer votre consentement à la publicité à tout moment (Paramètres → Options de confidentialité publicitaire), sans que cela n’affecte le traitement antérieur.
Comme NetRecon stocke ses données uniquement sur votre appareil et que nous n’exploitons aucune base d’utilisateurs, le moyen le plus direct d’exercer l’effacement est d’effacer les données de l’application ou de la désinstaller. Pour l’identifiant publicitaire, vous pouvez également le réinitialiser ou le supprimer dans les paramètres système de votre appareil. Pour tout le reste, contactez-nous à info@casava-it.be ; nous répondrons dans les délais légaux.
Vous avez également le droit d’introduire une réclamation auprès de votre autorité de protection des données — dans notre cas l’Autorité de protection des données (www.autoriteprotectiondonnees.be).
NetRecon est un utilitaire technique destiné à un public général et ne s’adresse pas aux enfants. Nous ne collectons pas sciemment de données à caractère personnel auprès d’enfants. L’application ne participe pas à des programmes publicitaires destinés aux enfants.
Les réglages de l’appareil contenant des secrets (comme les clés pré-partagées de téléviseur) sont conservés dans le coffre de clés chiffré d’Android. Le trafic publicitaire, de consentement et de paiement utilise des connexions HTTPS chiffrées. Notez que lorsque NetRecon audite d’autres appareils de votre réseau, il peut se connecter à des services non chiffrés (par exemple une page d’administration HTTP) — cela fait partie intégrante de l’audit de ces appareils, et ne constitue pas une transmission de vos données à caractère personnel.
Nous pouvons mettre à jour cette politique à mesure que l’application évolue. Les modifications importantes seront reflétées par une nouvelle date de « Dernière mise à jour » et, le cas échéant, signalées dans l’application ou la fiche de la boutique. La poursuite de l’utilisation après une mise à jour vaut acceptation de la politique révisée.
Questions sur cette politique ou vos données : info@casava-it.be.