vStream Digital Media / ShineVR

Bring Your Own Device (BYOD) Policy

Last updated: 03/02/25

Definitions

TermDefinition
Companymeans vStream Digital Media
ShineVRmeans the ShineVR product developed and operated by vStream Digital Media
GDPRmeans the General Data Protection Regulation
Responsible Personmeans Andrés Pitt, CTO
BYODBring Your Own Device - the practice of employees using their personal devices for work purposes
Personal DeviceAny computing device owned by an employee including smartphones, tablets, laptops, or desktop computers
Company DataAny data owned by or processed on behalf of vStream Digital Media or ShineVR, including emails, documents, customer data, and application data
Managed ApplicationsWork-related applications such as Google Workspace, Slack, and ShineVR testing applications

1. Policy Statement

vStream Digital Media recognises that employees may wish to use their personal devices for work purposes and that ShineVR application testing often occurs on personal smartphones. This Bring Your Own Device (BYOD) policy establishes security requirements and acceptable use guidelines for personal devices accessing Company systems or data.

Whilst the Company respects employee privacy and ownership of personal devices, employees who choose to use personal devices for work purposes must implement appropriate security measures to protect Company and ShineVR data. This policy balances operational flexibility with information security requirements.

2. Purpose

The purpose of this policy is to:

3. Scope

This policy applies to:

This policy does not apply to:

4. Permitted Uses Of Personal Devices

4.1 Approved Activities

Personal devices may be used for:

4.2 Prohibited Activities

Personal devices must not be used for:

4.3 ShineVR Application Testing

For employees testing ShineVR applications on personal smartphones:

5. Security Requirements For Personal Devices

All personal devices used for work purposes must meet the following mandatory security requirements:

5.1 Operating System and Software Updates

Mandatory Requirement: Devices must run current, supported operating systems with latest security updates

Specific Requirements:

5.2 Anti-Malware and Security Software

Mandatory Requirement: Devices must have active, up-to-date anti-malware protection

Mobile Devices (iOS/Android):

Recommended Mobile Anti-Malware Solutions:

Computers (Windows/macOS/Linux):

Recommended Computer Anti-Malware Solutions:

5.3 Device Lock and Authentication

Mandatory Requirements:

5.4 Encryption

Mandatory Requirement: Full device encryption must be enabled

Implementation:

Verification:

5.5 Network Security

Mandatory Requirements:

5.6 Application Security

Mandatory Requirements:

5.7 Data Storage and Backup

Mandatory Requirements:

5.8 Physical Security

Mandatory Requirements:

6. Employee Responsibilities

Employees using personal devices for work must:

6.1 Security Compliance

6.2 Software and Updates

6.3 Data Protection

6.4 Acceptable Use

6.5 Incident Reporting

Report immediately to CTO (andres@vstream.ie):

7. Company Responsibilities

The Company will:

7.1 Policy and Guidance

7.2 Support and Assistance

7.3 Incident Response

7.4 Privacy Respect

8. Company Support Limitations

8.1 Limited IT Support

The Company provides limited support for personal devices:

Supported:

Not Supported:

8.2 Employee Responsibility for Device Costs

Employees are responsible for:

8.3 No Company Liability for Personal Devices

The Company is not liable for:

9. Data Management And Separation

9.1 Work Data vs. Personal Data

9.2 Company Data Ownership

9.3 Data Deletion Upon Separation

When employment ends or employee stops using personal device for work:

10. Remote Wipe Capability

10.1 When Remote Wipe May Be Used

Company may remotely wipe work-related data from personal devices if:

10.2 Selective Wipe vs. Full Wipe

10.3 Employee Consent

10.4 Backup Recommendations

Employees should:

11. Privacy Considerations

11.1 Employee Privacy Protection

The Company respects employee privacy:

11.2 Company Data Access Rights

For work-related data only, Company retains rights to:

11.3 Transparency

Company will:

12. Compliance And Monitoring

12.1 Compliance Verification

12.2 Security Assessments

12.3 Enforcement

Failure to comply with BYOD security requirements may result in:

13. Special Considerations

13.1 Processing Customer Personal Data

Employees must not:

If customer data must be accessed:

13.2 Regulated Data (Health Data for ShineVR)

For health-related data (pain scores, clinical data):

13.3 Development and Source Code

Developers using personal devices:

13.4 International Travel

Employees travelling internationally with personal devices containing Company data:

14. Acceptable Use

14.1 Prohibited Activities

Personal devices used for work must not be used for:

14.2 Personal Use

15. Training And Awareness

15.1 BYOD Security Training

All employees using personal devices for work must complete:

15.2 Resources and Support

Company provides:

16. Exceptions

16.1 Exception Process

Exceptions to this policy may be considered in rare circumstances:

16.2 Temporary Exceptions

Short-term exceptions may be granted for:

All exceptions documented and tracked.

17. Policy Review And Updates

17.1 Regular Review

This policy will be reviewed:

17.2 Communication of Changes

18. Termination Of BYOD Privileges

The Company may terminate an employee's BYOD privileges:

Termination of BYOD privileges means:

19. Acknowledgement And Agreement

By using a personal device for work purposes, employees acknowledge and agree to:

20. Related Policies

This policy should be read in conjunction with:

21. Roles And Responsibilities

RoleResponsibilities
CTO (Responsible Person)Policy ownership and maintenance; approve exceptions; incident response; compliance monitoring; provide security guidance
IT SupportProvide configuration guidance; support Google Workspace setup; assist with security questions; respond to incidents
EmployeesImplement security requirements; maintain device security; report incidents; remove Company data upon separation; comply with all policy requirements
Line ManagersEnsure team members aware of policy; monitor compliance; support incident reporting; verify data removal upon separation

22. Contact Information

For questions about this policy or to report BYOD security incidents:

Data Protection Officer / CTO: Andrés Pitt Email: andres@vstream.ie Phone: (086) 788 6570

For Lost or Stolen Devices (Emergency): Contact CTO immediately: (086) 788 6570

BYOD Security Requirements Quick Reference Card

Mandatory Security Checklist:

Immediately Report to CTO:

Contact: andres@vstream.ie / (086) 788 6570