aboutsummaryrefslogtreecommitdiff
path: root/contrib/pp/pp.rst
diff options
context:
space:
mode:
Diffstat (limited to 'contrib/pp/pp.rst')
-rw-r--r--contrib/pp/pp.rst186
1 files changed, 186 insertions, 0 deletions
diff --git a/contrib/pp/pp.rst b/contrib/pp/pp.rst
new file mode 100644
index 0000000..a8ff838
--- /dev/null
+++ b/contrib/pp/pp.rst
@@ -0,0 +1,186 @@
1Privacy Policy
2==============
3
4Last Updated: 07.09.2021
5
6This Privacy Policy describes the policies and procedures of Anastasis
7SARL (“we,” “our,” or “us”) pertaining to the collection, use, and
8disclosure of your information on our sites and related mobile
9applications and products we offer (the “Services”). This Privacy
10Statement applies to your personal data when you use our Services, and
11does not apply to online websites or services that we do not own or
12control.
13
14
15Overview
16--------
17
18Your privacy is important to us. We follow a few fundamental
19principles: We don’t ask you for personally identifiable information
20(defined below). That being said, your contact information, such as
21your phone number, social media handle, or email address (depending on
22how you contact us), may be collected when you communicate with us,
23for example to report a bug or other error related to Anastasis. We
24don’t share your information with third parties except when strictly
25required to deliver you our Services and products, or to comply with
26the law. If you have any questions or concerns about this policy,
27please reach out to us at privacy@anastasis.lu.
28
29
30How you accept this policy
31--------------------------
32
33By using our Services or visiting our sites, you agree to the use, disclosure,
34and procedures outlined in this Privacy Policy.
35
36
37What personal information do we collect from our users?
38-------------------------------------------------------
39
40The information we collect from you falls into two categories: (i) personally
41identifiable information (i.e., data that could potentially identify you as an
42individual) (“Personal Information”), and (ii) non-personally identifiable
43information (i.e., information that cannot be used to identify who you are)
44(“Non-Personal Information”). This Privacy Policy covers both categories and
45will tell you how we might collect and use each type.
46
47We do our best to not collect any Personal Information from Anastasis
48users. The detailed Personal Information Anastasis asks from you during
49the regular backup and recovery process at the beginning is never shared
50with us and only used to create a cryptographic account identifier which
51does not allow us to recover any of your details.
52
53That being said, when using our Services to recover key material, we may
54inherently receive the following information (depending on your choice of
55authentication method):
56
57 * Bank account details necessary when receiving funds from you to authenticate via a SEPA transfer. We will store these as part of our business records for accounting, and our bank will also be legally obliged to store the details for many years.
58
59 * Your phone number when using SMS authentication. We rely on third party providers (such as your mobile network operator) to deliver the SMS to you. These third parties will see the SMS message sent to you and could thus learn that you are using Anastasis. SMS is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your SMS number on our systems, except maybe in short-term logs to diagnose errors.
60
61 * Your e-mail address when using E-mail authentication. We rely on the Internet and your E-mail provider to deliver the E-mail to you. Internet service providers will see the E-mail message sent to you and could thus learn that you are using Anastasis. E-mail is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your E-mail address on our systems, except maybe in short-term logs to diagnose errors.
62
63 * Your physical address when using postal mail authentication. We rely on external providers for printing and sending the letter to you. These providers will need to learn your address and could learn that you are using Anastasis. Physical mail has strict privacy protections by law, but governments are known to break postal secrecy. We do not store your physical address on our systems, except maybe in short-term logs to diagnose errors.
64
65 * When you contact us. We may collect certain information if you choose to contact us, for example to report a bug or other error with the Taler Wallet. This may include contact information such as your name, email address or phone number depending on the method you choose to contact us.
66
67
68How we collect and process information
69--------------------------------------
70
71We may process your information for the following reasons:
72
73 * to authenticate you during secret recovery
74 * to support you using Anastasis when you contact us
75
76
77How we share and use the information we gather
78----------------------------------------------
79
80We may share your authentication data with other providers that assist
81us in performing the authentication. We will try to use providers that
82to the best of our knowledge respect your privacy and have good
83privacy practices. We reserve the right to change authentication
84providers at any time to ensure availability of our services.
85
86We primarily use the limited information we receive directly from you to
87enhance Anastasis. Some ways we may use your Personal Information are
88to: Contact you when necessary to respond to your comments, answer your
89questions, or obtain additional information on issues related to bugs or
90errors with the Anastasis application that you reported.
91
92
93Agents or third party partners
94------------------------------
95
96We may provide your Personal Information to our employees, contractors,
97agents, service providers, and designees (“Agents”) to enable them to perform
98certain services for us exclusively, including: improvement and maintenance of
99our software and Services. By accepting this Privacy Policy, as outlined
100above, you consent to any such transfer.
101
102
103Protection of us and others
104---------------------------
105
106We reserve the right to access, read, preserve, and disclose any information
107that we reasonably believe is necessary to comply with the law or a court
108order.
109
110
111What personal information can I access or change?
112-------------------------------------------------
113
114You can request access to the information we have collected from
115you. You can do this by contacting us at privacy@anastasis.lu. We will
116make sure to provide you with a copy of the data we process about
117you. To comply with your request, we may ask you to verify your
118identity. We will fulfill your request by sending your copy
119electronically. For any subsequent access request, we may charge you
120with an administrative fee. If you believe that the information we
121have collected is incorrect, you are welcome to contact us so we can
122update it and keep your data accurate. Any data that is no longer
123needed for purposes specified in the “How We Use the Information We
124Gather” section will be deleted after ninety (90) days.
125
126
127Data retention
128--------------
129
130Information entered into our bug tracker will be retained indefinitely
131and is typically made public. We will only use it to triage the
132problem. Beyond that, we do not retain personally identifiable
133information about our users for longer than one week.
134
135
136Data security
137-------------
138
139We are committed to making sure your information is protected. We employ
140several physical and electronic safeguards to keep your information safe,
141including encrypted user passwords, two factor verification and authentication
142on passwords where possible, and securing connections with industry standard
143transport layer security. You are also welcome to contact us using GnuPG
144encrypted e-mail. Even with all these precautions, we cannot fully guarantee
145against the access, disclosure, alteration, or deletion of data through
146events, including but not limited to hardware or software failure or
147unauthorized use. Any information that you provide to us is done so entirely
148at your own risk.
149
150
151Changes and updates to privacy policy
152-------------------------------------
153
154We reserve the right to update and revise this privacy policy at any time. We
155occasionally review this Privacy Policy to make sure it complies with
156applicable laws and conforms to changes in our business. We may need to update
157this Privacy Policy, and we reserve the right to do so at any time. If we do
158revise this Privacy Policy, we will update the “Effective Date” at the top
159of this page so that you can tell if it has changed since your last visit. As
160we generally do not collect contact information and also do not track your
161visits, we will not be able to notify you directly. However, Anastasis clients
162may inform you about a change in the privacy policy once they detect that the
163policy has changed. Please review this Privacy Policy regularly to ensure that
164you are aware of its terms. Any use of our Services after an amendment to our
165Privacy Policy constitutes your acceptance to the revised or amended
166agreement.
167
168
169International users and visitors
170--------------------------------
171
172Our Services are (currently) hosted in Germany. If you are a user
173accessing the Services from the Switzerland, Asia, US, or any other
174region with laws or regulations governing personal data collection,
175use, and disclosure that differ from the laws of Germany, please be
176advised that through your continued use of the Services, which is
177governed by the law of the country hosting the service, you are
178transferring your Personal Information to Germany and you consent to
179that transfer.
180
181
182Questions
183---------
184
185Please contact us at privacy@anastasis.lu if you have questions about our
186privacy practices that are not addressed in this Privacy Statement.