0.html (13185B)
1 2 3 <html lang="en"> 4 <head> 5 <meta charset="utf-8" /> 6 <meta name="viewport" content="width=device-width, initial-scale=1.0" /> 7 <title>Privacy Policy — Taler Privacy Policy</title> 8 <link rel="stylesheet" href="_static/pygments.css" type="text/css" /> 9 <link rel="stylesheet" href="_static/epub.css" type="text/css" /> 10 <script id="documentation_options" data-url_root="./" src="_static/documentation_options.js"></script> 11 <script src="_static/jquery.js"></script> 12 <script src="_static/underscore.js"></script> 13 <script src="_static/doctools.js"></script> 14 </head><body> 15 16 <div class="document"> 17 <div class="documentwrapper"> 18 <div class="bodywrapper"> 19 <div class="body" role="main"> 20 21 <div class="section" id="privacy-policy"> 22 <h1>Privacy Policy<a class="headerlink" href="#privacy-policy" title="Permalink to this headline">¶</a></h1> 23 <p>Last Updated: 07.09.2021</p> 24 <p>This Privacy Policy describes the policies and procedures of Anastasis 25 SARL (“we,” “our,” or “us”) pertaining to the collection, use, and 26 disclosure of your information on our sites and related mobile 27 applications and products we offer (the “Services”). This Privacy 28 Statement applies to your personal data when you use our Services, and 29 does not apply to online websites or services that we do not own or 30 control.</p> 31 <div class="section" id="overview"> 32 <h2>Overview<a class="headerlink" href="#overview" title="Permalink to this headline">¶</a></h2> 33 <p>Your privacy is important to us. We follow a few fundamental 34 principles: We don’t ask you for personally identifiable information 35 (defined below). That being said, your contact information, such as 36 your phone number, social media handle, or email address (depending on 37 how you contact us), may be collected when you communicate with us, 38 for example to report a bug or other error related to Anastasis. We 39 don’t share your information with third parties except when strictly 40 required to deliver you our Services and products, or to comply with 41 the law. If you have any questions or concerns about this policy, 42 please reach out to us at <a class="reference external" href="mailto:privacy%40anastasis.lu">privacy<span>@</span>anastasis<span>.</span>lu</a>.</p> 43 </div> 44 <div class="section" id="how-you-accept-this-policy"> 45 <h2>How you accept this policy<a class="headerlink" href="#how-you-accept-this-policy" title="Permalink to this headline">¶</a></h2> 46 <p>By using our Services or visiting our sites, you agree to the use, disclosure, 47 and procedures outlined in this Privacy Policy.</p> 48 </div> 49 <div class="section" id="what-personal-information-do-we-collect-from-our-users"> 50 <h2>What personal information do we collect from our users?<a class="headerlink" href="#what-personal-information-do-we-collect-from-our-users" title="Permalink to this headline">¶</a></h2> 51 <p>The information we collect from you falls into two categories: (i) personally 52 identifiable information (i.e., data that could potentially identify you as an 53 individual) (“Personal Information”), and (ii) non-personally identifiable 54 information (i.e., information that cannot be used to identify who you are) 55 (“Non-Personal Information”). This Privacy Policy covers both categories and 56 will tell you how we might collect and use each type.</p> 57 <p>We do our best to not collect any Personal Information from Anastasis 58 users. The detailed Personal Information Anastasis asks from you during 59 the regular backup and recovery process at the beginning is never shared 60 with us and only used to create a cryptographic account identifier which 61 does not allow us to recover any of your details.</p> 62 <p>That being said, when using our Services to recover key material, we may 63 inherently receive the following information (depending on your choice of 64 authentication method):</p> 65 <blockquote> 66 <div><ul class="simple"> 67 <li><p>Bank account details necessary when receiving funds from you to authenticate via a SEPA transfer. We will store these as part of our business records for accounting, and our bank will also be legally obliged to store the details for many years.</p></li> 68 <li><p>Your phone number when using SMS authentication. We rely on third party providers (such as your mobile network operator) to deliver the SMS to you. These third parties will see the SMS message sent to you and could thus learn that you are using Anastasis. SMS is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your SMS number on our systems, except maybe in short-term logs to diagnose errors.</p></li> 69 <li><p>Your e-mail address when using E-mail authentication. We rely on the Internet and your E-mail provider to deliver the E-mail to you. Internet service providers will see the E-mail message sent to you and could thus learn that you are using Anastasis. E-mail is inherently insecure, and you should expect many governments and private parties to be able to observe these messages. However, we do not store your E-mail address on our systems, except maybe in short-term logs to diagnose errors.</p></li> 70 <li><p>Your physical address when using postal mail authentication. We rely on external providers for printing and sending the letter to you. These providers will need to learn your address and could learn that you are using Anastasis. Physical mail has strict privacy protections by law, but governments are known to break postal secrecy. We do not store your physical address on our systems, except maybe in short-term logs to diagnose errors.</p></li> 71 <li><p>When you contact us. We may collect certain information if you choose to contact us, for example to report a bug or other error with the Taler Wallet. This may include contact information such as your name, email address or phone number depending on the method you choose to contact us.</p></li> 72 </ul> 73 </div></blockquote> 74 </div> 75 <div class="section" id="how-we-collect-and-process-information"> 76 <h2>How we collect and process information<a class="headerlink" href="#how-we-collect-and-process-information" title="Permalink to this headline">¶</a></h2> 77 <p>We may process your information for the following reasons:</p> 78 <blockquote> 79 <div><ul class="simple"> 80 <li><p>to authenticate you during secret recovery</p></li> 81 <li><p>to support you using Anastasis when you contact us</p></li> 82 </ul> 83 </div></blockquote> 84 </div> 85 <div class="section" id="how-we-share-and-use-the-information-we-gather"> 86 <h2>How we share and use the information we gather<a class="headerlink" href="#how-we-share-and-use-the-information-we-gather" title="Permalink to this headline">¶</a></h2> 87 <p>We may share your authentication data with other providers that assist 88 us in performing the authentication. We will try to use providers that 89 to the best of our knowledge respect your privacy and have good 90 privacy practices. We reserve the right to change authentication 91 providers at any time to ensure availability of our services.</p> 92 <p>We primarily use the limited information we receive directly from you to 93 enhance Anastasis. Some ways we may use your Personal Information are 94 to: Contact you when necessary to respond to your comments, answer your 95 questions, or obtain additional information on issues related to bugs or 96 errors with the Anastasis application that you reported.</p> 97 </div> 98 <div class="section" id="agents-or-third-party-partners"> 99 <h2>Agents or third party partners<a class="headerlink" href="#agents-or-third-party-partners" title="Permalink to this headline">¶</a></h2> 100 <p>We may provide your Personal Information to our employees, contractors, 101 agents, service providers, and designees (“Agents”) to enable them to perform 102 certain services for us exclusively, including: improvement and maintenance of 103 our software and Services. By accepting this Privacy Policy, as outlined 104 above, you consent to any such transfer.</p> 105 </div> 106 <div class="section" id="protection-of-us-and-others"> 107 <h2>Protection of us and others<a class="headerlink" href="#protection-of-us-and-others" title="Permalink to this headline">¶</a></h2> 108 <p>We reserve the right to access, read, preserve, and disclose any information 109 that we reasonably believe is necessary to comply with the law or a court 110 order.</p> 111 </div> 112 <div class="section" id="what-personal-information-can-i-access-or-change"> 113 <h2>What personal information can I access or change?<a class="headerlink" href="#what-personal-information-can-i-access-or-change" title="Permalink to this headline">¶</a></h2> 114 <p>You can request access to the information we have collected from 115 you. You can do this by contacting us at <a class="reference external" href="mailto:privacy%40anastasis.lu">privacy<span>@</span>anastasis<span>.</span>lu</a>. We will 116 make sure to provide you with a copy of the data we process about 117 you. To comply with your request, we may ask you to verify your 118 identity. We will fulfill your request by sending your copy 119 electronically. For any subsequent access request, we may charge you 120 with an administrative fee. If you believe that the information we 121 have collected is incorrect, you are welcome to contact us so we can 122 update it and keep your data accurate. Any data that is no longer 123 needed for purposes specified in the “How We Use the Information We 124 Gather” section will be deleted after ninety (90) days.</p> 125 </div> 126 <div class="section" id="data-retention"> 127 <h2>Data retention<a class="headerlink" href="#data-retention" title="Permalink to this headline">¶</a></h2> 128 <p>Information entered into our bug tracker will be retained indefinitely 129 and is typically made public. We will only use it to triage the 130 problem. Beyond that, we do not retain personally identifiable 131 information about our users for longer than one week.</p> 132 </div> 133 <div class="section" id="data-security"> 134 <h2>Data security<a class="headerlink" href="#data-security" title="Permalink to this headline">¶</a></h2> 135 <p>We are committed to making sure your information is protected. We employ 136 several physical and electronic safeguards to keep your information safe, 137 including encrypted user passwords, two factor verification and authentication 138 on passwords where possible, and securing connections with industry standard 139 transport layer security. You are also welcome to contact us using GnuPG 140 encrypted e-mail. Even with all these precautions, we cannot fully guarantee 141 against the access, disclosure, alteration, or deletion of data through 142 events, including but not limited to hardware or software failure or 143 unauthorized use. Any information that you provide to us is done so entirely 144 at your own risk.</p> 145 </div> 146 <div class="section" id="changes-and-updates-to-privacy-policy"> 147 <h2>Changes and updates to privacy policy<a class="headerlink" href="#changes-and-updates-to-privacy-policy" title="Permalink to this headline">¶</a></h2> 148 <p>We reserve the right to update and revise this privacy policy at any time. We 149 occasionally review this Privacy Policy to make sure it complies with 150 applicable laws and conforms to changes in our business. We may need to update 151 this Privacy Policy, and we reserve the right to do so at any time. If we do 152 revise this Privacy Policy, we will update the “Effective Date” at the top 153 of this page so that you can tell if it has changed since your last visit. As 154 we generally do not collect contact information and also do not track your 155 visits, we will not be able to notify you directly. However, Anastasis clients 156 may inform you about a change in the privacy policy once they detect that the 157 policy has changed. Please review this Privacy Policy regularly to ensure that 158 you are aware of its terms. Any use of our Services after an amendment to our 159 Privacy Policy constitutes your acceptance to the revised or amended 160 agreement.</p> 161 </div> 162 <div class="section" id="international-users-and-visitors"> 163 <h2>International users and visitors<a class="headerlink" href="#international-users-and-visitors" title="Permalink to this headline">¶</a></h2> 164 <p>Our Services are (currently) hosted in Germany. If you are a user 165 accessing the Services from the Switzerland, Asia, US, or any other 166 region with laws or regulations governing personal data collection, 167 use, and disclosure that differ from the laws of Germany, please be 168 advised that through your continued use of the Services, which is 169 governed by the law of the country hosting the service, you are 170 transferring your Personal Information to Germany and you consent to 171 that transfer.</p> 172 </div> 173 <div class="section" id="questions"> 174 <h2>Questions<a class="headerlink" href="#questions" title="Permalink to this headline">¶</a></h2> 175 <p>Please contact us at <a class="reference external" href="mailto:privacy%40anastasis.lu">privacy<span>@</span>anastasis<span>.</span>lu</a> if you have questions about our 176 privacy practices that are not addressed in this Privacy Statement.</p> 177 </div> 178 </div> 179 180 181 <div class="clearer"></div> 182 </div> 183 </div> 184 </div> 185 <div class="clearer"></div> 186 </div> 187 </body> 188 </html>