Personvernpraksis for Passbolt - Open source password manager for teams
Passbolt - Open source password manager for teams av passbolt
This Privacy Policy constitutes a contract between:
Passbolt SA, a private company organised under the laws of the Duchy of Luxembourg with registered office in 9 Avenue des Hauts-Fourneaux, L-4362 Esch-Sur-Alzette, Luxembourg, hereinafter referred to as the “Company” or “Passbolt”
And you (hereinafter referred to as the "User");
Whereas the parties have agreed as follows:
1. Definitions
All terms given in this section of the Agreement shall have the following meaning for this Privacy Policy only, and shall not be construed to suggest otherwise:
(a)     Passbolt Solution: means the group of the copyrighted softwares which right to use, distribute and license is owned by Passbolt SA.
(b)     Passbolt Server: means the server component of the Passbolt Solution, consisting of a JSON API developped in PHP as available on the Github Passbolt account: https://www.github.com/passbolt/passbolt_api
(c)     Passbolt Browser Extension: (hereinafter referred to as the "Extension") means the browser web extension component of the Passbolt Solution as available on Mozilla Addons website or Chrome Marketplace website.
(d)    Service: the functionalities provided by the Passbolt Solution, including but not limited to login and logout, register, recover account, as well as create, update, delete and share passwords, groups, users, comments.
(e)    Service Provider: the person, organization or legal entity responsible for the hosting the Passbolt Server.
(f)    Personal Information: Any information that you provide about yourself while using the Passbolt Solution that could help someone else identify you as an individual entity. This may include information such as your name, location, IP address, system locale and preferences, picture, public key information, etc.
2. Data sent from the Extension
This extension is designed to work in collaboration with a Passbolt Server. You can select which Passbolt Server can receive data from the Extension by completing the setup for a given Passbolt Server. During the first step of the setup you will be explicitly adding the Passbolt Server url as a trusted domain.
This extension will send some of your personal information such as email address, first and last name, public OpenPGP keys and password related informations to the Passbolt Server only for the sole purpose of giving you access to the Service. When saving or updating passwords information, the password itself is sent in an encrypted OpenPGP message format.
The user passphrase or secret key is never sent to the Passbolt Server. The decrypted passwords are never sent to the Passbolt Server.
3. Cookies
The Extension stores cookies in order to provide a persistent authentication mechanism with the Passbolt Server. In short, it is required to know if you are logged in or not on a given Passbolt Server.
4. Persistent data stored in the Extension
This Extension stores a OpenPGP keyring, including the user secret key and other users public keys. The Extension also store the related user account information, such as the visual security code, your user id and username.This data is stored using the chrome.storage functionality of the Extension with remote synchronization disabled. 
The user passphrase is not stored in the persistent storage but may be stored in memory if you decide to use the “remember my passphrase” functionality. The decrypted passwords are not stored in the persistent storage but they may be stored in your clipboard if you decide to use this functionality.
5. Which websites can see if the Extension is installed
Any page on internet can learn about the presence of the plugin. This information is required to provide relevant help messages to assist the users with registration, account recovery, or otherwise prompt them to install the required Extension.
6. Service Provider Privacy Policy
When using the Extension with a given Passbolt Server you are bound to the privacy policy of the Service Provider. For example when using the extension with Passbolt SA demo Passbolt Server at https://demo.passbolt.com you agree to Passbolt SA privacy policy (https://www.passbolt.com/privacy) during the registration. As a User it is your responsibility to make sure the Passbolt Server you want to use provide a privacy policy.
7. Disclaimer of Warranty.
Passbolt is not liable to the User or Service Provider for any damages and/or losses (including an interruption of the business, loss of information, loss of profits, business reputation and other property damage) related to the use of Passbolt Solution.
THERE IS NO WARRANTY FOR THE PROGRAM, TO THE EXTENT PERMITTED BY
APPLICABLE LAW.  EXCEPT WHEN OTHERWISE STATED IN WRITING THE COPYRIGHT
HOLDERS AND/OR OTHER PARTIES PROVIDE THE PROGRAM "AS IS" WITHOUT WARRANTY OF ANY KIND, EITHER EXPRESSED OR IMPLIED, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE. THE ENTIRE RISK AS TO THE QUALITY AND PERFORMANCE OF THE PROGRAM IS WITH YOU.  SHOULD THE PROGRAM PROVE DEFECTIVE, YOU ASSUME THE COST OF ALL NECESSARY SERVICING, REPAIR OR CORRECTION.
8. Limitation of Liability.
Passbolt SA cannot be held responsible or liable for any 3rd Party Service Provider  complete or partial failure to perform any of its legal obligations including the absence of privacy policy, or any breach of such privacy policy resulting in the misuse of the User personal data. 
IN NO EVENT UNLESS REQUIRED BY APPLICABLE LAW OR AGREED TO IN WRITING
WILL ANY COPYRIGHT HOLDER, OR ANY OTHER PARTY WHO MODIFIES AND/OR CONVEYS THE PROGRAM AS PERMITTED ABOVE, BE LIABLE TO YOU FOR DAMAGES, INCLUDING ANY GENERAL, SPECIAL, INCIDENTAL OR CONSEQUENTIAL DAMAGES ARISING OUT OF THE USE OR INABILITY TO USE THE PROGRAM (INCLUDING BUT NOT LIMITED TO LOSS OF DATA OR DATA BEING RENDERED INACCURATE OR LOSSES SUSTAINED BY YOU OR THIRD PARTIES OR A FAILURE OF THE PROGRAM TO OPERATE WITH ANY OTHER PROGRAMS), EVEN IF SUCH HOLDER OR OTHER PARTY HAS BEEN ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.
9. Changes to This Privacy Policy
Passbolt SA may update our Privacy Policy from time to time, for example when releasing updates or new features. Thus, we advise you to review this page periodically for any changes. Passbolt SA will notify you of any changes by posting the new Privacy Policy on this page. These changes are effective immediately, after they are posted on this page.
10. Contact information
If you have any questions about this privacy policy please contact Passbolt SA at: contact@passbolt.com
