Data and Privacy Policy

This privacy policy describes our commitment to preserving the security of your Personal Data, your privacy, and your rights to your Personal Data. It is written in plain language because we want to communicate this to you. It therefore lacks some of the precision that a document drafted by and for legal professionals would have, but it still represents our good faith effort at describing what we and you agree to when you entrust us with your data.

Principles


At iCredential, we believe that the less information we know about you, the better. After all, it is impossible to lose, misuse, or abuse information we don’t have. To the extent that we have control over your data or data about you, we see ourselves as custodians of that data on your behalf.


We use your data solely to provide you with services in which you enrolled. Our business is providing iCredential products and services to you, the customer. We have no desire or interest to use or transfer the limited data we acquire for any other purposes.


Who are You


Unless otherwise noted, we refer you, the Customer, as an owner or organizer of an individual, family, team, or business account.


Non-Owners

If you are a non-owner member of a team, business, or family account, your use of 1Password may be subject to your organization’s privacy policy or practices, if any. Non-owner members of an account transfer some of the rights described here to the account owners.


Information We Keep and How We Use It


We retain two kinds of user information to deliver our services: Secure Data and Service Data. Both are treated securely with respect for customer privacy and data confidentiality, but there are important technical and usage differences.


Service Data


We inevitably acquire Service Data about your usage of iCredential, your account, and your payments through operating our services. We retain only enough Service Data to operate and maintain the services. This data is never used for any other purpose.


Service Data is kept confidential. It is visible to our staff and includes, but is not limited to, server logs, billing information, client IP addresses, number of vaults and number of items in vaults, company or family name, and email addresses. Service data includes the name you provide us for your profile and any image that you may upload as part of your profile.


We retain the right to hold and use Service Data to provide our services, troubleshoot problems, analyze the performance and demands on our services, and to provide our payment processors with the information they need to process payments.


Keeping Your Information Safe


We understand and accept our responsibility to protect Service Data and Secure Data. We use strict access control mechanisms, network isolation, and encryption to ensure that Secure and Service Data is only available to authorized personnel. Additionally, Secure Data cannot be decrypted even by those who do have access to it.


Data Processing Agreement

  • Your data is held on servers located within Australia.
  • Service Data is only available to members of our staff in Australia. We don't send your data anywhere else.


Customer support system


Our customer support and email services are hosted primarily in the United States. Any information you choose send us through email or our customer support system may pass through and be stored on a variety of intermediate services. If you wish, you may encrypt email to us using our PGP public key.


Your Responsibilities for Protecting Your Data


When you create a 1Password account you will receive an Secret Key and create a Master Password. Your Secret Key is generated on your computer and your Master Password is something you create yourself. For your protection, you should create a strong and unique Master Password to ensure that it is not easily guessed.


It is extremely important that you understand that anyone with both your Secret Key and Master Password can access your Secure Data. It is equally important that you keep a copy in a safe place for your own reference, because future access to your Secure Data depends on having access to both your Secret Key and your Master Password. We will never ask you for your Master Password or your full Secret Key, and you should never send either to us.


Due to the nature of our design and the sensitivity of the information you entrust to us (even in encrypted form), it may not be possible for us to help you with certain customer service requests unless you are listed as an account owner and are communicating from your verified email address. In the event that you change your email address, is very important that you update your email on your 1Password account(s) or you may eventually lose access.


Data Portability


We want happy customers, not trapped ones. We will not lock you out of your own data. However, we are unable to decrypt your Secure Data; you will need your Master Password and Secret Key to decrypt it.

You may export your 1Password data at any time you wish during the life of your account. If you discontinue payment, your account will enter a frozen (read-only) state for a period not less than six months during which you may still retrieve and export your data.


Export is limited to your Secure Data. Vault permissions, the structure of groups of individuals, and other information about the relationship between individuals and data is not guaranteed to be included in export.


Your Right to Knowing to What We Know


You have the right to know what we know about you and to see how that data is handled. You may request a screenshot of what we can see about you in our back office systems. However, to protect customer privacy, such requests must be carefully authenticated beyond demonstrating control of the customer’s email address.


Your Right to Have Your Data Erased


As we are merely custodians of your data, account owners have the right to instruct us to remove data permanently from our systems. To ensure that no one’s data is deleted without their consent, you must first delete your account through an authenticated session. After your account has been deleted, the account owner may contact us and ask for the data to be expunged. Once the request is authenticated, the data will be removed from our active systems within 72 hours.


Disaster recovery and data availability requirements mean that AgileBits has a legitimate interest in maintaining secure and immutable backups. Erasure requests will leave those backups untouched, and we will only remove data from backups if legally compelled to.


Cookies and Tracking


We do not engage in or support cross-service tracking.


We do set and use cookies (small text files placed on your device) on our own domains and subdomains to store settings that assist with identifying your account for sign-in. We also use third party analytics packages for our public pages that may set cookies on your computer. These are limited to our domains, and do not involve cross-service tracking. You may disable cookies in your browser and continue to use our services without impact.


Client applications, including web browsers, will store information about your account to assist with future sign-ins and keep some information available to you when you are not signed in. Users may remove all such information from their devices, but doing so will require that they provide complete information (account details, Master Password, and Secret Key) on subsequent sign-ins.


Consent for Underage Enrollment


Those under the age of 16 may not use the services without the consent or authorization of their parent or legal custodian. Family account organizers and team owners are responsible for that authorization when they add someone under the age of 16 to an account.


Disclosure


We will comply with applicable law with respect to providing Service Data and encrypted Secure Data to law enforcement agencies. If permitted, we will notify you of such a request and whether or not we have complied. Your Secure Data remains encrypted with keys which we do not posses, and so we can only hand over Secure Data in encrypted form.


Some Service Data is made available to family account organizers and team owners. In some limited circumstances we may provide some information to non-owner members of these accounts. Account owners will be informed in these circumstances.


Breach Notification


If the confidentiality of customer data is breached, we recognize our responsibility to our customers and to the public to disclose the nature of the risk and provide a transparent account of the events without undue delay. At a bare minimum, we must inform the applicable supervisory authorities as required by law and regulation.


Updates to our Privacy Policy


At our discretion, we may make changes to this Policy and note the date of the last revision. You should check here frequently if you need to know of updates to our Privacy Policy. We maintain the right to send you annoying email informing you of substantive changes. Previous versions will be made available from this page.


Contact Us


If you have any questions about this Policy, you can contact our support team

by mail at: info@mfsoftwaredev.com.au