Monitored company
OpenVPN
clause.watch tracks 2 legal documents published by OpenVPN (openvpn.net), re-reading each one every six hours. Below is what each document covers, in plain English.
Legal
OpenVPN Terms: Key User Overview
*Effective April 12, 2024. This summary is based on the text provided and is not a substitute for reviewing the linked Privacy Policy, Product Agreements, EULAs, and Data Processing Agreements (DPAs). Those documents may override these Terms for particular products.*
1. Data Collection and Usage
Information identified in the Terms
For accounts, OpenVPN may require:
- Name or entity name
- Mailing and email address
- Telephone contact information
- Valid payment information
- Additional information requested during registration
OpenVPN or payment vendors may store your payment method and continue charging it for amounts owed. OpenVPN may also participate in card-provider programs that update expired payment details.
If you use the services, additional customer or user data may be processed depending on the product. The DPA refers broadly to “Customer Data,” meaning personal data processed through the service on the customer’s behalf. The Terms also expressly mention possible usage information such as:
- Profile and email address
- Usage history
- IP addresses
- Traffic information
- Posted materials
The full categories, purposes, retention periods, and technologies used for collection are deferred to the Privacy Policy, which was not included in the provided text.
For business customers, OpenVPN generally acts as a processor/service provider processing Customer Data according to the customer’s documented instructions and to provide the service. Customers remain responsible for the accuracy, legality, notices, and consents associated with that data.
2. User Rights
The Terms state that users may manage certain information preferences concerning OpenVPN’s use and storage of personal information by contacting an OpenVPN support representative.
The DPA supports data deletion or removal requests where legally valid and requires OpenVPN, on termination, to delete or return Customer Data at the customer’s choice, subject to legal-retention and backup exceptions.
Applicable laws may provide additional rights, including access, correction, deletion, objection, restriction, portability, or rights concerning certain automated processing. The exact procedure and eligibility depend on the Privacy Policy and applicable law, including GDPR, UK/Swiss law, CCPA, PIPEDA, LGPD, and Australian privacy law.
3. Third-Party Sharing
OpenVPN may share or disclose data:
- With payment processors and authorized vendors
- With affiliated companies and Sub-Processors assisting with service delivery
- With third-party merchants whose products appear on the sites
- When required by law or legal process
- With law enforcement, regulators, or other third parties when investigating suspected unlawful activity
For reported violations, OpenVPN reserves broad authority to disclose profile information, email addresses, usage history, posted materials, IP addresses, and traffic information. Users expressly waive objections to such disclosures in those circumstances.
OpenVPN must impose data-protection obligations on Sub-Processors and remains responsible for their compliance under the DPA. Customers can opt in to Sub-Processor change notices. European customers may object to a new Sub-Processor on reasonable data-protection grounds, although OpenVPN may ultimately permit termination or suspension of the affected service.
4. AI/ML Training
The Terms and DPA provided do not expressly state whether personal data, Customer Data, usage data, or submitted content is used to train artificial-intelligence or machine-learning models.
The Terms do state that non-confidential information submitted through the sites—such as suggestions, ideas, designs, and product feedback—may be used without limitation or compensation. This could be relevant to internal development, but it is not an explicit AI-training authorization. Review the Privacy Policy and product-specific agreements or obtain written confirmation before submitting sensitive information.
5. Key User Obligations
Users must:
- Provide accurate and complete account and payment information
- Prevent unauthorized account access
- Avoid sharing one account name among multiple users where prohibited
- Comply with applicable laws and obtain necessary consents for Customer Data
- Avoid uploading prohibited Sensitive Data unless the applicable agreement permits it
- Secure credentials, data in transit, backups, and encryption
- Respect OpenVPN copyrights, GPL requirements, and trademark restrictions
- Avoid illegal, pornographic, infringing, misleading, defamatory, or unauthorized uses
Violations may lead to immediate account termination, investigation, reporting, and indemnification obligations.
6. Liability and Disputes
For the websites and Content, OpenVPN provides services “as is” and disclaims warranties such as fitness, accuracy, non-infringement, uninterrupted operation, and virus-free operation.
Liability for claims concerning the sites or Content is capped at $500, with broad exclusions for indirect, consequential, special, lost-profit, punitive, and exemplary damages. Product and service agreements control liability for the actual products and services and may contain different limits.
Most disputes must be resolved by binding JAMS arbitration, remotely by video, under the Federal Arbitration Act. Users waive jury trials and class or representative actions. Claims generally must be brought within one year after arising. Courts may still be used for temporary emergency injunctive relief.
7. Changes
OpenVPN may change the Terms at its discretion by revising the date and, in some cases, providing additional notice. Changes generally take effect immediately, and continued use constitutes acceptance. Additional notice is required for changes imposing new fees. Product-specific agreements are not changed unless amended according to their own procedures.
Privacy Policy
Privacy Policy Overview
1. Data Collection and Use
The policy says OpenVPN may collect:
- Contact and account data: name, email address, and phone number. An email address is the minimum required for registration.
- Payment data: credit-card information and other payment details when ordering. OpenVPN says card data is generally handled by third-party payment processors rather than stored directly by OpenVPN.
- Business and invoicing information: information voluntarily provided for billing or customer-service purposes.
- Technical information: source IP address, browser/user-agent information, and destination URLs.
- Cookie data: cookies are used, with cookie categories and controls available through the consent-management platform.
The information may be used to:
- Operate and improve the website and services;
- Provide customer support;
- Process orders and payments;
- Respond to inquiries;
- Send order-related emails and, potentially, marketing communications;
- Conduct marketing, advertising, and promotional activities.
Important limitation: The policy does not provide a clear data-retention schedule. It also does not clearly explain the legal bases for processing personal data, except that it refers generally to consent and other lawful bases under GDPR.
2. User Rights and Controls
Users may contact OpenVPN to:
- Access or obtain a copy of their account information;
- Correct or update information;
- Request deletion or account deactivation;
- Object to processing;
- Request restriction of processing;
- Request data portability;
- Withdraw consent where processing is based on consent;
- Opt out of marketing emails using unsubscribe links;
- Opt out of certain third-party marketing “sales” or “sharing” through website Privacy Settings.
EEA, UK, and Swiss residents may also complain to a data-protection authority. The policy states that OpenVPN will respond to rights requests as required by applicable law.
Practical issue: Several contact-email fields in the supplied policy are blank. This may make exercising rights more difficult unless the user locates a current support or privacy contact elsewhere on the website.
3. Third-Party Sharing
OpenVPN says it does not sell or trade personal information in the ordinary sense, but it may disclose personal information to:
- Payment processors;
- Resellers;
- Hosting, website, business, and customer-service providers;
- Other service providers assisting with orders and operations;
- Parties helping respond to prior product inquiries;
- Third parties for marketing its products and services.
These disclosures may qualify as a “sale” or “share” under applicable privacy laws. Users may opt out of marketing-related sharing.
Information may also be disclosed when OpenVPN believes this is necessary to:
- Comply with law;
- Enforce policies;
- Protect rights, property, or safety.
Non-personally identifiable information may be provided for marketing or advertising.
4. AI/ML Training
The policy does not say whether personal information, account data, support communications, or other user content is used to train artificial-intelligence or machine-learning models. Users should not assume that data is excluded from AI training. A separate terms document, data-processing agreement, or written company response may be needed for clarification.
5. Key User Obligations and Risks
- By using the website, users are stated to consent to the Privacy Policy.
- The website and services are directed to people 13 or older; the policy says information is not collected from children under 13.
- Users should provide accurate information and manage cookie and marketing preferences if they do not want optional tracking or marketing.
- Business customers agree that OpenVPN may identify them as customers and use their name and logo in client lists, sales presentations, marketing materials, and press releases.
- OpenVPN may develop a customer profile for promotional use on its websites. This is a significant marketing permission and is not expressly presented as requiring separate approval.
6. Liability and Disputes
The Privacy Policy itself contains few liability or dispute rules. It directs users to the separate Terms and Conditions, which allegedly contain disclaimers and liability limitations. Consequently, important issues—such as governing law, arbitration, venue, damages caps, and responsibility for security incidents—cannot be determined from this policy alone.
OpenVPN describes security measures including SSL transmission, encrypted payment-gateway storage, access controls, and confidentiality obligations. However, these measures are not a guarantee that data breaches or unauthorized access cannot occur.
7. Policy Changes
OpenVPN says it will post changes on the same Privacy Policy webpage. It does not promise individual notice by email, specify how much advance notice will be provided, or explain whether continued website use constitutes acceptance of material changes. Users should periodically review the policy, particularly before continuing to use the services.
Change history
2026-08-18 · Legal
Summary
The provided diff does not include the actual amended contract language. It only states:
> “Added approximately 71 words to the document”
Accordingly, it is not possible to identify the legal or commercial effect of the changes.
AI Training and Data Use
- No text is provided addressing whether customer data may be:
- Used to train, fine-tune, or improve AI models;
- Shared with model providers or other third parties;
- Used in aggregated, anonymized, or de-identified form;
- Retained for model-training or product-improvement purposes; or
- Excluded from training by default or only upon customer request.
- The available diff therefore does not establish whether the contract has changed the customer’s rights or the provider’s permissions regarding AI training.
Other Potential Changes
Because the added 71 words are not shown, the following issues cannot be assessed:
- Data ownership and licensing rights;
- Confidentiality obligations;
- Privacy and security responsibilities;
- Data retention and deletion;
- Intellectual-property ownership;
- Liability, indemnification, or warranty exposure;
- Subcontractor or third-party access; and
- Termination or post-termination data handling.
Conclusion
The actual inserted language is required for a meaningful legal review. The stated word-count change alone does not reveal any new obligations, permissions, restrictions, or risks.
Between 2025-02-02 and 2025-07-11 · Legal
Between 2023-11-23 and 2024-08-24 · Legal
Between 2022-12-08 and 2024-04-22 · Privacy Policy
Executive Summary
The diff primarily updates contact information, opt-out procedures, and privacy-rights language. It does not expressly add, remove, or modify any provision allowing customer data to be used to train artificial-intelligence (AI) models. No AI training, machine learning, model improvement, or related data-use language appears in the revised text.
Important Changes
1. New opt-out method for third-party sharing
The policy now states that individuals may opt out of sharing personal information with third parties by emailing privacy@openvpn.net with “OPT OUT.” It also permits requests through another unspecified method.
Risks and implications:
- The policy acknowledges that personal-information disclosures may constitute a “sale” or “share” under applicable privacy laws.
- The opt-out process may be incomplete because the alternative request method is not clearly described.
- The policy does not clearly explain whether opting out affects service functionality or whether it applies to all categories of sharing.
2. Expanded or clarified disclosure language
The policy continues to permit disclosure of personal information to third parties assisting with OpenVPN’s business and services, including for marketing, advertising, or other uses. The revised text expressly labels some disclosures as a “sale” or “share.”
Risk: The phrase “other uses” is broad and may allow disclosures beyond what customers reasonably expect. The policy should identify the categories of recipients, purposes, and types of information involved.
3. Updated privacy-rights contact information
Multiple rights-related provisions now direct customers to privacy@openvpn.net for:
- Access, correction, updating, or deletion requests
- GDPR deletion requests
- Objections to processing
- Marketing opt-outs
- Other consent-related requests
This creates a clearer central contact point, but the text should specify identity-verification requirements, response deadlines, appeal procedures, and any applicable fees or exceptions.
4. Security and payment-processing clarifications
The policy states that:
- Credit-card information is not stored by OpenVPN but may be stored by a third-party payment processor.
- Access to business and log information is controlled and limited to authorized personnel.
- Sensitive information is transmitted through a secure server.
Risk: These statements describe safeguards but do not guarantee security. The reference to third-party processors should ideally identify their role and explain that their independent privacy terms may apply.
5. International data transfers
The revised text confirms that OpenVPN uses Standard Contractual Clauses for transfers of data from certain jurisdictions. This is useful but does not explain supplementary safeguards, transfer destinations, or how customers may obtain a copy of the applicable clauses.
AI-Training Assessment
No provision in the diff expressly authorizes OpenVPN, its service providers, or other third parties to use customer data to train or improve AI models. The broad references to improving websites/services and using information for “other uses” could potentially be argued to cover analytics or product improvement, but they do not clearly authorize AI training. A separate, explicit AI-data-use clause would be needed to establish that right clearly.
Between 2022-11-08 and 2023-11-23 · Legal
Between 2021-07-31 and 2022-12-08 · Privacy Policy
Important Changes and Risks
1. No express AI-training provision identified
The diff does not add or remove language expressly addressing:
- Training, fine-tuning, or improving artificial-intelligence or machine-learning models;
- Use of customer data or prompts to develop AI systems;
- Human review or automated analysis of customer content;
- Whether customer data is de-identified before model training; or
- An opt-out from AI training.
Although the policy says information may be used to “improve our website” and may be disclosed for marketing, advertising, or other uses, those provisions do not clearly authorize AI-model training. They could nevertheless be drafted broadly enough to create ambiguity about whether analytics or other automated processing is permitted.
2. “Sale” and “share” terminology added or clarified
The policy now states that certain disclosures may constitute a “sale” or “share” under applicable laws. This appears intended to address U.S. privacy laws, particularly laws that distinguish between selling personal information and sharing it for targeted advertising.
Risks and implications:
- The policy acknowledges potentially regulated disclosures to third parties.
- Customers are told they may opt out, but the excerpt does not clearly explain the mechanism, scope, or consequences of opting out.
- The policy should identify the categories of information, recipients, purposes, and jurisdictions involved.
- The use of “applicable laws” without specifying the relevant rights may be too vague for some privacy regimes.
3. Customer-reference language appears to be added
The revised text introduces a heading or provision beginning:
> “Customer Reference You agree (i) that OpenVPN may identify you as a recipient of…”
The excerpt ends before the provision is complete, so its full effect cannot be determined. If the remaining language permits use of the customer’s name, logo, testimonial, or status as a customer, it may create a new marketing/publicity right for OpenVPN.
Key risks:
- No clear requirement for separate consent may be stated.
- The scope, duration, media, geographic reach, and revocation rights are unclear.
- The provision may conflict with confidentiality obligations or enterprise procurement requirements.
4. Data-security and payment clarifications
The policy confirms that:
- Access to systems and log information is restricted to authorized personnel.
- Credit-card data is not stored by OpenVPN but may be stored by a third-party payment processor.
These statements provide useful detail but may create expectations regarding access controls and third-party processor responsibility. The wording “system are accredited” appears grammatically defective and should be corrected.
5. Formatting and drafting changes
Numerous changes merely add missing spaces or punctuation and do not appear substantively material. However, the revised policy should be checked for broken headings, incomplete sentences, and consistent formatting—especially around the customer-reference provision and privacy-rights sections.
Between 2020-01-26 and 2021-07-31 · Privacy Policy
Summary of Important Changes
1. New privacy contact email and opt-out process
- The privacy contact email privacy@openvpn.net is added in several places.
- Customers may opt out of sharing personal information with third parties by emailing that address and writing “OPT OUT.”
- The same email is provided for requests to:
- Access, correct, update, or delete personal information;
- Deactivate and delete an account under the GDPR;
- Object to processing;
- Opt out of marketing communications; and
- Exercise other applicable data-protection rights.
Risk/impact: The policy now provides a clearer mechanism for exercising privacy rights and opting out of certain sharing. However, it does not specify how requests will be verified, the response deadlines, or whether the opt-out applies to all forms of disclosure.
2. Disclosure described as a potential “sale” or “share”
- The policy now expressly states that disclosures of personal information to third parties may constitute a “sale” or “share” under applicable laws.
- It also adds an opt-out reference for such disclosures.
Risk/impact: This acknowledges obligations under laws such as the California Consumer Privacy Act. The wording is broad and does not clearly identify which third parties, data categories, or purposes are covered. Customers may therefore have difficulty determining what data sharing they are opting out of.
3. New “Customer Reference” language
- A new section appears to state: “You agree (i) that OpenVPN may identify you as a recipient of…”
- The provision is incomplete in the supplied diff.
Risk/impact: If finalized, this could give OpenVPN permission to identify the customer publicly as a customer or recipient of its services, potentially including use of the customer’s name, logo, or other identifying information. The missing text makes the scope and any opt-out rights unclear. This should be reviewed in the complete policy or agreement.
4. GDPR and international-transfer provisions
- Privacy-rights contact details are consolidated around the new email address.
- The policy states that OpenVPN uses Standard Contractual Clauses for certain international data transfers.
Risk/impact: This provides a stated transfer mechanism but does not, in the excerpt, identify the relevant recipients, transfer locations, safeguards, or supplemental measures.
5. AI-model training
- No provision in the supplied diff expressly authorizes, prohibits, or otherwise changes the use of customer data to train AI models.
- The changes do not add language concerning artificial intelligence, machine learning, model training, model improvement, prompts, outputs, or use of customer content for those purposes.
6. Editorial/formatting changes
- Several changes remove spacing or punctuation around headings and sentences, such as “form.When” and “information.Our.”
- These appear editorial rather than substantive, but the final document should be proofread because the formatting could make provisions harder to interpret.
Between 2018-11-04 and 2019-12-10 · Privacy Policy
Summary of Important Changes
1. AI-model training and use of customer data
- No express provision was added or removed concerning the use of customer data to train, fine-tune, evaluate, or improve AI models.
- The policy continues to state generally that information may be used to:
- Improve the website and services;
- Respond to customer-service requests;
- Process transactions; and
- Send transaction-related emails.
- These general “improvement” purposes should not automatically be interpreted as authorization to train AI models, particularly where personal, sensitive, or customer-content data is involved. However, the language is broad enough that it could create uncertainty if OpenVPN later uses customer information in machine-learning systems.
- Customers seeking certainty should request an explicit statement addressing whether their data, communications, account information, or usage data may be used for AI training, whether data is de-identified, and whether an opt-out is available.
2. “Sale” and “share” disclosures under privacy laws
- The policy now states that disclosures to third parties for marketing, advertising, or other purposes may constitute a “sale” or “share” under applicable laws.
- This is legally significant because it acknowledges potential coverage under privacy laws such as the California Consumer Privacy Act.
- The policy also provides an opt-out mechanism, including contacting privacy@openvpn.net and writing “OPT OUT.”
- Risk: The language does not clearly identify:
- Which categories of data are sold or shared;
- Which third parties receive the data;
- Whether targeted advertising is involved; or
- How the opt-out request affects existing disclosures.
3. New or clarified customer-reference language
- A new section begins: “You agree (i) that OpenVPN may identify you as a recipient of…”
- The sentence appears incomplete in the supplied diff. If the full provision permits OpenVPN to identify the customer as a user, customer, or recipient of services, it may create a marketing, publicity, or trademark-use risk.
- The final language should be reviewed to determine whether customer names, logos, testimonials, or affiliation may be publicly used and whether consent can be withdrawn.
4. International data transfers
- The policy now references OpenVPN’s use of Standard Contractual Clauses for transfers of data from the European Economic Area.
- This provides a stated transfer mechanism but does not, by itself, explain supplementary safeguards, transfer-risk assessments, or the identity of recipients.
5. Security and payment information
- The policy clarifies that:
- Log information is access-controlled;
- Credit-card data is not stored by OpenVPN but may be stored by an accredited payment processor; and
- Business information is access-controlled.
- These are generally clarifications rather than major expansions of rights or obligations.
Overall assessment
Most edits are formatting, punctuation, or readability corrections. The most important substantive additions concern “sale”/“share” disclosures, opt-out rights, a potentially broad customer-reference clause, and international transfers. No specific AI-training authorization appears in the diff.