Palladin Export and Switching Specification

Polish version. The Polish version is legally binding.

Draft requiring review by qualified counsel before publication. Review must particularly cover the Data Act’s scope and workable migration and erasure. Section 1 describes existing code capabilities. Sections 2–6 set the standard adopted for launch and its requirements, rather than a completed full migration service. Full account export, the format register and erasure of all copies still require implementation or verification.

1. What can currently be exported

The web panel and mobile application support local Entry export to CSV or JSON for a selected scope, subject to permissions. Decryption occurs on the unlocked device. The file may contain plaintext passwords, API keys and other secrets stored in Entries. Save it securely and delete unnecessary copies; do not send it to support. The web panel also allows available Entry history to be included.

A separate audit-log export is not a full account export. The backend provides a 24-hour download window for it; individual signed links are short-lived. Download expiry does not confirm erasure of the stored file.

The previously described full account ZIP archive with a manifest, configuration, assets and billing is not yet available. A capability in code does not mean that every client has been publicly released. Requests for broader export, switching provider, porting to your own infrastructure or erasure without migration may be sent to patryk.roguszewski@palladin.io, identifying the account or Organization and scope, without secrets. Fulfilment requires identity and authority checks.

2. Scope of the standard and cooperation

  1. The standard in this and the following sections is intended to form part of the production-release agreement for paying and free customers. Statutory obligations apply according to the Data Act’s scope, rather than merely because a product is called SaaS. This project-status note does not exclude existing legal rights.
  2. Customers may choose to switch to another provider’s service of the same type, port data to their own infrastructure or erase without migration. For switching, the Customer provides the destination provider’s details and authorised contacts; for local porting, a secure delivery method.
  3. Palladin will provide reasonable assistance, information needed to exit and known limitations, and will maintain agreed functions, continuity and security during transition. The parties and authorised destination provider cooperate in good faith. Product differences may require adaptation by the recipient; this does not exclude statutory interoperability obligations.
  4. Export does not override other users’ permissions, confidentiality or third-party rights. Within an Organization, delivery depends on the Customer’s and requesting person’s authority. GDPR rights, including access and Article 20 portability, remain separate and do not depend on purchasing a Plan.

3. Timing, termination and fees

  1. The notice period before switching starts will not exceed two months. Transition will take place without undue delay, normally within a maximum of 30 calendar days after that period.
  2. If 30 days is technically unfeasible, Palladin will provide specific reasons and an alternative transitional period of no more than seven months within 14 working days of the request. The Customer may extend transition once for a period appropriate to its needs. Extension does not remove continuity and security duties.
  3. Following successful switching, the agreement covered by the migration ends and Palladin confirms this to the Customer. If erasure without migration is chosen, it ends upon expiry of the notice period. Rights to earlier termination under other law remain unaffected.
  4. After transition ends, the Customer has at least 30 calendar days to retrieve data. After that period or a later agreed date, provided switching succeeded, Palladin erases portable data and assets and their copies. Legally required further storage is limited to the data and duration required by law. Before launch, the erasure schedule and its execution must be verified for backups too; the earlier 90-day figure is not a verified state across the infrastructure. For B2B, the DPA coordinates details.
  5. Palladin will not charge switching fees. This is an adopted offer term even before the statutory prohibition of such fees from 12 January 2027. Ordinary, previously disclosed fees for periods of actual service remain payable; they must not disguise a migration fee. Refunds and consumer rights are covered by the Terms.

4. Full-export data and formats

The full process is to cover the following categories of data and assets where they are held for the Customer and are portable. This is an implementation scope, not a file list for an archive currently available.

Category Scope
Account and Organizations Profile, preferences, consent history, Organizations, memberships, invitations, roles and permissions.
Vaults and Entries Structure, Entries and available history, fields and relationships, metadata, ciphertext and plaintext decrypted only locally.
Reading materials Format descriptions, public keys, encrypted envelopes and parameters needed to read an encrypted copy. This does not include disclosure of Palladin’s secret authentication keys.
Agents and access Identifiers, configuration, public identities, assignments, requests, reasons, decisions, scopes, expiry times, limits and available usage history.
Audit and notifications Events, times, actors, targets and outcomes, non-secret metadata and notification preferences.
Customer assets Stored files, custom icons and other Customer digital assets where supported by the relevant feature.
Billing Plan, entitlement and transaction data held by Palladin once payments launch. Seller documents are also obtained from the seller identified at purchase.

Data should be provided in a commonly used, structured, machine-readable format; JSON and, where appropriate, CSV are planned for structured data, with original formats for files. Before launch, this page must provide a current register of structures, format versions, supported methods, standards and limitations, and migration-interface documentation. The complete register has not yet been published. Every export must clearly identify its scope, gaps and errors; an incomplete result must not be presented as a completed migration.

Pre-production Payment Card Entries may contain a card number, holder, expiry date and data entered in notes or custom fields. Local export can reveal them. The absence of dedicated CVV/CVC and PIN fields does not mean that arbitrary notes are detected or sanitised. Production support remains subject to legal review and a PCI scope assessment by a qualified PCI specialist/QSA.

5. Exclusions and technical limits

Export excludes Palladin infrastructure secrets, plaintext authentication keys for the Palladin API, password verifiers, raw session, refresh and push tokens, and confidential internal anti-fraud rules and risk assessments. It also excludes other customers’ data and information held only by independent sellers or providers. Exclusion of internal information must not impede or delay effective switching.

API keys and passwords saved by the User as Entry content are included in export. The exclusion of Palladin secrets above does not apply to these Entries. Palladin does not know the Master Password and cannot recreate lost decryption materials. Plaintext export requires the Customer’s access to the keys; migration assistance does not involve providing these keys to Palladin.

6. Infrastructure and contact

AWS has been selected as the infrastructure provider, but individual services’ regions, contracting entities and administrative access need verification. We do not claim that all data remains in one Irish region. The recipient list and Privacy Policy describe roles and personal-data transfers.

Before launch, information on this page must identify the jurisdictions of the infrastructure actually used and measures adopted against third-country governmental access contrary to EU law: technical safeguards, access controls, assessment of the request’s legal basis, scope limitation, remedies and appropriate contracts. This is an open requirement, not a claim that a complete Data Act Articles 28 and 32 procedure has been implemented. Client-side encryption protects content but does not eliminate access to all metadata.

Export and migration contact: patryk.roguszewski@palladin.io, phone +48 517 777 441.