Privacy Policy
Cybster Technologies, trading as SSLassist, respects your privacy. This policy explains how we manage personal information when you visit SSLassist, use our certificate tools, create an account, contact us or purchase or manage services.
Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply to us, we handle personal information in accordance with those requirements. We may also choose to follow the practices in this policy where a statutory exemption applies.
1. Information we collect
The information we collect depends on how you use SSLassist. It may include:
- Account information: your name, email address, organisation or account name, profile image, account role, password hash, two-factor authentication status and recovery-code hashes.
- Contact and support information: the details and content you provide when contacting us, together with related correspondence.
- Certificate and service information: domain names, certificate identifiers, order details, validation status, expiry dates, certificate files, certificate chains, CSRs and other information needed to provide certificate services.
- Payment information: transaction and billing information supplied by a payment provider. We do not intend to store complete payment-card numbers on SSLassist servers.
- Technical and security information: IP address, browser and device information, timestamps, session identifiers, audit events, authentication events, rate-limit information and diagnostic logs.
- Communication preferences: whether you have consented to optional marketing messages, when consent was recorded and unsubscribe or preference changes.
You may browse public information and use some tools without creating an account. We may still collect limited technical information needed to operate, secure and troubleshoot the service.
2. SSL tool inputs and private keys
Some SSLassist tools process certificate material supplied by you. Certificates and CSRs commonly contain public technical information. Private keys and passwords are highly sensitive and should only be submitted to a tool that expressly requires them.
- Private keys and private-key passwords are not intentionally stored in the SSLassist database or written to application logs.
- Where temporary files are required for an operation, they are kept outside the public web root and are intended to be removed promptly after the operation or short download period.
- Generated CSR and PFX downloads are held only for a short, configured session period and are not intended to be recoverable after expiry.
- Live SSL checks may be recorded for account history and security auditing, including the hostname and public diagnostic result.
- Do not submit material that you are not authorised to use, including another organisation’s private key.
No internet service can guarantee absolute security. You remain responsible for retaining secure backups of keys and certificates and for removing sensitive material from shared or untrusted devices.
3. How we collect and use information
We collect information directly from you, automatically from your browser or device, from certificate and network services you ask us to query, and from service providers involved in account, email, security, payment or certificate workflows.
We use information to:
- provide, operate and improve SSLassist and its tools;
- create and administer accounts, authenticate users and support two-factor authentication;
- perform certificate checks, generate requested files and manage certificate records;
- process enquiries, send transactional email and provide customer support;
- detect abuse, prevent fraud, investigate security events and enforce our Terms of Service;
- process certificate orders, validation, renewals, revocation and related provider interactions;
- meet legal, accounting, tax, recordkeeping and regulatory requirements; and
- send optional product news or offers where you have consented or where otherwise permitted by law.
We do not sell personal information. We do not use private keys or passwords for advertising, profiling or unrelated purposes.
4. Disclosure and overseas processing
We may disclose information where reasonably necessary to providers that support SSLassist, including:
- hosting, storage, database, security, content-delivery and monitoring providers;
- Cloudflare for bot protection, traffic security and related services;
- SMTP2GO for transactional and permitted marketing email delivery;
- Namecheap, certificate authorities and validation providers for certificate products and services;
- payment, accounting, professional advisory and customer-support providers; and
- government, regulatory, law-enforcement or legal parties where required or authorised by law, or where reasonably necessary to protect rights, security or safety.
Some providers operate globally. Personal information may be processed or stored outside Australia, likely including the United States, New Zealand and other countries in which our global infrastructure providers operate. The exact locations may change as providers alter their infrastructure. We take reasonable steps appropriate to the circumstances when using providers that handle personal information overseas.
We may also disclose information as part of a genuine business sale, restructure or transfer, subject to appropriate confidentiality and legal requirements.
5. Cookies, security and retention
SSLassist uses essential cookies and similar storage to maintain sessions, protect forms, remember authentication state and operate security features. Disabling essential cookies may prevent account and tool functions from working.
We use administrative, technical and physical safeguards that are reasonable for the nature of the information we hold. Measures may include access controls, password hashing, two-factor authentication, secure transport, audit logging, rate limiting, restricted storage locations and service-provider controls.
We retain information for as long as reasonably necessary for the purpose for which it was collected, to provide an active account or service, resolve disputes, investigate security events and satisfy legal, accounting or recordkeeping obligations. Retention periods vary by record type. When information is no longer required, we take reasonable steps to delete or de-identify it, subject to backups, legal holds and technical limitations.
If we become aware of a data breach, we will assess and respond to it in accordance with applicable law, including the Notifiable Data Breaches scheme where it applies.
6. Marketing communications
Optional marketing consent is not required to create an SSLassist account. Marketing messages will identify the sender and include a way to unsubscribe. We will process unsubscribe requests within the time required by the Spam Act 2003 (Cth). Transactional and security messages may still be sent where necessary to provide or protect your account or services.
7. Access, correction and complaints
You may ask to access personal information we hold about you or request correction of inaccurate, incomplete or out-of-date information. We may need to verify your identity before responding. In some circumstances, the law permits or requires us to refuse access; if so, we will explain the reason where permitted.
To make a privacy complaint, contact us with enough detail for us to investigate. We will acknowledge the complaint, review the relevant facts and respond within a reasonable period. If you are not satisfied and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner.
8. Children, automated decisions and changes
SSLassist is intended for business users and is not directed to children. Do not create an account for a child or submit a child’s personal information without appropriate authority.
SSLassist does not currently intend to use personal information to make solely automated decisions that significantly affect an individual’s rights or interests. If this changes, we will update this policy and provide information required by applicable law.
We may update this policy to reflect changes to our services, providers, practices or legal obligations. The current version and effective date will be published on this page. Material changes may also be communicated through the service or by email.
9. Contact us
Privacy questions, access or correction requests and complaints can be sent to:
Cybster Technologies trading as SSLassistEmail: [email protected]
Address: PO Box 713, ANNERLEY, QLD, 4103, Australia
ABN: 97060660264