[business name not configured] is the responsible party for personal information processed through ScepNet, as that term is used in the Protection of Personal Information Act, 2013 (POPIA). Contact us at [contact address not configured].
Account information. Your email address, a one-way hash of your password (never the password itself), your organization name, and — if you enable two-factor authentication — an encrypted authenticator secret.
Security records. Every sign-in, failed sign-in, password change, certificate issuance and revocation, and administrative action is recorded with the time, the account involved, your IP address and your browser's user-agent string. This log is append-only and hash-chained: entries cannot be altered or deleted, by us or by anyone else, without the chain visibly breaking.
Certificate data. The subject and subject alternative names of every certificate issued to you. In practice these identify devices — serial numbers, hostnames — and, for user certificates, may identify people by name or principal name. You choose what goes in them.
Payment records. What you bought, when, how much, and the reference our payment processor returns. We never see or store your card details.
We do not use analytics, advertising or tracking cookies. The only cookie we set is your session cookie. It is HTTP-only, restricted to this site, and expires after two hours. Cloudflare's anti-automation check sets its own cookie on the registration page.
We use these operators. They process data only to provide their service to us.
We do not sell personal information, and we do not share it for anyone else's marketing.
Under POPIA you may ask what we hold about you, ask us to correct it, object to processing, and complain to the Information Regulator.
You can ask us to delete your account by writing to [contact address not configured].
One limit worth stating plainly: we cannot delete entries from the audit log. It is append-only and hash-chained by design, and removing an entry would break the chain and destroy the integrity of the whole record. Those entries contain your email address, IP address and the actions taken. They age out on the retention schedule above.
The service and its database run on servers in France, within the European Union. If you are in South Africa, this means your information is transferred outside the country — permitted under section 72 of POPIA, because the receiving jurisdiction provides an equivalent level of protection.
Our operators may process data elsewhere; where they do, they are bound by their own contractual protections.
Passwords are hashed with bcrypt. Certificate authority private keys and two-factor secrets are encrypted at rest with a key held in the operating system's credential store rather than in the database or the application's configuration. Backups are encrypted with a key the server does not hold, so a compromise of the server does not expose its backup history. Access to anything that changes what your devices trust requires a second factor. The trust page sets this out in more detail, including what we cannot protect you against.
If a breach affects your personal information we will notify you and the Information Regulator as POPIA requires.
If we change this policy materially we will email the address on your account before the change takes effect.
[contact address not configured]