Legal

Privacy Policy

Last updated: 25 February 2026

This Privacy Policy describes how Absolute IT ("we", "us", or "our") collects, uses, and protects information about you when you use Cloud Interceptor ("Service") at scanit2.cloud. By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

1.1 Account Information

When you register, we collect:

  • Full name and email address
  • Company/business name (optional)
  • Password (stored as a one-way bcrypt hash — never in plain text)
  • Two-factor authentication secret (if enabled, stored encrypted)

1.2 Billing Information

Payment details (card number, CVV, expiry) are collected and stored exclusively by our payment processor, Stripe. We only receive a Stripe customer ID and subscription status. We never store raw payment card data.

1.3 Configuration Data

To provide the Service, we store:

  • SFTP account usernames and hashed passwords
  • SSH public keys (if used for SFTP authentication)
  • OAuth tokens for connected cloud services (SharePoint, Dropbox, Google Drive), stored encrypted in AWS Secrets Manager
  • Routing rules and destination folder configurations you set up
  • Custom domain or subdomain settings

1.4 Usage and Audit Data

We automatically collect:

  • File transfer job records (filename, file size, transfer status, timestamps, destination path)
  • SFTP authentication events (success/failure, IP address, timestamp)
  • Monthly usage rollups (total files transferred, total bytes transferred per account)
  • API request logs for security and debugging purposes

We do not access, read, or store the contents of files transferred through the Service beyond the temporary storage required for processing and delivery.

1.5 Technical Data

When you use the website, we may collect browser type, operating system, referring URL, and IP address for security monitoring and service improvement.

2. How We Use Your Information

We use collected information to:

  • Provide and operate the Service — process file transfers, authenticate SFTP connections, route files to destinations.
  • Manage your account and subscription — billing, plan enforcement, seat limits.
  • Send transactional communications — email verification, password reset, billing receipts, and service notices.
  • Ensure security — detect fraud, unauthorised access attempts, and abuse.
  • Comply with legal obligations — respond to lawful requests from authorities.
  • Improve the Service — aggregate, anonymised analytics on usage patterns.

We do not sell, rent, or share your personal information with third parties for marketing purposes.

3. Third-Party Service Providers

We use the following third parties to operate the Service. Each is bound by their own privacy and security obligations:

ProviderPurposeData Shared
Amazon Web Services (AWS)Cloud infrastructure, file storage, database, and secrets managementAll service data (hosted in Sydney, Australia)
StripePayment processing and subscription managementName, email, payment details
Microsoft (SharePoint)File delivery destination (at your direction)Files you choose to route to SharePoint; your OAuth token
DropboxFile delivery destination (at your direction)Files you choose to route to Dropbox; your OAuth token
Google (Drive)File delivery destination (at your direction)Files you choose to route to Google Drive; your OAuth token

4. Data Storage and Security

All data is stored on AWS infrastructure in the ap-southeast-2 (Sydney, Australia) region. Security measures include:

  • AES-256 encryption at rest for all stored data and files
  • TLS 1.2+ encryption for all data in transit
  • Credentials and sensitive data stored in encrypted secrets vaults
  • Network isolation with private infrastructure and strict access controls
  • Least-privilege access policies for all service components

Despite these measures, no system is completely secure. We encourage you to use strong, unique passwords and enable two-factor authentication on your account.

5. Data Retention

We retain your data for the following periods:

  • Account data: Retained while your account is active and for up to 30 days after deletion to allow for account recovery.
  • Files in transit (S3 landing bucket): Automatically purged within 7–90 days depending on your plan tier.
  • Archived files (S3 archive bucket): Retained for the period defined by your plan, then purged or transitioned to Glacier for long-term storage.
  • Audit and usage logs: Retained for 12 months to support dispute resolution and compliance.
  • Billing records: Retained for 7 years as required by Australian tax law.

6. Cookies

We use the following cookies:

  • Session cookies (httpOnly): Used to maintain your login session. These are essential for the Service to function and cannot be disabled.
  • Preference cookies: Store UI preferences (e.g., theme) to improve your experience.

We do not use advertising or cross-site tracking cookies. You can configure your browser to refuse cookies, but this may affect the functionality of the Service.

7. Your Rights

Under Australian privacy law (Privacy Act 1988) and, where applicable, other privacy regulations, you have the right to:

  • Access the personal information we hold about you.
  • Correct inaccurate or incomplete personal information.
  • Delete your account and associated personal data (subject to legal retention requirements).
  • Export your configuration data and transfer job history.
  • Withdraw consent for optional data processing (e.g., usage analytics).

To exercise these rights, contact us at privacy@scanit2.cloud. We will respond within 30 days.

8. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

9. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.

10. Contact

For privacy-related questions, requests, or complaints, please contact our Privacy Officer:

Privacy Officer — Absolute IT

Email: privacy@scanit2.cloud

Website: scanit2.cloud

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).