Legal
Privacy Policy
Last updated: 25 February 2026
This Privacy Policy describes how Absolute IT ("we", "us", or "our") collects, uses, and protects information about you when you use Cloud Interceptor ("Service") at scanit2.cloud. By using the Service, you agree to the collection and use of information in accordance with this policy.
1. Information We Collect
1.1 Account Information
When you register, we collect:
- Full name and email address
- Company/business name (optional)
- Password (stored as a one-way bcrypt hash — never in plain text)
- Two-factor authentication secret (if enabled, stored encrypted)
1.2 Billing Information
Payment details (card number, CVV, expiry) are collected and stored exclusively by our payment processor, Stripe. We only receive a Stripe customer ID and subscription status. We never store raw payment card data.
1.3 Configuration Data
To provide the Service, we store:
- SFTP account usernames and hashed passwords
- SSH public keys (if used for SFTP authentication)
- OAuth tokens for connected cloud services (SharePoint, Dropbox, Google Drive), stored encrypted in AWS Secrets Manager
- Routing rules and destination folder configurations you set up
- Custom domain or subdomain settings
1.4 Usage and Audit Data
We automatically collect:
- File transfer job records (filename, file size, transfer status, timestamps, destination path)
- SFTP authentication events (success/failure, IP address, timestamp)
- Monthly usage rollups (total files transferred, total bytes transferred per account)
- API request logs for security and debugging purposes
We do not access, read, or store the contents of files transferred through the Service beyond the temporary storage required for processing and delivery.
1.5 Technical Data
When you use the website, we may collect browser type, operating system, referring URL, and IP address for security monitoring and service improvement.
2. How We Use Your Information
We use collected information to:
- Provide and operate the Service — process file transfers, authenticate SFTP connections, route files to destinations.
- Manage your account and subscription — billing, plan enforcement, seat limits.
- Send transactional communications — email verification, password reset, billing receipts, and service notices.
- Ensure security — detect fraud, unauthorised access attempts, and abuse.
- Comply with legal obligations — respond to lawful requests from authorities.
- Improve the Service — aggregate, anonymised analytics on usage patterns.
We do not sell, rent, or share your personal information with third parties for marketing purposes.
3. Third-Party Service Providers
We use the following third parties to operate the Service. Each is bound by their own privacy and security obligations:
| Provider | Purpose | Data Shared |
|---|---|---|
| Amazon Web Services (AWS) | Cloud infrastructure, file storage, database, and secrets management | All service data (hosted in Sydney, Australia) |
| Stripe | Payment processing and subscription management | Name, email, payment details |
| Microsoft (SharePoint) | File delivery destination (at your direction) | Files you choose to route to SharePoint; your OAuth token |
| Dropbox | File delivery destination (at your direction) | Files you choose to route to Dropbox; your OAuth token |
| Google (Drive) | File delivery destination (at your direction) | Files you choose to route to Google Drive; your OAuth token |
4. Data Storage and Security
All data is stored on AWS infrastructure in the ap-southeast-2 (Sydney, Australia) region. Security measures include:
- AES-256 encryption at rest for all stored data and files
- TLS 1.2+ encryption for all data in transit
- Credentials and sensitive data stored in encrypted secrets vaults
- Network isolation with private infrastructure and strict access controls
- Least-privilege access policies for all service components
Despite these measures, no system is completely secure. We encourage you to use strong, unique passwords and enable two-factor authentication on your account.
5. Data Retention
We retain your data for the following periods:
- Account data: Retained while your account is active and for up to 30 days after deletion to allow for account recovery.
- Files in transit (S3 landing bucket): Automatically purged within 7–90 days depending on your plan tier.
- Archived files (S3 archive bucket): Retained for the period defined by your plan, then purged or transitioned to Glacier for long-term storage.
- Audit and usage logs: Retained for 12 months to support dispute resolution and compliance.
- Billing records: Retained for 7 years as required by Australian tax law.
6. Cookies
We use the following cookies:
- Session cookies (httpOnly): Used to maintain your login session. These are essential for the Service to function and cannot be disabled.
- Preference cookies: Store UI preferences (e.g., theme) to improve your experience.
We do not use advertising or cross-site tracking cookies. You can configure your browser to refuse cookies, but this may affect the functionality of the Service.
7. Your Rights
Under Australian privacy law (Privacy Act 1988) and, where applicable, other privacy regulations, you have the right to:
- Access the personal information we hold about you.
- Correct inaccurate or incomplete personal information.
- Delete your account and associated personal data (subject to legal retention requirements).
- Export your configuration data and transfer job history.
- Withdraw consent for optional data processing (e.g., usage analytics).
To exercise these rights, contact us at privacy@scanit2.cloud. We will respond within 30 days.
8. Children's Privacy
The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
9. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email or via an in-app notice at least 14 days before the changes take effect. The "Last updated" date at the top of this page reflects the most recent revision. Your continued use of the Service after the effective date constitutes acceptance of the revised policy.
10. Contact
For privacy-related questions, requests, or complaints, please contact our Privacy Officer:
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).