This policy explains how Syptime Pty Ltd (ABN 34 640 186 296) (Syptime, we, us) handles personal information in connection with CapSeal, our provenance verification platform at capseal.ai.
We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) in Schedule 1 of that Act.
We collect only what the service needs to work.
| Category | Examples | Source |
|---|---|---|
| Account information | Email address, password (stored only as a salted, peppered hash), company name if you give one | You, at sign-up |
| API credentials | API keys, stored only as a SHA-256 hash. We cannot recover a key and neither can anyone who obtains our database | Generated by us |
| Usage records | Number of API calls per key per day, total bytes processed, timestamp of last use | Generated automatically |
| Technical information | IP address (stored only as a hash, for rate limiting the public checker), request timestamps, error logs | Your browser or client |
| Correspondence | Emails you send us and our replies | You |
We do not collect sensitive information as defined in the Privacy Act, and we ask you not to send it to us.
We do not store the files you submit. A file posted to our verification endpoints is read in memory, analysed, and discarded when the response is sent. It is not written to disk, not written to a database, and not retained in any backup.
This matters because the files people send us are, by their nature, evidence: photographs of accidents, identity documents, inspection records. Holding a copy of all of it would create a risk out of all proportion to any benefit, so we do not.
A file may nonetheless contain personal information — faces, location coordinates in EXIF, names in document metadata. Because we do not retain the file, we do not retain any of that either. The only thing that outlives the request is the count of calls made by your API key.
If you submit a file, you are responsible for having the right to do so, including any consent required from the people it concerns.
We do not sell personal information. We do not use the files you submit to train models. We do not build advertising profiles.
We disclose personal information only to:
Our infrastructure is provided by Cloudflare, Inc., which operates a global network. Requests are served from the location closest to you, and account data is stored in Cloudflare's distributed database. This means your personal information may be stored or processed outside Australia, including in the United States and the European Union.
Under APP 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. You should be aware that overseas recipients may be subject to foreign laws that permit access by foreign authorities, and that we may not be able to compel an overseas recipient's compliance in the same way an Australian court could.
We keep account and usage records for as long as your account is open, and for up to seven years after closure where we need them for tax, accounting or legal purposes. Uploaded files are not retained at all, as set out in section 2.
No system is perfectly secure, and we do not claim otherwise. We tell you what we do so you can judge it.
Under APP 12 and APP 13 you may ask us for a copy of the personal information we hold about you, and ask us to correct anything inaccurate. You may also ask us to delete your account and the information associated with it.
Write to privacy@capseal.ai. We will respond within 30 days. There is no charge for a request, though we may charge a reasonable amount for a substantial one, and we will tell you before we do.
We may refuse a request in the limited circumstances the Privacy Act allows. If we do, we will tell you why in writing and how to complain.
We set one cookie: a session cookie named capseal_session, which keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and it expires after 30 days or when you sign out.
We use no advertising cookies, no third-party analytics, and no cross-site trackers.
We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If a breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
If you think we have mishandled your personal information, contact privacy@capseal.ai. We will acknowledge within 5 business days and aim to resolve the matter within 30 days.
If you are not satisfied with our response, you may complain to the OAIC: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.
We may update this policy. If a change materially affects how we handle your personal information we will tell you by email or a notice on the site before it takes effect. The version and date at the top of this page always reflect the current text.
Syptime Pty Ltd · ABN 34 640 186 296
3 Spring Street, Sydney NSW 2000, Australia
privacy@capseal.ai