Home  /  Knowledge Base  /  Privacy Policy

Privacy Policy

CertumSSL Respects Your Privacy

This privacy policy covers how we collect and use the personal information you provide on the CertumSSL website that links to this privacy policy. It also describes the choices available to you regarding our use of your personal information and how you can access and update that information. Personal information is information about you that can be used, directly or indirectly, to identify you (name, phone number, address, email addresses, etc.). Information that does not allow identification of you is not considered personal information. Except as described in this privacy policy, we will not disclose personal information to others without your authorization.

This policy is designed to comply with applicable data protection laws, including the European Union's General Data Protection Regulation (GDPR) where applicable.

Information Collection and Use

Forms

As is customary for all providers in the SSL certificate business, our site uses forms to collect personal information (including your name, address, telephone number, and email address) so you can place orders, manage your services, and request information and support. We may also request proof of identification, financial information, or other forms of information necessary to provide the services that you request.

Any information you transmit to us via forms on our site, or give us in any other way, including through email, our API, phone, or via contacting our support team will be stored. This information may be used for purposes of contacting you regarding your use of our services. You may update personal information stored or request not to be contacted by us — see below under "Updating Your Information".

Tracking Technologies

Our site uses cookies and tracking technologies to identify your account(s) so that you can securely utilize our services. The cookies are associated with your account; however, they utilize a session ID so that your internal account ID is never exposed. Furthermore, we utilize industry best practices to prevent session/cookie hijacking to ensure our use of cookies does not expose your personal information.

  • You can disable cookies in your web browser; however, doing so may prevent you from utilizing most services on our site.
  • An alternative to disabling cookies is to configure your web browser to delete all cookies upon closing the browser — this way you can utilize all of CertumSSL's services, while only storing/using cookies while they are necessary.

While using our site, our affiliates and/or analytics or service providers may use cookies and scripts to analyze web requests and site traffic trends, including users' movements around our site for purposes of gathering demographic information about our user base as a whole. We may receive data from these providers on an individual or aggregated basis which helps us better understand web site traffic trends; however, no personal information in our possession is relayed to any of these providers as part of this process.

Protocol Data

We gather certain information that is naturally transmitted as part of handling standard Internet protocols, such as HTTPS. We use this information, gathered as a result of your use of our services, via the Internet, to help personalize our site, diagnose problems with our servers, and to administer our site. This information may include Internet protocol (IP) addresses, browser type, referring/exit pages, operating system, date/time stamp and/or click-stream data. We also gather broad demographic information from this data to help us improve our site and service offerings.

WHOIS Data

Most certificate request forms may require publishing contact-related information in public directories as required by certificate authorities. We take steps to minimize the disclosure of your personal information to the extent permitted by relevant policies.

If you opt out of any available privacy service, your personal information may become publicly available. This means that anyone can download, store, copy, or distribute your personal information. Even if you enable privacy protection later on, information that has already been disclosed cannot be recalled.

Account Information

We collect the following types of personal information when you create or manage your CertumSSL account:

  • Full name or company name
  • Email address
  • Phone number
  • Billing address
  • Payment information (processed securely via Stripe)
  • Domain name(s) and certificate details (DV/OV/EV)
  • Organization details (for OV/EV certificates)

Security

We use security measures to protect against the loss, misuse, or alteration of the information under our control. When you enter sensitive information on our website forms, we encrypt the transmission of that information using Transport Layer Security (TLS).

We follow accepted industry standards to protect the personal information transferred to us, both during transmission and once we receive it. No method of transmission over the Internet, or method of information storage, is 100% secure. Therefore, we cannot guarantee its absolute security. If you have any questions about the security of your personal information, you can contact us via our Contact Page.

Google Analytics

We utilize "Google Analytics" to collect information about the use of our site, such as how often users visit, what pages they visit, and their click-path through our site. Google Analytics does not collect personal information as part of this process.

Google Analytics sets a permanent cookie in your web browser to identify you as a unique user the next time you visit this site. Information generated as a result of this process will be stored by Google on servers in the United States.

We use the information received from Google Analytics only to improve our site and the services that we offer. We do not combine the information collected by Google with any personal information.

Google's ability to use and share information collected by Google Analytics about your visits to our site is governed by Google's privacy policy: https://www.google.com/policies/privacy/. You can prevent Google Analytics from recognizing you on return visits to our site by deleting the Google Analytics cookie, or following the technique(s) described above in the Tracking Technologies section.

Data Retention and Access

Upon request, we will provide you with a confirmation about whether we hold, or process on behalf of a third party, any of your personal information. You may access, correct, or request deletion of your personal information by contacting us using any of the methods below:

  • Access your account on our site: Account Settings
  • You may send us mail at our physical address: No. 588, Laiyinda Road, 211112, Nanjing, China
  • You may send an email to: support@certumssl.com

We will respond to requests for access or to modify or deactivate personal information within thirty (30) days.

To deactivate your account, please log in and submit an authenticated contact form via our Contact Page.

Do Not Track Browser Setting

Some browsers allow you to automatically transmit a "Do Not Track" signal to websites that you visit. There is no established consensus as to what "Do Not Track" means in this context. We do not currently consider this signal from browsers when offering services on our site. To learn more about "Do Not Track", you can visit: https://allaboutdnt.com/.

What Happens to Your Personal Information if You Cancel Your Account

If your CertumSSL account is cancelled, all of your personal information is placed in "deactivated" status in our databases. Even though your account may be deactivated, that does not mean your personal information has been deleted from our databases. We will retain and use your personal information as necessary in order to meet our legal obligations, including retaining records of transactions for financial and tax compliance purposes.

Updating Your Information

After logging into your account on our site, you may update your account information or opt-out of receiving communications from us at any time (Account Home > "account maintenance").

Please recognize that, where your personal information is necessary for the provisioning of your requested services, or for the operation of our systems, the collection, use and disclosure of personal information is required and you cannot opt-out or delete the information without terminating your services.

Transfer of Data Abroad

If you are using our site from a country other than the country in which our servers are located, any of your communications with us may result in the transfer of information across international borders. You acknowledge and agree that in order to service our customers' requests, inquiries and/or issues, our support operations, including support provided via phone, chat, and email, are spread around the globe. Therefore, when you place a call, chat, or email from your country, it is possible that the call, chat, or email will be supported by CertumSSL personnel in another country, and that any information provided will be transferred to that country.

Regardless of any data transfer abroad, your information will be processed in accordance with this privacy policy. By using this site, calling, emailing, or chatting with our customer service personnel, or otherwise communicating electronically with us, you consent to such transfers.

Compliance with Laws and Law Enforcement

We cooperate with government and law enforcement officials and private parties to enforce and comply with the law. We will disclose any information about you to government or law enforcement officials or private parties as we, in our sole discretion, believe necessary or appropriate to respond to claims and legal process (including without limitation subpoenas), to protect our property and rights or the property and rights of a third party, to protect the safety of the public or any person, or to prevent or stop activity we consider to be illegal or unethical.

We will also share your information as required to comply with certificate authority policies and relevant regulations. To the extent we are legally permitted to do so, we will take reasonable steps to notify you in the event that we are required to provide your personal information to third parties as part of legal process.

Your Data Protection Rights

If you are located in the European Economic Area (EEA), Switzerland, or the United Kingdom, you have the following rights under applicable data protection laws:

Right of Access

You may request confirmation of whether we are processing your personal data, and if so, obtain access to that data. You may also request a copy of your data.

Right to Rectification

You may request the correction of inaccurate or incomplete personal data without undue delay.

Right to Erasure

You may request the deletion of your personal data where there is no compelling reason for us to continue processing it, such as when the data is no longer necessary, you withdraw consent, or the data has been processed unlawfully.

Right to Restrict Processing

You may request the restriction of processing of your personal data in certain circumstances, such as when you contest the accuracy of the data.

Right to Data Portability

You may receive your personal data in a structured, commonly used, and machine-readable format, and transmit that data to another controller where technically feasible.

Right to Object

You may object to the processing of your personal data where we rely on legitimate interests as the legal basis, including direct marketing purposes.

Exercising Your Rights

To exercise any of the above rights, please contact us via our Contact Page or email support@certumssl.com. We will respond to your request within one (1) month of receipt. We may request additional information to verify your identity before processing your request.

Right to Lodge a Complaint

If you believe your data protection rights have been violated, you have the right to lodge a complaint with the supervisory authority in your country of residence, place of work, or place of the alleged infringement. In the EU, this is typically your national data protection authority (e.g., the Information Commissioner's Office (ICO) in the UK).

Data Retention

We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected, including satisfying any legal, accounting, or reporting requirements. Specifically:

  • Account data: Retained while your account is active and for 36 months after your last activity.
  • Transaction records: Retained for 7 years for tax and accounting compliance.
  • Certificate-related data: Retained for the duration of the certificate validity plus 36 months for audit and support purposes.
  • Support correspondence: Retained for 3 years from the date of resolution.

Data Transfers

Your personal data may be transferred to and processed in countries outside the EEA, Switzerland, or the UK, including China. We ensure that such transfers comply with applicable data protection laws by implementing appropriate safeguards, including:

  • Standard Contractual Clauses (SCCs): Where data is transferred to third parties, we use the EU Commission's approved Standard Contractual Clauses.
  • Adequacy Decisions: We rely on EU Commission adequacy decisions where available for the destination country.
  • Technical measures: Data is encrypted in transit and at rest using industry-standard protocols (TLS 1.2+, AES-256).

Legal Basis for Processing

We process your personal data based on the following legal grounds:

  • Contract performance: Processing necessary to fulfill our contract with you (e.g., issuing certificates, managing your account).
  • Consent: Processing based on your explicit consent (e.g., marketing communications, which you may withdraw at any time).
  • Legitimate interests: Processing necessary for our legitimate business interests, such as fraud prevention, site security, and service improvement, provided these interests do not override your fundamental rights.
  • Legal obligation: Processing necessary for compliance with legal requirements (e.g., tax records, certificate authority policies).

Data Protection Officer

If you have any concerns regarding data protection, you may contact our data protection representative at dpo@certumssl.com.

Children's Privacy

Our site is not intended for children under the age of 18. We do not knowingly collect personal information from children under 18. If we learn that we have collected personal information from a child under 18, we will take steps to delete such information promptly.

Changes to Our Privacy Policy

We reserve the right to modify this privacy policy at any time. If we decide to change our privacy policy, we will post those changes to this privacy policy and any other places we deem appropriate, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we disclose it.

Contacting Us

If you have any questions about our privacy policy, or the practices of this site, please contact us at the address listed below: