SSLGuru, LLC ("SSLGuru", "we", "us") respects your privacy. This Policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have.
This Policy covers sslguru.com and the services we provide through it. It does not cover third-party websites that use certificates we sold, and it does not cover information embedded in an issued digital certificate, which is published by the Certification Authority and, for publicly trusted certificates, is logged permanently in public Certificate Transparency logs (see Section 5).
Controller. SSLGuru, LLC, 133 North Altadena Drive, Suite 402, Pasadena, CA 91107, United States, is the controller of the personal data described in this Policy. Where we process personal data on behalf of a business customer, that customer is the controller and we act as processor under our Data Processing Addendum.
Information you give us
Information collected automatically
Information from third parties
We do not deliberately collect special categories of data (health, biometrics, political opinions and similar). Please do not send them to us.
Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.
We do not use your personal data or your content to train generative artificial intelligence models, and we do not permit our vendors to do so.
We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.
Service and advisory emails — renewal reminders, expiry warnings, security advisories, billing notices and account notifications. These are part of the Service and you cannot unsubscribe from them while you hold an account.
Marketing emails — newsletters and product news. Every marketing email contains a one-click unsubscribe link and honours List-Unsubscribe headers. You may also email [email protected]. We honour opt-outs within 10 business days.
SMS. Where you opt in to text messages, standard message and data rates may apply and you may opt out by replying STOP. Mobile opt-in data and consent are never shared with third parties or affiliates for their own marketing or promotional purposes.
If you obtain a publicly trusted TLS certificate through us, the information embedded in it — including domain names, and for organisation-validated and extended-validation certificates the organisation name, locality and country — is published by the Certification Authority in public Certificate Transparency logs, which are append-only and permanent. This information cannot be edited, withdrawn or erased, including by revoking the certificate.
Consider this before including personal names in a certificate. Where information in an issued certificate becomes inaccurate, the correct remedy is revocation and reissue, not amendment.
A current list of our sub-processors is published at sslguru.com/subprocessors and business customers may subscribe to notification of changes.
We are based in the United States and our service providers may be located in the United States and other countries. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on:
We carry out and keep under review a transfer impact assessment for each transfer. A copy of the safeguards is available on request from [email protected].
We may keep data longer where necessary to comply with law, resolve a dispute or enforce our agreements. When retention ends we delete or irreversibly anonymise the data.
You have the right to:
You may lodge a complaint with your local supervisory authority. In Poland this is the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa; in the United Kingdom, the Information Commissioner's Office.
Under the CCPA as amended by the CPRA you have the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it; the right to delete; the right to correct; the right to opt out of sale or sharing for cross-context behavioural advertising; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.
We do not sell or share personal information as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes other than those permitted without a limitation right.
Categories of personal information we have collected in the last 12 months: identifiers; customer records (Cal. Civ. Code § 1798.80); commercial information; internet or network activity; geolocation inferred from IP address; and professional information. Business purposes for collection are listed in Section 3.
Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island have comparable rights of access, correction, deletion, portability and opt-out.
You also have the right to appeal a refusal: reply to our decision or email [email protected] with "appeal" in the subject line, and we will respond within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.
Universal opt-out signals. We honour the Global Privacy Control and other recognised universal opt-out mechanisms as a valid opt-out of sale, sharing and targeted advertising for the browser transmitting them, as required in California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas.
Email [email protected], use the privacy request form at sslguru.com/privacy-request, or write to the postal address in Section 12. We will verify your identity in proportion to the sensitivity of the request; for account holders, verification through the account is usually sufficient.
We respond within 30 days (EEA/UK) or 45 days (United States), extendable once where the request is complex, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.
An authorised agent may submit a request on your behalf with written authorisation; we may ask you to confirm the authorisation directly.
The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 16, or under 13 in the United States. If you believe a child has given us personal data, email [email protected] and we will delete it.
We maintain administrative, technical and physical safeguards appropriate to the risk, including encryption in transit and at rest, access control on a least-privilege basis, multi-factor authentication for administrative access, network segmentation, logging, vulnerability management and an incident response plan that is tested at least annually. No system is perfectly secure, and we cannot guarantee absolute security.
If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where required by Article 33 GDPR, notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights, and notify our business customers within 48 hours where we act as their processor. We will also comply with applicable U.S. state breach notification statutes.
Report a suspected vulnerability to [email protected]. We will acknowledge within 3 business days and we will not pursue legal action against good-faith security research conducted in accordance with our vulnerability disclosure policy.
Privacy enquiries: [email protected]
Post: SSLGuru, LLC, Attn: Privacy, 133 North Altadena Drive, Suite 402, Pasadena, CA 91107, United States
Telephone: 1-855-775-4878 (1-855-SSLGURU) · Direct: +1 626-377-9979
Technical support: [email protected]
We may update this Policy. For material changes we will give at least 30 days' notice by email to account holders and by prominent notice on the Site before the change takes effect. The Effective Date at the top shows when this version took effect, and previous versions are archived at sslguru.com/legal/archive.