Privacy policy

Effective Date: September 9, 2026 · Version 3.0 · Supersedes the version dated 08/15/2013, last updated 07/01/2024


1. Introduction

SSLGuru, LLC ("SSLGuru", "we", "us") respects your privacy. This Policy explains what personal data we collect, why, who we share it with, how long we keep it, and the rights you have.

This Policy covers sslguru.com and the services we provide through it. It does not cover third-party websites that use certificates we sold, and it does not cover information embedded in an issued digital certificate, which is published by the Certification Authority and, for publicly trusted certificates, is logged permanently in public Certificate Transparency logs (see Section 5).

Controller. SSLGuru, LLC, 133 North Altadena Drive, Suite 402, Pasadena, CA 91107, United States, is the controller of the personal data described in this Policy. Where we process personal data on behalf of a business customer, that customer is the controller and we act as processor under our Data Processing Addendum.

2. What We Collect

Information you give us

  • Identity and contact data: name, organisation, job title, postal address, email, telephone.
  • Account data: username, hashed password, security settings, support and communication history.
  • Order and billing data: products purchased, order history, billing address, tax identifiers, the last four digits and expiry of your payment card. We do not store full payment card numbers.
  • Validation data: the documents and confirmations a Certification Authority requires to validate your domain or organisation, which may include company registration extracts, and, for Extended Validation, evidence of the identity and authority of named individuals.
  • Content you submit: support tickets, live chat transcripts, survey responses.

Information collected automatically

  • Device and connection data: IP address, browser type and version, operating system, language, referring page, pages viewed, timestamps, clickstream.
  • Cookies and similar technologies, as described in our Cookie Policy.

Information from third parties

  • Payment confirmations and fraud signals from our payment processors.
  • Validation results from Certification Authorities.
  • Publicly available business registry and WHOIS/RDAP data used for validation.

We do not deliberately collect special categories of data (health, biometrics, political opinions and similar). Please do not send them to us.

3. Why We Use It, and Our Legal Basis

Purpose Legal basis (GDPR / UK GDPR)
Creating and administering your account; providing the Services Performance of a contract (Art. 6(1)(b))
Processing payments, invoicing, collections Contract; legal obligation (Art. 6(1)(b), (c))
Domain and organisation validation with the Certification Authority Contract; legal obligation and legitimate interests in operating a trustworthy PKI (Art. 6(1)(b), (c), (f))
Support, including live chat Contract; legitimate interests (Art. 6(1)(b), (f))
Service, security and expiry notices you cannot unsubscribe from Contract; legitimate interests in service continuity and security (Art. 6(1)(b), (f))
Marketing emails and newsletters Consent, or legitimate interests where an existing-customer soft opt-in applies; you may withdraw at any time (Art. 6(1)(a), (f))
Fraud prevention, abuse detection, network and information security Legitimate interests; legal obligation (Art. 6(1)(f), (c))
Analytics and product improvement Consent for non-essential cookies; otherwise legitimate interests (Art. 6(1)(a), (f))
Complying with law, responding to lawful requests, exercising or defending legal claims Legal obligation; legitimate interests (Art. 6(1)(c), (f))
Sanctions and export-control screening Legal obligation (Art. 6(1)(c))

Where we rely on legitimate interests, we have carried out a balancing assessment and will provide a summary on request.

We do not use your personal data or your content to train generative artificial intelligence models, and we do not permit our vendors to do so.

We do not sell your personal data, and we do not share it for cross-context behavioural advertising, as those terms are defined under California law.

4. Communications

Service and advisory emails — renewal reminders, expiry warnings, security advisories, billing notices and account notifications. These are part of the Service and you cannot unsubscribe from them while you hold an account.

Marketing emails — newsletters and product news. Every marketing email contains a one-click unsubscribe link and honours List-Unsubscribe headers. You may also email [email protected]. We honour opt-outs within 10 business days.

SMS. Where you opt in to text messages, standard message and data rates may apply and you may opt out by replying STOP. Mobile opt-in data and consent are never shared with third parties or affiliates for their own marketing or promotional purposes.

5. Certificate Data Is Public

If you obtain a publicly trusted TLS certificate through us, the information embedded in it — including domain names, and for organisation-validated and extended-validation certificates the organisation name, locality and country — is published by the Certification Authority in public Certificate Transparency logs, which are append-only and permanent. This information cannot be edited, withdrawn or erased, including by revoking the certificate.

Consider this before including personal names in a certificate. Where information in an issued certificate becomes inaccurate, the correct remedy is revocation and reissue, not amendment.

6. Who We Share It With

  • Certification Authorities — the data necessary to validate and issue your certificate. Each CA is an independent controller for that purpose and applies its own privacy notice and Certification Practice Statement.
  • Payment processors — to take payment and prevent fraud. They act as independent controllers for their own compliance purposes.
  • Service providers acting as our processors — hosting, email delivery, live chat, ticketing, CRM, analytics, accounting. They act only on our documented instructions and are bound by written contracts meeting Article 28 GDPR.
  • Group companies — Ionblade Web Hosting and Plenty of Pixels, where you hold services with them or where a shared function (billing, support) requires it.
  • Professional advisers, auditors and insurers, under duties of confidentiality.
  • Authorities and third parties where necessary to comply with a valid legal request, enforce our agreements, or protect the rights, property or safety of any person. We assess each request, require lawful process, and where we are legally permitted we notify the affected customer before disclosure.
  • An acquirer, in connection with a merger, acquisition or sale of assets, subject to this Policy continuing to apply.

A current list of our sub-processors is published at sslguru.com/subprocessors and business customers may subscribe to notification of changes.

7. International Transfers

We are based in the United States and our service providers may be located in the United States and other countries. Where personal data is transferred out of the European Economic Area, the United Kingdom or Switzerland, we rely on:

  • the European Commission's Standard Contractual Clauses (Decision (EU) 2021/914), with the UK International Data Transfer Addendum for UK transfers and the Swiss adaptations for Swiss transfers; and
  • where applicable, our certification under the EU-U.S. Data Privacy Framework, the UK Extension and the Swiss-U.S. Data Privacy Framework, together with the supplementary measures described in our transfer impact assessment.

We carry out and keep under review a transfer impact assessment for each transfer. A copy of the safeguards is available on request from [email protected].

8. How Long We Keep It

Data Retention
Account and profile data For the life of the account, then 24 months
Order, invoice and tax records 7 years from the transaction (tax and accounting rules)
Certificate validation evidence As required by the CA/Browser Forum Baseline Requirements and the issuing CA's CPS, currently a minimum of 7 years after certificate expiry or revocation
Support tickets and chat transcripts 3 years from closure
Marketing consent and opt-out records Until withdrawn, plus 5 years to evidence the withdrawal
Server and security logs 12 months, unless retained longer for an active investigation
Backups Rolling 35 days

We may keep data longer where necessary to comply with law, resolve a dispute or enforce our agreements. When retention ends we delete or irreversibly anonymise the data.

9. Your Rights

9.1 If you are in the EEA, the UK or Switzerland

You have the right to:

  • access your data;
  • have inaccurate data corrected;
  • have data erased;
  • restrict processing;
  • object to processing based on legitimate interests, and to direct marketing at any time;
  • receive your data in a portable format;
  • withdraw consent at any time without affecting prior processing; and
  • not be subject to a decision based solely on automated processing that produces legal or similarly significant effects (we do not carry out such processing).

You may lodge a complaint with your local supervisory authority. In Poland this is the Prezes Urzędu Ochrony Danych Osobowych (UODO), ul. Stawki 2, 00-193 Warszawa; in the United Kingdom, the Information Commissioner's Office.

9.2 If you are in California

Under the CCPA as amended by the CPRA you have the right to know the categories and specific pieces of personal information we have collected, the sources, the purposes, and the categories of third parties to whom we disclose it; the right to delete; the right to correct; the right to opt out of sale or sharing for cross-context behavioural advertising; the right to limit the use of sensitive personal information; and the right not to be discriminated against for exercising these rights.

We do not sell or share personal information as those terms are defined by the CCPA. We do not use or disclose sensitive personal information for purposes other than those permitted without a limitation right.

Categories of personal information we have collected in the last 12 months: identifiers; customer records (Cal. Civ. Code § 1798.80); commercial information; internet or network activity; geolocation inferred from IP address; and professional information. Business purposes for collection are listed in Section 3.

9.3 If you are in another U.S. state with a comprehensive privacy law

Residents of states including Virginia, Colorado, Connecticut, Utah, Texas, Oregon, Montana, Florida, Delaware, Iowa, Nebraska, New Hampshire, New Jersey, Tennessee, Minnesota, Maryland, Indiana, Kentucky and Rhode Island have comparable rights of access, correction, deletion, portability and opt-out.

You also have the right to appeal a refusal: reply to our decision or email [email protected] with "appeal" in the subject line, and we will respond within 45 days with a written explanation. If we deny the appeal, you may contact your state Attorney General.

Universal opt-out signals. We honour the Global Privacy Control and other recognised universal opt-out mechanisms as a valid opt-out of sale, sharing and targeted advertising for the browser transmitting them, as required in California, Colorado, Connecticut, Delaware, Maryland, Minnesota, Montana, Nebraska, New Hampshire, New Jersey, Oregon and Texas.

9.4 How to exercise your rights

Email [email protected], use the privacy request form at sslguru.com/privacy-request, or write to the postal address in Section 12. We will verify your identity in proportion to the sensitivity of the request; for account holders, verification through the account is usually sufficient.

We respond within 30 days (EEA/UK) or 45 days (United States), extendable once where the request is complex, and we will tell you if we need the extension. There is no charge unless a request is manifestly unfounded or excessive.

An authorised agent may submit a request on your behalf with written authorisation; we may ask you to confirm the authorisation directly.

10. Children

The Services are for business use and are not directed to children. We do not knowingly collect personal data from anyone under 16, or under 13 in the United States. If you believe a child has given us personal data, email [email protected] and we will delete it.

11. Security and Breach Notification

We maintain administrative, technical and physical safeguards appropriate to the risk, including encryption in transit and at rest, access control on a least-privilege basis, multi-factor authentication for administrative access, network segmentation, logging, vulnerability management and an incident response plan that is tested at least annually. No system is perfectly secure, and we cannot guarantee absolute security.

If a personal data breach occurs, we will notify the competent supervisory authority within 72 hours where required by Article 33 GDPR, notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights, and notify our business customers within 48 hours where we act as their processor. We will also comply with applicable U.S. state breach notification statutes.

Report a suspected vulnerability to [email protected]. We will acknowledge within 3 business days and we will not pursue legal action against good-faith security research conducted in accordance with our vulnerability disclosure policy.

12. Contact and Changes

Privacy enquiries: [email protected]

Post: SSLGuru, LLC, Attn: Privacy, 133 North Altadena Drive, Suite 402, Pasadena, CA 91107, United States

Telephone: 1-855-775-4878 (1-855-SSLGURU) · Direct: +1 626-377-9979

Technical support: [email protected]

We may update this Policy. For material changes we will give at least 30 days' notice by email to account holders and by prominent notice on the Site before the change takes effect. The Effective Date at the top shows when this version took effect, and previous versions are archived at sslguru.com/legal/archive.