Legal

Privacy Policy

Syptime Pty Ltd · Last updated 10 August 2026 · Version 1.0

This policy explains how Syptime Pty Ltd (ABN 34 640 186 296) (Syptime, we, us) handles personal information in connection with CapSeal, our provenance verification platform at capseal.ai.

We are bound by the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) in Schedule 1 of that Act.

  1. What we collect
  2. Files you submit for verification
  3. Why we collect it
  4. Who we disclose it to
  5. Overseas disclosure
  6. Security and retention
  7. Access, correction and deletion
  8. Cookies
  9. Data breaches
  10. Complaints
  11. Changes

1. What we collect

We collect only what the service needs to work.

CategoryExamplesSource
Account informationEmail address, password (stored only as a salted, peppered hash), company name if you give oneYou, at sign-up
API credentialsAPI keys, stored only as a SHA-256 hash. We cannot recover a key and neither can anyone who obtains our databaseGenerated by us
Usage recordsNumber of API calls per key per day, total bytes processed, timestamp of last useGenerated automatically
Technical informationIP address (stored only as a hash, for rate limiting the public checker), request timestamps, error logsYour browser or client
CorrespondenceEmails you send us and our repliesYou

We do not collect sensitive information as defined in the Privacy Act, and we ask you not to send it to us.

2. Files you submit for verification

We do not store the files you submit. A file posted to our verification endpoints is read in memory, analysed, and discarded when the response is sent. It is not written to disk, not written to a database, and not retained in any backup.

This matters because the files people send us are, by their nature, evidence: photographs of accidents, identity documents, inspection records. Holding a copy of all of it would create a risk out of all proportion to any benefit, so we do not.

A file may nonetheless contain personal information — faces, location coordinates in EXIF, names in document metadata. Because we do not retain the file, we do not retain any of that either. The only thing that outlives the request is the count of calls made by your API key.

If you submit a file, you are responsible for having the right to do so, including any consent required from the people it concerns.

3. Why we collect it

We do not sell personal information. We do not use the files you submit to train models. We do not build advertising profiles.

4. Who we disclose it to

We disclose personal information only to:

5. Overseas disclosure

Our infrastructure is provided by Cloudflare, Inc., which operates a global network. Requests are served from the location closest to you, and account data is stored in Cloudflare's distributed database. This means your personal information may be stored or processed outside Australia, including in the United States and the European Union.

Under APP 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. You should be aware that overseas recipients may be subject to foreign laws that permit access by foreign authorities, and that we may not be able to compel an overseas recipient's compliance in the same way an Australian court could.

6. Security and retention

We keep account and usage records for as long as your account is open, and for up to seven years after closure where we need them for tax, accounting or legal purposes. Uploaded files are not retained at all, as set out in section 2.

No system is perfectly secure, and we do not claim otherwise. We tell you what we do so you can judge it.

7. Access, correction and deletion

Under APP 12 and APP 13 you may ask us for a copy of the personal information we hold about you, and ask us to correct anything inaccurate. You may also ask us to delete your account and the information associated with it.

Write to privacy@capseal.ai. We will respond within 30 days. There is no charge for a request, though we may charge a reasonable amount for a substantial one, and we will tell you before we do.

We may refuse a request in the limited circumstances the Privacy Act allows. If we do, we will tell you why in writing and how to complain.

8. Cookies

We set one cookie: a session cookie named capseal_session, which keeps you signed in. It is HttpOnly, Secure and SameSite=Lax, and it expires after 30 days or when you sign out.

We use no advertising cookies, no third-party analytics, and no cross-site trackers.

9. Data breaches

We are covered by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. If a breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.

10. Complaints

If you think we have mishandled your personal information, contact privacy@capseal.ai. We will acknowledge within 5 business days and aim to resolve the matter within 30 days.

If you are not satisfied with our response, you may complain to the OAIC: oaic.gov.au, 1300 363 992, or GPO Box 5218, Sydney NSW 2001.

11. Changes

We may update this policy. If a change materially affects how we handle your personal information we will tell you by email or a notice on the site before it takes effect. The version and date at the top of this page always reflect the current text.

Contact

Syptime Pty Ltd · ABN 34 640 186 296
3 Spring Street, Sydney NSW 2000, Australia
privacy@capseal.ai