Privacy Policy

Last updated: 2026-10-02

1. Who we are

SSLMonitor is a service operated by Synergetix CC (CIPC Reg No: 2004/087165/23; VAT No: 4130271895), based in the Republic of South Africa (“we”, “us”, “our”). We are the responsible party under the Protection of Personal Information Act, 2013 (Act 4 of 2013) (“POPIA”) for personal information we process through SSLMonitor.

2. Scope

This policy applies to our website (sslmonitor.co.za) and the SSLMonitor application, including accounts, dashboards, scheduled/triggered certificate checks, email alerts, and support channels. It covers personal information concerning data subjects in South Africa and, where applicable, juristic persons.

3. What we collect

Depending on how you use SSLMonitor, we process the following categories:

  • Account & contact details: name, email address, organisation, role, phone numbers, and (if applicable) billing details.
  • Monitor configuration: hostnames, ports, and settings you enter. Hostnames and certificate subjects may contain personal information (e.g., names in SANs/subjects).
  • Certificate & TLS metadata: public X.509 certificate data (subject, issuer, validity dates, SANs, key size, signature algorithm), negotiated protocol details, and the public certificate (PEM) as presented by the monitored service. We do not collect private keys.
  • Operational logs & telemetry: check timestamps, status, latency, error messages, IP addresses of client connections to SSLMonitor, user-agent, and audit logs (e.g., sign-ins, settings changes).
  • Alert recipients: email addresses (and optional names) configured to receive service alerts (e.g., expiry warnings).
  • Support: inquiry contents, attachments, and contact methods used (email, phone, WhatsApp).
  • Cookies & similar: strictly necessary cookies for session/auth; optional analytics if enabled (see Cookies).

4. How we use your information

  • Provide, operate, and improve SSLMonitor (creating checks, storing certificate history, rendering dashboards).
  • Send service alerts you configure (e.g., impending certificate expiry) and administrative messages (service notices, security updates).
  • Security, fraud prevention, and abuse detection (rate limiting, audit logs, access controls).
  • Compliance with legal obligations and responding to lawful requests.
  • Customer support and troubleshooting.

5. Lawful processing under POPIA

We process personal information in line with POPIA’s conditions for lawful processing: accountability, processing limitation, purpose specification (including retention), further processing limitation, information quality, openness, security safeguards, and data subject participation.

Our typical justifications include:

  • Contract necessity: to provide the service you signed up for (account, monitors, alerts).
  • Consent: for optional features (e.g., non-essential cookies/analytics) or where you explicitly agree.
  • Legitimate/justified interests: to secure and improve the service (audit logs, security monitoring), balanced against your rights.
  • Legal obligations: responding to lawful requests and fulfilling POPIA duties (e.g., breach notifications).

6. Retention

We retain personal information only as long as needed for the purposes above and as required by law. As a guide:

  • Certificate check history: 24 months (to track trends and expiry). Aggregate statistics may be kept longer in non-identifiable form.
  • Stored PEM (public certs): up to 12 months after replacement (for troubleshooting/audit).
  • Audit/access logs: 12 months by default; longer if needed for security, investigations, or legal obligations.
  • Support records: 24 months for continuity and quality assurance.
  • Backups: rolling backups retained for ~35 days.

You can request deletion where POPIA permits and where we no longer have a lawful basis to retain the information.

7. Sharing & operators

We do not sell your personal information. We use vetted service providers (“operators” under POPIA) to host and operate SSLMonitor (e.g., cloud hosting, email delivery, error logging). These providers process limited personal information on our behalf under written terms that require appropriate security and POPIA-aligned safeguards. Oversight is exercised by our Information Officer.

8. Cross-border transfers

We may store or process data in South Africa and other countries via third-party cloud providers. When personal information is transferred outside South Africa, we ensure that one of the protections in POPIA section 72 applies (for example: a law, binding corporate rules, or a binding agreement ensuring an adequate level of protection; your explicit consent; contract necessity; or public interest).

9. Security & breach notification

We implement reasonable technical and organisational measures (network and application firewalls, TLS in transit, role-based access, audit logging, least-privilege access, vulnerability management, and off-site backups). No method is 100% secure; we continually monitor and improve controls.

If we have reasonable grounds to believe a “security compromise” has occurred involving personal information, we will notify the Information Regulator and the affected data subjects as soon as is reasonably possible, in the prescribed manner and form, subject to any lawful delay to avoid impeding a criminal investigation.

10. Your rights

Under POPIA, you can request access to your personal information, request correction or deletion, object to certain processing (including direct marketing), and lodge a complaint with the Information Regulator. We will respond in line with POPIA and applicable guidance.

  • Access/Correction: Ask for a copy of your personal information or corrections/updates.
  • Deletion: Request deletion where we no longer need the information or where POPIA permits.
  • Objection: Object to processing in certain cases, including direct marketing.
  • Complaint: You may lodge a complaint with the Information Regulator (see details below).

11. Cookies

We use strictly necessary cookies for authentication, session management, and security. If we enable analytics, we will ask for consent where required and provide opt-out controls. POPIA applies to personal information that may be collected through cookies and similar technologies.

12. Children

SSLMonitor is a business service and is not directed at children under 18. We do not knowingly collect personal information from minors without appropriate authority.

13. Changes to this policy

We may update this policy to reflect changes to our practices or legal requirements. Material changes will be highlighted here, and the “Last updated” date will change.

14. Contact us & the Information Regulator

Synergetix CC (Responsible Party)

Legal name: Synergetix CC (CIPC Reg No: 2004/087165/23)
Trading as: SSLMonitor
VAT Number: 4130271895
Email: support@synergetix.co.za
Telephone: +27 10 500 0824, +27 11 568 2291
WhatsApp / Support: +27 71 711 1700

Information Regulator (South Africa)

Woodmead North Office Park, 54 Maxwell Drive, Woodmead, Johannesburg, 2191
Tel: 010 023 5200 • Toll Free: 0800 017 160 • Email: enquiries@inforegulator.org.za
Complaints information and forms are available on the Information Regulator’s website.

This policy is intended to meet POPIA’s minimum requirements for lawful processing and transparency in our context (SSL/TLS certificate monitoring). It is not legal advice. Some obligations (e.g., PAIA manual) may apply separately depending on your organisation. If you have questions about your specific circumstances, please consult qualified counsel.


Service scope note SSLMonitor retrieves and stores public certificate material served by endpoints you configure. Certificate subjects/SANs may include personal information. Only configure monitors where you are authorised to do so. If you capture third-party data, you are responsible for ensuring a lawful basis under POPIA for that processing.