Privacy Policy
Outlining how InfraHost collects, handles, protects, and stores personal information across our infrastructure, services, and client portal.
Privacy Framework & Policy Scope
Effective Date: January 1, 2026 • InfraHost Australia (ABN: 67 545 081 521)
1. Compliance with the Privacy Act 1988 (Cth)
InfraHost is committed to protecting user privacy and handling personal data in strict compliance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). This policy governs all personal data collected via our main website (infrahost.com.au), client portal (portal.infrahost.com.au), Discord bot hosting infrastructure, web hosting nodes, and network diagnostic endpoints.
2. Information We Collect
We collect necessary personal and technical data to provide secure hosting services, handle billing, and fulfill legal compliance:
- Account & Identification Data: Full name, verified email address, billing address, contact phone number, and ABN/ACN (for business accounts or auDA domain registrations) collected via portal.infrahost.com.au.
- Discord Single Sign-On (SSO): Discord User ID, username, avatar hash, and linked email address obtained when authenticating via Discord OAuth.
- Financial & Payment Data: Credit card metadata, payment transaction tokens, and billing histories processed securely through Stripe. InfraHost does not store full 16-digit credit card numbers on local infrastructure.
- Technical Telemetry & Network Logs: Source IPv4/IPv6 addresses, browser user-agents, firewall scrubbing logs (via FortiGate® appliances), and latency metrics when utilizing network.infrahost.com.au.
3. How We Use Collected Information
InfraHost processes collected personal data exclusively for primary operational purposes:
- Provisioning and managing Pterodactyl container instances, DirectAdmin/cPanel accounts, and SSL certificates.
- Verifying account identity to prevent fraudulent orders or unauthorized access.
- Informing clients of scheduled system maintenance, emergency network audits, or invoice notifications.
- Mitigating volumetric DDoS attacks and isolating malicious traffic via FortiGate® hardware appliances.
4. Data Disclosure & Overseas Transfers
InfraHost does not sell, rent, or trade client personal information to third-party advertisers. Disclosure occurs strictly under necessary operating conditions:
- Payment Gateways: Payment metadata shared with Stripe for secure transaction processing under PCIDSS Level 1 standards.
- Domain Registries: Registrant identification disclosed to auDA (.au Domain Administration Ltd) and Synergy Wholesale as required for Australian domain registrations.
- Law Enforcement Requirements: Disclosure compelled by Australian law, court orders, or subpoenas issued by valid law enforcement authorities.
5. Data Security & Infrastructure Safeguards
InfraHost implements enterprise-grade technical and physical safeguards to prevent unauthorized data access, loss, or disclosure:
- All database connections, administrative portals, and client sessions are encrypted using 256-bit TLS/SSL encryption.
- Primary hosting infrastructure is co-located inside secure, ISO27001-certified Sydney carrier data centers with biometric access controls and 24/7 CCTV surveillance.
- Off-site backup snapshots are encrypted at rest on NVMe storage arrays.
6. Access, Correction, and Data Rights
Under APPs 12 and 13, Australian residents have the right to request access to personal information held by InfraHost or request corrections to inaccurate data. Account holders can update contact details directly inside portal.infrahost.com.au or submit a formal privacy request via our support ticket portal.
InfraHost
Portal Login