Privacy Policy & APP Compliance Statement
Last Updated: August 26, 2026 | Australian Privacy Principles (APP) Statutory Compliance Notice
APP 1 — Open and Transparent Management of Personal Information
Infrahost manages personal information in an open, accountable, and transparent manner. We maintain automated controls and internal policies to ensure compliance with Australian data protection laws, including regular audits of authentication logs, database encryption standards, and identity verification pipelines.
APP 2 — Anonymity and Pseudonymity
Due to legal, regulatory, and technical security mandates involved in enterprise cloud infrastructure management, user authentication requires verified identity matching. Pseudonymous or anonymous access to operational infrastructure and tenant controls is restricted under our security framework to prevent unauthorized system exploitation.
APP 3 & 4 — Collection of Solicited & Unsolicited Personal Information
We collect personal information solely when necessary to deliver cloud computing services, maintain identity federations, and comply with security auditing standards. Information collected via Single Sign-On (SSO) providers (Google, Discord) or manual sign-in forms includes:
- Full Legal Name and Primary Corporate/Individual Email Address.
- SSO Provider Unique Identification Identifiers (e.g., Google
subID, Discord User ID). - Profile Avatar URLs and multi-factor authentication (2FA) verification metadata.
- Network Telemetry: Origin IPv4/IPv6 address, browser User-Agent fingerprints, and access timestamps.
Any unsolicited personal information received is evaluated immediately and destroyed if not required for legitimate platform access control or legal record-keeping.
APP 5 — Notification of the Collection of Personal Information
At or before the time personal data is collected (such as when initiating Single Sign-On via Google or Discord), users are notified that their credentials will be verified against pre-approved database records. Access attempts from unrecognized accounts are immediately rejected with clear on-screen notifications.
APP 6 & 7 — Use, Disclosure & Direct Marketing
Personal data is strictly used for authentication, access control, system diagnostics, and security auditing. Infrahost does not engage in direct marketing, nor do we sell, lease, or commercialize personal user data to third parties under any circumstances.
APP 8 — Cross-Border Disclosure of Personal Information
All primary authentication databases and security audit logs are hosted strictly within Australian-domiciled data centers. When using third-party SSO providers (such as Google or Discord), identity tokens are transmitted securely over SSL/TLS directly between your web client and the respective identity provider's global endpoints.
APP 10 & 11 — Quality and Security of Personal Information
We take active measures to ensure collected data is accurate, complete, and up-to-date. In compliance with the Australian Cyber Security Centre (ACSC) security guidelines and APP 11:
- Passwords are stored using non-reversible
BCRYPTcryptographic hashing algorithms. - Database connections utilize strict Prepared Statements to prevent SQL injection vulnerabilities.
- Immutable, real-time security events are recorded in an internal
audit_logstable to track all login activities and system events. - Data destruction policies ensure soft-deleted or deactivated accounts are purged securely upon request.
APP 12 & 13 — Access to and Correction of Personal Information
Registered users have the right to request access to their stored personal details or request corrections to inaccurate information. You can manage your account profile directly within the Infrahost Enterprise Portal or submit a formal inquiry to our privacy officer at privacy@infrahost.com.au.