OzVPS provides virtual private server hosting and Enhance-powered Web Hosting services from our Australian data centre in Brisbane. This Privacy Policy describes what information we collect, why we collect it, how we use it and how we protect it. We handle personal information in line with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we hold ourselves to that standard regardless of whether the small business exemption would otherwise apply to us.
1. Who we are
For the purposes of the Privacy Act, OzVPS (ABN 58 947 584 850) is the entity responsible for the handling of your personal information. Our registered business is based in Queensland, Australia. Privacy enquiries can be sent to [email protected].
2. Information we collect
Account information
When you sign up for a service we collect your name, email address, billing address, phone number (if provided) and payment details. We require this information to provision services, issue invoices and comply with our legal obligations. Anonymous or pseudonymous interaction is supported for general enquiries but not for active services.
Service information
We collect operational data necessary to run our network: server hypervisor metrics, connection metadata (source IP, destination IP, port, byte counts), netflow records used for capacity planning and DDoS mitigation, and abuse-related records (logs that show the source of a reported violation). We do not inspect the contents of customer disks or databases, and we do not log inside-the-VPS application traffic.
Web Hosting customers
For our Web Hosting product on Enhance, we additionally process: site files, databases and mailboxes you upload or send through the service; DNS records you publish; and access logs (HTTP and SMTP). These are processed solely to deliver the hosting service.
Website information
Our public website (ozvps.com.au) uses Google Analytics 4 to understand how the site is used, which pages people find, and what is not working. It records pages viewed, approximate location derived from your IP address, device and browser type, and how you arrived at the site. It sets first-party cookies in your browser (named _ga and similar) so that repeat visits can be counted as one person rather than several. We have not enabled Google Signals, advertising features or remarketing. Google processes this data outside Australia; see section 5. Standard webserver access logs are retained for up to 30 days.
You can opt out at any time using Google's browser add-on, or by enabling Do Not Track or a content blocker. Nothing on the site requires analytics to work, and blocking it will not affect your service.
Information from third parties
Most of the personal information we hold is collected directly from you. In some cases we also receive personal information about you from third parties, for example fraud and chargeback signals from our payment processor, and abuse or infringement reports that identify the source of a complaint. If you do not provide the account information we ask for, we may be unable to provision a service, issue an invoice or meet our legal obligations, and we may decline or suspend the service.
3. How we use information
- Providing, maintaining and improving our hosting services
- Billing, invoicing, fraud prevention and chargeback handling
- Abuse mitigation, DDoS response and security operations
- Responding to support requests and legal process
- Capacity planning and network engineering
- Notifying you of material service changes, security incidents, or scheduled maintenance
We do not sell your personal information. We do not provide your data to advertisers or data brokers.
Disclosure required or authorised by law
We may access, preserve, use or disclose your personal information, account records, connection metadata or content where we reasonably believe it is required or authorised by or under an Australian law, a court or tribunal order, or a lawful direction from a law-enforcement agency or regulator. This includes cooperating with bodies such as the Australian Federal Police, state and territory police, the Australian Communications and Media Authority, the Office of the eSafety Commissioner and the Office of the Australian Information Commissioner. Where the law permits, we will limit any disclosure to what is reasonably necessary. Where we are lawfully prohibited from notifying you, or where notifying you would prejudice an investigation, we may act without prior notice to you.
4. Third parties
Payment processors
Payment details (card numbers, bank account details) are handled directly by our PCI-DSS-certified payment processor. We never see or store full card numbers. We only receive a tokenised reference, the last four digits and the card brand for reconciliation purposes.
Email delivery
Transactional and billing email (invoices, service notices, password resets) is sent through a specialist email delivery provider located overseas. Delivering that mail necessarily discloses your name and email address to them. See section 5 for how we handle overseas disclosures. We do not use third-party marketing platforms to target customers, and we do not sell or share your address for marketing.
Content delivery and security
Our client area is served through Cloudflare, a content delivery and security network. Requests to it pass through Cloudflare's global network, which processes connection data such as your IP address in order to route the request and filter attacks. Cloudflare is based overseas.
Service monitoring
We use an external uptime monitoring provider to check that our services are reachable and to power our public status page. It monitors our infrastructure, not your account, and is not given access to customer data.
Data centre
Our infrastructure is colocated in the Host Networks data centre in Brisbane. The facility operators are bound by confidentiality obligations and only have physical access to our equipment, not logical access to customer data.
5. Data location and overseas disclosure
Your content stays in Australia. All production customer data, meaning VPS disks, hosting accounts, databases, mailboxes and their backups, is stored on our infrastructure in Australia. We do not move it offshore, and we do not replicate it to overseas regions.
Some account information is handled overseas. Running the business requires a small number of specialist providers, and some of them operate outside Australia. Being straightforward about this matters more than a tidy claim, so here is the full list and what each one receives:
- Payment processing: your name, email address, billing address and card details go directly to our payment processor, which operates internationally. We never receive your full card number.
- Transactional email: your name and email address are disclosed to our email delivery provider, which is located overseas, so that invoices and service notices can reach you.
- Client area delivery and security: requests to our client area pass through Cloudflare's global network, which processes connection data including your IP address.
- Website analytics: Google Analytics processes your IP address, device information and the pages you view on our public website. Google is based overseas and operates its own global infrastructure.
Where we disclose personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including selecting established providers with published privacy commitments and contractual protections. Under APP 8 we remain accountable to you for that information. If you would rather not have your information handled this way, the practical consequence is that we cannot bill you or send you service notices, so we would be unable to provide the service.
6. Data retention
- Account records: retained while your account is active and for seven (7) years after closure for tax and audit purposes
- Invoices and billing records: seven (7) years per ATO record-keeping requirements
- Connection metadata / netflow: up to 90 days, used for capacity planning and abuse response
- Webserver access logs: up to 30 days
- Service disks (VPS images, hosting account data): deleted within 14 days of service termination unless legal hold applies
7. Access controls and security
We apply role-based access controls, multi-factor authentication on every account that can reach production, audit logging on production systems, and encryption at rest for backups. Access to customer data is limited to what is needed to operate the service and respond to support requests. Customer-managed data inside a VPS is your responsibility to protect. We cannot see into your operating system or applications.
No system is perfectly secure. We do not guarantee that our security measures will prevent every attack, and you should keep your own copies of anything you cannot afford to lose.
8. Data breach notification
If we suspect a data breach may have occurred, we will assess it promptly and, where required, within thirty (30) days. If we determine that an eligible data breach has occurred under the Notifiable Data Breaches scheme, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable.
A notification will describe what happened, the kinds of information involved, and the steps we recommend you take. We will publish material incidents affecting the platform on our status page. We may delay notifying you only where a law-enforcement agency or a law requires it.
9. Your rights
You have the right to:
- Request a copy of the personal information we hold about you
- Request correction of inaccurate or out-of-date information
- Request deletion of your account and associated personal information (subject to our retention obligations above)
- Lodge a complaint with the OAIC at oaic.gov.au
To exercise any of these rights, email [email protected] from the address on your account. We may ask you to verify your identity before we release or change anything, so that we are not handing your information to someone else. We will respond within 30 days, and we do not charge for making a request.
Complaints
If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact us first at [email protected] so we can try to resolve it. We will acknowledge your complaint within five (5) business days and aim to provide a written response within 30 days. If we need more time, we will tell you why and give you a revised timeframe.
If you are not satisfied with our response, or we do not respond within a reasonable time, you can escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001.
10. Cookies
The ozvps.com.au public website sets Google Analytics cookies (_ga and similar) to count visits. These are first-party analytics cookies. We do not use advertising or remarketing cookies, and we do not sell or share what they record.
The client area (account.ozvps.com.au) and control panels (the VPS panel and Enhance) set session and security cookies that are essential to the operation of those services and cannot be turned off without breaking them.
You can block or delete cookies in your browser settings at any time. Blocking the analytics cookies does not affect your ability to use the site or your service.
11. Assignment
If OzVPS is involved in a merger, acquisition or sale of assets, your information may be transferred to the successor entity. We will notify you of any change in ownership, and the successor will be bound by the terms of this Privacy Policy or a policy at least as protective.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be announced via the client area and by email. The "Last updated" date at the top of this page reflects the most recent revision.
13. Contact
Privacy enquiries: [email protected].
General enquiries: [email protected].
