Privacy Policy
1. Information Collection and Processing
We collect information necessary for operational continuity and service delivery. This includes your full name, business email address, organizational role, project scope descriptions, and technical infrastructure parameters. Server logs record access timestamps, IP addresses, browser identifiers, and referral URLs for security monitoring and capacity optimization. All data transmission utilizes TLS 1.3 encryption protocols, ensuring cryptographic protection during transit across public networks.
2. Cookies and Local Storage
Our platform utilizes essential cookies to maintain session continuity, preserve layout preferences, and authenticate user interactions. Functional cookies store your consent decisions and interface customizations for 12 months. Analytical cookies track aggregate access patterns to optimize server response times, retaining data for 24 hours. You may withdraw consent at any time through our cookie management interface, though disabling essential cookies will restrict platform functionality.
3. Purposes of Processing
We process personal data solely to fulfill consulting engagements, validate project requirements, generate compliance documentation, and maintain operational security. Legal bases include contractual necessity for service delivery, legitimate interests for infrastructure optimization, and regulatory compliance with Australian privacy legislation. We never sell, lease, or transfer personal information to third-party marketing entities or advertising networks.
4. Data Retention and Deletion
Personal information remains stored only until the specified processing purpose concludes, or as mandated by Australian tax and commercial legislation. Contact form submissions persist for 24 months to support warranty claims and technical support inquiries. Server access logs anonymize after 30 days, removing IP addresses and browser fingerprints. Upon written request, we permanently delete all records within 14 business days, excluding data required for regulatory reporting or legal defense.
5. Security Measures
We implement enterprise-grade security protocols to prevent unauthorized access, modification, or destruction of stored information. Infrastructure includes network segmentation, role-based access controls, automated vulnerability scanning, and quarterly penetration testing by accredited Australian security firms. All administrative systems require multi-factor authentication, and backup repositories maintain identical cryptographic encryption standards as primary databases.
6. Cross-Border Data Transfers
We do not transfer personal data outside Australian jurisdictional boundaries. All processing occurs within state-approved data centers located in Sydney, Melbourne, or Brisbane. Should international cloud infrastructure become necessary for scalability, we ensure appropriate safeguards through standard contractual clauses, binding corporate rules, or explicit user consent prior to cross-border transmission.
7. User Rights Under Australian Law
Under the Privacy Act 1988, you maintain the right to access, correct, or delete your personal information. Submit written requests to [email protected] specifying your identity verification details. We respond within 14 business days, providing data copies in machine-readable formats or confirming deletion completion. Additional rights include lodging complaints with the Office of the Australian Information Commissioner, updating marketing preferences, and requesting automated decision-making transparency.
8. Policy Updates and Contact Information
We reserve the right to modify this privacy policy in response to regulatory amendments or operational shifts. Updated versions publish here with revised effective dates, maintaining historical records for compliance verification. For data protection inquiries, contact our Privacy Officer at [email protected] or mail correspondence to Level 42, Sydney Tower, 100 Market Street, Sydney, NSW 2000, Australia.