Privacy policy
Privacy policy, in plain English
How Austin Technology collects, uses, stores and protects personal information, including the information in client systems we manage. Last updated 9 October 2026.
- ISO 27001Certified information security management, audited externally every year
- WAData we host ourselves stays in our three Perth data centres
- 30 daysThe longest we take to respond to an access, correction or complaint
- NeverWe do not sell personal information or rent out our contact lists
01At a glance
The short version
The full policy follows below. If you only read one part, read this.
What we collect
Contact and business details, support and billing records, job applications and how you use our website. We only ask for what we need.
Why we use it
To provide and support our services, keep systems secure, run our business, measure our advertising and, if you agree, send you useful updates.
Who sees it
Our team, the providers and suppliers who help us deliver services, and Google and Meta through the advertising tags on our website. Some process data overseas. We never sell it.
Your choices
Ask to see or correct your information, block advertising cookies, unsubscribe at any time and complain to us or to the OAIC.
In this policy
02Who we are
Who we are and what this covers
Austin Technology is the trading name of Austin IT Pty Ltd (ABN 70 615 425 557), a managed IT services provider at Level 2, 541 Hay Street, Subiaco WA 6008. In this policy, "we", "us" and "our" mean Austin IT Pty Ltd.
We handle personal information in line with the Privacy Act 1988 (Cth), including the Australian Privacy Principles. This policy explains how we do that for:
- clients, prospective clients and the people who work for them
- staff of our clients who use the systems we support, for example when they call our service desk
- people who apply for a job with us
- suppliers, partners and their contacts
- people who visit our website or contact us
Information we hold for our clients
When we provide managed IT services, we can access information held in our clients' systems, such as user accounts, email and files, device records and security logs. We handle that information on our client's behalf and only to deliver the services they have engaged us for, under our agreement with them and our confidentiality obligations.
Our client decides what their systems hold and is responsible for their own privacy obligations to the people concerned. If you have a question about information a business holds about you, please contact that business first. We will help them respond.
This policy does not cover the records of our own employees, which the Privacy Act treats separately.
Changes to this policy
We review this policy at least once a year and whenever our practices change. The current version is always on this page, with the date it was last updated.
03What we collect
The information we collect
What we hold depends on how you deal with us.
Clients and business contacts
- name, job title, organisation, email address, phone numbers and business address
- records of our dealings with you, such as enquiries, quotes, agreements, emails and meeting notes
- billing contacts, invoices and payment records
- your marketing preferences
People who use the systems we support
- name, contact details, role and the user accounts we manage for you
- service desk tickets, including the problem you report, our notes and any files you send
- technical information from managed devices and accounts, such as device names, IP addresses, sign in activity and security alerts
- any rating or comment you give when a ticket closes
Job applicants
- your CV, work history, qualifications and certifications
- referee details and what your referees tell us
- information about your right to work in Australia and notes from interviews
Website visitors
- what you enter in our forms
- technical information such as your IP address, browser and the pages you visit, which our hosting, security and analytics tools record
Sensitive information
We do not ask for sensitive information about you, such as health information, unless it is needed for a specific purpose and you agree, or the law allows it. Some of our clients hold sensitive information in their own systems, for example medical practices. We access it only when a task requires it, under the controls described in section 07.
04How we collect it
How we collect and hold it
How we collect it
Most of the information we hold comes from you: through our website forms, email, phone calls, our client portal, meetings and the documents you send us. We also collect information:
- from the systems we manage for our clients, through our monitoring, management and security tools
- from your employer or colleagues, for example when they set up an account for you or log a ticket on your behalf
- from referees and recruitment agencies, when you apply for a role
- from suppliers and distributors, for example when we order licences, hardware or internet services for you
- from public sources such as business websites, LinkedIn and the Australian Business Register
- automatically, when you visit our website
If we receive information we did not ask for, we check whether we could have collected it. If not, we destroy or de-identify it where it is lawful and reasonable to do so.
How we hold it
We hold information electronically: in our own systems, in AustinCloud (our private cloud in Perth data centres) and with the cloud providers described in section 06. We keep very little on paper.
Dealing with us anonymously
You can browse our website and ask general questions without telling us who you are, or by using a pseudonym. We cannot provide managed services, support you or consider a job application without knowing who you are.
05How we use it
Why we use your information
We use personal information for the purpose we collected it and for related purposes you would reasonably expect, including to:
- provide, support and improve our services and respond to your requests
- monitor and protect our own and our clients' systems and respond to security incidents
- manage accounts, quotes, agreements, billing and payments
- order licences, hardware and services from suppliers on your behalf
- measure satisfaction and train our team
- see which of our pages and ads lead to enquiries, and show our ads to people who have visited our website
- assess job applications
- meet our legal, audit and insurance obligations
- send you updates and invitations, if you have agreed to receive them
Marketing
We send marketing emails only to people who have agreed to receive them or who would reasonably expect them from us. Every marketing email has an unsubscribe link, and we action unsubscribe requests within five working days. You can also opt out by contacting us. Service messages about your account, such as outage notices and invoices, are not marketing and will still reach you.
Feedback and testimonials
When a ticket closes, we ask for a quick rating and optional comment. We use these to measure and improve our service. We publish a review with your name and organisation only with your permission.
Automated decisions
We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests. Our security tools can automatically block a suspicious sign in, quarantine a harmful email or isolate a device to stop an attack on a client's systems. These tools use technical information such as account names, device details, IP addresses and sign in activity, and our engineers can review and reverse their actions.
06Who we share it with
Who we share it with, and why
We share personal information only where it is needed for the purposes in section 05, where you have agreed or where the law requires or allows it. We never sell it.
| Who | Why | Examples |
|---|---|---|
| Technology providers | To run the systems we use to deliver services, such as email, our service desk, customer records, device management, security monitoring, backup and surveys | Microsoft 365, HubSpot and Simplesat. Ask us for the full list of our key providers |
| Advertising platforms | To measure which of our ads lead to visits and enquiries, and to show our ads to people who have visited our website | Google (Google Ads) and Meta (Facebook and Instagram), through the tags described in section 08 |
| Suppliers and carriers | To order, deliver and support licences, hardware and internet or phone services for you | Microsoft and our licensing distributor, hardware distributors and couriers, nbn and telecommunications carriers |
| Specialist partners | To deliver specialist work you have engaged us for, under confidentiality terms | Our penetration testing partner |
| Advisers, auditors and insurers | To get professional advice, pass our certification audits and manage insurance and claims | Lawyers, accountants, our ISO certification auditor and our insurers |
| Government and law enforcement | When the law requires or allows it | The ATO, the OAIC, the Australian Signals Directorate and police |
| A buyer of our business | If we sell or restructure all or part of our business, under confidentiality terms | A prospective buyer and their advisers |
Information stored or accessed overseas
Some of our providers store or process personal information outside Australia, or have support staff who can access it from overseas. The country most likely to be involved is the United States.
Information we host ourselves, in AustinCloud, stays in our Perth data centres. Our Microsoft 365 data is stored in Microsoft's Australian data centres and our HubSpot account is hosted in HubSpot's Australian region, but both providers can process some data overseas, for example for support and analytics.
Before we use a provider, we check its security and privacy terms and take reasonable steps to make sure it handles personal information consistently with the Australian Privacy Principles.
07How we protect it
Security, retention and breaches
You trust us with access to your systems, so we hold ourselves to the controls we recommend to our clients.
Certified security
We are certified to ISO/IEC 27001 for information security management, audited externally by Compass Assurance Services.
ISO 27001 and ISO 9001Controlled access
Our core platforms sit behind single sign on with multi factor authentication, and staff can access only what their role needs.
Single sign on / MFA / least privilegeGranular client access
We manage client Microsoft 365 tenants through Microsoft GDAP, which gives engineers specific roles rather than blanket access.
Microsoft GDAPHosted in Perth
AustinCloud runs in three Perth data centres, with backups on storage that cannot be altered or deleted for 30 days.
Immutable backupsKept only as long as needed
We keep information while we need it for the purposes in this policy or the law requires it, for example financial records for five years. Then we delete, destroy or de-identify it.
Retention and disposalBreaches handled properly
We contain and assess a suspected breach quickly, within 30 days at most, and notify the people affected and the OAIC if it is likely to cause serious harm.
Notifiable Data Breaches schemeIf a breach affects information we hold for a client, we tell the client promptly and work with them on who notifies, as our agreement sets out.
Security and governance08Our website
Our website and cookies
Cookies are small files a website stores in your browser. These are the tools on our site that collect information or set cookies.
| Tool | What it does | What it collects |
|---|---|---|
| Hosting and security | Keeps the site online and blocks attacks and bots, through our hosting provider, Cloudflare and the Sucuri firewall | IP address and request details in security logs. Sets the __cf_bm cookie, which expires after 30 minutes of inactivity |
| HubSpot forms | Runs our contact, enquiry and careers forms, hosted in HubSpot's Australian region | What you enter in the form, the page you sent it from and technical details |
| Google Analytics | Shows us which pages are used and which forms and buttons work, through Google Tag Manager | Pages visited, device and browser type and approximate location. Sets _ga cookies that last up to two years |
| Google Ads tag | Tells us which Google ads lead to visits and enquiries, and lets Google show our ads to people who have visited our site | The ad you clicked, pages visited and when you send a form. Sets the _gcl_au cookie for 90 days. Google may also use its own cookies, under Google's privacy policy |
| Meta pixel | Tells us which Facebook and Instagram ads lead to visits and enquiries, and lets Meta show our ads to people who have visited our site | Pages visited, your IP address and browser, and when you send a form. Meta can link this to a Facebook or Instagram account. Sets the _fbp cookie for 90 days, under Meta's privacy policy |
| Google Maps | Shows our office location on the contact page | Google receives your IP address and may set cookies, under Google's privacy policy |
| Email security check | Looks up the domain you enter in public DNS, through Cloudflare's resolver, and keeps the result for 15 minutes | The domain you enter. Your IP address is counted for up to a day to stop misuse, and not stored with the domain |
| Google Fonts | Loads the typefaces the site uses | Google receives your IP address when your browser requests the fonts |
| Cyber readiness scorecard | Keeps your answers in your browser, so a refresh or a return visit does not lose them | Your answers stay on your device. We see them only if you send the report form, which sends your score and answers with your details through HubSpot |
You can block or delete cookies in your browser settings, and use Google's opt out browser extension to stop Google Analytics. To control the ads you see, use My Ad Center in your Google account and Ad preferences in Facebook or Instagram. The site works without analytics or advertising cookies.
09Your rights
See it, correct it or complain
Asking costs nothing. This is how a request or complaint works.
- Step 1
Contact our privacy officer
Tell us what you would like to see, correct or complain about, using the details in section 10.
- Step 2
We confirm who you are
We check your identity before we release or change anything, so your information stays protected.
- Within 30 days
We respond
We give you access, make the correction or respond to your complaint. If we cannot, we explain why in writing.
- If needed
Take it to the OAIC
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.
The detail
Access. You can ask for the personal information we hold about you. There is no charge to ask. If giving access takes significant work, we may charge a reasonable fee and will tell you before we start. We can refuse access only where the Privacy Act allows, for example where it would affect someone else's privacy.
Correction. If information we hold is wrong, out of date or incomplete, tell us and we will correct it at no charge. If we disagree, we will explain why and, if you ask, note your view with the record.
Information in a client's systems. For information held in systems we manage for a business, please contact that business first. We will help them respond.
Complaints. Please complain to us in writing first. We will acknowledge your complaint, investigate and respond within 30 days. If you are not satisfied, or we have not responded within 30 days, you can lodge a complaint with the OAIC at oaic.gov.au or on 1300 363 992.
10Requests and complaints
Contact our privacy officer
For any question, request or complaint about personal information, contact our privacy officer. Include your name, how to reach you and what your request is about.
- 01
- 02Post. Privacy Officer, Austin IT Pty Ltd, Level 2, 541 Hay Street, Subiaco WA 6008
- 03Still not resolved? Contact the OAIC at oaic.gov.au or on 1300 363 992.
Monday to Friday, business hours. Ask for our privacy officer.
11Privacy
A question about
your information?
Email or call and ask for our privacy officer. We respond to every request and complaint within 30 days.