Privacy policy

Privacy policy, in plain English

How Austin Technology collects, uses, stores and protects personal information, including the information in client systems we manage. Last updated 9 October 2026.

  • ISO 27001Certified information security management, audited externally every year
  • WAData we host ourselves stays in our three Perth data centres
  • 30 daysThe longest we take to respond to an access, correction or complaint
  • NeverWe do not sell personal information or rent out our contact lists

01At a glance

The short version

The full policy follows below. If you only read one part, read this.

Collect

What we collect

Contact and business details, support and billing records, job applications and how you use our website. We only ask for what we need.

Use

Why we use it

To provide and support our services, keep systems secure, run our business, measure our advertising and, if you agree, send you useful updates.

Share

Who sees it

Our team, the providers and suppliers who help us deliver services, and Google and Meta through the advertising tags on our website. Some process data overseas. We never sell it.

Control

Your choices

Ask to see or correct your information, block advertising cookies, unsubscribe at any time and complain to us or to the OAIC.

In this policy

02Who we are

Who we are and what this covers

Austin Technology is the trading name of Austin IT Pty Ltd (ABN 70 615 425 557), a managed IT services provider at Level 2, 541 Hay Street, Subiaco WA 6008. In this policy, "we", "us" and "our" mean Austin IT Pty Ltd.

We handle personal information in line with the Privacy Act 1988 (Cth), including the Australian Privacy Principles. This policy explains how we do that for:

  • clients, prospective clients and the people who work for them
  • staff of our clients who use the systems we support, for example when they call our service desk
  • people who apply for a job with us
  • suppliers, partners and their contacts
  • people who visit our website or contact us

Information we hold for our clients

When we provide managed IT services, we can access information held in our clients' systems, such as user accounts, email and files, device records and security logs. We handle that information on our client's behalf and only to deliver the services they have engaged us for, under our agreement with them and our confidentiality obligations.

Our client decides what their systems hold and is responsible for their own privacy obligations to the people concerned. If you have a question about information a business holds about you, please contact that business first. We will help them respond.

This policy does not cover the records of our own employees, which the Privacy Act treats separately.

Changes to this policy

We review this policy at least once a year and whenever our practices change. The current version is always on this page, with the date it was last updated.

03What we collect

The information we collect

What we hold depends on how you deal with us.

Clients and business contacts

  • name, job title, organisation, email address, phone numbers and business address
  • records of our dealings with you, such as enquiries, quotes, agreements, emails and meeting notes
  • billing contacts, invoices and payment records
  • your marketing preferences

People who use the systems we support

  • name, contact details, role and the user accounts we manage for you
  • service desk tickets, including the problem you report, our notes and any files you send
  • technical information from managed devices and accounts, such as device names, IP addresses, sign in activity and security alerts
  • any rating or comment you give when a ticket closes

Job applicants

  • your CV, work history, qualifications and certifications
  • referee details and what your referees tell us
  • information about your right to work in Australia and notes from interviews

Website visitors

  • what you enter in our forms
  • technical information such as your IP address, browser and the pages you visit, which our hosting, security and analytics tools record

Sensitive information

We do not ask for sensitive information about you, such as health information, unless it is needed for a specific purpose and you agree, or the law allows it. Some of our clients hold sensitive information in their own systems, for example medical practices. We access it only when a task requires it, under the controls described in section 07.

04How we collect it

How we collect and hold it

How we collect it

Most of the information we hold comes from you: through our website forms, email, phone calls, our client portal, meetings and the documents you send us. We also collect information:

  • from the systems we manage for our clients, through our monitoring, management and security tools
  • from your employer or colleagues, for example when they set up an account for you or log a ticket on your behalf
  • from referees and recruitment agencies, when you apply for a role
  • from suppliers and distributors, for example when we order licences, hardware or internet services for you
  • from public sources such as business websites, LinkedIn and the Australian Business Register
  • automatically, when you visit our website

If we receive information we did not ask for, we check whether we could have collected it. If not, we destroy or de-identify it where it is lawful and reasonable to do so.

How we hold it

We hold information electronically: in our own systems, in AustinCloud (our private cloud in Perth data centres) and with the cloud providers described in section 06. We keep very little on paper.

Dealing with us anonymously

You can browse our website and ask general questions without telling us who you are, or by using a pseudonym. We cannot provide managed services, support you or consider a job application without knowing who you are.

05How we use it

Why we use your information

We use personal information for the purpose we collected it and for related purposes you would reasonably expect, including to:

  • provide, support and improve our services and respond to your requests
  • monitor and protect our own and our clients' systems and respond to security incidents
  • manage accounts, quotes, agreements, billing and payments
  • order licences, hardware and services from suppliers on your behalf
  • measure satisfaction and train our team
  • see which of our pages and ads lead to enquiries, and show our ads to people who have visited our website
  • assess job applications
  • meet our legal, audit and insurance obligations
  • send you updates and invitations, if you have agreed to receive them

Marketing

We send marketing emails only to people who have agreed to receive them or who would reasonably expect them from us. Every marketing email has an unsubscribe link, and we action unsubscribe requests within five working days. You can also opt out by contacting us. Service messages about your account, such as outage notices and invoices, are not marketing and will still reach you.

Feedback and testimonials

When a ticket closes, we ask for a quick rating and optional comment. We use these to measure and improve our service. We publish a review with your name and organisation only with your permission.

Automated decisions

We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests. Our security tools can automatically block a suspicious sign in, quarantine a harmful email or isolate a device to stop an attack on a client's systems. These tools use technical information such as account names, device details, IP addresses and sign in activity, and our engineers can review and reverse their actions.

06Who we share it with

Who we share it with, and why

We share personal information only where it is needed for the purposes in section 05, where you have agreed or where the law requires or allows it. We never sell it.

Who Austin Technology shares personal information with and why
WhoWhyExamples
Technology providersTo run the systems we use to deliver services, such as email, our service desk, customer records, device management, security monitoring, backup and surveysMicrosoft 365, HubSpot and Simplesat. Ask us for the full list of our key providers
Advertising platformsTo measure which of our ads lead to visits and enquiries, and to show our ads to people who have visited our websiteGoogle (Google Ads) and Meta (Facebook and Instagram), through the tags described in section 08
Suppliers and carriersTo order, deliver and support licences, hardware and internet or phone services for youMicrosoft and our licensing distributor, hardware distributors and couriers, nbn and telecommunications carriers
Specialist partnersTo deliver specialist work you have engaged us for, under confidentiality termsOur penetration testing partner
Advisers, auditors and insurersTo get professional advice, pass our certification audits and manage insurance and claimsLawyers, accountants, our ISO certification auditor and our insurers
Government and law enforcementWhen the law requires or allows itThe ATO, the OAIC, the Australian Signals Directorate and police
A buyer of our businessIf we sell or restructure all or part of our business, under confidentiality termsA prospective buyer and their advisers

Information stored or accessed overseas

Some of our providers store or process personal information outside Australia, or have support staff who can access it from overseas. The country most likely to be involved is the United States.

Information we host ourselves, in AustinCloud, stays in our Perth data centres. Our Microsoft 365 data is stored in Microsoft's Australian data centres and our HubSpot account is hosted in HubSpot's Australian region, but both providers can process some data overseas, for example for support and analytics.

Before we use a provider, we check its security and privacy terms and take reasonable steps to make sure it handles personal information consistently with the Australian Privacy Principles.

07How we protect it

Security, retention and breaches

You trust us with access to your systems, so we hold ourselves to the controls we recommend to our clients.

01

Certified security

We are certified to ISO/IEC 27001 for information security management, audited externally by Compass Assurance Services.

ISO 27001 and ISO 9001
02

Controlled access

Our core platforms sit behind single sign on with multi factor authentication, and staff can access only what their role needs.

Single sign on / MFA / least privilege
03

Granular client access

We manage client Microsoft 365 tenants through Microsoft GDAP, which gives engineers specific roles rather than blanket access.

Microsoft GDAP
04

Hosted in Perth

AustinCloud runs in three Perth data centres, with backups on storage that cannot be altered or deleted for 30 days.

Immutable backups
05

Kept only as long as needed

We keep information while we need it for the purposes in this policy or the law requires it, for example financial records for five years. Then we delete, destroy or de-identify it.

Retention and disposal
06

Breaches handled properly

We contain and assess a suspected breach quickly, within 30 days at most, and notify the people affected and the OAIC if it is likely to cause serious harm.

Notifiable Data Breaches scheme

If a breach affects information we hold for a client, we tell the client promptly and work with them on who notifies, as our agreement sets out.

Security and governance

08Our website

Our website and cookies

Cookies are small files a website stores in your browser. These are the tools on our site that collect information or set cookies.

Tools on the Austin Technology website that collect information or set cookies
ToolWhat it doesWhat it collects
Hosting and securityKeeps the site online and blocks attacks and bots, through our hosting provider, Cloudflare and the Sucuri firewallIP address and request details in security logs. Sets the __cf_bm cookie, which expires after 30 minutes of inactivity
HubSpot formsRuns our contact, enquiry and careers forms, hosted in HubSpot's Australian regionWhat you enter in the form, the page you sent it from and technical details
Google AnalyticsShows us which pages are used and which forms and buttons work, through Google Tag ManagerPages visited, device and browser type and approximate location. Sets _ga cookies that last up to two years
Google Ads tagTells us which Google ads lead to visits and enquiries, and lets Google show our ads to people who have visited our siteThe ad you clicked, pages visited and when you send a form. Sets the _gcl_au cookie for 90 days. Google may also use its own cookies, under Google's privacy policy
Meta pixelTells us which Facebook and Instagram ads lead to visits and enquiries, and lets Meta show our ads to people who have visited our sitePages visited, your IP address and browser, and when you send a form. Meta can link this to a Facebook or Instagram account. Sets the _fbp cookie for 90 days, under Meta's privacy policy
Google MapsShows our office location on the contact pageGoogle receives your IP address and may set cookies, under Google's privacy policy
Email security checkLooks up the domain you enter in public DNS, through Cloudflare's resolver, and keeps the result for 15 minutesThe domain you enter. Your IP address is counted for up to a day to stop misuse, and not stored with the domain
Google FontsLoads the typefaces the site usesGoogle receives your IP address when your browser requests the fonts
Cyber readiness scorecardKeeps your answers in your browser, so a refresh or a return visit does not lose themYour answers stay on your device. We see them only if you send the report form, which sends your score and answers with your details through HubSpot

You can block or delete cookies in your browser settings, and use Google's opt out browser extension to stop Google Analytics. To control the ads you see, use My Ad Center in your Google account and Ad preferences in Facebook or Instagram. The site works without analytics or advertising cookies.

09Your rights

See it, correct it or complain

Asking costs nothing. This is how a request or complaint works.

  1. Step 1

    Contact our privacy officer

    Tell us what you would like to see, correct or complain about, using the details in section 10.

  2. Step 2

    We confirm who you are

    We check your identity before we release or change anything, so your information stays protected.

  3. Within 30 days

    We respond

    We give you access, make the correction or respond to your complaint. If we cannot, we explain why in writing.

  4. If needed

    Take it to the OAIC

    If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.

The detail

Access. You can ask for the personal information we hold about you. There is no charge to ask. If giving access takes significant work, we may charge a reasonable fee and will tell you before we start. We can refuse access only where the Privacy Act allows, for example where it would affect someone else's privacy.

Correction. If information we hold is wrong, out of date or incomplete, tell us and we will correct it at no charge. If we disagree, we will explain why and, if you ask, note your view with the record.

Information in a client's systems. For information held in systems we manage for a business, please contact that business first. We will help them respond.

Complaints. Please complain to us in writing first. We will acknowledge your complaint, investigate and respond within 30 days. If you are not satisfied, or we have not responded within 30 days, you can lodge a complaint with the OAIC at oaic.gov.au or on 1300 363 992.

10Requests and complaints

Contact our privacy officer

For any question, request or complaint about personal information, contact our privacy officer. Include your name, how to reach you and what your request is about.

  1. 01
  2. 02
    Post. Privacy Officer, Austin IT Pty Ltd, Level 2, 541 Hay Street, Subiaco WA 6008
  3. 03
    Still not resolved? Contact the OAIC at oaic.gov.au or on 1300 363 992.
Call us 1300 787 429

Monday to Friday, business hours. Ask for our privacy officer.

11Privacy

A question about
your information?

Email or call and ask for our privacy officer. We respond to every request and complaint within 30 days.

Level 2, 541 Hay Street, Subiaco WA 6008 Onsite across the Perth metro area. Remote support across regional WA and Australia.