Privacy Policy

Ready. Robust. Resilient. Ready. Robust. Resilient. Ready. Robust. Resilient.

Privacy Policy

Effective date: 1 July 2026
Last reviewed: 1 July 2026
Website owner: Australian Cyber Essentials Pty Ltd
Website: australiancyberessentials.com.au

Australian Cyber Essentials Pty Ltd (ACN 698 774 953) (referred to as Australian Cyber Essentials, ACE, we, our, or us) respects your privacy and is committed to handling personal information in an open, transparent, and secure way.

In this Privacy Policy, you refers to any individual about whom we collect personal information.

This Privacy Policy explains how we collect, hold, use, disclose, store, and protect your personal information when you use our website, contact us, submit an enquiry, use our services, or otherwise interact with us.

This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), where those laws apply to us.

1. Scope of this Privacy Policy

This Privacy Policy applies to personal information collected through:

  • our website;
  • online enquiry forms;
  • email, telephone, or other direct communications with us;
  • website analytics, cookies, and similar technologies;
  • interactions with our service providers, where relevant;
  • services we provide to organisations; and
  • any other dealings you have with us in connection with our services.

This Privacy Policy does not apply to third-party websites that may be linked from our website. Those websites are responsible for their own privacy practices.

2. What is personal information?

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether it is recorded in a material form or not.

Examples include a person’s name, email address, phone number, business contact details, IP address where it can identify a person, and information submitted in an enquiry.

Sensitive information is a category of personal information and includes information about a person’s health, racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, sexual orientation, criminal record, biometric information, or membership of a professional or trade association or union.

3. What personal information we collect

We collect information about you and your interactions with us. The types of personal information we collect will depend on our dealings with you, but may include:

  • your name;
  • your email address;
  • your phone number;
  • your residential, mailing, or business address;
  • your job title, occupation, or role;
  • your business or organisation name;
  • information you provide through enquiries, surveys, social media, online forms, emails, or messages;
  • your history of purchases and use of our services;
  • testimonials and feedback; and
  • any other personal information you choose to provide to us.

We may also collect limited technical and usage information when you interact with our website, including:

  • IP address;
  • browser type and version;
  • device type and operating system;
  • pages visited;
  • date and time of access;
  • referring website;
  • approximate location derived from IP address;
  • website usage and interaction data; and
  • cookie or analytics identifiers.
4. Information we may handle when providing services

When providing services to organisations, we may handle information provided by or generated in connection with those organisations, their personnel, systems, training activities, assessments, or business processes.

This may include business contact information, assessment responses, training records, technical information, system or domain information, security-related information, and other information relevant to the services we provide.

Some of this information may contain personal information. Where information is about an identified or reasonably identifiable individual, we treat it as personal information and handle it in accordance with this Privacy Policy.

Where we handle information on behalf of a client, we will usually do so in accordance with our contract, the client’s lawful instructions, and applicable legal obligations. The client may remain primarily responsible for notifying its own personnel, customers, or other individuals about how their personal information is handled within the client’s systems, applications, networks, or business processes.

This Privacy Policy does not replace a client’s own privacy policy or collection notices.

5. Sensitive information

We do not intentionally collect sensitive information through our website.

Please do not submit sensitive information, confidential business information, security credentials, passwords, access keys, vulnerability details, legal advice, regulated data, or other highly confidential information through our website enquiry form unless we have specifically requested it and appropriate safeguards have been agreed.

If you provide sensitive information to us without being asked, we will handle it in accordance with applicable privacy laws and may delete, destroy, or de-identify it where we are not required to retain it.

6. Children and young people

Our website and services are intended for business and organisational users. We do not knowingly collect personal information from children through our website.

If we become aware that we have collected personal information from a child without appropriate authority, we will take reasonable steps to delete or de-identify that information, unless we are required or authorised by law to retain it.

Where we provide services to a client that involve children or young people, we will handle relevant personal information in accordance with our contract, the client’s lawful instructions, and applicable legal obligations.

7. If you do not provide us with your personal information

You do not have to provide us with your personal information.

However, if you do not provide us with your personal information, we may not be able to provide you with our services, communicate with you, or respond to your enquiries.

8. How we collect personal information

Where reasonable and practicable, we collect personal information directly from you.

We may collect personal information:

  • when you submit an enquiry through our website;
  • when you contact us by email, telephone, or another communication channel;
  • when you request information about our services;
  • when you interact with our website;
  • through cookies, pixels, tags, analytics tools, and similar technologies;
  • from our website hosting, email, security, or analytics providers;
  • when you participate in events we host, manage, or are involved with;
  • from affiliated or related companies;
  • from third-party suppliers and contractors who assist us to operate our business;
  • from sponsors, business partners, or event organisers;
  • from publicly available sources, where relevant and lawful; and
  • from third parties where you have authorised the disclosure, or where collection is otherwise permitted by law.
9. Events that we manage or deliver

If you participate in an event that we manage, host, or deliver, we may take photographs, video recordings, or audio-visual recordings that identify you.

We may use that media for event reporting, business, educational, and promotional purposes, including on our website and social media platforms.

Where relevant, we may provide that media to event sponsors or partners for similar purposes.

10. Why we collect, hold, use, and disclose personal information

The purposes for which we collect, hold, use, and disclose personal information depend on the nature of your interaction with us, but may include:

  • responding to your enquiries;
  • communicating with you about our services;
  • providing requested information;
  • arranging consultations, calls, or meetings;
  • assessing whether our services may be suitable for your organisation;
  • providing services to you or your organisation;
  • administering training, awareness, assessment, reporting, and related services;
  • managing client relationships and service delivery;
  • providing customer support;
  • managing our business operations;
  • improving our website, services, and user experience;
  • monitoring website performance, availability, and security;
  • detecting, investigating, and responding to cyber security events;
  • protecting our legal rights and business interests;
  • maintaining accurate business, financial, contractual, and audit records;
  • complying with legal, regulatory, insurance, and professional obligations; and
  • any other purpose notified to you at the time of collection, or otherwise permitted by law.

We may also use de-identified or aggregated information for reporting, analytics, benchmarking, service improvement, and business planning. We will take reasonable steps to ensure that de-identified information does not identify an individual.

We do not currently offer customer accounts, memberships, payment processing, or online purchasing through this website.

11. Direct marketing

We may use or disclose your business contact details to send you information about our services, updates, events, resources, or other opportunities that may interest you, where permitted by law.

We will only send electronic marketing communications in accordance with applicable laws, including the Spam Act 2003 (Cth).

You may opt out of receiving marketing communications from us at any time by using the unsubscribe function in the marketing communication or by contacting us using the contact details below.

We do not sell personal information to third parties for marketing purposes.

12. Cookies and website analytics

Our website may use cookies and similar technologies to support website functionality, improve user experience, analyse website traffic, and monitor website performance and security.

A cookie is a small file stored on your computer’s browser, which assists in managing customised settings of the website and delivering content.

Cookies and similar technologies may collect information such as:

  • pages visited;
  • time spent on pages;
  • links clicked;
  • referring website;
  • browser and device information;
  • approximate location based on IP address; and
  • repeat website visits.

We may use third-party analytics services, such as Google Analytics or similar tools, to help us understand how visitors use our website.

You can usually configure your browser to block, delete, or manage cookies. Some parts of the website may not function properly if cookies are disabled.

Where required, we will provide additional cookie notices or consent options.

13. Automated decision-making and artificial intelligence assisted tools

We may use technology tools, including commercially available artificial intelligence (AI) tools, to support business administration, website improvement, cyber security monitoring, customer support, document drafting, data analysis, service improvement, and other business purposes.

Where we use AI or automated tools, we take reasonable steps to ensure that personal information is handled lawfully, securely, and consistently with this Privacy Policy.

We do not knowingly input sensitive information, confidential client information, passwords, access credentials, security keys, regulated data, or other highly confidential information into public AI tools unless appropriate safeguards have been assessed and implemented.

We do not currently use computer programs to make decisions that could reasonably be expected to significantly affect an individual’s rights or interests.

If we use, or arrange for the use of, a computer program to make, or do something substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests, and personal information is used in that program, we will update this Privacy Policy in accordance with applicable Privacy Act requirements.

14. Disclosure of personal information

We may disclose personal information to third parties where reasonably necessary for the purposes described in this Privacy Policy, including:

  • website hosting providers;
  • cloud, email, and productivity service providers;
  • information technology and cyber security service providers;
  • website maintenance and support providers;
  • online form, spam prevention, and communication service providers;
  • analytics and website performance providers;
  • customer relationship management and administrative system providers;
  • training, event, and business administration providers;
  • payment, billing, and finance service providers;
  • professional advisers, including lawyers, accountants, auditors, and insurers;
  • contractors and consultants assisting us to provide services;
  • government, regulatory, or law enforcement bodies where required or authorised by law;
  • third parties involved in a business sale, restructure, merger, acquisition, financing, or due diligence process; and
  • any other third party where you have consented, or where disclosure is otherwise permitted by law.

We do not sell personal information.

We take reasonable steps to ensure that third parties who handle personal information on our behalf protect that information and use it only for authorised purposes.

15. Overseas disclosure

Some of our service providers, technology vendors, cloud providers, or support providers may store, access, or process personal information outside Australia.

The countries in which personal information may be handled can change depending on the systems and providers used. The countries in which overseas recipients are likely to be located may include Australia, New Zealand, the United States, the United Kingdom, member countries of the European Economic Area, Singapore, and other countries where our service providers or their approved sub-processors operate.

Where we disclose personal information overseas, we take reasonable steps to ensure that overseas recipients handle personal information in a way that is consistent with the Australian Privacy Principles, unless an exception applies under the Privacy Act.

These steps may include:

  • reviewing provider privacy and security practices;
  • using contractual privacy, confidentiality, and security obligations;
  • selecting reputable service providers;
  • limiting the personal information disclosed;
  • applying access controls;
  • monitoring provider arrangements where reasonable; and
  • requiring providers to use appropriate safeguards when engaging sub-processors.

Where our clients require specific data residency or overseas disclosure arrangements, these should be addressed in the relevant service agreement, proposal, statement of work, or other written agreement.

16. Storage and security of personal information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, unauthorised modification, and unauthorised disclosure.

Our safeguards may include technical, organisational, and administrative controls such as:

  • secure website hosting and system configuration;
  • access controls and least-privilege permissions;
  • multi-factor authentication where appropriate;
  • encryption in transit and, where appropriate, encryption at rest;
  • endpoint, network, and cloud security controls;
  • security monitoring, logging, and alerting;
  • vulnerability management and security maintenance;
  • secure configuration practices;
  • backup and recovery controls;
  • staff privacy and cyber security awareness training;
  • confidentiality obligations for personnel and service providers;
  • supplier security review and contractual controls;
  • incident response and data breach assessment processes; and
  • secure disposal and retention processes.

We limit access to personal information to personnel, contractors, and service providers who need access for authorised business purposes.

Although we take reasonable steps to protect personal information, no method of transmission over the internet or electronic storage is completely secure, and we cannot guarantee absolute security.

17. Data breaches

If we become aware of a suspected or actual data breach involving personal information, we will assess and respond to the incident in accordance with our legal obligations and incident response processes.

We aim to assess a suspected eligible data breach as soon as practicable, and in any event within 30 days of becoming aware of the suspected breach.

Where the Notifiable Data Breaches (NDB) scheme applies, we will assess whether the breach is likely to result in serious harm to affected individuals. If an eligible data breach has occurred, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.

Where we handle information on behalf of a client, we will work with the client in accordance with the applicable contract and incident response arrangements.

18. Data quality

We take reasonable steps to ensure that the personal information we collect, use, and disclose is accurate, up to date, complete, and relevant for the purpose for which it is handled.

You can help us by advising us if your personal information changes or if you believe information we hold about you is incorrect.

19. How long we keep personal information

We keep personal information only for as long as reasonably necessary for the purposes for which it was collected, including for business, legal, regulatory, accounting, insurance, dispute resolution, and record-keeping purposes.

Retention periods may vary depending on the type of information, the service provided, contractual requirements, legal obligations, and operational need.

Assessment records, training records, security-related records, incident records, service records, and business relationship records may be retained for periods reasonably required for cyber security, audit, insurance, contractual, legal, and evidentiary purposes.

When personal information is no longer required, we will take reasonable steps to destroy or de-identify it, unless we are required or authorised by law to retain it.

20. Access to personal information

You may request access to personal information we hold about you.

To make an access request, please contact us using the details below.

We may need to verify your identity before responding to your request.

In some circumstances, and where permitted by law, we may refuse your request for access to the personal information we hold about you, such as where access would unreasonably affect another person’s privacy, prejudice security, reveal commercially sensitive information, or be otherwise unlawful.

If we refuse access, we will provide reasons where reasonable and legally appropriate.

Where we hold personal information on behalf of a client, we may need to refer an access request to that client or consult with the client before responding.

21. Correction of personal information

You may request that we correct personal information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading.

If we are satisfied that correction is required, we will take reasonable steps to correct the information.

If we do not agree to a correction request, we will explain the reasons where reasonable and legally appropriate.

You may ask us to associate a statement with the information noting that you consider it to be inaccurate, out of date, incomplete, irrelevant, or misleading.

Where we hold personal information on behalf of a client, we may need to refer a correction request to that client or consult with the client before responding.

22. Anonymity and pseudonymity

Where lawful and practicable, you may interact with us anonymously or using a pseudonym.

However, in many cases, we will need your name and contact details to respond to an enquiry, provide information, manage a business relationship, deliver services, investigate a security matter, or meet legal and administrative requirements.

It is generally not practicable for us to deal with individuals anonymously or pseudonymously on an ongoing basis.

23. Government identifiers

We do not adopt, use, or disclose government-related identifiers, such as tax file numbers or Medicare numbers, as our own identifiers unless permitted or required by law.

24. Employee records

This Privacy Policy applies to personal information we collect about job applicants, contractors, and prospective personnel.

In some circumstances, the Privacy Act contains an exemption for employee records that are directly related to a current or former employment relationship. Where the exemption applies, we may rely on it.

We will still take reasonable steps to handle employee information securely and appropriately.

25. Third-party websites and services

Our website may contain links to third-party websites, platforms, or services.

We are not responsible for, and make no representations or warranties about, the privacy or security practices, content, or operation of third-party websites or services.

If you access a link on our website, those websites and services will be governed by their own privacy policies and terms of use.

You should review the privacy policies of those third parties before providing personal information to them.

26. Complaints

If you have a complaint about how we handle personal information, please contact us using the details below.

Please include enough information for us to understand and respond to your complaint.

We will acknowledge your complaint within a reasonable period and aim to respond within 30 days of receiving the information we reasonably need to assess it. If we need more time, we will let you know.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Telephone: 1300 363 992

27. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our practices, services, technologies, legal obligations, or regulatory guidance.

The updated version will be published on our website and will take effect from the date stated in the updated policy.

28. Contact us

If you have any questions about this Privacy Policy, or if you wish to request access to or correction of your personal information, please contact us using the following details:

Australian Cyber Essentials Pty Ltd
Website: australiancyberessentials.com.au
Email: privacy@australiancyberessentials.com.au
Phone: 1300 077 022
Postal address: 16 Nexus Way, Southport QLD 4215