Home / Privacy Policy
Legal & Compliance

Privacy
Policy.

Cyber Compliance Pro (ABN 86 711 059 645) is committed to protecting your personal information in accordance with Australian privacy law.

Quick answer: Cyber Compliance Pro's Privacy Policy explains what personal information it collects, why, how it's stored and secured, and the rights individuals have under the Australian Privacy Act and the Australian Privacy Principles.
Version 2.0
Effective: 30 July 2026
Classification: Public
Document Control
Owner Privacy Officer
Approved By Managing Director
Review Annual or upon legislative change
Applies To All staff, contractors and service providers
Classification Public
Version 2.0 — Effective 30 July 2026

1 Purpose of This Privacy Policy

Cyber Compliance Pro (ABN 86 711 059 645) is committed to protecting the privacy, confidentiality and security of personal information. This privacy policy explains how we collect, use, disclose, retain and protect personal information in accordance with the Privacy Act 1988 (Cth), Australian Privacy Principles (APPs), the Notifiable Data Breaches Scheme, and where applicable the Victorian Privacy and Data Protection Act 2014 and the Victorian Protective Data Security Standards (VPDSS).

As an information technology and cybersecurity services provider we recognise that clients entrust us with access to business systems and information. We implement governance, technical and operational controls designed to safeguard that information.

2 Scope

This privacy policy applies to visitors to our website, prospective customers, existing customers, suppliers, contractors, employees, job applicants and authorised users of our managed services.

Services include Managed IT Services, Cybersecurity, Microsoft 365, Azure, Cloud Solutions, Telephony (VoIP), Website Design and Hosting, Network Infrastructure, Backup and Disaster Recovery, Security Monitoring, Professional Services and 24/7 Helpdesk.

3 Legislative Framework

This privacy policy is designed to support compliance with:

  • Privacy Act 1988 (Cth)
  • Australian Privacy Principles
  • Notifiable Data Breaches Scheme
  • Spam Act 2003
  • Victorian Privacy and Data Protection Act 2014 (where applicable)
  • Victorian Protective Data Security Standards (where applicable)
  • Industry good practice including ISO/IEC 27001:2022, ISO/IEC 27701 and ACSC Essential Eight

4 Personal Information We Collect

Depending upon the services provided we may collect names, business contact details, identity verification information, email addresses, telephone numbers, IP addresses, audit logs, authentication records, device identifiers, support tickets, billing information, contracts, website usage information, call metadata, and information necessary to provide contracted services.

5 How We Collect Information

Information may be collected directly from you, through our website, contact forms, cookies, service desk, remote support sessions, monitoring tools, cloud services, suppliers, publicly available sources or where authorised by our customers.

6 Why We Collect Information

We collect information to deliver services, manage customer relationships, provide support, improve services, detect and respond to cyber threats, meet contractual obligations, comply with legal requirements, process payments and communicate with customers.

7 Security of Information

We maintain layered security controls including encryption, multifactor authentication, privileged access management, endpoint protection, secure remote administration, vulnerability management, security monitoring, logging, backup and disaster recovery, supplier due diligence, secure software configuration, staff training and regular policy reviews.

8 Managed Service Provider Responsibilities

Where we process information on behalf of customers we act only in accordance with contractual instructions unless required by law. Customers remain responsible for determining the purposes of processing their information.

9 Cloud, Microsoft 365 and VoIP

Cloud platforms may process data within Australia or other jurisdictions depending upon selected services. We undertake supplier due diligence and contractual reviews to ensure appropriate safeguards. VoIP services may generate call records, quality metrics and billing information necessary for service delivery.

10 Website, Cookies and Analytics

Our website uses cookies and similar technologies to improve functionality, understand website performance and enhance user experience. Users may configure browser settings to limit cookies, although this may affect website functionality.

11 Overseas Disclosure

Where overseas disclosure occurs we take reasonable steps to ensure recipients provide protections comparable to Australian privacy obligations through contractual commitments and security assessments.

12 Data Retention and Disposal

Information is retained only for legitimate business, contractual and regulatory purposes. When no longer required, information is securely destroyed, anonymised or de-identified using recognised industry practices.

13 Notifiable Data Breaches

Security incidents are assessed through documented incident response procedures. Where an eligible data breach occurs we comply with notification obligations under Australian law and contractual requirements.

14 Victorian Government Customers

Where services are supplied to Victorian public sector organisations we support customer obligations under the Victorian Protective Data Security Standards through governance, information classification, access control, audit logging, incident management, supplier security and secure disposal controls. Compliance with VPDSS remains the responsibility of the relevant public sector organisation.

15 Your Rights

Individuals may request access to or correction of their personal information, subject to lawful exceptions. Requests are verified before processing.

16 Complaints

Complaints should be submitted to our Privacy Officer. We aim to acknowledge complaints within five business days and provide a substantive response within thirty days. If you are not satisfied you may contact the Office of the Australian Information Commissioner.

17 Privacy Policy Review

This policy is reviewed annually or whenever legislative, regulatory or business changes require updates.

18 Contact Details

For privacy-related enquiries please contact our Privacy Officer:

Cyber Compliance Pro (ABN 86 711 059 645)
Appendix A

Security Controls

  • Multi-factor authentication
  • Least privilege access
  • Privileged account management
  • Endpoint protection
  • Patch and vulnerability management
  • Encrypted backups
  • Business continuity and disaster recovery
  • Secure remote support
  • Security awareness training
  • Supplier risk management
  • Audit logging
  • Change management
  • Incident response
Appendix B

Privacy Principles Summary

Cyber Compliance Pro maintains policies and procedures to support compliance with each of the following Australian Privacy Principles in the delivery of its services.

APP 1

Open and transparent management of personal information

APP 2

Anonymity and pseudonymity

APP 3

Collection of solicited personal information

APP 4

Dealing with unsolicited personal information

APP 5

Notification of the collection of personal information

APP 6

Use or disclosure of personal information

APP 7

Direct marketing

APP 8

Cross-border disclosure of personal information

APP 9

Adoption, use or disclosure of government related identifiers

APP 10

Quality of personal information

APP 11

Security of personal information

APP 12

Access to personal information

APP 13

Correction of personal information