Last Updated: 16 June 2026
This Privacy Policy (Privacy Policy or Policy) outlines how your information is collected, used, stored and disclosed when you access or use our Website and Services as defined in our website terms and conditions (Terms). This information is collected, used, stored and disclosed in accordance with the Privacy Act 1988 (Cth) (Privacy Act).
This Privacy Policy is incorporated by reference into our Terms and any applicable order forms, statements of work or agreements. Any capitalised terms not defined in this Policy are defined in the Terms. You agree to comply with all Terms when accessing or using our Website and Services, including this Privacy Policy.
Our payment processing is handled by third-party payment processors. Any Personal Information collected, stored and processed by those processors is governed by their own terms and conditions and privacy policy. We may also use this Personal Information for the purposes as set out in this Policy and in accordance with the terms set out in this Policy.
We collect Personal Information, as defined in the Privacy Act (including Sensitive Information as defined in the Privacy Act), when you access or use our Website and Services. We do not generally collect Sensitive Information through ordinary website use, standard business enquiries or online assessment forms. Sensitive Information may be incidentally accessed or processed where it is provided to us, contained within client systems, tickets, files, emails, logs or service environments, or reasonably necessary for the Services.
We collect information that you provide to us via use of our Website and Services as well as through any other means used to contact us.
Depending on the nature of your dealings with us and the services we provide, the information we collect may include the following.
The kinds of Personal Information we collect include:
We reserve the right to maintain, store and use any information or data provided by you where we reasonably believe that such action is required to comply with any legal or regulatory obligations, to prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including provision of Services, collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.
We automatically record information from your device and its software when you access our Website and Services, including your IP address, browser and device type, internet service provider, mobile phone carrier, platform type, the website from which you came and the website to which you are going when you leave our Website, date and time stamp and cookies that may uniquely identify your browser or account.
When accessing our Website or Services using a mobile device, we may also receive and collect identification numbers associated with your device, mobile carrier, device type and manufacturer, and, if enabled, geographical location data (including GPS). Please note that some of the information we collect, for example an IP address, can sometimes be used to approximate a device's location.
Our Website may use small pieces of data called cookies to identify a user who engages with our Website and to compile records of a user’s history of engaging with our Website. Cookies are stored by a user’s browser while the user browses a website. Cookies do not usually contain information that personally identifies a person, but each time the user visits the website, the browser sends the cookie data back to the server to notify the system of the user's previous activity. If you wish to disable cookies, you may do so through your browser settings. However, please be aware that if you choose to do this, some functionality of our Website will not be available to you.
The use of cookies by our third-party partners and platforms is governed by their own terms and privacy policies. We bear no responsibility for how those parties use your data in connection with cookies. If you are concerned with any use and storage of your data via cookies, please contact us using the details in paragraph 10.
We use Google Analytics, which allows us to track the use of our Website and Services by recording the number of users who have visited, the number of pages viewed, navigation patterns, what systems users have and the date and time of visits through cookies. This information is collected for statistical purposes and is not intended to directly identify you.
We may use a range of services and functions offered by Google Analytics. We also use Google Analytics to partner with third parties and advertise online. Our third-party partners may use technologies such as cookies and other third-party tracking technologies to gather information about your activities on our Website and other sites in order to provide you with advertising based on your browsing activities and interests.
For more information on how Google collects and processes your data, please visit Google's Privacy Policy. For instructions on how to opt out of Google Analytics data tracking, please visit Google Analytics Opt-out.
We use third-party payment processors and payment gateways to process payments made for our Services. Any Personal Information collected in connection with payment processing, including financial information where applicable, is collected, used and stored by those third-party providers in accordance with their own terms and conditions and privacy policies, details of which are available on our Website.
We do not store full payment card details or other direct payment credentials. However, we may retain payment-related records necessary for business, accounting and legal purposes, including invoices, receipts, transaction references, payment status, remittance details and other accounting records.
Where payments are made by credit card or through an online payment gateway, payment information is processed directly by the relevant third-party payment provider.
Where payments are made by direct bank transfer, we may collect or record limited payment information, such as the payer's name, remittance details, transaction references and bank account details to the extent such information appears in bank statements, payment confirmations or accounting records.
We use a range of third-party platforms and service providers to operate our business and deliver our services. These platforms may collect, store or process Personal Information in connection with the services we provide. The third-party platforms we currently use or may use include:
The use of your Personal Information by these third-party platforms is governed by their own terms and conditions and privacy policies.
As a managed IT and cybersecurity service provider, we may access, view, handle or incidentally process Personal Information and other information contained in client IT systems, client environments and service delivery platforms in the course of providing our services.
This may include user account details, business email addresses, device and asset records, access permissions, system logs, security alerts, support tickets, backup and patching information, audit records, Microsoft 365 / Entra ID information, application data, database records, files, emails, configuration information, Sensitive Information where incidentally included or reasonably necessary, and other client system data.
This information may be accessed or used where reasonably necessary for onboarding, managed IT services, cybersecurity monitoring, support, troubleshooting, system administration, reporting, migrations, backups and restores, governance reviews, risk assessments, incident coordination, project work, billing, service administration, offboarding, handover to another provider and transition assistance.
We do not generally collect client system data for our own purposes. We handle client system data as a service provider acting on our client’s instructions. Access is limited to what is reasonably necessary to provide the agreed services, support the client environment, meet contractual obligations, assist with offboarding, handover or transition to another provider, disclose relevant client information to a third party nominated or authorised by the client, or comply with legal or regulatory requirements. Our use of publicly available information about a business, domain or technology environment does not involve unauthorised access, intrusive testing, vulnerability scanning or security testing unless separately agreed under an appropriate engagement.
We may disclose limited information to subcontractors, technology vendors, suppliers, professional advisers, insurers and service providers where required for service delivery or business operations, and to another provider or third party nominated or authorised by the client for offboarding, handover or transition assistance. Our clients remain responsible for Personal Information in their own environments, including providing any required privacy notices, obtaining any required consents or authorisations, ensuring they have a lawful basis to collect and disclose that information to us for service delivery, and responding to requests or rights exercised by individuals in relation to that information.
We may use generative AI and agentic AI tools to support internal operations, drafting, documentation, analysis, technical research, automation, workflow support and service delivery.
We do not use AI tools to make solely automated decisions about individuals that would have a legal or significant effect on them.
We do not input client credentials, unnecessary Personal Information, sensitive system data or confidential client information into public AI tools unless approved and subject to suitable controls.
When we collect your Personal Information, as far as reasonably practicable, you are permitted to interact and/or contact us anonymously or by using a pseudonym except where:
We collect your Personal Information as outlined in this Privacy Policy for the purposes described below:
We do not sell, rent or trade Personal Information. We only disclose Personal Information as described in this Policy, where authorised by you, where reasonably necessary for the provision of our Services or business operations, or where required or permitted by law.
We take reasonable steps to protect your Personal Information in accordance with this Privacy Policy. Personal Information is generally stored electronically in secure third-party cloud platforms, business systems and service delivery platforms used by INTIRIS from time to time. We will assess and respond to eligible data breaches in accordance with applicable law, including the Notifiable Data Breaches scheme where applicable.
Personal Information submitted through our Website or online forms will be transferred electronically using secure HTTPS or SSL connections where supported by the relevant platform.
Information may be stored in Australia where available. However, some third-party cloud, SaaS, support, analytics, security, AI, backup, licensing and service delivery providers may store, process or access information from Australia or overseas depending on their platform architecture and support model. Internal access to systems containing Personal Information is limited to authorised personnel, contractors and service providers who require access for business, administrative or service delivery purposes. We use reasonable technical, organisational and security measures designed to protect Personal Information from misuse, interference, loss, unauthorised access, modification or disclosure. These measures may include unique user accounts, strong password requirements, multi-factor authentication, role-based access controls, conditional access policies, audit logging and monitoring, encryption in transit and, where supported by the relevant platform, encryption at rest, endpoint protection, backup and recovery processes, and security monitoring appropriate to the relevant system, platform and service being provided.
You agree and consent to us transferring and storing your Personal Information in the above manner.
Your Personal Information is accessible to our employees, contractors and our third-party service providers such as our Website host and technical support providers. We may also store your Personal Information in password-protected email databases for the purpose of sending out communications and marketing emails in accordance with this Privacy Policy. Depending on the services we provide, Personal Information may also be accessible to subcontractors, technology vendors, cloud and SaaS providers, backup providers, security monitoring providers, payment processors, professional advisers, insurers and other service providers engaged for service delivery or business operations.
Please note that no method of electronic transmission or storage is 100% secure and we cannot guarantee the absolute security of your Personal Information. Transmission of Personal Information over the Internet is at your own risk, and you should only enter, or instruct the entering of, Personal Information to the Website within a secure environment. It is your responsibility to ensure that you keep your Personal Information safe, including keeping your software up to date to prevent security breaches.
We reserve the right to maintain and store any information or data where we reasonably believe it is necessary to comply with any legal or regulatory obligations, protect rights or property, prevent criminal or other unlawful activity whether immediate or in the future, or where we have a legitimate business reason to do so, including collection of amounts owed, resolving disputes, enforcing our Terms or for record keeping integrity.
We take reasonable steps to destroy or de-identify your Personal Information when it is no longer required for the purpose for which it was collected, unless retention is required for legal, accounting, tax, contractual, insurance, audit, security, dispute resolution or other legitimate business purposes. Retention periods may differ for invoices, contracts, service tickets, security logs, incident records, backups, audit records and client service documentation, and certain records may be retained for longer periods as required by applicable laws (including laws relating to corporations, money laundering and financial reporting). Where we hold or access Personal Information in client systems or service delivery platforms as a service provider, we will take reasonable steps to support the client’s lawful instructions regarding retention, deletion, export or return, subject to legal, security, backup and operational constraints.
Your Personal Information may be disclosed to individuals and companies for the purposes described in this Policy, as outlined below:
Your Personal Information may be accessed by us, including our directors, employees, officers and contractors. You consent to us providing your Personal Information, including Sensitive Information, to our Related Bodies Corporate (as defined in the Corporations Act 2001 (Cth)) where reasonably necessary for the purposes described in this Policy and permitted by law, including where Sensitive Information is involved.
Your Personal Information may be disclosed by us to any party to whom we are required by law to provide your Personal Information and to any party to whom disclosure is permitted under the Australian Privacy Principles, or where we reasonably believe that disclosure is required to comply with any court orders, subpoenas, or other legal process or investigation including by tax authorities, if such disclosure is required by law. Where possible and appropriate, we will notify you if we are required by law to disclose your Personal Information.
Where permitted by law, we may use or disclose Personal Information (other than Sensitive Information, unless permitted by law) to keep you informed about relevant service updates, educational content, offers and related business communications. For this purpose, disclosure may be made to our third-party service providers who assist with communications and marketing. We may communicate with you via phone, email, social media, SMS, or regular mail using your business contact details where appropriate. If you have indicated a preference for a method of communication, we will endeavour to use that method wherever practical to do so.
We may use business contact details collected from enquiries, forms, assessments, customer relationships, events or similar interactions for direct marketing purposes, including service updates, educational content, offers and related communications. We do not use client technical data, security logs, ticket contents, confidential client information or system access information for general marketing purposes.
You can opt-out of direct marketing communication activities undertaken by us at any time by clicking the “unsubscribe†or “opt-out†link on email communications from us, replying ‘Stop’ to a promotional SMS or by contacting us by phone or email.
We may share your Personal Information with third parties if it is reasonably related to the provision of our Services. The third parties that we may share your Personal Information with include technology vendors, suppliers, distributors, consultants, contractors, professional advisers, lawyers, accountants, insurers, brokers, credit agencies, debt collection agencies and other service providers that perform services on our behalf or assist us in service delivery, business operations, legal compliance, risk management, insurance, audit, accounting or enforcement of our Terms. Such services we procure may include fulfilling our business requirements, identifying and disseminating advertisements, enforcement of our Terms, providing fraud detection and prevention services, processing payments or providing analytics services. We may also share your Personal Information with our business partners who offer goods or services to you jointly with us (for example, contests or promotions).
We may share your Personal Information where we have reason to believe that doing so is necessary to identify, contact or bring legal action against anyone damaging, injuring, or interfering (intentionally or unintentionally) with our rights or property, users, or anyone else who could be harmed by such activities.
We may also share your Personal Information with third parties with your consent in a separate agreement, for offboarding, handover to another provider, transition assistance or disclosure of relevant client information to a third party nominated or authorised by the client, in connection with any company transaction (such as a merger, sale of assets or shares, reorganisation, financing, change of control or acquisition of all or a portion of our business by another company or third party) or in the event of bankruptcy, dissolution, divestiture or any related or similar proceedings.
Note that we reserve the right to share your Personal Information with other third parties where, in our sole discretion, it is required to:
Please note that some of the parties listed above to whom your Personal Information may be disclosed may be located overseas or may store, process or access information from overseas. Countries may include Brazil and other countries in which our third-party cloud, SaaS, support, analytics, security, AI, backup, licensing and service delivery providers operate or use personnel, infrastructure or support teams.
We take reasonable steps to ensure that overseas recipients handle your Personal Information in a manner consistent with the Australian Privacy Principles, however to the maximum extent permitted by law, we are not liable for the privacy practices of such parties.
Please note that the transfer or disclosure of your Personal Information to overseas parties may involve privacy and security risks, including that overseas jurisdictions may have privacy laws that differ from those in Australia and may not provide equivalent protections. By providing your Personal Information to us, you acknowledge that overseas disclosures may occur as described in this Policy and you further consent to disclosure of Personal Information to such overseas recipients.
Our Website may, from time to time, contain links to and from websites which are owned or operated by other parties. You acknowledge and agree that we have no control over, and shall not be liable for, the privacy practices or content of these third-party websites and we do not make any representation about the privacy practices of any third-party websites, whether or not linked from or transferred from our Website. You are responsible for checking the privacy policy of any such third-party websites and applications so that you can be informed of how they will handle Personal Information.
We run pages or profiles on social media platforms used by INTIRIS from time to time, including LinkedIn, Instagram and other platforms we may use for business, marketing or communication purposes (Social Media Platforms). By accessing, interacting with and using our social media pages or profiles, you agree to the terms and privacy policy of those Social Media Platforms. You acknowledge and agree that Social Media Platforms may collect your information and that the privacy practices of those Social Media Platforms are not controlled by us and that we hold no responsibility for such privacy practices.
Social Media Platforms may allow public access to your public social media profile, which may include your username, age range, country/language, list of friends or other information that you make publicly available, and you understand that such information may therefore be accessible by us if you interact with our social media pages or profiles.
We may from time to time have access to statistics regarding the number of views, navigation patterns, posts that you like, comment on or share and any user interactions with our social media pages or profiles and may use such information for the purpose of our marketing and promotion strategies.
At any time, you may request access to Personal Information we hold about you. We may refuse to provide access if the law allows us to do so, in which case we will provide reasons for our decision as required by law.
We take reasonable steps to keep your Personal Information accurate, complete and up to date. If, at any time, you discover that information held about you is incorrect, you may contact us to have the information deleted or corrected.
You may request access to the information we hold about you, or request that we delete, update or correct any Personal Information we hold about you, by setting out your request in writing and sending it to us in accordance with paragraph 10.
We will process your request as soon as reasonably practicable, provided we are not otherwise prevented from doing so on legal grounds. If we are unable to meet your request, we will let you know why. If an individual contacts us about Personal Information contained in a client’s systems or environment, we may refer the request to the relevant client where appropriate because the client is generally responsible for the underlying Personal Information in its own environment, or take reasonable steps to assist the client to respond to the request in accordance with the client’s lawful instructions.
You may submit a written complaint about how we handle your Personal Information to our Privacy Officer via the details below. If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner or, if you are in the EU, a data protection authority or supervisory authority.
We reserve the right to amend this Privacy Policy from time to time with reasonable notice to you. While we endeavour to notify you as soon as reasonably possible of any changes to our Policies by email or by a notice on our Website, it is your responsibility to keep up to date with any changes or amendments by checking this page prior to using our Website and Services. This page contains our most accurate and up to date version of our Privacy Policy.
All requests for access or corrections to your Personal Information and complaints should be directed to our Privacy Officer. If submitting a complaint, please provide our Privacy Officer with full details of your complaint and any supporting documentation:
If you are not satisfied with our handling of your complaint or we have not replied to you within a reasonable period of time, then you are entitled to make a complaint to the Office of the Australian Information Commissioner.