Privacy Policy
1. Introduction
Concept Data Pty Ltd respects your privacy and is committed to protecting the personal information of our customers, partners, and website users.
We comply with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs).
As a provider of managed IT, cybersecurity, and advisory services, we may handle personal information as part of delivering services to our clients. This policy outlines how we collect, use, disclose, and protect that information.
Where Concept Data provides services to clients in regulated sectors such as healthcare, we handle information in accordance with contractual, regulatory, and security obligations applicable to those environments.
2. What is Personal Information
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
This may include, but is not limited to:
- Name, email address, phone number
- Job title and organisation details
- Billing and payment information
- Technical and usage data associated with IT systems
- Any other information provided to us in the course of delivering services
3. Collection of Personal Information
We collect personal information where it is reasonably necessary to:
- Provide our services
- Manage customer relationships
- Meet legal and regulatory obligations
Information may be collected when you:
- Engage us for services
- Contact us via phone, email or website
- Subscribe to communications or updates
- Interact with our support or service desk
- Visit our website
We may also receive personal information from third parties such as:
- Clients who engage us to support their systems
- Service providers and partners
- Publicly available sources
By providing personal information to us, you consent to its collection, use, and disclosure in accordance with this Privacy Policy.
4. How We Collect Personal Information
We collect personal information in a variety of ways, including:
- Directly from you
- Through electronic communications and systems
- Through service delivery platforms and tools
- Via our website and online forms
- From third parties where authorised
Where we receive personal information from a third party, we take reasonable steps to ensure it is handled in accordance with this policy.
5. Use of Personal Information
We use personal information for purposes including:
- Delivering managed IT, cybersecurity and consulting services
- Providing support, maintenance, and system monitoring
- Managing accounts, billing, and payments
- Communicating with clients and stakeholders
- Improving our services and customer experience
- Meeting legal and compliance requirements
We only collect and use personal information that is reasonably necessary for these purposes. In some cases, we process personal information on behalf of our clients as part of providing managed services. In these circumstances, we act in accordance with our contractual obligations and the instructions of the client.
6. Disclosure of Personal Information
We may disclose personal information to:
- Employees, contractors, and authorised personnel
- Service providers, vendors, and technology partners
- Professional advisers such as legal and accounting firms
- Insurers
- Regulatory authorities where required by law
We only disclose personal information where necessary and take reasonable steps to ensure that third parties handle it in accordance with applicable privacy laws.
In the event of a business transaction such as a merger, acquisition, or sale, personal information may be disclosed under confidentiality arrangements.
7. Overseas Disclosure
As part of delivering modern cloud-based services, personal information may be stored or processed outside Australia.
This may include platforms such as cloud infrastructure and software providers.
Where this occurs, Concept Data Pty Ltd takes reasonable steps to ensure overseas recipients handle personal information in a manner consistent with Australian Privacy Principles.
8. Security of Personal Information
Concept Data Pty Ltd is committed to protecting personal information against misuse, interference, loss, unauthorised access, modification, and disclosure.
We implement industry-recognised security controls, including:
- Encryption of data in transit and at rest where applicable
- Identity and access management controls based on least privilege
- Endpoint protection and device management
- Monitoring, logging, and threat detection capabilities
- Secure cloud and infrastructure environments
- Staff training and security awareness programs
Our security practices align with recognised frameworks including ISO 27001 and applicable cybersecurity standards.
While we take reasonable and industry-aligned steps to protect information, no method of transmission or storage is completely secure.
9. Data Breach Response
Concept Data Pty Ltd maintains processes to detect, respond to, and investigate suspected data breaches.
Where a data breach is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
10. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes for which it was collected or to comply with legal and regulatory obligations.
When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it.
11. Access and Correction
You may request access to personal information we hold about you.
You may also request correction of information if it is inaccurate, incomplete, or out of date.
Requests can be made by contacting us at:
Email: privacy@conceptdata.com.au
We will respond in accordance with the Privacy Act. An administrative fee may apply where permitted by law.
12. Complaints
If you have a concern or complaint about how we handle personal information, please contact us in writing:
Concept Data Pty Ltd
6/206 Greenhill Road
Eastwood SA 5063
We will investigate all complaints and respond in a reasonable timeframe.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
13. Website and Cookies
When you visit our website, we may collect technical information such as:
- Browser type
- Operating system
- Pages visited
- Referring websites
We use cookies and similar technologies to:
- Improve website functionality
- Analyse website usage
- Support marketing activities
You can manage cookie preferences through your browser settings.
Our website may contain links to third-party websites. We are not responsible for the privacy practices of those sites.
14. Changes to This Policy
We may update this Privacy Policy from time to time.
Updates will be published on our website and take effect immediately upon publication.
15. Contact Us
For privacy-related enquiries, contact:
Concept Data Pty Ltd
Email: privacy@conceptdata.com.au