Privacy policy
This policy was last revised on .
This privacy policy applies to CyberMetrix and our handling of personal information. CyberMetrix (ABN 67 609 784 358) is a technology company that provides Software as a Service (SaaS) and Platform as a Service solutions for governments and organisations (i.e. our customers).
Due to the commercial nature of our services, CyberMetrix, for the most part, collects the information of individuals in their professional capacity. For example, we collect information of the person who registers or activates the organisation’s administrator or user account, as part of their role within the customer organisation.
That being said, we recognise and value the protection of your personal information, which is an important part of our relationship with customers.
This Privacy Policy explains how we handle personal information. As an Australian company, we apply the privacy principles set out in the Australian Privacy Act 1988 (Cth), which guide how we collect and manage personal information. Importantly, we:
- give you clear information about our personal information handling practices,
- only collect personal information that is necessary for our functions,
- understand the purpose of our services, and restrict our use and disclosure of personal information in that regard, and
- take reasonable steps to keep the personal information we have secure.
Personal information
Personal information is information that identifies a person (or could reasonably lead to them being identified).
When providing our services, we collect some personal information. The types of personal information we collect and process depends on our relationship with you. We generally collect and process personal information from the following groups of people:
- Website visitors – We collect some personal information when people visit this website.
- Customers and prospective customers – Our customers are generally organisations, companies, corporations and government departments or agencies. The personal information we collect includes, for example, details of the contact person registered on the organisation’s administrator or user account.
- Customers that use our SaaS and PaaS services – When our customers activate their administrator or user account, we require some personal information to register the account. This information is limited and relates to details of the person in their professional capacity, i.e. business email and phone.
- People who are interested in working for CyberMetrix – We collect personal information of job applicants, and (where relevant) an applicant’s referees.
Personal information we collect
The types of personal information we collect and process are set out below. We generally collect this information when you interact with our platform and website. We may also collect this information in person, via email, mail or phone.
Why we collect and use personal information
We collect and process personal information for a number of reasons, which have been described in the table below:
We collect and use… | Purpose |
---|---|
Analytics data | To analyse the usage of our website and platform, including through the use of cookies, to improve your user experience. If you do not wish for us to use cookies, you can follow the process set out in our Cookie Notice. |
Enquiries information | To answer your questions about our cyber security maturity assessment platform and services |
Customer contact information |
To enter into a contract with you (e.g. Terms of Use)
To provide you with access to the CyberMetrix platform To communicate with you as part of our cyber security services To send our customers promotional emails. Whilst these emails may be sent to a customer’s contact person, they are intended for our customers organisations. |
Help and support information | To provide help and support in our customer’s use of the CyberMetrix platform |
Payment information | To accept payment for your purchase of our products or services |
Feedback information | To improve the types and quality of services offered, and the manner in which those services are provided to customers |
Access and correction requests, and privacy complaint information | To process your request or investigate your concern, and communicate with you |
Recruitment information | To process your job application and, if you are successful, to offer you a job and commence your employment |
Who we share your personal information with
CyberMetrix uses external parties (i.e. vendors) to provide services and functions on our behalf. In order for vendors to provide these services, we may share personal information that relates to the services being provided. We ensure that vendors only process personal information for the purpose it was provided to them, and not for any other purpose.
Our primary vendors that provide services on our behalf include:
- Google Analytics – provide analytics services, refer to the Google Privacy Policy.
- Google – provides data storage and SaaS related services, refer to the Google Privacy Policy.
- Amazon Web Services (AWS) – provides public cloud and IaaS related services, refer to the AWS Privacy Notice.
- HubSpot – provides our cloud based CRM services, refer to the HubSpot Privacy Policy.
- Mind Your Own Business (MYOB) – provides our accounting system, refer to the MYOB Group Privacy Policy.
We also have contracts with other domain specialists, subject matter experts, management consultants and information technology professionals to assist in providing our services. There may be limited instances where we share your information with these external parties for the purpose of providing services on our behalf.
We do not sell or share personal information with any advertisers, sponsors, content providers, media outlets, law enforcement or other person or entity, unless:
- We have your express permission, or
- There is a lawful ability or requirement for us to do so.
Anonymity
If you contact us with a general question, we may interact with you anonymously or through the use of pseudonym.
However, due to the nature of our business, we are unable to provide our cyber security maturity assessment platform anonymously, as we require factual information in order to register customer accounts and provide our cyber security maturity assessment services.
How we manage personal information
At CyberMetrix, we securely manage and dispose of personal information that we collect and process, as outlined below:
Accessing and correcting your personal information
CyberMetrix supports your right to:
- Access personal information we hold about you, or
- Correct your personal information, where you think that it is inaccurate, incomplete or out of date.
If you would like to access personal information we hold about you, we are happy to tell you what it is. We will not, however, tell someone else what personal information we hold about you (unless you permit us or there is a lawful ability or requirement for us to do so).
If you think the personal information we hold about you is incorrect, out of date or misleading, we are happy to correct it.
Questions and concerns?
If you have a question about this Privacy Policy or are concerned about how we handle personal information, please contact us at:
Online
Via the Contact Form on the footer of our website.
Address
Privacy OfficerCyberMetrix
GPO Box 1515
Brisbane, QLD 4001
Australia
If you have made a privacy compliant and are not happy with how we responded to your concern, you are able to contact the Office of the Australian Information Commissioner (OAIC). The OAIC’s process is available here.
Updates to this Privacy Policy
We may decide to update this Privacy Policy to ensure that our personal information handling practices are correctly reflected. If we make a significant change to this policy, we will notify you by publishing a notice on our website.
This policy was last revised on .