Privacy Policy

Effective Date: February 21, 2026

Compliance: Privacy Act 1988 (Cth)

Cyberlight Technology Pty Ltd ("we", "us", or "our") respects your privacy and is committed to protecting your personal information. This policy outlines our management of your data in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth).

While you may interact with our public website pseudonymously, providing accurate identity information is required to provision IT consultancy and managed technology services.

1. Information We Collect

We collect personal information necessary to deliver, manage, and bill for IT consultancy and managed technology services. This includes:

  • Identity Information: Full name, date of birth, and authorised representative details.
  • Contact Details: Service address, billing address, email addresses, and phone numbers.
  • Technical Data: IP addresses, device identifiers, MAC addresses, and diagnostic logs related to managed infrastructure.
  • Payment Information: Secure payment tokens (we do not store full credit card PANs on our servers).

2. How We Collect It (Cookies & Analytics)

We collect information directly from you when you submit forms, request quotes, or sign up for services. Additionally, we use passive collection methods to improve our digital platforms:

  • Cookies & Technical Data: We use strictly necessary technical data to secure form submissions and maintain platform integrity. Analytical cookies may be used to track aggregate website usage.
  • Third-Party Analytics: We may utilise platforms (e.g., Google Analytics) which capture anonymised browsing data. You can disable analytical tracking via your browser settings.

3. How We Use Your Data

Your information is used to fulfil our contractual and legal obligations. We do not, and will never, sell your personal data to data brokers.

  • Service Delivery: Provisioning and managing IT infrastructure, cybersecurity solutions, and managed service engagements.
  • Infrastructure Maintenance: Diagnosing technical faults and optimising performance across managed environments.
  • Legal Compliance: Meeting requirements under applicable Australian legislation, including the Privacy Act 1988.

4. Direct Marketing

With your consent, or where you would reasonably expect us to do so, we may use your contact details to notify you of service upgrades, security advisories, or new products that align with your business.

Opting Out: You have an absolute right to opt-out of direct marketing at any time. Every marketing email contains an "Unsubscribe" link, or you can adjust preferences within the Client Portal. (Note: You cannot opt-out of critical service notices or billing emails).

5. Data Disclosure & Cross-Border Flows

To deliver enterprise-grade services, we partner with specialised third parties. We take reasonable steps to ensure they comply with the APPs:

  • Domestic Disclosures: Technology vendors, wholesale suppliers, and local IT hardware distributors engaged in delivering your services.
  • Cross-Border Flows (APP 8): While core customer databases are hosted in Australia, we use global SaaS platforms (e.g., CRM systems, enterprise cloud providers) which may route or store encrypted diagnostic data in overseas regions such as the United States or the EU.

6. Data Security & Retention

Security Measures: We employ zero-trust principles. Data is encrypted in transit (TLS 1.3+) and at rest (AES-256). Staff access is restricted via role-based access controls and mandatory Multi-Factor Authentication (MFA).

Notifiable Data Breaches (NDB): In the unlikely event of a serious data breach that is likely to result in serious harm, Cyberlight complies fully with the NDB scheme, immediately notifying affected individuals and the OAIC.

Data Retention (APP 11): We retain your personal information only as long as necessary to provide services and comply with applicable laws. Once no longer required, data is securely destroyed or permanently de-identified.

7. Your Rights & Access

Under the APPs, you have the right to request access to the personal information we hold about you and request corrections if it is inaccurate or out-of-date.

To make a request, please contact our Privacy Officer by emailing the address below. We will respond within 30 days. No fee is charged for making a request.

8. Complaints

If you believe we have breached the Australian Privacy Principles, please contact us outlining your concern. We will investigate and respond in writing within 30 days.

If you are unsatisfied with our resolution, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (www.oaic.gov.au).

Cyberlight Technology Pty Ltd

ABN: 50 676 202 592

Melbourne, Victoria, Australia

privacy@cyberlight.com.au