Privacy Policy

How we collect, use, store and protect your personal information

Last updated: August 2026

Prismera (ABN TBC) ("Prismera", "we", "us", "our") is committed to protecting your privacy. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs), as well as the requirements of the Notifiable Data Breaches (NDB) scheme.

1. The Australian Privacy Principles

The APPs are binding privacy standards under the Privacy Act. They govern how Australian businesses and government agencies collect, use, store and disclose personal information. This policy is designed to meet those obligations, including APP 1 (open and transparent management of personal information), which requires us to maintain a clearly expressed and up-to-date privacy policy.

2. What personal information we collect

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. The personal information we collect depends on how you interact with us:

  • Contact and enquiry forms: when you use the contact form on our website, we collect your name, email address, phone number (optional) and the contents of your message.
  • IT health check and quiz: when you request a free IT health check or complete our security quiz, we collect your name, email address, company details and the answers you provide.
  • Newsletter subscription: if you subscribe to our email updates, we collect your email address.
  • Client service information: if you become a client, we collect the business and personal information needed to deliver our managed IT, cybersecurity, cloud and consulting services, including contact details, account credentials (stored securely), and information about your systems and users.
  • Website usage data: we use Google Analytics to understand how visitors use our website. This includes anonymised usage statistics such as pages visited, time on site and device type. See section 10 below.

3. How we collect personal information

We collect personal information directly from you in most cases: when you fill in a form on our website, email or call us, request a health check, subscribe to our newsletter, or engage us for services. We may also collect information from your systems (with your authorisation) when delivering services, and from publicly available sources where relevant to a service engagement.

Where we receive personal information about you from a third party (for example, a colleague who refers you), we will take reasonable steps to inform you that we hold that information and how it will be used.

4. Why we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information for the following purposes:

  • to respond to enquiries and provide information about our services;
  • to deliver managed IT, cybersecurity, cloud and consulting services you have engaged us for;
  • to schedule and conduct IT health checks and assessments;
  • to send you requested information, including newsletter updates you have opted into;
  • to invoice and manage our business relationship with you;
  • to meet our legal, regulatory and compliance obligations (including under the Privacy Act); and
  • to improve our website, services and customer experience.

We will not use or disclose your personal information for purposes unrelated to those listed above unless you would reasonably expect us to, the use is required or authorised by law, or you have given consent.

5. Direct marketing

If you opt in to receive marketing communications from us (for example, our newsletter), we may send you information about our services, security updates and industry insights. Every marketing email includes a simple unsubscribe mechanism. You can opt out at any time by following the unsubscribe link, or by contacting us using the details in section 11. We do not use sensitive information for direct marketing, and we do not sell or rent your personal information to third parties for their own marketing purposes.

6. Disclosure of personal information

We disclose personal information only to the extent necessary to run our business and deliver our services. This may include:

  • our staff and contractors who need it to perform their duties;
  • third-party service providers who help us operate, such as our email and hosting providers (including Google Workspace for business email and Microsoft 365), payment processors, and IT security tooling vendors;
  • professional advisers such as accountants and lawyers, where reasonably necessary; and
  • government or regulatory bodies where required or authorised by law.

All third parties engaged by us are required to handle personal information consistently with the Privacy Act and the APPs, or under obligations that are at least substantially similar.

7. Cross-border disclosure (APP 8)

Some of our service providers store or process data on servers located overseas. In particular, Google Analytics (used on this website) and some cloud platforms we use for service delivery may process data in the United States or other jurisdictions. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient complies with the APPs or is bound by a substantially similar privacy regime (such as the relevant data protection frameworks those providers adhere to).

8. Security of personal information (APP 11)

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include:

  • encryption of data in transit and at rest where practicable;
  • multi-factor authentication on administrative and email accounts;
  • access controls so staff only see information they need to do their job;
  • regular security monitoring, patching and backups; and
  • staff training on privacy and information handling.

We also comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to any individual whose information we hold, we will assess the breach, take reasonable steps to contain it, and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.

9. Access to and correction of personal information (APPs 12 and 13)

You have the right to request access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact us using the details in section 11. We will respond within a reasonable period (usually 30 days) and may need to verify your identity before providing access. In limited circumstances permitted by the Privacy Act, we may refuse a request; if we do, we will explain our reasons in writing.

10. Cookies and website analytics

Our website uses Google Analytics, a web analytics service provided by Google LLC, to collect standard internet log information and details of visitor behaviour in an anonymised form. This information is used to measure and improve our website. Google Analytics may use cookies and similar technologies, and data collected may be transmitted to and stored by Google on servers that may be located overseas. You can opt out of Google Analytics tracking by installing the Google Analytics opt-out browser add-on available at tools.google.com/dlpage/gaoptout. We do not use cookies to identify individual visitors.

11. Complaints and contact

If you have a question, concern or complaint about how we handle your personal information, please contact us:

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

12. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, technology or legal obligations. The current version will always be available on this page, and the "Last updated" date at the top will tell you when it was most recently reviewed.

← Back to home    Contact Us →