IT Support 247 Pty LtdPrivacy Policy

Document Control
| Owner | Privacy Officer |
| Approved By | Managing Director |
| Review | Annual or upon legislative change |
| Applies To | All staff, contractors and service providers |
| Classification | Public |
1. Purpose and Commitment
IT Support 247 Technology is committed to protecting the privacy, confidentiality and security of personal information. This policy explains how we collect, use, disclose, retain and protect personal information in accordance with the Privacy Act 1988 (Cth), Australian Privacy Principles (APPs), the Notifiable Data Breaches Scheme, and where applicable the Victorian Privacy and Data Protection Act 2014 and the Victorian Protective Data Security Standards (VPDSS).
As an information technology and cybersecurity services provider we recognise that clients entrust us with access to business systems and information. We implement governance, technical and operational controls designed to safeguard that information.
2. Scope
This policy applies to visitors to our website, prospective customers, existing customers, suppliers, contractors, employees, job applicants and authorised users of our managed services.
Services include Managed IT Services, Cybersecurity, Microsoft 365, Azure, Cloud Solutions, Telephony (VoIP), Website Design and Hosting, Network Infrastructure, Backup and Disaster Recovery, Security Monitoring, Professional Services and 24/7 Helpdesk.
3. Legislative Framework
This policy is designed to support compliance with:
- Privacy Act 1988 (Cth)
- Australian Privacy Principles
- Notifiable Data Breaches Scheme
- Spam Act 2003
- Victorian Privacy and Data Protection Act 2014 (where applicable)
- Victorian Protective Data Security Standards (where applicable)
- Industry good practice including ISO/IEC 27001:2022, ISO/IEC 27701 and ACSC Essential Eight.
4. Personal Information We Collect
Depending upon the services provided we may collect names, business contact details, identity verification information, email addresses, telephone numbers, IP addresses, audit logs, authentication records, device identifiers, support tickets, billing information, contracts, website usage information, call metadata, and information necessary to provide contracted services.
5. How We Collect Information
Information may be collected directly from you, through our website, contact forms, cookies, service desk, remote support sessions, monitoring tools, cloud services, suppliers, publicly available sources or where authorised by our customers.
6. Why We Collect Information
We collect information to deliver services, manage customer relationships, provide support, improve services, detect and respond to cyber threats, meet contractual obligations, comply with legal requirements, process payments and communicate with customers.
7. Security of Information
We maintain layered security controls including encryption, multifactor authentication, privileged access management, endpoint protection, secure remote administration, vulnerability management, security monitoring, logging, backup and disaster recovery, supplier due diligence, secure software configuration, staff training and regular policy reviews.
8. Managed Service Provider Responsibilities
Where we process information on behalf of customers we act only in accordance with contractual instructions unless required by law. Customers remain responsible for determining the purposes of processing their information.
9. Cloud, Microsoft 365 and VoIP
Cloud platforms may process data within Australia or other jurisdictions depending upon selected services. We undertake supplier due diligence and contractual reviews to ensure appropriate safeguards. VoIP services may generate call records, quality metrics and billing information necessary for service delivery.
10. Website, Cookies and Analytics
Our website uses cookies and similar technologies to improve functionality, understand website performance and enhance user experience. Users may configure browser settings to limit cookies, although this may affect website functionality.
11. Overseas Disclosure
Where overseas disclosure occurs we take reasonable steps to ensure recipients provide protections comparable to Australian privacy obligations through contractual commitments and security assessments.
12. Data Retention and Disposal
Information is retained only for legitimate business, contractual and regulatory purposes. When no longer required, information is securely destroyed, anonymised or de-identified using recognised industry practices.
13. Notifiable Data Breaches
Security incidents are assessed through documented incident response procedures. Where an eligible data breach occurs we comply with notification obligations under Australian law and contractual requirements.
14. Victorian Government Customers
Where services are supplied to Victorian public sector organisations we support customer obligations under the Victorian Protective Data Security Standards through governance, information classification, access control, audit logging, incident management, supplier security and secure disposal controls. Compliance with VPDSS remains the responsibility of the relevant public sector organisation.
15. Your Rights
Individuals may request access to or correction of their personal information, subject to lawful exceptions. Requests are verified before processing.
16. Complaints
Complaints should be submitted to our Privacy Officer. We aim to acknowledge complaints within five business days and provide a substantive response within thirty days. If you are not satisfied you may contact the Office of the Australian Information Commissioner.
17. Policy Review
This policy is reviewed annually or whenever legislative, regulatory or business changes require updates.
18. Contact Details
Appendix A – Security Controls
- Multi-factor authentication
- Least privilege access
- Privileged account management
- Endpoint protection
- Patch and vulnerability management
- Encrypted backups
- Business continuity and disaster recovery
- Secure remote support
- Security awareness training
- Supplier risk management
- Audit logging
- Change management
- Incident response
Appendix B – Privacy Principles Summary
| APP 1 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 2 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 3 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 4 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 5 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 6 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 7 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 8 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 9 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 10 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 11 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 12 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |
| APP 13 | IT Support 247 Technology maintains policies and procedures to support compliance with this Australian Privacy Principle in the delivery of its services. |

