# Privacy Policy

**Effective date:** 14 August 2026
**Last updated:** 19 August 2026

---

## 1. About this policy

TERESEC Pty Ltd (ABN 65 694 460 065) ("TERESEC", "we", "us", "our") provides cybersecurity consulting services in Australia. This policy explains how we handle personal information, including information collected through this website.

We handle personal information in accordance with the Australian Privacy Principles (APPs) in the *Privacy Act 1988* (Cth).

Some small businesses are not required by law to comply with the Privacy Act. We apply the APPs as a matter of practice regardless, because we handle sensitive commercial and security information on behalf of our clients. Where we provide services under a Commonwealth contract, we are bound by the Act and by any additional privacy obligations set out in that contract.

## 2. What personal information we collect

We collect only what we need to respond to enquiries and deliver our services.

**Through this website:**

- Name
- Email address
- Company or organisation name
- Telephone number, if you provide one
- The content of any message or enquiry you send us

**Through the security coverage check (check.teresec.com.au):**

- Name, work email address, organisation name and telephone number, if you request a full report
- The product and licence-tier selections you make and the answers you give. These are processed to produce your results and are encoded in the report link the tool issues for you; the link is valid for 7 days and displays the report to anyone who holds it, so who you share it with is your choice
- Anonymised hashes of selections, with timestamps and coarse source information, logged to detect abuse and automated enumeration. These hashes do not identify you
- Report emails are sent through our email delivery provider (Azure Communication Services)

**Through the course of business:**

- Contact details of client and prospective client personnel
- Correspondence and records of our dealings with you
- Information necessary to deliver an engagement, including details of your systems and environment

**Automatically:**

- Technical information logged by our hosting and content delivery providers, including IP address, browser type, pages requested and timestamps
- Information about how this website is used, including pages viewed, time spent on them, how you arrived at the site, and general information about your device and browser. Where this is collected through analytics cookies, it happens only if you consent. See section 7.

We do not seek to collect sensitive information as defined in the Privacy Act, such as health information, racial or ethnic origin, or political opinions. Please do not send us sensitive information through the website.

## 3. How we collect personal information

We collect personal information:

- Directly from you, when you complete a form on this website, email us, or speak with us
- Automatically, through server and content delivery logs when you visit this website
- From your organisation, where a client provides contact details of its personnel for the purposes of an engagement
- From publicly available sources, such as a company website or a professional networking profile, where we are researching a prospective client

Where we collect your personal information from someone other than you, we take reasonable steps to make you aware of the collection, as required by APP 5.

## 4. Why we collect it, and how we use it

We collect, hold and use personal information to:

- Respond to your enquiry
- Deliver a security coverage report you request through the security coverage check, and follow up on that request
- Provide, manage and improve our services
- Communicate with you about an engagement
- Meet our contractual, legal and regulatory obligations
- Maintain business records
- Understand how this website is used, so that we can improve it
- Send you information about our services, where you have consented or would reasonably expect it, and always with a way to opt out

We do not sell personal information. We do not trade personal information for any benefit, service or advantage.

## 5. Who we disclose personal information to

We disclose personal information only where it is necessary, and only to:

- **Service providers** who help us operate this website and our business, including website hosting, content delivery and security, and email delivery
- **Professional advisers and insurers**, where reasonably required
- **Law enforcement or regulators**, where required or authorised by law

**How we choose and manage service providers.** We keep the number of third parties that handle personal information to a minimum, and we prefer arrangements that allow data to be held in Australia. Before engaging a provider we consider how they handle personal information and where they hold it. We take reasonable steps, including through our contracts with them, to ensure they handle personal information consistently with this policy and the Australian Privacy Principles, and we limit what each provider receives to what it needs in order to perform its function.

If you would like to know which providers currently handle personal information on our behalf, contact us at [info@teresec.com.au](mailto:info@teresec.com.au) and we will tell you.

## 6. Sending information overseas

Some of the service providers we rely on operate outside Australia. Where that is the case, they are most likely to be located in the **United States**.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, as required by APP 8.

**Where your information is held.** Enquiries you send us through this website are processed and stored in Australia. Where we hold client or prospect information in a database under our control, that data is stored in Australia.

## 7. Cookies and website analytics

We do not use advertising cookies, and we do not track you across other websites.

### Strictly necessary cookies

Our content delivery and security provider may set cookies required to deliver and protect the site, for example to distinguish automated traffic from human visitors, or to record that a security check has been passed. These are always active because the site cannot be delivered securely without them. They are not used for advertising and are not used to build a profile of you.

When you submit our contact form, or submit a check or report request on the security coverage check, a security check runs to confirm the submission comes from a person rather than an automated system. This check is cookieless and does not track you across other websites.

We also store your cookie preferences so that we do not ask you again on every visit.

### Analytics

We use two analytics services, and they are treated differently because they work differently.

**Cloudflare Web Analytics** is privacy-preserving and **sets no cookies**. It gives us aggregate figures such as page views, referring sites and general location. It does not identify you and does not track you across other websites. Because it sets no cookies and collects no personal identifiers, it runs for all visitors - on this website and on the security coverage check (check.teresec.com.au).

**Google Analytics** gives us a more detailed picture of how the site is used, including which pages people read and how they arrived. It sets cookies and processes information, including your IP address, through Google LLC in the **United States**.

**Google Analytics only runs if you consent.** When you first visit, you are asked whether to allow analytics cookies. If you decline, Google Analytics is not loaded and its cookies are not set. You can change your choice at any time through the cookie preferences link on the site.

We use analytics information only in aggregate, to understand how the site is used and improve it. We do not use it to identify individual visitors, and we do not combine it with information you send us through our contact form.

### Your choices

- Decline analytics cookies when asked, or change your preference at any time through the cookie preferences link
- Install Google's [browser opt-out add-on](https://tools.google.com/dlpage/gaoptout) to opt out of Google Analytics on any website
- Configure your browser to refuse cookies. Blocking strictly necessary cookies may prevent parts of this site from working

For more information on how Google handles this data, see Google's [privacy policy](https://policies.google.com/privacy).

## 8. How we protect personal information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.

Security is our profession, so we hold ourselves to the practices we recommend to clients. The controls we maintain include:

- Encryption of data in transit using TLS
- Access control on a least-privilege basis
- Multi-factor authentication on business systems
- Patching and vulnerability management of systems under our control
- Assessment and periodic review of the service providers we rely on
- Collecting and retaining only the information we actually need

No system is perfectly secure. If we become aware of a data breach likely to result in serious harm, we will respond in accordance with the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.

## 9. How long we keep it

We keep personal information only as long as needed for the purposes described in this policy, or as required by law. Enquiries that do not lead to an engagement - including report requests made through the security coverage check - are deleted within 12 months. Records relating to an engagement are retained for 7 years to meet legal, tax and professional obligations. Report links issued by the security coverage check expire after 7 days; the tool itself stores nothing in a database.

## 10. Accessing and correcting your information

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

Contact us at [info@teresec.com.au](mailto:info@teresec.com.au). We will respond within a reasonable period, ordinarily within 30 days. We do not charge for making a request. If we refuse access or correction, we will tell you why in writing and explain how to complain.

## 11. Complaints

If you believe we have mishandled your personal information, contact us at [info@teresec.com.au](mailto:info@teresec.com.au) with details of your concern. We will acknowledge your complaint and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner:

- Website: [oaic.gov.au](https://www.oaic.gov.au)
- Phone: 1300 363 992
- Post: GPO Box 5218, Sydney NSW 2001

## 12. Anonymity

You may deal with us anonymously or under a pseudonym where it is lawful and practicable to do so. In most cases we will need your contact details to respond to an enquiry or deliver services.

## 13. Changes to this policy

We may update this policy from time to time. The current version is always available on this website, and the effective date appears at the top.

## 14. Contact

**TERESEC Pty Ltd**
ABN 65 694 460 065
Email: [info@teresec.com.au](mailto:info@teresec.com.au)
