Skip to content
YSYarra Secure

Privacy

Privacy Policy

How Yarra Secure collects, uses, protects, and deletes personal information. Designed with reference to the Australian Privacy Principles, and to be read together with our engagement documents.

Last updated: June 2026

1. Who we are

Yarra Secure (ABN 30 139 311 250) is a cyber security and IT setup consultancy founded by Sam, based in Melbourne CBD, Victoria and working with clients Australia wide. We help small businesses reduce cyber risk and set up their technology securely — which means clients trust us with information about their people, systems, and weaknesses. We treat that trust as the core of the business.

This policy explains what personal information we collect, why, how we protect it, how long we keep it, and the choices you have. It is designed with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and should be read together with the engagement documents that govern any services we provide to you.

2. Contact details

Privacy questions, requests, and concerns come straight to the founder: email contact@yarrasecure.com.au or call 0435 315 894. Postal contact is available on request. We aim to acknowledge privacy enquiries within two business days.

3. Scope of this policy

This policy covers personal information handled through our website (yarrasecure.com.au), business enquiries, marketing, and the delivery of our services. Where a signed engagement document (such as a statement of work or confidentiality agreement) sets stricter rules for particular information, the stricter rules apply to that engagement.

4. Types of personal information we collect

We collect only what we need, and we collect it in categories:

Enquiry and contact data. Your name, business name, email address, phone number, website URL, and the content of your messages when you contact us or book a call.

Client and project data. During engagements: business process information, names and roles of relevant staff, system configuration details (settings — not the content of your client records), questionnaire responses, and project correspondence.

Security findings and sensitive operational information. Security review work produces information about weaknesses in your systems. We treat findings as confidential information of the highest sensitivity: they are shared only with the recipients you authorise in writing, stored with strict access controls, and deleted on schedule (see section 16).

Payment and invoice information. Billing contact details, ABNs, invoice records, and payment references. We do not collect or store your credit card numbers; payments are made by bank transfer to the account on our invoices.

What we never ask for. We do not ask for your passwords, MFA codes, or credentials — by web form, email, or phone. Anyone requesting these while claiming to represent Yarra Secure should be treated as an impersonator; call 0435 315 894 to verify.

5. Website analytics and cookies

Our website currently uses no advertising trackers and no third-party analytics cookies. Standard technical logs (such as those kept by our hosting provider for security and performance) may record IP addresses and request data. If we introduce analytics or other cookies in future, we will update this policy and our cookie information first, and we will prefer privacy-respecting tools that do not track individuals across websites.

6. How information is collected

Directly from you: through the website contact form (which opens an email from your own mail client to us), by email, by phone, in meetings, and through the questionnaires and screen-share sessions used to deliver engagements. We do not buy marketing lists, and we do not use software to harvest contact details.

7. Why we use your information

We use personal information to:

respond to enquiries and provide quotes · scope and deliver the services you engage us for · communicate about active projects · issue invoices and keep accurate business records · maintain the security of our own systems · improve our services and resources · and, only with your consent, send occasional marketing (see section 9).

Legal and administrative reasons. We may also use or retain information where needed to comply with Australian law (including tax record-keeping), to establish or defend legal claims, to respond to lawful requests by authorities, or to enforce our agreements.

We do not sell personal information. Ever.

8. Marketing communications and consent

We send marketing email (such as our occasional security notes) only to people who have opted in, and business outreach only on a basis consistent with the Spam Act 2003 (Cth). Every commercial message identifies Yarra Secure and includes a working unsubscribe.

9. Our unsubscribe commitment

Reply “unsubscribe” to any marketing message, or email contact@yarrasecure.com.au, and we will remove you promptly — our standard is same business day where possible and never more than five business days — and add you to our no-contact list so you are not contacted again. Unsubscribing from marketing does not affect service emails for any active engagement, unless you ask for that too.

10. AI tools and client data

We use AI tools in our own work under strict internal rules: client confidential data, security findings, and client personal information are not entered into external AI tools unless you have expressly agreed in writing to a named tool for a named purpose. We do not use client data to train AI models. Where we set up AI-assisted workflows for clients, the data boundaries are documented and approved by the client before anything goes live.

11. Disclosure to service providers

We disclose personal information only as needed to run the business: to service providers that support our operations (email, document storage, accounting, and invoicing platforms) under their own security and privacy obligations; to our professional advisers (lawyer, accountant, insurer) under confidentiality; where required or authorised by law; or with your consent. Security findings are never disclosed to third parties without your written authorisation, except where the law requires it.

12. Overseas disclosure

Where practical we prefer service providers that store data in Australia. Some platforms we use may process or store data overseas (for example, in the provider’s global cloud infrastructure). Where that occurs, we take reasonable steps consistent with the Australian Privacy Principles to ensure the information remains protected, including choosing reputable providers with strong published security practices.

13. Storage and security measures

We apply to our own systems the standards we recommend to clients: multi-factor authentication on all business accounts, unique passwords managed in a password manager, encrypted devices, access-controlled cloud storage, prompt software updates, and separation of administrative access. Engagement records are kept in per-client folders with access limited to Sam and the recipients you authorise. No system is perfectly secure — see section 17 for how we respond if something goes wrong.

14. Access controls

Access to personal information is limited to the people who need it for the purposes above — in practice, Sam and, where you have authorised them, named recipients on your engagement. Any future contractor would be bound by written confidentiality and data handling obligations at least as strict as this policy before accessing any client information.

15. Your responsibilities when sending us data

Please send project materials only through the channels we agree for your engagement, and never send passwords, MFA codes, identity documents, or your own clients’ records unless we have specifically agreed a secure method and a genuine need. Where screenshots are needed, redact personal details that are not relevant — our evidence guidelines show you how. If you accidentally send something sensitive, tell us and we will delete it from the receiving channel.

16. Retention and deletion

We keep information only as long as it is needed:

Enquiries that don’t become engagements: deleted within 12 months. Engagement records and security findings: retained for 12 months after the engagement ends (so we can support you on follow-up questions), then securely deleted — or earlier on your request, unless a legal obligation or active dispute requires retention, in which case we tell you. Contracts, invoices, and tax records: retained for the periods required by Australian law (generally up to seven years). Consent and unsubscribe records: kept while marketing continues, so your choices are honoured.

Secure deletion includes purging from trash and version history where our platforms allow, and removal from backup rotation within a further 90 days.

17. Data breach response

If a data breach involving personal information occurs, we follow our documented data breach response procedure: contain the incident, preserve evidence, assess the harm promptly, take remedial action, and notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme. Where the affected information belongs to a client engagement, we notify that client promptly with the facts — our standard is honesty first.

18. Access and correction requests

You can ask what personal information we hold about you, request a copy, or ask us to correct it. Email contact@yarrasecure.com.au with your request. We respond within 30 days, usually much faster, and we don’t charge for reasonable requests. If we cannot provide or correct something (for example, where the law requires us to retain a record), we will explain why.

19. Complaints

If you believe we have mishandled your personal information, contact us first — contact@yarrasecure.com.au or 0435 315 894 — and we will investigate and respond in writing within 10 business days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. We will cooperate fully with any OAIC process.

20. Updates to this policy

We review this policy at least annually and whenever our tools or practices change. The current version is always published at yarrasecure.com.au/privacy, with the “last updated” date below. Material changes affecting active clients are communicated directly.

Questions about this policy: contact@yarrasecure.com.au · 0435 315 894 · Yarra Secure, Melbourne CBD, Victoria. See also our Terms of Use.