Privacy
Privacy Policy
How Yarra Secure collects, uses, protects, and deletes personal information. Designed with reference to the Australian Privacy Principles, and to be read together with our engagement documents.
Last updated: September 2026
1. Who we are
Yarra Secure (ABN 30 139 311 250) is a cyber security and IT setup consultancy founded by Sam, based in Melbourne CBD, Victoria and working with clients Australia wide. We help small businesses reduce cyber risk and set up their technology securely — which means clients trust us with information about their people, systems, and weaknesses. We treat that trust as the core of the business.
This policy explains what personal information we collect, why, how we protect it, how long we keep it, and the choices you have. It is designed with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and should be read together with the engagement documents that govern any services we provide to you.
2. Contact details
Privacy questions, requests, and concerns come straight to the founder: email contact@yarrasecure.com.au or call 0435 315 894. Postal contact is available on request. We aim to acknowledge privacy enquiries within two business days.
3. Scope of this policy
This policy covers personal information handled through our website (yarrasecure.com.au), business enquiries, marketing, and the delivery of our services. Where a signed engagement document (such as a statement of work or confidentiality agreement) sets stricter rules for particular information, the stricter rules apply to that engagement.
4. Types of personal information we collect
We collect only what we need, and we collect it in categories:
Enquiry and contact data. Your name, business name, work email address, optional phone number, optional website or domain, industry, service interest, the content of your message, and your separate privacy and marketing choices when you contact us or book a call.
Client and project data. During engagements: business process information, names and roles of relevant staff, system configuration details (settings — not the content of your client records), questionnaire responses, and project correspondence.
Security findings and sensitive operational information. Security review work produces information about weaknesses in your systems. We treat findings as confidential information of the highest sensitivity: they are shared only with the recipients you authorise in writing, stored with strict access controls, and deleted on schedule (see section 16).
Payment and invoice information. Billing contact details, ABNs, invoice records, and payment references. We do not collect or store your credit card numbers; payments are made by bank transfer to the account on our invoices.
What we never ask for. We do not ask for your passwords, MFA codes, or credentials — by web form, email, or phone. Anyone requesting these while claiming to represent Yarra Secure should be treated as an impersonator; call 0435 315 894 to verify.
6. How information is collected
Directly from you: through the website contact form, by email, by phone, in meetings, and through the questionnaires and screen-share sessions used to deliver engagements. When online email delivery is enabled, the contact form sends information to a same-origin Yarra Secure endpoint, which validates it and uses Resend to deliver an email notification to us. Basic request information, including an IP address where available, is converted to a hashed key for a best-effort, per-instance abuse limit. Records become eligible for removal after 15 minutes, are pruned as later requests arrive, and the in-memory map is capped. This control is not shared across every Vercel instance and is not a durable record or a substitute for hosting-layer abuse controls.
When online delivery is unavailable, the contact page may instead offer an email draft. You can review and edit the draft in your email app. Nothing is sent to Yarra Secure until you press Send in that app; your email provider handles the draft and message under its own terms. The page also shows our direct email address and phone number.
When a real Cal.com booking URL is configured, booking links open Cal.com and may include the supplied source, industry, service, and domain as URL query context so the enquiry can be prefilled and attributed. Cal.com also receives the technical request information normally sent when you visit an external site. When Cal.com is not configured, booking links stay on our contact page and no booking context is sent to Cal.com.
The public snapshot at scan.yarrasecure.com.au receives the domain you submit and your confirmation that you own it or have permission to assess it. Its checks use public DNS and passive sources; they do not sign in to your systems or collect equipment credentials. A separate public Supabase database stores the domain and bounded result summary, coarse referral context, and a hash of the result token. It does not contain the private console’s client records or authenticated reports.
That public database also stores keyed hashes derived from request IP addresses for abuse prevention, rather than raw IP addresses in those tables. Daily aggregate counts contain only approved source and campaign categories, result state and check coverage, with no domain, contact details, result token or IP identifier. Hosting providers may separately process request information as described in section 5. See section 16 for expiry and cleanup limitations.
The public scanner’s online enquiry collection is currently disabled while email delivery is being verified. It offers direct contact options without placing contact fields or scan context in URL query strings, fragments or prefilled email links. If you follow an older scanner link containing bounded scan context, our contact page validates that context, removes the fragment and lets you review any prefilled details before submitting a form or sending an email draft.
We do not buy marketing lists, and we do not use software to harvest contact details.
7. Why we use your information
We use personal information to:
respond to enquiries and provide quotes · scope and deliver the services you engage us for · communicate about active projects · issue invoices and keep accurate business records · maintain the security of our own systems · improve our services and resources · and, only with your consent, send occasional marketing (see section 8).
Legal and administrative reasons. We may also use or retain information where needed to comply with Australian law (including tax record-keeping), to establish or defend legal claims, to respond to lawful requests by authorities, or to enforce our agreements.
We do not sell personal information. Ever.
8. Marketing communications and consent
The contact form’s marketing opt-in is optional and separate from the required acknowledgement that lets us respond to your enquiry. Leaving the marketing box unticked does not affect whether we answer or provide a quote.
We send marketing email (such as occasional security notes) to people who have opted in, and conduct business outreach only on a basis consistent with the Spam Act 2003 (Cth). Every commercial message identifies Yarra Secure and includes a working unsubscribe.
9. Our unsubscribe commitment
Reply “unsubscribe” to any marketing message, or email contact@yarrasecure.com.au, and we will remove you promptly — our standard is same business day where possible and never more than five business days — and add you to our no-contact list so you are not contacted again. Unsubscribing from marketing does not affect service emails for any active engagement, unless you ask for that too.
10. AI tools and client data
We use AI tools in our own work under strict internal rules: client confidential data, security findings, and client personal information are not entered into external AI tools unless you have expressly agreed in writing to a named tool for a named purpose. We do not use client data to train AI models. Where we set up AI-assisted workflows for clients, the data boundaries are documented and approved by the client before anything goes live.
11. Disclosure to service providers
We disclose personal information only as needed to run the business: to service providers that support our operations under their own terms and security obligations; to professional advisers under confidentiality; where required or authorised by law; or with your consent.
Current website providers include Vercel for hosting and aggregate web analytics, and Supabase for the separate public scanner and private console databases. The public scanner stores the limited result, abuse-prevention and aggregate data described in section 6. When online contact-form delivery is enabled, Resend receives the form fields needed to deliver the enquiry notification. Email drafts and messages sent from your email app are handled by email providers, not submitted automatically through Resend by this website. Vercel Analytics receives page-view and limited conversion-event data, not the content of your enquiry. Other operational providers may include email, document storage, accounting, and invoicing platforms. Cal.com is an optional booking provider: it receives the booking-link context described in section 6 only when a real Cal.com URL is configured and you follow that link. Security findings are not disclosed outside an engagement without your written authorisation, except where the law requires it.
12. Overseas disclosure
Where practical we prefer service providers that store data in Australia. Some platforms we use may process or store data overseas (including Resend, Vercel, or another provider’s global cloud infrastructure). Our public scanner and private console Supabase databases are currently configured in Sydney, Australia. Our configured Resend sending region is Tokyo, Japan, for use when email delivery is enabled. These regional settings are not a guarantee that all provider processing remains in those locations. If Cal.com booking is configured and used, its processing may also occur overseas. Where that occurs, we take reasonable steps consistent with the Australian Privacy Principles to ensure the information remains protected, including choosing reputable providers with strong published security practices.
13. Storage and security measures
We apply to our own systems the standards we recommend to clients: multi-factor authentication on all business accounts, unique passwords managed in a password manager, encrypted devices, access-controlled cloud storage, prompt software updates, and separation of administrative access. Engagement records are kept in per-client folders with access limited to Sam and the recipients you authorise. No system is perfectly secure — see section 17 for how we respond if something goes wrong.
14. Access controls
Access to personal information is limited to the people who need it for the purposes above — in practice, Sam and, where you have authorised them, named recipients on your engagement. Any future contractor would be bound by written confidentiality and data handling obligations at least as strict as this policy before accessing any client information.
15. Your responsibilities when sending us data
Please send project materials only through the channels we agree for your engagement, and never send passwords, MFA codes, identity documents, or your own clients’ records unless we have specifically agreed a secure method and a genuine need. Where screenshots are needed, redact personal details that are not relevant — our evidence guidelines show you how. If you accidentally send something sensitive, tell us and we will delete it from the receiving channel.
16. Retention and deletion
We aim to keep information only while it serves the purposes above, while recognising that provider backups, security records, delivery logs, legal holds, and statutory obligations can affect the exact deletion date:
Enquiries that don’t become engagements: generally retained for no more than 12 months, then scheduled for deletion. Contact-delivery metadata may remain in Resend or email systems for the period set by those services. Engagement records and security findings: generally retained for 12 months after the engagement ends so we can support follow-up questions, then scheduled for secure deletion — or considered for earlier deletion on request. A legal obligation, active dispute, security need, or agreed engagement term may require a different period, in which case we document the reason. Contracts, invoices, and tax records: retained for the periods required by Australian law (generally up to seven years). Consent and unsubscribe records: kept while marketing continues, so your choices are honoured.
Public scanner records: result tokens expire after 30 minutes. Stored results carry a 30-minute expiry, abuse-prevention counters an expiry of up to 24 hours, and daily aggregates a 90-day expiry. Token expiry is not a guarantee of deletion at that time. Automated cleanup is not currently operational, so stored records may remain beyond their expiry until cleanup is performed.
Where our platforms allow, secure deletion includes clearing active storage, trash, and version history. Copies may persist for a limited period in encrypted backups or provider security logs before they rotate out under the provider’s retention schedule.
17. Data breach response
If a data breach involving personal information occurs, we follow our documented data breach response procedure: contain the incident, preserve evidence, assess the harm promptly, take remedial action, and notify affected individuals and the Office of the Australian Information Commissioner where required under the Notifiable Data Breaches scheme. Where the affected information belongs to a client engagement, we notify that client promptly with the facts — our standard is honesty first.
18. Access and correction requests
You can ask what personal information we hold about you, request a copy, or ask us to correct it. Email contact@yarrasecure.com.au with your request. We respond within 30 days, usually much faster, and we don’t charge for reasonable requests. If we cannot provide or correct something (for example, where the law requires us to retain a record), we will explain why.
19. Complaints
If you believe we have mishandled your personal information, contact us first — contact@yarrasecure.com.au or 0435 315 894 — and we will investigate and respond in writing within 10 business days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. We will cooperate fully with any OAIC process.
20. Updates to this policy
We review this policy at least annually and whenever our tools or practices change. The current version is always published at yarrasecure.com.au/privacy, with the “last updated” date below. Material changes affecting active clients are communicated directly.