Last updated

Privacy policy.

InfoSec Collective is a collective of senior information security practitioners. This notice explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For any privacy question or request, contact us at privacy@infoseccollective.com.au.

What we collect

We collect personal information both directly from you and automatically as you use the site. The table below is a guide, not an exhaustive list.

Information How we collect it Why we collect it
Contact and identity details — name, email, organisation Directly, when you submit the contact form or correspond with us Responding to your enquiry
Engagement and service data Directly, as part of delivering a service to you Service delivery
Usage and device information — pages viewed, browser type, approximate location Automatically, through cookies and analytics when you visit the site Analytics and improvement
IP address and browser or device security signals Automatically, through Cloudflare Turnstile when you use the contact form Bot protection

Sensitive information

We do not seek to collect sensitive information. As defined in the Privacy Act 1988 (Cth), this includes information about your health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal record. Please do not submit it through our contact form or in correspondence. Where we receive sensitive information we did not ask for, we will destroy or de-identify it as soon as practicable, unless the law requires us to retain it.

How we use it

  • To respond to your enquiry and deliver a service you have engaged us for.
  • To keep the site secure, troubleshoot issues, and understand how it is used.
  • To contact you about a service, or where you have opted in to marketing from us. You can opt out of marketing at any time.
  • We may share your details with the sub-processors listed below, for the purpose shown against each of them. We do not share your details with another party for their own use, except where required for compliance purposes or to comply with a valid legal request.

Cookies

We use two kinds of cookies: essential cookies that keep the site working, and analytics cookies that help us understand how it is used. Our analytics are provided by Google — see the sub-processors table below. You can block or delete cookies at any time through your browser settings, though blocking essential cookies may affect how the site functions.

Sub-processors

We rely on a small number of trusted providers to operate the service. We select providers that are subject to privacy and security obligations consistent with this notice. Some hold data outside Australia; where they do, the country is shown below.

Provider Purpose Where data is held
Microsoft Email Australia
SMTP2GO Contact-form email delivery Australia
Cloudflare Website hosting and bot protection (Turnstile) Globally
Google Analytics United States

Cloudflare operates a global edge network by design, serving the site from the location nearest to each visitor, so a fixed list of countries is not practicable. The locations shown reflect how we currently configure each provider and may change as the service evolves; we will update this table when it does.

When you use the contact form, Cloudflare Turnstile processes your IP address and browser or device security signals on our behalf to tell humans from bots, and Cloudflare also uses those signals to improve its bot-detection service. We do not provide the contents of the contact form — your name, email, organisation, or message — to Cloudflare for this purpose.

Retention

  • Data collected through a service with you is retained for the duration of our relationship with you.
  • All other data — including contact form submissions, email correspondence, and analytics — is retained for up to 12 months.

Security

We apply industry-standard controls to protect the information we hold on your behalf. Given what we do for a living, we treat this as foundational rather than incidental.

Data breaches

If an eligible data breach occurs — one that is likely to result in serious harm to an affected individual — we will act to contain it and notify the affected individuals and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.

Children

Our services are built for organisations and the people who work in them. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@infoseccollective.com.au and we will delete it.

Dealing with us anonymously

You can interact with us anonymously or using a pseudonym where it is practicable for us to deal with you that way. Some interactions require us to verify your identity — for example, actioning a privacy request — and we cannot proceed anonymously in those cases.

Automated decisions

We do not make decisions that affect you using solely automated processing of your personal information.

Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may request access to the personal information we hold about you and correction of anything that is inaccurate, out of date, or incomplete. Beyond those statutory rights, we also choose to offer erasure, restriction, and portability of your information where it is practicable for us to provide them. Email privacy@infoseccollective.com.au to exercise any of these.

Complaints

If you believe we have mishandled your personal information, tell us first at privacy@infoseccollective.com.au. We will acknowledge your complaint within 5 business days and aim to give you a full response within 30 days. If you are not satisfied with our response, you can escalate the matter to the Office of the Australian Information Commissioner at oaic.gov.au.

Updates

We will update this notice as our services evolve. Monitor this page for the latest version.