Last updated

Privacy policy.

InfoSec Collective is a collective of senior information security practitioners. This notice explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For any privacy question or request, contact us at privacy@infoseccollective.com.au.

What we collect

We collect personal information both directly from you and automatically as you use the site. The table below is a guide, not an exhaustive list.

Information How we collect it Why we collect it
Contact and identity details — name, email, organisation Directly, when you submit the contact form or correspond with us Responding to your enquiry
Engagement and service data Directly, as part of delivering a service to you Service delivery
Usage and device information — pages viewed, referring site, browser and device type, country Automatically, through Cloudflare Web Analytics when you visit the site Analytics and improvement
IP address and browser or device security signals Automatically, through Cloudflare Turnstile when you use the contact form Bot protection

Sensitive information

We do not seek to collect sensitive information. As defined in the Privacy Act 1988 (Cth), this includes information about your health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, or criminal record. Please do not submit it through our contact form or in correspondence. Where we receive sensitive information we did not ask for, we will destroy or de-identify it as soon as practicable, unless the law requires us to retain it.

How we use it

  • To respond to your enquiry and deliver a service you have engaged us for.
  • To keep the site secure, troubleshoot issues, and understand how it is used.
  • To contact you about a service, or where you have opted in to marketing from us. You can opt out of marketing at any time.
  • We may share your details with the sub-processors listed below, for the purpose shown against each of them. We do not share your details with another party for their own use, except where required for compliance purposes or to comply with a valid legal request.

Cookies

We set no cookies of our own, and our analytics set none. Cloudflare Web Analytics counts page views without setting cookies, without writing to your browser’s local storage, and without fingerprinting your browser or device. It does not identify you, track you across sites, or track you over time. It derives a country from your IP address as the page loads; the analytics record keeps the country and not the address.

The Cloudflare Turnstile widget on our contact page is served by Cloudflare from its own domain and runs under Cloudflare’s own terms. To run and secure the challenge, Cloudflare may store data on your device, including cookies. We do not control what it stores and we do not read it. See the sub-processors table below for what Turnstile processes on our behalf.

Separately from analytics, Cloudflare receives your IP address whenever it serves you a page, and processes it to deliver and secure the site. You can block or delete stored data at any time through your browser settings, though blocking it may stop the contact form’s bot check from completing.

Sub-processors

We rely on a small number of trusted providers to operate the service. We select providers that are subject to privacy and security obligations consistent with this notice. Some hold data outside Australia; where they do, the country is shown below.

Provider Purpose Where data is held
Microsoft Email Australia
SMTP2GO Contact-form email delivery Australia
Cloudflare Website hosting, analytics, and bot protection (Turnstile) Globally

Cloudflare operates a global edge network by design, serving the site from the location nearest to each visitor, so a fixed list of countries is not practicable. The locations shown reflect how we currently configure each provider and may change as the service evolves; we will update this table when it does.

When you use the contact form, Cloudflare Turnstile processes your IP address and browser or device security signals on our behalf to tell humans from bots, and Cloudflare also uses those signals to improve its bot-detection service. We do not provide the contents of the contact form — your name, email, organisation, or message — to Cloudflare for this purpose.

Retention

  • Data collected through a service with you is retained for the duration of our relationship with you.
  • All other data — including contact form submissions, email correspondence, and analytics — is retained for up to 12 months.

Security

We apply industry-standard controls to protect the information we hold on your behalf. Given what we do for a living, we treat this as foundational rather than incidental.

Data breaches

If an eligible data breach occurs — one that is likely to result in serious harm to an affected individual — we will act to contain it and notify the affected individuals and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme.

Children

Our services are built for organisations and the people who work in them. They are not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, email privacy@infoseccollective.com.au and we will delete it.

Dealing with us anonymously

You can interact with us anonymously or using a pseudonym where it is practicable for us to deal with you that way. Some interactions require us to verify your identity — for example, actioning a privacy request — and we cannot proceed anonymously in those cases.

Automated decisions

We do not make decisions that affect you using solely automated processing of your personal information.

Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you may request access to the personal information we hold about you and correction of anything that is inaccurate, out of date, or incomplete. Beyond those statutory rights, we also choose to offer erasure, restriction, and portability of your information where it is practicable for us to provide them. Email privacy@infoseccollective.com.au to exercise any of these.

Complaints

If you believe we have mishandled your personal information, tell us first at privacy@infoseccollective.com.au. We will acknowledge your complaint within 5 business days and aim to give you a full response within 30 days. If you are not satisfied with our response, you can escalate the matter to the Office of the Australian Information Commissioner at oaic.gov.au.

Updates

We will update this notice as our services evolve. Monitor this page for the latest version.