Privacy Policy
iTecz Solutions is committed to protecting your privacy. This policy explains how we collect, hold, use, disclose and protect your personal information across our website and all of our products, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1 Who this policy covers
This Privacy Policy applies to iTecz Solutions Pty Ltd (ACN 621 473 256), trading as iTecz Solutions (“iTecz”, “we”, “us” or “our”). We are an Australian software studio, and we are the entity responsible for the personal information handled across:
- our corporate website at itecz.au; and
- each of our products and services, including CFM (treasury & finance), KKMS (kitchen & restaurant management), KKDM (asset & maintenance ERP), Penetration Testing, Secure Code Review and Open Source Security, including their respective subdomains (cfm.itecz.au, kkms.itecz.au, kkdm.itecz.au, vapt.itecz.au, scr.itecz.au and oss.itecz.au).
Because all of these products are operated by the same legal entity, a single privacy policy governs them all. By using our website or services, you agree to the handling of your personal information as described here. Where we provide a product or service under a separate written agreement, that agreement may include additional privacy or data-processing terms, which apply alongside this policy.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in the Privacy Act 1988 (Cth).
2 The information we collect
The kinds of personal information we collect depend on how you interact with us. They may include:
| Category | Examples |
|---|---|
| Contact & identity | Name, business name, job title, email address, phone number, postal address. |
| Account & usage | Login credentials, settings and the records you create while using our products. |
| Communications | Enquiries, support requests, feedback and correspondence you send us. |
| Technical & device | IP address, browser and device type, and standard server-log information recorded when you visit our sites. |
| Engagement data (security services) | For Penetration Testing, Secure Code Review and related services: scoping details, system information and findings you authorise us to assess under a signed engagement. |
Sensitive information
We do not generally seek sensitive information (such as health, racial, political or biometric information). If we ever need to collect it, we will do so only with your consent and where reasonably necessary, unless an exception under the Privacy Act applies.
3 How we collect personal information
We collect personal information in the following ways:
- Directly from you — when you contact us, request a demo or quote, sign up for or use a product, enter into an engagement, or correspond with us.
- Automatically — through standard server logs when you visit our websites (for example, your IP address and browser type).
- From third parties — such as your employer or organisation, our service providers, or publicly available sources, where it is reasonable and lawful to do so.
Where it is reasonable and practicable, we collect personal information directly from you. If you provide us with personal information about another person, you must ensure you are authorised to do so and that they are aware of this policy.
4 Why we collect, hold, use and disclose it
We collect and use personal information for purposes connected with our business, including to:
- provide, operate, maintain and improve our websites, products and services;
- respond to your enquiries and provide customer and technical support;
- create and administer accounts, process orders and manage billing;
- deliver services we are engaged to perform, including security assessments;
- send you service, support and account messages;
- maintain security, prevent fraud and misuse, and keep audit trails;
- comply with our legal obligations and enforce our agreements.
We will only use or disclose your personal information for the purpose for which it was collected, for a directly related secondary purpose you would reasonably expect, or where you have consented or the law otherwise permits or requires it (APP 6).
5 Who we disclose your information to
We may disclose your personal information to:
- Service providers who help us run our business — including cloud hosting, infrastructure, email and support tools — under obligations of confidentiality;
- Professional advisers such as our lawyers, accountants and auditors;
- Government, regulatory or law enforcement bodies where required or authorised by law;
- A purchaser or successor in the event of a sale, merger or restructure of our business.
We do not sell your personal information.
6 How we keep your information secure
We store your personal information on servers located in Australia, and take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure (APP 11). These steps include access controls, encryption in transit, audit logging, secure development practices and staff confidentiality obligations. No method of transmission or storage is completely secure, however, and we cannot guarantee absolute security.
Notifiable Data Breaches
If a data breach occurs that is likely to result in serious harm to affected individuals, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.
7 Accessing & correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading (APPs 12 and 13). To make a request, contact us using the details below. We will respond within a reasonable period and may need to verify your identity first. In limited cases the law allows us to decline access, in which case we will explain why.
8 How long we keep your information
We keep personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to keep it by law. When it is no longer needed, we take reasonable steps to securely destroy or de-identify it.
9 Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact us first using the details below so we can investigate and respond. We will acknowledge your complaint and aim to resolve it within a reasonable time.
If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
10 Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The current version will always be available on this page, with the “Last updated” date shown at the top. We encourage you to review it periodically.
11 Contact us
For any privacy question, request or complaint, please contact our Privacy Officer:
iTecz Solutions Pty Ltd — Privacy Officer
Email: support@itecz.com.au
Post: 10 Layton Court, Truganina, Victoria 3029, Australia