Legal
Privacy Policy.
What we collect, why we have it, where it lives, and how we move it between us and you without leaving it lying around.
Effective 21 August 2026 · version 1.0
- 1. Who we are
- 2. The standard we hold ourselves to
- 3. What this website collects
- 4. What we collect when you deal with us
- 5. Sensitive information
- 6. What we never hold
- 7. How we use information
- 8. Exchanging information securely
- 9. When we work inside your systems
- 10. Who else handles it, and where
- 11. How we protect it
- 12. How long we keep it
- 13. If something goes wrong
- 14. Access, correction and complaints
- 15. Links to other sites
- 16. Changes to this policy
- 17. Contact us
1. Who we are
Business Innovise Hub Pty Ltd (ACN 680 230 362), of Moama NSW 2731 — “we”, “us”, “BIH” — is a consulting and digital solutions business. We provide business IT and Microsoft 365 support, websites, custom software and systems, AI training, cybersecurity awareness training, and strategy and consulting. We also build and operate our own software platforms.
This policy covers personal information we handle as a business: through this website, when you enquire or become a client, when we work on systems that hold your organisation’s data, and when people apply to work with us. Individual platforms and client systems may have their own privacy terms that sit alongside this one — where they do, the more specific document governs that system.
2. The standard we hold ourselves to
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and we follow the Notifiable Data Breaches scheme. Some small businesses are exempt from parts of that Act because of their turnover. We do not rely on that exemption. We work with health and disability information, and the sensible position for a business in that field is to meet the standard rather than argue about whether it applies to us.
Where we handle health information we also have obligations under state health-records law — principally the Health Records and Information Privacy Act 2002 (NSW) and the Health Records Act 2001 (Vic), depending on where the organisation and the individuals are.
3. What this website collects
Very little, and we would rather be specific than reassuring:
- This site sets no cookies. There is no analytics, no advertising or conversion pixel, and no session tracking. Nothing on this website follows you between pages, or between sites.
- The contact form does not send us anything by itself. It assembles your answers into a draft email in your own email program, addressed to us. Nothing leaves your device until you press send, and if you close the draft we never see it.
- Our host sees the usual connection data. The site is served by Cloudflare, which processes the technical details of each request — including your IP address — to deliver pages and to protect the site from attack and abuse.
- Our typefaces are loaded from Google Fonts. That means your browser requests files from Google’s servers, and your IP address and browser details reach Google as part of that request. We do not receive that information.
4. What we collect when you deal with us
- When you enquire
- Your name, the organisation you are with, your email address and phone number, and whatever you tell us about what you need.
- When you become a client
- Contact details for the people we deal with, billing and account details, the agreements and scoping notes between us, records of the work, support requests, and the correspondence that goes with all of it.
- Information inside the systems we work on
- To build, migrate, support or repair a system, we sometimes need access to the data it holds. For our clients that can include information about their clients, patients, participants, residents, members, staff or customers. We treat that as the client organisation’s information, held on their instructions — see section 9.
- When you apply for a role
- Your application, CV, referee details and our notes from the process. If we do not proceed, we keep the application only as long as we might reasonably need it, then destroy it.
- When you attend training
- Attendance and, for cybersecurity awareness training, results of simulated exercises. Where we report to an employer we agree in advance whether reporting is individual or aggregate.
We collect information directly from you wherever we can. If we ever collect it from someone else — a referrer, or a colleague who passes on your details — we will tell you.
5. Sensitive information
Some of what we handle is sensitive information under the Privacy Act. It attracts stricter rules, and it is the reason this policy exists in this much detail. In our work it can include:
- Health information — care and clinical records, progress notes, medication and observation records, incident reports.
- Disability information, including NDIS participant details, plans and funding.
- Criminal record and screening checks held for a client’s staff compliance, such as police checks and working-with-children or NDIS worker screening.
- Where a client’s records contain them: racial or ethnic origin, religious beliefs, sexual orientation, or union membership.
We collect sensitive information only where we need it to do the work you have engaged us for, or where the law requires or permits it. We do not use it for anything else, and we never use it for marketing.
6. What we never hold
We do not store your card numbers. We do not collect, hold or record credit or debit card numbers, expiry dates or security codes (CVV). If a payment ever needs a card, it is taken through a payment provider’s own system and the card details go to them, not to us.
We also do not keep your passwords in readable form. Where we need access to a system of yours we ask for a named account of our own, or an administrator consent flow that you control and can revoke.
7. How we use information
- To answer your enquiry and quote for work.
- To deliver, support and improve the services you have engaged us for.
- To invoice you and keep the business records the law requires.
- To keep systems secure — investigating faults, misuse and security incidents.
- To meet a legal obligation, or where the law otherwise requires or permits it.
We do not sell personal information. We do not trade, rent or share it for anyone else’s marketing. If we ever want to use something you have given us as a public reference, we will ask you first and we will show you the exact wording.
8. Exchanging information securely
Most privacy incidents are not break-ins. They are ordinary material sent by an ordinary route to slightly the wrong person. So the way we move files and messages between us matters as much as where we store them.
What we use
- Secure sharing links from our Microsoft 365 environment, rather than attachments. A link is issued to named recipients, can be set to expire, and can be switched off afterwards — which an attachment sitting in a mailbox cannot.
- Microsoft 365 email, encrypted in transit between mail systems that support it, with message protection applied where the content warrants it.
- Your own system where you have one. If you have a secure portal, document library or ticketing system, we would rather use yours than move the material at all.
What we ask of you
Please do not send us sensitive material by SMS or consumer messaging apps, through a public file-sharing link, or as an unprotected attachment to a personal email address. If you are not sure how to get something to us safely, ask us and we will send you a secure link to upload it.
No method of transmission is perfectly secure, and we will not pretend otherwise. What we can say is that we choose the channel deliberately, we keep the number of copies down, and we remove access when the work is finished.
9. When we work inside your systems
When we build, host, migrate or support a system for an organisation, the personal information in it belongs to that organisation’s relationship with its own people — not to ours. In that work:
- The organisation decides what is collected and why. We act on their instructions.
- Our access is the least we need to do the job, under named accounts, and it is removed when the engagement or the task ends.
- We do not use anything we see in a client’s system for our own purposes, and we do not move it into our own records except where we need to in order to do the work.
- Systems we build and run for clients are provisioned with a separate database per organisation, so one client’s records are not sitting in a shared table with another’s.
- Where we use demonstration data to show a system, it is invented. We do not demonstrate on a real client’s records.
If you are an individual whose information sits in a system we run for an organisation, that organisation is the right place to start for access, correction or a complaint. Tell us and we will help them respond.
10. Who else handles it, and where
We use a small number of established providers to run the business, and each one only sees what it needs to:
- Microsoft — Microsoft 365 for our email, documents and secure sharing.
- Cloudflare — hosting, content delivery and protection for our websites.
- DigitalOcean — infrastructure for the systems we build and operate, hosted in Sydney, Australia.
- Accounting, payment and email-delivery providers — for invoicing and for the transactional email a system sends on your behalf.
We disclose personal information to a provider only so it can perform that function for us, and we require it to be handled accordingly.
Information going outside Australia
The systems we build for clients are hosted in Australia. Some of the services above are global, so parts of their processing, support or backup may happen outside Australia — including in the United States and Europe. Before we use a provider for anything sensitive we check what it commits to, and if a project needs sensitive information to be processed overseas we will tell you which service, which country and why, before it happens.
We may also disclose information where the law requires it — for example to a regulator, or in response to a court order.
11. How we protect it
Specifics rather than adjectives:
- Multi-factor authentication on every account of ours that can reach client information.
- Named individual accounts and least privilege. No shared logins, and access scoped to the job.
- Encryption in transit for our websites, systems and mail, and encryption at rest as provided by the platforms we use.
- Credentials kept in a password manager — not in email, chat or documents.
- Company devices with disk encryption, screen locks and current updates.
- Separation between clients in the systems we host, and separation between our test and live environments.
- Access reviewed and removed when a person changes role or an engagement ends.
- Backups for the systems we operate, with restores tested rather than assumed.
What we do not claim. We hold no ISO 27001 or SOC 2 certification and we do not describe our security as bank-grade or military-grade. We are a two-founder business that follows the practices above. If you need a certified supplier, tell us early and we will say so plainly rather than compete for the work.
12. How long we keep it — and what happens when you leave
When an engagement ends, we hand over and then we let go. You get a complete copy of your data, in a usable format, and then we remove ours — including from backups, as those cycle out. We are not a long-term archive of your information, and you should not rely on us as one. Take the handover copy and keep it somewhere you control.
Otherwise we keep personal information only as long as we have a reason to:
- Enquiries that do not become work — kept while there is a live conversation, then destroyed.
- Project material — working copies, exports and migration files are deleted once the work is delivered and verified.
- Data inside a system we run for a client — kept to that client’s own retention rules while the system is live, and handed back and removed when it is not.
- Our own accounting and contract records — the agreement and the invoices between us are our business records, and tax and corporate law requires us to keep those for a period after the work ends. That is a record of the commercial relationship, not a copy of your data, and nothing of yours can be retrieved from it.
When we no longer need something and are not required to keep it, we destroy it or de-identify it.
13. If something goes wrong
If we suspect a data breach we investigate straight away, contain it, and assess whether it is likely to cause serious harm. Where it is, we notify the affected individuals and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires. If the breach involves a system we run for a client, we tell that client first and promptly, because the notification is theirs to make and they need the facts to make it.
We will tell you what happened, what information was involved, and what to do about it. We would rather report an incident awkwardly than quietly.
14. Access, correction and complaints
You can ask us what personal information we hold about you, ask for a copy, and ask us to correct it if it is wrong or out of date. Email [email protected] and we will respond within 30 days. We may need to verify who you are first. There is no charge to ask; if a request needs substantial work we will tell you the cost before doing it.
A request reaches what we still hold when you ask. As section 12 says, once an engagement has ended and we have handed your data back, we no longer hold it — so there is nothing for us to retrieve, and the copy you were given is the record.
There are other limited situations where we cannot give access — for example where doing so would reveal someone else’s personal information, or where the information belongs to a client’s system rather than to us. If we refuse, we will tell you why in writing.
If you think we have mishandled your personal information, tell us and we will look into it and reply. If you are not satisfied with our response, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
15. Links to other sites
Where we link to another organisation’s site, their privacy practices are theirs, not ours. Read their policy before giving them anything.
16. Changes to this policy
We update this page when our practices change. The effective date at the top tells you which version you are reading. If a change materially affects how we handle information we already hold about you, we will tell you rather than rely on you noticing.
17. Contact us
Privacy questions, access requests and complaints:
- Email — [email protected]
- Phone — +61 487 468 588, Monday to Friday 9am–5pm
- Post — Business Innovise Hub Pty Ltd, Moama NSW 2731