Privacy Policy

Perth IT Care
Unit 4/264 Kalamunda Rd, Maida Vale WA
help@perthitcare.com.au · (08) 6336 7722

Last updated: 15-7-26


1. About this policy

Perth IT Care is committed to protecting the privacy of the people whose personal information we handle. This policy explains what personal information we collect, how we use and disclose it, how we keep it secure, and how you can access or correct information we hold about you.

We handle personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth). You can read the APPs on the website of the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

2. Who this policy covers

This policy covers two groups of people:

Our clients and their representatives. If you are a business or an individual who engages Perth IT Care for IT support, web services, hosting, or related work, this policy covers the personal information we collect from and about you directly.

Individuals whose data we handle on behalf of our clients. As an IT service provider, we often access personal information stored in our clients' systems — for example, when we administer a client's Microsoft 365 tenant, we may access mailboxes, files, and directory records belonging to the client's staff and their contacts. In these cases, our client controls that information and instructs us on how it may be used. We handle it only to deliver the services our client has asked us to provide.

If you are an individual whose data we handle on behalf of one of our clients, you should also contact that client directly with any questions about how they use your personal information.

3. What we collect and why

We collect personal information that is reasonably necessary for us to deliver our services, operate our business, and meet our legal obligations. The kinds of personal information we may collect include:

  • Contact details (name, business name, email, phone, address)
  • Billing and payment information
  • Technical information about your systems and devices (only where relevant to services we deliver)
  • Records of our communications with you (emails, tickets, phone notes)
  • Credentials required to deliver contracted services (stored in a dedicated credential vault, described below)
  • Website usage information collected via cookies and analytics on our website

We collect this information directly from you where practicable — for example, when you engage our services, contact us, or use our website. Occasionally we may receive information about you from third parties, such as a referrer or another service provider, in which case we will take reasonable steps to make you aware of that.

We use your personal information to:

  • Deliver the services you have engaged us for
  • Communicate with you about your services, your account, and support matters
  • Bill you and process payments
  • Maintain accurate records
  • Comply with legal and regulatory obligations
  • Improve our services

We do not sell your personal information. We do not use your personal information for marketing to third parties.

4. Sensitive information

Sensitive information — including health information — receives additional protection under the Privacy Act. We only collect sensitive information where it is reasonably necessary for our services, and only with your consent or where required or authorised by law. We use it only for the purpose for which it was collected, or a directly related secondary purpose you would reasonably expect.

5. Remote access to client systems

Delivering IT support requires us to access client devices, servers, and cloud services. To do this, we use industry-standard remote monitoring and management (RMM) tools, remote desktop tools, and administrative access to client cloud tenants (for example, Microsoft 365, Google Workspace, and hosting control panels).

While delivering support, we may see personal information stored on the devices and systems we access. We only access what is necessary to resolve the issue at hand, we do not retain copies of client data on our own systems except where necessary for service delivery, and our staff are bound by confidentiality obligations.

Clients can request records of our remote access activity at any time.

6. Administration of client Microsoft 365 and cloud tenants

Where we administer a client's Microsoft 365 tenant, Google Workspace, or similar cloud environment, we hold delegated administrative access. This may allow us to see, but not routinely use, personal information belonging to the client's staff and contacts — including mailbox contents, files, calendar entries, and directory records.

We access this information only to deliver services the client has asked for, such as onboarding a new user, investigating a security incident, or configuring a mail flow rule. We do not access client tenant data for our own purposes.

7. Use of AI service providers

We use AI service providers to help us deliver our services more efficiently — for example, to draft communications, analyse system data, summarise information, and generate documentation.

Where we use AI service providers, the information we share with them is only what is needed for the task. We use commercial AI services that contractually restrict how our data is used, do not train their models on our data, and provide contractual data protection commitments including Standard Contractual Clauses for international data transfers.

If we ever change how we use AI services in a way that materially affects how your personal information is handled, we will update this policy.

8. Credential storage

Where we hold credentials on behalf of clients (for example, service account passwords, API keys, or admin credentials), we store them in a dedicated encrypted credential vault with access limited to authorised staff. Credentials are removed when they are no longer needed for the service we deliver.

9. Who we share information with

We share personal information with third-party service providers who help us deliver our services. These providers only receive the information they need to perform their function for us, and they are bound by contractual and legal obligations to protect it.

Our current key service providers include:

Provider Purpose Location of processing
Microsoft Client tenant administration, our own email and productivity tools Australia and United States
Atera Remote monitoring and management (RMM) United States
Xero Accounting and billing Australia
Keeper Security Credential storage United States
Synergy Wholesale Web hosting, domain registration, DNS Australia
PRISM / Rhipe Microsoft 365 licence provisioning Australia
Acronis Cloud backup services Multiple regions, per client configuration
Vocus Voice and Teams telephony services Australia
AI service providers AI-assisted drafting, analysis, and documentation United States
Google Google Workspace administration (where applicable) Australia and United States

We may also disclose your personal information where required or authorised by law, in response to a lawful request from a government or regulatory body, or where necessary to protect our rights or the safety of others.

10. Sending information overseas

Some of the service providers listed above process personal information outside Australia. Where personal information is sent overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the APPs, including through contractual protections such as Standard Contractual Clauses.

By providing us with your personal information, you acknowledge that some of it may be processed overseas as described above.

11. How we protect your information

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our measures include:

  • Multi-factor authentication on our systems and administrative accounts
  • Encrypted credential storage
  • Endpoint protection on staff devices
  • Access limited to staff who need it for their role
  • Confidentiality obligations for all staff and contractors
  • Regular review of security practices

No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.

12. Data breach notification

We take data security seriously. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information we hold, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act.

13. How long we keep your information

We keep personal information only for as long as we need it, or as long as we are required to keep it by law. In general:

  • Financial and billing records: at least 7 years, as required by Australian tax law
  • Contracts and engagement records: for the duration of our engagement with you, and for a further 6 years after the engagement ends
  • Support and ticket history: for the duration of our engagement, and for a reasonable period afterwards to allow us to respond to follow-up queries
  • Credentials: only while needed for a current service; removed when no longer needed
  • Marketing information: only while you have consented to receive marketing from us
  • Website analytics: in accordance with our analytics provider's standard retention (typically no more than 26 months)

When personal information is no longer needed, we take reasonable steps to destroy or de-identify it.

14. Website and cookies

Our website (www.perthitcare.com.au) uses cookies and similar technologies to help the site function and to understand how visitors use it. You can control cookies through your browser settings. Disabling cookies may affect how the site functions for you.

15. Accessing and correcting your information

You have the right to ask what personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, or misleading.

To make a request, contact us using the details at the top of this policy. We may need to verify your identity before we release information. There is no charge for making a request, but we may charge a reasonable administrative fee if we need to compile a significant amount of information.

We will respond to your request within a reasonable time, generally within 30 days.

16. Complaints

If you have a concern about how we have handled your personal information, please contact us first using the details at the top of this policy. We will acknowledge your complaint promptly and aim to respond within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:

17. Changes to this policy

We may update this policy from time to time. The current version is always available on our website. The "Last updated" date at the top of this policy shows when it was last changed.


This policy was last reviewed on 15-7-26.