Perth IT Care
Unit 4/264 Kalamunda Rd, Maida Vale WA
help@perthitcare.com.au · (08) 6336 7722
Last updated: 15-7-26
Perth IT Care is committed to protecting the privacy of the people whose personal information we handle. This policy explains what personal information we collect, how we use and disclose it, how we keep it secure, and how you can access or correct information we hold about you.
We handle personal information in accordance with the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth). You can read the APPs on the website of the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
This policy covers two groups of people:
Our clients and their representatives. If you are a business or an individual who engages Perth IT Care for IT support, web services, hosting, or related work, this policy covers the personal information we collect from and about you directly.
Individuals whose data we handle on behalf of our clients. As an IT service provider, we often access personal information stored in our clients' systems — for example, when we administer a client's Microsoft 365 tenant, we may access mailboxes, files, and directory records belonging to the client's staff and their contacts. In these cases, our client controls that information and instructs us on how it may be used. We handle it only to deliver the services our client has asked us to provide.
If you are an individual whose data we handle on behalf of one of our clients, you should also contact that client directly with any questions about how they use your personal information.
We collect personal information that is reasonably necessary for us to deliver our services, operate our business, and meet our legal obligations. The kinds of personal information we may collect include:
We collect this information directly from you where practicable — for example, when you engage our services, contact us, or use our website. Occasionally we may receive information about you from third parties, such as a referrer or another service provider, in which case we will take reasonable steps to make you aware of that.
We use your personal information to:
We do not sell your personal information. We do not use your personal information for marketing to third parties.
Sensitive information — including health information — receives additional protection under the Privacy Act. We only collect sensitive information where it is reasonably necessary for our services, and only with your consent or where required or authorised by law. We use it only for the purpose for which it was collected, or a directly related secondary purpose you would reasonably expect.
Delivering IT support requires us to access client devices, servers, and cloud services. To do this, we use industry-standard remote monitoring and management (RMM) tools, remote desktop tools, and administrative access to client cloud tenants (for example, Microsoft 365, Google Workspace, and hosting control panels).
While delivering support, we may see personal information stored on the devices and systems we access. We only access what is necessary to resolve the issue at hand, we do not retain copies of client data on our own systems except where necessary for service delivery, and our staff are bound by confidentiality obligations.
Clients can request records of our remote access activity at any time.
Where we administer a client's Microsoft 365 tenant, Google Workspace, or similar cloud environment, we hold delegated administrative access. This may allow us to see, but not routinely use, personal information belonging to the client's staff and contacts — including mailbox contents, files, calendar entries, and directory records.
We access this information only to deliver services the client has asked for, such as onboarding a new user, investigating a security incident, or configuring a mail flow rule. We do not access client tenant data for our own purposes.
We use AI service providers to help us deliver our services more efficiently — for example, to draft communications, analyse system data, summarise information, and generate documentation.
Where we use AI service providers, the information we share with them is only what is needed for the task. We use commercial AI services that contractually restrict how our data is used, do not train their models on our data, and provide contractual data protection commitments including Standard Contractual Clauses for international data transfers.
If we ever change how we use AI services in a way that materially affects how your personal information is handled, we will update this policy.
Where we hold credentials on behalf of clients (for example, service account passwords, API keys, or admin credentials), we store them in a dedicated encrypted credential vault with access limited to authorised staff. Credentials are removed when they are no longer needed for the service we deliver.
We share personal information with third-party service providers who help us deliver our services. These providers only receive the information they need to perform their function for us, and they are bound by contractual and legal obligations to protect it.
Our current key service providers include:
| Provider | Purpose | Location of processing |
|---|---|---|
| Microsoft | Client tenant administration, our own email and productivity tools | Australia and United States |
| Atera | Remote monitoring and management (RMM) | United States |
| Xero | Accounting and billing | Australia |
| Keeper Security | Credential storage | United States |
| Synergy Wholesale | Web hosting, domain registration, DNS | Australia |
| PRISM / Rhipe | Microsoft 365 licence provisioning | Australia |
| Acronis | Cloud backup services | Multiple regions, per client configuration |
| Vocus | Voice and Teams telephony services | Australia |
| AI service providers | AI-assisted drafting, analysis, and documentation | United States |
| Google Workspace administration (where applicable) | Australia and United States |
We may also disclose your personal information where required or authorised by law, in response to a lawful request from a government or regulatory body, or where necessary to protect our rights or the safety of others.
Some of the service providers listed above process personal information outside Australia. Where personal information is sent overseas, we take reasonable steps to ensure the overseas recipient handles it consistently with the APPs, including through contractual protections such as Standard Contractual Clauses.
By providing us with your personal information, you acknowledge that some of it may be processed overseas as described above.
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our measures include:
No system is completely secure, and we cannot guarantee absolute security of information transmitted over the internet.
We take data security seriously. If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information we hold, we will notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
We keep personal information only for as long as we need it, or as long as we are required to keep it by law. In general:
When personal information is no longer needed, we take reasonable steps to destroy or de-identify it.
Our website (www.perthitcare.com.au) uses cookies and similar technologies to help the site function and to understand how visitors use it. You can control cookies through your browser settings. Disabling cookies may affect how the site functions for you.
You have the right to ask what personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, or misleading.
To make a request, contact us using the details at the top of this policy. We may need to verify your identity before we release information. There is no charge for making a request, but we may charge a reasonable administrative fee if we need to compile a significant amount of information.
We will respond to your request within a reasonable time, generally within 30 days.
If you have a concern about how we have handled your personal information, please contact us first using the details at the top of this policy. We will acknowledge your complaint promptly and aim to respond within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner:
We may update this policy from time to time. The current version is always available on our website. The "Last updated" date at the top of this policy shows when it was last changed.
This policy was last reviewed on 15-7-26.