privacy --plain-english
Privacy
We sell security work. A privacy policy nobody can read would be a poor advertisement for it, so this one says what actually happens in words you can check.
Where we stand
We are not legally bound by the Privacy Act. We follow it anyway.
IN-SEC is under the $3 million small business threshold and is therefore not currently bound by the Privacy Act 1988. We do not rely on that. We meet the Australian Privacy Principles voluntarily and honour the rights below for anyone who asks, wherever they live. We have not opted in to the Privacy Act via the OAIC register.
There is a second reason beyond principle. The statutory tort for serious invasions of privacy commenced on 10 June 2025 and reaches organisations that are not bound by the Privacy Act. Being exempt from the Act does not make you exempt from misusing someone’s information.
What we collect, and when
If you email us
We get whatever you put in the email — your name, your email address, your phone number if you include it, and whatever you tell us about your business. If you attach a questionnaire, we get that too. We use it to answer you and, if it goes further, to scope the work.
Every time anyone loads a page
Our host records the standard web server log: the IP address the request came from, the page requested, the time, and the browser used. That happens on every website and we cannot switch it off. We do not use those logs to build a picture of you, and we do not try to work out who you are from them.
Booking a call — not live yet
The online booking calendar is not switched on. When it is, it will ask for your name, your email address, how many staff you have, whether you run Microsoft 365 or Google Workspace, and what prompted you to book. This page will be updated on the day that changes, not afterwards.
What we do not collect
We do not run advertising or remarketing, we do not sell or share your information with anyone for their own purposes, and we do not collect sensitive information through this website. There is no login, so there is no account and no password.
Who else sees it
These are the services we use today. All of them store information outside Australia, which means your information may be handled overseas.
| Service | What for | Where |
|---|---|---|
| Hostinger | Website hosting and server logs | Overseas |
| Email provider | Receiving and storing enquiries sent to our address | Overseas |
Not yet in use, and listed here so the picture is complete rather than flattering: Cal.com (Booking the twenty-minute call). Google Analytics 4 (Counting page views and where visitors came from). Microsoft Clarity (Anonymised session recordings, excluding the contact page). HubSpot (Recording enquiries and conversations). Each one will move into the table above on the day it is switched on.
How long we keep it
- Enquiry emails and the conversation that follows — Five years from our last contact, which is the general period the Australian Taxation Office requires business records to be kept.
- Server logs, including IP addresses — Kept only as long as our host retains them, and not used to build a profile of you.
- Booking details — Deleted once the call has happened and any follow-up is closed, unless you become a client.
What you can ask us to do
These apply to anyone who asks, wherever you live. We are not going to check which country you are in before deciding whether you have rights over your own information.
- Ask what we hold — We will tell you, in plain terms, within a reasonable time and at no cost.
- Correct it — If something we hold about you is wrong, tell us and we will fix it.
- Have it deleted — Ask and we will delete it, unless we are required to keep it.
- Object, or ask us to stop — Tell us to stop contacting you and we will, permanently.
- Complain — To us first. If we do not resolve it, you can take it to the Office of the Australian Information Commissioner.
Email enquiries@in-sec.org and put Privacy request in the subject line. We will acknowledge within two business days.
If we get it wrong
Tell us first, at the address above, and we will look into it and write back. If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. You do not need our permission to do that.
Keeping it safe
This site collects nothing through a form, so there is nothing to intercept in transit beyond the page itself, which is served over HTTPS. Enquiry emails sit in a mailbox protected by multi-factor authentication. Client assessment material is handled under the separate terms in your engagement letter, which are stricter than this page.