Privacy Policy
This document outlines how Stoic IT collects, uses, and protects your personal information when you interact with our services. Your privacy is our priority.
PStoic IT ("we", "us", "our") is committed to protecting the privacy of your personal information. This Privacy Policy explains how we collect, hold, use, and disclose your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Privacy and Other Legislation Amendment Act 2024 (Cth).
As a provider of IT services to healthcare organisations, we recognise the heightened sensitivity of the environments in which we operate and take our privacy obligations seriously.
1. What Personal Information We Collect
We may collect the following types of personal information:
(a) Contact information: your name, email address, phone number, and company name, collected through our website contact form ("Book a conversation").
(b) Communication records: the content of your enquiry or message submitted through our website form, email correspondence, or phone conversations.
(c) Technical data: your IP address, browser type and version, operating system, referral source, pages visited, time and date of visits, and other website usage data collected through cookies and analytics tools.
(d) Business information: details about your organisation, IT environment, and service requirements that you provide during consultations or onboarding.
We do not collect sensitive information (as defined in the Privacy Act) through this Website. If sensitive information is required in the course of providing our services, we will obtain your explicit consent before collecting it.
2. How We Collect Personal Information
We collect personal information:
(a) directly from you, when you submit an enquiry through our website contact form, email us, call us, or engage with us in person;
(b) from third parties, such as referral partners or your existing IT providers, where you have consented to or would reasonably expect such disclosure; and
(c) automatically, through cookies, web analytics tools (such as Google Analytics), and server logs when you visit our Website.
Where practicable, we will collect personal information directly from you. We will not collect personal information unless it is reasonably necessary for our business functions or activities.
3. Why We Collect and How We Use Personal Information
We collect and use your personal information for the following purposes:
(a) to respond to your enquiries and communicate with you about our services;
(b) to provide, manage, and improve our IT services;
(c) to send you information about our services that may be relevant to you (with your consent, where required);
(d) to comply with our legal and regulatory obligations;
(e) to protect our legitimate business interests, including enforcing our Terms and Conditions;
(f) to analyse website usage and improve the performance, content, and user experience of our Website; and
(g) for any other purpose you have consented to or that is required or authorised by law.
We will not use or disclose your personal information for a purpose other than the purpose for which it was collected, a related purpose that you would reasonably expect, or a purpose to which you have consented, unless required or authorised by law.
4. Disclosure of Personal Information
We may disclose your personal information to:
(a) our employees, contractors, and service providers who assist us in operating our business and Website (for example, web hosting providers, email service providers, and CRM platforms);
(b) professional advisers, including accountants, auditors, and lawyers;
(c) government and regulatory authorities, where required by law; and
(d) any other third party with your consent.
We take reasonable steps to ensure that any third party to whom we disclose your personal information is bound by obligations of confidentiality and privacy that are at least as restrictive as those set out in this Privacy Policy.
5. Overseas Disclosure
Some of our service providers (such as cloud hosting, analytics, or email platforms) may store or process data in countries outside Australia, including the United States, the European Union, and other jurisdictions.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, in accordance with APP 8. Where this is not practicable, we will seek your consent or rely on another exception under the Privacy Act.
6. Cookies and Website Analytics
Our Website uses cookies and similar tracking technologies to improve your browsing experience and analyse website traffic.
Cookies we may use include:
(a) Essential cookies: required for the Website to function properly.
(b) Analytics cookies: used to collect information about how visitors use our Website (for example, Google Analytics). This data is aggregated and anonymised where possible.
(c) Third party cookies: set by third party services embedded on our Website.
You can manage your cookie preferences through your browser settings. Disabling cookies may affect the functionality of certain parts of the Website.
Google Analytics may transfer data to servers outside Australia. Google's privacy practices are governed by their own privacy policy. We use IP anonymisation where available.
7. Data Security
We take reasonable technical and organisational steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification, or disclosure, in accordance with APP 11 (as strengthened by the Privacy and Other Legislation Amendment Act 2024).
Our security measures include, but are not limited to:
(a) encrypting data in transit and at rest where appropriate;
(b) restricting access to personal information to authorised personnel only;
(c) using secure hosting environments;
(d) regularly reviewing and updating our security practices; and
(e) deactivating access for personnel who no longer require it.
No method of transmission over the internet or electronic storage is completely secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
8. Data Retention and Destruction
We will retain your personal information only for as long as it is needed for the purposes for which it was collected, or as required by law.
When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it in accordance with APP 11.2.
9. Access and Correction
Under APPs 12 and 13, you have the right to:
(a) request access to the personal information we hold about you; and
(b) request correction of any personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
To make a request, please contact us using the details in section 13 below. We will respond to your request within a reasonable period (and in any case within 30 days). We may ask you to verify your identity before processing your request.
We will not charge you for making an access or correction request, but we may charge a reasonable fee for providing access if the request requires a significant amount of time or resources.
10. Direct Marketing
We may use your personal information to send you marketing communications about our services where you have consented or where we have a reasonable basis to believe you would expect to receive such communications.
You may opt out of receiving marketing communications from us at any time by using the unsubscribe link in our emails or by contacting us directly. We will process your opt-out request promptly and free of charge.
We comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) in relation to all electronic marketing communications.
11. Notifiable Data Breaches
In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. This includes:
(a) taking reasonable steps to contain the breach and assess the risk of serious harm;
(b) notifying affected individuals as soon as practicable; and
(c) notifying the Office of the Australian Information Commissioner (OAIC).
12. Complaints
If you believe that we have breached the APPs or mishandled your personal information, you may lodge a complaint with us using the contact details in section 13. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Post: GPO Box 5218, Sydney NSW 2001
13. Contact Us
If you have any questions about this Privacy Policy, wish to make an access or correction request, or have a privacy related complaint, please contact us:
Stoic IT
Email: support@stoic-it.com
Phone: (02) 8188 0108
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. Any changes will be posted on this page with an updated "Last updated" date. We encourage you to review this Privacy Policy periodicly.
Your continued use of the Website after any changes constitutes your acceptance of the updated Privacy Policy.