Privacy policy.
Last updated: 1 September 2026
This policy applies to THE TRUSTEE FOR SECURE MEASURE UNIT TRUST (ABN 29 734 661 094) ("Secure Measure", "we", "our", "us"). We provide cybersecurity services to businesses from Sydney, Australia. We are bound by the Australian Privacy Principles ("APPs") in the Privacy Act 1988 (Cth), and we take them seriously – handling information carefully is our trade.
This policy explains what personal information we collect, why, and what we do with it. If anything here is unclear, contact us and we will explain it plainly.
What we don't do
Because we are a business-to-business security consultancy, our data practices are narrower than most privacy policies you will read:
- We do not sell or rent personal information to anyone.
- We do not send marketing or newsletter emails.
- We do not run advertising or ad-tracking on our website.
- We do not run credit checks on individuals or use debt collectors.
- Our website sets no cookies of its own and runs no analytics scripts.
The information we collect
- Enquiries. When you contact us through our website form or by email, we collect what you give us: your name, email address, job title, company name, and your message.
- Questionnaire responses. If you complete our security maturity questionnaire, we collect your answers along with the name, email, job title and company you provide.
- Business relationships. In the course of working with clients, suppliers and partners we hold ordinary business contact details and the correspondence and documents of the engagement.
- Job applications. If you apply to work with us, we collect your application, CV, work history and referee details, and – with your consent or where the law permits – the results of reference and background checks.
- Technical logs. Our hosting provider keeps standard web server logs (IP address, browser type, pages requested) which we use for security and to keep the site working.
We do not collect sensitive information (such as health, biometric or criminal-history information) about website visitors or business contacts. If a recruitment or client engagement ever requires it, we will ask for your express consent first.
Personal information inside client systems
Our security work sometimes gives us access to systems that contain personal information our clients hold about their own customers and staff. That information belongs to the client. We access it only as needed to deliver the engagement, handle it under the client's instructions and our contractual confidentiality and security obligations, and never use it for our own purposes.
How we use information
- To respond to enquiries and questionnaire submissions.
- To deliver, administer and invoice our services.
- To assess job applications.
- To protect the security of our own systems and to meet our legal obligations.
Who we share it with
We share personal information only with:
- Service providers that run parts of our operations: website hosting and delivery (Cloudflare), our customer relationship system that receives contact-form submissions (HubSpot), our questionnaire platform (JotForm), and the productivity, email and file-storage tools we use to run the business. Each is bound to handle the data only for us.
- Professional advisers (lawyers, accountants, insurers) where needed.
- Authorities, where the law requires it – for example in response to a warrant or subpoena.
- A buyer or successor, if we ever sell or restructure the business, under the same protections.
Some of these providers store data outside Australia (typically in the United States). Where they do, we take reasonable steps, as APP 8 requires, to ensure your information is protected to a comparable standard.
Cookies and third-party tools on this site
Our own pages set no cookies. Two third-party tools do run in specific places:
- HubSpot, on our contact page only, delivers the form submission to us and may set cookies that recognise a returning visitor.
- JotForm, on the questionnaire page only, provides the embedded questionnaire.
You can block or clear cookies in your browser; the site works without them. If you prefer not to load these tools at all, you can email us directly instead of using the forms.
How we secure information
We apply the same discipline we sell: encryption in transit, multi-factor authentication, least-privilege access to systems that hold personal information, monitored and patched infrastructure, and staff obligations of confidentiality. We keep personal information only while we need it for the purposes above or as the law requires, then delete or de-identify it.
Access, correction and deletion
You may ask us at any time to see the personal information we hold about you, to correct it, or to delete it. Contact us via the Connect page or by post (below). We will verify your identity, acknowledge your request within 7 days, and usually complete it within 30 days. If we cannot do what you ask – for example, where the law requires us to keep a record – we will tell you why.
Complaints
If you believe we have mishandled your personal information, contact us first and we will investigate and respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au/about-us/contact-us).
Contact us
- Website: via the Connect page
- Post: PO Box A2572, South Sydney, NSW 1235, Australia
Changes to this policy
We update this policy when our practices change and publish the current version on this page, with the date above.