PRIVACY POLICY
We help organisations handle information responsibly, so we hold ourselves to the same standard. This policy explains what personal information Atomic Cyber collects, why, where it goes and the choices you have. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Who we are
Atomic Cyber (ABN 71 050 661 793) is an independent cybersecurity and AI consulting business based in Melbourne, Victoria. In this policy, "we", "us" and "our" mean Atomic Cyber. You can reach us about privacy at gday@atomiccyber.com.au.
What we collect
We collect only what we need to respond to you and to run our business:
- Enquiry details. When you use our contact form or email us: your name, email address, company (if you give it), the service you're interested in and your message.
- Business contact details. When we work with you or your organisation: names, roles, work email addresses, phone numbers and correspondence.
- Technical information. When you visit the site, our hosting and security providers automatically process your IP address, browser type, device information and the pages you request. This is used to deliver the site and protect it from abuse.
We don't ask for sensitive information (such as health information or racial or ethnic origin) through this website, so please don't include it in an enquiry. You can contact us without giving your real name, but we'll need a valid email address to reply.
How we use it
- to reply to your enquiry and discuss how we might help
- to scope, deliver, invoice and administer engagements
- to keep the website secure, including detecting spam and automated abuse
- to meet our legal, tax and accounting obligations
We won't use your details for marketing unless you've asked to hear from us (for example, by subscribing to our newsletter). You can opt out at any time. We don't sell or rent personal information, and we don't use it to train AI models.
Information we handle during engagements
When we work with your organisation, we may be given access to systems, documents or data that include personal information. We treat that information as confidential. We use it only to deliver the agreed work, handle it according to our engagement terms and any confidentiality agreement, and return or securely delete it when the engagement ends, unless the law requires us to keep it. Where our engagement terms say something more specific, those terms apply.
Who we share it with
We use a small number of trusted service providers to run the website and our business. They process information on our behalf and only for the purposes below:
| Provider | What they do for us | Where data may be processed |
|---|---|---|
| Cloudflare | Website hosting, security and delivery of contact form submissions | Global network, including Australia and the United States |
| Resend | Delivering contact form submissions to our inbox | United States |
| Google Workspace | Business email and document storage | Australia, the United States and other countries where Google operates |
| Google Fonts | Serving the typefaces used on this site (receives your IP address) | United States and other countries where Google operates |
| Substack | Hosting our articles and newsletter, and the article images shown on this site | United States |
We may also share information with our professional advisers (such as accountants, lawyers and insurers), with specialist partners we engage to deliver part of a project (only with your organisation's agreement), or where the law requires or authorises it.
Overseas disclosure
As the table shows, some of our providers store or process information outside Australia, mainly in the United States. We choose established providers with strong security practices and contractual privacy commitments, and we take reasonable steps to make sure they handle personal information consistently with the APPs.
Cookies and analytics
This site doesn't use advertising cookies or cross-site tracking. Our hosting provider may set strictly necessary cookies to protect the site from bots and abuse. If we add analytics, we'll use privacy-friendly, cookieless tools that report aggregate visitor numbers without identifying you, and we'll update this policy.
Links to LinkedIn, Substack and other external sites are governed by those sites' own privacy policies.
How we protect it
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include encrypted connections (HTTPS), multi-factor authentication on our accounts, encrypted devices, least-privilege access, and choosing providers with strong security controls. No system is perfectly secure, but we work hard to keep ours that way.
How long we keep it
We keep enquiry details for as long as we need them to respond and follow up, and generally no longer than two years if no engagement follows. We keep engagement and financial records for as long as the law requires (for example, tax records for five years). When we no longer need personal information, we securely delete or de-identify it.
Access, correction and deletion
You can ask to see the personal information we hold about you, ask us to correct it, or ask us to delete it where we're not required to keep it. Email gday@atomiccyber.com.au. We'll respond within 30 days and won't charge you for making a request. If we can't do what you ask, we'll explain why.
Data breaches
If a data breach involving your personal information is likely to result in serious harm, we'll notify you and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
Questions and complaints
If you have a question or concern about how we've handled your personal information, email gday@atomiccyber.com.au. We'll acknowledge your complaint within five business days and aim to resolve it within 30 days.
If you're not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this policy
We may update this policy as our services or providers change. The latest version will always be on this page, with the date it was last updated.