Legal

Privacy policy

How we collect, use, store and disclose personal information, and what you can do about it.

Last updated: 8 August 2026

Contents

Next Cyber Pty Ltd (ABN 17 700 967 826, ACN 700 967 826) is bound by the Australian Privacy Principles in the Privacy Act 1988 (Cth). This policy explains how we handle personal information. In this policy, “we”, “us” and “our” mean Next Cyber Pty Ltd.

What we collect

We collect only what we need to provide our services and run our business.

  • Contact information — name, organisation, role, email address and phone number, provided when you enquire, engage us or attend an event.
  • Client account information — billing details, contract records and the names and contact details of authorised representatives.
  • Technical and service data — device identifiers, user account names, system configuration, log and telemetry data generated by the systems we manage on your behalf.
  • Website usage data — pages viewed, referring source and general location, collected in aggregate. See the cookies section below.

We do not collect sensitive information as defined by the Privacy Act unless it is necessary and you have consented, or we are required or authorised by law to do so.

How we collect it

Directly from you in most cases — through this website, by email or phone, or in the course of delivering services. We also collect technical data automatically from systems we are engaged to manage, under the terms of the relevant service agreement.

Why we collect it and how we use it

  • To respond to your enquiry and provide the services you have engaged us for.
  • To monitor, secure, support and report on the systems we manage.
  • To investigate and respond to security incidents.
  • To administer our contracts, invoicing and business records.
  • To meet our legal, regulatory and insurance obligations.

We do not sell personal information. We do not add enquiry contacts to a marketing list without asking, and any communications we do send carry an unsubscribe option.

Client data we access as a service provider

When we manage your systems, we may access personal information that you hold about your customers, staff or clients. In relation to that information we act as a service provider on your behalf: we handle it only as necessary to deliver the contracted service, we do not use it for any other purpose, and we return or destroy it in accordance with the service agreement when our engagement ends.

Who we disclose it to

We may disclose personal information to:

  • Our personnel and contractors, on a need-to-know basis.
  • Technology suppliers and platform providers used to deliver our services (list your material sub-processors here).
  • Professional advisers, insurers and auditors.
  • Law enforcement or regulators where we are required or authorised by law.

We require our suppliers to protect personal information to a standard consistent with this policy.

Overseas disclosure

We store client and business data in Australian data centres wherever practicable. Some software-as-a-service platforms we rely on may process limited data overseas. Identify those platforms and countries here, and confirm what steps you take to ensure they handle the information consistently with the Australian Privacy Principles.

Security

We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our own controls are described on our security page. No system is perfectly secure, and we do not claim otherwise.

Data breaches

If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly. Where an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

Where the breach concerns data we handle on a client's behalf, we will notify that client without unreasonable delay and support their own assessment and notification obligations.

Retention

We keep personal information only as long as we need it for the purposes described above, or as required by law — including record-keeping obligations under tax, corporations and contract law. When it is no longer needed, we destroy or de-identify it. State your actual retention periods.

Cookies and analytics

We use four services on this website. Two see only aggregate traffic. The third is our customer relationship system, which links your browsing to you personally once you send us an enquiry. The fourth records how pages are used, so we can see where the site confuses people. Each is described below. We do not advertise on this site and none of these services is used to target you with ads, but one of them sets cookies that Microsoft also uses for advertising across its own properties — we would rather say so plainly than let you find it in a cookie inspector.

  • Google Analytics (GA4) — pages viewed, referring source, approximate location, device and browser type, collected in aggregate. Google Analytics sets cookies to distinguish visitors and sessions. See Google's privacy policy for how Google handles this data, and its opt-out browser add-on if you would rather not be counted.
  • Cloudflare Web Analytics — aggregate traffic and performance data, collected without cookies or any identifier that persists across visits.
  • HubSpot — our customer relationship system, and the one that does more than count. It sets cookies (__hstc, hubspotutk, __hssc, __hssrc) on your first visit to recognise your browser across visits. While you are simply reading, that record is anonymous to us. If you send us an enquiry, the details you typed are stored in HubSpot as your contact record, and the pages you viewed before you enquired are attached to it — so we can see what you were researching before you got in touch. Our HubSpot account is hosted in Sydney and this data is held in Australia. See HubSpot's privacy policy. If you would rather we did not keep it, write to us and we will delete your record.
  • Microsoft Clarity — records how pages are actually used: mouse movement, scrolling, clicks and the order you moved through the site, replayed back to us as a session so we can see where the site is confusing or broken. What you type is not recorded — Clarity masks form fields and dropdowns automatically, so the contents of the enquiry form above are never captured this way. It sets _clck, _clsk, CLID, MUID, ANONCHK and MR. MUID and MR are shared with Microsoft across its other services, including advertising. See Microsoft's privacy statement.

You can block cookies in your browser settings; the site will still work without them, though we will not know you visited.

Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date or incomplete. Write to [email protected]. We will respond within a reasonable period, normally 30 days. We may need to verify your identity first. If we refuse a request, we will tell you why in writing.

Complaints

If you believe we have breached the Australian Privacy Principles, contact us at [email protected]. We will acknowledge your complaint within five business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Changes to this policy

We may update this policy from time to time. The current version is always published here with the date it was last updated. Material changes affecting clients will be communicated directly.

Contact

Privacy Officer, Next Cyber Pty Ltd
[email protected]
+61 2 6294 3425