Legal

Privacy Policy

Effective Date: 1st June 2024

Last Updated: 27th April 2026

Introduction

Divelio Consulting (ABN: 16754221396) ("we," "our," or "us") is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, and store your personal information when you visit our website divelio.com.au or engage with our cybersecurity and AI consulting services.

What Personal Information We Collect

Information You Provide to Us

We may collect the following personal information when you voluntarily provide it to us:

  • Contact Information: Name, email address, phone number, postal address, company name, job title
  • Business Information: Company size, industry, location, business challenges and objectives
  • Communication Records: Messages, inquiries, consultation requests, correspondence, and meeting notes
  • Consultation Information: Information shared during consultations, security assessments, and service delivery
  • Financial Information: Billing details, payment information, and invoicing records
  • Website Account Information: Username, password, and account preferences (if applicable)

Information We Collect Automatically

When you visit our website or use our services, we may automatically collect:

  • Technical Information: IP address, browser type, operating system, device identifiers
  • Usage Information: Pages visited, time spent on our website, referring websites, search terms
  • Location Information: General location based on IP address
  • Cookies and Similar Technologies: As described in our Cookie section below

Sensitive Information

We do not intentionally collect sensitive information as defined under the Privacy Act 1988, such as health information, racial or ethnic origin, political opinions, religious beliefs, or criminal records. If sensitive information is inadvertently provided, we will handle it in accordance with APP 3 and seek your consent for its collection and use.

How We Collect Personal Information

  • Direct Collection: When you provide information via our website forms, email, phone calls, meetings, or written communications
  • Website Interactions: Through cookies, analytics tools, and website functionality
  • Third Parties: From publicly available sources, business contacts, or referral partners (with appropriate consents)
  • Service Delivery: During the provision of our consulting services

Why We Collect and Use Your Personal Information

Service Provision

  • Delivering cybersecurity and AI consulting services
  • Conducting security assessments, audits, and risk evaluations
  • Developing customized security strategies and recommendations
  • Implementing agreed solutions and providing ongoing support
  • Managing client relationships and project delivery

Communication and Administration

  • Responding to inquiries and consultation requests
  • Scheduling appointments and managing bookings
  • Sending service-related communications and updates
  • Providing customer support and technical assistance
  • Processing payments and managing billing

Business Operations

  • Improving our services and developing new offerings
  • Website functionality and user experience enhancement
  • Internal record keeping and business administration
  • Compliance with legal and regulatory obligations
  • Quality assurance and training purposes

Marketing and Business Development (with consent)

  • Sending newsletters, industry insights, and relevant content
  • Promoting our services and upcoming events
  • Conducting market research and business development
  • Building relationships within the cybersecurity and AI community

When We Disclose Your Personal Information

Service Providers and Contractors

We may share your information with trusted third-party service providers who assist us in operating our business, including:

  • Cloud hosting and IT infrastructure providers
  • Payment processing and accounting services
  • Email marketing and communication platforms
  • Website analytics and performance monitoring tools
  • Professional advisors (lawyers, accountants, consultants)

All service providers are required to handle your personal information in accordance with the Privacy Act 1988 and our privacy requirements.

Legal and Regulatory Requirements

We may disclose your personal information where required or permitted by Australian law, including:

  • Compliance with court orders, subpoenas, or legal processes
  • Cooperation with law enforcement or regulatory investigations
  • Protection of our legal rights, property, or safety
  • Protection of the rights, property, or safety of our clients or the public
  • Prevention or investigation of suspected illegal activities

Business Transfers

In the event of a merger, acquisition, or sale of our business assets, your personal information may be transferred to the new entity. We will notify you of any such transfer and ensure the receiving party is bound by similar privacy obligations.

With Your Consent

We may disclose your personal information to other parties with your express consent or as otherwise permitted under the APPs.

Overseas Disclosure

Some of our service providers may be located overseas, including in:

  • United States (cloud hosting, software services)
  • European Union (software and analytics services)
  • Other countries where our technology partners operate

When we disclose personal information overseas, we take reasonable steps to ensure the recipient complies with the APPs or is subject to substantially similar privacy protections.

Data Security and Protection

As a cybersecurity consultancy, we implement comprehensive security measures to protect your personal information:

Technical Security Measures

  • End-to-end encryption for data transmission and storage
  • Multi-factor authentication for system access
  • Regular security assessments and penetration testing
  • Intrusion detection and monitoring systems
  • Secure backup and disaster recovery procedures
  • Regular software updates and security patches

Administrative Security Measures

  • Staff training on privacy and security obligations
  • Background checks for employees with access to personal information
  • Clear data handling policies and procedures
  • Regular review and updating of security practices
  • Incident response and data breach protocols

Physical Security Measures

  • Secured office facilities with controlled access
  • Locked storage for physical documents containing personal information
  • Secure disposal of documents and electronic media
  • Environmental controls to protect IT equipment

Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes for which it was collected or as required by law:

  • Active Client Records: Retained for the duration of our service relationship and for 7 years thereafter for legal and business purposes
  • Marketing Communications: Retained until you unsubscribe or request removal
  • Website Analytics: Typically retained for 2–3 years
  • Financial Records: Retained for 7 years in accordance with taxation and business record requirements
  • Legal Compliance: Some records may be retained longer to meet regulatory or legal obligations

Your Rights Under Australian Privacy Law

Access to Your Personal Information (APP 12)

You have the right to request access to the personal information we hold about you. We will provide access unless an exception under the Privacy Act applies. We may charge a reasonable fee for providing access to cover our administrative costs.

Correction of Personal Information (APP 13)

You have the right to request correction of your personal information if you believe it is inaccurate, out-of-date, incomplete, irrelevant, or misleading. We will take reasonable steps to correct the information or, if we disagree with your request, attach a statement to the record noting your requested correction.

Complaints About Privacy Breaches (APP 1)

If you believe we have breached your privacy, you can make a complaint to us. We will:

  • Acknowledge your complaint within 5 business days
  • Investigate your complaint thoroughly and respond within 30 days
  • Take appropriate action to resolve any identified issues

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Marketing Communications

You can opt out of receiving marketing communications at any time by:

  • Using the unsubscribe link in our emails
  • Contacting us directly using the details in the "Contact Us" section
  • Updating your preferences if you have an online account

Cookies and Website Analytics

Our website uses cookies and similar technologies to enhance your browsing experience and analyse website performance:

Types of Cookies We Use

  • Strictly Necessary Cookies: Essential for website functionality and security
  • Performance Cookies: Help us understand how visitors use our website
  • Functional Cookies: Remember your preferences and settings
  • Marketing Cookies: Deliver relevant advertisements and measure campaign effectiveness

Third-Party Analytics

We use Google Analytics to analyse website traffic and user behaviour. Google Analytics may collect information about your website usage and may combine this with information from other websites. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on.

We also use Microsoft Clarity to understand how visitors interact with our website. Clarity collects information about your interactions on our site, including mouse movements, clicks, scrolls, and pages visited, and may record sessions for behavioural analysis. Clarity does not capture keystrokes in form fields. For more information, see Microsoft's privacy statement at privacy.microsoft.com/privacystatement.

Managing Cookies

You can control cookies through your browser settings, though disabling certain cookies may affect website functionality. Most browsers allow you to:

  • View cookies stored on your device
  • Delete individual cookies or all cookies
  • Block cookies from specific websites
  • Block all cookies from being set

Third-Party Websites and Services

Our website may contain links to third-party websites or integrate with external services. This Privacy Policy only applies to our website and services. We are not responsible for the privacy practices of third-party websites or services, and we encourage you to read their privacy policies.

Third-Party Services We Use

  • Google Analytics for website analytics
  • Microsoft Clarity for session replay and heatmap analytics
  • Calendly for appointment scheduling

Notifiable Data Breaches

In accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988, we will:

  • Assess any data security incidents to determine if they constitute an eligible data breach
  • Notify the OAIC within 72 hours if a breach is likely to result in serious harm
  • Notify affected individuals if a breach is likely to result in serious harm
  • Maintain records of all data breaches and our response actions

Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal requirements. When we make changes, we will:

  • Update the "Last Updated" date at the top of this policy
  • Post the revised policy on our website
  • Notify you by email if the changes are significant and we have your email address
  • Provide notice on our website homepage for material changes

We encourage you to review this Privacy Policy regularly to stay informed about how we handle your personal information.

Contact Us

If you have any questions about this Privacy Policy, wish to access or correct your personal information, or want to make a privacy complaint, please contact us:

Divelio Consulting
Email: [email protected]

For general inquiries:
Email: [email protected]

We will respond to your inquiry or request as soon as practicable and within the timeframes required under the Privacy Act 1988.