Draft — pending legal review
This document has not yet been reviewed by a qualified Australian lawyer. Do not rely on it as legal advice. It will be finalised before go-live.
Privacy Policy
How Aussie Cyber collects, uses, and protects your personal information.
Effective date: 1 April 2026 · Last updated: 1 April 2026
01.About this policy
DJC Systems Pty Ltd (ABN 50 007 440 191), trading as Aussie Cyber ("Aussie Cyber", "we", "us", "our"), operates the Aussie Cyber platform at aussiecyber.com.au. This Privacy Policy explains how we collect, use, store, and disclose personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By accessing or using our platform, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use the platform.
02.What personal information we collect
We collect only the information necessary to provide our services. This includes:
- Identity information — your name, email address, and organisational details provided when your account is created.
- Authentication tokens — OAuth tokens issued by Microsoft 365 to verify your identity. We do not store passwords.
- Training data — your progress through security awareness training modules, quiz results, and video completion records.
- Phishing simulation data — whether you interacted with a simulated phishing email (opened, clicked, or submitted a form). See Section 5 for important details on credential handling.
- Endpoint data — device names, operating systems, agent status, and security incident data synced from Aussie Cyber Endpoint Manager.
- Usage data — log data, IP addresses, browser type, and platform activity for security, troubleshooting, and service improvement.
- Billing information — subscription tier, user count, and invoice history. Payment card details are processed by our payment processor and are not stored by Aussie Cyber.
03.How we collect personal information
We collect personal information:
- Directly from you or your organisation's administrator when you sign up or are added as a user.
- Via Microsoft 365 OAuth flows when you authenticate.
- Automatically through your use of the platform (log data, usage analytics).
- From our endpoint and identity protection systems, for endpoint and identity threat data.
04.How we use personal information
We use personal information to:
- Provide, maintain, and improve the Aussie Cyber platform.
- Authenticate users and maintain secure sessions.
- Assign, track, and report on security awareness training.
- Conduct phishing simulations as authorised by your organisation.
- Monitor and report on endpoint and identity security status.
- Process billing and manage subscriptions.
- Send service communications, security alerts, and billing notifications.
- Comply with legal obligations.
We do not use personal information for advertising or sell it to third parties.
05.Phishing simulations and credential handling
Aussie Cyber conducts simulated phishing campaigns on behalf of your organisation. These simulations are used to assess and improve your team's security awareness.
Important: If a simulated phishing page includes a credential entry form, Aussie Cyber records only that a submission was attempted (a boolean flag). We never capture, store, log, transmit, or inspect the actual values entered — whether usernames, passwords, or any other credentials. This is an architectural guarantee, not a policy-only commitment.
Employees of subscribing organisations acknowledge, via their organisation's acceptance of our Terms of Service, that phishing simulations may occur without individual prior notice. This is a standard and necessary component of effective security awareness programmes.
06.Password storage
Aussie Cyber does not support password-based authentication and does not store passwords under any circumstances. All authentication is handled via Microsoft 365 OAuth. We never hold or process your organisational account credentials.
07.Disclosure of personal information
We may disclose personal information to:
- Endpoint and identity protection partners — for the purpose of deploying and managing Aussie Cyber Endpoint Manager and Identity Protection services.
- Microsoft — as the identity provider during the OAuth authentication flow.
- Cloudflare — for delivery of training video content via Cloudflare Stream.
- Payment processors — for billing and subscription management.
- Legal authorities — where required by Australian law, court order, or regulatory obligation.
All third-party providers are engaged under appropriate data processing agreements and are required to handle personal information in accordance with applicable privacy laws.
08.Data storage and security
Personal information is stored on servers located in Australia (Microsoft Azure). We implement industry-standard security controls including encryption at rest and in transit, access controls, and audit logging.
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme.
09.Data retention
We retain personal information for as long as your organisation's subscription is active and for a period of 90 days after account cancellation, after which it is deleted or de-identified.
Some data may be retained for longer periods where required by law or for legitimate business purposes such as resolving disputes or enforcing our agreements.
On account cancellation, we will send a data retention notice to the account administrator detailing what data will be deleted and when.
10.Access, correction, and complaints
You have the right to request access to or correction of personal information we hold about you. To make a request, contact us at enquiries@djc.com.au.
If you believe we have handled your personal information in a way that does not comply with the Privacy Act 1988, you may lodge a complaint with us. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11.Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or a prominent notice on the platform. Continued use of the platform after changes take effect constitutes acceptance of the updated policy.
12.Contact us
For privacy-related enquiries, contact DJC Systems Pty Ltd t/a Aussie Cyber (ABN 50 007 440 191) at enquiries@djc.com.au or by mail at our registered business address in Australia.
© 2026 Aussie Cyber · Australian owned and operated