Version: 2.0
Effective date: 10 July 2026
Last reviewed: July 2026
Policy owner: Privacy Officer, TechBrain
This Policy is reviewed at least every two years, and following any material change to our data handling practices, as part of TechBrain’s ISO/IEC 27001 certified Information Security Management System.
TechBrain is committed to protecting the privacy of personal information we collect as part of the services we offer. This Policy sets out how we comply with our obligations under the Privacy Act 1988 (Cth) (Act) and the Australian Privacy Principles (APPs), which regulate how we collect, use, disclose and hold your personal information, and how you may access and correct it.
This Privacy Policy applies to personal information that TechBrain collects and handles about individuals who interact with us, including website visitors, prospective and current client contacts, newsletter subscribers, enquirers, supplier and partner contacts, job applicants and other business contacts.
It applies to personal information collected through our website, our online enquiry, quote and newsletter forms, consultation bookings, our HubSpot CRM, and our marketing communications.
Personal information about our employees and contractors that we handle in connection with their employment or engagement is managed under TechBrain’s internal privacy and employment processes, and is not the primary focus of this public Privacy Policy.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. Sensitive information is a special category of personal information and includes information such as health information.
We generally do not seek sensitive information through our website, CRM or marketing activities. Please do not include sensitive information in website forms unless it is necessary for your enquiry. Where we need to collect sensitive information, we do so only with your consent and where the collection is reasonably necessary, or where otherwise permitted by law.
Depending on how you interact with us, we may collect:
Website and email interaction data may be personal information where it identifies you or is linked to other information we hold about you.
We collect personal information in a range of ways, including face to face, by telephone, through online or paper forms, by email, when you book a consultation, and through your use of our website. We may also collect business contact information from referrals, events, business partners, and publicly available professional sources, where it is lawful and reasonable to do so.
Where practicable, you may interact with us anonymously or by using a pseudonym, for example when browsing our website. However, we will usually need your contact details to respond to enquiries, provide quotes, arrange consultations or deliver services.
Sometimes we receive personal information that we did not ask for or take any active steps to collect, for example an unsolicited job application, a misdirected email, or information you volunteer to us that we did not request (unsolicited personal information).
When this happens, we assess as soon as practicable whether we could have lawfully collected that information had we actually requested it, applying the same standards we use when we collect personal information directly. If we determine we could not have collected it, and it is lawful and reasonable to do so, we will destroy the information securely or ensure it is de-identified as soon as practicable.
Where we determine we could have collected the information, or it is not lawful or reasonable to destroy or de-identify it (for example, where we are otherwise required to retain records), we will keep and handle that information in the same way as personal information we collect directly, in accordance with the rest of this Privacy Policy.
Our website uses cookies, pixels and similar technologies, including HubSpot tracking technology, to understand how visitors use our site, remember preferences, measure the performance of our marketing, and, where you have identified yourself to us, associate website and email engagement with your contact record.
The information collected may include your IP address, device and browser details, cookie identifiers, pages visited, referring pages, and email open and click activity. This information may be personal information where it identifies you or is linked to other information we hold.
You can manage cookies through your browser settings and through the cookie controls on our website. If you disable non-essential cookies, you can still use most of our website, though some features, analytics or personalisation may not work as intended.
We collect, use and store personal information to provide and manage our services and our relationship with you, including to:
Our services, products and activities may change from time to time.
We use HubSpot, a customer relationship management and marketing platform, to manage contact records, enquiries, marketing preferences, email communications and website analytics. HubSpot is a third-party service provider to TechBrain, and we require it to handle personal information under contractual privacy and security obligations.
We configure HubSpot so that eligible customer data is hosted in HubSpot’s Australian (Sydney) data region. HubSpot, Inc. is headquartered in the United States, and HubSpot affiliates, support personnel and sub-processors may access or process personal information from outside Australia (see Disclosure of personal information to overseas recipients below).
We send marketing communications, including marketing emails, only where we have your consent, you are paying or have previously paid for products or services provided by us, or are otherwise permitted under the Spam Act 2003 (Cth) and the Privacy Act.
Our marketing messages identify TechBrain as the sender, include our contact details, and provide a simple unsubscribe option. You can opt out of marketing communications at any time, and we action unsubscribe requests within 5 business days. Opting out of marketing will not affect service, security, billing or account messages about services you have requested.
We use HubSpot to generate an internal lead-priority indicator based on information such as enquiry type, your business contact details and organisation, pages viewed, forms submitted, email engagement and marketing preferences. This helps our team decide how and when to follow up.
This indicator is advisory and supports human decision making. It does not, by itself, determine whether you receive our services, your pricing, eligibility, contract terms, or any other matter that could significantly affect your rights or interests, and we do not use AI predictive scoring for this purpose. You may contact our Privacy Officer to ask how your information has been handled.
We take reasonable steps to protect personal information from loss, misuse, interference, and unauthorised access, modification or disclosure. TechBrain maintains an ISO/IEC 27001 certified information security management system within its certified scope, and applies risk-based administrative, technical and physical controls, including access controls, security monitoring, confidentiality obligations, staff training and supplier due diligence.
We retain personal information only for as long as it is needed for the purposes described in this Policy or as required by law. When personal information is no longer required and we are not required to retain it, we take reasonable steps to securely destroy or de-identify it.
Although we take reasonable steps to secure personal information, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
We take the security of your personal information seriously. In the event of a data breach involving personal information we hold that is likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth).
This means that, where required under the NDB scheme, we will:
Not every security incident meets the threshold for notification. If we are able to take remedial action that prevents a breach from being likely to result in serious harm, notification under the NDB scheme may not be required. Where we do need to notify you, we will do so as soon as practicable using a method appropriate to the circumstances.
You can read more about the NDB scheme on the OAIC website at oaic.gov.au/privacy/notifiable-data-breaches.
We use and disclose personal information for the purposes for which it was collected, for related purposes you would reasonably expect, with your consent, or where otherwise permitted or required by law.
We disclose personal information to third party service providers who support our operations, such as our HubSpot CRM and marketing platform, cloud hosting and data storage, email delivery, analytics, our professional advisers (legal, insurance, accounting) and security providers. We take reasonable steps to ensure these providers handle personal information consistently with the Act and the APPs.
We will not otherwise disclose your personal information unless: you have consented; you would reasonably expect us to; it is required or authorised by law; or it is reasonably necessary for an enforcement body.
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date and complete. Please contact our Privacy Officer if any information we hold about you needs correcting.
Some of our service providers, or their sub-processors, are located outside Australia or may process information overseas. In particular, our CRM and marketing provider HubSpot, Inc. is based in the United States. Although we configure eligible customer data to be hosted in HubSpot’s Australian (Sydney) data region, some personal information may be accessed or processed outside Australia, primarily in the United States (for example by HubSpot, Inc. and certain infrastructure providers) and in other countries where HubSpot’s support affiliates operate.
Before disclosing personal information to overseas recipients, we take reasonable steps intended to ensure the recipient handles it consistently with the APPs, such as contractual privacy and security obligations and due diligence on the provider’s controls. Where APP 8 applies, TechBrain may remain accountable under the Privacy Act for how an overseas recipient handles personal information.
You may request access to the personal information we hold about you, and ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. We will respond within a reasonable period. We may decline access or correction where the Act permits, and where we do, we will give you our reasons and the options available to you.
To make a request, contact our Privacy Officer, 70 Hay St, Subiaco WA 6008, [email protected], 08 9201 2340.
Under the Act, we may refuse access in certain circumstances, for example where granting access would pose a serious threat to the life, health or safety of any individual, have an unreasonable impact on the privacy of others, be unlawful, relate to anticipated legal proceedings, or prejudice enforcement activities. If we refuse access or correction, we will provide written reasons and information about how to complain.
If you believe we have breached the Australian Privacy Principles, you can complain to our Privacy Officer in writing using the contact details above. We will investigate and aim to respond within one calendar month, and will let you know if we need more time.
If you are not satisfied with our response, or we do not respond within a reasonable period, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. The OAIC will generally expect you to have raised your complaint with us first.
We review our policies every 2 years or earlier subject to changes in the Privacy Act, our practices or our legal obligations. The current version is always available on our website. Each version of this Policy is identified by the version number, effective date and last-reviewed date shown at the top of this page.