iTec Help
Privacy Policy
How we collect, use, disclose and protect personal information, under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Who we are
- Entity
- iTec Help — a registered business name of The Trustee for the Dous Family Trust
- ABN
- 56 377 845 269
- Address
- Level 1, Unit 6/287 Victoria Rd, Rydalmere NSW 2116
- Privacy contact
- help@itechelp.com.au
iTec Help is a managed IT and cybersecurity services provider based in Sydney, Australia. We respect your privacy and are committed to protecting the personal information we hold about you. This policy applies to personal information handled through our business operations and through our internal platform, iTech HQ.
02What we collect
The kinds of personal information we collect depend on your relationship with us, and may include:
- Contact & client records — name, email, phone, job title and the organisation you represent.
- Support tickets & helpdesk content — your requester details and the content of your requests, including message bodies, correspondence and attachments. Where a remote session is recorded and transcribed, the transcript may contain personal information you disclose.
- Agreements & e-signatures — the signatory's name plus metadata to evidence agreement, including IP address and timestamps.
- Marketing & campaign data — recipient details and engagement information (delivered, opened, unsubscribed).
- Technical & usage information — collected automatically, such as IP address, device/browser information and cookie identifiers.
We do not generally seek to collect “sensitive information” (such as health, race, religion or political views). If we ever need to, we will only do so with your consent or where permitted by law.
03How we collect it
- Directly from you — when you contact us, request a quote, raise a ticket, sign an agreement or subscribe.
- In the course of providing services — as we deliver managed IT and cybersecurity services.
- Automatically — through our website and platform (cookies, section 9).
- From third parties — e.g. a colleague who provides your details, or public sources like the Australian Business Register when we verify company details.
04Why we use it
We collect and use personal information to:
- provide, manage and support our IT and cybersecurity services;
- respond to and resolve support tickets and enquiries;
- create, manage and evidence agreements and contracts;
- manage client relationships and accounts, including billing and accounting;
- send service-related communications and, where permitted, direct marketing (section 8);
- maintain the security, integrity and performance of our systems;
- meet our legal, regulatory and contractual obligations; and improve our services.
We only use personal information for the primary purpose it was collected, a related secondary purpose you would reasonably expect, or where you have consented or the law permits.
05Disclosure & sub-processors
We do not sell personal information. We disclose it only where necessary — to the service providers below, to professional advisers where required, to authorities where required or authorised by law, and to a successor entity in a business sale (subject to protections).
| Provider | Purpose | Data location |
|---|---|---|
| Supabase | Database (Postgres) & file storage | Sydney, Australia |
| Vercel | Application hosting | Sydney (syd1) |
| Microsoft 365 / Graph | Email & Entra ID single sign-on | Australia |
| Xero | Accounting & invoicing | Australia |
| Resend | Transactional & marketing email | United States |
| Anthropic | AI features | United States |
| OpenAI | AI features (speech-to-text, images) | United States |
06Overseas disclosure (APP 8)
Some providers process personal information outside Australia — Resend, Anthropic and OpenAI (all United States). Our database, file storage and hosting (Supabase, Vercel) are configured for Sydney, Australia, and our Microsoft 365 and Xero data is held in Australia.
Before disclosing personal information overseas we take reasonable steps to ensure it is handled consistently with the APPs, including through contractual data-protection terms. Where AI features are used, we limit the personal information disclosed and use our providers' business/API tiers, under which your data is not used to train their models and is subject to zero- or limited-retention handling.
07How we keep it secure (APP 11)
We take reasonable steps to protect personal information, including:
- Access control — Microsoft Entra ID single sign-on (SSO) with multi-factor authentication (MFA).
- Least privilege — enforced in the database with row-level security (RLS).
- Encryption in transit — TLS/HTTPS with HTTP Strict Transport Security.
- Encryption at rest — database and file storage encrypted at rest.
- Application hardening — a strict Content-Security-Policy, secure headers and rate limiting.
- Backups — encrypted, off-site database backups on a regular schedule.
- Monitoring & secure destruction — we monitor for security events and securely destroy or de-identify data when no longer needed.
No system is completely secure. If a data breach likely to cause serious harm occurs, we respond under our Incident Response Plan and the Notifiable Data Breaches (NDB) scheme.
08Direct marketing & opt-out
We may send marketing about our services where you would reasonably expect it or have consented, consistent with the Privacy Act and the Spam Act 2003 (Cth). Every marketing email includes a functional unsubscribe link; you can also opt out by emailing help@itechelp.com.au. Opting out of marketing does not affect transactional communications needed to provide our services.
10Retention & destruction
We keep personal information only as long as needed, or as required by law. Indicative periods:
- Client & contact records — the duration of the relationship and 7 years after it ends.
- Support tickets, content & attachments — 7 years.
- Session-recording transcripts — 2 years; any screen recording is kept with the ticket for the same period.
- Agreements & signing metadata — 7 years.
- Accounting records (Xero) — a minimum of 5 years (ATO requirement).
- Marketing/campaign data — until you unsubscribe; we then keep a minimal suppression record to honour your opt-out.
11Access & correction (APP 12 & 13)
You can request access to the personal information we hold about you and ask us to correct it. Contact us (below) and we will respond within a reasonable period (generally 30 days), verify your identity, provide access where practicable, and correct information where appropriate or explain why we decline. We do not usually charge for access requests.
12Complaints
If you believe we have mishandled your personal information, please contact us first at help@itechelp.com.au or by post (Level 1, Unit 6/287 Victoria Rd, Rydalmere NSW 2116). We aim to respond within 30 days.
If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) — oaic.gov.au, 1300 363 992, GPO Box 5288, Sydney NSW 2001.
Contact us
iTec Help — Privacy Contact
Email: help@itechelp.com.au
Address: Level 1, Unit 6/287 Victoria Rd, Rydalmere NSW 2116
ABN: 56 377 845 269
We may update this policy to reflect changes in our practices or legal obligations; the current version is always available here. Last updated 14 August 2026.