Privacy Policy

THE BEACH GEEK PTY LTD (ABN 93 655 538 060)
(Compliant with Australian Privacy Act 1988 & the Australian Privacy Principles) 

 

  1. Purpose of This Policy

1.1 
This Privacy Policy explains how The Beach Geek Pty Ltd (“The Beach Geek”, “we”, “our”, “us”) collects, uses, stores, protects, and discloses personal information when providing our services. 

1.2 
We comply with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs) and the Notifiable Data Breaches (NDB) Scheme. 

1.3 
By using our services, you consent to the practices described in this Policy. 

 

  1. What Information We Collect

We may collect the following types of information: 

2.1 Client Information 

  • business name 
  • contact details 
  • billing details 
  • authorised representative details (which may include name, contact information, date of birth, and other identifying information necessary to verify identity or authority) 

2.2 User Information 

  • names, email addresses 
  • Microsoft 365 or Google Workspace user details 
  • user activity logs generated by managed service tools 

2.3 Technical and Device Information 

Collected automatically through security and monitoring tools: 

  • device name and type 
  • operating system and version 
  • security status 
  • IP addresses and geolocation approximations 
  • login audits and authentication data 
  • installed software details 
  • configuration data 
  • system performance metrics 

2.4 Security & Monitoring Data 

Used solely for cybersecurity and service delivery: 

  • alerts and threat indicators 
  • malware detection events 
  • suspicious login attempts 
  • network traffic patterns (non-content) 
  • configuration vulnerabilities 
  • endpoint risk scores 

We do not monitor employee behaviour, productivity, keystrokes, personal content, or communications. 

2.5 Cookies and Tracking 

We use tracking pixels and similar technologies (such as AdsWizz) to understand how visitors interact with our site and to measure the effectiveness of our advertising. These tools may collect your IP address, device identifiers, and site activity. This data may be shared with third-party advertising partners.

2.6 Support Interactions 

When you contact our helpdesk: 

  • phone calls 
  • emails 
  • helpdesk tickets 
  • chat transcripts 
  • troubleshooting logs 

2.7 Payment Information 

  • last four digits of card (actual card data is stored by our payment provider) 
  • billing address 
  • transaction records 

 

  1. How We Use Your Information

We use collected information to: 

  • provide and manage our services 
  • secure and monitor Client environments 
  • detect and respond to cybersecurity threats 
  • perform maintenance and troubleshooting 
  • deliver support services 
  • improve performance and reliability 
  • maintain compliance 
  • manage billing and payments 
  • communicate updates, notices, and alerts 
  • create aggregated, non-identifiable analytics 

 

  1. Why We Perform Cybersecurity Monitoring

4.1 
To reduce risk and protect your systems, our tools continuously monitor: 

  • device health and security posture 
  • suspicious authentication attempts 
  • threat alerts from SOC services 
  • malware and phishing indicators 
  • network performance and anomalies 
  • software patch status 

4.2 
Monitoring is not employee surveillance. 
It is strictly limited to security, system integrity, and operational performance. 

4.3 
Clients are responsible for informing their staff, contractors, and users that monitoring is performed under this Policy. 

 

  1. How We Store and Protect Your Information

We take reasonable steps to protect information from: 

  • unauthorised access 
  • misuse or interference 
  • loss 
  • modification 
  • disclosure 

Safeguards include: 

  • encryption 
  • MFA across systems 
  • least-privilege access controls 
  • SOC-managed monitoring 
  • secure storage systems within Australia or trusted SOC-compliant providers 
  • vendor security assessments 
  • regular audits and reviews 
  • secure credential management 

 

  1. Third-Party Service Providers

6.1 
We may use reputable third-party providers to deliver aspects of our services, including: 

  • cloud platforms 
  • backup providers 
  • SOC and cybersecurity vendors 
  • monitoring and management tools 
  • payment gateways 
  • email or communication platforms 

6.2 
Where third-party vendors store or process data, they must comply with: 

  • Australian privacy laws 
  • their own contractual privacy obligations 
  • industry-standard security practices 

6.3 
We do not sell or rent personal information to third parties. 

 

  1. Disclosure of Information

We may disclose information to: 

  • authorised Client representatives 
  • third-party vendors involved in service delivery 
  • law enforcement where legally required 
  • government authorities 
  • subcontractors who assist in service delivery 
  • professional advisors (e.g., legal, accounting, insurance) 

 

  1. Data Breaches

8.1 
If a data breach is likely to cause serious harm, we will notify: 

  • affected Clients, and 
  • the Office of the Australian Information Commissioner (OAIC) 
    as required under the Notifiable Data Breaches (NDB) Scheme. 

8.2 
We will also take all reasonable steps to contain and remediate the breach. 

 

  1. Accessing and Correcting Your Information

9.1 
You may request access to the personal information we hold about you. 

9.2 
We may charge a reasonable fee for retrieving archived or historical data. 

9.3 
If any information is inaccurate or outdated, you may request a correction. 

 

  1. Data Retention

10.1 
We retain personal information only as long as necessary to provide services or meet legal obligations. 

10.2 
Some records may need to be retained for compliance, security, or audit requirements. 

10.3 
After retention periods expire, information is securely deleted or anonymised. 

 

  1. Overseas Disclosure

11.1 
Some third-party tools or SOC providers may store or process data outside Australia. 

11.2 
We only use overseas vendors that maintain robust security controls and comply with relevant standards. 

11.3 
By using our services, you consent to this limited overseas processing. 

 

  1. Updates to This Policy

12.1 
We may update this Policy from time to time. 
Updates take effect after being published on our website. 

12.2 
Continued use of our services constitutes acceptance of the updated Policy. 

 

  1. Contact Us

For privacy-related questions or concerns: 

Contact us using the Web Contact Form