Privacy Policy

Scope and who we are

CSPRO provides managed information technology, cybersecurity, cloud, telecommunications, helpdesk, onsite and remote support services, as well as related websites, client portals and mobile applications. In this policy, CSPRO, we, us and our refer to Computer Support Professionals Pty Ltd.

This policy applies to personal information handled through our business operations, services, websites, portals, apps, support channels, events, marketing, recruitment and supplier relationships. A specific collection notice or service agreement may provide additional information for a particular service. If it is inconsistent with this policy, the more specific notice applies to that collection to the extent permitted by law.

This policy does not override any rights under the Privacy Act 1988 (Cth), the Australian Privacy Principles or other applicable privacy laws. Some employee records may be treated differently where an exemption or other law applies.

Personal information we collect and hold

The types of personal information we collect depend on the relationship and the services used. They may include:

  • Identity and contact information. Name, organisation, position, postal or service address, email address, telephone number, username and account identifiers.
  • Account and authentication information. Login records, authentication status, organisation membership, role, permissions, password-reset information and multi-factor authentication settings. We do not ask users to send passwords to us.
  • Support and service information. Support requests, call or chat records, correspondence, device and system details, screenshots, diagnostic files, configuration information, service history and material a customer chooses to provide so that we can assist.
  • Technical and usage information. Internet protocol address, device type, operating system, browser, app version, timestamps, feature use, audit events, crash information, security logs and similar diagnostic data.
  • Commercial and transaction information. Quotes, orders, licences, invoices, payment status, service entitlements and transaction references. If a payment provider processes card details, that provider handles them under its own privacy terms and CSPRO generally receives limited transaction information.
  • Website and marketing information. Cookie identifiers, analytics events, referral source, subscription preferences, campaign interactions and records of consent or opt-out choices.
  • Premises and communications information. Site access details, authorised contacts, call recordings where notice is given, and CCTV or visitor information at locations where it is used.
  • Recruitment and supplier information. Employment history, qualifications, references, right-to-work information, professional details and payment or tax information relevant to a contractor or supplier relationship.

Support material can sometimes contain personal or sensitive information about a customer, its personnel or third parties. Customers should provide only what is reasonably necessary. CSPRO collects sensitive information only where it is reasonably necessary for our functions and permitted by law, including where valid consent has been given or another legal basis applies.

How we collect personal information

We usually collect personal information directly from the individual when they contact us, create or use an account, submit a support request, use our services or websites, attend an event, subscribe to communications, apply for a role, or deal with us as a supplier.

We may also collect information from:

  • the organisation that employs or engages the individual, including an authorised administrator who creates or manages an account
  • customers, business partners, referrers, distributors and third-party service providers
  • devices, systems and applications connected to a service, where collection is authorised
  • publicly available sources and professional directories
  • cookies, analytics tools, security systems and service logs, and
  • government bodies, regulators or law-enforcement agencies where permitted or required by law.

Where practicable, we tell individuals why information is being collected, the main consequences of not providing it, and the usual disclosures. If CSPRO receives personal information that it did not request, we assess whether it could have been lawfully collected and destroy or de-identify it where required and lawful to do so.

Why we collect, hold, use and disclose information

We handle personal information for purposes reasonably connected with our functions and activities, including to:

  • respond to enquiries, prepare quotes, onboard customers and manage relationships
  • provide, configure, monitor, secure, support, maintain and improve services
  • authenticate users, administer accounts and apply customer-authorised access controls
  • investigate faults, security events, misuse, fraud, complaints and service incidents
  • process orders and payments, issue invoices and maintain tax and accounting records
  • communicate service notices, maintenance information, security alerts and changes
  • analyse service performance and improve reliability, usability and customer support
  • manage suppliers, personnel, recruitment, insurance, audits and business operations
  • meet legal, regulatory, contractual and professional obligations, and
  • send marketing where permitted and manage communication preferences.

We may use or disclose information for another purpose where the individual has consented or where the use or disclosure is authorised or required by law.

Anonymity and not providing information

Individuals may deal with us anonymously or under a pseudonym where lawful and practicable. This may be suitable for a general enquiry, but is usually not practical where CSPRO must verify identity, provide account access, attend a site, supply a paid service, investigate a security matter or meet legal obligations.

If required information is not provided, we may be unable to provide the requested service, create or secure an account, respond to a request, process a transaction or consider an application.

Who we disclose personal information to

Depending on the service, we may disclose personal information to:

  • the customer organisation and its authorised account administrators
  • CSPRO personnel, related entities and authorised contractors who need the information for their work
  • cloud hosting, data storage, identity, communications, monitoring, cybersecurity, analytics, payment, logistics and professional service providers
  • hardware, software, telecommunications and licensing vendors where needed to supply or support a product or service
  • insurers, auditors, lawyers, accountants, financiers and advisers
  • a prospective buyer, investor or successor as part of a genuine corporate transaction, subject to appropriate confidentiality safeguards, and
  • courts, regulators, government bodies and law-enforcement agencies where authorised or required by law.

We do not sell personal information. We require service providers to handle personal information only for authorised purposes and to apply appropriate confidentiality and security controls, subject to the terms and functionality of the relevant service.

Overseas disclosures

CSPRO operates and uses service providers in more than one country. Personal information is likely to be disclosed to recipients in Pakistan, the United States and New Zealand, and may be processed or stored in other countries depending on the customer service, provider configuration and support arrangement.

Before an overseas disclosure, we take reasonable steps required by applicable law. These steps may include due diligence, contractual privacy and security obligations, access controls and selecting an appropriate data region. Overseas laws and remedies may differ from those in Australia. A service-specific collection notice or agreement may identify additional locations.

Mobile apps portals and device information

When a person uses a CSPRO mobile app or client portal, we may collect account details, organisation and role information, support content, usage events, device and app information, internet protocol address, crash diagnostics, notification tokens and security logs.

An app may request access to a camera, photos, files or notifications when the user chooses a feature that needs that access, such as attaching an image to a support request. Permission can usually be controlled in device settings, but the related feature may not work if permission is refused. We do not use an app permission for an unrelated purpose.

If an account is supplied or managed by an employer or other customer organisation, its authorised administrators may manage the account and may access information associated with that organisation, subject to their authority and applicable law.

Cookies analytics and online advertising

Our websites and online services may use cookies, pixels, software development kits and similar technologies for essential operation, security, preferences, analytics and, where used, advertising measurement. These technologies can collect identifiers and information about a browser, device and interactions with our online services.

Users can control many cookies through browser or device settings and any consent controls we provide. Blocking some technologies may affect functionality. Third-party analytics and advertising providers handle information under their own privacy terms. Where required, we seek consent before using non-essential technologies.

Direct marketing

Where permitted by law, we may use contact information to send updates about CSPRO products, services, events or resources that may be relevant. Commercial electronic messages identify CSPRO and include a functional unsubscribe option. A person can opt out at any time by using that option or contacting us. We action opt-out requests within the period required by law and do not charge for opting out.

Service, account, billing and security communications are not marketing and may still be sent where needed to provide or protect a service.

Security

We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures are selected according to the nature of the information and may include access controls, multi-factor authentication, encryption in appropriate contexts, logging and monitoring, security testing, personnel training, supplier controls, physical safeguards and incident-response procedures.

No system or transmission method is completely secure. Users must protect account credentials, use available security features and promptly tell us about suspected unauthorised access. We do not ask users to provide passwords by email or support ticket.

Retention deletion and de-identification

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide and secure services, and to meet legal, accounting, insurance, dispute and contractual requirements. When information is no longer required, we take reasonable steps to delete or de-identify it, subject to lawful exceptions and technical backup cycles.

Record type

Typical retention approach

Active account and service records

For the account or service relationship and for a reasonable period afterwards where needed for support, security, disputes or legal obligations.

Deleted app account profile

Removed from active systems generally within 30 days after identity and authority are verified, subject to the exceptions below.

Backup copies

May remain in encrypted or access-controlled backups for up to 90 days before routine overwrite or expiry.

Security and audit logs

Generally retained for 90 days. Selected logs may be retained through supplier storage for up to 12 months, or longer where needed for an active investigation.

Billing tax contract and legal records

Generally retained for up to 7 years, or longer where required by law or reasonably necessary for a current claim or dispute.

Actual periods can vary because of the service configuration, a legal hold, an active security incident, a customer contract or a statutory requirement. Deletion from active systems does not require us to restore and edit a backup; information in a backup is isolated from ordinary use and expires through the normal backup cycle.

App account and associated data deletion

A CSPRO app user can request deletion of their account and associated personal information without reinstalling the app.

  • Email info@cspro.com.au with the subject App account deletion request. Include the account email address and organisation name, but do not send a password.
  • CSPRO will verify identity and, where the account is organisation-managed, may verify the request with the authorised customer administrator.
  • After verification, CSPRO will confirm the outcome and generally complete deletion from active systems within 30 days.

The deletion normally covers the account profile, authentication and preference information, app notification token, and support content held only for operation of that account. We may retain or de-identify information that must be kept for tax, billing, contractual, fraud-prevention, security, dispute or other legal reasons. The typical periods for backups, logs and business records are described above.

If information is controlled by a customer organisation or a third-party integration, CSPRO may need the authorised organisation to approve the request or may direct the individual to that controller or provider. Closing an account does not cancel unpaid charges or a separate service agreement.

Access and correction

An individual may ask for access to personal information CSPRO holds about them and may ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Requests can be made using the contact details at the end of this policy. No fee is charged for making a request.

We may ask for enough information to verify identity and locate the records. If the law permits a reasonable access charge, we will explain it in advance. We respond within a reasonable period and, if we refuse access or correction, provide written reasons and available complaint options where required by law.

Privacy questions and complaints

A privacy question or complaint should be sent to CSPRO using the contact details below and should describe the concern and the outcome sought. We will acknowledge the matter, investigate it fairly and aim to respond within 30 days. If more time is reasonably needed, we will explain why and provide an updated timeframe.

If the matter is not resolved, an individual may contact the Office of the Australian Information Commissioner. Information about making a privacy complaint is available at oaic.gov.au. The OAIC generally expects a person to first give the organisation a reasonable opportunity to respond.

Data breaches

CSPRO maintains procedures to assess and respond to suspected data breaches. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify affected individuals and the relevant regulator in accordance with that law. We may also provide practical steps individuals can take to reduce potential harm.

Children

CSPRO services, websites, portals and apps are primarily intended for organisations and adults and are not directed to children. We do not knowingly seek personal information from a child without appropriate authority. If a parent, guardian or customer believes a child has provided information without proper authority, they should contact us so that we can assess and address it.

Automated decisions

At the effective date of this policy, CSPRO does not arrange for a computer program to use personal information to make decisions that could reasonably be expected to significantly affect an individual's rights or interests. If that practice changes, we will update this policy to explain the kinds of personal information used and the kinds of decisions involved, as required by law.

Changes to this policy

We review this policy periodically and update it when our practices, services or legal obligations change. The current version is published on our website with its effective date. If a change is material, we will take reasonable steps to provide additional notice where appropriate. A change does not reduce rights that cannot lawfully be reduced.

Contact CSPRO

Privacy Officer
Computer Support Professionals Pty Ltd trading as CSPRO
Suite 444, 100 George Street
Parramatta NSW 2150
Australia

Email info@cspro.com.au

Telephone 1300 660 368

Website www.cspro.com.au