top of page

Privacy Policy

1. Introduction

CYONSE PTY LTD (ABN 80 694 798 868) ("Cyonse", "we", "us", "our") is committed to protecting the privacy of individuals whose personal information we collect, hold, use, and disclose in the course of our business activities.


This Privacy Policy explains how we manage personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs").


This Policy applies to all personal information collected through our website located at https://www.cyonse.au ("Website"), through direct enquiries, and in connection with our role as an introducer and referral coordinator for cyber incident response services.


By using our website or providing us with your personal information, you consent to the collection, use, and disclosure of your information as described in this Policy.

2. What Personal Information We Collect

We may collect the following types of personal information:


Contact details: name, email address, phone number, job title, and organisation name 

Business information: company name, ABN, industry, and nature of cyber incident or enquiry
Correspondence: records of communications you send to us via email, contact forms, or other channels
Technical data: IP address, browser type, device information, and website usage data collected automatically when you visit our Website


We do not collect sensitive information (such as health information, financial account details, or government identifiers) through this Website unless you voluntarily provide it in the course of an enquiry. If you do provide sensitive information, we will handle it with additional care in accordance with APP 3.

4. Purpose of Collection

We collect and use personal information for the following purposes:


to respond to your enquiries and provide information about our services;
to perform our role as an introducer and referral coordinator, including identifying and referring appropriate service providers from our Exclusive Network;
to communicate with insurers, brokers, law firms, and service providers in connection with a cyber incident referral;
to manage our business operations, including record-keeping and compliance 
obligations;

to improve our Website and services; and
to comply with applicable laws and regulatory requirements.


We will not use your personal information for a purpose other than those listed above without your consent, unless permitted or required by law

3. How We Collect Personal Information

5.1 Third-Party Disclosure


In the course of our referral coordination activities, we may disclose your personal information to:


Law firms: nominated by Cyonse to manage the engagement of service providers in 
connection with a cyber incident, for the purpose of maintaining legal professional 
privilege;
Service providers: members of Cyonse's Exclusive Network of specialist cyber incident response providers, to the extent necessary to facilitate a referral;
Insurers and brokers: who have referred a matter to Cyonse or who are involved in the management of a cyber insurance claim; and
Technology and platform providers: who assist us in operating our Website and business systems, subject to confidentiality obligations.


We do not sell, rent, or trade your personal information to third parties for marketing purposes.

​

5.2 Legal Disclosure 


We may disclose personal information where required or authorised by law, including to regulators, courts, or law enforcement agencies.

6. Cross-Border Disclosure

Some of the third parties to whom we disclose personal information may be located outside Australia, including cloud service providers and technology platforms. Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle your information in a manner consistent with the APPs, in accordance with APP 8.

​

By providing us with your personal information, you consent to it being disclosed to overseas recipients where necessary for the purposes described in this Policy.

7. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, in accordance with APP 11. 

 

These steps include:


encryption of data in transit using TLS 1.2 or higher, and encryption of data at rest using industry-standard encryption protocols where practicable;

multi-factor authentication for all staff and contractor access to systems holding personal information;
secure file transfer processes for client data, including the use of encrypted channels, 
and avoiding transmission of sensitive information via unencrypted email;
access controls that restrict access to personal information on a need-to-know basis, 
including role-based permissions and audit logging;

contractor screening and confidentiality controls for contractors engaged on incident response matters, including background checks where appropriate and confidentiality agreements prior to engagement;
regular privacy and security awareness training for our personnel; and
an internal data breach response plan, together with periodic reviews of our security posture and information handling practices.


Given the sensitive nature of cyber incident information, we apply heightened care to any information shared with us in connection with an incident referral. We strongly recommend that you do not submit confidential incident data, legally privileged communications, or sensitive organisational information through this Website's general contact channels.

8. Data Breach Notification

If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will comply with our obligations under the Notifiable Data Breaches scheme (Part IIIC of the Privacy Act), including notifying affected individuals and the Office of the Australian Information Commissioner 
("OAIC") as required.

9. Cookies and Website Analytics

Our Website may use cookies and similar tracking technologies to collect technical data about your visit, including pages viewed, time spent on the Website, and referring URLs. 

 

This information is used in aggregate form to improve our Website and is not used to identify you personally.
You may disable cookies through your browser settings. Disabling cookies may affect the functionality of some parts of our Website.

 

We may use third-party analytics tools (such as Google Analytics) to assist with this analysis. Those tools are subject to their own privacy policies.

10. Data Retention

We retain personal information for as long as necessary to fulfil the purposes for which it was collected, or as required by law. When personal information is no longer required, we take reasonable steps to destroy or de-identify it in accordance with APP 11.

 

For information collected in connection with a cyber incident referral, insurance-related matter, or associated business records, we generally retain that information for up to seven (7) years from the date the matter is finalised, unless a longer retention period is required or permitted by law, regulation, or contractual obligation.

 

Different retention periods may apply depending on the nature of the information, the purpose for which it was collected, and our legal, regulatory, insurance, and operational obligations.

11. Access and Correction

You have the right to request access to the personal information we hold about you, and to request correction of any information that is inaccurate, out of date, incomplete, or misleading, in accordance with APPs 12 and 13.


To make an access or correction request, please contact us using the details in Section 13. We will respond within a reasonable time and in accordance with our obligations under the Privacy Act. We may charge a reasonable fee for providing access where permitted by law.

12. Complaints

If you believe we have handled your personal information in a way that does not comply with the Privacy Act or this Policy, you may lodge a complaint with us by contacting us using the details in Section 13.


We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you may escalate your complaint to the OAIC at:


Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992

13. Contact Us

For any privacy-related enquiries, access or correction requests, or complaints, please contact:


Privacy Officer
CYONSE PTY LTD
Email: info@cyonse.au

14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The updated Policy will be posted on our Website with a revised effective date. We encourage you to review this Policy periodically.


Last updated: 1 June 2026

CYONSE PTY LTD
ABN: 80 694 798 868
Effective Date: 1 June 2026

bottom of page