Privacy policy
Last updated: 11 October 2026.
This policy explains how Curity Pty Ltd (ABN 97 664 894 026), trading as Curity IT Solutions (“Curity”, “we”, “us”), collects, uses, stores and discloses personal information. We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
What personal information we collect
- Contact details: your name, business name, role, email address, phone number and business address
- Enquiries: what you tell us when you call, email, book a meeting or use our contact form
- Client service information: details of the people we support for our clients, such as user names, devices, support requests and the information needed to resolve them
- Billing information: billing contacts, invoices and payment records. We don’t store full card numbers
- Phone calls: calls to our phone system may be recorded and transcribed for quality, training and to record support requests accurately
- Website information: technical details such as your browser, device and the pages you visit, collected through cookies and similar technology
We only collect sensitive information, such as health information, where it’s necessary to provide our services to a client and the law allows it.
How we collect it
Mostly directly from you: when you contact us, book a meeting, become a client or ask for support. We also collect information from our clients about their staff, from publicly available sources, and automatically from the systems we manage under our service agreements.
Why we collect and use it
- To answer enquiries and provide quotes
- To deliver IT support, monitoring, security and the other services in our agreements
- To manage accounts, billing and our relationship with you
- To keep our systems and our clients’ systems secure
- To improve our services and train our team
- To send you service updates and, if you agree, occasional information about our services. You can opt out at any time
- To meet our legal obligations
Information we handle for our clients
When we support a client’s systems, we may be able to access personal information that belongs to that client, such as their staff, customers or patients. We only access it as needed to provide the service, we keep it confidential under our service agreement, and the client remains responsible for how that information is collected and used.
How we use AI
We use AI tools to help our team, for example to summarise support calls into tickets and to find the right procedure. These tools run on platforms with business-grade data protection, they get only the access they need, and a person at Curity remains responsible for every outcome. We don’t use AI to make decisions about you that have a legal or similarly significant effect.
Who we disclose it to
We don’t sell personal information. We share it only when needed with:
- Service providers who help us run our business, such as Datto, our accounting system, our phone system, Microsoft 365, website hosting and Google (website analytics)
- Vendors, distributors and software providers, when needed to supply or support a product or service for you
- Our security operations centre (SOC) and network operations centre (NOC) partners, who monitor our clients’ systems
- Professional advisers, and government or law enforcement agencies where the law requires it
Overseas disclosure
We store the information we hold in Australia. Our main systems use Australian data centres: Microsoft 365 and Azure data is held in Microsoft’s Australian regions, and backups are stored with Datto in Sydney. Some of the companies that provide our cloud, IT management and AI services are based overseas, mainly in the United States, and some information may be accessed or processed outside Australia, for example when a provider gives technical support or delivers part of its service. When that happens, we take reasonable steps to make sure the information is protected to a standard similar to the Australian Privacy Principles.
How we protect it
We apply the same security we provide to our clients: multi-factor authentication, encryption, least-privilege access, monitored and patched systems, monitored backups and staff security training. Passwords and credentials are stored only in an approved password management system. When we no longer need personal information, we securely destroy or de-identify it, unless the law requires us to keep it.
Cookies and website analytics
We use Google Analytics 4 to understand how people use our website, so we can improve it. It sets cookies (named _ga and _ga_ followed by an ID) that tell us things like which pages are visited, how long visitors stay, the type of device and browser, the approximate area a visit comes from (city or region, worked out from your internet address, which Google Analytics does not store) and how visitors found us. It also records when someone sends our contact form, but not what they wrote.
We use this information in summary form only. We don’t use it to identify you, we don’t combine it with other information to work out who you are, and we don’t use it for advertising. Google signals and advertising features are turned off, and Google keeps the analytics data for 14 months. Google may process this data outside Australia, including in the United States. You can read how Google uses this information at policies.google.com/technologies/partner-sites.
You can block or delete cookies in your browser settings, or stop Google Analytics collecting information about your visits with the Google Analytics opt-out browser add-on. The website still works if you do.
Our website also uses a small number of cookies needed for it to work, such as for staff who sign in to edit the site. Videos on our site don’t load or set cookies until you press play, and play with Vimeo’s tracking turned off. Booking a meeting takes you to Microsoft Bookings, which has its own privacy statement.
Data breaches
If a data breach is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
Accessing or correcting your information
You can ask to access or correct the personal information we hold about you by emailing hello@curity.com.au. We’ll respond within 30 days. If we can’t give you access, we’ll explain why.
Complaints
If you have a privacy concern or complaint, contact us on hello@curity.com.au or (07) 4401 5141, or write to us at Level 1, 243 Ingham Road, Garbutt QLD 4814. We’ll acknowledge your complaint and aim to resolve it within 30 days. If you’re not satisfied, you can contact the OAIC.
Changes to this policy
We may update this policy from time to time. The latest version is always on this page.