LEGAL · HARDROCK CYBER

Privacy Policy

How Hardrock Cyber collects, uses, stores and protects your personal information — in plain English, aligned with the Australian Privacy Act.

Last updated: June 2026

ON THIS PAGE

Who we are

Information we collect

How we use it

Storage & security

Your rights

Contact us

Who we are

Hardrock Cyber is the trading name of Hardrock Management Services Pty Ltd — an independent Australian cyber security consultancy based in North Queensland and serving clients Australia-wide. We specialise in cyber security audits, assessments and inspections, and the advisory and remediation work that follows — helping organisations measure and strengthen their defences through structured, evidence-based engagements conducted with our own purpose-built audit tools. This policy explains what personal information we collect, how we use and protect it, and your rights under Australian privacy law.

Information we collect

We collect only the information we need to deliver our services, gathered mainly during onsite audits and through this website:

• Client & contact details — your name, organisation, site name, the consultant assigned, audit dates and contact information.

• Audit data — your responses to cyber security assessment questions (for example, multi-factor authentication and application control), maturity ratings, evidence and certification notes, and the resulting findings.

• Technical & usage data — limited application logs such as audit session timestamps, and standard website analytics if you visit our site.

We do not collect sensitive information (such as health, financial or biometric data) through our audit tools unless you choose to include it in free-text notes — which we actively discourage.

How we use it

We use the information we collect to:

• Conduct and document your cyber security maturity assessment.

• Produce clear, professional audit reports.

• Provide remediation recommendations and advisory support.

• Improve our tools and methodology, using de-identified data wherever possible.

• Meet our legal and regulatory obligations.

We never sell your data, and we don't use it for marketing without your explicit consent.

Storage & security

Protecting your information is central to how we work:

• Onsite audit tool — assessment data is stored locally in an encrypted database on the consultant's secured Windows device, and operates air-gapped from your network by design.

• Reports & records — completed reports and related files are held on Hardrock Cyber's encrypted systems, with access strictly limited on a need-to-know basis.

• Security controls — we apply the ASD Essential Eight principles, strong access controls (including hardware security keys for layered authentication), regular backups, and industry-standard encryption for data at rest and in transit.

• Retention — we keep your data only as long as needed for the engagement or as required by law.

• Third parties — any service provider we rely on is bound by strict confidentiality obligations.

Your rights

Under the Australian Privacy Principles in the Privacy Act 1988 (Cth), you have the right to:

• Access the personal information we hold about you, and ask us to correct it.

• Request deletion or de-identification of your information, subject to our legal obligations.

• Withdraw your consent where applicable.

• Make a complaint about how we have handled your information.

We will acknowledge and respond to requests within 30 days. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Contact us

For any privacy question, access request or complaint, please get in touch:

Hardrock Cyber (Hardrock Management Services Pty Ltd)

Email: tech@hardrockcyber.com.au

Phone: (07) 2111 7945

Postal address available on request.

We will investigate and respond promptly, in line with Australian privacy law.