OramatelOramatel

Privacy Policy

Last updated 1 August 2026

Oramatel (“we”, “us”) is a sole-operator network engineering and cybersecurity consultancy based in Melbourne, Australia. This policy explains what personal information we collect, why, and what you can do about it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What we collect from this website

  • Analytics. We use Cloudflare Web Analytics, which is cookie-free and does not fingerprint or track individuals across sites. It reports aggregate page views, referrers and country.
  • Enquiry forms. Our consultation form is hosted by Tally. It collects the details you choose to provide — typically name, email, organisation and a description of your requirement.
  • Email. If you email us, we retain that correspondence.

We do not sell personal information, and we do not use it for advertising or profiling.

What we collect during an engagement

Delivering network and security work necessarily involves access to technical information about your environment — device inventories, configurations, logs, network diagrams and, where relevant, user account names. Some of this is personal information.

  • We collect only what the engagement requires.
  • We prefer read-only access and time-limited credentials wherever the work allows it.
  • We do not extract, copy or retain client business data beyond what is needed to produce the agreed deliverable and its supporting evidence.

Why we collect it

We collect, hold, use and disclose personal information only for these purposes:

  • To respond to your enquiry and work out whether we can help you
  • To scope, quote, deliver and support the services you engage us for
  • To produce the assessment reports and documentation you have asked us for
  • To invoice you and keep the tax and financial records we are required to keep
  • To meet our legal, insurance and professional-indemnity obligations

We do not use personal information for any secondary purpose you would not reasonably expect, and we do not sell it, rent it, or use it for advertising or profiling.

How we store it

Engagement records are stored on encrypted devices and in access-controlled cloud storage with multi-factor authentication. Credentials supplied for an engagement are held in a password manager and destroyed, or rotation is requested, at the end of the engagement.

Who we disclose it to

We do not disclose your information to third parties except: to the service providers who host our infrastructure; where you have asked us to work alongside your existing IT provider or MSP; or where required by law.

Overseas disclosure. We are likely to disclose personal information to recipients outside Australia, because two of our providers are based overseas:

  • Cloudflare, Inc. — website hosting and privacy-preserving analytics. Cloudflare is headquartered in the United States and operates a global network.
  • Tally BV — our enquiry form. Tally is based in Belgium and stores form data within the European Union.

We do not otherwise transfer personal information overseas. If that changes, we will update this page and name the countries involved.

How long we keep it

Enquiries that do not proceed are deleted within 12 months. Engagement records and deliverables are retained for seven years to meet tax, professional-indemnity and audit-evidence obligations, then destroyed.

Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

Accessing and correcting your information

You can ask us what personal information we hold about you, ask us to correct it, or ask us to delete it where we are not required to keep it. Email [email protected] and we will respond within 30 days.

Making a complaint

If you believe we have breached the Australian Privacy Principles, email [email protected] with the word “complaint” in the subject line and enough detail for us to investigate. What happens next:

  • We acknowledge your complaint in writing within 5 business days.
  • We investigate, which may include asking you for further information, and respond substantively within 30 days.
  • Our response will explain what we found, what we have done about it, and what we will do differently.

If you are not satisfied with our response, or we have not responded within 30 days, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or by phone on 1300 363 992.

Changes

We will update this page if our practices change, and update the date at the top.