Privacy Policy

Mercury Information Security Services Pty Ltd ("Mercury", "we", "our" or "us") is committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Mercury provides cybersecurity consulting, advisory, assurance and testing services throughout Australia.

This Privacy Policy explains how we collect, use, disclose and protect personal information when you visit our website, contact us or engage our services.

When using our website, information we may collect:

Information You Provide

Name

Organisation

Job title

Email address

Phone number

Information submitted through contact forms

Information provided when requesting services, reports or information

Information Collected Automatically

When you browse our website, we may collect technical information such as:

IP address

Browser type and version

Device information

Pages visited

Date and time of access

Website referral information

Website usage statistics

How We Use Your Information

We use personal information to:

Respond to enquiries and requests

Provide information about our services

Deliver cybersecurity consulting and assurance services

Manage client relationships

Improve our website and service offerings

Meet contractual, legal and regulatory obligations

Maintain the security and integrity of our systems

We will only use personal information for the purpose for which it was collected or for a related purpose that would reasonably be expected.

Cookies and Analytics

Our website may use cookies and similar technologies to improve user experience and analyse website performance.

Cookies help us understand how visitors use our website, identify technical issues and improve website functionality. You can configure your browser to reject cookies; however, some website features may not operate correctly.

Marketing Communications

If you contact Mercury, we may occasionally send information relating to our services, security insights, events or company updates.

You may opt out of marketing communications at any time by following the unsubscribe instructions in our communications or by contacting us directly.

Disclosure of Personal Information

We may disclose personal information to:

Employees and contractors involved in delivering services

Service providers supporting our business operations

Regulatory or law enforcement agencies where required by law

Mercury does not sell personal information to third parties.

Client Engagements

As a cybersecurity consultancy, Mercury may access information contained within client environments while delivering agreed services. Such access occurs only in accordance with contractual obligations and client instructions. Responsibility for the collection and use of personal information within client systems remains with the client.

Information Security

Mercury applies administrative, technical and physical safeguards designed to protect personal information from unauthorised access, disclosure, alteration and loss. Access to personal information is restricted to personnel who require it for legitimate business purposes. Personal information is retained only for as long as necessary to fulfil legal, contractual and operational requirements.

Overseas Disclosure

Mercury is an Australian-based organisation and engagement-related data is primarily stored and processed within Australia. Where third-party systems or service providers operate outside Australia, Mercury takes reasonable steps to ensure appropriate privacy, contractual and security protections are in place.

Access and Correction

You may request access to personal information we hold about you and request corrections where required. Mercury will respond to such requests within a reasonable timeframe.

Data Breaches

If a data breach involving personal information occurs, Mercury will assess and respond to the incident in accordance with applicable Australian privacy laws, including the Notifiable Data Breaches Scheme where required.

Third-Party Websites

Our website may contain links to third-party websites. Mercury is not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of any third-party sites you visit.

Changes to This Policy

Mercury may update this Privacy Policy from time to time. The current version will always be available on this website. Continued use of the website after changes take effect constitutes acceptance of the updated policy.

Contact Us

If you have any questions, requests or complaints regarding privacy or the handling of personal information, please contact us:

Mercury Information Security Services Pty Ltd
Email: [email protected]
Website: www.mercuryiss.com.au

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) via www.oaic.gov.au.