Privacy Policy
Mercury Information Security Services Pty Ltd ("Mercury", "we", "our" or "us") is committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Mercury provides cybersecurity consulting, advisory, assurance and testing services throughout Australia.
This Privacy Policy explains how we collect, use, disclose and protect personal information when you visit our website, contact us or engage our services.
When using our website, information we may collect:
Information You Provide
Name
Organisation
Job title
Email address
Phone number
Information submitted through contact forms
Information provided when requesting services, reports or information
Information Collected Automatically
When you browse our website, we may collect technical information such as:
IP address
Browser type and version
Device information
Pages visited
Date and time of access
Website referral information
Website usage statistics
How We Use Your Information
We use personal information to:
Respond to enquiries and requests
Provide information about our services
Deliver cybersecurity consulting and assurance services
Manage client relationships
Improve our website and service offerings
Meet contractual, legal and regulatory obligations
Maintain the security and integrity of our systems
We will only use personal information for the purpose for which it was collected or for a related purpose that would reasonably be expected.
Cookies and Analytics
Our website may use cookies and similar technologies to improve user experience and analyse website performance.
Cookies help us understand how visitors use our website, identify technical issues and improve website functionality. You can configure your browser to reject cookies; however, some website features may not operate correctly.
Marketing Communications
If you contact Mercury, we may occasionally send information relating to our services, security insights, events or company updates.
You may opt out of marketing communications at any time by following the unsubscribe instructions in our communications or by contacting us directly.
Disclosure of Personal Information
We may disclose personal information to:
Employees and contractors involved in delivering services
Service providers supporting our business operations
Regulatory or law enforcement agencies where required by law
Mercury does not sell personal information to third parties.
Client Engagements
As a cybersecurity consultancy, Mercury may access information contained within client environments while delivering agreed services. Such access occurs only in accordance with contractual obligations and client instructions. Responsibility for the collection and use of personal information within client systems remains with the client.
Information Security
Mercury applies administrative, technical and physical safeguards designed to protect personal information from unauthorised access, disclosure, alteration and loss. Access to personal information is restricted to personnel who require it for legitimate business purposes. Personal information is retained only for as long as necessary to fulfil legal, contractual and operational requirements.
Overseas Disclosure
Mercury is an Australian-based organisation and engagement-related data is primarily stored and processed within Australia. Where third-party systems or service providers operate outside Australia, Mercury takes reasonable steps to ensure appropriate privacy, contractual and security protections are in place.
Access and Correction
You may request access to personal information we hold about you and request corrections where required. Mercury will respond to such requests within a reasonable timeframe.
Data Breaches
If a data breach involving personal information occurs, Mercury will assess and respond to the incident in accordance with applicable Australian privacy laws, including the Notifiable Data Breaches Scheme where required.
Third-Party Websites
Our website may contain links to third-party websites. Mercury is not responsible for the privacy practices or content of external websites. We encourage you to review the privacy policies of any third-party sites you visit.
Changes to This Policy
Mercury may update this Privacy Policy from time to time. The current version will always be available on this website. Continued use of the website after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have any questions, requests or complaints regarding privacy or the handling of personal information, please contact us:
Mercury Information Security Services Pty Ltd
Email: [email protected]
Website: www.mercuryiss.com.au
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) via www.oaic.gov.au.