Legal · Cenvra

Privacy Policy

How Cenvra collects, uses, discloses and protects personal information.

Document owner
Tim Speelman, Managing Director
Version
1.0
Effective date
17 August 2026
Next review
17 August 2027
Classification
Public
Applies to
Clients, website visitors, applicants, personnel and suppliers

Who we are

Cenvra is a cybersecurity advisory practice based in Brisbane, Queensland. Cenvra is a trading name of Speelman Group Pty Ltd, ABN 73 697 724 860.

This policy explains how we collect, use, disclose and protect personal information. It applies to our website, our client engagements, our recruitment and our employment records.

We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where we deliver services to a Queensland Government agency, we also comply with the Queensland Privacy Principles and the mandatory notification of data breach requirements under the Information Privacy Act 2009 (Qld), as required by our contract with that agency.

We commit to these standards because our clients expect it and because we assess other organisations against them.

What personal information we collect

We collect only what we need. In most engagements, the information that matters is technical, not personal.

CategoryExamples
Business contactsName, job title, employer, work email, work phone number
Engagement informationNames and roles of client staff involved in an engagement, meeting notes, approvals and sign-offs
Technical informationAccount names, user identifiers and access records encountered during assessment or testing work
Website visitorsInformation you provide through an enquiry, and standard server log information
Job applicantsApplication, CV, work history, qualifications, referee comments and screening check results
Employees and contractorsRecords required to employ or engage you, including pay, tax, superannuation, leave and emergency contacts
SuppliersContact and payment details for the individuals we deal with

Sensitive information. We do not seek sensitive information. We may hold a limited amount where it is necessary and you have consented, such as health information relevant to a workplace adjustment, or the results of a national police check for a person we employ or engage.

Testing and assessment work. Penetration testing, vulnerability assessment and security assessment work can incidentally expose personal information held in a client's systems. We treat that information as belonging to the client. We do not extract more than is needed to demonstrate a finding, we do not retain it beyond the engagement, and we handle it under the terms of the engagement agreement.

How we collect it

We collect personal information directly from you wherever we can, including when you contact us, engage us, apply for a role, or work with us on an engagement.

We may also collect it from others, including a client who tells us who to speak to, a referee you nominate, a screening provider, or a publicly available source such as a company website or a professional networking profile.

Why we collect it and how we use it

  1. To deliver, manage and support the services a client has engaged us for.
  2. To communicate with you about an engagement, an enquiry or a proposal.
  3. To assess candidates and manage our employment and contractor relationships.
  4. To meet our legal, tax, insurance and work health and safety obligations.
  5. To manage our own security, including access control and incident response.
  6. To invoice and to keep the business records the law requires us to keep.

We do not sell personal information. We do not use it for automated decision making. We do not use it for direct marketing beyond responding to enquiries and occasional service updates to existing business contacts, who can opt out at any time by replying and asking us to stop.

Who we disclose it to

RecipientReason
Delivery partnersWhere a partner such as a testing or technology partner is engaged on the work, and only where the client has agreed. Partners are bound by confidentiality and privacy obligations
Service providersCloud, email, accounting, payroll and screening providers who support the running of the business
Insurers and advisersWhere reasonably required, including in connection with a claim
Regulators and law enforcementWhere the law requires or authorises it
A purchaserIf the business or part of it is sold, subject to equivalent privacy protection

Overseas disclosure. We use Microsoft 365 and other business software. Our primary data location is Australia. Some providers may store or process information overseas, including in the United States, or provide support from overseas. Before we disclose personal information to an overseas recipient we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, and we rely on contractual protection to do that.

How we protect it

We apply the controls we would expect any organisation we assess to apply.

  • Multi-factor authentication on every account
  • Encryption on every device, and encryption of information in transit
  • Access granted on a need-to-know basis and reviewed regularly
  • Managed, patched and monitored devices
  • Screening of all personnel, and confidentiality obligations that survive the engagement
  • Backups, and a tested plan for responding to an incident

No control set is perfect. If something goes wrong, our Privacy and Data Breach Response Plan sets out how we contain it, assess it and notify the people affected.

How long we keep it

InformationRetention
Client engagement records and reportsSeven years from the end of the engagement, or as agreed in the engagement contract
Test evidence, credentials and extractsDestroyed at the end of the engagement unless the client asks otherwise in writing
Employee recordsSeven years after employment ends, as required by the Fair Work Act 2009 (Cth)
Unsuccessful job applicationsTwelve months, unless you ask us to keep them longer
Financial and tax recordsSeven years, as required by law
Enquiries that do not proceedTwenty four months

When we no longer need information, we destroy it or de-identify it.

Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it. Contact us using the details at the end of this policy.

We will respond within 30 days. We will verify your identity first. There is no charge for making a request, though we may charge a reasonable amount for the work involved in supplying a large volume of material. If we refuse a request we will tell you why in writing, and tell you how to complain.

If the information sits inside a client's systems rather than ours, we will tell you and point you to the client, who is the right organisation to ask.

Data breaches

If a data breach happens and it is likely to result in serious harm to anyone whose personal information is involved, we will contain it, assess it promptly, and notify the individuals affected and the relevant regulator.

Where the information belongs to a client, we will notify the client immediately so they can meet their own obligations, and we will support their response.

Our website

Our website is a static site. We do not use advertising trackers or third-party analytics profiling. Our hosting provider keeps standard server logs, which may include IP addresses, for security and reliability purposes.

If you contact us through the website, we use your details only to respond to you.

Making a complaint

  1. Contact us using the details below. Tell us what happened and what outcome you are looking for.
  2. We will acknowledge your complaint within 5 working days and respond substantively within 30 days.
  3. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to the Office of the Information Commissioner Queensland at oic.qld.gov.au where the matter concerns work we did for a Queensland Government agency.

Changes to this policy

We review this policy at least annually and whenever our services, systems or obligations change materially. The current version is always the one published on our website.

Contact us

Privacy Officer
Tim Speelman, Managing Director
Entity
Speelman Group Pty Ltd t/a Cenvra, ABN 73 697 724 860
This document is approved and issued for use from 17 August 2026. Approved by Tim Speelman, Managing Director. Version 1.0 · Next review 17 August 2027.
Cenvra is a trading name of Speelman Group Pty Ltd · ABN 73 697 724 860 · Brisbane, Queensland.