Privacy Policy
How Cenvra collects, uses, discloses and protects personal information.
Who we are
Cenvra is a cybersecurity advisory practice based in Brisbane, Queensland. Cenvra is a trading name of Speelman Group Pty Ltd, ABN 73 697 724 860.
This policy explains how we collect, use, disclose and protect personal information. It applies to our website, our client engagements, our recruitment and our employment records.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth). Where we deliver services to a Queensland Government agency, we also comply with the Queensland Privacy Principles and the mandatory notification of data breach requirements under the Information Privacy Act 2009 (Qld), as required by our contract with that agency.
We commit to these standards because our clients expect it and because we assess other organisations against them.
What personal information we collect
We collect only what we need. In most engagements, the information that matters is technical, not personal.
| Category | Examples |
|---|---|
| Business contacts | Name, job title, employer, work email, work phone number |
| Engagement information | Names and roles of client staff involved in an engagement, meeting notes, approvals and sign-offs |
| Technical information | Account names, user identifiers and access records encountered during assessment or testing work |
| Website visitors | Information you provide through an enquiry, and standard server log information |
| Job applicants | Application, CV, work history, qualifications, referee comments and screening check results |
| Employees and contractors | Records required to employ or engage you, including pay, tax, superannuation, leave and emergency contacts |
| Suppliers | Contact and payment details for the individuals we deal with |
Sensitive information. We do not seek sensitive information. We may hold a limited amount where it is necessary and you have consented, such as health information relevant to a workplace adjustment, or the results of a national police check for a person we employ or engage.
Testing and assessment work. Penetration testing, vulnerability assessment and security assessment work can incidentally expose personal information held in a client's systems. We treat that information as belonging to the client. We do not extract more than is needed to demonstrate a finding, we do not retain it beyond the engagement, and we handle it under the terms of the engagement agreement.
How we collect it
We collect personal information directly from you wherever we can, including when you contact us, engage us, apply for a role, or work with us on an engagement.
We may also collect it from others, including a client who tells us who to speak to, a referee you nominate, a screening provider, or a publicly available source such as a company website or a professional networking profile.
Why we collect it and how we use it
- To deliver, manage and support the services a client has engaged us for.
- To communicate with you about an engagement, an enquiry or a proposal.
- To assess candidates and manage our employment and contractor relationships.
- To meet our legal, tax, insurance and work health and safety obligations.
- To manage our own security, including access control and incident response.
- To invoice and to keep the business records the law requires us to keep.
We do not sell personal information. We do not use it for automated decision making. We do not use it for direct marketing beyond responding to enquiries and occasional service updates to existing business contacts, who can opt out at any time by replying and asking us to stop.
Who we disclose it to
| Recipient | Reason |
|---|---|
| Delivery partners | Where a partner such as a testing or technology partner is engaged on the work, and only where the client has agreed. Partners are bound by confidentiality and privacy obligations |
| Service providers | Cloud, email, accounting, payroll and screening providers who support the running of the business |
| Insurers and advisers | Where reasonably required, including in connection with a claim |
| Regulators and law enforcement | Where the law requires or authorises it |
| A purchaser | If the business or part of it is sold, subject to equivalent privacy protection |
Overseas disclosure. We use Microsoft 365 and other business software. Our primary data location is Australia. Some providers may store or process information overseas, including in the United States, or provide support from overseas. Before we disclose personal information to an overseas recipient we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, and we rely on contractual protection to do that.
How we protect it
We apply the controls we would expect any organisation we assess to apply.
- Multi-factor authentication on every account
- Encryption on every device, and encryption of information in transit
- Access granted on a need-to-know basis and reviewed regularly
- Managed, patched and monitored devices
- Screening of all personnel, and confidentiality obligations that survive the engagement
- Backups, and a tested plan for responding to an incident
No control set is perfect. If something goes wrong, our Privacy and Data Breach Response Plan sets out how we contain it, assess it and notify the people affected.
How long we keep it
| Information | Retention |
|---|---|
| Client engagement records and reports | Seven years from the end of the engagement, or as agreed in the engagement contract |
| Test evidence, credentials and extracts | Destroyed at the end of the engagement unless the client asks otherwise in writing |
| Employee records | Seven years after employment ends, as required by the Fair Work Act 2009 (Cth) |
| Unsuccessful job applications | Twelve months, unless you ask us to keep them longer |
| Financial and tax records | Seven years, as required by law |
| Enquiries that do not proceed | Twenty four months |
When we no longer need information, we destroy it or de-identify it.
Accessing and correcting your information
You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it. Contact us using the details at the end of this policy.
We will respond within 30 days. We will verify your identity first. There is no charge for making a request, though we may charge a reasonable amount for the work involved in supplying a large volume of material. If we refuse a request we will tell you why in writing, and tell you how to complain.
If the information sits inside a client's systems rather than ours, we will tell you and point you to the client, who is the right organisation to ask.
Data breaches
If a data breach happens and it is likely to result in serious harm to anyone whose personal information is involved, we will contain it, assess it promptly, and notify the individuals affected and the relevant regulator.
Where the information belongs to a client, we will notify the client immediately so they can meet their own obligations, and we will support their response.
Our website
Our website is a static site. We do not use advertising trackers or third-party analytics profiling. Our hosting provider keeps standard server logs, which may include IP addresses, for security and reliability purposes.
If you contact us through the website, we use your details only to respond to you.
Making a complaint
- Contact us using the details below. Tell us what happened and what outcome you are looking for.
- We will acknowledge your complaint within 5 working days and respond substantively within 30 days.
- If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to the Office of the Information Commissioner Queensland at oic.qld.gov.au where the matter concerns work we did for a Queensland Government agency.
Changes to this policy
We review this policy at least annually and whenever our services, systems or obligations change materially. The current version is always the one published on our website.
Contact us
Cenvra is a trading name of Speelman Group Pty Ltd · ABN 73 697 724 860 · Brisbane, Queensland.