TOKNET legal
Privacy Policy
1. About This Policy
1.1 This Privacy Policy explains how Toknet (“Toknet”, “we”, “us”, “our”) collects, uses, stores and discloses personal information when you contact us, engage us for Services, purchase a Product or use our website.
1.2 We are committed to handling personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply.
2. Information We Collect
2.1 We collect only information reasonably needed to operate our business and provide our Services and Products. This may include:
- contact details, including your name, business name, email address, phone number and postal address
- billing details, including ABN, invoicing and payment information
- engagement details, including correspondence, project requirements and information supplied under a Statement of Work
- technical information and limited administrative access required for work in a Microsoft 365 or SharePoint environment
- website usage information, such as pages visited, device information and general analytics
2.2 We do not intentionally collect sensitive information unless you provide it directly, it is reasonably necessary and we are permitted to collect it.
3. How We Collect Information
3.1 We usually collect information directly from you when you request a quote, communicate with us, accept a Statement of Work, provide access or make a purchase.
3.2 We may also receive information from your organisation, authorised representatives, service providers or automatically through our website. Where required, we will take reasonable steps to notify you about the collection.
4. How We Use Information
4.1 We use personal information to:
- provide, deliver and support Services and Products
- prepare quotes, manage engagements, issue invoices and process payments
- communicate with you and respond to enquiries
- secure and improve our business, website and services
- meet legal, accounting, insurance and professional obligations
4.2 We do not use personal information for unrelated marketing without consent. You may opt out of marketing communications at any time.
5. Client Systems and Data
5.1 Some engagements require limited access to personal information held in a Client's Microsoft 365, SharePoint or related environment.
5.2 We access and use that information only as reasonably necessary to provide the agreed Services, restrict access to authorised people and follow the Client's reasonable security instructions.
5.3 The Client is responsible for confirming it is authorised to give us access and for managing its own users, licences, backups and retention obligations.
6. Disclosure and Overseas Processing
6.1 We do not sell personal information. We may disclose it to:
- subcontractors or specialist consultants assisting with an engagement under confidentiality obligations
- accounting, legal, insurance and other professional advisers
- service providers used for email, cloud storage, security, invoicing and business administration
- government authorities or other parties where required or authorised by law
6.2 Providers such as Microsoft may store or process information outside Australia. The locations may vary according to the provider and service configuration. You may contact us for current information relevant to your engagement.
7. Storage, Security and Data Breaches
7.1 We use reputable service providers and take reasonable technical and organisational steps to protect personal information from misuse, loss and unauthorised access, modification or disclosure.
7.2 No system is completely secure. If we become aware of a suspected data breach, we will take reasonable steps to contain and assess it and will notify affected individuals and the Office of the Australian Information Commissioner where required by law.
8. Retention and Deletion
8.1 We retain personal information only for as long as reasonably needed for the purpose for which it was collected, to support an engagement, resolve a dispute or meet legal and business record-keeping obligations.
8.2 When information is no longer required, we take reasonable steps to securely delete or de-identify it. Project-specific return or deletion requirements may also be agreed in writing.
9. Website and Cookies
9.1 Our website may use essential cookies and limited, general analytics to support functionality and understand how the site is used. You can control cookies through your browser settings.
9.2 Information submitted through an enquiry form is used to respond to the enquiry. We do not add you to a mailing list without consent.
9.3 The website is intended for business and professional use and does not knowingly collect information from children.
10. Access and Correction
10.1 You may ask to access personal information we hold about you or request a correction if it is inaccurate, out of date or incomplete.
10.2 We may need to verify your identity. If we cannot provide access or make a requested correction, we will explain why where required by law.
11. Privacy Complaints
11.1 Please send privacy questions or complaints to legal@toknet.com.au. We aim to acknowledge a complaint within 7 days and respond within 30 days.
11.2 If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
12. Changes to This Policy
12.1 We may update this policy when our practices, services or legal obligations change. The version published on our website or provided for an engagement is the current version.