Pinnacle IT Systems Pty Ltd (“Pinnacle IT”, “we”, “us” or “our”) provides managed IT, cloud, networking, communications and related technology services.
We recognise the importance of protecting the security and privacy of information entrusted to us. This notice explains how we collect, use, protect and manage personal information and customer data.
Information we collect
Depending on how you interact with us, we may collect:
- names, job titles and contact details;
- customer, supplier and account information;
- service requests, support records and correspondence;
- billing, purchasing and contract information;
- device, system, network and security information;
- website usage information, including IP addresses and cookies; and
- other information provided to us in connection with our services.
When delivering managed IT services, we may also have authorised access to information stored within a customer’s systems.
How we use information
We may use information to:
- provide, manage and support our services;
- respond to enquiries and service requests;
- maintain, monitor and secure systems;
- investigate incidents, faults and outages;
- manage customer and supplier relationships;
- process orders, licensing, invoices and payments;
- improve our services and business operations;
- meet legal, regulatory and contractual obligations; and
- protect our customers, personnel, systems and business interests.
Where we handle information on behalf of a customer, we do so in accordance with the customer’s instructions and the applicable service agreement.
Disclosure of information
We may disclose information to authorised personnel, contractors, technology vendors, cloud providers, telecommunications providers, professional advisers and other service providers where reasonably required to deliver our services or operate our business.
We may also disclose information where required or authorised by law.
We do not sell personal information.
Some service providers may store or process information outside Australia.
How we protect information
Pinnacle IT maintains administrative, technical and physical safeguards designed to protect information from misuse, loss, unauthorised access, modification or disclosure.
Depending on the relevant system and service, these safeguards may include:
- access controls and least-privilege access;
- multi-factor authentication;
- encryption and secure communication methods;
- endpoint, email and network security controls;
- system monitoring and logging;
- patching and vulnerability management;
- backup and recovery arrangements;
- employee confidentiality and security awareness requirements; and
- documented incident-response processes.
The controls applied to a customer environment depend on the services purchased, the systems in use and the customer’s approved configuration.
No technology environment can be guaranteed to be completely secure. Customers are also responsible for maintaining appropriate user access, internal policies, passwords, devices and systems that are outside Pinnacle IT’s management.
Customer data
Pinnacle IT does not claim ownership of customer data.
We access customer data only where reasonably required to provide services, respond to support requests, maintain or secure systems, investigate incidents, comply with customer instructions or meet legal obligations.
Customer data is retained and deleted in accordance with the applicable service agreement, legal requirements and the technical capabilities of the relevant platforms.
Data retention
We retain personal information and business records only for as long as reasonably required for service delivery, contractual, legal, security, insurance and operational purposes.
When information is no longer required, we take reasonable steps to delete, destroy or de-identify it.
Data breaches
Pinnacle IT maintains processes for identifying, assessing and responding to suspected security incidents and data breaches.
Where required by law, we will notify affected individuals and the Office of the Australian Information Commissioner.
Suspected security incidents involving Pinnacle IT should be reported promptly to:
Email: servicedesk@pinnacleit.com.au
Access, correction and complaints
Individuals may request access to personal information we hold about them or ask us to correct information that is inaccurate, incomplete or out of date.
Privacy concerns or complaints may be submitted to our Privacy Officer. We may need to verify your identity before responding to a request.
Privacy Officer
Pinnacle IT Systems Pty Ltd
Email: servicedesk@pinnacleit.com.au
Changes to this notice
We may update this notice from time to time to reflect changes to our services, legal obligations or privacy and security practices. The current version will be published on our website.
