IT First Responder

Privacy Policy

Current version — effective 16 August 2026
IT First Responder Pty Ltd
ABN: 24 617 080 127

IT FIRST RESPONDER PRIVACY POLICY

Current version — effective 16 August 2026

IT First Responder Pty Ltd (ABN 24 617 080 127) (ITFR, we, us or our) respects privacy and handles personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other applicable privacy laws. This policy explains our information-handling practices. It is not a substitute for service-specific privacy, data-processing or security terms agreed with a customer.

Privacy contact: IT First Responder Pty Ltd, 02 8003 4009, [email protected]. Please use this contact for privacy enquiries, access or correction requests, complaints and data-breach questions.

1. Scope and who is responsible

This policy applies to personal information collected through our websites, forms, portals, service desk, proposals, contracts, events, communications and delivery of IT, managed support, Microsoft 365, cloud, endpoint, identity, email, network, SOC/MDR/XDR, backup, incident-response, project, connectivity, telephony, governance, advisory, hardware, software and AI/Copilot services.

ITFR may act as an APP entity for its own business operations. When a customer gives us personal information about its employees, contractors, users, customers or other individuals for managed services, ITFR generally handles it on the customer’s documented instructions and the customer remains responsible for its notices, consents and lawful authority. The customer’s contract, statement of work and any data-processing schedule govern that handling if they differ from this public policy.

The Privacy Act’s small-business exemption may apply in some circumstances, but ITFR follows this policy as a matter of practice and contract. Whether the Privacy Act applies depends on turnover and statutory exceptions; the exemption does not remove contractual, confidentiality, security, consumer, state or territory obligations.

2. Personal information we collect

Depending on the relationship and service, we may collect:

  • identity and contact details, job title, employer and authorised-contact information;
  • billing, payment authorisation, tax and transaction information (we do not intentionally store full payment-card numbers where our payment provider processes them);
  • service requests, recordings or transcripts where notified, correspondence, proposals, contracts, preferences and feedback;
  • device, endpoint, network, identity, email, security, access, authentication, configuration, log, telemetry, alert, vulnerability, backup and incident-response information;
  • information contained in customer systems, files, mailboxes, tickets, backups and cloud tenants that we are authorised to access;
  • website and technical information such as IP address, browser, device, referring page, approximate location, cookies and interaction data;
  • information supplied by customers about their personnel, customers, suppliers and users; and
  • information needed to investigate fraud, misuse, threats, complaints, disputes or legal obligations.

We do not seek sensitive information unless it is reasonably necessary and permitted by law or the customer has instructed us to handle it. If sensitive or health information is placed in a service system, the customer must ensure it has lawful authority and appropriate safeguards.

3. How we collect information

We collect information directly from individuals and customers, from authorised customer systems and service providers, and automatically through websites, portals, logs, cookies and security tools. We may receive information from Microsoft, cloud, security, backup, telecommunications, payment, identity, analytics and other providers, from public sources, and from a customer’s authorised representative.

Where practicable, we will provide an APP 5 collection notice or link when collecting personal information. If a customer supplies information about another person, the customer must provide any notice and obtain any consent required by law, unless an exception applies.

4. Why we collect, use and disclose information

We collect, use and disclose personal information as reasonably necessary to:

  • provide, administer, secure, monitor, support, troubleshoot and improve contracted services;
  • manage accounts, quotes, proposals, orders, billing, renewals, procurement, warranties and customer relationships;
  • authenticate users, administer identities and permissions, detect threats, investigate incidents and protect people, systems and information;
  • perform migrations, backups, restores, projects, audits, advisory work and service reporting;
  • communicate service notices, maintenance, security alerts, support updates and other essential information;
  • send marketing communications where permitted, subject to unsubscribe rights;
  • maintain records, meet legal and regulatory duties, respond to lawful requests and establish, exercise or defend legal claims; and
  • manage risk, quality, fraud, complaints, workplace safety and business operations.

We will not use or disclose personal information for a materially unrelated purpose unless permitted or required by law, reasonably expected, or the individual consents. We do not sell personal information.

5. Service providers, disclosures and overseas handling

We may disclose information to personnel, related entities, subcontractors and technology providers that help us deliver services, including hosting, Microsoft and cloud platforms, RMM/PSA and ticketing systems, backup and security platforms, SOC/MDR/XDR providers, identity and email providers, telecommunications carriers, payment processors, accountants, insurers, professional advisers, auditors, debt-recovery providers and government or law-enforcement bodies where authorised or required.

Some providers may store or access information outside Australia, including in the countries in which Microsoft, cloud, security, backup, support, communications and other providers operate. Before an overseas disclosure, ITFR will take steps required by APP 8 or rely on a lawful exception. Overseas recipients may be subject to foreign laws and may not provide identical protections. Current provider locations can change; customers may request more detail for a particular service.

When acting for a customer, we may disclose information to the customer, its authorised users and its nominated providers on the customer’s instructions. We may disclose information to police, regulators, courts, insurers, advisers or emergency services where necessary, authorised or required by law.

6. Cookies, analytics and communications

Our websites may use necessary cookies, preference cookies, analytics and security technologies. These may record device, browser, IP, page and interaction information. We may use third-party analytics, hosting, consent-management, advertising or embedded-content providers where configured. Browser settings and available consent controls can limit cookies, but disabling necessary cookies may affect functionality. Our marketing messages include an unsubscribe facility. Service, security, billing and account notices may continue where necessary to perform a contract or comply with law.

7. Microsoft 365, cloud, security telemetry and AI

Managed services may require access to tenant, endpoint, identity, email, network, backup and security telemetry. Access is limited to authorised personnel and tools for the agreed purpose, but security logs and alerts can contain usernames, addresses, message metadata, device identifiers or fragments of customer content.

Where AI, Copilot, automation or machine-assisted tools are used, they may process prompts, configuration data, service records or other information according to the applicable service configuration and provider terms. ITFR will use reasonable controls and human review appropriate to the task. Customers must not provide information to an AI tool unless authorised and must review material outputs; AI output is not a legal, financial, medical, compliance or security guarantee.

8. Security and data retention

ITFR takes reasonable steps appropriate to the circumstances to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Controls may include access restriction, authentication, least privilege, logging, encryption where appropriate, backups, supplier controls, staff training, incident procedures and secure disposal. No method of transmission or storage is completely secure, and this policy does not promise that a breach can never occur.

We retain personal information only for as long as reasonably necessary for the purpose collected, service delivery, security, backups, dispute management, legal obligations, tax, audit and legitimate business records. Retention periods vary by system and service. When no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to backup cycles, legal holds, customer instructions and lawful retention duties.

9. Data breaches and incident notification

We maintain procedures to identify, contain, assess, remediate and record suspected privacy incidents. Where the Notifiable Data Breaches scheme applies and an eligible data breach is reasonably believed to have occurred, ITFR will notify the OAIC and affected individuals as required by law. We will notify an affected customer without undue delay where required by the customer contract or reasonably necessary, provide available information, and cooperate with the customer’s response. Notification timing and content may be affected by law-enforcement, security, forensic or safety considerations.

10. Access and correction

An individual may request access to, or correction of, personal information we hold by contacting [email protected]. We may need to verify identity and authority, clarify the request and consult a customer where the information is held on the customer’s behalf. We will respond within the period required by applicable law, ordinarily within 30 days for an access request, and explain any permitted refusal or charge. We may redact information about another person, confidential business information or security-sensitive details where lawful.

If information is inaccurate, incomplete, out-of-date or misleading, please identify the correction sought and supporting material. If we refuse correction, we will provide reasons where required and, where appropriate, associate a statement with the record.

11. Complaints and external review

Privacy complaints should be sent to [email protected] or IT First Responder Pty Ltd, marked “Privacy Complaint”. We will acknowledge and investigate complaints using a fair, confidential process and respond within a reasonable period. If you are not satisfied, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992. Nothing in this policy limits a person’s rights under applicable law, including the statutory cause of action for serious invasions of privacy where its requirements are met.

12. Direct marketing

We may send information about ITFR services, products, events and relevant offerings where permitted by law. We will identify ourselves and provide a simple unsubscribe method. You can opt out at any time; transactional, security, service and account communications are not marketing and may continue.

13. Children, sensitive information and identity

Our services are directed to businesses and professionals, not children. We do not knowingly collect children’s information except where a customer lawfully provides it for an agreed service. We may collect sensitive information only where reasonably necessary and permitted by law, with additional controls appropriate to the sensitivity and risk. We may ask for identity or authority evidence before disclosing or changing information.

14. Employees, contractors and customer-controlled data

Employee records may be subject to the employee-records exemption or other applicable rules. Customer-controlled data remains subject to the customer’s instructions, contract and policies. Customers must ensure their collection, disclosure to ITFR, access permissions, retention, cross-border transfers and use of personal information are lawful. ITFR may refuse or suspend access that is unlawful, unsafe or outside the agreed authority.

15. Changes and version history

We may update this policy to reflect changes in law, technology, services or practices. We will publish the new version and effective date. Material changes will be notified where required or reasonably appropriate. An updated public policy does not retrospectively alter contractual privacy terms or the version incorporated into an accepted quote, proposal or service agreement.

Version: 16 August 2026 · Entity: IT First Responder Pty Ltd · ABN: 24 617 080 127.

Historical Privacy Policy — Effective 7 June 2021

IT First Responder

Privacy Policy

Boufarhat Corp Pty LTD T/A IT First Responder
Effective Date: 7 June, 2021

1. IT FIRST RESPONDER RESPECT YOUR INDIVIDUAL PRIVACY

This Privacy Policy (‘Policy’) embodies our commitment to its protection through adherence to fair electronic information practices. This Policy puts you, the individual, in control of how your personal information is processed. You have our promise that we will not electronically process your personal information in any way that is incompatible with this Policy. If you have questions or concerns regarding this statement, you should first contact IT First Responder using the online form or call us on 1300 281 548.

This Privacy Policy protects your privacy by informing you about:

  • The types of personal information IT First Responder collects about you through its websites
  • How it collects that information
  • The general purposes for which it collects such information

2. IT FIRST RESPONDER ASSURES YOU THAT

It takes reasonable precautions to protect personal information from loss, misuse, unauthorised access, disclosure, alteration or destruction. Implements reasonable policies and procedures to ensure that personal information is kept only for the purposes for which it has been gathered; Uses reasonable measures to ensure that we have accurately and completely recorded the personal information you have provided, and Provides you reasonable access to your personal information as well as procedures for correcting or modifying that information where appropriate. Ensuring accountability to individuals who believe that IT First Responder has not complied with these privacy principles.

3. GETTING TO KNOW OUR CUSTOMERS

IT First Responder is in the business of supplying goods and services to our customers. That requires more than simply offering innovative technical services. It also requires that we understand you, our valued customer, and your needs.

We get to know you primarily through the information you provide to us when you contact us to use one or more of our services. The information you provide ranges from basic contact information to payment information. All of the information we request from you when purchasing our goods and/or services is obligatory. When you purchase our goods and/or services, you agree to provide us with complete and current information.

After you have purchased any of our goods and/or services, we may communicate with you about your account, answer questions you may have about what we provided you, or any other relevant matter. Those communications are essential to our relationship with you and to our ability to provide you with quality service that is responsive to your needs. At the same time, those communications give us helpful insights about you, your preferences, and the ways in which we might improve our services. We therefore may maintain this information for future use by IT First Responder.

The information we receive from or about you is stored on systems designed to prevent the loss, misuse, unauthorised access, disclosure, alteration, or destruction of that information. We also encrypt your transmission of sensitive information to us (e.g., credit card numbers, account passwords) in the interest of heightened privacy protection and information integrity.

4. THIRD PARTY ADVERTISING AND COOKIES

We use links to some of our vendors on our website. In the course of providing these links, some of these companies may place or recognise a unique ‘cookie’ on your browser and may use information (not including your name, address, e-mail address, or telephone number) about your visits to their and other web sites in order to measure advertising effectiveness and to provide advertisements about goods and services of interest to you. Please also examine the Privacy Policies of these companies.

5. INFORMATION CORRECTION OR CHANGES

You have the ability to correct or change certain information in our records, such as your address and contact information. The process for changing your information begins on the Your Account page. You may change this information at any time and as often as necessary. If you need assistance or have questions about correcting information, you can contact us by using our online form or by calling us on 1300 281 548.

6. HOW WE PUT INFORMATION TO GOOD USE

We use any information about you for purposes of monitoring and improving our internal operations, as well as to ensure we bill you properly, administer your account in accordance with good and proper accounting practices, and properly supply the goods and/or services you have requested.

We also use the information we collect to monitor and improve our internal operations For example; we may correlate Web site traffic information with data about individual users. This data helps us to determine how much our customers use parts of the site, allowing us to enhance it to fit the needs of as many of our customers as possible. We may also break down overall usage statistics according to customers’ domain names, browser types, and MIME types by reading this information from the browser string (information contained in every user’s browser).

Another example of our use of information to enhance the experience of users in our network of sites is our reliance on cookie files. We use cookie files to make it easier for users to access our site or services. A cookie file is a small data file that certain Web sites write to your hard drive when you visit them. A cookie file can contain information such as a user ID that the site uses to track the pages you have visited. However, the only personal information a cookie can contain is information you supply yourself. A cookie cannot read data off your hard disk or read cookie files created by other sites. We use cookies to track user traffic patterns (as described above) when you register for IT First Responder services. When you register, we may use a cookie to store a unique, random user ID. We use this ID to identify you anonymously in our database and to track the pages you visit on our site. If you have set your browser to warn you before accepting cookies, you will receive the warning message with each cookie. You may refuse cookies by turning them off in your browser.

Finally, we use the information we collect to direct important notices and information affecting your account or services, as well as to provide general information that may be of interest to you, including newsletters, surveys, and information about our services or product offerings. You may opt-out of receiving information from us simply by notifying us of your desire in accordance with the opt-out instructions contained in any information message you receive from us. Note, however, that in order to fulfil our service obligations to you, we must continue sending you notices and other important information affecting your account or services.

7. WITH WHOM WE MAY SHARE INFORMATION

We value you as our own customer and we do not share or disclose any information about you to any external company or organization. The information that you supply to us is used to conduct business transactions with you and to enable us to better meet your needs and requirements. Your information is not sold or given to any other organization.

When you supply us with a credit card number that is used to make a payment to us we securely transmit this to our bank where the credit card transaction is either accepted or declined by the bank. We do not store your credit card details on any of our sites or systems. The bank stores any necessary details about our transaction/s with you, we do store a payment authorisation reference number associated with your transaction/s. It is not possible for this reference number to be used for any other purpose other than recording the fact that we conducted a credit card transaction with you.

8. OUR ACCOUNTABILITY TO YOU

By purchasing our goods and/or services, you obtain the protections of, and consent to the data processing practices described in, this Privacy Policy. When you purchase our services, you also represent to us that you have provided notice to, and obtained consent from, any third-party individuals whose personal data you supply to us with regard to:

the purposes for which such third party’s personal data have been collected,
the intended recipients or categories of recipients of the third party’s personal data,
which of the third party’s data are obligatory and which data, if any, are voluntary, and
how the third party can access and, if necessary, rectify the data held about them.
In addition to the privacy protections that we provide, our employees, agents, and business partners are independently responsible for ensuring compliance with this Privacy Policy, as described below.

9. EMPLOYEE ACCOUNTABILITY

Only those IT First Responder employees that have a legitimate business purpose for accessing and handling information obtained by us are given the authorisation to do so. The unauthorised access or use of such information by an IT First Responder employee is prohibited and constitutes grounds for disciplinary and/or legal action.
Additionally, our information management systems are configured in such a way as to block or inhibit employees from accessing information that they have no authority to access.

10. SECURITY

This website takes every precaution to protect our users’ information. When users submit sensitive information via the website, their information is protected both online and offline. When our registration/order form asks users to enter sensitive information (such as credit card numbers), it is encrypted and protected with SSL encryption. While on a secure page, such as our order form, the lock icon on the bottom of Web browsers such as Google Chrome and Microsoft Internet Explorer becomes locked, as opposed to un-locked, or open, when you are just ‘surfing’.

While we use SSL encryption to protect sensitive information online, users’ information is restricted in our offices and is only accessible by certain authorised staff. Furthermore, ALL employees are kept up-to-date on our security and privacy practices. Every quarter, as well as any time new policies, are added, employees are notified and/or reminded about the importance we place on privacy, and what they can do to ensure our customers’ information is protected.

11. CHANGES TO THIS POLICY

We reserve the right to modify this privacy policy at any time, so please review it frequently. Changes and clarifications will take effect immediately upon their posting on the website. If we make material changes to this policy, we will notify you here that it has been updated, so that you are aware of what information we collect, how we use it, and under what circumstances, if any, we use and/or disclose it.

Pin It on Pinterest

Share This