Privacy policy

How we handle personal information, and the rights you have over it. We keep this in plain language on purpose.

Last updated: 7 August 2026

Extranet Systems Pty Ltd (ABN as shown on our invoices), referred to here as "Extranet Systems", "we" or "us", respects your privacy. This policy explains what personal information we collect, why we collect it, who we share it with, how we protect it, and how you can access, correct or complain about it.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we operate outside Australia, we also comply with the applicable local law.

What we collect

We only collect personal information that we reasonably need to do our work. In practice that is:

Information you give us

  • Contact and enquiry details: your name, work email address, phone number, company and the content of your message when you complete a form, request an assessment report, register interest in a service, or ask us to call you back.
  • Assessment and calculator responses: the answers you provide in our free online tools, and the resulting score, so we can prepare the report you requested.
  • Chat conversations: if you use the chat assistant on our website and then ask to speak with a person, we keep the conversation transcript together with the contact details you provide, so the person who calls you back has context. We also include the list of pages you viewed on our site during that visit, so the person who calls you back knows what you were looking at. We ask for your agreement before we do this.
  • Recruitment information: if you apply to work with us, the information in your application and any information referees provide.
  • Client and supplier information: the business contact details of the people we work with at client and supplier organisations.

Information collected automatically

  • Website analytics: pages visited, approximate location, referring site, browser and device type. This is used in aggregate to understand what is useful on our site. The one exception is described under Chat conversations above: if you give us your details through the chat assistant, the pages you viewed in that visit are attached to your enquiry.
  • Technical logs: IP address, request time and page requested, kept for security monitoring and to diagnose faults.

Information we do not seek

We do not ask for sensitive information (such as health, racial or ethnic origin, political opinions or religious beliefs) through our website, and we ask that you do not send it to us. We do not knowingly collect information from children.

We do not sell personal information to anyone, and we do not use your information to train third-party AI models.

Why we collect it

  • To answer your enquiry and provide the report, assessment or information you asked for.
  • To deliver, support and improve the services our clients engage us for.
  • To contact you about the matter you raised, and where you have agreed, about related services that may be relevant to you.
  • To meet our legal, contractual, insurance and record-keeping obligations.
  • To protect our systems and our clients' systems from misuse and security threats.

If you do not provide the information we ask for, we may not be able to respond to your enquiry or deliver the service you requested.

Who we share it with

We disclose personal information only where it is necessary, and only to:

  • Our people: the Extranet Systems team members who need it to respond to you or deliver a service, including our teams in Australia, Bahrain and Egypt.
  • Service providers: the platforms we use to run our business, such as email, collaboration and communication tools, hosting and infrastructure providers, and analytics. These providers are bound to protect the information and use it only for the service they provide to us.
  • AI processing: where our website assistant answers a question, the question may be processed by an AI service provider. Depending on our configuration this may be a service hosted overseas, or a model running on our own infrastructure in Australia. See "Sending information overseas" below.
  • Professional advisers and authorities: our advisers, insurers and auditors, and law enforcement or regulators where we are required or authorised by law.
  • A purchaser: if our business or part of it is sold, transferred as part of that transaction, subject to equivalent privacy protection.

Sending information overseas

We operate offices in Australia, in Seef, Bahrain and in Cairo, Egypt, and our team members in those locations may access information in the course of delivering services.

Some of the service providers we use, including certain AI, email and cloud providers, store or process information outside Australia, including in the United States and the European Union. Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, including through contractual protections.

Where data sovereignty matters to you or your organisation, tell us. We routinely design solutions that keep data inside Australia, including running AI models on infrastructure we control, and we can apply the same approach to our own handling of your information.

How we protect it

We are ISO 27001 certified, and we apply the same security practices to our own information that we recommend to our clients:

  • Access to personal information is limited to the people who need it for their role.
  • Systems are protected with multi-factor authentication, encryption in transit, network controls and monitoring.
  • Backups are encrypted, and access to them is controlled.
  • Our staff are trained on privacy and security, and are bound by confidentiality obligations.
  • We review our controls regularly, including through independent testing.

No system can be guaranteed completely secure. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

How long we keep it

We keep personal information only for as long as we need it for the purpose we collected it, or for as long as the law requires.

  • Website enquiries, assessment responses and chat transcripts: retained for up to 24 months from your last contact with us, then deleted automatically.
  • Client records: retained for the life of the engagement and then for the period required by our contractual, tax and professional obligations.
  • Recruitment information: retained for up to 12 months unless you ask us to keep it on file for future roles.

When information is no longer needed, we destroy it or de-identify it.

Cookies and analytics

Our website uses cookies and similar technologies to keep the site working properly, remember your preferences and understand how the site is used. You can block or delete cookies in your browser settings; some parts of the site may not work as well if you do.

We may use analytics and advertising technologies provided by third parties. These providers set their own cookies and handle information under their own privacy policies.

The chat assistant stores a small amount of information in your own browser so a conversation survives moving between pages. Nothing here is sent to us unless you choose to give us your contact details:

  • For the current tab only (cleared when you close it): the open conversation and whether the chat panel was open.
  • Kept until you clear your browsing data: the list of pages you have viewed on our site, whether you have used the chat before, and whether we have already offered you help today so that we do not repeat it.

Clearing your site data in your browser removes all of it.

Marketing and how to opt out

Where you have agreed, or where it is permitted under the Spam Act 2003 (Cth), we may send you information about our services. Every marketing message includes an unsubscribe link, and you can opt out at any time by using that link or by emailing us. Opting out of marketing does not stop us contacting you about a service you have engaged us for.

Your rights: access, correction and deletion

You may ask us to:

  • Access the personal information we hold about you.
  • Correct it if it is inaccurate, out of date, incomplete or misleading.
  • Delete it, where we are not required to keep it.

Email contact@extranetsystems.com.au with the subject "Privacy request". We will verify your identity and respond within 30 days. There is no charge to make a request. If we refuse access or correction, we will explain why in writing and tell you how to complain.

Complaints

If you believe we have mishandled your personal information, please contact our Privacy Officer at contact@extranetsystems.com.au or call 1300 290 196. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Contact us

Privacy Officer, Extranet Systems Pty Ltd

Email: contact@extranetsystems.com.au · Phone: 1300 290 196

Level 39, 264 George Street, Sydney NSW 2000, and 77 Market Street, Wollongong NSW 2500

Changes to this policy

We review this policy regularly and will publish any updated version on this page with a new "last updated" date. If a change materially affects how we handle your information, we will take reasonable steps to tell you.

See also: our other policies, including our modern slavery and compliance commitments.

Questions about how we handle data?

Data sovereignty, retention and security are things we design for every day. Ask us anything.

Contact us Call 1300 290 196
Social media & sharing icons powered by UltimatelySocial