This policy explains how Techila Software PTY LTD handles personal information. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where a negotiated agreement with a client contains privacy obligations, that agreement prevails to the extent of any inconsistency.
We are an Australian proprietary limited company operating from Belmont, Western Australia, designing, building, integrating, migrating and maintaining software for Australian businesses, principally in the mid-market.
This policy covers three settings, and the distinction between them matters:
In the third setting we usually act on the client's instructions. The client decides what the system holds, who may access it and how long it is kept; we handle that information on documented instructions and do not use it for our own purposes. The client remains accountable to their own users, customers and staff for collection notices, consents, access requests and breach notifications concerning it. We assist them to meet those obligations, including by implementing technical measures and providing information reasonably needed to answer a request. Where we do determine the purpose ourselves, this policy applies directly.
Depending on the setting, we may hold: contact details submitted through this website, including name, company, position, work email, telephone number and enquiry content; information given during scoping and delivery about roles, working patterns and systems used; support records such as incident descriptions, account identifiers, log extracts and screenshots; billing records including accounts payable contacts, purchase order references and payment status; and technical information about visitors to this website, described in section 10.
We do not operate a recruitment channel and do not solicit resumes; unsolicited employment material is deleted without assessment. We do not intentionally collect sensitive information or information about children, and ask that such details not be included in website enquiries or support tickets.
Where practicable we collect it directly from the individual: through website forms, by telephone or email, in workshops, or through tickets raised in a support channel. We sometimes receive it indirectly, where a client supplies their staff contact details so we can grant access, where an integration delivers records at the client's direction, or where a professional adviser provides details in the course of a matter. Where information reaches us from a third party without the individual having dealt with us, we rely on the disclosing party having authority to provide it and take reasonable steps to notify the individual where required.
We use personal information to respond to enquiries, prepare and discuss quotes, deliver contracted work, provide support, invoice and collect payment, meet legal and tax obligations, maintain security and improve the operation of our systems. We do not sell personal information and do not use client or end-user data to develop products or train models. Where we wish to use information for an unrelated purpose, we seek consent or rely on a permitted exception under the Australian Privacy Principles.
We disclose personal information only where reasonably necessary, and only to: cloud hosting and infrastructure providers, located in Australia wherever a suitable local region exists; service providers engaged for monitoring, error reporting, email delivery and payment processing, under written terms requiring them to protect it; professional advisers, auditors and insurers in connection with a claim; and law enforcement, regulators or courts where disclosure is required or authorised by law, or necessary to prevent a serious threat to life, health or safety. Where we engage a provider to deliver services to a client, we notify the client and remain accountable for that provider's handling.
Our preference is Australian data residency. We choose Australian hosting regions where the required service is available locally and record each environment's location in the documentation handed to the client.
Some providers operate support or backup functions offshore, and a few services have no Australian region. Before disclosing personal information to an overseas recipient we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles, ordinarily by contractual commitment and by considering the laws of the destination. We also tell clients which parts of a solution involve an overseas recipient, so the decision is made by them as the accountable entity.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include multi-factor authentication on administrative accounts, least-privilege access reviewed when roles change, full-disk encryption on company devices, encryption of data in transit and at rest, centralised logging, patching of production dependencies and tested backup and restore procedures. Production credentials are held in a managed secret store rather than source code, and access to client environments is granted per person and revoked at the end of an engagement.
We apply similar practices in the software we build, including role-based access and audit logging where an engagement calls for it. No system is immune to compromise, so we plan on the assumption that controls occasionally fail and keep recovery procedures current.
We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires:
When information is no longer required and retention is not required by law, we take reasonable steps to destroy it or render it unidentifiable: deletion from production systems, secure erasure of devices before disposal, and rotation of credentials tied to the engagement. Where information sits in a client-operated system, we ask the client to authorise or perform the deletion.
You may request access to the personal information we hold about you, or ask us to correct it. Write to us using the contact details below, describing what you are looking for in enough detail that we can locate it. We acknowledge within two Business Days and respond substantively within thirty days.
Access is provided unless an exception applies, for example where it would unreasonably affect another person's privacy, prejudice an investigation, or where legal professional privilege attaches to the material. If we refuse, we explain why in writing and how to complain. There is no charge for a request or a correction; if substantial work is involved we agree any cost with you first. Where your information sits in a system operated for a client, direct the request to that client, who controls the data — we will help them answer it and will not respond directly without their instruction.
This website uses a small number of cookies. Essential cookies support basic functions such as form submission and remembering preferences; they do not track you across other sites. Analytics cookies, where used, record aggregated information such as pages viewed, approximate location derived from IP address, device type and referring site, which tells us which pages are useful and which are not read at all. You can refuse or delete cookies in your browser settings. Doing so may affect how some pages behave but will not prevent you contacting us by telephone or email. Any overseas processing involved in analytics is handled in accordance with section 6.
We send marketing only where you have asked for it or where a relationship exists and the law permits. Each message carries an unsubscribe link, and you may also ask us to stop by replying or writing to us. Opting out of marketing does not affect service, support or billing messages, which relate to an engagement.
If we suspect an eligible data breach — where personal information is lost or subject to unauthorised access or disclosure and serious harm is likely — we act under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth). We contain the incident, investigate what occurred and what information is affected, and assess whether serious harm is likely. Where the threshold is met, we notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, describing what happened, the kinds of information involved and the steps people should take.
Where a suspected breach occurs in a client-operated system, we notify the client without delay and without waiting for our own assessment to conclude, so that they can meet their own obligations. Contractual notification timeframes are set out in the relevant support or hosting agreement.
We review this policy at least annually and update it when our practices, systems or obligations change. The version and effective date appear at the top of this page. Material changes will be published here and, where appropriate, notified directly to affected clients.
Questions about this policy, requests to access or correct information, and complaints about our handling of personal information should come to us first. Please describe what happened, when, and the outcome you seek. We acknowledge complaints within two Business Days and aim to resolve them within thirty days.
If you are not satisfied with our response, or we do not respond within a reasonable period, you may escalate the matter to the Office of the Australian Information Commissioner. Giving us the chance to put it right first usually resolves matters faster, and we treat a complaint as information we would rather have.
Techila Software PTY LTD
1a/25 Belgravia Street, Belmont WA 6104
Telephone: 08 6193 7005
Email: info@techilasoftware.com.au
Complaints may be raised with us using the contact details above. Where a privacy complaint remains unresolved, you may refer it to the Office of the Australian Information Commissioner.