Skip to content
digisys

Privacy Policy

Last updated 2026-07-21

Draft prepared for review by a qualified legal professional — not yet reviewed. Do not treat as legal advice.

About this policy

This policy explains how Digital Systems Aus Pty Ltd ("DigiSys", "we", "us") collects, holds, uses and discloses personal information through our website at digisys.com.au, our Customer Portal and our services.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where this policy and the law differ, the law wins — and if anything here is unclear, contact us and we'll explain it in plain terms.

What we collect

We collect personal information you give us directly, and a limited amount that is generated when you use our website and Customer Portal:

  • Contact form and enquiry details — your name, email address, phone number, business name and the message you send us.
  • Customer Portal account data — your name, business details, sign-in details and records of the services, licences and invoices associated with your account.
  • Billing information — records of invoices and payments. Card payments are processed by Stripe; we do not store your full card details on our systems.
  • Correspondence — emails and messages you exchange with our team.
  • Website usage data and cookies — analytics information is collected only after you consent through our cookie banner. See our Cookie Policy for detail.

Why we collect it

We collect personal information only for purposes connected to running our business and serving you:

  • Responding to your enquiries and providing quotes.
  • Delivering, managing and supporting the services you've engaged us for.
  • Operating your Customer Portal account, including invoicing and online payment.
  • Sending service communications, such as notices about your services, invoices or scheduled work.
  • Improving our website and services, using analytics collected with your consent.
  • Meeting our legal and record-keeping obligations.

How we hold and protect it

Our systems and the data they hold are hosted on Amazon Web Services (AWS) infrastructure in the Sydney region, so your information stays in Australia.

Security is our own line of business, and we apply the same discipline to ourselves that we sell: access to personal information is restricted to staff who need it, data is encrypted in transit, and our systems and practices are reviewed and tested on an ongoing basis.

No system is perfectly secure, and we can't promise otherwise — but if a data breach involving your personal information is likely to result in serious harm, we will notify you and the regulator as required by the Notifiable Data Breaches scheme.

Who we share it with

We do not sell personal information, and we don't share it with anyone for their marketing. We disclose personal information only to the service providers that keep our business running, and only what they need:

  • Amazon Web Services (AWS) — hosting of our systems and data in the Sydney region.
  • Stripe — processing of card payments made through the Customer Portal. Stripe handles your card details directly; some of Stripe's processing may occur overseas.
  • Xero — our accounting platform, used for invoicing and financial records.
  • Professional advisers, regulators or law enforcement — where the law requires or permits it.

Overseas disclosure

Our hosting is Australian, but some of our service providers (such as Stripe) are global companies whose processing may occur outside Australia. Where that happens, we take reasonable steps, consistent with APP 8, to ensure your information is handled in line with the Australian Privacy Principles.

Cookies and analytics

Our website uses a small number of essential cookies to function, and analytics cookies only if you consent through the cookie banner shown on your first visit. You can change your choice at any time.

The full detail — what each type of cookie does and how to change your settings — is in our Cookie Policy.

Access and correction

You can ask us at any time what personal information we hold about you, ask for a copy, or ask us to correct anything that's inaccurate or out of date. Much of your information is already visible to you in the Customer Portal.

To make a request, email admin@digisys.com.au. We'll respond within a reasonable time, and if we ever have to refuse a request (for example, where the law requires us to keep a record), we'll explain why.

How long we keep it

We keep personal information for as long as we need it for the purposes above — typically while you're a customer and for the record-keeping periods Australian law requires afterwards (for example, financial records). When we no longer need it, we delete or de-identify it.

Complaints and contact

If you think we've mishandled your personal information, contact us first at admin@digisys.com.au — we take complaints seriously and will investigate and respond to you promptly.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

We may update this policy from time to time; the current version will always be published on this page with its last-updated date.