SouthCore (“we”, “us”, or “our”) is dedicated to safeguarding the privacy and security of personal information. This Privacy Policy sets out how we collect, hold, use, disclose, and manage personal data in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Scope and Jurisdiction
This policy applies to all personal information collected by SouthCore in connection with our website (https://southcore.au/), commercial consultations, technical assessments, and the provision of managed IT and cyber security services to Australian businesses.
SouthCore is an Australian-owned technology provider headquartered in Melbourne, Victoria. We conduct all operations in accordance with the laws of the State of Victoria and the Commonwealth of Australia.
2. What Personal Information We Collect
The types of personal information we may collect depend upon your interaction with us, and may include:
- Contact and Identity Information: Full name, corporate email address, business telephone number, business address, and company name.
- Commercial and Technical Context: Team size, infrastructure environment (such as Microsoft 365 tenant details, on-premise server architecture, current IT provider), operational requirements, and specific service interests.
- Technical and Analytical Data: IP address, browser type and version, device operating system, referring URL, time-stamp logs, and interaction data collected through functional and analytical cookies.
- Service Operations Data: Where clients engage us for managed IT and cyber security services, technical system telemetry, authentication logs, and support ticket correspondence necessary to deliver contracted services.
3. How We Collect Personal Information
We collect personal information through lawful and fair means, primarily directly from you:
- When you complete an online enquiry, consultation request, or assessment tool on our website.
- When you correspond with our team via email (e.g. sales@southcore.au or support@southcore.au) or telephone.
- When your organisation enters into a service agreement, onboarding process, or technical review with SouthCore.
- Automatically through standard server access logs and analytics when you navigate our website.
4. Purpose of Collection, Use, and Disclosure
We collect, hold, use, and disclose personal information for legitimate business purposes, including:
- Responding to commercial enquiries and scheduling technical consultations.
- Providing, monitoring, and supporting managed IT services, cyber security defenses, and cloud environments.
- Delivering requested reports, such as Essential Eight maturity assessments and cost calculations.
- Fulfilling legal and regulatory obligations, including under the Notifiable Data Breaches (NDB) scheme.
- Improving website performance, technical diagnostics, and service quality.
We do not sell, rent, or trade your personal information to any third parties for marketing purposes.
5. Data Storage, Security, and Sovereignty (APP 11)
As a cyber security and managed IT provider, SouthCore treats data security as paramount. In compliance with APP 11, we take all reasonable and robust technical and organisational measures to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure.
These safeguards include:
- Encryption: TLS 1.3 encryption for data in transit across all web properties and AES-256 encryption for data at rest.
- Access Controls: Strict role-based access controls (RBAC) and mandatory phishing-resistant Multi-Factor Authentication (MFA) across all staff accounts.
- Australian Data Residency: Where practicable, client data and corporate information are stored within sovereign Australian data centres (e.g. Microsoft Azure Australia East / Australia Southeast regions).
- Monitoring & Audit: Continuous security event monitoring, centralized audit logging, and regular privilege reviews.
6. Notifiable Data Breaches (NDB) Scheme
SouthCore is committed to complying with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. In the event of an eligible data breach involving personal information likely to result in serious harm, SouthCore will promptly assess the incident, take containment action, and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with statutory timelines.
7. Cross-Border Disclosures
In standard operations, SouthCore prioritises Australian data storage. However, some cloud infrastructure, software providers, and enterprise threat intelligence networks may utilise overseas data infrastructure. Where personal data is transferred internationally, SouthCore takes reasonable steps under APP 8 to ensure the recipient adheres to privacy standards comparable to the Australian Privacy Principles.
8. Access and Correction of Personal Information (APP 12 & 13)
Under the APPs, you have the right to request access to the personal information SouthCore holds about you and to request corrections if you believe the information is inaccurate, out-of-date, incomplete, irrelevant, or misleading.
To request access or correction, please email our Privacy Officer at privacy@southcore.au. We will respond to your request within 30 calendar days.
9. Cookies and Analytics
Our website uses essential and analytical cookies to ensure site functionality, enhance user experience, and measure aggregate visitor patterns. You may configure your browser settings to refuse cookies; however, certain interactive tools (such as assessments and calculators) may require functional cookies to operate properly.
10. Inquiries and Complaints
If you have any questions about this Privacy Policy or wish to lodge a complaint regarding our handling of your personal information, please contact us in writing:
SouthCore Privacy Officer
Email: privacy@southcore.au
General Enquiries: sales@southcore.au
Location: Melbourne, Victoria, Australia
We investigate all complaints promptly and provide a written response. If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Telephone: 1300 363 992