Effective
ITNode provides managed IT support to dental practices, medical practices and businesses across Victoria. This policy explains how we handle personal information.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Because our clients include healthcare providers, we may handle health information on their behalf, which carries additional obligations. We treat that information accordingly.
What we collect
We collect only what we need to provide and support our services.
From enquiries and clients
- Name, business or practice name, email address and phone number
- The content of your enquiry or support request
- Billing and account details for clients
- Records of the support we have provided
From our website
- Information you enter into our contact form
- Standard technical data your browser sends, such as IP address, browser type and pages visited
- Analytics data about how the site is used, in aggregate
From client systems we support
Delivering IT support means our technicians may be able to access systems that contain personal information, including patient records held by our healthcare clients. We access that information only where it is necessary to deliver the service requested, and we do not use it for any other purpose.
Where we handle information on behalf of a client, that client remains the organisation responsible for it under the Privacy Act. We act on their instructions.
How we use it
- To respond to your enquiry
- To provide, maintain and support IT services
- To diagnose faults and restore systems
- To manage billing and our client relationship
- To meet our legal and record-keeping obligations
We do not sell personal information. We do not use client system data for marketing.
Who we share it with
We disclose personal information only where it is necessary, and only to:
- Service providers who help us operate — for example hosting, backup, security monitoring and accounting providers — under obligations of confidentiality
- A person or organisation you have authorised us to deal with
- Law enforcement or a regulator where we are required or permitted by law
Some of our providers may store data outside Australia. Where that occurs, we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles. If you would like to know where a specific service stores data, ask us and we will tell you.
How we protect it
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Those steps include:
- Multi-factor authentication on our accounts and remote access
- Individual named logins, with access limited to what each role requires
- Encryption of portable devices and of data in transit
- Logged and controlled remote access to client systems
- Continuous security monitoring of the systems we manage
- Regular patching, and backups that we test
- Staff training on privacy and security
No system can be guaranteed secure. If a data breach occurs that is likely to result in serious harm, we will act promptly to contain it, notify the affected client, and support them in meeting their obligations under the Notifiable Data Breaches scheme. Where the obligation is ours, we will notify the Office of the Australian Information Commissioner and affected individuals.
How long we keep it
We keep personal information only as long as we need it for the purpose it was collected, or as long as we are required to keep it by law. Business and financial records are generally kept for seven years. When information is no longer needed and we are not required to retain it, we destroy or de-identify it.
Data held within a client's own systems is retained according to that client's policies and their own legal obligations, not ours.
Cookies and analytics
Our website uses cookies to function correctly and to understand how the site is used. You can block or delete cookies in your browser settings, though some parts of the site may not work as intended if you do.
We use analytics to see which pages are useful and where visitors have difficulty. This is reported to us in aggregate.
Accessing and correcting your information
You may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is wrong. Contact us using the details below.
We will respond within a reasonable period. We do not charge for making a request. In limited circumstances we may need to refuse access — if we do, we will explain why in writing.
If your request relates to records held by a practice we support, that request should go to the practice. They are the organisation that holds those records.
Complaints
If you believe we have mishandled your personal information, contact us first. We will acknowledge your complaint and respond with an outcome.
If you are not satisfied with our response, you can raise it with the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
We may update this policy from time to time. The effective date at the top of this page shows when it was last changed. The current version is always available here.
Contact us
ITNode
Wheelers Hill, Victoria, Australia
Phone: 0451 055 008
Or use our contact form.
