Skip to content

Legal

Privacy Policy

What we collect, why we collect it, and what we do not do. Last updated 7 September 2026.

The short version

  • This site sets no cookies and runs no analytics, no advertising pixels, and no third-party trackers. We do not know who visits, and we are not trying to find out.
  • We only get your details if you type them in. The contact form is the only place this site asks you for personal information. Nothing else on it collects anything beyond the ordinary server logs any website produces.
  • We never sell or share your information for marketing, and we do not add you to a mailing list from an enquiry.

Who we are

Syprical (ABN 83 340 057 097) is a cyber security and IT consulting practice based in Newcastle, NSW. In this policy, "we", "us" and "our" mean Syprical, and "personal information" has the meaning given to it by the Privacy Act 1988 (Cth).

We handle personal information in accordance with the Australian Privacy Principles (APPs), whether or not the small business exemption in the Privacy Act applies to us. We would rather commit to the standard than argue about whether we have to meet it, particularly in this line of work.

What we collect

There are only two ways this site obtains information about you.

1. What you type into the contact form

The contact form at /contact collects:

  • First name (required) and last name (optional)
  • Email address (required), so we can reply
  • Phone number (required), so we can call you if that is quicker than typing
  • Your message, and anything you choose to put in it

Last name is optional on purpose. Not everybody has a family name, and we are not going to make somebody invent one to ask us a question.

Two things travel with the form that you do not type. The spam check described below receives a one-time token from your browser along with your IP address, and your IP address is also recorded against the enquiry itself, where it is used to limit how many submissions one source can make and to investigate abuse of the form. That is the only case where an IP address is joined to something you typed, and it is why the paragraph below distinguishes it from ordinary server logs.

Please do not put sensitive information into the message box. If you are contacting us about a live security incident, tell us that you have one and we will arrange a secure channel before you send us any detail.

2. Standard server logs

Our hosting provider, Cloudflare, records ordinary request information such as IP address, timestamp, requested URL, and browser user-agent. This is generated automatically by the act of serving a web page, is used for security and reliability, and is not used to build a profile of you. These logs are not joined to contact form submissions; the one place your IP address is attached to something you typed is the enquiry itself, described above.

Cookies, analytics and tracking

This site sets no cookies. It runs no analytics package, no advertising or conversion pixels, no session recording, no heatmaps, and no social media trackers. There is no consent banner on this site because there is nothing to consent to.

The single third-party script on the site is Cloudflare Turnstile, which loads only on the contact page. It is the anti-spam check that replaces the traditional "prove you are human" puzzle. It is designed to work without cookies and without tracking users across sites, and we use it solely to stop automated submissions.

Why we collect it, and what we do with it

We collect contact form information for one purpose: to respond to your enquiry and, if you decide to work with us, to provide the services you ask for.

When you submit the form, this is exactly what happens:

  1. Turnstile checks the submission is not automated. If that check cannot be completed, the form fails safe and refuses the submission rather than accepting it unchecked.
  2. Your enquiry is passed to our client portal, where it is held as unverified.
  3. We email you a confirmation link. Until you click it, nothing happens. Your enquiry is not actioned and nobody is notified.
  4. Once you confirm, we receive the enquiry and reply.

That confirmation step is a double opt-in. It exists so that nobody can use our form to send you mail you did not ask for, and so that an enquiry we act on is one a real person actually sent.

We do not use enquiry details for marketing, add you to a newsletter, sell or rent them to anybody, or use them to train any machine learning model.

Who else can see it

We keep the list of third parties deliberately short. Personal information you give us may be handled by:

  • Cloudflare, which hosts this website, our client portal, and delivers our email. Enquiry data is stored in a Cloudflare database.
  • Microsoft, as the operator of the mailbox that receives our email.
  • Twilio, only if you have asked us to send you SMS notifications as part of an engagement. This never applies to a website enquiry.

We may also disclose information where we are required to by law, or where it is necessary to investigate a security incident or protect our legal interests. We do not disclose personal information to anybody else.

Overseas disclosure

The providers above are global companies and may store or process data on servers outside Australia, including in the United States. By submitting an enquiry you consent to that handling. We select providers that offer contractual protections for personal information, but you should know that overseas storage means the information may be subject to foreign laws.

How long we keep it

  • Unconfirmed enquiries are removed once they have sat unverified long enough to be clearly abandoned. They are never actioned.
  • Enquiries that do not become clients are kept while there is a reasonable prospect of the conversation continuing, and then deleted on request or during routine cleanup.
  • Client records are kept for as long as we provide services to you, and afterwards for the period we are required to retain business and tax records under Australian law. In practice that means quotes, engagement letters and invoices are retained for at least five years from the end of the engagement.

How we protect it

We would be poor advertisements for our own services if we were careless with this, so specifically: the site and portal are served only over HTTPS with HSTS; the portal requires multi-factor authentication for staff access; access to client data follows least privilege; credentials are held in a password manager and never in code; and our infrastructure is change-controlled with automated drift detection.

No system is perfectly secure, and anyone who tells you otherwise is selling something. What we can commit to is that we treat our own environment as in-scope for the standards we advise clients to meet.

Accessing, correcting or deleting your information

You can ask us at any time to tell you what personal information we hold about you, correct anything that is wrong, or delete it. Email hello@syprical.com.au and we will respond within 30 days, usually much sooner.

There is no charge for this. We may ask you to verify your identity first, which is a protection for you rather than an obstacle: we are not going to hand your details to somebody who has simply learnt your email address.

If we cannot delete something, we will tell you why. The usual reason is a legal retention obligation on tax and business records.

Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved, and what you should do about it. We would rather over-notify than manage your expectations downwards.

Complaints

If you think we have mishandled your personal information, please tell us first at hello@syprical.com.au. We take complaints seriously and will investigate and respond in writing.

If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.

Reporting a security issue

If you have found a security vulnerability in this site or our portal, we want to hear about it. Our security contact is published at/.well-known/security.txt. We will not pursue anybody who reports a genuine issue to us in good faith.

Changes to this policy

If we change this policy we will update the date at the top of the page. Where a change is significant and affects information we already hold, we will contact affected clients directly rather than relying on you to notice a new date.

Contact us

Questions about privacy, or about this policy, go to hello@syprical.com.au, or by post to PO Box 1284, Newcastle NSW 2300.

Questions about how we handle your data?

Ask us directly. We will give you a straight answer, in writing, from a person.

Get in touch