Privacy Policy

HSM IT Solutions Pty Ltd
ABN 70 615 441 757
Last updated: 16 September 2026

This policy explains how HSM IT Solutions collects, holds, uses, discloses and protects personal information in connection with our business, website and technology services.

1. About this Privacy Policy

HSM IT Solutions Pty Ltd (“HSM IT Solutions”, “HSM IT”, “we”, “us” or “our”) is committed to protecting the privacy and security of personal information.

This Privacy Policy explains how we collect, hold, use, disclose and protect personal information in connection with our business, website and technology services.

Where applicable, we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy applies to personal information collected through:

  • our website at www.hsmit.com.au;
  • our managed IT and support services;
  • cybersecurity and monitoring services;
  • Microsoft 365, cloud and infrastructure services;
  • backup and disaster recovery services;
  • telecommunications and communication services;
  • project and consulting services;
  • support tickets and remote support sessions;
  • telephone, email and other communications with us;
  • our dealings with customers, prospective customers, suppliers, contractors and other business contacts; and
  • recruitment, employment applications and engagement with prospective personnel.

2. The personal information we collect

The types of personal information we collect depend on how you interact with us and the services we provide. This may include:

  • your name;
  • business or organisation name;
  • job title or position;
  • business and personal email addresses;
  • telephone and mobile numbers;
  • business addresses;
  • account and billing information;
  • information contained in correspondence, support requests and enquiries;
  • usernames and account identifiers;
  • device names and identifiers;
  • IP addresses;
  • system, network and application information;
  • authentication and security information;
  • audit and activity logs;
  • information relating to IT incidents or cybersecurity events;
  • information required to provide technical support;
  • information you provide through website forms;
  • records of communications with us; and
  • other information reasonably necessary to provide our services.

When providing managed IT services to our clients, our systems or personnel may also have access to personal information stored within a client’s IT environment. Depending on the client and services involved, this may include employee, customer, supplier or other third-party information.

We only access such information where reasonably necessary to provide our services or where authorised by our client.

Sensitive information

In the normal course of business, HSM IT Solutions does not seek to collect sensitive information unless it is reasonably necessary for our functions or activities.

However, when providing IT services to clients, we may incidentally access systems containing sensitive information such as health, financial, employment or other confidential information.

Where we handle sensitive information, we take appropriate measures to protect that information and only access, use or disclose it where authorised or permitted by law.

Recruitment information

If you apply for a role with HSM IT Solutions, we may collect information reasonably necessary to assess and manage your application, including:

  • your resume or curriculum vitae;
  • employment and education history;
  • professional qualifications and certifications;
  • references and referee details;
  • information relevant to your suitability for the role; and
  • identity, work-rights or background information where reasonably required and permitted by law.

We use recruitment information for recruitment, workforce planning and related employment or contractor administration purposes.

3. How we collect personal information

We may collect personal information:

  • directly from you;
  • through our website;
  • when you submit an enquiry or request a consultation;
  • when you contact our service desk;
  • when you email or telephone us;
  • during meetings or consultations;
  • through support tickets;
  • during remote or onsite technical support;
  • through monitoring and management systems used to provide IT services;
  • from your employer or organisation;
  • from an authorised representative;
  • from our suppliers and service providers;
  • through publicly available sources; and
  • where otherwise permitted by law.

Where practical, we collect personal information directly from the individual concerned.

Where appropriate, we may provide a collection notice at or before the time we collect personal information, or as soon as practicable afterwards. A collection notice may explain the particular purpose of collection, likely disclosures, overseas handling and other matters relevant to that collection.

Unsolicited personal information

We may occasionally receive personal information that we did not request, for example through an email, support ticket, file attachment or information supplied by a client or third party.

Where required, we will assess whether we could have collected the information under the Australian Privacy Principles. If not, and if we are not otherwise required or authorised to retain it, we will take reasonable steps to destroy or de-identify it.

4. Information collected through our website

When you visit our website, we may automatically collect certain technical information, including:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • pages visited;
  • referring website;
  • approximate geographic location;
  • date and time of access; and
  • website usage and interaction information.

We may use cookies, analytics tools and similar technologies to operate our website, understand how visitors use it, improve website performance and measure the effectiveness of our marketing. Depending on our website configuration, these technologies may include essential or session cookies, analytics, conversion measurement, advertising or remarketing technologies and similar services provided by third parties.

These technologies may collect or derive information such as device and browser identifiers, IP address, pages viewed, interactions with website content, referring sources and advertising or campaign information. The specific technologies and providers we use may change over time.

You can control or disable cookies through your browser settings. Disabling some cookies may affect the functionality of the website.

5. Why we collect and use personal information

We may collect, hold and use personal information for purposes including:

  • providing managed IT services and technical support;
  • responding to enquiries;
  • providing quotations and proposals;
  • establishing and managing client accounts;
  • managing Microsoft 365, cloud and technology environments;
  • providing cybersecurity services;
  • monitoring and maintaining client IT systems;
  • investigating and responding to cybersecurity incidents;
  • managing backups and disaster recovery services;
  • providing telecommunications services;
  • performing IT projects and migrations;
  • processing payments and invoices;
  • communicating with clients and users;
  • maintaining business records;
  • managing suppliers and contractors;
  • improving our products and services;
  • maintaining and improving our website;
  • security, fraud prevention and risk management;
  • complying with contractual obligations;
  • complying with legal and regulatory requirements; and
  • other purposes reasonably related to the operation of our business.

If you do not provide information

If you do not provide personal information that we reasonably require, we may be unable to respond to an enquiry, verify your authority, provide technical support, establish or administer an account, deliver some or all of our services, process a transaction or assess an application.

6. Managed IT and access to client information

As a managed service provider, HSM IT Solutions may administer, monitor, support or access technology systems owned or controlled by our clients. Depending on the services provided, these systems may include:

  • Microsoft 365;
  • email systems;
  • SharePoint and OneDrive;
  • servers;
  • computers and mobile devices;
  • cloud infrastructure;
  • networking equipment;
  • backup platforms;
  • cybersecurity platforms;
  • telephone systems;
  • identity and authentication platforms; and
  • business applications.

Our access to information within client systems is for the purpose of delivering contracted services, maintaining security, troubleshooting issues and carrying out authorised work.

Where HSM IT Solutions handles personal information on behalf of a client, the client may remain responsible for determining how that information is collected and used.

We require our personnel to handle client information confidentially and in accordance with our security policies and applicable contractual requirements.

7. Disclosure of personal information

We do not sell personal information.

We may disclose personal information where reasonably necessary to operate our business or provide our services, including to:

  • technology vendors;
  • cloud service providers;
  • Microsoft and other software providers;
  • cybersecurity providers;
  • backup and disaster recovery providers;
  • telecommunications providers;
  • hosting providers;
  • IT distributors and licensing providers;
  • payment and financial service providers;
  • professional advisers, including accountants and lawyers;
  • contractors and service partners assisting us in providing services;
  • insurers;
  • government agencies, regulators, courts or law enforcement where required or authorised by law;
  • a prospective or actual purchaser, investor, adviser or other party involved in a merger, acquisition, financing, sale, restructure or transfer of all or part of our business or assets, subject to appropriate confidentiality and privacy protections; and
  • another party where you have authorised us to disclose the information.

We take reasonable steps to ensure third parties handling personal information on our behalf provide appropriate protections for that information.

8. Overseas disclosure and processing

HSM IT Solutions uses technology and cloud-based service providers whose infrastructure, support personnel or data processing operations may be located outside Australia. As a result, personal information may be stored, accessed or processed in countries outside Australia.

Depending on the service involved, overseas locations may include New Zealand, the United Kingdom, the United States, countries within the European Economic Area, Singapore, and other locations in which our technology providers or their authorised subprocessors operate.

The exact location may vary depending on the service, client configuration and service provider.

Where required, we take reasonable steps to ensure overseas handling of personal information is consistent with applicable Australian privacy requirements.

9. Security of personal information

Protecting information is a core part of our business. HSM IT Solutions uses administrative, physical and technical safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.

Depending on the nature of the system and information involved, our controls may include:

  • access controls;
  • multi-factor authentication;
  • identity and authentication controls;
  • endpoint security;
  • network security;
  • encryption;
  • security monitoring;
  • vulnerability and patch management;
  • backup and recovery controls;
  • logging and auditing;
  • security awareness measures;
  • restricted administrative access;
  • policies and procedures; and
  • incident response processes.

No technology environment can be guaranteed to be completely secure. We continually review our security measures based on risk, technology changes and our business requirements.

10. Data retention

We retain personal information only for as long as reasonably necessary for:

  • providing our services;
  • meeting contractual requirements;
  • maintaining appropriate business and support records;
  • resolving disputes;
  • security and audit purposes; and
  • satisfying legal, taxation, insurance or regulatory requirements.

Retention periods vary depending on the type of information and the reason it is held.

Where personal information is no longer required and we are not legally required to retain it, we take reasonable steps to securely delete, destroy or de-identify it.

Backup copies may remain within protected backup systems until they are removed through the normal backup retention lifecycle.

11. Direct marketing

Where permitted by law, we may use contact information to provide information about HSM IT Solutions services, cybersecurity information, technology updates, events, offers, newsletters and other information we believe may be relevant to your organisation.

You may unsubscribe from marketing communications at any time by using the unsubscribe option contained in the communication or by contacting us.

We will not require you to continue receiving marketing communications as a condition of receiving our IT services unless those communications are necessary for delivery of the service.

Service notifications, security alerts, billing communications and other operational messages are not considered marketing communications.

12. Accessing your personal information

You may request access to personal information we hold about you. Requests can be made using the contact information at the end of this Privacy Policy.

We may need to verify your identity before providing access.

In some circumstances, applicable law may permit or require us to refuse access to particular information. If we refuse a request, we will provide an explanation where required by law.

13. Correcting your personal information

We take reasonable steps to ensure personal information we hold is accurate, complete and up to date.

If you believe information we hold about you is incorrect, incomplete or out of date, please contact us and request that it be corrected.

We may take reasonable steps to verify the information before making the correction.

14. Data breaches

HSM IT Solutions maintains processes for identifying, assessing and responding to suspected or confirmed data breaches.

If a data breach involving personal information is likely to result in serious harm and notification is required under applicable law, we will take appropriate action, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

We may also notify affected clients, regulators, insurers, law enforcement or other parties where appropriate or legally required.

15. Third-party websites and services

Our website may contain links to websites, platforms or services operated by third parties.

HSM IT Solutions is not responsible for the privacy practices or content of third-party websites.

We recommend reviewing the privacy policy of a third-party service before providing personal information to it.

16. Anonymity and pseudonyms

Where practical and lawful, you may interact with us anonymously or using a pseudonym.

However, because of the nature of our IT services, there are many situations where we need to know your identity in order to provide technical support, verify authority, protect client systems, maintain security, establish an account, provide services, or meet legal or contractual requirements.

17. Artificial intelligence and automated technologies

HSM IT Solutions may use artificial intelligence (AI), machine learning and other automated technologies to assist in delivering, securing, managing and improving our services.

These technologies may be used for purposes including:

  • assisting with technical support and troubleshooting;
  • analysing system, security and operational information;
  • cybersecurity monitoring, threat detection and incident analysis;
  • generating or summarising technical documentation;
  • assisting with service desk and ticket management;
  • meeting transcription, summarisation and note-taking;
  • preparing reports, recommendations and communications;
  • workflow automation and data analysis; and
  • improving the efficiency and quality of our services.

Where personal, confidential or client information is processed using an AI-enabled service, we take reasonable steps to ensure the service and its use are appropriate for the intended purpose and that suitable privacy, security, access and data-handling controls are applied.

We may use third-party AI and cloud service providers. Information processed by those providers may be stored, accessed or processed outside Australia in accordance with the overseas disclosure and processing section of this Privacy Policy.

We seek to minimise the personal and confidential information provided to AI-enabled services and only use such information where reasonably necessary for an authorised business or service purpose. HSM IT Solutions does not knowingly use personal information or confidential client information to train general-purpose AI models. Where AI-enabled services process client information, we take reasonable steps to use business or enterprise-grade services and to configure available controls so that client information is not used for general-purpose model training.

AI-generated outputs may be reviewed by HSM IT Solutions personnel where appropriate before being relied upon for material decisions or client-facing advice.

18. Automated decision-making

HSM IT Solutions may use automated systems for activities such as cybersecurity monitoring, threat detection, spam filtering, system monitoring, service management and workflow automation.

These systems may automatically identify, classify, prioritise, recommend or respond to technical, security or service events. Information used by these systems may include account identifiers, authentication information, device and network identifiers, IP addresses, security events, logs and system activity, depending on the service involved.

Where personal information is used in automated decision-making that could reasonably be expected to significantly affect an individual’s rights or interests, we will handle that information in accordance with applicable privacy requirements. Where required by law, this Privacy Policy will identify the kinds of personal information used and the kinds of automated decisions or related actions involved.

19. Privacy complaints

If you have a concern or complaint about how HSM IT Solutions has handled your personal information, please contact our Privacy Officer using the details below. Please provide enough information for us to understand and investigate your concern.

We will acknowledge and investigate privacy complaints and aim to respond within a reasonable period.

If you are not satisfied with our response, you may be entitled to contact the Office of the Australian Information Commissioner (OAIC). Information about privacy rights and the complaints process is available at www.oaic.gov.au.

20. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our services, information-handling practices, new technologies, service providers, or applicable laws and regulatory requirements.

The current version will be published on our website and will state the date it was last updated. We recommend reviewing this Privacy Policy periodically.

21. Contact us

Questions, requests or complaints relating to privacy can be directed to our Privacy Officer:

Organisation: HSM IT Solutions Pty Ltd
Privacy contact: Privacy Officer, HSM IT Solutions
ABN: 70 615 441 757
Address: Suite 3, Level 2, 1C Grand Avenue, Rosehill NSW 2142, Australia
Phone: 1300 755 788
Email: info@hsmit.com.au
Website: www.hsmit.com.au

Please include “Privacy Request” in the subject line when contacting us by email regarding a privacy matter.

To top