{vintaris}Enterprise Security, Architected for Mid-Market
  • Services >
    Cyber Security AssessmentEssential Eight AssessmentCyber Security ConsultingEndpoint Protection (EDR)Identity Protection (ITP)Data Loss Prevention (DLP)Vulnerability ManagementPenTestingCyber Awareness TrainingComplianceDigital ForensicsIncident Response TrainingAI Agent SecurityAPI Security
  • Industries >
    Retail & LogisticsHealthcare ClinicsLight ManufacturingProfessional ServicesSmall Business
  • Team
  • Engagement >
    Engagement ModelOn-Site DeliveryCyber Insurance RequirementsCyber Insurance Risk Assessment Guide
  • Contact
  • Become a Partner
Free 2-Minute CheckLet's Talk Security
Free 2-Minute CheckLet's Talk Security
Services >
Cyber Security AssessmentEssential Eight AssessmentCyber Security ConsultingEndpoint Protection (EDR)Identity Protection (ITP)Data Loss Prevention (DLP)Vulnerability ManagementPenTestingCyber Awareness TrainingComplianceDigital ForensicsIncident Response TrainingAI Agent SecurityAPI Security
Industries >
Retail & LogisticsHealthcare ClinicsLight ManufacturingProfessional ServicesSmall Business
Engagement >
Engagement ModelOn-Site DeliveryCyber Insurance RequirementsCyber Insurance Risk Assessment Guide
TeamContactBecome a Partner
~/vintaris/privacy
Legal

Privacy Policy

Vintaris Solutions Pty Ltd (ABN 11 693 625 544) ("Vintaris", "we", "us", "our") is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Last Updated: 17 July 2026

Scope of this Policy: please read first

This Policy applies only to:

  • our website (vintaris.com), including enquiry and contact forms and the free self-assessment questionnaire("Health Check" preview); and
  • our self-service assessment portal (the "Self-Service Portal"), where you can create an account, complete a paid self-service questionnaire, and make payment.

This Policy does not apply to our main client portal. If you become a Vintaris client and are given access to the main client portal, that environment (where more detailed security information may be handled) is governed by a separate privacy policy which you will be asked to agree to at that time.

The Self-Service Portal is deliberately limited: it collects your account details, your questionnaire answers, and your payment. It does not collect logins or credentials to your systems, and it does not accept evidence or document uploads. Those only occur (if at all) within the main client portal under its separate policy.

By using the website or the Self-Service Portal, or providing us with your information, you consent to our handling of your personal information as described in this Policy.

1. What personal information we collect

Depending on how you use the website and Self-Service Portal, we may collect:

1.1 Contact and identity information, such as your name, work email address, business name, phone number, and role, provided via enquiry forms, the free questionnaire, or account creation.

1.2 Questionnaire answers, the answers you input into our free self-assessment and our paid self-service questionnaire, and general information about your business that you choose to provide in them. These answers are self-reported by you.

1.3 Account information, such as your login credentials for the Self-Service Portal (stored securely), your selected industry, and your account settings.

1.4 Payment information, where you purchase the self-service assessment, payment is processed by our third-party payment provider (Stripe). We do not collect or store your full card details ourselves.

1.5 Technical and usage information, such as your IP address, device and browser information, and how you interact with the website and Self-Service Portal, collected through cookies, analytics, and similar technologies (see clause 8).

1.6 We generally collect personal information directly from you. Where we collect it by automated means (such as analytics) or from a third party, we handle it in accordance with this Policy.

2. How we collect it

We collect personal information when you: submit an enquiry or contact form; complete the free self-assessment questionnaire; create a Self-Service Portal account; complete the paid self-service questionnaire; make a payment; or otherwise interact with the website or Self-Service Portal.

You are not obliged to provide personal information, but if you do not, we may be unable to provide some or all of these Services to you.

3. Why we collect, hold, and use it

We collect, hold, and use personal information to:

3.1 provide the free and paid self-service questionnaires and generate your results and any automated report;

3.2 create and manage your Self-Service Portal account and process your payment;

3.3 respond to your enquiries and provide support;

3.4 send you your results and communicate with you about your assessment, and, where you have not opted out, send you related security insights and information about our services (you may unsubscribe at any time);

3.5 improve, develop, and secure the website and Self-Service Portal, including through de-identified and aggregated analysis;

3.6 comply with our legal obligations and protect our legal rights.

3.7 We will only use your personal information for a purpose for which it was collected, a directly related purpose you would reasonably expect, or as otherwise permitted or required by law.

4. Direct marketing and communications

4.1 We may send you marketing communications about our services where permitted by law and consistent with the Spam Act 2003 (Cth). Every marketing message includes an unsubscribe option.

4.2 You can opt out of marketing at any time via the unsubscribe link or by contacting us, and we will action opt-outs promptly. We may still send you non-marketing service messages (such as your results, account, or transaction messages).

5. Sensitivity of questionnaire answers

5.1 We recognise that your questionnaire answers may indicate aspects of your business's security posture. We treat this information with care, restrict internal access to it, and use it only for the purposes described in this Policy.

5.2 The free and paid self-service questionnaires are self-reported and are not a verified audit. We do not, through these Services, collect credentials to your systems or evidence or document uploads. (See our Terms and Conditions for the self-assessment disclaimer.)

6. When we disclose personal information

6.1 We do not sell your personal information.

6.2 We may disclose personal information to:

  • (a) our service providers who help us operate the website and Self-Service Portal, such as hosting, our payment processor (Stripe), and email, CRM, and analytics providers, who are bound to protect it and use it only to provide services to us. Some of these providers may process data overseas (see clause 7);
  • (b) professional advisers (such as lawyers and accountants) where reasonably necessary;
  • (c) a purchaser or successor in the event of a sale or restructure of our business;
  • (d) government, regulatory, or law-enforcement bodies where required or authorised by law.

7. Data storage and location

7.1 Where your data is stored. We host our core infrastructure and store the personal information you provide to us through the website and Self-Service Portal primarily in Australia.

7.2 Overseas processing by trusted providers. Some third-party providers we use (for example, our payment processor Stripe, and certain email, CRM, or analytics tools) may store or process personal information outside Australia. Where this occurs, we take reasonable steps to ensure the recipient handles your personal information consistently with the Australian Privacy Principles, as required under APP 8. By providing your information, you acknowledge it may be processed overseas by such providers for these purposes.

7.3 We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, including access controls, encryption where appropriate, and secure authentication. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.

7.4 We retain personal information only for as long as necessary to fulfil the purposes described in this Policy, or as required by law, after which we take reasonable steps to destroy or de-identify it.

8. Cookies and analytics

8.1 We use cookies and similar technologies to operate the website and Self-Service Portal, remember your preferences, and understand usage. You can control cookies through your browser settings, though disabling some may affect how these Services work.

8.2 We use analytics and related technologies to understand and improve usage, and to help deliver and secure these Services, including tools provided by Google and Cloudflare. Where we use questionnaire or usage data for service-improvement studies, we anonymise it first.

9. Access, correction, and complaints

9.1 You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. Contact us using the details below; we will respond within a reasonable period and in accordance with the Privacy Act.

9.2 We may need to verify your identity before actioning a request. We do not charge for making a request, though a reasonable cost may apply to providing access in some cases, as permitted by law.

9.3 Complaints. If you believe we have breached the Australian Privacy Principles, please contact us first so we can investigate and respond. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

10. Third-party links and children

10.1 The website and Self-Service Portal may link to third-party websites or services. We are not responsible for their privacy practices, and we encourage you to review their policies.

10.2 These Services are intended for businesses and are not directed at individuals under 18. We do not knowingly collect personal information from children.

11. Changes to this Policy

We may update this Policy from time to time. The current version will be published at our website with the "last updated" date. Material changes will be notified where reasonably practicable. Your continued use after changes are published constitutes acceptance of the updated Policy.

12. How to contact us

For privacy questions, requests, or complaints:Vintaris Solutions Pty Ltd (ABN 11 693 625 544)
Address: PO BOX 353, Carina QLD 4152, Australia
Email: connect@vintaris.com

{vintaris}

Enterprise Security, Architected for Mid-Market.

Brisbane-based. Delivering Australia-wide, on site and remote.

Start here

  • Cyber Security Assessment
  • Essential Eight Assessment
  • Cyber Security Consulting
  • Cyber Insurance Risk Assessment

All Services

  • Endpoint Protection (EDR)
  • Identity Protection (ITP)
  • Data Loss Prevention (DLP)
  • Vulnerability Management
  • PenTesting
  • Cyber Awareness Training
  • Compliance
  • Digital Forensics
  • Incident Response Training
  • AI Agent Security
  • API Security

Industries

  • Retail & Logistics
  • Healthcare Clinics
  • Light Manufacturing
  • Professional Services
  • Small Business

Company

  • Our Team
  • Case Studies
  • Engagement
  • On-Site Delivery
  • Become a Partner
  • Contact

Legal

  • Privacy & Data Use
  • Terms of Use

Resources

  • PCI DSS Requirements Guide
  • Incident Response Plan Template
  • Tabletop Exercises Guide
  • Free Cyber Security Health Check
  • OT Security Guide
  • Insights

© 2026 vintaris. All rights reserved.