Privacy policy
This policy explains what personal information Silvatron Pty Ltd collects, why we collect it, who we share it with and how you can control it. It applies to visitors and enquirers in Australia, the European Economic Area, the United Kingdom and the United States.
Scope and who is responsible
Silvatron Pty Ltd is an Australian company based in Melbourne, Victoria. We are the controller of the personal information described here. Where the General Data Protection Regulation applies, Silvatron Pty Ltd is the data controller.
This policy covers silvatron.com, the enquiry forms on it, and the email and telephone contact that follows from them. It does not cover client systems we build or operate under a services agreement. In that work we act as a processor on the client's instructions, and the client's own privacy notice governs the handling of end user data.
We do not sell personal information. We do not share it for cross context behavioural advertising.
What we collect
Information you give us
When you submit the contact form, or email or call us, we collect what you choose to provide. In practice that is your name, work email address, company name, telephone number where you give one, and the content of your enquiry.
Please do not send us sensitive information, health information, government identifiers or production data through the website. If a proposal requires that material, we will agree a secure channel and a written basis for handling it first.
Information collected automatically
Our hosting provider records standard technical information for every request to the site. That includes the internet protocol address, the time of the request, the page requested, the referring page, and the browser and operating system reported by your device. These logs exist to keep the site available and to detect abuse.
The site does not require an account, and we do not build behavioural profiles of visitors.
Why we use it and our lawful basis
Under Australian law we collect personal information only where it is reasonably necessary for our business functions, consistent with Australian Privacy Principle 3. Where the General Data Protection Regulation applies, we rely on the bases set out below.
- Responding to your enquiry. To answer the question you asked and to scope the work you described. Lawful basis: steps taken at your request before entering a contract, and our legitimate interest in responding to business enquiries.
- Delivering engaged work. To administer a proposal, statement of work or services agreement. Lawful basis: performance of a contract.
- Keeping the site secure and available. To operate, monitor and protect the website. Lawful basis: our legitimate interest in the security and integrity of our systems.
- Meeting legal obligations. To keep tax, corporate and financial records. Lawful basis: compliance with a legal obligation.
- Occasional direct marketing. To send relevant material to business contacts. Lawful basis: consent where required, otherwise legitimate interest. Every message carries an unsubscribe option and we act on it.
Where we rely on legitimate interest, we have considered the effect on you and limited the handling accordingly. You may object to that handling at any time using the contact details below.
Cookies and analytics
This website sets no cookies of its own. It carries no advertising pixels, no social media trackers and no third party scripts. Nothing is written to your browser storage by visiting a page.
We review aggregate traffic using server side request logs held by our hosting provider. Those counts are not tied to a named individual and are not used for profiling.
If we later introduce measurement that requires consent, we will publish a cookie notice, request consent before any non essential cookie is set, and update this policy before that change takes effect.
Who we share it with
We disclose personal information only where it is necessary, and only to the following categories of recipient.
- Service providers. Our website host and form handler, our email and productivity provider, and the systems we use to manage proposals and accounts. Each is bound by contract to handle the information only on our instructions.
- Professional advisers. Our accountants, auditors and lawyers, where they need the information to advise us.
- Regulators and law enforcement. Where disclosure is required or authorised by Australian law, or by a valid order of a court or tribunal.
- A successor entity. If our business or part of it is transferred, the receiving entity would take on the information under the terms of this policy.
We do not disclose your enquiry to other clients, and we do not use your company name as a reference without written approval.
Storage and international transfer
Our primary records are held in Australia. Some of our service providers process data in the United States, the European Union and other jurisdictions, and our delivery team includes engineers in Sri Lanka who may access project correspondence in the course of engaged work.
Before disclosing personal information to an overseas recipient we take the steps required by Australian Privacy Principle 8 to satisfy ourselves that the recipient will handle it consistently with the Australian Privacy Principles. Where personal data leaves the European Economic Area or the United Kingdom, we rely on the European Commission standard contractual clauses, the United Kingdom international data transfer addendum, or an adequacy decision, as applicable.
You may ask us which providers hold your information and where. We will answer that question in writing.
How long we keep it
We keep personal information only as long as it serves the purpose it was collected for, or as long as the law requires. Our standard periods are below.
Enquiries that do not proceed
Twenty four months from the last contact, then deleted.
Enquiries that become engagements
Held for the life of the engagement and for seven years afterwards, to meet Australian tax and corporations record keeping obligations.
Contract and billing records
Seven years from the end of the financial year in which the record was created.
Server and request logs
Up to thirty days in our hosting provider systems, then rotated out.
Marketing subscriptions
Until you unsubscribe, then a suppression record only, so we do not contact you again.
When a period ends, the record is deleted or irreversibly de-identified.
Security
The site is served over HTTPS with transport security enforced. Access to enquiry records is restricted to the people who need it, protected by multi-factor authentication, and reviewed when someone changes role or leaves.
No transmission over the internet is completely secure. If a data breach occurs that is likely to result in serious harm, we assess it immediately, notify affected people, and make any notification required of us without delay.
Your rights
Everyone we hold information about may ask us for the following, whichever law applies to them.
- Access. A copy of the personal information we hold about you, and an explanation of how it is used.
- Correction. Correction of information that is inaccurate, out of date, incomplete or misleading.
- Erasure. Deletion of your information where we no longer need it, where you withdraw consent we relied on, or where you object and no overriding ground applies. Records we must keep for tax or corporate purposes are the exception.
- Objection and restriction. An objection to handling based on legitimate interest, or a restriction while a dispute about accuracy is resolved.
- Portability. Where the General Data Protection Regulation applies and handling is automated and based on consent or contract, a copy in a structured, commonly used, machine readable format.
- Withdrawal of consent. Withdrawal at any time, without affecting handling carried out before the withdrawal.
- Marketing opt out. Removal from any direct marketing, acted on promptly and permanently.
United States residents, including residents of California, may request the categories of personal information collected, the purposes of collection, the categories of recipient, and deletion of that information. We do not sell or share personal information as those terms are defined in United States state privacy law, so no opt out of sale is required.
To exercise any of these, email info@silvatron.com. We will confirm receipt and respond within thirty days. We may need to verify your identity before acting, and we will not charge a fee for a reasonable request.
Changes to this policy
We update this policy when our practice changes or the law requires it. The version and date appear at the top of the page. Where a change materially affects how we handle information already collected, we will tell affected contacts directly.
Complaints and contact
Raise any privacy question or complaint with us first. Write to our privacy contact with the detail of your concern. We will acknowledge within five business days and give you a written response within thirty days.
Privacy contact, Silvatron Pty Ltd
Office 4492, Ground Floor, 470 St Kilda Road, Melbourne VIC 3004, Australia
Questions about how we handle your information?
Ask our privacy contact directly. We answer in writing, and we will tell you exactly what we hold.