Privacy Policy
How RiseSI handles personal information on this website.
This notice explains the personal data RiseSI Technologies Pty Ltd may process when you visit risesi.com.au, send an enquiry or communicate with us before a separate client agreement applies.
Effective 16 September 2026 · English-language notice
1. Who we are and the law considered
RISESI TECHNOLOGIES PTY LTD (ABN 89 690 837 480; ACN 690 837 480) is an Australian company. In this policy, “RiseSI”, “we”, “us” and “our” refer to that company. Personal information means information or an opinion about an identified person, or a person who is reasonably identifiable.
This policy describes our handling practices. The Privacy Act 1988 (Cth), Australian Privacy Principles and Notifiable Data Breaches scheme apply where RiseSI or the relevant activity is covered. Coverage can depend on turnover, the activity and statutory exceptions; we do not assume that every small business is exempt. Applicable state or territory laws and agreed client obligations also apply where relevant.
2. Personal data we may collect
Depending on how you interact with us, we may collect:
- business contact details, including name, role, employer, email address and telephone number;
- enquiry and correspondence content, including the company, business problem or frustration, current operation or project, help required, users and intended outcome, together with any documents subsequently provided for the agreed review;
- commercial and administration records, such as proposals, instructions, invoices, payments and communications;
- technical information made available when the website is requested, such as IP address, browser or device information, request time, requested page, security events and similar server or network records; and
- records of consent, preferences, requests and our response.
Please do not send attachments, sensitive personal data, credentials, production datasets or unnecessary personal information in an initial enquiry. Describe the requirement first. RiseSI will request any necessary documents through an appropriate transfer method and handling arrangement. If material arrives unsolicited, we will limit access and handle or remove it as appropriate to its sensitivity, purpose and legal requirements.
3. How data is obtained
We obtain data directly from you or your organisation, from correspondence and business administration, and automatically through the technical delivery and protection of the website. We may also receive business contact information from a colleague, adviser or publicly available professional source where the use is lawful and relevant.
4. Purposes of processing
We process personal data only for clear and relevant purposes, which may include:
- delivering, securing, maintaining and diagnosing the website;
- reviewing an enquiry, communicating with you and determining whether a RiseSI pathway appears suitable;
- preparing or administering a Capability Review, proposal, order or other requested pre-contract step;
- managing the commercial relationship, records, payments, agreed service reviews, data-export requests and professional communications;
- protecting RiseSI, clients and users from misuse, fraud, security incidents or legal claims;
- meeting accounting, tax, regulatory, legal and lawful authority requirements; and
- improving our service approach using appropriately limited or aggregated business information.
Where consent is required, it must be voluntary, informed, specific and capable of being demonstrated. You may withdraw consent, subject to applicable law, although withdrawal does not invalidate processing already lawfully completed. We collect information reasonably necessary for our business functions and use or disclose it for the stated purpose, related uses permitted by law, or another use you authorise. Sensitive information is collected only where necessary and with consent where required, or where a lawful exception applies.
5. Cookies, Cloudflare and embedded media
This website does not intentionally deploy first-party advertising cookies or behavioural analytics. Cloudflare supports DNS, delivery, availability and security and may process technical request information or use strictly necessary controls according to its services and policies.
Pages containing Oracle videos use YouTube’s privacy-enhanced embed domain. Loading or playing an embedded video can still cause Google or YouTube to receive technical information, including an IP address and browser data, and may result in storage or identifiers under their policies. You can avoid this processing by not visiting or interacting with pages containing embedded videos.
The contact-page email launcher opens your chosen email application. The message is sent through your email provider only when you choose to send it. Our business email provider and any configured routing provider handle message content and delivery information to deliver and protect correspondence. The website does not itself submit the email.
6. Sharing and processors
We do not sell personal data. We may disclose limited data to authorised personnel, professional advisers, payment or banking providers, email and productivity providers, Cloudflare, Oracle or other infrastructure providers, and public authorities where necessary for the stated purpose, the requested service, security, a legal obligation or a lawful request.
Providers handle information under their applicable terms and privacy policies. We use appropriate access and contractual controls for providers handling personal information on our behalf. No arrangement with a provider removes a legal responsibility that remains with RiseSI.
7. Overseas handling and client hosting
Cloudflare provides website delivery and security through a global network, and embedded videos are supplied by Google/YouTube. Those providers can handle technical information in the United States and other countries where they operate. Business email and authorised operational access can also involve overseas handling, including access from Vietnam where relevant to our work. Information is not represented as remaining exclusively in Australia.
Where Australian Privacy Principle 8 applies to an overseas disclosure, we take the required reasonable steps concerning the recipient’s handling of personal information, unless a lawful exception applies. Using this website is not consent to waive those protections. Relevant provider details appear in the Cloudflare Privacy Policy and Google Privacy Policy.
Client application hosting regions, approved providers, access locations and handling responsibilities are addressed separately in the proposal and service arrangements. Requirements to restrict data to Australia must be agreed and implemented for that deployment. Contact us for information about the locations relevant to your enquiry or engagement.
8. Retention
We retain data only for a period reasonably connected to the stated purpose and legal obligations. A preliminary enquiry that does not become an engagement is ordinarily retained for up to 24 months after the last meaningful communication, unless deletion is requested and permitted or a longer period is required for security, accounting, legal claims or another lawful reason. Contract, invoice and project records may be kept for the applicable agreement, statutory limitation, accounting and tax periods. Technical logs and backups follow the relevant security need and provider schedule.
Where a client ends a hosted platform service, access ends according to the agreed service period and closure arrangements. The client agreement specifies the data-export format, collection window, transition responsibilities and retention or deletion arrangements. Ending platform access does not itself mean all data is immediately deleted: necessary legal records and applicable backups remain subject to their lawful retention requirements. RiseSI will handle client-controlled data according to the agreed processing role and lawful instructions.
9. Access, correction and other requests
You can ask to access or correct personal information we hold about you. We consider requests under this policy and applicable law, verify identity or authority where reasonably necessary, and explain a refusal and available complaint options unless the law prevents us from doing so. We do not charge to make a request or to correct information; any permitted charge for providing access is explained in advance and must not be excessive.
You can also ask us to stop optional communications, withdraw consent where processing depends on it, or delete information no longer needed. These requests are considered alongside lawful retention obligations; Australian law does not provide an unrestricted right to erase every record.
Send requests to enquiries@risesi.com.au. If the information is controlled by a client, we will direct the request appropriately or assist under the agreed arrangement. Declining a sales enquiry or ending a service does not remove applicable privacy rights. Exercising those rights is separate from paid migration or additional development work.
10. Security and incidents
We use technical and organisational measures selected for the nature, context and risk of the processing. No internet or storage system is guaranteed to be completely secure. If an incident occurs, RiseSI will investigate, contain and assess it, cooperate with affected clients, and make notifications required by law and the applicable agreement. Where the Notifiable Data Breaches scheme applies, eligible breaches are notified to affected individuals and the Office of the Australian Information Commissioner as required.
11. Children
The website and services are directed to business users and are not intended for children. Do not provide a child’s data through an enquiry. If a project could process children’s data, the legal authority, consent, safeguards and best interests of the child must be separately assessed before processing.
12. External sites and changes
External links and embedded services are governed by their own notices. We may update this notice when the website, providers, practices or law changes. The effective date above identifies the current published version. Material changes will be presented appropriately on the website.
13. Contact and complaints
For a privacy question, request or complaint, email enquiries@risesi.com.au with “Privacy” in the subject line and describe the issue and outcome sought. We will investigate and aim to respond within 30 days, or explain why more time is needed. If the matter remains unresolved, you can contact the Office of the Australian Information Commissioner where it has jurisdiction, or another applicable regulator. This process does not restrict rights or deadlines provided by law.