everything information

Privacy policy

How we collect, use, store and protect personal information.

Last updated 24 September 2026
At a glance

We never sell your data

Personal information is used only to deliver our services and meet our obligations.

Stored in Australia

Our core business records are stored in Australia.

ISO/IEC 27001 certified

Protected by a certified information security management system.

Our commitment

Everything Information Pty Ltd (ACN 163 503 286, ABN 37 163 503 286) as trustee for the Everything Information Trust (ABN 42 595 121 669) ("EI", "we", "us", "our").

We are an Australian information governance and technology advisory firm. As a small business we may not be required to comply with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth), but we have chosen to handle personal information in accordance with them.

Our information security management system is certified to ISO/IEC 27001:2022, and our use of artificial intelligence is governed by an AI management system aligned with ISO/IEC 42001. This policy explains what personal information we collect, why, how we hold and protect it, who we share it with, and how you can access or correct it or make a complaint.

The personal information we collect

Depending on how you deal with us, we collect:

  • Contact and business details: your name, position, organisation, email address, telephone number, and business address, when you contact us, request information, or engage us, or when you are a client's representative.
  • Contract and signing records: when you sign an agreement with us electronically, your name, email address, and, where used, your mobile number, together with the signing record. The signing record includes the time and date of each action, your IP address, the authentication steps used, and your signature. If a document is witnessed, we also collect the witness's name, email address, IP address, and location.
  • Billing records: invoices, payment details, and correspondence about fees.
  • Website information: your IP address and information collected by cookies when you visit our website (see Cookies and our website), and any details you submit through our website.
  • Recruitment information: when you apply to work with us, your application, CV, and referee details.
  • Client engagement data: information about individuals that our clients give us, or that we access, while we deliver services (see Information we handle on a client's behalf).

We don't ask for sensitive information (for example health information or criminal records) unless it's needed for a particular engagement or role and you have agreed. Unsolicited sensitive information we receive is handled under the APPs, and destroyed or de-identified where that's lawful and reasonable.

You can deal with us anonymously or using a pseudonym where it's practicable, for example for a general enquiry. We can't provide services or enter into an agreement without identifying you.

How and why we use it

We collect personal information directly from you where we can, and otherwise from your organisation, publicly available sources, or referees you nominate. We use it to:

  • respond to enquiries and provide the services requested;
  • form, sign, administer, and keep records of our agreements;
  • invoice and receive payment;
  • manage our relationship with clients and their representatives;
  • assess job applications;
  • operate, secure, and improve our website and systems, including understanding how our website is used; and
  • meet our legal, regulatory, insurance, and professional obligations.

We don't sell personal information. We only send marketing where you have agreed or the law otherwise allows it, and you can opt out at any time.

Information we handle on a client's behalf

When we deliver services, we may handle personal information that belongs to our client's organisation, for example information about its staff or customers in the systems we review. In that case we act on our client's instructions under our agreement with that client, and the client's own privacy policy also applies.

When the engagement ends, we return or securely destroy that information in line with our agreement with the client. If you have a question about information we hold for one of our clients, we may refer you to that client.

Electronic signing

We sign agreements through an Australian electronic signature provider that hosts its data in Australia. The provider collects the signing details described in The personal information we collect, and creates a tamper-evident audit trail and certificate of completion that we keep as part of our records.

Some of the provider's own service providers (for email and SMS delivery, and document rendering) may process limited details, such as your name, email address, or mobile number, outside Australia while delivering messages or rendering documents (see Overseas disclosure).

Who we share it with

We share personal information only as needed for the purposes in How and why we use it, with:

  • service providers that host, store, or process information for us: cloud productivity and storage, customer relationship and records systems, our electronic signature provider, website analytics, and our accounting and payment providers;
  • our professional advisers, insurers, and auditors, including our ISO certification body;
  • anyone you have authorised, or who represents you; and
  • regulators, courts, or others where the law requires or authorises it.

We choose service providers that we assess as protecting information appropriately, as part of our information security management system. Our service providers handle personal information under their own terms and privacy policies, which may allow them to use de-identified or aggregated information to operate and improve their services.

Overseas disclosure

We store our core records in Australia, including in our Microsoft 365 and Microsoft Dataverse environments, which are hosted in Australia.

Some of our service providers, and some of the providers they use, such as those delivering email and SMS messages, rendering documents for electronic signing, or providing website analytics, may process limited personal information outside Australia.

Where personal information is processed outside Australia, we take reasonable steps to ensure it is handled consistently with the APPs.

How long we keep it

We keep personal information only for as long as we need it for the purposes described in this policy, or as the law requires. For example:

  • we keep client contact, contract and signing, and billing records for 7 years after our last transaction with the client, in line with record-keeping requirements;
  • we keep information we handle on a client's behalf, and destroy it, in line with our agreement with that client; and
  • we keep recruitment information for 12 months after the recruitment process closes, unless you agree to us keeping it longer.

We may keep information longer where the law requires it, or to preserve it for a legal proceeding, claim, or regulatory inquiry. When information is no longer needed, we securely destroy or de-identify it. Copies held in backups are kept secure and deleted in the ordinary course.

Cookies and our website

Our website uses cookies and similar technologies to operate, keep the site secure, and understand how visitors use it.

We use a third-party web analytics service to collect information about visits to our website, such as the pages viewed, time spent on the site, the website that referred you, your browser and device type, and your general location (for example your city or region, derived from your IP address). The service uses cookies to recognise returning visitors, and processes this information on our behalf to produce reports on how our website is used. We use these reports only to understand and improve our website. We don't use them to identify you, and we don't combine them with other information we hold about you.

You can refuse or delete cookies through your browser settings, or use browser tools and extensions that block analytics. Some parts of our website may not work properly if you disable cookies.

Automated decisions and our use of AI

We use artificial intelligence (AI) tools under an AI management system aligned with ISO/IEC 42001, which includes the following:

  • Human oversight: AI-assisted outputs and decisions in our operations remain subject to appropriate human oversight. We don't use computer programs to make decisions about individuals that could significantly affect their rights or interests.
  • Assessment: each AI system we use has an owner and is assessed before use for its potential impact on individuals, including privacy. Its permitted uses, and the kinds of information it may be used with, are recorded.
  • Data protection: our use of AI complies with data protection law and with our information security management system.
  • Transparency: we tell clients about our use of AI technologies where it is material to the services we provide.

How we protect it

We protect personal information through controls in our ISO/IEC 27001-certified information security management system. They include:

  • access limited to people who need it, with multi-factor authentication;
  • encryption;
  • supplier assurance;
  • logging and monitoring; and
  • staff security training.

Data breaches

If a data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme. Where we hold the information for a client, we notify that client, and assist them to notify.

Access and correction

You can ask for access to the personal information we hold about you, or ask us to correct it, by contacting us.

  • We usually respond within 7 days.
  • Where a correction needs investigation, we tell you the outcome within 30 days.
  • We don't charge for a request.
  • If we refuse access or correction, we tell you why and how to complain.

Complaints

To complain about how we have handled your personal information, contact our Privacy Officer.

We acknowledge complaints within 7 days and give you our decision within 30 days.

If you are not satisfied, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.

Contact us

Privacy Officer, Everything Information

Email: privacy@everythinginfo.cloud

Changes to this policy

We review this policy at least annually and when our practices change. We publish the current version at this page, with the date it was last updated.