Home  /  Privacy Policy

Legal

Privacy Policy

How BrokerReady handles personal information, written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Last updated 4 September 2026 Applies to brokerready.com.au and to the services we provide
About this policy

Two kinds of information, and it matters which is which.

BrokerReady provides managed IT, automation, cyber and compliance services, and website design and hosting. Most of our clients are insurance brokerages, underwriting agencies and authorised representative networks.
Ours to account for

Information we collect for our own purposes

Enquiries from this website, contact details for the people we deal with at client businesses, and records of the support we provide. It sits in our CRM so that we can deal with you, and it is never sold or traded. We decide what happens to this information and we are accountable for it.

Your client’s, not ours

Information we handle on behalf of a client

When we manage a brokerage’s Microsoft 365 tenancy, broking platform or website, we necessarily have access to information that belongs to that business — including, in some cases, information about their own customers. We do not own it and we do not use it for our own purposes. Section 6 covers this.

1

What personal information we collect

From people who contact us

  • Name, business name, email address, phone number
  • What prompted you to get in touch
  • Anything else you choose to tell us in a message or on a call

From the people we work with at client businesses

  • Name, role, work email address, work phone number
  • Records of support requests, and what we did about them
  • Device and account details needed to provide the service — for example which laptop is assigned to whom, and what systems someone has access to

From website visitors

  • Standard web server logs — IP address, browser and device type, and which pages were requested — kept for security and troubleshooting

We do not run analytics software on this website. We do not track you across other sites, and we do not build a profile of your visit.

We do not collect sensitive information as that term is defined in the Privacy Act — health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record — unless you volunteer it to us, and we have no reason to ask for it.
2

How we collect it

We collect personal information directly from you: when you fill in a form on our website, book a call, send an email, ring us, or raise a support request.

We also generate information in the course of providing the service — support ticket histories, device inventories, access records and the compliance evidence our clients ask us to keep.

If we collect information about you from someone else — for example, your employer tells us you are a new starter who needs an account set up — we handle it under this policy in the same way.

3

Why we collect it, and what we use it for

  • To respond to enquiries and provide quotes
  • To deliver the services a client has engaged us for
  • To manage accounts, licences and access on a client’s behalf
  • To produce the records and reports our clients rely on to meet their own obligations
  • To bill for the work
  • To improve how we run our own business
  • To meet our legal obligations
Your details sit in our CRM so that we can deal with you, and that is all it is for. We do not sell personal information, we do not rent or trade contact lists, and we do not disclose anything for someone else’s marketing. We do not build profiles of individuals and we do not use personal information to make automated decisions about anyone.

Our newsletter

We send a newsletter by email to [CONFIRM — who is on this list? Clients only, or anyone who has enquired or subscribed? The answer decides how you describe consent here]. Every one carries an unsubscribe link, and we act on it straight away. You can also ask us to take you off the list by emailing [email protected]. Unsubscribing does not affect the service you get from us.

4

Who we disclose it to

We disclose personal information to:

  • Our own service providers, where they need it to help us deliver the service. This includes the platforms we run our business on — our professional services automation system, our monitoring and management tools, our automation platform, Microsoft, and our hosting providers.
  • Your employer or the business that engaged us, where the information relates to that engagement.
  • Anyone you have asked us to deal with, such as a software vendor we are raising a ticket with on your behalf.
  • A regulator, court or law enforcement body, where we are required or authorised by law.

We do not disclose personal information to anyone else without your consent, unless the Privacy Act permits or requires it.

5

Overseas disclosure

Australian client websites we host are hosted on Amazon Web Services in the Sydney region (ap‑southeast‑2), Australia.

Some of the platforms we use to run our business may store or process data outside Australia. [TO CONFIRM AND LIST — check the hosting region for each of HaloPSA, Rewst, N‑central, Hudu and your own Microsoft 365 tenancy, then name the ones that sit offshore and the country each is in]

This is one of the most commonly checked sections in a due diligence questionnaire. A named list of platforms and countries is worth far more than a general statement, and it is the section a broker’s licensee is most likely to come back on.

We also support clients with offices outside Australia, including in the Philippines and the United Kingdom. Where we provide services to those offices, information about their staff may be accessed from Australia.

Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.

6

Information we handle on behalf of our clients

When we manage a client’s systems, we have access to information held in those systems. That may include information about the client’s own customers.

In that situation:

  • The client decides what that information is used for. We act on their instructions.
  • We access it only where it is necessary to deliver the service — for example, restoring a mailbox, investigating a fault, or migrating data between platforms.
  • We do not use it for our own purposes and we do not disclose it to anyone else.
  • We keep records of access, because our clients need those records to meet their own obligations.
If you are a customer of one of our clients and you want to know how your information is handled, the business you deal with is the right place to ask. They hold that information; we look after the systems it sits in. If they ask us to help them respond to you, we will.
7

How we store and protect it

We take the security of information seriously — it is most of what we do for a living.

  • Access to client systems is restricted to the people who need it, and access is reviewed on a schedule.
  • Multi-factor authentication is enforced on our own accounts and on the tools we use to manage client environments.
  • Access is removed when a person leaves, and the removal is recorded.
  • Backups are taken and restoration is tested.
  • Data is encrypted in transit and at rest.
  • Endpoint protection runs on every device we manage.
  • We assess our own environment, and the environments we manage, against the Essential Eight.

No system is perfectly secure, and we will not pretend otherwise. If a data breach occurs that is likely to result in serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

8

Cookies and our website

Our website uses cookies only to make the site work.

  • Essential cookies, needed for the site to function.
  • The Microsoft Bookings calendar embedded on our Contact page sets its own cookies. That booking form is Microsoft’s, not ours, and what it sets is governed by Microsoft’s privacy statement.

We do not use analytics or advertising cookies. Nothing on this site tracks you for marketing purposes.

You can block or delete cookies through your browser settings. Some parts of the site may not work properly if you do.

9

How long we keep it

We keep personal information for as long as we need it for the purpose we collected it, and for as long as we are required to keep it by law.

  • Client records — support history, billing records and the compliance evidence we produced for you: seven years after the agreement ends, which matches our record-keeping obligations.
  • Enquiries that did not become clients — two years, then the contact details are deleted.
  • Information inside a client’s own systems — that belongs to the client. When an agreement ends we hand it back or remove our access on their instructions.

When we no longer need information, we destroy it or de-identify it.

10

Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and you can ask us to correct it if it is wrong.

Email [email protected] or write to us at the address at the bottom of this page. We will respond within a reasonable time, and normally within 30 days.

There is no charge for making a request. If a request takes substantial work we may charge a reasonable cost, and we will tell you before we do.

In limited circumstances we may refuse a request — for example, where giving you access would unreasonably affect someone else’s privacy. If we refuse, we will tell you why in writing.

11

Complaints

If you think we have mishandled your personal information, tell us. Email [email protected] with the details.

Privacy complaints are handled by a director of BrokerReady, not passed to a support queue.

We will acknowledge your complaint and investigate it. If you are not satisfied with how we handle it, you can complain to the Office of the Australian Information Commissioner:

12

Changes to this policy

We may update this policy from time to time. The current version is always on this page, and the date at the top tells you when it last changed.

Contact us

Questions about this policy? Ask us directly.

Access requests, corrections and complaints all go to the same address, and a person reads them.
EntityThe Trustee for Broker Tech Trust
ABN64 665 760 939
Postal and registered address18/29 Main Street, Buderim QLD 4556, Australia
Privacy enquiries[email protected]
Regulator (OAIC)oaic.gov.au  ·  1300 363 992