Privacy Policy
Yubsara Investments Pty Ltd trading as Yusatech
Effective Date: 1 January 2024 | Last Updated: 3 May 2026
| Entity | Yubsara Investments Pty Ltd trading as Yusatech ("Yusatech," "we," "us," or "our") |
|---|---|
| ABN | 32 660 772 896 |
| Registered Office | 17 Hansel Drive, Werribee, Victoria 3030, Australia |
| Privacy Officer Email | privacy@yusatech.com.au |
| Telephone | 03 87631390 |
1. Introduction
Yubsara Investments Pty Ltd, trading as Yusatech, is committed to protecting the privacy of individuals whose personal information we collect, hold, use and disclose. This Privacy Policy ("Policy") describes how we manage personal information in accordance with:
- the Privacy Act 1988 (Cth) ("Privacy Act");
- the Australian Privacy Principles ("APPs") set out in Schedule 1 of the Privacy Act;
- the Notifiable Data Breaches scheme established under Part IIIC of the Privacy Act; and
- other applicable Australian privacy laws, including the Privacy and Other Legislation Amendment Act 2024 (Cth) to the extent its provisions have commenced.
This Policy applies to all personal information we collect through our website (yusatech.com.au and any associated subdomains), our products and services, our marketing activities, our recruitment processes, and any other interactions you have with us.
By providing personal information to us, or by using our website, products, or services, you acknowledge that we may collect, hold, use, and disclose your personal information in accordance with this Policy.
2. Definitions
In this Policy, unless the context requires otherwise:
- "APP" or "Australian Privacy Principle" means an Australian Privacy Principle set out in Schedule 1 of the Privacy Act.
- "OAIC" means the Office of the Australian Information Commissioner.
- "Personal information" has the meaning given in section 6 of the Privacy Act — being information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not.
- "Sensitive information" has the meaning given in section 6 of the Privacy Act, and includes information about an individual's racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, health information, and biometric information.
- "Eligible data breach" has the meaning given in section 26WE of the Privacy Act.
3. Kinds of Personal Information We Collect
The kinds of personal information we collect and hold depend on the nature of your interaction with us.
3.1 Identification and contact information
- Full name, preferred name, and titles.
- Postal and physical addresses.
- Email addresses.
- Telephone and mobile numbers.
- Date of birth (where reasonably necessary).
3.2 Business and professional information
- Business or trading name, ABN/ACN, position or job title.
- Industry and professional qualifications relevant to the services we provide.
- Domain registration eligibility information (where applicable for .com.au registrations).
3.3 Financial and transactional information
- Billing addresses and tax invoice information.
- Bank account details (for refunds or direct debit, where applicable).
- Records of transactions, services purchased, and payment history.
We do not store full credit card details on our systems. Card payments are processed by PCI-DSS compliant third-party payment gateways.
3.4 Technical and online activity information
- Internet Protocol (IP) address and approximate geographic location.
- Device identifiers, browser type and version, operating system.
- Pages visited, time and duration of visits, referring URLs, and clickstream data.
- Cookies, pixels, web beacons, and similar tracking technologies (see Section 9).
3.5 Communications and support information
- Records of correspondence, enquiries, support tickets, and feedback.
- Survey and research responses (where you participate voluntarily).
- Content you submit through forms, including project briefs and content for websites we develop.
3.6 Sensitive information
We do not generally collect sensitive information. Where we do require sensitive information, we will collect it only with your express consent and only where reasonably necessary for, or directly related to, one or more of our functions or activities, in accordance with APP 3.3.
3.7 Anonymity and pseudonymity
In accordance with APP 2, you have the option of dealing with us anonymously or under a pseudonym where it is lawful and practicable to do so. However, in many cases (for example, when entering into a service contract, registering a domain on your behalf, or issuing a tax invoice) it will not be practicable for us to deal with you anonymously or pseudonymously.
4. How We Collect Personal Information
Wherever reasonable and practicable, we collect personal information directly from you, in accordance with APP 3.6. We may collect personal information through the following channels:
- Website forms, contact forms, quote requests, and account registrations.
- Email correspondence, telephone calls, video conferences, and in-person meetings.
- Service agreements, statements of work, invoices, and project deliverables.
- Automated technologies (cookies, analytics, server logs) when you interact with our website (see Section 9).
- Job applications, including résumés, cover letters, and references.
- Subscriptions to our newsletters or marketing communications.
- Third parties, only where you have consented or where collection from a third party is required or authorised by law (for example, publicly available information, credit reporting bodies where applicable, or referrals from existing clients).
If we receive personal information about you from a third party that we did not solicit and could not have collected directly, we will, in accordance with APP 4, determine within a reasonable period whether we could have collected the information ourselves. If we could not, we will destroy or de-identify that information as soon as practicable, unless it would be unlawful or unreasonable to do so.
5. Why We Collect, Hold, Use and Disclose Personal Information
We collect, hold, use and disclose personal information for the following primary purposes:
- To provide, support, and invoice for our products and services, including website development, hosting, email, IT support, and learning management system services.
- To respond to enquiries, quote requests, and customer support requests.
- To register and manage domain names on your behalf, where this requires us to provide your information to a domain registrar or registry.
- To verify your identity and protect against fraud and unauthorised access.
- To manage and improve our website, products, services, and customer experience.
- To recruit, evaluate, and engage with employees, contractors, and applicants.
- To comply with our legal, regulatory, accounting, and reporting obligations.
- To establish, exercise, or defend legal claims.
We may also use or disclose personal information for a secondary purpose related to a primary purpose where you would reasonably expect such use or disclosure, where you have consented, or where the use or disclosure is otherwise required or authorised by or under Australian law (in accordance with APP 6).
6. Direct Marketing
We may use your personal information to send you marketing communications about our products, services, offers, and updates that we believe may be of interest to you. We will only send direct marketing communications in accordance with APP 7, the Spam Act 2003 (Cth), and the Do Not Call Register Act 2006 (Cth).
Each marketing communication we send will contain a clear and functional means by which you can opt out (such as an unsubscribe link). You may opt out of receiving direct marketing communications from us at any time by:
- using the unsubscribe mechanism in the relevant communication; or
- contacting our Privacy Officer using the details in Section 17.
Even after you opt out, we may continue to send you transactional, administrative, or service communications relating to your account or our services.
7. Disclosure of Personal Information
We may disclose your personal information to the following categories of recipients:
- Service providers and contractors: including hosting providers, cloud infrastructure providers, payment processors, email and productivity platform providers, customer relationship management platforms, analytics providers, marketing platforms, IT support providers, and professional advisers (accountants, auditors, lawyers).
- Domain registrars and registries: where required to register, transfer, or maintain a domain name on your behalf (including auDA-accredited registrars for .au domains and ICANN-accredited registrars for international domains).
- Government, regulatory, and law enforcement bodies: where disclosure is required or authorised by Australian law, court order, or in response to a lawful request.
- Successors and assigns: in connection with a sale, merger, restructure, or transfer of our business or assets, subject to confidentiality obligations.
- With your consent: to any other recipient where you have given express or implied consent to that disclosure.
We do not sell, rent, or trade personal information.
7.1 Cross-border disclosure
Some of our service providers and platforms are located, store data, or process data outside of Australia. By using our services, you acknowledge that your personal information may be disclosed to recipients in the following jurisdictions, among others:
- United States of America (e.g., cloud infrastructure, analytics, productivity, and marketing platforms).
- European Union and United Kingdom (e.g., hosting and software-as-a-service providers).
- Other jurisdictions where our service providers from time to time host or process data.
Before disclosing personal information to an overseas recipient, we will, in accordance with APP 8, take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information. These steps may include requiring the recipient to be bound by contractual obligations consistent with the APPs, or relying on a permitted exception under APP 8.2.
8. Data Quality
We take reasonable steps, in accordance with APP 10, to ensure that the personal information we collect is accurate, up to date, and complete, and that the personal information we use or disclose is accurate, up to date, complete, and relevant having regard to the purpose of the use or disclosure. You can help us maintain accurate records by promptly notifying us of any changes to your personal information using the contact details in Section 17.
9. Cookies and Online Tracking Technologies
Our website uses cookies and similar tracking technologies to operate, secure, analyse, and improve our website. The categories of cookies we use include:
- Strictly necessary cookies: essential to enable core website functionality such as session management, authentication, and security.
- Functional cookies: remember your preferences and settings to improve your experience.
- Analytics cookies: help us understand how visitors use our website (for example, Google Analytics) so we can improve content and performance.
- Marketing and advertising cookies: where used, allow us and our advertising partners to deliver relevant advertisements and measure campaign performance.
You can control or disable cookies through your browser settings. Disabling certain cookies may affect the functionality of our website. Where required by law, we will obtain your consent before deploying non-essential cookies.
We may use third-party analytics services (such as Google Analytics) which collect information about your use of our website. The information collected by these services is governed by the respective providers' privacy policies. You can opt out of Google Analytics by installing the Google Analytics Opt-out Browser Add-on at tools.google.com/dlpage/gaoptout.
10. Automated Decision-Making
We do not currently use automated decision-making, including profiling, that produces legal effects concerning you or similarly significantly affects you. If we begin to use such automated decision-making in the future, we will update this Policy to disclose the kinds of personal information used and the decisions made, in accordance with the transparency requirements introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth) when those provisions commence.
11. Data Security
We take reasonable steps, in accordance with APP 11.1, to protect personal information we hold from misuse, interference, and loss, and from unauthorised access, modification, or disclosure. These steps include:
- Encryption of data in transit using TLS protocols and encryption of data at rest where appropriate.
- Access controls and authentication requirements (including multi-factor authentication for administrative access).
- Role-based access permissions on a need-to-know basis.
- Regular software updates, vulnerability patching, and security testing.
- Secure backup procedures and disaster recovery planning.
- Staff training on privacy and information security obligations.
- Confidentiality and data protection clauses in contracts with service providers.
- Physical security measures for premises and equipment.
While we take reasonable steps to protect personal information, no method of transmission over the internet or method of electronic storage is completely secure. We cannot guarantee absolute security.
12. Data Retention and Destruction
We retain personal information only for as long as is reasonably necessary for the purposes for which it was collected, or as required by Australian law. Indicative retention periods include:
| Category | Retention Period | Applicable Law |
|---|---|---|
| Tax and financial records | At least 7 years from the relevant tax year | Income Tax Assessment Act 1997 (Cth); A New Tax System (Goods and Services Tax) Act 1999 (Cth) |
| Corporate and contractual records | At least 7 years from the end of the contract or relationship | Corporations Act 2001 (Cth) |
| Marketing data | Until you withdraw consent or opt out of communications | APP 7; Spam Act 2003 (Cth) |
| Website analytics data | As configured in our analytics platforms (typically up to 14 months) | — |
| Unsuccessful job applications | Up to 12 months after the role is filled, unless a longer period is consented to | — |
When personal information is no longer required and we are not legally required to retain it, we take reasonable steps to destroy the information or to ensure that the information is de-identified, in accordance with APP 11.2.
13. Notifiable Data Breaches
We comply with the Notifiable Data Breaches scheme established under Part IIIC of the Privacy Act. If we become aware that there are reasonable grounds to believe that an eligible data breach has occurred, we will:
- Promptly carry out a reasonable and expeditious assessment to determine whether an eligible data breach has occurred.
- Take all reasonable steps to contain the breach and mitigate any harm.
- Notify the Australian Information Commissioner as soon as practicable.
- Notify affected individuals (or, where direct notification is not practicable, publish a statement on our website) where required by the scheme, including a description of the breach, the kinds of information involved, and the steps individuals should take in response.
We maintain an internal data breach response plan to support compliance with these obligations.
14. Your Rights — Access, Correction, and Complaints
14.1 Right to access
You may request access to the personal information we hold about you in accordance with APP 12. We will respond to your request within a reasonable period (and in any event within 30 days where practicable). We will provide access in the manner you request, unless it is unreasonable or impracticable to do so. We may charge a reasonable fee for the cost of providing access; we will not charge you for making the request itself.
We may decline to provide access in the limited circumstances permitted by APP 12, including where providing access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, or where access would be unlawful. If we decline a request, we will provide written reasons and information about complaint mechanisms.
14.2 Right to correction
You may request that we correct personal information we hold about you that you consider to be inaccurate, out of date, incomplete, irrelevant, or misleading, in accordance with APP 13. We will take reasonable steps to correct the information unless we are not satisfied that it meets that description. If we refuse to make a correction, we will provide written reasons and, on your request, associate a statement with the information indicating that you consider it to be inaccurate, out of date, incomplete, irrelevant, or misleading.
14.3 Complaints
If you believe we have breached the APPs, the Privacy Act, or this Policy, you may make a complaint to our Privacy Officer using the contact details in Section 17. Please provide as much detail as possible about the alleged breach so we can investigate efficiently.
We will acknowledge your complaint within seven (7) business days and aim to provide a substantive response within 30 days. If we are unable to resolve your complaint to your satisfaction, you may lodge a complaint with the Office of the Australian Information Commissioner:
Online: www.oaic.gov.au
Telephone: 1300 363 992
Post: GPO Box 5288, Sydney NSW 2001
15. Children's Privacy
Our services are directed to businesses and adults. We do not knowingly collect personal information from individuals under the age of 16. If you are a parent or guardian and you believe we have collected personal information of a person under 16, please contact our Privacy Officer using the details in Section 17 and we will take reasonable steps to delete that information.
We will comply with the Children's Online Privacy Code (when made by the Information Commissioner under the Privacy and Other Legislation Amendment Act 2024 (Cth)) to the extent it applies to us.
16. Third-Party Links
Our website may contain links to websites, applications, or services operated by third parties. We are not responsible for the privacy practices or content of those third parties. We encourage you to review the privacy policies of any third-party site or service before providing them with personal information.
17. Contact — Privacy Officer
If you have any questions, requests, or complaints in relation to this Policy or our handling of your personal information, please contact our Privacy Officer:
Email: privacy@yusatech.com.au
Telephone: 03 87631390
Post: 17 Hansel Drive, Werribee, Victoria 3030, Australia
18. Changes to This Policy
We may amend this Policy from time to time to reflect changes in our practices, technology, legal obligations, or other factors. The version of the Policy in effect at the time you provide personal information will apply to that information. We will publish the current version of the Policy on our website and update the "Last Updated" date at the top of this page.
Where changes are material, we will take reasonable steps to bring those changes to your attention (for example, by email to active clients or a prominent notice on our website). Your continued use of our services after changes take effect indicates your acceptance of the revised Policy.
19. Governing Law
This Policy is governed by the laws of the State of Victoria, Australia. Any disputes relating to this Policy will be subject to the non-exclusive jurisdiction of the courts of Victoria and the Commonwealth of Australia.
Yubsara Investments Pty Ltd T/A Yusatech — ABN 32 660 772 896 — Privacy Policy v1.0, effective 1 January 2024, last updated 3 May 2026.