Your Privacy Matters

Privacy Policy

Effective Date: 10 February 2026Last Updated: 10 February 2026

1. Introduction

This Privacy Policy explains how Shadowtek Pty Ltd (ACN 627 829 878) as Trustee for The Dey Family Trust (ABN 32 913 781 386) ("Shadowtek", "we", "us", or "our") collects, uses, discloses, and protects your personal information when you use our website, services, or interact with us.

We are committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Contact Information
  • Email: [email protected]
  • Postal Address: PO Box 6, Warwick, QLD 4370, Australia
  • Website: https://www.shadowtek.com.au/

2. Information We Collect

2.1 Personal Information You Provide

We collect personal information that you voluntarily provide to us when you:

  • Request a quote or consultation
  • Purchase our services
  • Create an account or client portal access
  • Subscribe to service notifications
  • Contact us for support or inquiries
  • Engage us for web development, hosting, or security services

This information may include:

  • Full name and business name
  • Email address
  • Phone number
  • Billing and payment information
  • Business address
  • Website credentials and access details (for service delivery)
  • Technical specifications and project requirements
  • Communications and correspondence with us

2.2 Information We Collect Automatically

When you visit our website or use our services, we automatically collect certain technical information, including:

  • IP address and device identifiers
  • Browser type and version
  • Operating system
  • Pages visited and time spent on pages
  • Referring website addresses
  • Click patterns and navigation paths
  • Server logs and hosting performance data
  • Security event logs and threat detection data

2.3 Cookies and Tracking Technologies

We use cookies and similar tracking technologies on our website to collect information such as your IP address, browser data, device identifiers, pages visited, and interactions with our website.

We use the following tracking technologies on our website:

  • Google Analytics: For website traffic analysis and user behavior patterns
  • Facebook Pixel: For understanding visitor engagement and website performance optimization
  • Website Heatmaps (e.g., Hotjar/Microsoft Clarity): For analyzing how users interact with our website to improve user experience

You can control cookies through your browser settings. However, disabling cookies may limit your ability to use certain features of our website.

3. How We Use Your Information

We collect and use your personal information only for legitimate business purposes, including:

3.1 Service Delivery and Administration

  • Providing web development, hosting, security, and maintenance services
  • Processing payments and managing billing
  • Creating and managing your client account
  • Communicating about your projects and service status
  • Providing technical support and customer service
  • Managing server infrastructure and ensuring website uptime

3.2 Security and Protection

  • Monitoring and protecting against security threats, malware, and unauthorized access
  • Conducting security audits and vulnerability assessments
  • Implementing and maintaining Cloudflare WAF, Imunify360, and other security measures
  • Investigating and responding to security incidents
  • Backing up client data and ensuring business continuity

3.3 Legal and Compliance

  • Complying with legal obligations and regulatory requirements
  • Enforcing our Terms of Service and other agreements
  • Protecting our legal rights and interests
  • Responding to law enforcement requests or court orders

3.4 Business Operations and Improvement

  • Analyzing website performance and user experience
  • Improving our services, products, and website functionality
  • Conducting internal research and development
  • Maintaining accurate business records
Important Note on Marketing

Our marketing communications are strictly limited to billing and service-related communications for existing clients (including transactional emails related to billing, service updates, security notifications, and administrative matters directly connected to the services you have purchased). We do not send general newsletters or promotional communications unless you have specifically opted in.

4. How We Share Your Information

We do not sell, rent, or trade your personal information to third parties. We may share your information only in the following limited circumstances:

4.1 Service Providers and Business Partners

We may share your information with trusted third-party service providers who assist us in operating our business, including:

  • Payment Processors: To process credit card and payment transactions securely
  • Hosting Infrastructure Providers: For server infrastructure and data center operations
  • Security Service Providers: Including Cloudflare, Imunify360, and security monitoring services
  • Cloud Storage Providers: For secure backup and data redundancy
  • Domain Registrars: For domain registration and DNS management services

These service providers are contractually obligated to protect your information and use it only for the specific purposes we authorize.

4.2 Legal Requirements

We may disclose your personal information if required by law, court order, subpoena, or government authority, or if we believe in good faith that such disclosure is necessary to:

  • Comply with legal obligations
  • Protect and defend our rights or property
  • Prevent fraud or illegal activity
  • Protect the safety of our employees, clients, or the public

4.3 Business Transfers

In the event of a merger, acquisition, reorganization, or sale of assets, your personal information may be transferred to the acquiring entity, subject to the same privacy protections outlined in this Policy.

5. Data Security

We implement robust technical, administrative, and physical security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction. Our security measures include:

Enterprise-grade encryption for data transmission and storage
Cloudflare Web Application Firewall (WAF) protection
Imunify360 real-time threat defense and malware scanning
CloudLinux account isolation to prevent cross-contamination
LiteSpeed-powered hosting infrastructure with DDoS protection
Multi-factor authentication for administrative access
Regular security audits and vulnerability assessments
Automated backup systems with encrypted off-site storage
24/7 proactive monitoring and incident response
Strict access controls and employee confidentiality obligations

Despite our best efforts, no system is completely secure. We cannot guarantee absolute security of your information transmitted to or stored on our systems.

6. Data Retention

We retain your personal information only for as long as necessary to fulfill the purposes outlined in this Privacy Policy, unless a longer retention period is required or permitted by law.

Retention Periods

Active Client Data

Retained for the duration of our service relationship plus a reasonable period afterward for business continuity and dispute resolution

Financial and Legal Records

Retained for a minimum of 7 years to comply with Australian taxation, accounting, and other legal requirements

Security Logs

Retained for a minimum of 12 months for security analysis and incident investigation

Website Analytics

Typically retained for 24–36 months for trend analysis

Support Communications

Retained for 3 years for quality assurance and legal protection

When personal information is no longer required, we securely delete or anonymize it in accordance with our data destruction policies.

7. Your Privacy Rights

Under the Australian Privacy Principles, you have the following rights regarding your personal information:

7.1 Right to Access

You have the right to request access to the personal information we hold about you. We will provide you with a copy of your information in a commonly used format within a reasonable timeframe.

7.2 Right to Correction

If you believe any personal information we hold about you is inaccurate, incomplete, or out-of-date, you have the right to request correction. We will take reasonable steps to correct the information within 30 days of your request.

7.3 Right to Complain

If you believe we have breached the Australian Privacy Principles, you have the right to lodge a complaint with us. We will investigate your complaint and respond within a reasonable timeframe (typically 30 days).

7.4 Right to Opt-Out

You have the right to opt-out of receiving service-related communications from us, although this may limit our ability to provide certain services to you. You cannot opt-out of essential transactional communications related to billing, security alerts, or service delivery.

7.5 How to Exercise Your Rights

Contact Details for Privacy Requests
  • Email: [email protected]
  • Subject Line: Privacy Rights Request
  • Postal Address: PO Box 6, Warwick, QLD 4370, Australia

Please include your full name, contact information, and a detailed description of your request. We may require verification of your identity before processing your request.

8. International Data Transfers

Our primary operations and data storage are located in Australia. However, some of our service providers and infrastructure partners may be located overseas, including:

  • United States (Cloudflare, payment processors, cloud storage providers)
  • European Union (backup and redundancy systems)
  • Singapore (regional content delivery network nodes)

When we transfer your personal information overseas, we ensure that appropriate safeguards are in place through:

  • Contractual clauses requiring compliance with Australian privacy standards
  • Service providers subject to privacy laws substantially similar to the APPs
  • Data processing agreements with explicit security and confidentiality obligations

9. Third-Party Websites and Services

Our website may contain links to third-party websites, services, or resources that are not operated or controlled by Shadowtek. This Privacy Policy does not apply to third-party websites.

We are not responsible for the privacy practices or content of third-party websites. We encourage you to review the privacy policies of any third-party websites you visit.

10. Children's Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a child without parental consent, we will take steps to delete that information promptly.

11. Changes to This Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, legal requirements, or for other operational reasons.

Notification of Changes

  • We will update the "Last Updated" date at the top of this Policy
  • Material changes will be communicated via email to active clients
  • Continued use of our services after changes become effective constitutes acceptance of the updated Policy
  • We recommend reviewing this Policy periodically to stay informed

12. Privacy Complaints and Dispute Resolution

If you have concerns about how we handle your personal information, we encourage you to contact us first:

Step 1: Internal Complaint

We will acknowledge your complaint within 5 business days and provide a full response within 30 days.

Step 2: External Resolution

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Email: [email protected]
  • Mail: GPO Box 5218, Sydney NSW 2001

13. Contact Information

For questions, concerns, or requests regarding this Privacy Policy or our privacy practices, please contact us:

Shadowtek Pty Ltd
  • ACN: 627 829 878
  • Email: [email protected]
  • Postal Address: PO Box 6, Warwick, QLD 4370, Australia
  • Website: https://www.shadowtek.com.au/
  • Privacy Officer: Steven Dey

Acknowledgment: By using our website or services, you acknowledge that you have read, understood, and agree to be bound by this Privacy Policy.