Privacy Policy

Burley Assurance
Last updated: July 2026

1. Introduction

Burley Assurance is a Canberra-based cyber assurance and defence consulting practice. We are committed to handling personal information responsibly, transparently, and in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy explains how we collect, use, store, and protect personal information in connection with our website and consulting services.

2. Information we collect

2.1 Information you provide directly

When you contact us through this website or engage us for services, we may collect your name, organisation, job title, email address, and any other information you choose to include in your correspondence.

2.2 Automatically collected information

Our website may collect limited technical data including IP addresses and pages visited through analytics tools. This data is aggregate and non-identifiable. We do not use cookies for advertising or tracking purposes.

2.3 Sensitive information

We do not collect sensitive personal information through this website. Where sensitive information is required as part of a professional engagement, such as security clearance status relevant to a project, it is collected directly and handled under the terms of the applicable engagement agreement.

3. How we collect personal information

We collect personal information directly from you when you submit an enquiry through our contact form, correspond with us by email, or engage us for consulting services. We do not collect personal information from third parties without your knowledge.

4. How we use your information

We use personal information to respond to your enquiry, assess whether we can assist with your requirements, deliver agreed services, and meet our legal and professional obligations. We do not use your information for direct marketing and we do not sell, rent, or share your information with third parties except where required by law or necessary to deliver services you have requested.

5. Disclosure of personal information

We may disclose personal information to professional advisers, subcontractors engaged to assist with service delivery, or government and regulatory bodies where required by law. Any subcontractors engaged are subject to confidentiality obligations consistent with this policy.

6. Data storage and security

Personal information is stored securely in Australian-based systems or systems operated under equivalent privacy protections. As a cyber assurance practice we apply appropriate technical and organisational controls including access controls, encryption in transit, and secure credential management to protect personal information from unauthorised access, loss, or disclosure.

7. Data retention

We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by applicable law, professional obligations, or contractual requirements. When information is no longer required it is securely destroyed or de-identified.

8. Access and correction

You have the right to request access to personal information we hold about you and to request correction of information that is inaccurate, incomplete, or out of date. We will respond to access and correction requests within a reasonable timeframe. If we are unable to provide access or make a requested correction we will explain our reasons in writing.

9. Complaints

If you believe we have mishandled your personal information, please contact us in the first instance using the details below. We will investigate and respond within a reasonable timeframe. If you are not satisfied with our response you may lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.

10. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on this page with the date of last update.

11. Contact

Burley Assurance
Canberra, ACT
info@burleyassurance.com.au