Privacy policy
How Vectra Corporation Pty Ltd collects, uses and protects personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Who we are
Vectra Corporation Pty Ltd (ACN, "Vectra", "we", "us") is an Australian pure-play cybersecurity company, part of Ensign InfoSecurity. Our head office is at Level 10, 121 King William Street, Adelaide SA 5000.
This policy describes how we handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). If you are a European Union or United Kingdom resident, this policy should be read together with the relevant GDPR / UK GDPR addenda available on request.
What information we collect
We collect personal information that is reasonably necessary for Vectra's functions and activities as a cybersecurity services company. Depending on context this may include:
- Contact information (name, business email, phone, employer, role) provided through the contact form, sales enquiries, event registrations or during engagements.
- Technical information relating to incidents, assessments and managed services - including log data, telemetry and forensic artefacts provided or generated during the performance of our services.
- Information you provide if you apply for a role with us, including CV, employment history and right-to-work evidence.
- Usage information from this website - cookies and similar technologies, as described in our Cookies Policy.
How we use personal information
- To respond to enquiries and provide our services under contract with a customer.
- To manage our business relationships - including invoicing, security reviews and service reporting.
- To comply with our legal and regulatory obligations, including cyber-incident reporting where we are directed to act on behalf of an affected customer.
- To communicate about Vectra services and threat intelligence you have opted into. You can opt out at any time.
- To recruit and assess candidates.
- To protect Vectra systems, customers and personnel from security threats - including logging, monitoring and incident response on our own infrastructure.
How we protect your information
Vectra applies the same practices we recommend to our customers - ISO/IEC 27001-certified information security management, Essential Eight-aligned controls, role-based access, encryption in transit and at rest, and 24x7 monitoring of systems handling personal or customer information.
We take reasonable steps to destroy or de-identify personal information when it is no longer needed for the purpose for which it was collected, subject to contractual or legal retention requirements.
Disclosure and overseas recipients
We do not sell personal information. We disclose personal information only where necessary to deliver our services, meet our legal obligations, or with your explicit consent. Typical recipients include our professional advisers, our parent company Ensign InfoSecurity, our subcontracted service providers, and - where required by law - Australian regulators and law enforcement.
Where personal information is disclosed to a recipient outside Australia, we take reasonable steps to ensure the recipient handles that information consistently with the APPs. Our Managed Detection and Response service uses data residency inside AWS Australia (ap-southeast-2 / ap-southeast-4) and does not transfer customer telemetry offshore unless explicitly agreed.
Your rights
- Access - you can request a copy of the personal information we hold about you.
- Correction - you can ask us to correct information that is inaccurate, out-of-date, incomplete or misleading.
- Complaint - you can lodge a complaint about our handling of personal information, and escalate to the Office of the Australian Information Commissioner if the response is unsatisfactory.
- Opt-out - you can unsubscribe from marketing communications at any time using the link in each email, or by emailing the address below.
Contact
Requests and complaints should be directed to privacy@vectra-corp.com or to the Privacy Officer, Vectra Corporation Pty Ltd, Level 10, 121 King William Street, Adelaide SA 5000. We aim to respond to requests within 30 days.
If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au or 1300 363 992.