Privacy
Privacy is part of the architecture.
Public disclosure is minimised and customer, staff and operational detail remains inside protected boundaries.
Plain-language overview. Associated Ventures minimises what this public site collects. It uses necessary technical records to deliver and protect the site and stores a theme preference in your browser. Public account, customer and Data Vault services are not production-active. This policy is legal-review-ready, not legal advice or a claim of legal certification.
1. Scope and definitions
Associated Ventures operates this public information, status and portal-gateway website in Australia. This policy applies to visitors and people who contact us through an approved pathway. “Personal information” and “sensitive information” have the meanings given by the Privacy Act 1988 (Cth), where applicable. Whether the Act and Australian Privacy Principles apply depends on the operator’s circumstances; we adopt APP-aligned practices voluntarily where they do not otherwise apply.
2. What we collect
We may receive information deliberately supplied in an enquiry, including name, contact details, message and related service context. Do not send credentials, identity documents, health information, customer records or confidential files in an initial public enquiry. The public server may record request time, requested resource, response code, source IP address, user-agent and security events. These records support delivery, diagnosis, abuse prevention and audit. The current public pages do not provide open registration, production customer accounts, unrestricted uploads or production Data Vault storage.
3. How and why information is collected
Information is collected directly when you contact us and automatically when browsers request public resources. We use only what is reasonably needed to respond, operate and secure services, maintain accurate records, meet legal obligations and establish or exercise legal rights. Information received from an authorised service provider or referrer is handled for the same compatible purpose. We seek to minimise collection and may decline or securely dispose of unsolicited information we do not need.
4. Browser storage, cookies and analytics
A code and browser audit found that the public shell uses local storage to remember the visitor’s dark or light theme preference. Ordinary public navigation does not require an analytics or advertising cookie, and no public analytics product was identified in this release. Network infrastructure or a separately governed external destination may use its own necessary controls. If tracking or analytics is introduced, this notice and any required choice mechanism must be updated before activation.
5. Use, communication and disclosure
We use information for the purpose explained at collection, a related expected purpose, with consent, or as authorised or required by law. We may give limited information to authorised contractors and infrastructure providers that help deliver, secure, investigate or recover services, subject to appropriate access boundaries. We do not state that we sell personal information. Direct marketing will only occur where lawful; each applicable electronic message should provide a workable unsubscribe path, and suppression information may be retained so a request remains effective.
6. Sensitive information, identifiers and children
We do not invite sensitive information or government-related identifiers through public pages. We collect or use them only with appropriate consent or another lawful basis and when genuinely necessary. This site is directed to a general audience, not specifically to children; a parent or guardian should assist a minor with a consequential enquiry.
7. Accuracy, access and correction
We take reasonable steps to keep information relevant and accurate. A person may use the verified contact pathway to request access or correction. We may need proportionate identity verification and may refuse or limit a request where law permits, explaining the reason and available complaint route where required. Never send identity evidence until a controlled channel is agreed.
8. Storage, security, retention and deletion
Controls may include encrypted transport, least privilege, service segregation, authentication for private systems, audit records, controlled secrets, backups and tested recovery. No control eliminates all risk. Information is retained only for operational, security, contractual, legal or evidentiary needs, then deleted or de-identified where appropriate. Backup copies may expire later through controlled rotation; deletion can be delayed by legal holds, incident preservation or mandatory recordkeeping.
9. Overseas handling
No specific country of overseas recipient has been verified for the public site. Internet and external-provider delivery can involve access or processing outside Australia. Before any material overseas disclosure is activated, the operator should identify recipients and locations where practicable, assess applicable safeguards and update collection notices. External websites are governed by their own privacy practices.
10. Incidents, enquiries and complaints
Suspected incidents are contained, investigated and documented according to available evidence. Where the Privacy Act and Notifiable Data Breaches scheme apply, eligible breaches will be assessed and notified as required. Use the verified public contact pathway for a privacy enquiry or complaint and provide only minimum identifying detail. We will seek to understand, investigate and communicate an outcome; unresolved matters may be taken to the OAIC or another competent body where its jurisdiction applies.
11. Future services and policy changes
Portal, CRM, document-vault or credential-vault activation would require service-specific collection notices, retention rules, identity controls and independent Australian legal and security review before real information is accepted. Material changes will be identified by a new version and effective date and, where practicable, a prominent website notice. Related documents: Terms, Accessibility, Responsible security reporting and Legal information.