Privacy
Your information, and what we actually do with it.
Most privacy policies are written to be unreadable, which rather defeats the point of publishing one. This is the plain version. It covers this website, what happens when you contact us, and the separate question of what we can reach inside a client's systems.
The short version
The whole thing in five lines.
Every line here is true of the policy underneath it. If the two ever disagree, the policy is the one that counts.
- We collect what you type into a form on this site, and what your browser tells the server. Nothing is bought in from anywhere else.
- We use it to reply to you, to do the work you engaged us for, and to send the monthly email if you asked for it.
- We do not sell it, rent it or trade it, and we do not hand it over for anyone else to market to you.
- The site sets no cookies of its own. The measurement tags do, and your browser can block them without breaking anything.
- You can ask what we hold, ask for it corrected, or ask for it removed, and we will do it.
Who we are
Coast IT is the trading name of Coast IT Solutions, ABN 19 775 836 767, a managed IT provider based on the Gold Coast and operating since 2020. In this policy "we", "us" and "our" mean Coast IT Solutions.
This policy covers coastit.au and every form on it, and it covers the information we hold about you as somebody who has enquired, subscribed, booked a call or become a client.
It sits alongside a client service agreement rather than replacing it. Where an agreement says something more specific about a client's own information, the agreement is the one that governs.
We handle personal information in line with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). We do that as a matter of practice, not only where the Act compels a business of our size to.
The two kinds of information we hold
There are two, they are governed differently, and most privacy policies written for an IT provider only describe the first one.
The first is information about you, given to us directly or picked up by this website. That is what the rest of this policy is about.
The second is information sitting inside a client's own systems. Looking after a business's technology means holding administrative access to it, so in the ordinary course of the work we can reach mailboxes, files, user accounts and device records belonging to a client's staff, and sometimes to that client's own customers, or in a school to students and their families.
We treat that information as the client's, not ours. We work on their instructions, only to deliver and support the service they engaged us for. We do not use it for our own purposes, we do not mine it, and we do not disclose it to anybody else except where the client asks us to or the law requires it.
If you are a staff member, a customer, a student or a parent at an organisation we look after, that organisation decides what is collected about you and why, and its privacy policy is the one that governs it. Ask them first. If they need us to help with your request, we will.
What you give us
Everything in this section is something you typed or told us.
- The enquiry form
- Your name and email address, plus your company, phone number and message if you fill those in. We also record which page the form was on and when it was sent, so a reply has some context to it.
- The newsletter form
- Your name and email address. Nothing else, because there is nothing a third field would let us do.
- The booking calendar
- Whatever the calendar asks for when you book a call. The calendar is run for us by GoHighLevel and opens in a frame on our page rather than on our own server.
- The Cyber Risk Scorecard
- At risk.coastit.au: your answers to the questions, and the contact details you give so the score can be sent back to you.
- Ringing or emailing us
- Whatever you choose to tell us, which is usually the problem you are having and how to get back to you.
- Becoming a client
- The things needed to run the account: contact and billing details, the people we are authorised to take instructions from, and a record of the work done.
We never ask you to send a password, a bank account detail or a card number through a form on this site or by email, and you should not send one. If you get a message that appears to be from us asking for any of those, ring us on the number at the bottom of this page before you act on it.
This site is not aimed at children and we do not knowingly collect information from them.
What the site collects on its own
Two things happen without you doing anything.
The first is ordinary web logs. This site is hosted and delivered by Netlify, whose servers record the IP address a request came from, the browser and device type, which pages were asked for, and the date and time. That is how any website on the internet works, and it is what keeps the site up and shows us when something is being attacked.
The second is measurement. Three tags can run on this site, each only if it has been configured. Any that has not been is not on the page at all, rather than sitting there switched off.
- Google Analytics 4
- Which pages get read, roughly what part of the world a visit came from, and whether an enquiry followed. It is not tied to your name.
- Microsoft Clarity
- Builds heatmaps and records how a page is used, including scrolling, clicks and mouse movement, so we can see where a page confuses people. It records the session rather than the person, and it masks the contents of form fields by default.
- Meta Pixel
- Whether an advertisement led to an enquiry, so we are not paying for advertising that does nothing.
Clarity is the one worth knowing about, because most people do not expect a website to record how they moved around it. That is why it is named here rather than folded into a sentence about analytics.
Cookies
This site sets no cookies of its own, and ships no JavaScript bundle. What cookies you pick up here come from the measurement tags above and from the booking calendar once you open it.
You can block or delete them in your browser settings, or use a private window. Blocking them does not stop the site working, and it does not stop you enquiring or booking. It only means we cannot tell that a return visit is a return visit.
Why we hold it
For the reason you gave it to us, which is one of these.
- To reply to an enquiry, and to quote on work
- To deliver, monitor and support the services a client has engaged us for
- To raise invoices and get paid
- To send the monthly email, if you asked for it
- To keep this site working, and to see when it is being abused
- To meet obligations that apply to us under Australian law, including tax and record keeping
Nothing on this site makes an automated decision about you. The Cyber Risk Scorecard does score your answers automatically, and that score is a guide to what is worth looking at rather than a decision about you or something we act on by itself.
From 10 December 2026 the Privacy Act requires a policy to describe automated decisions that could significantly affect a person's rights or interests. We do not make any. If that ever changes, this is the section where it will be written down.
The monthly email
One email a month with the new Tech Tip Tuesdays piece in it. You get it because you asked for it, either on this site or by telling us.
Every one of them carries an unsubscribe link, and it works on the first click. That is what the Spam Act 2003 requires and it is also just how it should work. We do not buy or rent mailing lists.
Replying to an enquiry, quoting on work, or anything else to do with a service you have actually engaged us for is not marketing, and unsubscribing from the monthly email does not stop us answering you.
Who else sees it
We do not sell, rent or trade personal information, and we do not pass it to anybody else so they can market to you.
It does reach the companies whose systems we run the business on. The main ones, and what each is for:
- GoHighLevel
- Customer records, the forms on this site, the booking calendar and outgoing email. Supplied to us through Growably, which is why the calendar is served from links.growably.com.
- Microsoft
- Email, files and documents, and the Clarity measurement described above.
- Netlify
- Hosting and delivery of this website.
- Website analytics.
- Meta
- Advertising measurement.
- SuperOps
- Ticketing and asset records for clients.
- N-able
- Monitoring and patching of client systems.
Each is engaged to do that job and no other. Two of them are worth being straight about: Google and Meta also handle what they collect under their own privacy policies and for their own purposes, which is the deal with any advertising or analytics platform. If that matters to you, read theirs, and block the tags.
We also disclose information to our accountant, insurer or professional advisers where they genuinely need it, and to a law enforcement agency, court or regulator where the law requires it, for example under a warrant, subpoena or a validly issued court order. We do not hand over more than what has been asked for.
If the business is ever sold or restructured, records would move with it, and anybody affected would be told.
Where it is held
Some of it is held or reached from overseas. GoHighLevel, Netlify, Google and Meta are United States companies and their systems are principally there. Microsoft operates in many countries, including Australia.
Australian Privacy Principle 8 asks us to take reasonable steps to satisfy ourselves that an overseas recipient will handle information properly. In practice that means using established providers that publish their security and privacy terms, and not sending personal information to one that does not.
Those companies are still subject to the laws of the countries they operate in, and we cannot change that. Anybody who tells you otherwise about a cloud service has not read it either.
How we protect it
Access to the systems that hold personal information is limited to what the work requires and protected by multi factor authentication. The devices we work from are patched and running managed endpoint protection. Traffic to and from this site is encrypted, and every form on it posts over HTTPS.
Our own environment is set up against the ACSC Essential Eight, which is the same benchmark we hold client environments to. It would be a strange business that sold a standard it did not run itself.
What we will not tell you is that any of this makes a breach impossible. No system is completely secure, and a provider claiming otherwise is selling something. What we can tell you is that the controls here are the ones we would put in a client's environment, and that they get reviewed rather than set up once and forgotten.
If something goes wrong
If we have reason to think personal information has been lost, or has reached somebody it should not have, we work out what happened and how much harm it could do. The Privacy Act allows 30 days for that assessment. We would treat 30 days as an outer limit rather than a target, because the risk to the people involved grows while nobody is telling them.
If it turns out to be an eligible data breach likely to result in serious harm, we notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
Where the breach is inside a client's own systems rather than ours, the client is usually the organisation that has to notify. We work through it with them, help them meet the obligation, and do not sit on it.
How long we keep it
As long as we need it for the reason it was collected, and after that as long as the law requires.
- An enquiry that does not go anywhere: kept while there is a reasonable prospect of picking the conversation back up, then removed
- Newsletter subscribers: until you unsubscribe, and we keep a record of the unsubscribe so you are not added back by accident
- Client records: for the term of the agreement and for a period afterwards, set out in that agreement
- Anything attached to an invoice or a transaction: at least five years, because Australian tax record keeping rules require it
If you want something removed sooner than that, ask. Where there is no legal reason to keep it, we will remove it.
Seeing and correcting your information
You can ask what we hold about you, ask for a copy of it, and ask us to correct anything that is wrong or out of date. Email us and say what you are after.
We will confirm it is really you before sending anything, which is a protection for you rather than an obstacle. Expect a reply within 30 days. There is no charge, unless a request is unusually large or repeated, in which case we would tell you what it would cost before doing any of it.
If we cannot give you access, or cannot make a correction you have asked for, we will tell you why in writing and what you can do about it.
If the information is inside a client's systems rather than ours, see section 2. The organisation you dealt with is the right place to start, and we will help them answer you.
Complaints
Tell us first. Email us with what happened and what you want done about it. We will acknowledge it, look into it properly, and come back to you within 30 days.
If you are not satisfied with how we handled it, you can take it to the Office of the Australian Information Commissioner. The OAIC asks that you complain to the business first and give it 30 days to respond, which is exactly what the paragraph above is for. Their complaint process is at oaic.gov.au.
Changes to this policy
We update this page when what we do changes. The date at the top is the date of the version you are reading.
If a change materially affects how we handle information we already hold, we will tell clients and subscribers directly, rather than quietly editing the page and treating your next visit as agreement to it.
Ask us
Want to know what we hold about you?
Email and say so. You do not need a reason, you do not need to quote a section of the Act at us, and it costs nothing. We will confirm it is you, then tell you.
PO Box 3209, Nerang QLD 4211
Not happy with how we handled it? You can take a privacy complaint to the Office of the Australian Information Commissioner at oaic.gov.au. They ask that you come to us first and give us 30 days.