Privacy Policy

Overview

Implicit OT Pty Ltd (ABN: 71 683 125 751) (“we”, “us”, “our”) is committed to protecting the privacy of individuals who interact with our website and services. This Privacy Policy describes how we collect, use, disclose, and manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

By using our website at implicitot.com (including any associated domains such as implicitot.com.au) or engaging with our services, you agree to the collection and use of information in accordance with this policy.

If you have any questions about this policy or how we handle your personal information, please contact us at [email protected]

Information we collect

We collect personal information only where necessary for our business functions. The types of personal information we may collect include:

  • Contact details — name, email address, phone number, job title, and organisation
  • Enquiry and consultation information — details you provide when submitting a contact form or booking a consultation
  • Newsletter subscription details — email address if you subscribe to Thursday Thoughts or other communications
  • Website usage information — browser type, pages visited, time and date of visit, IP address and general location (via analytics tools and server logs)
  • Communications — content of emails or messages you send us

We do not collect sensitive information (as defined under the Privacy Act) unless you voluntarily provide it and we have a lawful reason to collect it. Where we do collect sensitive information (for example, information related to security clearances for certain defence‑related engagements), we treat it with heightened care and only use it for the specific permitted purpose.

How we use your information

We use personal information only for the purposes for which it was collected, or for directly related purposes, including:

  • Responding to enquiries and consultation requests
  • Delivering services we have been engaged to provide
  • Sending Thursday Thoughts and other communications you have opted into
  • Improving our website and understanding how it is used (in aggregate)
  • Complying with legal and regulatory obligations
  • Maintaining records of our professional engagements

We will not use your personal information for a purpose you would not reasonably expect, and we will not use it for direct marketing without your consent.

Implicit OT does not currently use automated decision‑making processes that produce legal effects or similarly significant effects on individuals. Our services are delivered by qualified human consultants, and all assessments, risk ratings, and recommendations are subject to professional review before being communicated to clients. Where we use analytical tools to process technical data (for example, network scanning or vulnerability assessment tools), the outputs are reviewed by our consultants before any decisions or recommendations are made. If this changes in future, we will update this policy to explain any automated decision‑making that significantly affects individuals, in line with changes to Australian privacy law.

Disclosure of personal information

We do not sell, rent, or share personal information with third parties for their own marketing purposes.

We may disclose personal information to:

  • Our service providers — including cloud hosting, email platform, and analytics providers — who process data on our behalf under confidentiality and data protection obligations
  • Professional advisors — such as legal, accounting, or insurance advisors — where necessary
  • Subcontractors and consultants — where required to deliver services under a contract and subject to confidentiality
  • Law enforcement or regulatory bodies — where required or authorised by Australian law
  • A prospective purchaser or investor — in connection with a business sale or restructuring, subject to confidentiality protections

Where we engage third‑party service providers, we take reasonable steps to ensure they handle your information in accordance with Australian privacy law.

Some of our service providers are likely to be located overseas, including in the United States and European Union (for example, cloud and email platforms such as Microsoft 365 and associated services). Before disclosing personal information to overseas recipients, we take reasonable steps to ensure they handle information consistently with the APPs, including through contractual privacy commitments and data processing agreements. Individuals are notified of this possibility through this Policy. By using our website and services, you consent to your information being processed in these jurisdictions, where privacy protections may differ from Australia.

Security

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. These measures include access controls, encrypted transmission (HTTPS/TLS), and limiting access to personal information to those who need it for their role.

No method of transmission over the internet or electronic storage is completely secure. While we strive to protect your personal information, we cannot guarantee absolute security.

If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will assess the incident and, where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act.

If you become aware of any security incident involving your personal information, please contact us immediately at [email protected]

Retention

We retain personal information for as long as necessary to fulfil the purpose for which it was collected, and to meet our legal, regulatory, and business obligations. When personal information is no longer required, we take reasonable steps to destroy or de‑identify it.

Professional engagement records (for example, client contact details and associated deliverables) may be retained for up to seven years in line with standard business record‑keeping and tax requirements. Certain records (such as WHS incident records or security clearance‑related records) may be retained for longer where required by law or contractual obligations.

Your rights

Under the Privacy Act 1988 and the Australian Privacy Principles, you have the right to:

  • Access personal information we hold about you
  • Request correction of personal information that is inaccurate, incomplete, or out of date
  • Make a complaint if you believe we have handled your personal information in a way that does not comply with the APPs
  • Opt out of receiving marketing communications at any time

To exercise any of these rights, contact us at [email protected].We will respond to access and correction requests within 30 days. We may need to verify your identity before processing a request.

In some cases, we may lawfully refuse access or correction (for example, where providing access would pose a serious threat to the life, health, or safety of any person, have an unreasonable impact on the privacy of others, or relate to existing or anticipated legal proceedings). If we refuse a request, we will provide reasons and explain your options, including your right to complain to the OAIC.

If you are not satisfied with our response to a complaint, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

Cookies and analytics

Our website may use cookies and similar technologies to improve your experience and analyse how our site is used. Cookies are small text files stored on your device.

We use analytics cookies (for example, Google Analytics with IP anonymisation) to understand site traffic and page performance. These tools may collect information such as your IP address, browser type, pages visited, and time spent on the site. This information is used in aggregate and is not used to identify you personally except where necessary for security purposes (for example, detecting malicious activity).

You can configure your browser to refuse cookies or to alert you when cookies are being sent. If you disable cookies, some features of our website may not function correctly.

We do not use advertising or tracking cookies for marketing or cross‑site targeted advertising.

Third‑party links

Our website may contain links to third‑party websites, including LinkedIn and other external resources. We are not responsible for the privacy practices or content of those sites and encourage you to review their privacy policies before providing any personal information.

Contact us

For any questions, concerns, or requests relating to this Privacy Policy or the personal information we hold, please contact:

Implicit OT Pty Ltd
Privacy enquiries: [email protected]
General enquiries: [email protected]

We aim to acknowledge all privacy enquiries within 5 business days and resolve them within 30 business days.

This policy may be updated from time to time. Any changes will be published on this page with an updated date. Continued use of our website following such changes constitutes your acceptance of the updated policy.