Privacy, in plain English
Sfinco is a sole trader, not a data company. This page says exactly what happens to your information when you use this website or get in touch, without the usual wall of legal text.
The enquiry form
The "Enquire about an audit" form on the SMB Cyber Audits page opens your own email app and sends straight to hello@sfinco.com.au. Sfinco doesn't run a database or a server that stores what you type, it lands in the inbox the same way any email would. It's kept there for as long as it's useful for following up, and deleted when it isn't.
No tracking, no cookies
This site doesn't run Google Analytics, advertising pixels, or any other tracking script. Nothing about your visit is collected or sold. If that ever changes, this page will change first.
If you become an SMB Cyber Audit client
An audit involves a closer look at how a business uses technology, which naturally means handling more information than a simple enquiry. That's covered by its own, more detailed client data handling notice, given to every client alongside the engagement agreement, before an audit begins. In short: no passwords or account credentials are ever collected, notes and reports stay on a single, non-networked device, nothing is shared with any third party, and everything is deleted 12 months after the report is delivered unless you ask for it sooner.
Where Sfinco stands under the Privacy Act
As a sole trader with turnover under $3 million, Sfinco most likely falls under the Privacy Act 1988's small business exemption, meaning the Australian Privacy Principles don't strictly apply yet. Sfinco follows the practices on this page regardless of whether the exemption technically covers it, because that's what a client or visitor should reasonably expect, not because a law requires it.
Questions
If anything here is unclear, or you'd like to know what's held about you, corrected, or deleted early, email hello@sfinco.com.au. Same address as everything else.