Home/Privacy Policy

Privacy Policy

How EG Eloma collects, uses, shares and protects your personal information, in line with the Australian Privacy Principles.

Australian ownedMicrosoft PartnerASD Essential Eight aligned24/7 supportFixed written quotes5 countries

EG Eloma (ABN 76 693 175 012) ("EG Eloma", "we", "us", "our") is an Australian business based at 71 Gipps Street, Collingwood, Melbourne, VIC 3066, Australia. We respect your privacy. This policy explains what personal information we collect, why we collect it, how we use, share and protect it, and how you can access it, correct it or make a complaint.

We are bound by the Privacy Act 1988 (Cth) (the Privacy Act), including the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme. Where they apply to us, we also comply with the privacy laws of the other countries we serve, including the UK General Data Protection Regulation (UK GDPR), the EU GDPR, the New Zealand Privacy Act 2020, Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable US state privacy laws.

Who this policy covers

This policy applies to personal information about visitors to this website, people who contact us or request a quote, our clients and their staff, our suppliers, and job applicants. It does not cover the websites or services of other organisations, including Microsoft, Google and Meta, which have their own privacy policies.

Personal information we collect

  • Contact and identity details, such as your name, job title, business name, email address, phone number and country.
  • Enquiry details, such as your industry, the products you are interested in and anything you tell us in a form, email, chat or call.
  • Client service information, such as administrator contacts, user names and work email addresses of your staff when we set up or manage services like Microsoft 365, support tickets, and the configuration of systems we manage for you.
  • Billing information, such as billing contacts, invoices and payment records. Card payments are handled by our payment provider; we do not store full card numbers.
  • Technical information that our hosting provider records automatically when you visit the website, such as IP address, browser type, date and time, and pages requested. We use these server logs only to keep the website secure and working.
  • Recruitment information, such as your résumé and referee details, if you apply to work with us.

We do not ask for sensitive information (such as health information, racial or ethnic origin, religious beliefs or criminal records). If you give it to us without our asking, we will only keep it if the law allows and we need it; otherwise we will securely delete it. We do not use government identifiers, such as tax file numbers or Medicare numbers, to identify you.

Dealing with us anonymously

You can browse this website without telling us who you are, and you can ask general questions without giving your name or by using a pseudonym. To give you a quote or provide services, we will need your contact details.

How we collect personal information

  • Directly from you, when you fill in our contact form, email, phone or meet us, or use our services and client portal.
  • From your organisation, for example when your manager or IT administrator asks us to set up an account for you.
  • From platforms you authorise us to manage, such as Microsoft 365, Google Ads, Google Business Profile, Google Analytics, Google Search Console, Meta Business Suite and telecommunications carriers.
  • From publicly available sources, such as the Australian Business Register (ABN Lookup) and business websites.

If we receive personal information we did not ask for, we will check whether we could have collected it lawfully. If we could not, we will destroy or de-identify it as soon as practicable.

Cookies, analytics and Google services

This website does not currently use analytics cookies, advertising cookies, tracking pixels or social media plugins, and it does not show ads. Our fonts are hosted on our own website, so loading our pages does not send your IP address to Google Fonts. This website does not set cookies.

If we start using Google Analytics, Google Ads conversion tracking or remarketing, or Google reCAPTCHA, we will:

  • update this policy before we do, and name the tools we use;
  • explain that Google uses cookies and similar technologies to collect and process data, as described in How Google uses information from sites or apps that use its services;
  • ask for your consent before setting non-essential cookies where the law requires it, including for visitors in the UK, European Economic Area and Switzerland, and pass your choice to Google using Google Consent Mode, as Google's EU user consent policy requires;
  • never use remarketing or personalised advertising based on sensitive information.

You can control how Google personalises ads in My Ad Center, block Google Analytics with the Google Analytics opt-out browser add-on, and delete or block cookies in your browser settings.

When we manage your Google, Microsoft or Meta accounts

When you ask us to manage accounts such as Google Ads, Google Business Profile, Google Analytics, Microsoft 365 or Meta Business Suite, we access the data in those accounts only to provide the services you have asked for, under your instructions and our agreement with you. We do not use that data for our own marketing and we do not sell it. The platform provider's own privacy policy applies to the data it processes, for example the Google Privacy Policy and the Microsoft Privacy Statement.

How we use personal information

  • To respond to your enquiry and prepare quotes.
  • To provide, set up, support and improve the services you have asked for.
  • To manage our relationship with you, including billing and account administration.
  • To keep our systems, our clients' systems and this website secure, and to prevent fraud and misuse.
  • To assess job applications.
  • To meet our legal, tax and regulatory obligations.
  • To send you information about our services, only where you have agreed or the law allows (see Direct marketing below).

We only use or disclose personal information for another purpose if you consent, if you would reasonably expect it, or if the Privacy Act otherwise allows it.

Direct marketing

We only send marketing emails or SMS messages with your consent, as required by the Spam Act 2003 (Cth). Every marketing message identifies us and includes a simple way to unsubscribe, and we act on unsubscribe requests within five working days. We do not make marketing calls to numbers on the Do Not Call Register unless the law allows it. You can opt out at any time by using the unsubscribe link or by contacting us. We do not sell or rent marketing lists.

Automated decisions

We do not use computer programs to make decisions about you, using your personal information, that could significantly affect your rights or interests. If that changes, we will update this policy to explain what decisions are made and what information is used, as the Privacy Act will require from 10 December 2026.

Who we share personal information with

  • Service providers who help us run our business, such as website hosting, cloud, email, phone, payment, accounting and IT security providers.
  • Platform providers, when you ask us to act for you, such as Microsoft (licences and Microsoft 365 setup), Google and Meta (advertising and business listings) and telecommunications carriers (phone numbers and number porting).
  • Related companies within Eloma Group that help us deliver our services.
  • Our professional advisers, such as accountants, auditors, lawyers and insurers.
  • Government agencies, regulators, courts or law enforcement, where the law requires or allows it.
  • A buyer or successor of our business, if our business or assets are sold, under confidentiality obligations.

We require our service providers to protect personal information and use it only for the services they provide to us. We do not sell personal information.

Sending information overseas

Some of our service providers and platform providers, including Microsoft, Google and Meta, store or process data outside Australia, including in the United States and other countries where they or our related companies operate. Before we disclose personal information overseas, we take reasonable steps, as required by APP 8, to ensure the recipient handles it consistently with the APPs, for example through contracts and by choosing reputable providers.

How we protect personal information

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include multi-factor authentication, least-privilege access, encryption in transit and at rest where available, regular backups, security monitoring, confidentiality obligations for staff and contractors, and security practices aligned with the ASD Essential Eight. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Data breaches

If we suspect a data breach, we act quickly to contain it and assess the risk. If an eligible data breach is likely to result in serious harm, we will notify the people affected and the Office of the Australian Information Commissioner (OAIC), as required by the Notifiable Data Breaches scheme, and the relevant overseas regulator where the law requires.

How long we keep information

We keep personal information only for as long as we need it for the purposes in this policy or as the law requires. For example, we keep business and tax records for at least five years, as Australian tax law requires. When we no longer need personal information, we securely destroy or de-identify it.

Accessing and correcting your information

You can ask to see the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details below. We will need to confirm your identity, and we will respond within 30 days. There is no charge to make a request. If giving you access involves significant cost, we will tell you about any reasonable charge before we proceed. If we refuse a request, we will explain why in writing, as the Privacy Act allows, and tell you how to complain.

If you are outside Australia

  • UK and European Economic Area: we process personal information to perform a contract with you, for our legitimate interests in running and promoting our business, to meet legal obligations, or with your consent. You can ask to access, correct, delete, restrict or move your information, object to processing, and withdraw consent at any time. You can complain to the UK Information Commissioner's Office or your local data protection authority.
  • New Zealand: you have rights to access and correct your information under the Privacy Act 2020 and can complain to the Office of the Privacy Commissioner.
  • Canada: you can access and correct your information and withdraw consent under PIPEDA, and can complain to the Office of the Privacy Commissioner of Canada.
  • United States: we do not sell personal information or share it for cross-context behavioural advertising. Depending on the state you live in, you may have the right to access, correct or delete your information, and we will not discriminate against you for using these rights.

Children

Our services are for businesses and organisations. This website is not directed at children, and we do not knowingly collect personal information from children under 16. If you believe a child has given us personal information, please contact us and we will delete it.

Complaints

If you have a concern about how we have handled your personal information, please contact our Privacy Officer using the details below. We will acknowledge your complaint promptly, investigate it and give you a written response within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992, or to the privacy regulator in your country.

Changes to this policy

We may update this policy from time to time, for example when the law changes or we start using new tools. The latest version will always be on this page, with the date it was last updated. If we make a significant change, we will tell clients directly.

Contact us

Privacy Officer, EG Eloma (ABN 76 693 175 012)
71 Gipps Street, Collingwood, Melbourne, VIC 3066, Australia
Email: connect@egeloma.com.au
Phone: 1800 054 555

See also our Website Terms of Use.