This Privacy Policy explains how Oday Pty Ltd ("Oday", "we", "us") collects, uses, discloses, and protects your personal information. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Oday Pty Ltd is an Australian-owned cybersecurity company providing AI-powered penetration testing and vulnerability assessment services. Our contact details are:
We collect personal information necessary to provide our services and respond to enquiries. This may include:
We do not collect sensitive personal information (health, financial, or biometric data) in the course of providing cybersecurity services.
We collect information directly from you when you:
We use your personal information to:
We will not use your information for purposes unrelated to those above without your consent.
We do not sell, rent, or trade your personal information. We may share information in limited circumstances:
We do not disclose client identities, engagement details, or security findings to third parties without your written consent.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. Security measures include encrypted communications, access controls, and secure file handling for all engagement deliverables.
Reports and credentials are delivered via secure, encrypted channels. We do not transmit sensitive engagement data over unencrypted email.
We retain personal information for as long as necessary to fulfil the purpose it was collected for, including legal and accounting requirements. Engagement files including reports are retained for 7 years in accordance with standard professional services practice. You may request earlier deletion — see section 9.
We primarily store and process data in Australia. Where we use overseas cloud services (e.g. email infrastructure), we take reasonable steps to ensure those providers maintain security standards consistent with the APPs.
Under the Privacy Act, you have the right to:
To exercise any of these rights, contact us at hello@oday.com.au. We will respond within 30 days.
Our website uses standard web server logs and may in future use analytics tools. We do not currently use third-party advertising cookies. If this changes, this policy will be updated and notice provided.
We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. In the unlikely event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
If you believe we have breached your privacy rights, please contact us first at hello@oday.com.au. If you are not satisfied with our response, you may lodge a complaint with the OAIC at oaic.gov.au.
We may update this policy from time to time. Changes will be posted on this page with an updated "Last Updated" date. Continued use of our services after changes constitutes acceptance.