Privacy by governance, not afterthought.
Effective 30 August 2026. This policy describes how Cyber Security Agency Australia Pty Ltd handles personal information associated with this public digital headquarters and related corporate correspondence.
1. Purpose and scope
This policy applies to personal information collected through cs-agency.com.au, direct corporate correspondence, approved research or engagement enquiries, and other interactions expressly linked to this policy. It does not automatically govern the separate privacy practices of WARDALE, Solurius, AUTTO Connect, CSiA or third-party services where a separate notice applies.
2. Information we may collect
Depending on how you interact with CSA, we may receive your name, organisation, professional role, email address, telephone number, correspondence, enquiry details, technical information about use of the website, and other information you voluntarily provide. The public website is designed to minimise unnecessary collection.
3. How we use information
We may use information to respond to enquiries, manage institutional relationships, operate and secure the website, investigate incidents, maintain records, improve our systems, conduct approved research or engagement activity, comply with legal obligations, and protect CSA, its stakeholders and the integrity of its services.
4. AI and automated processing
CSA develops and uses intelligent systems. Where personal information is used in an AI-assisted or automated process, CSA aims to apply purpose limitation, human accountability, security, evidence and governance proportionate to the decision and risk. Material automated decision-making affecting rights or interests will be addressed through the applicable product or service notice and control framework.
5. Service providers and overseas processing
CSA may use cloud, communications, security, development, analytics or other service providers located in Australia, the United States or other jurisdictions. Where personal information is disclosed or processed through such providers, CSA applies contractual, technical and governance controls appropriate to the information and relationship. Provider use does not imply endorsement or partnership beyond the actual service relationship.
6. Security and retention
CSA applies administrative, technical and organisational safeguards designed to protect information against unauthorised access, misuse, loss, alteration or disclosure. Information is retained only for as long as reasonably required for the relevant purpose, legal obligation, security need, evidence requirement or approved record-keeping function.
7. Cookies, logs and analytics
The site may use essential technical storage, security logs and limited analytics needed to operate, protect and understand the website. If CSA introduces non-essential advertising or tracking technologies, the relevant disclosures and consent controls will be updated before those technologies are enabled where required.
8. Access, correction and privacy enquiries
You may request access to or correction of personal information held by CSA, or raise a privacy concern, by contacting info@cs-agency.com.au. We may need to verify identity before acting on a request.
9. Changes
CSA may update this policy as its systems, legal obligations and operating environments evolve. The effective date will be updated when material changes are published.
10. Contact
Cyber Security Agency Australia Pty Ltd
ABN 89 659 238 570 · ACN 659 238 570
Brisbane, Queensland, Australia
North America Office: 30 Wall Street, 8th Floor, New York, NY 10005, United States
info@cs-agency.com.au