Our Commitment to Your Privacy
Wildfire Data Recovery Pty Ltd (ABN: 59 655 101 057) is committed to protecting your personal information in accordance with Australian privacy laws. As a data recovery and digital forensics company, we understand the sensitive nature of the information entrusted to us and take our privacy obligations seriously. This policy should be read alongside our Cookie Policy and Terms & Conditions.
About Wildfire Data Recovery
Wildfire Data Recovery is a Brisbane-based data recovery and digital forensics company servicing clients throughout Australia. We specialise in recovering data from damaged, failed, or corrupted storage devices including hard drives, solid-state drives (SSDs), RAID arrays, USB flash drives, memory cards, and mobile devices.
We also provide forensic data recovery services for legal proceedings, insurance claims, and corporate investigations. Our services are used by individuals, businesses, government agencies, legal firms, and law enforcement organisations. Learn more about our team and our recovery process.
Our Details
Business Name: Wildfire Data Recovery Pty Ltd
ABN: 59 655 101 057
Location: Brendale, Queensland 4500, Australia
Website: www.wildfiredata.com.aum.au
Phone: 1300 806 557
Australian Privacy Law Framework
This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained within that Act. These laws regulate how organisations collect, use, store, and disclose personal information.
Key Legislation We Comply With
Privacy Act 1988 (Cth) – The primary legislation governing privacy in Australia
Australian Privacy Principles (APPs) – 13 principles regulating personal information handling
Notifiable Data Breaches (NDB) Scheme – Mandatory reporting of eligible data breaches
Spam Act 2003 (Cth) – Regulation of commercial electronic messages
Do Not Call Register Act 2006 (Cth) – Telemarketing restrictions
The 13 Australian Privacy Principles cover:
APPs 1-2
Open and transparent management of personal information
APPs 3-5
Collection of solicited and unsolicited personal information
APPs 6-7
Use, disclosure, and direct marketing
APP 8
Cross-border disclosure of personal information
APP 9
Adoption, use, or disclosure of government identifiers
APPs 10-11
Quality and security of personal information
APP 12
Access to personal information
APP 13
Correction of personal information
Information We Collect
Under APP 3, we only collect personal information that is reasonably necessary for our data recovery services and business functions. The types of information we collect depend on the nature of your interaction with us.
Sensitive Information
Under APP 3.3, "sensitive information" includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric data. We generally do not collect sensitive information unless it is contained within your recovered data (which we do not access or view) or is necessary for forensic services ordered by a court or legal authority.
How We Collect Your Information
In accordance with APP 3.5, we collect personal information only by lawful and fair means. We primarily collect information directly from you, but may also receive information from third parties in certain circumstances.
Directly From You
When you fill out our enquiry forms, call us, email us, or visit our premises
From Our Website
Automatically through cookies and analytics when you browse our site (see our Cookie Policy)
From Third Parties
Referrals from IT companies, legal firms, insurance companies, or other service providers (with your consent)
Courier Services
Shipping details when you send your device to us via Australia Post, StarTrack, or other carriers
How We Use Your Information
Under APP 6, we only use your personal information for the primary purpose for which it was collected, or for secondary purposes that are directly related and reasonably expected, or with your consent.
What We Will NEVER Do
We will NEVER:
• Sell your personal information to third parties
• Access, view, or copy your recovered data for our own purposes
• Share your information for marketing by unrelated third parties
• Use your recovered data for any purpose other than returning it to you
• Keep copies of your data after you have collected it (unless legally required)
Direct Marketing
Under APP 7, we may use your personal information for direct marketing purposes only if you have consented, or if you would reasonably expect us to use your information for this purpose and we provide an easy opt-out mechanism.
We comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) for all marketing communications.
Marketing We May Send
Service updates, relevant tips for data protection, and information about our data recovery services (only with your consent or to existing customers)
Marketing We Don't Send
We do not send unsolicited marketing to people who have not engaged with us, and we never share your details with third parties for their marketing
Opting Out of Marketing
You can opt out of marketing communications at any time by:
• Clicking the "unsubscribe" link in any marketing email
• Emailing us at privacy@wildfiredata.com.aum.au
• Calling us on 1300 806 557
• Replying "STOP" to any SMS marketing message
We will action your request within 5 business days as required by the Spam Act.
Disclosure of Your Information
Under APP 6, we may disclose your personal information to third parties only for the purposes described in this policy, with your consent, or as required by law.
Cloud Services
Secure Australian-based cloud storage for business records
Australian data centres onlyCross-Border Disclosure
Under APP 8, before disclosing personal information to an overseas recipient, we must take reasonable steps to ensure the recipient complies with the Australian Privacy Principles, or obtain your consent.
Your Data Stays in Australia
Your recovered data never leaves Australia. All data recovery work is performed at our Brisbane facility, and we use Australian-based servers for any digital storage. We do not transfer your recovered files overseas under any circumstances.
However, some of our service providers (such as Google Analytics, payment processors) may store data overseas. Where this occurs:
Your Rights Under APP 8
If we disclose your personal information to an overseas recipient who breaches the APPs, we remain accountable for that breach under Australian law. You can contact us if you have concerns about overseas disclosure, and we will provide details of the specific countries and safeguards involved.
Data Security
Under APP 11, we are required to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Given the sensitive nature of data recovery work, we implement security measures that exceed standard industry requirements.
Physical Security
Secure premises with restricted access, 24/7 CCTV monitoring, alarm systems, and secure storage for client devices
Network Security
Firewalls, intrusion detection systems, encrypted connections (TLS 1.3), and isolated recovery networks
Data Encryption
AES-256 encryption for stored data, encrypted backups, and secure data transfer protocols
Access Controls
Role-based access, strong password policies, multi-factor authentication, and audit logging
Staff Training
Regular privacy and security training, confidentiality agreements, and background checks for all staff
Secure Destruction
DOD-compliant data wiping, physical destruction of media when required, certificates of destruction available
Our Security Credentials
Class 100 ISO Certified Cleanroom – For physical hard drive repairs in contamination-free environment
Chain of Custody Procedures – Full tracking and documentation for forensic cases
Confidentiality Agreements – All staff sign NDAs and confidentiality agreements
Insurance – Professional indemnity and cyber liability insurance coverage
Data Retention & Destruction
Under APP 11.2, we must destroy or de-identify personal information when it is no longer needed for any purpose permitted under the APPs. We have established clear retention periods for different types of information.
Secure Data Destruction
When data is no longer required, we use the following destruction methods:
Digital Data: DOD 5220.22-M compliant multi-pass overwriting, or cryptographic erasure
Physical Media: Degaussing, shredding, or incineration (certificates available on request)
Paper Records: Cross-cut shredding via secure document destruction service
Notifiable Data Breaches (NDB Scheme)
Under the Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988), we are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a data breach is likely to result in serious harm.
Our Data Breach Response
In the unlikely event of a data breach that is likely to result in serious harm, we will:
1. Contain the breach and assess the risk
2. Notify the OAIC within 30 days (or as soon as practicable)
3. Notify affected individuals with details of the breach and recommended steps
4. Take remedial action to prevent future breaches
5. Document the incident and our response
An "eligible data breach" occurs when:
• There is unauthorised access to, disclosure of, or loss of personal information
• A reasonable person would conclude that access/disclosure is likely to result in serious harm
• We have been unable to prevent the likely risk of serious harm through remedial action
Your Rights Under Australian Privacy Law
The Australian Privacy Principles give you specific rights regarding your personal information. We are committed to respecting and facilitating these rights.
Right to Access (APP 12)
You can request access to the personal information we hold about you. We will respond within 30 days.
Right to Correction (APP 13)
You can request correction of any inaccurate, incomplete, or outdated information we hold about you.
Right to Opt-Out
You can opt out of direct marketing at any time by contacting us or using unsubscribe links.
Right to Know
You can ask what information we hold, why we hold it, and to whom we have disclosed it.
Right to Anonymity (APP 2)
Where practicable, you can deal with us anonymously or using a pseudonym (e.g., general enquiries).
Right to Complain
You can lodge a complaint if you believe we have breached the APPs. See Section 14 for details.
How to Make a Request
To exercise any of these rights, contact us at:
Email: privacy@wildfiredata.com.aum.au
Phone: 1300 806 557
Post: Privacy Officer, Wildfire Data Recovery, Brendale QLD 4500
We may need to verify your identity before processing your request. There is generally no fee for access requests, but we may charge a reasonable fee for administrative costs if your request is complex or voluminous.
Information for International Visitors (GDPR)
If you are visiting our website from the European Union (EU), European Economic Area (EEA), or United Kingdom (UK), you may have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR.
Additional Rights for EU/UK Residents
Right to Erasure ("Right to be Forgotten") – Request deletion of your personal data
Right to Restriction – Request we limit how we process your data
Right to Data Portability – Receive your data in a structured, machine-readable format
Right to Object – Object to processing based on legitimate interests
Rights Related to Automated Decision-Making – We do not make automated decisions that significantly affect you
While we are an Australian business primarily serving Australian customers, we respect the privacy rights of all visitors. If you are an EU/UK resident and wish to exercise GDPR rights, please contact our Privacy Officer at privacy@wildfiredata.com.aum.au.
Complaints
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you have the right to lodge a complaint.
Step 1: Contact Us First
We encourage you to contact us first so we can investigate and resolve your concerns. Email privacy@wildfiredata.com.aum.au or call 1300 806 557. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
Step 2: OAIC Complaint
If you are not satisfied with our response, or if we do not respond within 30 days, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Office of the Australian Information Commissioner (OAIC)
The independent regulator for privacy in Australia
GPO Box 5218, Sydney NSW 2001
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:
• We will update the "Last Updated" date at the top of this policy
• For significant changes, we will notify you via email (if we have your email address) or by posting a prominent notice on our website
• We encourage you to review this policy periodically
Your continued use of our services after any changes indicates your acceptance of the updated policy. If you do not agree with changes, you should discontinue using our services and contact us to discuss your concerns.
Contact Us
If you have any questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please contact our Privacy Officer:
Wildfire Data Recovery - Privacy Officer
We're here to help with any privacy-related enquiries
Brendale, Queensland 4500
Australia
Mon-Fri: 8:00 AM - 6:00 PM
Sat: 9:00 AM - 2:00 PM
Ready to Recover Your Data?
If you need help recovering data from a failed or damaged device, we're here to help. Get started today: