Legal Document
This Privacy Policy explains how Wildfire Data Recovery collects, uses, stores, and protects your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Last Updated: December 2025
Version: 3.0
Jurisdiction: Australia
Quick Navigation:
About Us
Information We Collect
How We Use It
Data Security
Your Rights
Complaints
Contact Us
Wildfire Data Recovery Pty Ltd (ABN: 59 655 101 057) is committed to protecting your personal information in accordance with Australian privacy laws. As a data recovery and digital forensics company, we understand the sensitive nature of the information entrusted to us and take our privacy obligations seriously. This policy should be read alongside our Cookie Policy and Terms & Conditions.
Wildfire Data Recovery is a Brisbane-based data recovery and digital forensics company servicing clients throughout Australia. We specialise in recovering data from damaged, failed, or corrupted storage devices including hard drives, solid-state drives (SSDs), RAID arrays, USB flash drives, memory cards, and mobile devices.
We also provide forensic data recovery services for legal proceedings, insurance claims, and corporate investigations. Our services are used by individuals, businesses, government agencies, legal firms, and law enforcement organisations. Learn more about our team and our recovery process.
Business Name: Wildfire Data Recovery Pty Ltd
ABN: 59 655 101 057
Location: Brendale, Queensland 4500, Australia
Website: www.wildfiredata.com.aum.au
Phone: 1300 806 557
This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained within that Act. These laws regulate how organisations collect, use, store, and disclose personal information.
Privacy Act 1988 (Cth) – The primary legislation governing privacy in Australia
Australian Privacy Principles (APPs) – 13 principles regulating personal information handling
Notifiable Data Breaches (NDB) Scheme – Mandatory reporting of eligible data breaches
Spam Act 2003 (Cth) – Regulation of commercial electronic messages
Do Not Call Register Act 2006 (Cth) – Telemarketing restrictions
The 13 Australian Privacy Principles cover:
Open and transparent management of personal information
Collection of solicited and unsolicited personal information
Use, disclosure, and direct marketing
Cross-border disclosure of personal information
Adoption, use, or disclosure of government identifiers
Quality and security of personal information
Access to personal information
Correction of personal information
Under APP 3, we only collect personal information that is reasonably necessary for our data recovery services and business functions. The types of information we collect depend on the nature of your interaction with us.
Information that identifies who you are
Data Type
Examples
Why We Collect It
Full Name
First name, surname, title
To identify you and address correspondence correctly
Contact Details
Email, phone number, postal address
To communicate about your job and return your device
Business Details
Company name, ABN, position/role
For business clients, invoicing, and legal compliance
Information about the storage device you submit for recovery
Data Type
Examples
Why We Collect It
Device Details
Make, model, serial number, capacity
To identify and track your device throughout the recovery process
Fault Description
Symptoms, history of failure, physical damage
To diagnose the issue and determine recovery approach
Access Credentials
Passwords, PINs, encryption keys (if provided)
To access encrypted devices for data recovery (stored securely, deleted after job completion)
The actual data we recover from your device
SENSITIVE
Data Type
Examples
Our Approach
Recovered Files
Documents, photos, videos, databases, emails
We do not access, view, or analyse your personal files beyond what is necessary to verify successful recovery
File Metadata
File names, sizes, dates, folder structure
Used only to generate file listings for you to review and confirm recovery success
Information required for payment processing
Data Type
Examples
Security Measures
Payment Details
Credit card (via secure gateway), bank transfer details
We do NOT store full credit card numbers. Payments processed via PCI-DSS compliant payment gateways (Square, PayPal)
Billing Information
Invoices, payment history, ABN
Retained for 7 years as required by Australian tax law (ATO requirements)
Information collected automatically when you visit our website (see our Cookie Policy)
Data Type
Examples
Purpose
IP Address
Your internet protocol address
Security, fraud prevention, and approximate location for analytics
Browser Data
Browser type, version, operating system
To optimise our website for your device and browser
Usage Data
Pages visited, time on site, referral source
To improve our website and understand how visitors find us
Under APP 3.3, “sensitive information” includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric data. We generally do not collect sensitive information unless it is contained within your recovered data (which we do not access or view) or is necessary for forensic services ordered by a court or legal authority.
In accordance with APP 3.5, we collect personal information only by lawful and fair means. We primarily collect information directly from you, but may also receive information from third parties in certain circumstances.
When you fill out our enquiry forms, call us, email us, or visit our premises
Automatically through cookies and analytics when you browse our site (see our Cookie Policy)
Referrals from IT companies, legal firms, insurance companies, or other service providers (with your consent)
Shipping details when you send your device to us via Australia Post, StarTrack, or other carriers
Under APP 6, we only use your personal information for the primary purpose for which it was collected, or for secondary purposes that are directly related and reasonably expected, or with your consent.
The main reasons we collect and use your information
Purpose
Description
Legal Basis (APP)
Service Delivery
To provide data recovery and forensic services you have requested
APP 6.1 – Primary purpose
Communication
To contact you about your job status, provide quotes, and answer enquiries
APP 6.1 – Primary purpose
Billing & Payments
To process payments, issue invoices, and manage accounts
APP 6.1 – Primary purpose
Device Tracking
To track your device through our recovery process and maintain chain of custody
APP 6.1 – Primary purpose
Legal Compliance
To comply with Australian laws, regulations, and court orders
APP 6.2(b) – Required by law
Related purposes you would reasonably expect
Purpose
Description
Legal Basis (APP)
Service Improvement
To improve our services, processes, and website
APP 6.2(a) – Related secondary purpose
Analytics
To analyse website usage and marketing effectiveness (anonymised where possible)
APP 6.2(a) – Related secondary purpose
Feedback Requests
To request reviews or testimonials after service completion
APP 6.2(a) – Related secondary purpose
We will NEVER:
• Sell your personal information to third parties
• Access, view, or copy your recovered data for our own purposes
• Share your information for marketing by unrelated third parties
• Use your recovered data for any purpose other than returning it to you
• Keep copies of your data after you have collected it (unless legally required)
Under APP 7, we may use your personal information for direct marketing purposes only if you have consented, or if you would reasonably expect us to use your information for this purpose and we provide an easy opt-out mechanism.
We comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) for all marketing communications.
Service updates, relevant tips for data protection, and information about our data recovery services (only with your consent or to existing customers)
We do not send unsolicited marketing to people who have not engaged with us, and we never share your details with third parties for their marketing
You can opt out of marketing communications at any time by:
• Clicking the “unsubscribe” link in any marketing email
• Emailing us at privacy@wildfiredata.com.aum.au
• Calling us on 1300 806 557
• Replying “STOP” to any SMS marketing message
We will action your request within 5 business days as required by the Spam Act.
Under APP 6, we may disclose your personal information to third parties only for the purposes described in this policy, with your consent, or as required by law.
Square, PayPal, and banks for payment processing
Australia Post, StarTrack for device shipping
Google Analytics for website analytics (anonymised)
Secure Australian-based cloud storage for business records
Australian data centres only
Circumstances where we may be required to disclose information
Circumstance
Authority
Legal Basis
Court Orders
Australian courts and tribunals
APP 6.2(b) – Required or authorised by law
Law Enforcement
Queensland Police, AFP, other agencies with lawful authority
APP 6.2(e) – Enforcement related activity
Regulatory Bodies
OAIC, ACCC, ATO, ASIC
APP 6.2(b) – Required or authorised by law
Serious Threats
Emergency services, relevant authorities
APP 6.2(c) – Prevent serious threat to life, health, or safety
Under APP 8, before disclosing personal information to an overseas recipient, we must take reasonable steps to ensure the recipient complies with the Australian Privacy Principles, or obtain your consent.
Your recovered data never leaves Australia. All data recovery work is performed at our Brisbane facility, and we use Australian-based servers for any digital storage. We do not transfer your recovered files overseas under any circumstances.
However, some of our service providers (such as Google Analytics, payment processors) may store data overseas. Where this occurs:
Third-party services that may process data overseas
Service
Data Type
Countries
Google Analytics
Website usage (anonymised)
USA, EU – IP anonymisation enabled
Payment Gateways
Payment card data (tokenised)
USA – PCI-DSS Level 1 compliant
Email Services
Email addresses, communications
Australia preferred; USA backup
If we disclose your personal information to an overseas recipient who breaches the APPs, we remain accountable for that breach under Australian law. You can contact us if you have concerns about overseas disclosure, and we will provide details of the specific countries and safeguards involved.
Under APP 11, we are required to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Given the sensitive nature of data recovery work, we implement security measures that exceed standard industry requirements.
Secure premises with restricted access, 24/7 CCTV monitoring, alarm systems, and secure storage for client devices
Firewalls, intrusion detection systems, encrypted connections (TLS 1.3), and isolated recovery networks
AES-256 encryption for stored data, encrypted backups, and secure data transfer protocols
Role-based access, strong password policies, multi-factor authentication, and audit logging
Regular privacy and security training, confidentiality agreements, and background checks for all staff
DOD-compliant data wiping, physical destruction of media when required, certificates of destruction available
Class 100 ISO Certified Cleanroom – For physical hard drive repairs in contamination-free environment
Chain of Custody Procedures – Full tracking and documentation for forensic cases
Confidentiality Agreements – All staff sign NDAs and confidentiality agreements
Insurance – Professional indemnity and cyber liability insurance coverage
Under APP 11.2, we must destroy or de-identify personal information when it is no longer needed for any purpose permitted under the APPs. We have established clear retention periods for different types of information.
How long we keep different types of information
Data Type
Retention Period
Reason
Your Recovered Data
14 days after collection/delivery
Short grace period in case of issues, then securely wiped
Job Records
7 years
Australian tax and business record requirements
Invoices & Financial Records
7 years
ATO requirements under tax law
Forensic Case Files
As directed by client/court
Legal proceedings may require extended retention
Marketing Preferences
Until you opt out + 2 years
To maintain your preferences and suppression lists
Website Analytics
26 months
Google Analytics default retention period
When data is no longer required, we use the following destruction methods:
Digital Data: DOD 5220.22-M compliant multi-pass overwriting, or cryptographic erasure
Physical Media: Degaussing, shredding, or incineration (certificates available on request)
Paper Records: Cross-cut shredding via secure document destruction service
Under the Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988), we are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a data breach is likely to result in serious harm.
In the unlikely event of a data breach that is likely to result in serious harm, we will:
1. Contain the breach and assess the risk
2. Notify the OAIC within 30 days (or as soon as practicable)
3. Notify affected individuals with details of the breach and recommended steps
4. Take remedial action to prevent future breaches
5. Document the incident and our response
An “eligible data breach” occurs when:
• There is unauthorised access to, disclosure of, or loss of personal information
• A reasonable person would conclude that access/disclosure is likely to result in serious harm
• We have been unable to prevent the likely risk of serious harm through remedial action
The Australian Privacy Principles give you specific rights regarding your personal information. We are committed to respecting and facilitating these rights.
You can request access to the personal information we hold about you. We will respond within 30 days.
You can request correction of any inaccurate, incomplete, or outdated information we hold about you.
You can opt out of direct marketing at any time by contacting us or using unsubscribe links.
You can ask what information we hold, why we hold it, and to whom we have disclosed it.
Where practicable, you can deal with us anonymously or using a pseudonym (e.g., general enquiries).
You can lodge a complaint if you believe we have breached the APPs. See Section 14 for details.
To exercise any of these rights, contact us at:
Email: privacy@wildfiredata.com.aum.au
Phone: 1300 806 557
Post: Privacy Officer, Wildfire Data Recovery, Brendale QLD 4500
We may need to verify your identity before processing your request. There is generally no fee for access requests, but we may charge a reasonable fee for administrative costs if your request is complex or voluminous.
If you are visiting our website from the European Union (EU), European Economic Area (EEA), or United Kingdom (UK), you may have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR.
Right to Erasure (“Right to be Forgotten”) – Request deletion of your personal data
Right to Restriction – Request we limit how we process your data
Right to Data Portability – Receive your data in a structured, machine-readable format
Right to Object – Object to processing based on legitimate interests
Rights Related to Automated Decision-Making – We do not make automated decisions that significantly affect you
While we are an Australian business primarily serving Australian customers, we respect the privacy rights of all visitors. If you are an EU/UK resident and wish to exercise GDPR rights, please contact our Privacy Officer at privacy@wildfiredata.com.aum.au.
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you have the right to lodge a complaint.
We encourage you to contact us first so we can investigate and resolve your concerns. Email privacy@wildfiredata.com.aum.au or call 1300 806 557. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, or if we do not respond within 30 days, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
The independent regulator for privacy in Australia
Website
Phone
Online Complaint
Post
GPO Box 5218, Sydney NSW 2001
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:
• We will update the “Last Updated” date at the top of this policy
• For significant changes, we will notify you via email (if we have your email address) or by posting a prominent notice on our website
• We encourage you to review this policy periodically
Your continued use of our services after any changes indicates your acceptance of the updated policy. If you do not agree with changes, you should discontinue using our services and contact us to discuss your concerns.
If you have any questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please contact our Privacy Officer:
We’re here to help with any privacy-related enquiries
Address
Brendale, Queensland 4500
Australia
privacy@wildfiredata.com.aum.au
Phone
Business Hours
Mon-Fri: 8:00 AM – 6:00 PM
Sat: 9:00 AM – 2:00 PM
If you need help recovering data from a failed or damaged device, we’re here to help. Get started today:
Download a copy of this Privacy Policy for your records
—
## **PART 6: JavaScript (Final closing)**
“`html
Your rights, as stated in our privacy policy, are paramount to our operations.
Trust is built upon our adherence to the principles laid out in our privacy policy.
We encourage continuous dialogue regarding our privacy policy to enhance understanding.
Our privacy policy will always be a work in progress as we learn and adapt.
We are committed to ensuring that our privacy policy is effective for all.
Thank you for trusting us with your data as outlined in our privacy policy.
Our privacy policy is always accessible for your review and feedback.
We hope this privacy policy reassures you of our dedication to your data.
Ultimately, our privacy policy serves to protect your interests and rights.
Engagement with our privacy policy is an ongoing process for both parties.
This privacy policy not only complies with regulations but also exceeds expectations.
We aim to maintain transparency in our privacy policy implementation.
Our privacy policy is a living document that evolves with our practices.
This ensures that our privacy policy reflects your expectations and needs.
We are dedicated to following this privacy policy to uphold our values.
In summary, understanding our privacy policy is essential to our partnership.
We encourage clients to engage with us regarding the privacy policy as needed.
Your privacy policy rights are important to us, and we take them seriously.
We will continuously review and improve our privacy policy to meet your needs.
Our privacy policy will guide our interactions with all personal information.
We will ensure that our privacy policy aligns with best practices in the industry.
The principles outlined in our privacy policy reflect our commitment to your data security.
We have taken every measure to ensure that our privacy policy is straightforward and accessible.
Your understanding of our privacy policy aids in fostering a secure relationship between us.
The enforcement of this privacy policy is crucial for maintaining your trust in our services.
We commit to revising our privacy policy regularly, ensuring it remains up-to-date with legal standards.
Please feel free to inquire about our privacy policy if you have any questions or concerns.
We have implemented strict guidelines to adhere to this privacy policy.
Our privacy policy is designed to maintain transparency and trust between us and our clients.
We encourage you to read this privacy policy thoroughly to understand our practices.
This privacy policy details what information we collect and how we use it.
Our comprehensive privacy policy outlines the measures we take to protect your information while using our services.
At Wildfire Data Recovery, we prioritise your privacy policy to ensure that all your personal information is handled with care and respect.