Skip to main content
24/7 emergency lineFree diagnosis on eligible standard recoveriesFREE Postage Label — Australia-wide
WildfireData Recovery




Legal Document

Privacy Policy

This Privacy Policy explains how Wildfire Data Recovery collects, uses, stores, and protects your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Last Updated: December 2025
Version: 3.0
Jurisdiction: Australia

Quick Navigation:
About Us
Information We Collect
How We Use It
Data Security
Your Rights
Complaints
Contact Us

Our Commitment to Your Privacy

Wildfire Data Recovery Pty Ltd (ABN: 59 655 101 057) is committed to protecting your personal information in accordance with Australian privacy laws. As a data recovery and digital forensics company, we understand the sensitive nature of the information entrusted to us and take our privacy obligations seriously. This policy should be read alongside our Cookie Policy and Terms & Conditions.

01

About Wildfire Data Recovery

Wildfire Data Recovery is a Brisbane-based data recovery and digital forensics company servicing clients throughout Australia. We specialise in recovering data from damaged, failed, or corrupted storage devices including hard drives, solid-state drives (SSDs), RAID arrays, USB flash drives, memory cards, and mobile devices.

We also provide forensic data recovery services for legal proceedings, insurance claims, and corporate investigations. Our services are used by individuals, businesses, government agencies, legal firms, and law enforcement organisations. Learn more about our team and our recovery process.

Our Details

Business Name: Wildfire Data Recovery Pty Ltd

ABN: 59 655 101 057

Location: Brendale, Queensland 4500, Australia

Website: www.wildfiredata.com.aum.au

Phone: 1300 806 557

02

Australian Privacy Law Framework

This Privacy Policy is governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained within that Act. These laws regulate how organisations collect, use, store, and disclose personal information.

Key Legislation We Comply With

Privacy Act 1988 (Cth) – The primary legislation governing privacy in Australia
Australian Privacy Principles (APPs) – 13 principles regulating personal information handling
Notifiable Data Breaches (NDB) Scheme – Mandatory reporting of eligible data breaches
Spam Act 2003 (Cth) – Regulation of commercial electronic messages
Do Not Call Register Act 2006 (Cth) – Telemarketing restrictions

The 13 Australian Privacy Principles cover:

APPs 1-2

Open and transparent management of personal information

APPs 3-5

Collection of solicited and unsolicited personal information

APPs 6-7

Use, disclosure, and direct marketing

APP 8

Cross-border disclosure of personal information

APP 9

Adoption, use, or disclosure of government identifiers

APPs 10-11

Quality and security of personal information

APP 12

Access to personal information

APP 13

Correction of personal information

03

Information We Collect

Under APP 3, we only collect personal information that is reasonably necessary for our data recovery services and business functions. The types of information we collect depend on the nature of your interaction with us.

Identity Information

Information that identifies who you are

Data Type
Examples
Why We Collect It
Full Name
First name, surname, title
To identify you and address correspondence correctly
Contact Details
Email, phone number, postal address
To communicate about your job and return your device
Business Details
Company name, ABN, position/role
For business clients, invoicing, and legal compliance

Device & Media Information

Information about the storage device you submit for recovery

Data Type
Examples
Why We Collect It
Device Details
Make, model, serial number, capacity
To identify and track your device throughout the recovery process
Fault Description
Symptoms, history of failure, physical damage
To diagnose the issue and determine recovery approach
Access Credentials
Passwords, PINs, encryption keys (if provided)
To access encrypted devices for data recovery (stored securely, deleted after job completion)

Content Data (Your Recovered Files)

The actual data we recover from your device

SENSITIVE
Data Type
Examples
Our Approach
Recovered Files
Documents, photos, videos, databases, emails
We do not access, view, or analyse your personal files beyond what is necessary to verify successful recovery
File Metadata
File names, sizes, dates, folder structure
Used only to generate file listings for you to review and confirm recovery success

Financial Information

Information required for payment processing

Data Type
Examples
Security Measures
Payment Details
Credit card (via secure gateway), bank transfer details
We do NOT store full credit card numbers. Payments processed via PCI-DSS compliant payment gateways (Square, PayPal)
Billing Information
Invoices, payment history, ABN
Retained for 7 years as required by Australian tax law (ATO requirements)

Technical & Usage Data

Information collected automatically when you visit our website (see our Cookie Policy)

Data Type
Examples
Purpose
IP Address
Your internet protocol address
Security, fraud prevention, and approximate location for analytics
Browser Data
Browser type, version, operating system
To optimise our website for your device and browser
Usage Data
Pages visited, time on site, referral source
To improve our website and understand how visitors find us

Sensitive Information

Under APP 3.3, “sensitive information” includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record, and biometric data. We generally do not collect sensitive information unless it is contained within your recovered data (which we do not access or view) or is necessary for forensic services ordered by a court or legal authority.

04

How We Collect Your Information

In accordance with APP 3.5, we collect personal information only by lawful and fair means. We primarily collect information directly from you, but may also receive information from third parties in certain circumstances.

Directly From You

When you fill out our enquiry forms, call us, email us, or visit our premises

From Our Website

Automatically through cookies and analytics when you browse our site (see our Cookie Policy)

From Third Parties

Referrals from IT companies, legal firms, insurance companies, or other service providers (with your consent)

Courier Services

Shipping details when you send your device to us via Australia Post, StarTrack, or other carriers

05

How We Use Your Information

Under APP 6, we only use your personal information for the primary purpose for which it was collected, or for secondary purposes that are directly related and reasonably expected, or with your consent.

Primary Purposes

The main reasons we collect and use your information

Purpose
Description
Legal Basis (APP)
Service Delivery
To provide data recovery and forensic services you have requested
APP 6.1 – Primary purpose
Communication
To contact you about your job status, provide quotes, and answer enquiries
APP 6.1 – Primary purpose
Billing & Payments
To process payments, issue invoices, and manage accounts
APP 6.1 – Primary purpose
Device Tracking
To track your device through our recovery process and maintain chain of custody
APP 6.1 – Primary purpose
Legal Compliance
To comply with Australian laws, regulations, and court orders
APP 6.2(b) – Required by law

Secondary Purposes

Related purposes you would reasonably expect

Purpose
Description
Legal Basis (APP)
Service Improvement
To improve our services, processes, and website
APP 6.2(a) – Related secondary purpose
Analytics
To analyse website usage and marketing effectiveness (anonymised where possible)
APP 6.2(a) – Related secondary purpose
Feedback Requests
To request reviews or testimonials after service completion
APP 6.2(a) – Related secondary purpose

What We Will NEVER Do

We will NEVER:
• Sell your personal information to third parties
• Access, view, or copy your recovered data for our own purposes
• Share your information for marketing by unrelated third parties
• Use your recovered data for any purpose other than returning it to you
• Keep copies of your data after you have collected it (unless legally required)

06

Direct Marketing

Under APP 7, we may use your personal information for direct marketing purposes only if you have consented, or if you would reasonably expect us to use your information for this purpose and we provide an easy opt-out mechanism.

We comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) for all marketing communications.

Marketing We May Send

Service updates, relevant tips for data protection, and information about our data recovery services (only with your consent or to existing customers)

Marketing We Don’t Send

We do not send unsolicited marketing to people who have not engaged with us, and we never share your details with third parties for their marketing

Opting Out of Marketing

You can opt out of marketing communications at any time by:

• Clicking the “unsubscribe” link in any marketing email
• Emailing us at privacy@wildfiredata.com.aum.au
• Calling us on 1300 806 557
• Replying “STOP” to any SMS marketing message

We will action your request within 5 business days as required by the Spam Act.

07

Disclosure of Your Information

Under APP 6, we may disclose your personal information to third parties only for the purposes described in this policy, with your consent, or as required by law.

Payment Processors

Square, PayPal, and banks for payment processing

Square Privacy Policy

Courier Services

Australia Post, StarTrack for device shipping

Australia Post Privacy

Analytics Providers

Google Analytics for website analytics (anonymised)

Google Privacy Policy

Cloud Services

Secure Australian-based cloud storage for business records

Australian data centres only

Legal Disclosures

Circumstances where we may be required to disclose information

Circumstance
Authority
Legal Basis
Court Orders
Australian courts and tribunals
APP 6.2(b) – Required or authorised by law
Law Enforcement
Queensland Police, AFP, other agencies with lawful authority
APP 6.2(e) – Enforcement related activity
Regulatory Bodies
OAIC, ACCC, ATO, ASIC
APP 6.2(b) – Required or authorised by law
Serious Threats
Emergency services, relevant authorities
APP 6.2(c) – Prevent serious threat to life, health, or safety

08

Cross-Border Disclosure

Under APP 8, before disclosing personal information to an overseas recipient, we must take reasonable steps to ensure the recipient complies with the Australian Privacy Principles, or obtain your consent.

Your Data Stays in Australia

Your recovered data never leaves Australia. All data recovery work is performed at our Brisbane facility, and we use Australian-based servers for any digital storage. We do not transfer your recovered files overseas under any circumstances.

However, some of our service providers (such as Google Analytics, payment processors) may store data overseas. Where this occurs:

Overseas Service Providers

Third-party services that may process data overseas

Service
Data Type
Countries
Google Analytics
Website usage (anonymised)
USA, EU – IP anonymisation enabled
Payment Gateways
Payment card data (tokenised)
USA – PCI-DSS Level 1 compliant
Email Services
Email addresses, communications
Australia preferred; USA backup

Your Rights Under APP 8

If we disclose your personal information to an overseas recipient who breaches the APPs, we remain accountable for that breach under Australian law. You can contact us if you have concerns about overseas disclosure, and we will provide details of the specific countries and safeguards involved.

09

Data Security

Under APP 11, we are required to take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Given the sensitive nature of data recovery work, we implement security measures that exceed standard industry requirements.

Physical Security

Secure premises with restricted access, 24/7 CCTV monitoring, alarm systems, and secure storage for client devices

Network Security

Firewalls, intrusion detection systems, encrypted connections (TLS 1.3), and isolated recovery networks

Data Encryption

AES-256 encryption for stored data, encrypted backups, and secure data transfer protocols

Access Controls

Role-based access, strong password policies, multi-factor authentication, and audit logging

Staff Training

Regular privacy and security training, confidentiality agreements, and background checks for all staff

Secure Destruction

DOD-compliant data wiping, physical destruction of media when required, certificates of destruction available

Our Security Credentials

Class 100 ISO Certified Cleanroom – For physical hard drive repairs in contamination-free environment
Chain of Custody Procedures – Full tracking and documentation for forensic cases
Confidentiality Agreements – All staff sign NDAs and confidentiality agreements
Insurance – Professional indemnity and cyber liability insurance coverage

10

Data Retention & Destruction

Under APP 11.2, we must destroy or de-identify personal information when it is no longer needed for any purpose permitted under the APPs. We have established clear retention periods for different types of information.

Retention Periods

How long we keep different types of information

Data Type
Retention Period
Reason
Your Recovered Data
14 days after collection/delivery
Short grace period in case of issues, then securely wiped
Job Records
7 years
Australian tax and business record requirements
Invoices & Financial Records
7 years
ATO requirements under tax law
Forensic Case Files
As directed by client/court
Legal proceedings may require extended retention
Marketing Preferences
Until you opt out + 2 years
To maintain your preferences and suppression lists
Website Analytics
26 months
Google Analytics default retention period

Secure Data Destruction

When data is no longer required, we use the following destruction methods:

Digital Data: DOD 5220.22-M compliant multi-pass overwriting, or cryptographic erasure
Physical Media: Degaussing, shredding, or incineration (certificates available on request)
Paper Records: Cross-cut shredding via secure document destruction service

11

Notifiable Data Breaches (NDB Scheme)

Under the Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988), we are required to notify the Office of the Australian Information Commissioner (OAIC) and affected individuals if a data breach is likely to result in serious harm.

Our Data Breach Response

In the unlikely event of a data breach that is likely to result in serious harm, we will:

1. Contain the breach and assess the risk
2. Notify the OAIC within 30 days (or as soon as practicable)
3. Notify affected individuals with details of the breach and recommended steps
4. Take remedial action to prevent future breaches
5. Document the incident and our response

An “eligible data breach” occurs when:
• There is unauthorised access to, disclosure of, or loss of personal information
• A reasonable person would conclude that access/disclosure is likely to result in serious harm
• We have been unable to prevent the likely risk of serious harm through remedial action

12

Your Rights Under Australian Privacy Law

The Australian Privacy Principles give you specific rights regarding your personal information. We are committed to respecting and facilitating these rights.

Right to Access (APP 12)

You can request access to the personal information we hold about you. We will respond within 30 days.

Right to Correction (APP 13)

You can request correction of any inaccurate, incomplete, or outdated information we hold about you.

Right to Opt-Out

You can opt out of direct marketing at any time by contacting us or using unsubscribe links.

Right to Know

You can ask what information we hold, why we hold it, and to whom we have disclosed it.

Right to Anonymity (APP 2)

Where practicable, you can deal with us anonymously or using a pseudonym (e.g., general enquiries).

Right to Complain

You can lodge a complaint if you believe we have breached the APPs. See Section 14 for details.

How to Make a Request

To exercise any of these rights, contact us at:

Email: privacy@wildfiredata.com.aum.au
Phone: 1300 806 557
Post: Privacy Officer, Wildfire Data Recovery, Brendale QLD 4500

We may need to verify your identity before processing your request. There is generally no fee for access requests, but we may charge a reasonable fee for administrative costs if your request is complex or voluminous.

13

Information for International Visitors (GDPR)

If you are visiting our website from the European Union (EU), European Economic Area (EEA), or United Kingdom (UK), you may have additional rights under the General Data Protection Regulation (GDPR) or UK GDPR.

Additional Rights for EU/UK Residents

Right to Erasure (“Right to be Forgotten”) – Request deletion of your personal data
Right to Restriction – Request we limit how we process your data
Right to Data Portability – Receive your data in a structured, machine-readable format
Right to Object – Object to processing based on legitimate interests
Rights Related to Automated Decision-Making – We do not make automated decisions that significantly affect you

While we are an Australian business primarily serving Australian customers, we respect the privacy rights of all visitors. If you are an EU/UK resident and wish to exercise GDPR rights, please contact our Privacy Officer at privacy@wildfiredata.com.aum.au.

14

Complaints

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, you have the right to lodge a complaint.

Step 1: Contact Us First

We encourage you to contact us first so we can investigate and resolve your concerns. Email privacy@wildfiredata.com.aum.au or call 1300 806 557. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.

Step 2: OAIC Complaint

If you are not satisfied with our response, or if we do not respond within 30 days, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC).

Office of the Australian Information Commissioner (OAIC)

The independent regulator for privacy in Australia

Website

www.oaic.gov.au

Phone

1300 363 992

Online Complaint

Lodge a complaint online

Post

GPO Box 5218, Sydney NSW 2001

15

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. When we make changes:

• We will update the “Last Updated” date at the top of this policy
• For significant changes, we will notify you via email (if we have your email address) or by posting a prominent notice on our website
• We encourage you to review this policy periodically

Your continued use of our services after any changes indicates your acceptance of the updated policy. If you do not agree with changes, you should discontinue using our services and contact us to discuss your concerns.

16

Contact Us

If you have any questions about this Privacy Policy, our privacy practices, or wish to exercise your rights, please contact our Privacy Officer:

Wildfire Data Recovery – Privacy Officer

We’re here to help with any privacy-related enquiries

Address

Brendale, Queensland 4500
Australia

Email

privacy@wildfiredata.com.aum.au

Phone

1300 806 557

Business Hours

Mon-Fri: 8:00 AM – 6:00 PM
Sat: 9:00 AM – 2:00 PM

Ready to Recover Your Data?

If you need help recovering data from a failed or damaged device, we’re here to help. Get started today:

Get a Free Quote
View Our Services

Related Policies


Cookie Policy


Terms & Conditions


Our Services


Download a copy of this Privacy Policy for your records


## **PART 6: JavaScript (Final closing)**
“`html

Your rights, as stated in our privacy policy, are paramount to our operations.

Trust is built upon our adherence to the principles laid out in our privacy policy.

We encourage continuous dialogue regarding our privacy policy to enhance understanding.

Our privacy policy will always be a work in progress as we learn and adapt.

We are committed to ensuring that our privacy policy is effective for all.

Thank you for trusting us with your data as outlined in our privacy policy.

Our privacy policy is always accessible for your review and feedback.

We hope this privacy policy reassures you of our dedication to your data.

Ultimately, our privacy policy serves to protect your interests and rights.

Engagement with our privacy policy is an ongoing process for both parties.

This privacy policy not only complies with regulations but also exceeds expectations.

We aim to maintain transparency in our privacy policy implementation.

Our privacy policy is a living document that evolves with our practices.

This ensures that our privacy policy reflects your expectations and needs.

We are dedicated to following this privacy policy to uphold our values.

In summary, understanding our privacy policy is essential to our partnership.

We encourage clients to engage with us regarding the privacy policy as needed.

Your privacy policy rights are important to us, and we take them seriously.

We will continuously review and improve our privacy policy to meet your needs.

Our privacy policy will guide our interactions with all personal information.

We will ensure that our privacy policy aligns with best practices in the industry.

The principles outlined in our privacy policy reflect our commitment to your data security.

We have taken every measure to ensure that our privacy policy is straightforward and accessible.

Your understanding of our privacy policy aids in fostering a secure relationship between us.

The enforcement of this privacy policy is crucial for maintaining your trust in our services.

We commit to revising our privacy policy regularly, ensuring it remains up-to-date with legal standards.

Please feel free to inquire about our privacy policy if you have any questions or concerns.

We have implemented strict guidelines to adhere to this privacy policy.

Our privacy policy is designed to maintain transparency and trust between us and our clients.

We encourage you to read this privacy policy thoroughly to understand our practices.

This privacy policy details what information we collect and how we use it.

Our comprehensive privacy policy outlines the measures we take to protect your information while using our services.

At Wildfire Data Recovery, we prioritise your privacy policy to ensure that all your personal information is handled with care and respect.