GOVERNANCE
Privacy Policy
PRIVACY POLICY
Spectrum Data Systems International (SDSI)
Effective date: 5 September 2026
1. About this policy
Spectrum Data Systems International (SDSI) ACN 096 657 804, is committed to managing personal information openly, responsibly and securely. In this policy, 'SDSI', 'we', 'us' and 'our' refer to that company.
This policy explains how SDSI collects, holds, uses and discloses personal information, and how an individual may request access or correction or make a privacy complaint. It applies to the SDSI website and to business dealings in which SDSI controls personal information.
SDSI manages personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and any other privacy obligations that apply to its activities.
2. Customer-controlled operational information
SDSI supplies, integrates and supports mission-critical systems for emergency-service and public-safety organisations. Where SDSI handles personal information solely on behalf of a customer under a contract, the customer generally determines why and how that information is handled. SDSI handles that information only as authorised by the customer, the relevant contract and applicable law.
Requests concerning personal information held within a customer's operational system should normally be directed to that customer or agency. SDSI will assist the customer where required. SDSI does not use customer-controlled operational information for its own marketing purposes.
3. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It includes information whether or not it is true and whether or not it is recorded in a material form.
4. Personal information SDSI collects and holds
Depending on the relationship and circumstances, SDSI may collect and hold:
- identity and contact information, such as a name, business address, email address and telephone number
- professional and business information, such as an organisation, position and areas of responsibility
- enquiries, correspondence, meeting notes and records of communications
- customer, supplier and partner contact information and relationship records
- support and service information, including service requests and authorised-user details
- website and technical information, such as IP address, device and browser details, page interactions, timestamps, cookies and similar technologies
- privacy preferences and records of requests, complaints or consents, and
- other information an individual chooses to provide to SDSI.
5. Sensitive and operationally sensitive information
SDSI does not ask visitors to provide sensitive information through its public website. The contact form is not intended for patient information, clinical information, incident records, passwords, security credentials or operationally sensitive information. Visitors should not submit that information through the website or ordinary email.
Where SDSI handles sensitive or operational information on behalf of a customer, it does so under the customer's authority, the applicable contract and relevant law.
6. How SDSI collects personal information
SDSI may collect personal information:
- directly from an individual through the website contact form, email, telephone, meetings or other communications
- automatically when an individual uses the website, through cookies, server logs, analytics and similar technologies
- from the individual's employer, agency or authorised representative
- from customers, suppliers, business partners and professional advisers, and
- from publicly available sources such as professional directories, public registers and business networking platforms.
Where reasonable and practicable, SDSI collects personal information directly from the individual. If SDSI receives unsolicited personal information that it could not lawfully have collected, it will destroy or de-identify that information where lawful and reasonable to do so.
7. Why SDSI handles personal information
SDSI may collect, hold, use and disclose personal information to:
- respond to enquiries and communicate with individuals
- provide, implement, integrate, maintain and support products and services
- manage customer, supplier, partner and professional relationships
- prepare proposals, administer contracts, issue invoices and meet procurement obligations
- operate, secure, monitor and improve SDSI's website, systems, services and business processes
- manage demonstrations, events and requested business communications
- prevent, investigate and respond to security incidents, fraud, misuse or legal claims, and
- meet legal, regulatory, insurance, audit, contractual and governance obligations.
SDSI will not use or disclose personal information for an unrelated secondary purpose unless the individual has consented or the use or disclosure is otherwise authorised by law.
8. Who SDSI may disclose personal information to
Where reasonably necessary, SDSI may disclose personal information to:
- authorised SDSI personnel and contractors
- customers, product vendors, integration partners and delivery partners involved in an authorised engagement
- website hosting, cloud, email, communications, analytics, security, storage, support and other technology providers
- banks, accounting and administrative service providers
- insurers, auditors, lawyers and other professional advisers
- regulators, courts, tribunals, law-enforcement bodies and government agencies where required or authorised by law, and
- a prospective purchaser or adviser in connection with a proposed corporate transaction, subject to appropriate confidentiality controls.
SDSI does not sell or rent personal information. SDSI expects service providers and contractors to handle personal information only for authorised purposes and with appropriate safeguards.
9. Overseas disclosures
SDSI uses website, cloud, email, analytics, communications, security and support providers that may operate outside Australia or use overseas personnel or subprocessors. Personal information may therefore be disclosed to recipients in regions including North America, Europe, the Middle East and the Asia-Pacific. The locations used by global providers may change and it may not always be practicable to specify every country.
Before disclosing personal information to an overseas recipient, SDSI will take the reasonable steps required by APP 8 to ensure the recipient does not breach the APPs in relation to that information, unless an applicable exception applies. Further information about likely overseas locations may be requested from the Privacy Officer.
10. Website, cookies and analytics
The SDSI website uses essential technologies needed to operate and secure the site. It may also use analytics cookies or similar technologies to understand website use and improve content and performance. These technologies may collect a visitor's IP address, device and browser information, pages visited, interactions and timestamps.
Where a cookie preference tool is displayed, visitors can use it to accept, reject or change preferences for non-essential cookies. Disabling some technologies may affect website functionality. Embedded content, such as video or maps, may be supplied by third parties and may be unavailable until the relevant consent is provided.
The website may contain links to third-party websites. SDSI is not responsible for those organisations' privacy practices, and visitors should review their privacy information separately.
11. Business communications
SDSI does not use the website contact form to enrol visitors in marketing communications without a separate choice. SDSI may send relevant business communications where an individual has requested them, consented to receive them or would reasonably expect them and the law permits it. Any applicable marketing communication will provide a simple way to unsubscribe. An individual may also opt out by emailing info@sdsi.com.au.
12. Security and retention
SDSI takes reasonable technical, organisational and physical steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Safeguards may include access controls, authentication, encryption where appropriate, monitoring, secure backups, staff training, confidentiality obligations and supplier assurance.
SDSI retains personal information only for as long as reasonably needed for the purpose for which it was collected, or as required by law, contract, insurance, audit or legitimate recordkeeping obligations. When information is no longer required, SDSI takes reasonable steps to destroy it securely or de-identify it.
No internet transmission or storage method can be guaranteed to be completely secure. Visitors should not send passwords, security credentials, patient data or operationally sensitive information through ordinary email or the public website unless SDSI has provided an approved secure channel.
13. Access and correction
An individual may request access to personal information SDSI holds about them or ask SDSI to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. A request can be made using the contact details below. SDSI may ask for reasonable evidence of identity before acting on a request.
SDSI will respond within a reasonable period. SDSI does not charge for making an access or correction request. Where permitted by law, SDSI may charge reasonable costs for providing access after giving advance notice. If SDSI refuses access or correction, it will provide written reasons where required and explain available complaint avenues.
14. Privacy complaints
An individual who believes SDSI has breached the APPs or otherwise mishandled their personal information may make a complaint to the Privacy Officer using the contact details below. The complaint should describe the issue, the outcome sought and enough information for SDSI to investigate it.
SDSI will acknowledge the complaint promptly, investigate it fairly and communicate its response. SDSI will normally aim to provide a substantive response within 30 calendar days. If additional time is reasonably required, SDSI will explain why and provide an updated timeframe.
If an individual is not satisfied after giving SDSI a reasonable opportunity to respond, they may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or telephone 1300 363 992.
15. Data breaches
SDSI maintains processes to identify, contain, assess and respond to suspected data breaches. Where a breach is an eligible data breach under the Notifiable Data Breaches scheme, SDSI will notify the OAIC and affected individuals as required by the Privacy Act.
16. Anonymity and automated decisions
Where lawful and practicable, an individual may interact with SDSI anonymously or using a pseudonym. SDSI may need the individual's identity where it is required by law or necessary to provide a service, investigate an issue, manage a contract, verify authority or protect security.
SDSI does not use personal information collected through its public website to make decisions solely by automated means that could reasonably be expected to significantly affect an individual's rights or interests.
17. Contacting SDSI about privacy
Privacy Officer
SDSI Emergency Asset Management Pty Ltd
trading as Spectrum Data Systems International (SDSI)
42 Manilla Street
East Brisbane QLD 4169
Australia
Email: info@sdsi.com.au
Telephone: +61 7 3435 3600
18. Changes to this policy
SDSI may update this policy when its practices, services, suppliers or legal obligations change. The current version and effective date will be published on the SDSI website. Material changes will be communicated where reasonable and appropriate.