Privacy & Data Protection

Privacy Policy

Last updated: April 2026

1. Introduction

Real Bytes Pty Ltd (ABN 94 620 082 706) ("Real Bytes", "we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, hold, use, disclose, and safeguard your personal information when you visit our website or use our services.

We handle personal information in accordance with the Privacy Act 1988 (Cth), as amended by the Privacy and Other Legislation Amendment Act 2024, and the Australian Privacy Principles (APPs) set out in Schedule 1 of the Privacy Act. We also comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.

2. Information We Collect

We may collect the following types of personal information:

  • Contact Information: Name, email address, phone number, company name
  • Technical Data: IP address, browser type, pages visited, time spent on site
  • Service Data: Information you provide when requesting support, quotes, or consultations
  • Customer Data: For managed services clients, this includes data and information relating to the client (including any personal information) that is supplied by the client, or created, accessed, processed or stored by Real Bytes in the course of performing the Services. Customer Data is accessed only to provide the Services and is treated as confidential under our standard Terms.
  • Communications: Records of correspondence when you contact us

3. How We Use Your Information

We use your information to:

  • Provide and improve our managed IT services
  • Respond to enquiries and provide customer support
  • Send service updates, invoices, and relevant communications
  • Comply with legal obligations
  • Improve our website and user experience

We do not sell your personal information to third parties.

4. Disclosure of Your Information

We may share your information with:

  • Service Providers: Trusted third-party vendors who assist in our operations (for example, cloud hosting, ticketing, and PSA systems), bound by contractual confidentiality and data protection obligations
  • Legal Authorities: When required or authorised by Australian law, court order, or to protect our legal rights
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, where the recipient agrees to handle your information consistent with this policy

Overseas disclosure (APP 8): Some of our service providers may store or process data outside Australia, including in the United States and the European Union. Where this occurs, we take reasonable steps to ensure the overseas recipient handles your personal information in a manner consistent with the APPs.

We do not sell your personal information and we do not use it for automated decision-making that has a legal or similarly significant effect on you.

5. Data Storage & Security

Your data is primarily stored on secure servers located in Australia. We implement reasonable technical and organisational security measures including encryption in transit and at rest, role-based access controls, multi-factor authentication, logging, and regular security reviews.

While we take all reasonable steps to protect your data, no method of transmission or storage is completely secure. If we become aware of an eligible data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in line with the Notifiable Data Breaches scheme.

Cyber incident reporting: Where required by law, we may notify and cooperate with relevant Australian authorities (including the Australian Cyber Security Centre) in relation to a cyber incident, including by providing information reasonably necessary to meet legal or regulatory obligations. Unless required by law, we have no obligation to make any external report on a client's behalf.

5a. Customer Data Retention & Offboarding (Managed Services)

For managed services clients, when our agreement ends or expires, Real Bytes will make any Customer Data we hold available to the client for a 60 day Offboarding Period.

After the Offboarding Period, we may (subject to applicable law) permanently and irretrievably delete all Customer Data in accordance with our usual practices, including secure wiping or disposal of storage devices. Hosted services and backup services relating to Customer Data also cease at the end of the Offboarding Period unless extended in writing on prepaid terms.

Clients remain responsible for ensuring their Customer Data is properly exported before the end of the Offboarding Period. Full details are in our standard Terms and Conditions.

6. Cookies

Our website may use cookies to enhance your browsing experience. You can choose to disable cookies through your browser settings, though this may affect the functionality of our site.

7. Your Rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Request access to the personal information we hold about you (APP 12)
  • Request correction of inaccurate, out of date, incomplete, irrelevant, or misleading information (APP 13)
  • Request deletion or de-identification of your information, where we are not required to retain it under Australian law
  • Withdraw consent or opt out of direct marketing communications at any time
  • Make a complaint about how we have handled your personal information (see section 11 below)

We will respond to access and correction requests within a reasonable period, typically within 30 days.

8. Third-Party Links

Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites and encourage you to review their privacy policies before providing any personal information.

9. Children's Privacy

Our services are intended for Australian businesses and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can take appropriate steps to remove it.

10. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our practices or to legal and regulatory requirements, including amendments to the Privacy Act. We will post the updated policy on our website with a revised "Last updated" date. Material changes will be highlighted where practicable.

11. Complaints and the OAIC

If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact us first using the details below. We will investigate and respond within a reasonable period, generally within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • Post: GPO Box 5288, Sydney NSW 2001

12. Contact Us

If you have any questions or concerns about this Privacy Policy, wish to exercise your rights, or want to raise a complaint, please contact our Privacy Officer:

Real Bytes Pty Ltd, ABN 94 620 082 706, Brisbane, QLD, Australia.