Skip to content

Privacy Policy

Sturtvale Holdings Pty Ltd

ABN: 25 637 263 355

Trading as Indi Technology and Consulting

Last updated: 12 August 2026


1. Overview

Sturtvale Holdings Pty Ltd (ABN 25 637 263 355), trading as Indi Technology and Consulting, is committed to protecting the privacy of clients, website visitors, service users and other individuals who interact with our business, systems, applications and services.

In this Privacy Policy, "Inditech", "we", "our" and "us" refers to Sturtvale Holdings Pty Ltd trading as Indi Technology and Consulting.

We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). We collect, hold, use and disclose personal information in accordance with the APPs, the Notifiable Data Breaches scheme and other applicable Australian privacy laws.

This Privacy Policy explains how we manage personal information and how individuals may contact us to access or correct their personal information, make a privacy enquiry, or lodge a privacy complaint.

A hard copy of this Privacy Policy can be made available on request.

2. Scope of this Privacy Policy

This Privacy Policy applies to personal information collected, held, used or disclosed by Inditech through our business operations, websites, client engagements, support services, cloud services, managed technology services, applications, portals and digital platforms.

This Privacy Policy is intended to apply not only to visitors of our website, but also to individuals who interact with Inditech through other systems or services, including customer support systems, Microsoft 365 and Entra-integrated applications, Teams applications, managed service platforms, client portals, collaboration tools and other business systems used to provide our services.

3. What is personal information?

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.

Personal information may include names, email addresses, phone numbers, business contact details, job titles, employer details, correspondence, account details, support records, system records, device or usage information, billing information and other information reasonably required for us to provide our services.

Sensitive information may include information such as health information, government identifiers, biometric information, information about racial or ethnic origin, religious beliefs, political opinions, membership of professional or trade associations, criminal records, or other categories of sensitive information as defined by the Privacy Act. We only collect sensitive information where it is reasonably necessary for our functions or activities and where permitted by law.

4. How we collect personal information

We collect personal information where it is reasonably necessary for our business functions, client services, contractual obligations, employment-related activities, security operations or legal compliance.

We may collect personal information through:

  • direct business interactions with clients, prospective clients, suppliers and partners;
  • managed IT services, consulting engagements and technical support activities;
  • service desk tickets, emails, telephone calls, online meetings, chat messages and correspondence;
  • website enquiries and newsletter subscriptions;
  • client portals, customer support systems, cloud platforms and collaboration tools;
  • Microsoft 365, Entra ID, Teams applications and other systems connected to our business or services;
  • recruitment, employment and contractor onboarding processes;
  • publicly available sources, including business websites and professional networking platforms;
  • third-party service providers, where lawful and appropriate; and
  • security, monitoring, logging, audit and diagnostic systems used to protect our services and clients.

Where practical, we collect personal information directly from the individual concerned. In some cases, we may collect personal information from a client organisation, employer, authorised representative, public source, technology system, service provider or other third party.

5. Why we collect, use and disclose personal information

We collect, use and disclose personal information for lawful business purposes that are reasonably necessary for our functions and activities.

These purposes may include:

  • providing managed IT, cybersecurity, consulting, cloud, support and related technology services;
  • responding to enquiries, support requests, incidents and service desk tickets;
  • administering client accounts, billing, contracts and service agreements;
  • communicating with clients, suppliers, partners, employees, contractors and other individuals;
  • managing user access, identity, authentication, permissions and security controls;
  • monitoring, securing, maintaining and improving our systems, services and client environments;
  • performing troubleshooting, diagnostics, reporting, auditing and compliance activities;
  • providing newsletters, service updates, security alerts and relevant business communications;
  • assessing employment, contractor or supplier relationships;
  • meeting legal, regulatory, contractual, insurance and professional obligations;
  • preventing fraud, misuse, cyber threats, unauthorised access and other security risks; and
  • any other purpose notified at the time of collection, authorised by the individual, or permitted by law.

We will not use or disclose personal information for a purpose unrelated to the purpose for which it was collected unless the individual has consented, the use or disclosure would reasonably be expected and is related to the original purpose, or another exception under the Privacy Act applies.

6. Artificial intelligence and automated processing

Inditech may use artificial intelligence, machine-assisted technologies and automated processing tools to assist with service delivery, administration, technical support, documentation, cybersecurity monitoring, communications, data analysis, reporting and business operations.

Where personal information is processed using AI-enabled or automated systems, that processing is conducted within secure business environments that apply organisational governance controls, access restrictions, auditability, security monitoring, retention controls and data protection measures.

Personal information provided to Inditech may be processed by AI-assisted systems where that use is reasonably necessary for our business functions, service delivery, security operations, legal compliance, or other purposes described in this Privacy Policy.

Inditech does not intentionally submit personal information to publicly available AI services in a way that permits that information to be used to train public AI models. Where AI-assisted processing is used, personal information remains subject to the same confidentiality, privacy, security, access and retention controls that apply to other information managed by Inditech.

AI-assisted outputs may contain or infer personal information. Where this occurs, we treat that information as personal information and manage it in accordance with the APPs.

Inditech maintains human oversight of business decisions where appropriate and does not rely solely on AI-assisted processing to make decisions that would have a significant legal or similarly significant effect on an individual unless permitted by law and appropriate safeguards are in place.

Individuals may contact us using the details in this Privacy Policy if they require further information about our use of AI-assisted technologies in relation to their personal information.

7. Direct marketing

We may use personal information to provide newsletters, service updates, event invitations, security alerts, product updates or information about services that may be relevant to clients or other business contacts.

Individuals may opt out of direct marketing communications at any time by using the unsubscribe mechanism in the communication or by contacting us using the details in this Privacy Policy.

We will not use sensitive information for direct marketing unless permitted by law.

8. Anonymity and pseudonymity

Where practical, individuals may choose to interact with us anonymously or using a pseudonym.

In many cases, however, we may need to identify an individual in order to provide services, respond to enquiries, administer accounts, investigate support matters, manage security, or meet legal and contractual obligations.

If an individual wishes to use a pseudonym when dealing with us, they should contact us in writing so that we can assess whether this is practical in the circumstances.

9. Disclosure of personal information

We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy.

This may include disclosure to:

  • employees, contractors and authorised representatives of Inditech;
  • client organisations and their authorised representatives;
  • cloud, hosting, software, telecommunications, cybersecurity and managed service providers;
  • professional advisers, including legal, accounting, insurance and compliance advisers;
  • payment, billing, finance and administrative service providers;
  • recruitment, employment and contractor management providers;
  • government agencies, regulators, law enforcement bodies or courts where required or authorised by law; and
  • other third parties where the individual has consented or where disclosure is otherwise permitted by law.

We take reasonable steps to ensure that service providers and third parties who handle personal information on our behalf are subject to appropriate confidentiality, privacy, security or contractual obligations.

10. Overseas storage, processing and disclosure

Inditech uses cloud-based and technology service providers to operate our business and deliver services to clients. As a result, personal information may be stored, processed, backed up, replicated, accessed or supported from locations outside Australia.

Where personal information is disclosed overseas or processed using overseas-based service providers, we take reasonable steps to ensure that appropriate contractual, technical and organisational safeguards are in place to protect that information in accordance with the APPs.

Overseas processing may occur through cloud service providers, software platforms, support services, cybersecurity services, backup systems or other technology services used by Inditech or by our clients.

11. Security of personal information

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.

Our security measures may include administrative, technical and physical controls such as:

  • multi-factor authentication;
  • role-based access controls;
  • least-privilege access principles;
  • encryption of data in transit or at rest where appropriate;
  • secure configuration and system hardening;
  • endpoint protection and security monitoring;
  • logging, auditing and alerting;
  • vulnerability management and patching;
  • backup, disaster recovery and business continuity processes;
  • secure disposal or destruction of information no longer required;
  • confidentiality obligations for staff and contractors; and
  • review of service providers and third-party access arrangements.

No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect personal information, we cannot guarantee the security of information transmitted to us over the internet.

12. Retention and destruction of personal information

We retain personal information for as long as reasonably required for the purposes for which it was collected, including to provide services, meet contractual obligations, maintain business records, resolve disputes, support security and audit requirements, and comply with legal, regulatory, insurance or professional obligations.

When personal information is no longer required, we take reasonable steps to securely destroy, delete, de-identify or archive it in accordance with our business requirements and legal obligations.

13. Access to and correction of personal information

Individuals may request access to personal information that we hold about them.

Individuals may also request correction of their personal information if they believe it is inaccurate, out of date, incomplete, irrelevant or misleading.

We will respond to access and correction requests within a reasonable period. We may need to verify the identity of the person making the request before providing access or making corrections.

There may be circumstances where we are not required or permitted to provide access or make a correction. If this occurs, we will explain the reason where it is reasonable and lawful to do so.

14. Quality of personal information

We take reasonable steps to ensure that personal information we collect, use or disclose is accurate, up to date, complete and relevant for the purpose for which it is used.

Individuals can help us maintain accurate information by notifying us of changes to their details.

15. Government-related identifiers

We do not use government-related identifiers, such as tax file numbers, Medicare numbers or other government-issued identifiers, as our own internal identifiers unless permitted by law.

Where we collect or handle government-related identifiers, we do so only where reasonably necessary, authorised or required by law, or where required to provide services to a client.

16. Website, analytics and cookies

Inditech operates the website located at https://inditech.com.au.

When individuals use our website, we may collect technical and usage information such as IP address, browser type, device information, pages visited, referring websites, approximate location, time and date of access, and other website analytics information.

We may use cookies, pixels, analytics technologies and similar tools to operate the website, improve user experience, analyse usage, secure the website, understand visitor traffic and support business communications.

Most browsers allow users to disable or manage cookies. Disabling cookies may affect the functionality or performance of parts of our website.

Our website does not collect personal information through online forms. If an individual contacts us using the email address or telephone number published on our website, we collect and use the information in that enquiry for the purpose of responding to it and for related business purposes described in this Privacy Policy.

17. Third-party websites and services

Our website, applications or communications may contain links to third-party websites, services or platforms. We are not responsible for the privacy practices, security or content of third-party websites or services.

Individuals should review the privacy policies of any third-party websites or services they access.

18. Children's privacy

Our services are primarily intended for businesses, organisations and adults.

We do not knowingly collect personal information from children except where required to deliver services on behalf of a client, where authorised by a parent, guardian, school, organisation or other appropriate authority, or where otherwise permitted by law.

If we become aware that we have collected personal information from a child without appropriate authority, we will take reasonable steps to delete or de-identify that information, unless we are required or permitted to retain it by law.

19. Notifiable data breaches

If we become aware of a data breach involving personal information, we will assess the incident and take appropriate steps to contain, investigate and remediate the matter.

Where we determine that an eligible data breach has occurred and is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner where required by the Notifiable Data Breaches scheme.

20. Privacy complaints

Individuals may contact us if they have a question, concern or complaint about how we handle personal information.

Privacy complaints should be made in writing using the contact details below. We will acknowledge and investigate complaints within a reasonable period and will take reasonable steps to resolve the matter.

If an individual is not satisfied with our response, they may contact the Office of the Australian Information Commissioner.

Office of the Australian Information Commissioner
Website: https://www.oaic.gov.au
Phone: 1300 363 992

21. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our business, services, systems, legal obligations or privacy practices.

The current version of this Privacy Policy will be made available on our website or otherwise on request.

22. Contact details

For privacy enquiries, access or correction requests, complaints, or questions about this Privacy Policy, please contact:

Sturtvale Holdings Pty Ltd trading as Indi Technology and Consulting
Attention: The Director
Email: Click to reveal email
Phone: Click to reveal phone
Website: https://inditech.com.au