1. Scope and who is responsible
This policy applies to YUMA IT PTY LTD (ABN 62 684 389 839, ACN 684 389 839), trading as Yuma IT when we collect or hold personal information through this website, enquiries, sales, contracting, support, managed services, professional services, or administration of Kelpie.
Kelpie is primarily customer-controlled software. When a customer runs Kelpie in its own environment, that customer controls the incident, user, evidence, identity, and integration data stored there. We do not receive that data merely because the customer uses Kelpie. The customer’s privacy notice and instructions apply to its handling of that data.
If we host Kelpie or access Customer Data to provide requested support or services, the customer generally determines why and how that data is handled and we act as its service provider. The Order and any data processing agreement govern that work.
2. Personal information we collect
Depending on how you deal with us, we may collect:
- identity and contact details, such as name, employer, role, business email, phone number, and address;
- account and access details, such as username, organisation, role, authentication events, and support permissions;
- commercial records, such as enquiries, quotes, Orders, invoices, marketplace identifiers, and payment status;
- communications, feedback, meeting notes, support requests, diagnostics, and correspondence;
- website and security data, such as IP address, browser, device, timestamps, requested pages, referral information, and protective service logs; and
- Customer Data that an authorised customer intentionally gives us for managed hosting, support, incident investigation, or professional services.
Customer Data can contain sensitive security and incident material and may contain personal or sensitive information about staff, customers, threat actors, or other people. Customers should disclose only what is necessary and authorised.
3. How we collect information
We usually collect information directly from you when you contact us, arrange a demonstration, enter an Order, use support, or work with us. We may also receive it from your employer, authorised colleagues, procurement partners, cloud marketplaces, identity providers, integrations you enable, public business sources, and service providers.
This public site does not provide a Kelpie sign-in or collect payment details. Its hosting and security providers may automatically process basic request and security logs needed to deliver and protect the site. Contact links take you to Yuma IT services, which are also covered by the applicable Yuma IT privacy notice.
4. Why we use personal information
- respond to enquiries, demonstrate Kelpie, prepare Orders, and manage customer relationships;
- supply licences, managed services, support, updates, training, and professional services;
- authenticate authorised users and protect accounts, systems, customers, and the public website;
- diagnose faults, investigate security events, maintain service quality, and improve Kelpie;
- invoice, account, audit, insure, manage risk, and meet legal or regulatory duties;
- send product, security, service, or renewal notices and requested communications; and
- establish, exercise, or defend legal claims and enforce contracts.
We do not sell personal information. We do not use Customer Data from a customer-controlled deployment to advertise to individuals or train general-purpose AI models.
5. When we disclose information
We may disclose personal information to personnel who need it; hosting, security, identity, communications, billing, accounting, legal, insurance, and support providers; authorised resellers or marketplaces; a buyer or successor in a business transaction; regulators, courts, or law enforcement where required or authorised; and other parties with consent or as reasonably expected for the purpose of collection.
Service providers may use information only to provide contracted services or meet their legal duties. We take reasonable steps appropriate to the relationship and information to require suitable privacy and security protections.
6. Overseas processing
Our business is based in Australia. Some infrastructure, security, communications, software, marketplace, and support providers may process information outside Australia, including in the United States and other countries where they or their subprocessors operate.
Customer-controlled deployments remain in locations chosen by the customer unless data is intentionally provided to us or another provider. Where practical, an Order or provider documentation identifies relevant hosting locations. We take reasonable steps required by Australian privacy law before overseas disclosure.
7. Security and retention
We use administrative, technical, and physical safeguards appropriate to the information and service, including access controls, authentication, logging, secure development, supplier review, and protected communications. No method of storage or transmission is completely secure.
We retain personal information only as long as reasonably needed for the purposes above, contractual support, security, backup, accounting, insurance, dispute, and legal requirements. We then delete, destroy, or de-identify it where reasonably practicable. Customer-controlled retention is set and operated by the customer.
8. Access and correction
You may ask to access or correct personal information we hold about you by emailing hello@yumait.com.au. We may need to verify your identity. If an exception permits us to refuse, we will generally give written reasons and available complaint options.
For information held in a customer-controlled Kelpie deployment, contact that customer first. We will assist the customer where required by our contract and applicable law.
9. Privacy questions and complaints
Send a privacy question or complaint to hello@yumait.com.au or 49 Phillip Ave, Watson ACT 2602, Australia. Include enough detail for us to investigate, but do not email incident evidence, credentials, or sensitive records unless we provide a secure method.
We will acknowledge a complaint within 5 business days and aim to respond within 30 days. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
10. Data incidents
We assess suspected unauthorised access, disclosure, or loss involving information we control and take containment, investigation, remediation, and notification steps required by law. For Customer Data we handle as a service provider, we notify and cooperate with the affected customer under the contract so responsibilities can be coordinated.
11. Children
Kelpie is business security software and is not directed to children. Do not provide personal information about a child unless it is necessary, lawful, authorised, and appropriately protected for a genuine incident response or security purpose.
12. Changes and contact
We may update this policy when our practices, providers, products, or legal duties change. The effective date shows the latest version. Material changes will be highlighted or communicated where appropriate.
Contact: YUMA IT PTY LTD, 49 Phillip Ave, Watson ACT 2602, Australia; hello@yumait.com.au. You may request this policy in another reasonably available format free of charge.
