Client portal

Sign in to manage tickets, messages, and your account.

Sign in to portal
NexusByte banner
Privacy Policy

Last Updated: 7 September 2026

Privacy Policy

This Privacy Policy explains how NexusByte (ABN 48 450 169 339) (NexusByte, we, us, our) collects, holds, uses and discloses personal information, and how you can access it, correct it or complain about how we have handled it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, and this policy is written to meet Australian Privacy Principle 1.

It applies to everyone whose personal information we handle: customers and prospective customers, users of our client portal, newsletter subscribers, visitors to www.nexusbyte.com.au (the Site), and people who apply to work with us as employees or contractors. Personal information is any information about an identified individual, or an individual who is reasonably identifiable.

1. The personal information we collect

What we collect depends on how you deal with us. It may include:

  • Identity and contact details: your name, email address, phone numbers, postal or service address, and, for business customers, your company name, role and ABN.
  • Enquiries and bookings: the service you need, the date and time you book, the address we are to attend, and what you tell us about the problem.
  • Data recovery jobs: the device type, brand and model, a description of the fault, the files you are looking for, previous recovery attempts, how you will get the device to us, and the service you select. For phones and tablets we also collect the credentials needed to unlock the device: the passcode and, for Apple devices, the Apple ID and password, together with any lockdown files you upload.
  • Client portal accounts: your name, email address, sign-in activity, the team members you invite, and the support tickets and messages you send through the portal.
  • Payments: when you pay by card on the Site, Square collects your card details directly. We receive only a payment reference, the amount and the outcome. When you pay by bank transfer we see the payer name that your bank sends with the transfer.
  • Newsletter: your email address and the date you subscribed or unsubscribed.
  • Website use: your IP address, browser and device type, the pages you visit and how you reached the Site, collected through cookies and similar technologies described in our Cookie Policy.
  • Working with us: if you apply to join us as an employee or contractor, the information in your application, your qualifications and work history, and the details of your referees.

We do not ask for sensitive information such as health, religious or political information. A device you give us for repair or data recovery may contain sensitive information about you or other people. We access the contents of a device only to the extent the work requires, and we do not copy, review or use that content for any other purpose.

2. How we collect it

We collect personal information directly from you when you fill in a form on the Site, book a service, submit a job, create or use a portal account, subscribe to our newsletter, email, call or message us, or deal with our technicians. We collect website use information automatically as you browse. We sometimes receive personal information from others: from a colleague who invites you to their portal account or books a service on your business's behalf, from referees you nominate, and from publicly available business registers when we verify a business customer.

If you give us personal information about someone else, such as the owner of a device or a team member, you confirm that you are authorised to do so and that they know we will handle it under this policy.

3. Why we collect and use it

We use personal information for the purposes for which it was collected and for closely related purposes you would reasonably expect. In particular, to:

  • Respond to your enquiry and provide, schedule and carry out the services you ask for.
  • Lodge, identify and complete data recovery and data destruction jobs, including sending you the job number and job sheet by email and SMS, and unlocking and reading a device you have submitted.
  • Operate your client portal account, including team access and support tickets.
  • Invoice you, process payments and keep the accounting records the law requires.
  • Send you our newsletter and other marketing where you have subscribed or asked to receive it. Every marketing email includes an unsubscribe link, and we comply with the Spam Act 2003 (Cth). We do not send marketing by SMS.
  • Keep the Site secure, prevent spam and fraud, and understand how the Site is used so we can improve it.
  • Assess applications from people who want to work with us.
  • Meet our legal obligations and establish, exercise or defend legal claims.

4. Who we disclose it to

We disclose personal information only where we need to in order to run our business and provide our services. We do not sell or rent personal information, and we do not give it to anyone else for their own marketing.

4.1 Our people

Our employees and contractors have access to the personal information they need to do their work, and no more. They are bound by confidentiality obligations and by this policy.

4.2 Service providers

We use the following providers to operate the Site and our services. Each is permitted to use personal information only to provide its service to us.

  • Vercel (United States) hosts the Site and runs its forms and portal.
  • Neon hosts our database in Sydney, Australia, on Amazon Web Services infrastructure. This is where bookings, jobs, portal accounts, newsletter subscriptions and uploaded job files are stored.
  • Square (Square AU Pty Ltd) processes card payments. Your card details are entered into Square's secure form and go directly to Square; we never receive or store your card number. Square's handling of your information is described in its privacy policy.
  • Twilio (United States) sends our SMS messages, such as your job number. Your mobile number and the message content are shared with Twilio for that purpose only.
  • Resend (United States) sends our transactional emails, such as booking confirmations and job sheets, and our newsletter.
  • Google (United States) provides Google Analytics, which tells us how the Site is used; reCAPTCHA, which protects our forms from bots; and the map embedded on our contact page and footer. Google's use of information is described in its privacy policy.
  • Mapbox (United States) powers the address search on our forms. The text you type into the address field is sent to Mapbox to suggest matching addresses; only the address you choose is stored with your enquiry, booking or job.

4.3 Other disclosures

We may also disclose personal information where the law requires or permits it, for example to a court, regulator or law enforcement agency; to our professional advisers; and, if we sell or restructure our business, to the buyer and their advisers under confidentiality obligations. Otherwise we disclose personal information only with your consent.

5. Overseas disclosure

Our database is in Australia. As section 4 shows, some of our service providers store or process information in the United States. Before using an overseas provider we satisfy ourselves that it protects personal information to a standard comparable with the Australian Privacy Principles, through its contractual commitments and security certifications, and we limit what we send to what the service needs. By providing us with personal information you consent to these disclosures.

6. Device credentials and job files

Passcodes, Apple IDs, Apple passwords and lockdown files you give us for a data recovery job are used only to access the device you have submitted. They are sent to the technician with the job, are never printed on your job sheet or included in your confirmation email, and lockdown files can be opened only by our staff after signing in. All of them are deleted from our systems no later than 90 days after the job is lodged. We recommend that you change your Apple password once your job is complete.

7. How we protect it

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Those steps include:

  • Encrypting all traffic to and from the Site, and storing our database and backups on infrastructure that encrypts data at rest.
  • Limiting access to customer information to staff who need it, behind individual sign-ins, with uploaded job files available only to signed-in staff.
  • Keeping card details out of our systems altogether by using Square's hosted payment form.
  • Rate limiting and bot protection on every form, and content security controls on the Site.
  • Deleting device credentials and job files automatically after 90 days, and applying the retention periods in section 8.
  • Keeping the software the Site runs on up to date, and reviewing our security when we add a new feature or provider.

No system is completely secure, and we cannot guarantee that information sent over the internet will never be intercepted. If a data breach occurs that is likely to result in serious harm to you, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

8. How long we keep it

  • Data recovery job records (your contact details, the device and fault details, and payment references) are kept for 7 years to meet our tax and accounting obligations. Recovered data is held for 14 days after payment and deleted no later than 90 days after the job. Device credentials and uploaded files are deleted within 90 days of lodgement.
  • Bookings, quotes, invoices and service records are kept for 7 years after the work for the same reason.
  • Enquiries that do not become a job are kept for as long as needed to respond to you and for a reasonable period afterwards, and no longer than 2 years.
  • Client portal accounts are kept while the account is open. When it is closed, we delete the account and keep only the transaction records the law requires.
  • Newsletter subscriptions are kept until you unsubscribe. We keep a record of your unsubscribe so that we do not email you again.
  • Website analytics are held in Google Analytics in aggregated form and are not linked to your name.
  • Applications to work with us are kept for 12 months after the position is filled, unless you ask us to delete them sooner or you join us.

When we no longer need personal information for any purpose for which it may be used or disclosed, and we are not required to keep it, we delete it or de-identify it.

9. Cookies and analytics

The Site uses cookies for security, sign-in and analytics, and the map and payment form embedded on the Site set cookies of their own. Our Cookie Policy lists each cookie, who sets it and how long it lasts, and explains how to control them.

10. Dealing with us anonymously

You may make a general enquiry about our services by phone or through the Site without identifying yourself. We need your name and contact details to book a visit, submit a job, open a portal account or send you a quote, because we cannot otherwise provide those services.

11. Access and correction

You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details in section 14. We will verify your identity, and respond within 30 days. Access is free; if a request is unusually large or complex we may ask for a reasonable fee to cover the cost of retrieving and preparing the information, and we will tell you before any fee applies.

We may decline access in the limited circumstances the Privacy Act allows, for example where giving access would unreasonably affect another person's privacy, would prejudice legal proceedings, or would be unlawful. If we decline to give access or to make a correction, we will tell you why in writing and how you can complain. If we decline a correction, you may ask us to attach a statement to the record noting that you believe it is inaccurate.

Portal users can update their own name and contact details in the portal at any time. Newsletter subscribers can unsubscribe using the link in any email or by contacting us.

12. Complaints

If you believe we have mishandled your personal information or breached the Australian Privacy Principles, please contact us first using the details in section 14. We will acknowledge your complaint within 5 Business Days, investigate it, and give you a written response within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at www.oaic.gov.au, by phone on 1300 363 992, or by email to enquiries@oaic.gov.au.

13. Changes to this policy

We update this policy when our practices, our providers or the law change. The current version is always published on the Site with its “Last Updated” date. Where a change materially affects how we handle information we already hold about you, we will tell you by email or through the portal.

14. Contact us

NexusByte
ABN: 48 450 169 339
Email: info@nexusbyte.com.au
Phone: +61 2 7235 2223
WhatsApp: +61 414 082 893
Office (by appointment): 28 Blues Point Road, McMahons Point NSW 2060