Last updated: 9 August 2026
1. About this policy
CirculaTech Pty Ltd (ABN 86 693 524 604) (“CirculaTech”, “we”, “us”, “our”) provides IT asset disposition and device lifecycle management services, including secure collection, certified data erasure, diagnostics, redeployment, recycling and reporting.
We take privacy seriously because our business exists to protect information at the point where it is most often mishandled — the end of a device’s life. This policy explains how we handle personal information.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy covers:
- Personal information we collect about visitors to our website and people who contact us
- Personal information we collect about our clients and their staff in the course of providing services
- Data held on devices that come into our custody
2. Information we collect about website visitors and enquirers
Information you give us directly. When you download a guide, complete a form, book a consultation or contact us, we collect the details you provide — typically your name, email address, company name, job title and phone number.
Information collected automatically. When you visit our website we may collect your IP address, browser type, device type, pages viewed, time spent, and the source that referred you. This is collected through standard web analytics and cookies.
Information from third parties. We may receive business contact information from data providers, publicly available sources such as company websites and LinkedIn, or from referrals. Where we contact you using information obtained this way, we will tell you how we obtained it if you ask.
3. Why we collect it and how we use it
We use personal information to:
- Provide the guides, documents or information you have requested
- Respond to enquiries and arrange consultations
- Provide, administer and improve our services
- Communicate with clients about active engagements
- Send information about our services where we are permitted to do so
- Meet our legal, contractual and record-keeping obligations
- Understand how our website is used so we can improve it
Direct marketing. If we send you marketing communications, every message will identify us and include a simple way to opt out. If you opt out we will stop, and we will apply that request across all channels we use — email, SMS and any other. You can also opt out at any time by contacting us at the address in section 12.
4. Data held on devices in our custody
When we collect devices from a client, those devices frequently still contain data — which may include personal information about the client’s employees, customers or other individuals. We do not access, review, copy, extract or use that data for any purpose.
Our handling is as follows:
- Devices are sealed in tamper-evident packaging at the point of collection, with unique seal identifiers recorded before the devices leave the client’s site
- Custody is documented at every transfer between the client’s site and our processing facility
- Devices are held in access-controlled conditions at all times
- Data is destroyed by certified, software-based erasure to the NIST SP 800-88 standard, rendering it irrecoverable
- A digitally signed certificate of erasure is issued for each device, matched to its serial number
- Where a device cannot be erased, the data-bearing component is physically destroyed and this is recorded
We act as a service provider to our clients in respect of this data. The client remains responsible for determining what is collected and for their own obligations to the individuals concerned. Our contracts with clients set out our obligations in detail.
If you are an individual whose data may have been held on a device processed by us, contact the organisation that owned the device in the first instance. If you contact us directly we will assist where we are able to.
5. Who we disclose information to
We disclose personal information only where necessary, and only to:
- Subcontracted logistics providers — couriers engaged to transport devices. They handle sealed consignments and are not given access to device contents.
- Downstream processing and recycling partners — licensed facilities that receive materials for recycling after erasure has been completed. Devices are erased before they reach these partners.
- Service providers — including our IT, hosting, CRM, email and analytics providers, who process information on our behalf under confidentiality obligations.
- Professional advisers — legal, accounting and insurance advisers where required.
- Law enforcement or regulators — where we are required or authorised by law.
We do not sell personal information, and we do not disclose it to third parties for their own marketing purposes.
6. Overseas disclosure
Some of the service providers we use — for example cloud hosting, email and CRM platforms — may store data outside Australia, including in the United States and the European Union. Where this occurs we take reasonable steps to ensure the information is handled consistently with the Australian Privacy Principles.
All data erasure is performed at our Melbourne, Australia facility. No device leaves our custody carrying client data.
Once a device has been erased to the NIST SP 800-88 standard and its erasure certificate issued, it no longer holds client data. Erased devices may then be resold into international markets as refurbished hardware. Devices sent to our e-waste partners for destruction are destroyed in Australia.
7. Security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include:
- Access-controlled physical facilities for devices awaiting and undergoing processing
- Tamper-evident sealing and documented chain of custody
- Restricted, role-based access to our systems
- Certified erasure processes with per-device verification and certification
- Confidentiality obligations on staff and subcontractors
No method of transmission or storage is completely secure. If you believe your information has been compromised, contact us immediately using the details in section 12.
8. How long we keep information
We retain personal information only as long as necessary for the purpose it was collected, or as required by law.
- Enquiry and marketing contact details: retained until you opt out or ask us to delete them, and then removed from active use.
- Client engagement records, asset registers and erasure certificates: retained for seven years so clients can produce evidence of compliant disposal during audits. This is a core part of the service.
- Data on devices: destroyed during processing. We do not retain copies of any data held on client devices at any point.
9. Data breaches
We maintain procedures for identifying, containing and assessing suspected data breaches.
If a data breach occurs that is likely to result in serious harm to any individual, we will notify the affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
Where a breach concerns data held on a client’s devices in our custody, we will notify that client without delay so they can meet their own notification obligations.
10. Cookies and analytics
Our website uses cookies and similar technologies to operate the site, remember your preferences and understand how the site is used.
We use web analytics to measure page visits, traffic sources and engagement. Where you arrive via a link in one of our emails or campaigns, we may record that you visited so we understand which material is useful.
You can disable cookies in your browser settings. Some parts of the site may not function correctly if you do.
11. Accessing and correcting your information
You have the right to ask what personal information we hold about you, to ask us to correct it if it is wrong, and to ask us to delete it where we are able to.
Contact us using the details below. We will respond within a reasonable period, and generally within 30 days. We do not charge for access requests, though a reasonable cost may apply where a request is complex.
We may need to verify your identity before releasing information.
12. Complaints and contact
If you have a question about this policy, or believe we have mishandled your personal information, contact us:
Privacy Officer
CirculaTech Pty Ltd
Email: support@circulatech.com.au
Phone: 1300 001 277
Post: PO BOX 333, Kerrimuir VIC 3129
We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner:
Website: oaic.gov.au
Phone: 1300 363 992
13. Changes to this policy
We may update this policy from time to time. The current version is always available at circulatech.com.au/privacy-policy/, and the date at the top shows when it was last changed.