Baseline Assurance

Privacy Policy – Baseline Assurance

Who we are
Baseline Assurance is an Australian-owned business that helps small businesses get cyber-ready in 14 business days with fixed-fee policy packs aligned to the ACSC Essential Eight Maturity Level 1.

Last updated: 12 June 2026
Privacy contact: admin@baselineassurance.au

Summary

We keep this simple because the OAIC says a policy should speak to your customers, not just manage legal risk.

  • Applies to: anyone using baselineassurance.au, requesting a proposal, using live chat, or buying a Starter, Standard, Plus or CIRP pack
  • We collect: name, work email, phone, business name, staff size, IT contact, billing details, and basic website data
  • We use it to: deliver your policies, Gap Report and attestation letter, run your handover call, and invoice you
  • We share with: your IT provider (when you ask), and trusted providers like payment and cloud storage. We never sell data
  • Overseas: some providers store data in the United States
  • Your rights: ask for access, correction or make a complaint — email admin@baselineassurance.au

1. What we collect

  • Contact details: name, job title, work email, phone
  • Business details: company name, ABN, industry, staff count band
  • Service information: notes about your current setup, existing policies, answers to our assessment questions
  • Billing: invoices and payment confirmations (card data is processed by our payment provider, not held by us)
  • Communications: emails and chat transcripts
  • Website usage: IP address, browser, pages visited, cookies

We do not collect sensitive information.

2. How we collect it

Directly from you through forms, email, phone and live chat on baselineassurance.au. Sometimes from your IT provider with your permission. Automatically through cookies. Occasionally from public sources like ABN Lookup to confirm business details.

3. How we hold it

Data is stored in secure cloud systems with multi-factor authentication, encryption in transit and at rest, and access limited to staff delivering your project. We follow the same Essential Eight ML1 controls we recommend to clients. We keep client files for 7 years for legal and insurance purposes, then delete them. Unconverted enquiries are deleted after 12 months.

4. Why we use it

To prepare and deliver your policy pack, create your Gap Report showing your Essential Eight score, issue your attestation letter, coordinate workshops and the handover call, send annual review reminders, improve our services using de-identified data, and meet our legal obligations.

5. Who we disclose to

Only when needed: your nominated IT provider, our payment processor, cloud hosting and email providers, and our accountants. We do not sell personal information and we do not disclose it for marketing by others.

6. Overseas disclosure

Our cloud and analytics providers may store information in the United States. We take reasonable steps to ensure they protect it in line with Australian Privacy Principles.

7. Access and correction

Email admin@baselineassurance.au to request access to your information or to correct it. We will respond within 30 days and verify your identity first.

8. Complaints

Email admin@baselineassurance.au with details of your concern. We will acknowledge within 5 business days, investigate, and reply within 30 days. If you are not satisfied you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

9. Anonymity

You can browse our website anonymously. To receive a proposal or policy pack we need your real contact details.

10. Cookies

We use essential cookies for the site to work and analytics cookies to improve it. You can turn cookies off in your browser.

11. Availability and updates

This policy is free on our website. Ask us at admin@baselineassurance.au if you need it in another format. We review it at least annually to keep it current, as required by APP 1.

← Back to home