Last updated 5 October 2026.
Who we are
WaTo Consulting Pty Ltd (ABN 96 626 938 663) ("WaTo", "we", "us" or "our") provides IT, digital, cyber-security, website, hosting, business and equipment services. Our address is 54 Howards Road, Beverley SA 5009.
This policy explains how we handle personal information. Where the Privacy Act 1988 (Cth) applies to us, we comply with the Australian Privacy Principles (APPs). We aim to follow the same practical privacy standards in our other activities as well.
Personal information we collect
The information we collect depends on how you deal with us and may include:
- your name, contact details, business, role and authorised contacts;
- enquiries, quotes, orders, contracts, support requests and communications;
- billing, transaction and account information;
- site addresses, asset details, serial numbers, device and system information;
- technical logs, IP addresses, browser information, diagnostic results and security events;
- credentials or access information where needed to provide an authorised service;
- information visible to us while providing remote, on-site, hosting, backup, migration, recovery or cyber-security services; and
- job applicant, contractor or supplier information where relevant.
We may encounter sensitive information in a customer's systems or in a support request. We ask customers not to provide sensitive information unless it is reasonably necessary and an appropriate, authorised method has been agreed. Where required, we collect sensitive information with consent or as otherwise permitted by law.
How we collect information
We usually collect information directly from you by website form, service request, chat, email, phone, SMS, remote-support session, meeting or in-person service. We may also receive it from your employer or another authorised contact, a referral partner, a vendor or distributor, a public source, or systems and devices that you authorise us to support.
Our website and security systems may automatically record technical information such as IP address, date and time, requested page, browser, referring address and security events.
Why we use information
We use personal information to:
- respond to enquiries and prepare quotes;
- verify identity, authority and account access;
- provide, administer, secure and improve our services;
- diagnose faults, maintain service records and communicate progress;
- manage accounts, billing, warranties, suppliers and customer relationships;
- prevent fraud, misuse and cyber-security incidents;
- meet insurance, legal, regulatory and record-keeping obligations; and
- send relevant marketing where we have consent or another lawful basis.
If required information is not provided, we may be unable to verify a request, provide a quote or safely deliver the service.
Customer systems and data
When a customer gives us authorised access to systems or data, we normally handle that information to provide the requested service on the customer's instructions. The customer remains responsible for having appropriate notices, permissions and lawful authority for the information it asks us to access or process. We limit access to what is reasonably needed for the work.
Who we disclose information to
We may disclose information where reasonably necessary to our staff and authorised contractors; hosting, cloud, communications, ticketing, backup, monitoring, security and software providers; banks and payment or accounting providers; product vendors, distributors and warranty providers; professional advisers and insurers; and regulators, courts, law-enforcement bodies or other parties where authorised or required by law.
We do not sell personal information. We require service providers to handle information for the relevant purpose and with appropriate safeguards, subject to their own legal obligations.
Overseas processing
Some cloud, communications, software and support providers operate globally. Personal information may therefore be stored in or accessed from the United States and other countries in which those providers or their subprocessors operate. The countries can vary by product and customer configuration. Where APP 8 applies, we take reasonable steps required by law before disclosing personal information overseas. Contact us if you need details about providers used for a particular service.
Website cookies, chat and analytics
The website uses limited first-party cookies to remember interface choices, such as the visual character shown during a visit and whether the floating help panel was minimised. These cookies are not used for advertising.
The website includes Smallchat live chat, which may receive technical information when its service loads and any information you enter into chat. If Google Analytics 4 is enabled in the future, it may collect website usage information such as pages viewed, approximate location and device or browser details. We do not use website analytics to make significant decisions about individuals. You can restrict cookies using your browser, although some preferences may no longer be remembered.
Direct marketing
We may send service-related messages that are necessary to manage your account or work. We send commercial electronic marketing only where permitted, identify the sender and provide a functional way to unsubscribe. You can opt out at any time; we will action the request within the period required by law. Opting out of marketing does not stop necessary service, security, billing or contractual messages.
Storage, security and retention
We use reasonable administrative, physical and technical safeguards appropriate to the information and service. No internet transmission or storage system is completely secure, so we cannot promise absolute security.
We keep information only for as long as reasonably needed for the purposes for which it was collected, to maintain service and business records, resolve disputes, or meet legal, insurance and tax obligations. We then delete, destroy or de-identify it where reasonable and lawful. Backup copies may remain until they are overwritten under normal retention cycles.
If a data breach occurs, we investigate, contain and assess it. Where the Notifiable Data Breaches scheme or another law applies, we notify affected individuals and the relevant regulator as required.
Access and correction
You may ask to access personal information we hold about you or to have inaccurate information corrected. We may need to verify your identity and authority. We will respond within a reasonable period and, where the APPs apply, give any required reasons if access or correction is refused. We do not usually charge for a request, but may charge a reasonable cost where the law permits and we tell you in advance.
Privacy complaints
Send a privacy request or complaint to info@wato.com.au, call (08) 7123 0805, or write to WaTo Consulting Pty Ltd, 54 Howards Road, Beverley SA 5009. Please describe what happened and the outcome you seek.
We will acknowledge and investigate a complaint and aim to respond within 30 days. If you are not satisfied and the Privacy Act applies, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Related terms
The Website Terms of Use, Service Terms, Acceptable Use Policy and any applicable SLA also apply to how we provide our website and services.
Changes to this policy
We may update this policy when our practices, providers or legal obligations change. The current version and update date will remain on this page.