Privacy Policy

Privacy Policy

How Reyman Pty Ltd handles personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

1. About Axisonic

This policy applies to personal information handled by Reyman Pty Ltd, ABN 68 649 031 649 (ACN 649 031 649), head office Kellyville NSW 2155. Australian-owned, Australian-operated and an SME, Axisonic delivers digital and technology services to government and enterprise clients in Australia and internationally.

We are committed to protecting the privacy of individuals whose personal information we collect. This policy explains what we collect, why, how we handle it, and the choices available to you.

2. Australian Privacy Principles

We are bound by the Privacy Act 1988 (Cth) and, where applicable, the Australian Privacy Principles (APPs) and the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. "Personal information" in this policy has the meaning given in section 6 of the Privacy Act — information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Our handling of personal information is guided by the APP principles of open and transparent management, collection only for lawful purposes, use and disclosure consistent with those purposes, data quality and security, and individual access and correction rights.

3. Information We Collect

The types of personal information we may collect include:

  • Contact details — name, email address, phone number, and organisation details.
  • Customer information — billing and delivery addresses, payment details, and account records.
  • Website analytics — technical data such as device, browser, and usage patterns collected via analytics tools.
  • Project information — requirements, briefs, and correspondence related to the services we deliver.
  • Support requests — details you provide when contacting our technical support or help desk.
  • Employment information — information provided by applicants when applying for roles with Axisonic.
  • Supplier information — details of individuals associated with our suppliers and subcontractors.

4. How Information Is Collected

We collect personal information through a range of legitimate channels, including:

  • Website forms — enquiry, consultation, and contact forms on this website.
  • Contracts — quotes, statements of work, and agreements.
  • Email — correspondence with our team.
  • Support systems — help desk and support tickets.
  • Meetings — discovery sessions, calls, and video meetings.
  • Third-party platforms — information you share with us through platforms such as LinkedIn or other business tools.

We only collect personal information that is reasonably necessary for our functions and activities, and we collect it directly from you unless it is unreasonable or impracticable to do so.

5. Why Information Is Collected

We collect personal information for legitimate business purposes, including to:

  • respond to enquiries and provide consultations;
  • quote for, deliver, and support the services you engage us to provide;
  • manage our client, supplier, and subcontractor relationships;
  • invoice for services and maintain business records;
  • consider applications for employment; and
  • meet our legal, regulatory, and professional obligations.

6. How Information Is Used and Disclosed

We use personal information for the purpose for which it was collected and for related secondary purposes that you would reasonably expect. We may disclose personal information:

  • to our service providers (see section 7) who help us deliver services;
  • to our professional advisers, including legal and accounting advisers;
  • to government agencies where required or authorised by law; and
  • to any person you authorise us to disclose it to.

We do not sell personal information. Where we disclose information to subcontractors engaged to deliver part of our services, we remain accountable for their handling of that information.

7. Service Providers

We engage service providers to help operate our business and deliver services. Categories of providers we may use include:

  • Cloud providers — for hosting and infrastructure, such as AWS and GCP.
  • Email providers — for business email and communications.
  • CRM providers — for managing client and pipeline information, such as Salesforce.
  • Analytics platforms — for understanding website usage and improving our services.
  • AI providers — for AI-assisted delivery, such as OpenAI, Anthropic, Gemini and Llama platforms. Where available, we use zero-data-retention configurations so prompts and business data are not used to train public foundation models.
  • Collaboration and automation tools — for project delivery and workflow automation, such as Slack and Make.

We require our service providers to handle personal information consistently with this policy and applicable privacy law, and we only provide them with the information needed to perform their role.

8. Overseas Disclosure

Axisonic operates delivery and support resources in multiple locations, including Australia and India (Ludhiana). As a result, personal information we hold may be accessed by or disclosed to our personnel located outside Australia, and may be processed by cloud and technology providers whose infrastructure is located overseas.

Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles the information in a manner consistent with the Australian Privacy Principles, including through contractual safeguards and the application of our internal security standards.

9. Australian Data Residency

Where an engagement requires it — for example, a government agency with data sovereignty obligations — we can scope deployment to Australian data centres, with residency, retention, and sovereignty controls matched to the client's security and privacy requirements. This is agreed on a per-engagement basis and documented in the relevant contract.

10. Government Information

Where we handle personal information on behalf of a government agency, we apply enhanced handling requirements, including restricted access, data residency and retention controls, and compliance with the agency's contractual security obligations and applicable government policies. Government data is only used for the purposes of the engagement and is never used for unrelated purposes.

11. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include:

  • encryption of data in transit and at rest;
  • access controls and multi-factor authentication for internal systems;
  • secure development and testing practices before systems go live; and
  • staff awareness and confidentiality obligations.

12. Data Retention and Destruction

We keep personal information only for as long as it is needed for the purposes for which it was collected, or as required by law (for example, taxation and record-keeping obligations). When personal information is no longer needed, we take reasonable steps to destroy it or de-identify it. Clients may also request the erasure of project data and system teardowns at any time; upon authorisation, we securely purge the associated data in accordance with the engagement terms.

13. Access and Correction

You may request access to the personal information we hold about you, or ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will respond within a reasonable period and, where we refuse a request, we will explain our reasons in writing. To make a request, contact our Privacy Contact (section 16).

14. Notifiable Data Breaches

We comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth). If we reasonably believe an eligible data breach has occurred, we will undertake a prompt assessment, and where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.

15. Privacy Complaints

If you believe we have mishandled your personal information, please contact our Privacy Contact in the first instance. We will acknowledge your complaint, investigate it, and respond within a reasonable period. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner at www.oaic.gov.au.

16. Privacy Contact

For any privacy enquiry, access or correction request, or complaint, please contact:

Privacy Contact: privacy@axisonic.com
Entity: Reyman Pty Ltd
ABN: 68 649 031 649
Head office: Kellyville NSW 2155