Privacy policy & data handling.
How LettersCorp Pty Ltd, trading as LCorp IT, collects, uses, stores and protects personal information. Written in plain English, because you should not need a lawyer to understand what happens to your data.
About this policy.
LettersCorp Pty Ltd (ABN 68 682 045 192), trading as LCorp IT ("LCorp IT", "we", "us", "our"), is a managed service provider based on the Gold Coast, servicing businesses across south-east Queensland and beyond.
We are committed to protecting your privacy. This policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to our website at lcorpit.com.au, our client portal, and the managed IT, cybersecurity, cloud and consulting services we provide.
"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
By using our website or engaging our services, you acknowledge that you have read and understood this policy. If you provide us with personal information about someone else (for example, your staff), you confirm that you are authorised to do so and have told them about this policy.
What we collect.
The kinds of personal information we collect depend on how you interact with us. It may include:
- Identity and contact details - name, job title, employer, business email address, phone number and postal address.
- Account and portal details - login email, hashed password, multi-factor authentication settings, and session records (including IP address and browser details) for our client portal.
- Service and support information - details you provide in onboarding, offboarding and access-request forms, support tickets, and communications with our helpdesk, including staff names, roles, device details, licence assignments and software in use.
- Technical and environment information - information about your IT systems, networks, devices, domains, user accounts and configurations that we need in order to manage and secure them.
- Billing information - business details, invoicing contacts and payment records. We do not store full card numbers; payments are processed by our accounting and payment providers.
- Website usage data - IP address, browser type, pages visited, referring site and the outcome of anti-bot checks.
- Marketing preferences - whether you have opted in or out of receiving communications from us.
Sensitive information
We do not generally seek to collect sensitive information (such as health information, racial or ethnic origin, political or religious beliefs, or criminal history). If we encounter sensitive information while providing services, for example within data stored on a client system we manage, we handle it only as necessary to deliver the service and in accordance with this policy and our client agreements.
How we collect it.
Where practicable we collect personal information directly from you. This happens when you:
- Submit an enquiry or consultation request through our website.
- Sign up for, or use, our client portal.
- Contact our helpdesk by phone, email, chat or ticket.
- Complete onboarding, offboarding or access-request forms.
- Enter into a services agreement with us.
- Interact with us on social media or at events.
We may also collect personal information from third parties where it is reasonably necessary, including from your employer (if they are our client), from our technology vendors and partners, from publicly available sources, and from the systems we manage on your behalf.
Where it is lawful and practicable, you can deal with us anonymously or using a pseudonym. In most cases, however, we will need to identify you to provide services or respond to an enquiry.
Why we collect it.
We collect, hold, use and disclose personal information for the following purposes:
- To provide, manage, support and secure the IT services you or your employer have engaged us to deliver.
- To respond to enquiries, book consultations and prepare quotes and proposals.
- To authenticate users, provision and de-provision accounts, and manage access to systems.
- To monitor systems, detect and respond to security incidents, and meet our obligations under our client agreements.
- To invoice, process payments, and manage our accounts and records.
- To manage domain names, licences and subscriptions on your behalf.
- To improve our services, website and internal processes.
- To send service notifications, and with your consent, marketing communications.
- To comply with our legal and regulatory obligations, and to establish, exercise or defend legal claims.
We will only use or disclose personal information for a secondary purpose where you would reasonably expect it, where you have consented, or where it is otherwise permitted or required by law.
Client data we manage.
As a managed service provider, we routinely have administrative access to our clients' systems, including email platforms, file storage, identity directories, endpoints and network equipment. Those systems contain personal information about our clients' staff, customers and suppliers.
In relation to that data, our client is generally the entity responsible for it, and we act on their instructions and under the terms of our services agreement. We:
- Access client data only to the extent necessary to deliver, support and secure the services.
- Do not sell, trade or rent client data to anyone, ever.
- Apply the same security controls to client data as we apply to our own.
- Return, hand over or securely delete client data at the end of an engagement, in line with the agreement and any legal retention obligations.
If you are a customer or employee of one of our clients and you have a question about how your information is handled, we recommend contacting that organisation in the first instance. We will assist them in responding.
Use of AI tools.
LCorp IT uses artificial intelligence (AI) tools to assist with day-to-day operations. This includes tasks such as summarising and triaging support tickets, drafting documentation and correspondence, analysing logs and alerts, and helping our engineers resolve issues faster.
In carrying out that work, client data (including personal information) may be processed by those AI tools. We take the following measures to protect it:
- Contained within our data loss protection controls. Our AI tooling operates inside LCorp IT's organisational environment and is governed by our data loss prevention (DLP) policies. Data cannot be freely copied out of that environment, and access is restricted to authorised LCorp IT staff.
- Paid business services only. We use paid, business-grade AI services under the provider's commercial terms, configured so that our data is not used for model training. We do not paste client data into free, consumer-grade AI tools.
- No training on your data. Under the terms of our agreements with our AI providers, client data we submit is not used to train or improve their publicly available models.
- Human oversight. AI output is used to assist our engineers, not to replace them. Decisions that affect your systems, accounts or data are made or reviewed by a person.
- Minimisation. We only provide an AI tool with the information reasonably necessary for the task at hand.
If you would prefer that your organisation's data is not processed by AI tools, or you require specific restrictions, please contact us. We will work with you to accommodate reasonable requests, and will document any agreed restrictions in your services agreement.
Storage & security.
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure.
Where your data lives
Client data is stored securely in Australian data centres. Our primary storage platforms and providers are:
We also use Anthropic (Claude) for the AI assistance described in section 06. Anthropic does not store client data as a system of record; information sent to it is processed transiently to complete a task. Anthropic's infrastructure is located in the United States, so that processing is an overseas disclosure and is covered in section 09.
How we protect it
- Phishing-resistant multi-factor authentication using FIDO2 hardware security keys is enforced on all LCorp IT staff accounts. Multi-factor authentication is also required on our client portal.
- Access to client systems is granted on a least-privilege basis, logged, and reviewed regularly.
- Data is encrypted in transit and at rest on the platforms above.
- Portal passwords are stored only as salted hashes. Authenticator secrets and one-time codes are encrypted or hashed, never stored in plain text.
- 24/7 Managed Detection and Response (MDR) monitors our environment and our clients' environments around the clock, with a human security operations team able to isolate compromised accounts and devices at any hour.
- Endpoint detection and response, email security and data loss prevention controls are applied across our environment.
- Staff are bound by confidentiality obligations and receive regular security awareness training.
- Our security posture is fully aligned with the CIS Controls v8.1 framework published by the Center for Internet Security.
No system is completely secure. If you believe your information has been compromised, please contact us immediately using the details in section 18.
Who we share it with.
We do not sell personal information. We may disclose personal information to:
- Technology and hosting providers - including Microsoft, Google, Synergy Wholesale, Anthropic and Cloudflare, so that we can deliver, host and secure our services.
- Security and service delivery tools - including Blackpoint Cyber (24/7 managed detection and response) and SuperOps (professional services automation, ticketing, and remote monitoring and management), together with our documentation and transactional email platforms.
- Software vendors and distributors - where we procure, license or support their products on your behalf.
- Professional advisers - accountants, lawyers, insurers and auditors, where reasonably necessary.
- Payment and accounting providers - to invoice and process payments.
- Credit reporting bodies - Equifax, Experian and CreditorWatch, to whom we may report payment information as described in section 13.
- Government agencies, regulators and law enforcement - where required or authorised by law, including under the Notifiable Data Breaches scheme.
- A purchaser or successor - in connection with a sale, merger or restructure of our business, subject to equivalent privacy commitments.
We require our providers to handle personal information securely and only for the purpose for which it was disclosed.
Overseas disclosure.
Our default position is to keep client data within Australia, and we select Australian regions wherever a provider offers them.
Some of the providers we use are global companies headquartered outside Australia, principally in the United States. Personal information may be processed outside Australia in the following cases: 24/7 managed detection and response provided by Blackpoint Cyber (United States); our professional services automation and remote monitoring platform, SuperOps (United States); AI assistance provided by Anthropic (United States), whose services do not currently offer an Australian processing region; vendor support; content delivery and anti-bot verification (Cloudflare); and transactional email. In each case only the information reasonably necessary for the task is sent, and it is not retained by the recipient as a system of record.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient handles it in a way that is consistent with the Australian Privacy Principles, including by relying on contractual data protection terms and the provider's published security and privacy commitments.
Website & cookies.
Our website is designed to collect as little as possible. We do not use advertising trackers or third-party analytics cookies.
lcorp_auth) that keeps you signed in. It is removed when you log out or when the session expires.You can block or delete cookies in your browser settings. Doing so may prevent you from signing in to the client portal.
Our website may link to third-party sites. We are not responsible for the privacy practices of those sites and encourage you to read their policies.
Retention & deletion.
We keep personal information only for as long as it is needed for the purposes described in this policy, or as required by law. As a guide:
- Website enquiries are kept for as long as needed to respond and follow up, and are deleted if no engagement follows.
- Client account, support and configuration records are kept for the life of the engagement and for a reasonable period afterwards to support handover, warranty and legal obligations.
- Financial records are kept for a minimum of seven years as required by Australian tax law.
- Portal session records are automatically purged once the session expires.
When personal information is no longer required, we take reasonable steps to destroy it or permanently de-identify it.
Direct marketing.
We may send you information about our services, security advisories and industry updates where you have consented or would reasonably expect it, in accordance with the Privacy Act and the Spam Act 2003 (Cth).
Every marketing message we send includes a simple way to unsubscribe. You can also opt out at any time by emailing us. Service-related communications (for example, outage notices, security alerts or renewal reminders) are not marketing and may continue while you remain a client.
Credit reporting.
Where we supply services on credit terms, we are a credit provider under Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code. This section applies to individuals whose personal information may be included in credit reporting, for example sole traders, partners, directors and guarantors of our business clients.
What we may disclose
We may disclose the following credit information to credit reporting bodies (CRBs):
- Identification details, such as name, date of birth, address and ABN.
- The fact that we have provided credit, the type and amount of credit, and the date the account was opened or closed.
- Repayment history information, being whether payments were made on time.
- Default information, where an amount of $150 or more is at least 60 days overdue and we have given the required notices.
- Payment information, being that an overdue amount has since been paid.
- Information about serious credit infringements, such as fraud or an intentional attempt to evade payment.
Who we disclose it to
The credit reporting bodies we may use are:
A CRB may include the information we provide in reports it gives to other credit providers to help them assess your creditworthiness. Each CRB has its own policy explaining how it manages credit information, available at the links above.
Your rights
- You can ask a CRB not to use your credit information for pre-screening of direct marketing by credit providers.
- If you believe you have been, or are likely to be, a victim of fraud, you can ask a CRB not to use or disclose your credit information for a ban period.
- You can request access to, or correction of, the credit information we hold about you, and complain about our handling of it, using the process in sections 14 and 16.
Before we disclose default information about you to a CRB we will notify you in writing, as the Privacy Act requires, and give you an opportunity to pay or dispute the amount.
Access & correction.
You have the right to request access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
To make a request, contact us using the details in section 18. We will need to verify your identity before releasing information. We will respond within a reasonable period, usually within 30 days. We do not charge for making a request, though we may charge a reasonable fee for the cost of retrieving and providing large amounts of information.
In some circumstances we may refuse access or correction as permitted by the Privacy Act. If we do, we will explain why in writing and tell you how to complain.
If the information relates to a client organisation's systems that we manage, we may need to refer your request to that organisation.
Data breaches.
We maintain an incident response plan and participate in the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act.
If we become aware of a data breach that is likely to result in serious harm to any individual, we will take immediate steps to contain it, assess it, and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required. Where the breach involves a client's data, we will notify that client without undue delay so they can meet their own obligations.
Complaints.
If you believe we have breached the Australian Privacy Principles or mishandled your personal information, please contact us first using the details in section 18. We take complaints seriously and will acknowledge your complaint promptly, investigate it, and respond in writing, usually within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:
Changes to this policy.
We may update this policy from time to time to reflect changes in our practices, technology or the law. The current version will always be published at lcorpit.com.au/privacy.html, with the effective date shown at the top. Material changes affecting existing clients will be communicated directly.
Contact us.
Privacy questions, access requests and complaints can be directed to our Privacy Officer:
LettersCorp Pty Ltd T/A LCorp IT
PO Box 430
Oxenford QLD 4210
Australia