1. Scope and responsibility
This policy applies to YUMA IT PTY LTD (ABN 62 684 389 839, ACN 684 389 839), trading as Yuma IT when we collect or hold personal information through this website, enquiries, sales, contracting, support, managed services, professional services, or DingoDocs administration.
DingoDocs is primarily customer-controlled software. When a customer runs DingoDocs in its own environment, that customer controls user, assessment, evidence, finding, report, identity, and integration data stored there. We do not receive that data merely because DingoDocs is used.
2. Information we collect
Depending on how you deal with us, we may collect:
- identity and business contact details, including name, employer, role, email, phone number, and address;
- account and access details, including organisation, role, authentication events, and support permissions;
- commercial records, including enquiries, demonstrations, quotes, Orders, invoices, marketplace identifiers, and payment status;
- communications, feedback, support requests, diagnostics, meeting notes, and correspondence;
- website and security data, including IP address, browser, device, timestamps, requested pages, referral information, and protective service logs; and
- Customer Data an authorised customer intentionally gives us for hosting, support, investigation, or professional services.
Customer Data may contain confidential assessment material, security evidence, credentials, or personal and sensitive information. Customers should provide only material that is necessary and authorised.
3. How we collect information
We usually collect information directly from you when you contact us, arrange a demonstration, accept an Order, request support, or work with us. We may also receive it from your employer, an authorised partner, AWS Marketplace, public business records, or services you ask us to use.
If we receive personal information we did not request, we assess whether we could lawfully have collected it. If not, we destroy or de-identify it where lawful and reasonable.
4. Why we use information
We use personal information to:
- respond to enquiries, arrange demonstrations, and manage relationships;
- prepare and administer Orders, subscriptions, invoices, marketplace entitlements, and support;
- provide hosting, professional services, security response, and requested technical assistance;
- operate, secure, diagnose, maintain, and improve our website and services;
- meet legal, accounting, insurance, audit, and regulatory duties; and
- send relevant business communications where permitted, with an unsubscribe option for marketing.
We do not sell personal information. We do not use Customer Data to train general-purpose AI models.
5. Disclosure and service providers
We may disclose personal information to staff and contractors who need it, professional advisers, insurers, payment and marketplace providers, hosting and security providers, communication providers, and authorities where required or authorised by law.
We require service providers to use information only for the agreed service and to protect it appropriately. A customer controls disclosures from its own DingoDocs deployment.
6. Overseas handling
Some providers may store or process business contact, marketplace, support, or website data outside Australia, including in the United States and other locations selected by the customer or provider. Countries can change as providers update their services.
Where Australian privacy law applies, we take reasonable steps required by law before disclosing personal information overseas. Customers choose the regions and providers used for customer-controlled DingoDocs deployments.
7. Website data and cookies
Our website and infrastructure may record standard request and security logs needed to deliver pages, prevent abuse, diagnose faults, and understand aggregate use. We do not use third-party advertising cookies on this site.
Your browser can block or delete cookies. Essential security or preference functions may not work if required storage is disabled.
8. Security and retention
We use administrative, technical, and physical safeguards appropriate to the information and risk. No internet transmission or storage system is completely secure.
We retain personal information only while needed for the purpose collected, legal and accounting obligations, security, disputes, and contract administration. We then delete or de-identify it where lawful. Customer-controlled deployment retention is set and operated by the customer.
9. Access and correction
You may ask to access or correct personal information we hold about you by contacting hello@yumait.com.au. We may need to verify your identity. If law permits us to refuse, we will explain the reason and available complaint path where required.
For information held in a customer-controlled DingoDocs deployment, contact the customer that operates that deployment first.
10. Privacy complaints
Send privacy questions or complaints to hello@yumait.com.au with enough detail for us to investigate. We will acknowledge the complaint and respond within a reasonable time.
If you are not satisfied, you may contact the Office of the Australian Information Commissioner. Other privacy regulators may also have jurisdiction depending on your location.
11. Changes and contact
We may update this policy when our practices, providers, products, or legal obligations change. The effective date on this page identifies the current version.
Contact: YUMA IT PTY LTD, 49 Phillip Ave, Watson ACT 2602, Australia; hello@yumait.com.au; or our contact page.