Privacy statement
Last updated: 28 August 2026
We ask companies to trust us with sensitive information about their systems. It would be poor form to be vague about what we do with information about the people who contact us. This page is short on purpose.
What we collect from this website
- The enquiry form. Your name, company, work email, what is driving the enquiry, any deadline, and whatever you write in the message field.
- Nothing else. There are no analytics scripts, no advertising pixels, no cookies set by us, and no third-party trackers on this site.
- The self-check calculator collects nothing. The six numbers you enter run entirely in your browser. They are never transmitted, stored or seen by us unless you choose to paste them into the enquiry form yourself.
Our hosting provider processes standard connection logs, including IP address, in order to serve the site and defend it against abuse. We do not use those logs to identify or profile visitors.
Why we hold it and what we do with it
Solely to reply to you and, if it goes further, to scope and deliver an engagement. We do not sell it, rent it, share it with advertisers, or add you to a mailing list. If you enquire and we don't end up working together, we delete the enquiry within twelve months.
Client engagement data
During an engagement we may see findings about your environment, including file paths, permission structures and the existence of sensitive content. This information is:
- accessed read-only, scoped in the statement of work, and time-boxed to the engagement
- held in the client's own tenant wherever the client prefers, and otherwise in an encrypted store under our control
- never used as a case study, example or marketing material without written permission and appropriate de-identification
- deleted on the timetable set out in the engagement's data handling schedule
Access credentials granted to us are revoked on delivery. You can verify every action we take in your own audit logs, and we will tell you which log to read and how on day one.
Automated decision-making
We do not use any computer program to make, or substantially help make, decisions about individuals who contact us. Enquiries are read and answered by a person.
Disclosure to others
We use a small number of service providers to run the business โ hosting, email and document storage. They process information on our instructions only. Where an engagement requires a specialist associate, such as a penetration tester or a privacy lawyer, we tell you who they are and get your agreement before they see anything.
We do not disclose personal information to overseas recipients for marketing purposes. Some of our service providers store data outside Australia; we will tell you which and where on request.
Security
Encryption in transit and at rest, multi-factor authentication on every account, least-privilege access, and logging. We carry professional indemnity and cyber liability insurance. If we ever suffer an eligible data breach we will notify affected people and the OAIC as required under the Notifiable Data Breaches scheme.
Your rights
You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Email privacy@z3roday.com and we will respond within 30 days.
If you are unhappy with how we handled a privacy matter, tell us first and we will try to fix it. If that doesn't resolve it, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, or to the Office of the Privacy Commissioner in New Zealand at privacy.org.nz.
Changes
If this statement changes materially we will update the date at the top and, where it affects an active client, tell you directly.