My IT and Apps (we, us, our) is committed to protecting your privacy. We handle personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). This Privacy Policy tells you what personal information we collect, how and why we collect and use it, who we share it with, how we keep it secure, and the choices and rights available to you.
Introduction & scope
This Privacy Policy applies to personal information we collect through, and in connection with:
- our website at myitandapps.com.au and its sub-pages, including product pages (the Website);
- our business consulting and technology services (the Services);
- our software products, including the Cordex Forms plugin, the Cordex Relationship Map Dataverse solution and any other apps, plugins, connectors or tools we make available (the Products); and
- our dealings with customers, prospective customers, suppliers and other contacts.
This Policy should be read together with our Terms & Conditions and, for the Cordex Forms software, the Cordex Forms Terms and, for the Cordex Relationship Map software, the Cordex Relationship Map Terms. By using the Website, engaging our Services, or purchasing or using our Products, you acknowledge you have read and understood this Policy.
Who we are
My IT and Apps is an Australian business providing business consulting and information-technology services and software, specialising in the Microsoft Power Platform, Dynamics 365 CE, system integration and data migration.
ABN 82 659 633 888 · GITC Q-7120
Privacy enquiries: privacy@myitandapps.com.au
General enquiries: support@myitandapps.com.au
Key terms
- Personal information has the meaning in the Privacy Act, information or an opinion about an identified individual, or an individual who is reasonably identifiable.
- Sensitive information is a subset of personal information (such as health information, or information about racial or ethnic origin, religious beliefs or memberships) that attracts higher protection under the APPs.
- Your Content means data, records, form submissions, credentials or materials you (or your website's visitors) provide, upload or process through our Services or Products.
- Customer means a business or individual that engages our Services or licenses our Products.
Information we collect
The personal information we collect depends on how you interact with us. It may include:
Information you give us
- Enquiry and contact details: when you submit a form on our Website or email us: your name, email address, company/organisation, phone number, the service or product you are interested in, and the content of your message.
- Engagement information: when you become a Customer: contact and role details of your personnel, project requirements, and information exchanged during delivery.
- Purchase and licensing information: when you buy a Product licence: your name, business and billing contact details, and the licence and order records. Card payments are processed by our checkout provider; we do not collect or store full payment-card numbers.
- Correspondence: records of your communications with us and any support requests.
Information we collect automatically
- Technical and usage data: when you visit the Website: IP address, browser and device type, referring pages, and pages viewed (see Cookies & analytics).
- Spam-protection signals: our contact forms use Google reCAPTCHA, which collects hardware, software and interaction data to distinguish humans from bots.
- Delivery diagnostics: if an enquiry email cannot be delivered, the enquiry details (including the sender's IP address) may be written to a secure, non-public log so we can follow up and diagnose the fault.
We generally do not seek sensitive information. If you provide sensitive information to us voluntarily (for example in a free-text message), you consent to us handling it for the purpose for which you provided it.
How we collect it
We collect personal information directly from you, when you complete a form, email or call us, enter into an engagement, or purchase a licence, and automatically through your use of the Website. In some cases we may collect information from third parties, such as our checkout provider (in relation to a purchase) or publicly available business sources. Where it is reasonable and practicable, we collect personal information directly from the individual concerned.
Why we collect & use it
We collect, hold, use and disclose personal information for purposes including to:
- respond to your enquiries and provide information you request;
- provide, manage and improve our Services and Products, and provide support;
- process orders, licences, renewals, invoicing and payments;
- operate, secure, maintain and improve the Website;
- protect against spam, fraud, misuse and security threats;
- send you service, transactional and (where permitted) marketing communications;
- maintain business records and manage our relationship with you; and
- comply with our legal obligations and enforce our legal rights.
We will only use or disclose your personal information for the purpose for which it was collected, a related purpose you would reasonably expect, a purpose you have consented to, or as otherwise permitted or required by law.
Cordex Forms & your data
It is important to understand how data flows when you use Cordex Forms, because in most cases we do not receive the data your website collects.
You control the data; the software runs in your environment. Cordex Forms is installed on your own WordPress site and writes form submissions directly into your own Microsoft Dataverse, Dynamics 365 or SharePoint. Your Microsoft credentials are encrypted and stored on your server and are never sent to us or to the browser. In privacy terms, you are the entity responsible for that personal information, and we are a provider of software you operate.
- Submission data (leads, enquiries, uploaded files and related records) is captured by your forms and delivered to your Microsoft environment. It is not routed to My IT and Apps in the ordinary course of the software operating.
- Your responsibilities. As the operator of the site, you are responsible for having a lawful basis and any necessary consents to collect and process that data, for your own privacy notice to your visitors, and for configuring the plugin's privacy controls (such as IP-truncation and metadata capture) in line with your obligations.
- When we do access data. We may access limited information you choose to send us, for example, if you share configuration details, logs or sample records when requesting support. We handle any such information under this Policy and only for the purpose of assisting you.
- Licensing data. We (and our licensing/checkout provider) process the account and licence-key information needed to issue, validate and renew your licence.
Cordex Relationship Map & your data
Cordex Relationship Map is installed as a solution into your own Microsoft Dataverse or Dynamics 365 environment. As with Cordex Forms, in the ordinary course of the software operating we do not receive the data it reads or writes.
The map runs where your data already lives. It is a set of self-contained web resources and a PCF control inside your environment. It reads and writes records through the Dataverse Web API as the signed-in user, within that user's own security roles, and no external services are required for the map itself. Nothing is sent anywhere unless a user explicitly asks Cordex AI a question. In privacy terms, you are the entity responsible for that personal information, and we are a provider of software you operate.
- Relationship data. Stakeholder role and sentiment tags, influence lines, sentiment history, engagement scores, configuration profiles and the licence row are stored in Dataverse tables that ship with the solution, inside your environment, and are subject to your own retention and access controls.
- Cordex AI. When a user asks a question, requests a brief or runs a sentiment assessment, the relevant map data (and, if your administrator has enabled full system access, read-only query results) is sent to the AI provider you have configured - Claude (Anthropic), Azure OpenAI or an in-tenant flow - under your own account and API key. That provider's privacy terms apply to that transfer. We do not operate or proxy the provider, and provider keys are stored AES-256 encrypted in your environment. Features that widen data egress, including any AI read on your own staff or teams, are off by default and enabled only by your administrator.
- Your responsibilities. As the operator of the environment, you are responsible for having a lawful basis and any necessary consents to record and process stakeholder, sentiment and engagement information about individuals - including your own personnel - for your own privacy notice, and for completing your own AI-compliance review before enabling optional AI features.
- When we do access data. We may access limited information you choose to send us, for example configuration exports, logs or screenshots when requesting support. We handle any such information under this Policy and only for the purpose of assisting you.
- Licensing data. We (and our licensing/checkout provider) process the account and licence-key information needed to issue, validate and renew your licence, and the seat-band counts needed to enforce it.
Consulting & technology services
When we deliver consulting, implementation, integration, data-migration or support Services, we may access or process personal information contained in your systems or data (for example during a Dynamics 365 or data-migration project). Where we do so on your behalf, we act on your instructions and only to the extent necessary to deliver the engagement. The specific handling, security and confidentiality arrangements for an engagement are set out in the applicable Service Agreement, which operates alongside this Policy.
Disclosure & service providers
We do not sell your personal information. We may disclose personal information to:
- Service providers who help us operate our business, under confidentiality obligations, including our email/communications provider (Microsoft 365), spam-protection provider (Google reCAPTCHA), web-font provider (Google Fonts), hosting provider, and our licensing/checkout provider for Product purchases;
- Professional advisers such as accountants, auditors and lawyers, where reasonably required;
- Purchasers or successors in connection with a sale, merger or reorganisation of our business; and
- Authorities and others where required or authorised by law, or to protect our rights, safety or property or those of others.
Overseas disclosure
Some of our service providers store or process data outside Australia. In particular, Microsoft and Google operate data centres in various countries, and our checkout provider may process data overseas. Where personal information is disclosed to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the APPs. By providing your personal information you acknowledge that it may be stored or processed overseas, including in the United States, the European Union and other locations where these providers operate.
Third-party services
Our Website, Services and Products interoperate with third-party platforms, including Microsoft (Dataverse, Dynamics 365, SharePoint, Azure, Microsoft 365), Google (reCAPTCHA and Fonts), WordPress and form plugins, and our checkout provider. Your use of, and those providers' handling of your information under, their own services is governed by their respective privacy policies. We encourage you to review them:
- Microsoft: privacy.microsoft.com
- Google (reCAPTCHA & Fonts): policies.google.com/privacy
Data security
We take reasonable technical and organisational measures to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include restricting access on a need-to-know basis, keeping credentials and secrets outside the public web root and encrypted, using secure transport, and applying spam and abuse controls to our forms. However, no method of transmission over the internet or method of electronic storage is completely secure, and we cannot guarantee absolute security.
Data retention
We keep personal information only for as long as necessary for the purposes described in this Policy, to satisfy our legal, accounting, tax and record-keeping obligations, and to resolve disputes and enforce our agreements. When personal information is no longer required, we take reasonable steps to destroy or de-identify it. For data held within your own systems or Microsoft environment through Cordex Forms or Cordex Relationship Map, retention is controlled by you.
Direct marketing
We may send you information about our Services and Products that we think may interest you, where permitted by law. Every marketing message includes a way to opt out, and you can also opt out at any time by contacting us at privacy@myitandapps.com.au. We do not use sensitive information for direct marketing without your consent, and we do not sell your information to third parties for their marketing.
Access & correction
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact our Privacy Officer at privacy@myitandapps.com.au. We will respond within a reasonable period and may need to verify your identity first. Access is generally free; if a request is complex we may advise you of any reasonable cost beforehand. If we decline access or correction, we will explain why in writing, where we are required to do so.
Data breaches
We maintain procedures to identify, contain, assess and respond to data-security incidents. If an eligible data breach involving your personal information occurs, we will notify you and the Office of the Australian Information Commissioner (OAIC) where required under the Notifiable Data Breaches scheme.
Children's privacy
Our Website, Services and Products are directed to businesses and are not intended for children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will take reasonable steps to delete it.
Your choices
You can choose not to provide certain personal information, but this may mean we are unable to respond to your enquiry or provide a Service or Product. You can manage cookies through your browser, opt out of marketing at any time, and request access to or correction of your information as described above. Where we rely on your consent, you may withdraw it at any time (without affecting handling that has already occurred).
Complaints
If you have a concern or complaint about how we have handled your personal information, please contact our Privacy Officer at privacy@myitandapps.com.au. We will acknowledge your complaint, investigate it and aim to respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner:
Web: oaic.gov.au · Phone: 1300 363 992
Changes to this policy
We may update this Privacy Policy from time to time. The current version will be posted on this page with a revised "Last updated" date, and changes take effect when posted (or on any later date we specify). We encourage you to review this page periodically. Your continued use of the Website, Services or Products after changes take effect constitutes acceptance of the updated Policy.
Contact us
For any privacy question, request or complaint, please contact our Privacy Officer:
Email: privacy@myitandapps.com.au
Web: myitandapps.com.au