# Privacy Policy: Incisive Cyber

**Effective Date:** August 14, 2026  
**Status:** Active & Mandatory  

---

## 1. Introduction

Incisive Cyber ("we", "us", "our") respects your privacy. As a cybersecurity advisory firm, data protection, confidentiality, and technical integrity are fundamental to our practice. 

This Privacy Policy explains how we collect, use, and protect personal information in compliance with the **Australian Privacy Act 1988 (Cth)**, the **13 Australian Privacy Principles (APPs)**, applicable **NSW privacy standards (PPIPA)**, and international privacy benchmarks (such as the **GDPR**).

---

## 2. Information We Collect

We practice strict data minimisation. We only collect information essential for delivering high-assurance advisory services and maintaining website security:

- **Inquiry & Contact Data:** Name, business email, job title, organisation name, and details provided when submitting our confidential contact form.
- **Security & Technical Telemetry:** Standard, non-identifying HTTP server logs (IP address, browser user agent, timestamps) processed at the network edge strictly for security monitoring and Content Security Policy (CSP) enforcement.

### Cookies & Tracking
We operate a **zero-tracking website**. We do not use third-party advertising pixels, cross-site trackers, or behavioural profiling cookies.

---

## 3. How We Use Information

We use collected information exclusively to:
1. Deliver executive security advisory, Virtual CISO, and resilience engineering services.
2. Respond promptly and confidentially to your consultation requests.
3. Maintain, protect, and audit the security of our digital infrastructure.

**Zero Commercial Data Sales:** We **never** sell, rent, trade, or share your personal or business information with third parties for marketing purposes.

---

## 4. Security & Zero-Trust Governance

In alignment with our core operating principles (**Legal, Ethical, Moral, Secure**), all data entrusted to Incisive Cyber is safeguarded by strict zero-trust controls:
- **Technical Safeguards:** Modern TLS 1.3 encryption in transit and AES-256 encryption at rest.
- **Automated Pre-Flight Verification:** Continuous static analysis (`npm run sec-check`) ensuring zero unauthorised script execution or data leakage.
- **Restricted Access:** Access is limited strictly to authorised advisory partners bound by non-disclosure agreements.

---

## 5. Your Rights & Complaints

You have the right to request access to, correction of, or deletion of any personal information we hold about you.

* **Contact Us:** Email our Privacy Lead at `privacy@incisivecyber.com` (or submit a request via our secure contact form). We acknowledge inquiries within 5 business days.
* **Regulatory Oversight:** If you believe a privacy issue remains unresolved, you may lodge a complaint with the [Office of the Australian Information Commissioner (OAIC)](https://www.oaic.gov.au) or the [Information and Privacy Commission NSW (IPC NSW)](https://www.ipc.nsw.gov.au).

---

*Incisive Cyber — Clarity. Resilience. Insight.*
