top of page

Privacy Policy

Last updated: 7 September 2026

​

1. Background

​

We’re Sabirus Advisory (Sabirus, we, us or our), a boutique multidisciplinary consultancy based in Sydney Australia (ABN 24 701 980 789).

 

This Policy explains how we collect, hold, use and disclose personal information.

 

We comply with the Australian Privacy Principles (APPs) as set out in the Privacy Act 1988 (Cth).

 

This Policy applies to personal information we collect from:

​

  • clients and prospective clients, and the individuals within client organisations we deal with in the course of an engagement

  • people who contact us, subscribe to our updates, or engage with our website or professional profiles (including LinkedIn)

  • our contractors, associates and referral partners, and their representatives, and

  • job applicants and people we consider engaging to work with us.

 

We update this Policy from time to time. The current version is always available at sabirus.com.au, or on request (see Contact us, below).

Where an engagement requires us to handle personal information on a client's behalf, we do so under the terms of that engagement and the applicable confidentiality obligations, in addition to this Policy.

 

2. What personal information do we collect?

 

We collect the minimum personal information we reasonably need to carry out our work, run our business, and comply with our legal and professional obligations. For example:

​

  • when you enquire about our services or engage us, we may collect your name, job title, organisation, and contact details, and the information you give us about the engagement itself

  • in the course of an engagement, we may collect information contained in the material a client shares with us for review — which may include personal information of the client's own staff, customers or other individuals, provided to us so we can advise on it

  • when you subscribe to our updates or insights, we collect your name, organisation and email address

  • when you contact us by email, phone, our website, or social media, we may collect your contact details and the content of your message

  • when a contractor, associate or referral partner works with us, we may collect the name, contact details and relevant professional information of their representatives

  • when you apply to work with us, we collect your name, contact details, CV, work history, qualifications and referee information

  • when we engage you to work with us, we collect the information needed to manage that relationship, including payment and, where relevant, ABN details.

​

Sensitive and third-party information handled during engagements

​

Some engagements — for example, privacy impact assessments, incident response, or regulatory investigations — may require us to review material containing sensitive information (such as health information) about individuals who are not our direct client. We only handle this information for the purpose of the engagement, under the client's instructions and any confidentiality terms agreed with the client, and we do not use it for

any other purpose.

​

If you don't want to give us your information…

 

…you don’t have to. However, if you don't, we may not be able to respond to your enquiry, provide our services, or consider your application.

 

3. How do we collect personal information?

​

We generally collect personal information directly from you — for example, when you contact us, engage us, subscribe to our updates, or apply to work with us.

​

Where an engagement requires it, we may also collect personal information from or about third parties as instructed by a client, or from publicly available sources (for example, a company register or a professional networking profile) in the course of preparing for or delivering our advice.

​

4. Why do we collect, use and disclose personal information?

​

We collect, use and disclose personal information to carry out our advisory work, manage our business, and comply with the law. For example:

​

  • delivering the services a client has engaged us for

  • responding to enquiries and managing our client relationships

  • sending updates or insights to people who have subscribed to receive them

  • managing our engagements with contractors, associates and referral partners

  • recruiting and managing people who work with us

  • invoicing and processing payments, and

  • meeting our legal, regulatory and professional obligations.

 

We collect, use and disclose personal information where you've consented, where it's reasonably necessary for the purposes above, or where the law otherwise permits or requires it.

 

Direct marketing

​

We will only send you marketing about our services (such as insights or event invitations) if you've agreed to receive it, or as otherwise permitted by law. You can opt out at any time using the unsubscribe link in any email, or by contacting us directly (see 'Contact us', below).

 

Retention

 

We keep personal information only for as long as we need it for the purposes it was collected, to meet our professional and legal obligations (including record-keeping obligations that may follow the end of an engagement), or as otherwise agreed with a client. When we no longer need it, we securely destroy or de-identify it.

​

Third parties and service providers

​

We may share personal information with third parties who help us run our business, such as:

​

  • IT, cloud hosting, data storage and security providers

  • professional advisers (for example, our accountants or lawyers), and

  • subcontractors or associates engaged to help deliver a specific engagement, on a confidential basis.

 

We take steps to ensure these third parties handle personal information securely and only for the purposes we've engaged them for.

 

We do not sell personal information.

 

5. Overseas storage and disclosure

 

We may store or process personal information using cloud-based systems that are located, or have back-up facilities, outside Australia. Where this occurs, we take reasonable steps to ensure the information continues to be handled in a manner consistent with the APPs, including through contractual and technical security measures with our service providers.

​

6. Your rights

​

You can ask us to:

​

  • give you access to the personal information we hold about you

  • correct that information if it's wrong or out of date, or

  • give you a copy of it.

​

There are some limits on these rights. For example, we may not be able to give you access to information about other people, or information we're required by law to withhold.

​

Where we hold a client's information under an enagement, we may need to refer your request to that client.

​

We'll respond to a request within a reasonable time, generally within 30 days. There's no fee to make a request, though we may need to first confirm your identity.

​

7. Complaints

​

If you're concerned about how we've handled your personal information, please contact us and we'll look into it. We will:

​

  • acknowledge your complaint promptly

  • investigate the matter, including gathering relevant facts and documents, and

  • respond to you in writing with our findings and what we'll do to address the issue, generally within 30 days.

​

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner: oaic.gov.au | 1300 363 992.

​

8. Contact us

​

If you have any questions about this Policy, or wish to make a request or a complaint, please contact us hello@sabirus.com.au

bottom of page