How Edge4Ward Pty Ltd collects, stores, processes, and protects data in the course of delivering our services.
Last updated: 3 June 2025
This Data Policy sets out how Edge4Ward Pty Ltd ("Edge4Ward", "we", "us") collects, stores, processes, and protects data — including personal information, client data, and operational data — in the course of operating our business and delivering professional services.
This policy applies to all Edge4Ward employees, contractors, and representatives; all data systems managed or operated by Edge4Ward; and data processed on behalf of clients as part of service delivery. This policy should be read alongside our Privacy Policy and Terms of Use.
Information relating to identified or identifiable individuals, including contact details, employment information, and usage data. Handling is governed by the Privacy Act 1988 (Cth) and our Privacy Policy.
Data provided to us by clients in the course of service delivery, which may include business records, system data, employee information, financial data, or other proprietary information. This data remains the property of the client at all times.
Data generated in the operation of our own systems, including logs, analytics, system performance data, and internal business records.
Certain engagements may involve sensitive categories of data including health information, financial records, or government identifiers. Additional safeguards apply as described in Section 6.
Edge4Ward is committed to the following principles in all data handling activities:
Where Edge4Ward processes data on behalf of a client as part of a service engagement:
Edge4Ward uses industry-leading cloud infrastructure providers for data storage and processing. Primary data residency is in Australia.
All infrastructure providers are selected based on their security certifications, data residency capabilities, and compliance with applicable Australian standards.
We retain data for the minimum period necessary. General retention periods include:
Upon expiry of the applicable retention period, data is securely deleted or de-identified using industry-standard methods.
Edge4Ward may engage third-party sub-processors to assist in delivering services. All sub-processors are subject to a prior security and privacy assessment, contractual data protection obligations, and limitations on the use of data solely for authorised purposes. A list of key sub-processors is available on request.
In the event of a data breach:
To report a suspected security incident: security@edge4ward.com.au
Where data is transferred outside Australia, Edge4Ward takes reasonable steps to ensure the receiving party provides equivalent data protection to that required under Australian law. For clients subject to the GDPR, Edge4Ward can provide appropriate transfer mechanism documentation including Standard Contractual Clauses (SCCs).
Subject to applicable law, individuals whose personal data we hold have the right to access, correct, delete, restrict processing of, and port their data, as well as the right to object to certain processing and to withdraw consent. To exercise any of these rights, contact our Privacy Officer (see Section 12). We will respond within 30 days.
Edge4Ward's data governance function is overseen by our Privacy Officer.
This Data Policy is reviewed and updated at least annually. The current version is always available at this URL.