Privacy policy
What we collect, why we collect it, who we share it with, and how to access, correct or complain about it.
This policy explains how COMPwize collects, uses, stores and discloses personal information, and how you can access it, correct it or complain about how we have handled it. It is written to follow the Australian Privacy Principles in the Privacy Act 1988 (Cth). COMPwize is a small business, and small businesses are not always covered by that Act, but we work to those standards anyway. This policy covers information we collect through www.compwize.com.au, by phone, by message, in person, and while repairing and supporting your equipment.
On this page
- 1. Who we are and how to contact us
- 2. What personal information we collect
- 3. How we collect it
- 4. Website forms and FormSubmit
- 5. Fonts, cookies and analytics
- 6. Why we use your information
- 7. Who we disclose information to
- 8. Data on your device during a repair
- 9. How we keep information secure
- 10. How long we keep information, and how we destroy it
- 11. Overseas disclosure
- 12. Direct marketing and opting out
- 13. Access and correction
- 14. Complaints about privacy
- 15. Data breaches
- 16. Children's information
- 17. Changes to this policy
- 18. Effective date and contact
1. Who we are and how to contact us
COMPwize is a one-person computer repair and IT support business serving Western Sydney and the area around Mount Druitt, New South Wales.
Michael Rafla is the person responsible for privacy at COMPwize. Privacy questions, access requests and complaints come to him directly.
Phone 02 9833 1800. Contact form: www.compwize.com.au/contact. Web www.compwize.com.au. Hours Monday to Friday 8am to 7pm, Saturday 9am to 4pm.
2. What personal information we collect
We collect only what we need to do the work and keep proper records. Depending on the job, that can include:
Your name, phone number and email address.
Your suburb, and your street address where you have asked for pickup and delivery or an onsite visit.
Device details: make, model, serial number, the fault, its condition when we received it, and what we did to it.
Account or licence details you give us to complete a job, such as a Windows product key or a device password. See section 8.
Payment records: the invoice, what was paid, when and by what method. We do not store full card numbers, as card payments are handled by a payment processor.
Our correspondence with you: booking form submissions, emails, text messages, WhatsApp and Messenger conversations, and notes of phone calls.
Business customer details such as business name, ABN, site contacts and network details.
We do not collect sensitive information such as health, racial or political information, and we ask you not to send it to us.
3. How we collect it
Directly from you in almost every case: through a booking or contact form on www.compwize.com.au, by phone or text on 02 9833 1800, by email, through WhatsApp or Facebook Messenger, in person at a pickup, delivery or onsite visit, and at a COMPwize Locker once the lockers are open.
We also collect technical information from the device itself while diagnosing and repairing it.
Sometimes we collect information about you from someone else, for example when a family member books a repair for you or a business books a job for a staff member. This policy applies then too.
If you do not give us the information we ask for, we may not be able to do the job. We will tell you if that is the case.
4. Website forms and FormSubmit
Forms on www.compwize.com.au are delivered to us by a third-party form-forwarding service called FormSubmit.
What you type into a form, including your name, contact details and what you write about your device, passes through FormSubmit's systems on the way to our inbox. FormSubmit handles it under its own privacy policy and terms, we do not control its systems, and its servers may be outside Australia.
If you would rather not use the form, call 02 9833 1800 or email us directly.
5. Fonts, cookies and analytics
Our website loads web fonts from Google's servers. When a page loads, your browser requests the font files from Google, and Google receives your IP address and basic browser information as part of that request. Google handles that under its own privacy policy.
We do not set advertising cookies and we do not run advertising trackers or retargeting pixels.
We do not currently run website analytics.
The site may use a small number of functional cookies or local storage entries needed for it to work, and these do not identify you. Our web host keeps standard server logs, which can include IP addresses, for security and troubleshooting.
6. Why we use your information
We use personal information to quote, book and carry out your repair, build, remote session or onsite visit; to contact you about the job, including pickup slots and telling you when a device is ready; to order parts and lodge warranty claims; to take payment and issue tax invoices; to keep a service history so we know what was done to a device if it comes back; to handle warranty claims and complaints; and to meet our record-keeping, tax and legal obligations.
We do not sell your personal information or share it with data brokers.
7. Who we disclose information to
We share personal information only where it is needed to do the job or where the law requires it:
Parts suppliers and distributors, when we order a part or lodge a warranty claim. They usually receive the make, model and serial number, and sometimes your name.
Couriers or freight companies, if a part or device has to be shipped. They receive the address and a contact number.
Locker host businesses, once the lockers are open. A host provides the space and the opening hours. It does not receive your repair details and cannot open your compartment.
Payment processors and our bank, for card and transfer payments.
Managed IT Helpdesk, our managed services division, where you are a managed client or moving to a managed plan. It operates under its own agreement and privacy arrangements.
Our accountant and bookkeeper, for invoicing and tax.
Software and cloud providers we use to run the business, such as email, messaging, remote support and backup tools.
Police or another authority, where we are required to report something or are compelled by law. See section 8.
Anyone else you ask us to deal with, such as a family member arranging the repair for you.
8. Data on your device during a repair
We access only what the job requires. A hardware repair usually means we log in, test and log out. A software repair may mean we look at your files, email settings or browser to find the fault.
We do not browse your personal files, photos or messages out of curiosity, and we do not copy them.
Where we take a backup or drive image as part of a job, we tell you, keep it only as long as the job needs it, and delete it once you confirm the device is working. Tell us if you want it kept or handed to you. Data recovery jobs handle your files only to copy them back to you.
Access credentials you give us are used only for the job and deleted when it closes.
If we come across material that appears to be clearly illegal, we are obliged to report it to the authorities and will do so without notifying you first. This is set out in our terms and conditions.
9. How we keep information secure
Devices in our care are kept in a locked, alarmed area of a private premises, not on public display, and are not left unattended in a vehicle.
Our computers are password protected, use full disk encryption, and run current security software and updates. Business accounts use multi-factor authentication where the provider offers it.
Paper records, where we keep any, are stored securely and destroyed by shredding. Only Michael Rafla has access to customer records, as there are no other staff.
No system is perfectly secure. If something goes wrong, section 14 explains what we do.
10. How long we keep information, and how we destroy it
We keep job and invoice records for at least 7 years, because tax and business record-keeping law requires it, and enough service history to support the warranty on the work.
Backups and drive images taken as part of a job are deleted once the job is closed and you have confirmed the device is working, unless you asked us to keep them. Passwords and access credentials are deleted when the job closes. Website enquiries that do not become jobs are deleted once they are clearly no longer live.
When information is no longer needed and we are not required to keep it, we delete or destroy it securely. Drives are wiped or physically destroyed. Paper is shredded.
11. Overseas disclosure
We are a local business and we keep customer records in Australia. Some of the services we use to run the business, however, store or process data overseas.
That includes our website form-forwarding service, email and messaging providers, cloud storage, remote support software, and the font service described in section 5. These providers are typically based in the United States or hold data in data centres in the United States, Europe or Asia. When you message us through WhatsApp or Facebook Messenger, those conversations are held by Meta under its own privacy policy and may be stored overseas.
We take reasonable steps to use providers with proper security and privacy practices, but information held overseas is also subject to the laws of that country. If you would prefer your information stayed out of those services, call us and tell us.
12. Direct marketing and opting out
We may occasionally send an email or text about our services, a reminder that a machine is due for a clean-out, or a note about something affecting your device.
Every marketing message includes a way to opt out. You can also opt out any time by replying, by calling 02 9833 1800, or by using our contact form at www.compwize.com.au/contact. We action opt-outs promptly.
Opting out of marketing does not stop messages about a job you have booked, such as a pickup confirmation or a notice that a device is ready. Those are service messages, not marketing.
We do not use your information for third-party marketing and we do not supply your details to anyone else for marketing.
13. Access and correction
You can ask for a copy of the personal information we hold about you. Contact us on 02 9833 1800 or use our contact form at www.compwize.com.au/contact. We may ask you to confirm who you are first.
We aim to respond within 30 days. There is no charge for a simple request. If a request is large and takes substantial time, we will tell you what it would cost before we start.
If anything we hold is wrong, out of date or incomplete, tell us and we will correct it.
There are limited situations where we cannot give access, for example where it would affect another person's privacy or the law prevents it. If we refuse, we will explain why in writing and tell you how to complain.
You can ask us to delete information we hold. We will, unless we are required to keep it for tax, legal or warranty reasons, and we will tell you what we have to keep and why.
14. Complaints about privacy
If you think we have mishandled your personal information, tell us first. Call 02 9833 1800 or use our contact form at www.compwize.com.au/contact with the details.
We aim to acknowledge your complaint within 2 business days, investigate it, and give you a written response within 30 days. If it will take longer we will tell you why.
If you are not satisfied with our response, you can take the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Complaints about the service itself, rather than privacy, are dealt with under our terms and conditions and can be escalated to NSW Fair Trading.
15. Data breaches
If personal information we hold is lost, or accessed or disclosed without authorisation, we will act quickly to contain it and work out what happened.
Where a breach is likely to result in serious harm to anyone affected, we will notify the people affected and the Office of the Australian Information Commissioner, in line with the Notifiable Data Breaches scheme. We will tell you what happened, what information was involved, and what you should do about it.
16. Children's information
Our services are aimed at adults and we do not market to children.
We often repair devices belonging to children and teenagers. Where the customer is under 18 we deal with a parent or guardian for the booking, the approval and the payment.
We collect only what the repair needs, and we do not access a young person's files beyond that. If you believe we hold information about a child that we should not, contact us and we will look into it.
17. Changes to this policy
We may update this policy. The current version is always at www.compwize.com.au/privacy. If we make a significant change we will say so on the page and update the effective date below.
18. Effective date and contact
This policy is effective from 23 September 2026.
COMPwize, phone 02 9833 1800, contact form www.compwize.com.au/contact, web www.compwize.com.au.
Last updated September 2026. Questions about this page? Call 02 9833 1800 or use the contact form.
