Privacy Policy

Summary

Two separate regimes govern how blueAPACHE handles information. The website privacy policy covers what it collects from site visitors and customers, why, who it shares it with, cookies, and how to access your information or complain. The Service Agreement adds contractual obligations that bind blueAPACHE once you are a customer: clause 17 on information security, clause 18 on privacy, and the liability clauses that cap what you can recover if either fails. This page sets out both, notes where blueAPACHE's published data residency position and its contractual overseas-transfer consent do not agree, and flags the clauses that most often surprise buyers — including the one where blueAPACHE has no backup obligation at all unless your Service Order says otherwise.

Key facts

Label Value
Privacy Officer By post: Privacy Officer, blueAPACHE, 383 Johnston Street, Abbotsford Victoria 3067
Governing legislation Privacy Act 1988 (Cth) and the Australian Privacy Principles
Data breach notification Immediately, and in any event within 24 hours of discovery
Overseas transfer Prohibited without consent, but standing consent is given to several countries (see below)
GDPR data Customer warrants it will not provide data subject to GDPR
Customer Records on request Within 10 Business Days
Backup obligation Only to the extent set out in the Service Order
Marketing or profiling with Customer Data Prohibited
Subcontracting Permitted without customer consent or notification
Privacy/security/confidentiality/IP liability $1 million per event, $2 million in aggregate
Privacy breach termination Not remedied within 20 Business Days
Policy changes Updated without notice; major changes flagged by a prominent site notice

The website privacy policy

blueAPACHE's published policy explains what it collects from customers and site visitors, why it collects it, who it shares it with, how it secures it, how cookies are used, and how to access your information or complain.

It states that password and network protection and secure storage of paper records are used to protect information. The site uses cookies and pixels, including third-party tracking from LinkedIn, Facebook and Instagram, which you can block or delete through your browser. The policy can change without notice; a major change is flagged on the site with opt-out instructions if it affects how personal information is used. Complaints and questions go in writing to the Privacy Officer at the Abbotsford address.

The contractual regime: privacy (clause 18)

Mutual compliance (18.1). Each party must comply with the Privacy Act 1988 (Cth) as though bound by it when collecting, receiving, using, disclosing, transferring or otherwise handling Personal Information — a contractual obligation that applies even to a party that would not otherwise be an APP entity. Each must also comply with the other's policies on Personal Information and any reasonable written directions.

Purpose limitation (18.2). Personal Information may be collected, used and disclosed only for performance of rights and obligations under the agreement, and for associated administration: invoicing, payment, contract management, risk management, insurance, renewals, delivery, maintenance and support. Onward disclosure is prohibited except to the disclosing party's own personnel to the minimum extent necessary, as required by law, or with the other party's prior written consent. Anyone receiving the information must handle it consistently with the disclosing party's obligations.

Customer consent warranty (18.6). The Customer warrants that it has obtained express informed consent from each individual whose Personal Information blueAPACHE will obtain, covering use in any manner reasonably contemplated by the agreement or stated in blueAPACHE's privacy policy, including overseas transfer. The obligation to collect that individual consent sits with the customer, not with blueAPACHE.

GDPR exclusion (18.6). The Customer warrants it will not provide blueAPACHE with, or ask it to process, any personal data subject to the General Data Protection Regulation (EU) 2016/679. Any organisation with EU or UK data subjects should treat this as a gating issue before contracting rather than a detail to resolve later.

Data breach notification, and the disclosure restriction

Where an eligible data breach as defined in the Privacy Act involves Personal Information, the breaching party must notify the other immediately, and in any event within 24 hours of discovery. The clock runs from discovery, not from confirmation or completed assessment, and no carve-out is stated. The notification must include everything required to be provided to the Office of the Australian Information Commissioner and to affected individuals under the Privacy Act.

The breaching party must also co-operate with any investigation or audit, and provide access to its locations, personnel, processes and systems.

Clause 18.4(c) then imposes a restriction worth reading carefully. The breaching party must not disclose to any third party — expressly including the Information Commissioner — the existence or circumstances of an eligible data breach without the other party's prior written approval. The only carve-out is narrow: disclosure may proceed without approval where the non-breaching party does not make a notification it is lawfully required to make and the breaching party is required by law to notify.

If your organisation carries its own regulatory notification duties — APRA prudential standards, or a sector-specific regime with its own clock — check that this clause does not cut across them before signing.

Overseas transfer, and the residency question

Clause 18.3 prohibits either party transferring or disclosing Personal Information outside Australia or the country of first collection without the other's prior written consent. It then grants blueAPACHE a standing consent from the customer to transfer to:

That consent is conditioned on it being necessary or convenient for blueAPACHE to meet its obligations.

Separately, blueAPACHE's published data sovereignty position states that customer data is stored and processed within Australian-based data centres, remains subject to Australian legal jurisdiction, and is covered by governance controls that minimise exposure to foreign access. It states cross-border transfers do not occur by default and are enabled only where contractually agreed, supported by encryption, contractual safeguards and vendor risk assessments. Administrative access is controlled through role-based permissions, multi-factor authentication and audit logging.

These two positions are not obviously reconcilable, and this directory does not attempt to reconcile them. The marketing position describes Australian-only storage and processing; the contract grants a standing consent to transfer personal information to at least three named jurisdictions plus any country a contractor operates from. Both are blueAPACHE's own published words. If data location is material to your decision, get the operative answer in writing, per service, before signing — the residency statement does not name the data centre operators or facilities, does not distinguish between the different emPOWER services which may sit on different infrastructure, and does not address support or administrative access performed from outside Australia.

The subcontracting clause compounds this. Under clause 27.4 blueAPACHE may subcontract the whole or any part of the agreement without customer consent or notification, and is under no obligation to disclose a subcontractor's identity or location. Read with the standing consent covering "any country where blueAPACHE or its contractors are currently providing the Services from", the set of countries your data may reach is not fixed at signature and you have no contractual right to be told when it changes. Organisations with fourth-party risk obligations should negotiate a notification or approval right onto the Service Order and establish the current subcontractor set and locations.

The contractual regime: information security (clause 17)

Access control (17.2). blueAPACHE must take all reasonable steps to ensure no unauthorised party gains physical or electronic access to Customer Records or Customer Data.

Integrity (17.2). It must implement practices and processes sufficient to identify and protect against complete or partial loss, complete or partial corruption, malicious deletion and accidental deletion of Customer Records. As drafted this integrity obligation attaches to Customer Records; whether it extends to Customer Data is worth confirming.

Security features (17.2). blueAPACHE must implement the security features set out in the relevant Schedule. The actual technical controls — encryption, authentication, audit logging and the rest — are therefore in the Schedules and Service Orders, which are not published. The Schedule for your service is the only place the real controls can be established.

Records production (17.3). Customer Records must be provided to you or your nominee within 10 Business Days of request, in a form, method or media you reasonably request.

No marketing or profiling (17.3). blueAPACHE must not access, use, disclose or modify Customer Data for marketing or profiling purposes, whether or not any individual is identifiable.

No encumbrances (17.3). It must not create any lien, security interest or other encumbrance over Customer Data or Customer Records.

The backup clause, and why it matters more than it looks

Clause 17.3 requires blueAPACHE to back up Customer Data only to the extent set out in the Service Order.

If backup is not specified there, blueAPACHE has no backup obligation — and clause 19.4(a)(i) then excludes liability for loss of or damage to Customer Data entirely.

Where a backup or disaster recovery obligation does exist and is breached, liability is limited to the cost of restoring the data to the version that should have existed at the most recent Recovery Point Objective. Not the value of the data, and not the consequences of losing it.

Separately, liability for loss of or damage to data stored, processed or transferred in connection with customer equipment as part of emPOWER Co-location Services is excluded outright.

Backup intervals, Restore Time Objective and Recovery Point Objective all sit in the Schedules and Service Orders. The practical consequence is that "is backup included?" is not a service question but a document question: check the Service Order, not the brochure. See offsite backup as a service and disaster recovery as a service for what those services cover.

Your obligations

Security policies (3.19). You must comply with blueAPACHE's security policies and directions as reasonably requested by its security manager, and must inform blueAPACHE promptly if you believe there has been any suspected security compromise, including a significant virus or malicious attack. Breach of clause 3.19 triggers the customer indemnity in clause 19.5.

Anti-virus (3.18). Unless a Service Description says blueAPACHE is responsible, you must install, configure and operate anti-virus software on all customer network equipment, customer managed equipment and other equipment interfacing with the services, in accordance with industry best practice.

Liability for a privacy or security failure

Breaches of clause 16 (confidential information), clause 17 (information security), clause 18 (privacy) or clause 20 (IP indemnity) carry a higher cap than general liability: $1 million per event or series of connected events, and $2 million in the aggregate for all claims under the agreement.

Set that against blueAPACHE's insurance obligation of $1 million professional indemnity per occurrence and in the annual aggregate — half the aggregate exposure the liability clause contemplates. The General Terms do not require cyber liability insurance.

A privacy breach not remedied within 20 Business Days of written notice is an express termination ground.

Address discrepancy noted

The origin privacy policy gives the Privacy Officer's address as 383 Johnston Street, Abbotsford Victoria 3067. That is not one of the offices listed on the contact page, and the General Terms and Conditions v3.6 name a different Brisbane address from the one the contact page and the ISO 27001 certificate give. Both are reproduced as published rather than resolved. Privacy correspondence should go to the Abbotsford address because the policy directs it there specifically.

Related

Frequently asked questions

What personal information does blueAPACHE collect from the website?

The published policy covers what it collects from customers and site visitors, why, who it is shared with and how it is secured, including cookies and pixels with third-party tracking from LinkedIn, Facebook and Instagram, which you can block or delete through your browser.

Will blueAPACHE send me marketing?

The policy explains its marketing use and the opt-out available where a major change affects how personal information is used. Under the contract, blueAPACHE must not use Customer Data for marketing or profiling purposes, whether or not an individual is identifiable.

Does blueAPACHE share my information with other companies?

Under clause 18.2 it may disclose Personal Information only to its own personnel to the minimum extent necessary, as required by law, or with your prior written consent. Separately, it may subcontract any part of the agreement without your consent or notification and need not disclose who the subcontractor is or where they are.

How do I access or correct my information, or complain?

Write to the Privacy Officer, blueAPACHE, 383 Johnston Street, Abbotsford Victoria 3067, or use the contact page. You may request access, correction, or make a complaint.

How quickly must a data breach be notified?

Immediately, and in any event within 24 hours of discovery, with all the information required to be given to the Office of the Australian Information Commissioner and to affected individuals.

Can blueAPACHE tell the regulator about a breach?

Not without your prior written approval. Clause 18.4(c) prohibits the breaching party disclosing the existence or circumstances of an eligible data breach to any third party, expressly including the Information Commissioner, unless you fail to make a notification you are lawfully required to make and blueAPACHE is itself legally required to notify.

Can blueAPACHE move my organisation's personal information overseas?

Yes, within limits. Clause 18.3 prohibits transfer without consent but grants standing consent to the United States, any EU Member State, the United Kingdom, any country where blueAPACHE or its contractors currently provide the services from, and any other country named in its privacy policy.

Is my data kept in Australia?

blueAPACHE's published position is that data is stored and processed in Australian data centres under Australian jurisdiction. Its contract grants a standing consent to transfer personal information to several overseas jurisdictions. The two positions are recorded here as published; confirm the operative answer per service in writing before relying on either.

Does blueAPACHE handle GDPR-regulated data?

No. The customer warrants it will not provide, or ask blueAPACHE to process, personal data subject to the GDPR.

Is my data backed up?

Only to the extent your Service Order says so. If backup is not specified there, blueAPACHE has no backup obligation and liability for data loss is excluded entirely. Where an obligation exists and is breached, liability is limited to the cost of restoring to the last Recovery Point Objective.

What can I recover if there is a privacy or security breach?

Up to $1 million per event or series of connected events and $2 million in aggregate for breaches of confidentiality, information security, privacy or the IP indemnity. Indirect and consequential loss is excluded.

What security controls does blueAPACHE actually apply?

The General Terms require reasonable steps against unauthorised access, protection against loss, corruption and deletion of Customer Records, and implementation of the security features in the relevant Schedule. The specific controls are in the Schedule, which is not published, so it must be obtained.

How long does blueAPACHE take to hand back my records?

Customer Records within 10 Business Days of request. Customer Data is treated differently: it is deleted at the end of the Service Period with no stated grace period, and you are solely responsible for taking a copy first.

Source

Drawn from blueAPACHE's published privacy policy and data sovereignty statements on the origin site, together with the General Terms and Conditions v3.6 as represented in this directory's knowledge base, covering data protection and privacy, information security obligations, cross-border data transfers, backup and disaster recovery obligations, liability and indemnity, subcontracting and assignment, customer obligations, and termination rights. Clause numbers are reproduced as the source gives them. The Schedules are not published and their security features are not inferred here. Where the published residency position and the contractual transfer consent differ, both are shown and neither is treated as settled. This page is a plain-language summary, not legal advice.

Knowledge Base

What is the purpose of blueAPACHE's Privacy Policy page?

The page explains how blueAPACHE (Blue Apache Pty Ltd) collects, uses, stores and protects personal information, along with the privacy rights and choices available to individuals.

What is the legal name of the organization behind blueAPACHE?

The organization's legal name is Blue Apache Pty Ltd, operating under the alternate name blueAPACHE.

What is the customer support contact phone number listed for blueAPACHE?

The customer support contact number is +61-3-8696-9369, serving the Australia (AU) area.

Under what law must blueAPACHE and its customers handle Personal Information?

Under Clause 18.1 of blueAPACHE's General Terms and Conditions v3.6, both blueAPACHE and its customers must comply with the Privacy Act 1988 (Cth), including any subordinate legislative instruments or regulations, as though they were bound by it even if they would not otherwise be classified as APP entities.

For what purposes can Personal Information be collected, used, or disclosed under blueAPACHE's terms?

Under Clause 18.2, Personal Information may only be collected, used, and disclosed for performing rights and obligations under the Service Agreement and for administrative tasks tied to service performance, such as invoicing, payment, contract management, risk management, insurance, renewals, delivery, maintenance, and support.

Is Personal Information allowed to be used for marketing or profiling under blueAPACHE's policy?

No. Marketing or profiling purposes are explicitly prohibited uses of Personal Information under Clause 18.2 of the General Terms and Conditions.

How is Personal Information restricted from being disclosed to personnel?

Personal Information may only be disclosed to personnel on a minimum-necessary basis, as required by law, or with prior written consent from the other party.

What are blueAPACHE's data breach notification requirements?

Under Clause 18.4, if an eligible data breach occurs involving Personal Information provided by the other party, the breaching party must notify immediately and within 24 hours of discovery. The notification must include all information required by the Privacy Act for the Office of the Australian Information Commissioner and affected individuals, and the breaching party must cooperate with the investigation.

Do blueAPACHE's Privacy Act obligations apply only to entities legally classified as APP entities?

No. The contractual obligation to comply with the Privacy Act 1988 (Cth) under Clause 18.1 applies even to parties who would not otherwise be classified as APP (Australian Privacy Principles) entities.

Images on This Page