Privacy Policy
Last updated: 31 August 2026
Schmitt Procurement (ABN TODO_ABN) (“we”, “us”) provides procurement and contract advisory services across Regional Queensland. We are committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy explains what we collect, why we collect it, and the choices you have. It applies to this website and to our services.
1. What we collect
- Contact details you give us — name, email address, phone number, business name.
- Enquiry content — whatever you choose to write to us about your situation.
- Commercial information — contracts, pricing, supplier details and spend data you provide so that we can carry out the work you engage us for.
- Billing information — the records we must keep for invoicing and tax. We do not store full payment card numbers.
We collect only what we need. Where it is lawful and practicable, you may deal with us anonymously or under a pseudonym — for example, for an initial general enquiry.
2. Sensitive information
We do not seek sensitive information (as defined in the Privacy Act) unless it is directly necessary for a matter you have asked us to handle — for example, an incident involving harassment, stalkerware or exposure of personal data. Where that occurs, we collect it only with your consent, use it only for that matter, and delete it when the matter is closed unless the law requires otherwise.
3. This website
The contact form on this site does not transmit your details to us or to any third party. It composes a message in your own email application, which you then send yourself. No submission is stored on this website.
This site does not use advertising or tracking cookies. Our hosting provider may keep standard server logs (IP address, request time, user agent) for security and reliability purposes.
4. How we use your information
- To respond to your enquiry and provide a quote;
- To deliver, support and secure the services you engage us for;
- To invoice you and keep required financial records;
- To meet our legal and regulatory obligations.
We do not sell your personal information, and we do not use it for direct marketing.
5. Disclosure
We disclose personal information only where necessary: to service providers who support our operations (such as hosting, email or accounting providers) under obligations of confidentiality; to third parties you have authorised us to deal with on your behalf (for example your internet provider or software vendor); or where required or authorised by law.
6. Overseas disclosure
Some of the software and infrastructure providers we rely on store data outside Australia, including in the United States and the European Union. Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the APPs.
7. Security and retention
We protect personal information with access controls, encryption in transit, need-to-know access limited to the engagement, and prompt removal of access once work is complete. We keep information only as long as it is needed for the purpose it was collected or as required by law, and then destroy or de-identify it.
No method of transmission or storage is perfectly secure. Standard email in particular is not encrypted end to end — if a matter is sensitive, tell us and we will arrange a more suitable channel before you send details.
8. Confidentiality and non-disclosure
Beyond our privacy obligations, we treat client information as confidential by default and will enter into a non-disclosure agreement on request, before substantive discussions begin.
9. Data breaches
We maintain a response plan for data breaches. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by the Notifiable Data Breaches scheme.
10. Access and correction
You may ask us for a copy of the personal information we hold about you, and ask us to correct it if it is inaccurate or out of date. Write to hello@schmitt.au. We will respond within a reasonable period, normally 30 days. We may need to verify your identity first. If we refuse access or correction, we will explain why in writing.
11. Complaints
If you believe we have mishandled your personal information, contact us first at hello@schmitt.au. We will acknowledge your complaint and aim to resolve it within 30 days. If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
12. Changes
We may update this policy from time to time. The current version is always published on this page with its last-updated date.
13. Contact
Schmitt Procurement · ABN TODO_ABN · Regional Queensland · hello@schmitt.au · TODO_PHONE