Privacy Policy
Effective: July 2026 · Version 1.3 · Netready Cloud MSP — Melbourne, VIC
dennis@ncmsp.com.au | 0455 336 685 | ncmsp.com.au
1. Introduction
Netready Cloud MSP (“we”, “us”, “our”) is a sole operator managed IT services business based in Melbourne, Victoria, Australia. We provide Microsoft 365 management, endpoint security, Azure monitoring, identity management, and related IT services to small and medium businesses.
We are committed to protecting the privacy of our clients, their staff, and visitors to our website. This Privacy Policy explains what personal information we collect, why we collect it, how we use and protect it, and your rights under the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By engaging our services or visiting our website (ncmsp.com.au), you agree to the terms of this Privacy Policy.
2. Who We Are
Business Name: Netready Cloud MSP Location: Melbourne, Victoria, Australia Email: dennis@ncmsp.com.au Phone: 0455 336 685 Website: ncmsp.com.au Operator: Dennis Odri
Important: Netready Cloud MSP is not a Microsoft reseller or Cloud Solution Provider (CSP). Clients enroll directly with Microsoft as Partners in their own right and maintain their own licensing relationships with Microsoft. This is central to understanding how client data flows in our service model.
3. What Information We Collect
3.1 Information you provide directly
When you contact us, engage our services, or visit our website, you may provide:
- Name and job title
- Business name and ABN
- Email address and phone number
- Business address
- Details about your current IT environment and requirements
- Payment and billing information (invoiced separately; payment processed via third-party platforms)
3.2 Information collected through service delivery
In the course of providing managed IT services, we may access or process:
- Microsoft 365 tenant configuration data (Exchange Online, Entra ID, Intune, Teams, SharePoint)
- Endpoint device information (device name, operating system, compliance status, patch level)
- Security and audit logs from Microsoft Defender for Endpoint, Entra ID, and Azure Monitor
- User account information within your Microsoft 365 tenant (usernames, email addresses, role assignments)
- Helpdesk support requests, including descriptions of technical issues
- Azure subscription and resource configuration data
All access to client Microsoft 365 and Azure environments is conducted through Microsoft’s Granular Delegated Admin Privileges (GDAP) framework. This access is formally consented to by the client, is scoped to specific roles, and is fully audited within the client’s own Microsoft tenant activity logs.
3.3 Information collected automatically
When you visit our website, we may automatically collect:
- IP address and approximate geographic location
- Browser type and version
- Pages visited and time spent on pages
- Referring website or search terms
4. Why We Collect Personal Information
We collect personal information only for purposes directly related to our service delivery, business operations, and legal obligations.
4.1 Service delivery
- To onboard you as a client and establish delegated administrative access to your Microsoft environment
- To manage, monitor, and secure your Microsoft 365 tenant, endpoints, identities, and Azure resources
- To provide helpdesk and technical support to you and your staff
- To configure security policies, Conditional Access rules, and endpoint compliance baselines
- To guide your enrollment in the Microsoft AI Cloud Partner Program
4.2 Billing and administration
- To issue invoices and manage payment for managed services
- To maintain records of service agreements and onboarding documentation
- To communicate with you about service scope, renewals, and pricing changes
4.3 Legal and compliance
- To comply with applicable Australian laws and regulations
- To maintain records required under tax and business law
- To respond to lawful requests from regulatory authorities
4.4 Website and marketing
- To respond to enquiries submitted through our website
- To improve the content and usability of our website
- To send you relevant communications about our services, where you have consented
5. How We Store and Protect Your Information
5.1 Storage locations
- Microsoft 365 (our own business tenant) — business correspondence, client records, and operational documentation
- Accounting and invoicing software — billing records and financial information
- Secure email — client communications
- Client Microsoft tenants — accessed only via GDAP during active service delivery; not stored in our systems independently
5.2 Security measures
We apply the same enterprise-grade security standards to our own business that we implement for clients:
- Multi-factor authentication (MFA) enforced on all accounts
- Microsoft Entra ID with Conditional Access policies protecting administrative access
- Microsoft Defender for Endpoint on all devices used for client work
- Role-based access control — client data accessed only as needed to deliver services
- GDAP access scoped to minimum necessary permissions
- Regular security reviews and patch management
5.3 Retention
- Client records and correspondence — 7 years from end of engagement
- Financial and billing records — 7 years
- Support and helpdesk records — 3 years from resolution
- Website enquiry data — 2 years, or until the enquiry is resolved
When information is no longer required, it is securely deleted from our systems.
6. Disclosure of Personal Information
6.1 We do not sell your data
Netready Cloud MSP does not sell, rent, or trade personal information to third parties under any circumstances.
6.2 Service delivery disclosures
In the course of delivering services, we may engage with or route information through:
- Microsoft Corporation — as the platform provider for Microsoft 365, Azure, Entra ID, Intune, and Defender. Microsoft’s services are governed by their own privacy policies and data processing agreements.
- Accounting and invoicing software providers — solely for billing and financial administration
- Professional advisors — including accountants or lawyers, where legally required and subject to confidentiality obligations
6.3 Legal disclosures
We may disclose personal information where required by law, including in response to a court order, subpoena, or lawful request from a government or regulatory authority.
6.4 Business succession
In the event that Netready Cloud MSP is wound up, sold, or its service obligations are transferred to another operator, clients will be notified in advance. Personal information may be transferred only under equivalent privacy protections.
7. Microsoft Cloud Services and Client Data
A significant part of our service delivery involves accessing and managing data that resides in client Microsoft 365 and Azure tenants.
7.1 Client data sovereignty
Client data within Microsoft 365 and Azure tenants belongs to the client at all times. Netready Cloud MSP accesses this data only through GDAP delegated administration, which:
- Is formally authorised by the client at onboarding via the Microsoft Partner Center consent flow
- Is scoped to specific administrative roles required for service delivery
- Creates a full audit trail within the client’s own Microsoft tenant
- Can be revoked by the client at any time through Microsoft’s Partner Center
7.2 Data residency
Microsoft 365 and Azure data residency is determined by the client’s Microsoft tenant configuration and the geographic region selected at tenant creation. Netready Cloud MSP does not control or alter data residency settings. Australian tenants typically store data in Australian or Asia-Pacific Microsoft datacentres, subject to Microsoft’s own data residency policies.
7.3 Microsoft’s privacy obligations
Microsoft Corporation acts as a data processor for data held within Microsoft 365 and Azure. We recommend clients review Microsoft’s privacy documentation at microsoft.com/privacy.
8. Your Privacy Rights
Under the Australian Privacy Act 1988 and the Australian Privacy Principles, you have the right to:
8.1 Access your information
You may request a copy of the personal information we hold about you. We will respond within 30 days.
8.2 Correct your information
If you believe information we hold is inaccurate, out of date, or misleading, you may request a correction. We will action reasonable correction requests promptly.
8.3 Withdraw consent
Where we rely on your consent to process personal information, you may withdraw that consent at any time by contacting us. Withdrawal will not affect the lawfulness of processing conducted prior to withdrawal.
8.4 Make a complaint
If you believe we have handled your personal information in breach of the Australian Privacy Principles, you may lodge a complaint by contacting us directly. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC):
- Website: oaic.gov.au
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
9. Website and Cookies
9.1 Cookies
Our website may use cookies and similar tracking technologies to understand how visitors use our site, improve performance and content, and remember your preferences. You can disable cookies in your browser settings, though some functionality may be affected.
9.2 Third-party analytics
We may use third-party analytics tools (such as Google Analytics) to understand website traffic and visitor behaviour. These tools collect anonymised data and are subject to their own privacy policies. We do not combine analytics data with personally identifiable information.
9.3 External links
Our website may contain links to third-party websites, including Microsoft’s Partner documentation and support resources. We are not responsible for the privacy practices of those websites and encourage you to review their respective privacy policies.
10. Cross-Border Data Transfers
In delivering services, some personal information may be processed by systems located outside Australia — primarily through Microsoft’s global cloud infrastructure. Microsoft maintains Standard Contractual Clauses and other safeguards for international data transfers as described in their Data Processing Addendum.
We take reasonable steps to ensure that overseas recipients of personal information handle it in a manner consistent with the Australian Privacy Principles.
11. Children’s Privacy
Our services are intended for business clients and are not directed at individuals under 18 years of age. We do not knowingly collect personal information from minors. If you believe we have inadvertently collected such information, please contact us immediately and we will take steps to delete it.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our business practices, service model, or legal obligations. When we make material changes, we will:
- Post the updated policy on our website with a revised effective date
- Notify active clients by email where the changes are significant
We encourage you to review this policy periodically. Continued use of our services after notification of changes constitutes acceptance of the updated policy.
13. Contact Us
For any privacy-related enquiries, access requests, correction requests, or complaints, please contact:
Dennis Odri Owner & Principal IT Consultant, Netready Cloud MSP 📞 0455 336 685 ✉️ dennis@ncmsp.com.au 🌐 ncmsp.com.au 📍 Melbourne, Victoria, Australia
Note: This Privacy Policy does not constitute legal advice. Netready Cloud MSP recommends that clients with specific regulatory obligations (such as obligations under the Notifiable Data Breaches scheme, health privacy legislation, or financial services regulations) seek independent legal advice regarding their own privacy compliance requirements.