PBT Data Security Policy

PBT Logo

Progressive Business Technologies

Data Security Policy

Read alongside our Privacy Policy:  This policy describes the measures PBT takes to protect Client Data and should be read together with our Privacy Policy, which addresses how we collect, use and disclose personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1

Purpose and Scope

1.1This document describes the measures Progressive Business Technologies Pty Ltd (ABN: 90 113 802 707) (PBT) takes to protect Client Data. This policy should be read in conjunction with our Privacy Policy, which addresses how we collect, use, and disclose personal information in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1.2For the purposes of this policy, Client Data includes remote access details, client databases, files containing client information, and any personal information which we collect and store in the course of providing our services.
1.3PBT provides services which may require us to store and access Client Data on our infrastructure, including:
System implementation projects
Ongoing system support and maintenance (including upgrades)
Artificial Intelligence (AI) enabled services and tools
2

Our Approach to Data Security

2.1PBT takes Client Data protection seriously and implements a multi-layered approach to infrastructure and data security. We understand that data security is critical to our clients, and we make it a priority to maintain and implement security practices and policies that are reasonable in the circumstances and appropriate for the type and sensitivity of data we handle.
2.2We assess our security posture against the Australian Cyber Security Centre (ACSC) Essential Eight framework and implement controls appropriate to our risk profile.
3

General Security Measures

3.1 Access Controls
All users' computers and servers require domain authentication (username and password)
Complex password policies enforced across our network environment
Two-factor authentication (2FA) required for all staff to access PBT devices (via Duo Security)
All Microsoft 365 accounts have 2FA enabled
Remote access to PBT environment via SSTP VPN and Remote Gateway Access with complex passwords
3.2 Endpoint and Network Security
Active patching processes maintained for servers and desktop environments
Endpoint protection software on all servers and workstations
Web protection software to monitor and control website activity
Email spam and malware filtering
End-user devices have encrypted hard drives
3.3 Backup and Recovery
Multiple backup strategies to different destinations
Backup destinations include third-party infrastructure located in Australia
3.4 Staff Training and Awareness
Ongoing cyber security training for all staff, including AI-specific security awareness
PBT participates in the ACSC's Cyber Security Partnership Program and maintains current understanding of ACSC Information Security Principles and Guidelines
4

Storage of Client Remote Access Details

4.1To provide implementation and support services, we may require clients to provide us with remote access to applications and databases within their infrastructure, including logins, usernames, and passwords.
4.2We protect client remote access information through the following measures:
Secure, purpose-specific application for storing remote access details
Database encryption at rest for stored credentials
Username/password plus 2FA code required for application access
Auto-lock after 30 minutes of inactivity requiring 2FA re-entry
Comprehensive audit trail of all access attempts
Client credentials are never input into AI tools or services
4.3Client responsibility. We recommend that clients also maintain their own access logs and implement complementary security measures. Clients should notify PBT immediately of any suspected unauthorised access to credentials we hold.
5

Storage of Client Databases

5.1Where possible, we prefer not to hold or transfer client databases on our infrastructure. However, this is sometimes necessary when providing our services.
5.2When we do store client databases:
Databases are loaded onto test SQL servers accessible only from internal devices or via VPN/Remote Desktop Gateway
End-user devices have encrypted hard drives
Standard retention period of 30 days, with longer periods for ongoing projects
6

Storage of Client Files

6.1Client files include proposals, solution design documents, project documentation, import files, and related materials generated during service delivery.
6.2Our approach to client file storage:
We encourage clients to provide access to a client-managed SharePoint site where possible
Alternatively, PBT can provide a shared SharePoint site for client access
Files encrypted at rest within SharePoint
7

Third-Party Service Providers

7.1PBT utilises third-party cloud service providers for certain aspects of data storage and processing. We take the following steps to ensure these providers maintain appropriate security:
Where possible, selection of providers with demonstrated security credentials and relevant certifications (e.g., ISO 27001, SOC 2)
Where feasible, selection of providers that store data within Australia
7.2Our primary third-party providers include Microsoft (Azure/Microsoft 365).
8

Artificial Intelligence (AI) Services

8.0PBT uses and provides AI-enabled services to enhance our service delivery and improve outcomes for our clients. This section outlines our approach to the secure and responsible use of AI.
8.1 AI Services We Use and Provide
8.1PBT may utilise AI services for purposes including:
Assisting with code development, debugging, and technical problem-solving
Document drafting and analysis
Data analysis and reporting
Process automation and workflow optimisation
8.2 AI Data Retention
8.2PBT only uses AI services whose contractual terms expressly prohibit the use of customer inputs to train the provider's general-purpose or foundation models. In addition, we select AI providers and configurations that either:
(a)do not retain input data or outputs beyond the immediate processing session; or
(b)retain data only for the minimum period necessary (typically 30 days or less).
9

Data Breach Response

9.0PBT is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988.
9.1 What Constitutes an Eligible Data Breach
9.1An eligible data breach occurs when:
There is unauthorised access to, disclosure of, or loss of personal information
A reasonable person would conclude that the breach is likely to result in serious harm to any of the individuals to whom the information relates
9.2 Our Response Process
9.2aContainment (Immediate). Upon becoming aware of a breach, we will take immediate steps to contain the breach and limit any further compromise.
9.2bAssessment (Within 72 hours). We will conduct a reasonable and expeditious assessment to determine whether the breach is likely to result in serious harm.
9.2cNotification (Within 30 days of becoming aware). If we determine that an eligible data breach has occurred, we will:
Notify the Office of the Australian Information Commissioner (OAIC)
Notify affected individuals (or the relevant client organisation who can notify their individuals)
Provide recommendations for steps individuals can take to protect themselves
9.3 Client Notification
9.3In addition to our NDB scheme obligations, we will notify affected clients of any security incident affecting their data as soon as practicable, regardless of whether the incident meets the threshold for an eligible data breach.
10

Client Rights

10.0Under the Privacy Act 1988, individuals have certain rights regarding their personal information. These rights extend to personal information we hold as part of Client Data.
10.1 Access
10.1Individuals may request access to personal information we hold about them. Where we hold personal information on behalf of a client organisation, we may direct the request to that organisation.
10.2 Correction
10.2Individuals may request correction of personal information that is inaccurate, out of date, incomplete, irrelevant, or misleading.
10.3 Deletion
10.3Subject to any legal requirements, clients may request deletion of their data.
10.4 How to Make a Request
10.4Requests should be directed to our Privacy Officer at admin@pbt.net.au. We will respond to access and correction requests within 30 days.
11

Liability

11.1Liability for any matter arising under or in connection with this Policy is governed by the limitation of liability provisions in PBT's Standard Terms and Conditions of Service, which apply in full.
12

Client Acknowledgement

12.1By engaging PBT's services, you acknowledge that:
You have read and understood this Data Security Policy
You consent to the collection, use, and storage of data as described in these policies
You are responsible for maintaining your own security measures and access logs
You will notify PBT promptly of any suspected security incidents affecting credentials or access you have provided to us
While PBT implements reasonable security measures, no system is completely immune from security incidents