Data Protection Policy
Last updated: August 8, 2026
CrumpIT (ABN 65 588 251 132) (“CrumpIT”, “we”, “us”, “our”) is an information technology services business based in Orange, New South Wales, Australia. We provide computer repairs and upgrades, custom PC builds, networking, cyber security, business IT support, web development and design, app development, AI setup, digital marketing, graphic and motion design, software support, remote support, and an online store.
When you leave a computer, phone or storage device with us — or give us access to your systems remotely — you are trusting us with your data. This policy explains exactly how we protect it. It works alongside our Privacy Policy, which covers the personal information we hold about you as a customer.
Our commitments
- We access the data on your device only to the extent needed to do the job you have engaged us for — for example, testing that files open after a repair, or migrating your data to a new machine at your request.
- We never browse, copy, use or disclose your personal files beyond what the job requires.
- Everything we see in the course of service work is treated as strictly confidential.
- Devices in our care are stored securely and are only accessible to the technician working on your job.
Backups and data loss
- Service work carries an inherent risk of data loss. Please back up your device before bringing it in. If you cannot, ask us about our backup service before work begins.
- Where you engage us to back up data, the backup is verified before risky work proceeds, and our working copy is securely deleted within 30 days of the job being completed and collected, unless we agree otherwise with you.
- Data recovery from failed media is attempted on a best-effort basis and can never be guaranteed.
Passwords and access
- We ask for passwords or sign-in access only where the job genuinely requires it (for example, to test a repair on the Windows desktop).
- Where possible, we suggest creating a temporary account or PIN for us instead of sharing your own.
- We recommend changing any password you have shared with us once your job is complete. Passwords recorded for a job are securely destroyed when the job closes.
Drives, disposal and recycling
- Replaced storage drives are returned to you on request. Otherwise, any drive we dispose of or recycle is first securely erased using industry-standard wiping methods, or physically destroyed if it cannot be wiped.
- Devices we recycle on your behalf have all storage removed and treated the same way.
Remote support
- Remote sessions run only with your knowledge and consent, using reputable tools, and end when the job ends — we do not retain unattended access to your systems unless you have specifically engaged us for managed support that requires it.
- You can watch everything we do during a remote session and end it at any time.
Business customers
For managed IT and business support engagements, data handling, access levels, backup schedules and retention are agreed in the engagement scope. Where we process data your business holds about others, we do so on your instructions and consistently with the Privacy Act 1988 (Cth).
If something goes wrong
If we become aware of a breach involving your data that is likely to result in serious harm, we will notify you promptly, take immediate steps to contain it, and follow the Notifiable Data Breaches scheme, including notifying the Office of the Australian Information Commissioner where required.
Contact us
Questions about this policy can be sent to support@crumpit.com.au, by phone on 0423 870 531, or through our contact page.