Privacy Policy

Effective 31 July 2026

What we collect

Intake details you give us (name, email, phone, website, incident description), scanner queries (the domain scanned, results, and an email if you choose to leave one), and standard server logs.

Cookies & analytics

Essential cookies keep the site working and remember your cookie choice. With your consent — given through the banner and changeable any time via “Cookie settings” in the footer — we also use analytics and advertising cookies: Google Analytics to understand traffic, and the Meta (Facebook/Instagram) pixel and Conversions API to measure and target our advertising. These load only after you accept; if you choose “Essential only” they never run, and you can withdraw consent at any time.

Incident data

During an engagement we access your website files, databases and logs solely to perform the work. Where compromised material includes personal information of your customers, we analyse it only as needed to scope the breach, we do not copy it beyond the forensic working set, and we destroy working copies at engagement close. We never warehouse leaked datasets.

What we share

Nothing, except: processors we use to operate (hosting, email, payments via Stripe), and where law requires. We never sell or trade data.

Where it lives

Intake and incident records are stored on our own infrastructure. Payment card details never touch our servers — they go directly to Stripe.

Your rights

Ask us what we hold about you, ask for correction or deletion: team@mywebsitehasbeenhacked.com. Australian Privacy Principles and GDPR rights are honoured where they apply.

Call now — 24/7+61 3 4328 3894