Trust Centre
Everything about how Geeks360 handles your information, secures its own systems, and decides what to publish — in one place, so you do not have to hunt through a footer to find it.
Why this page exists
If you are considering handing an IT provider administrative access to your business, you should be able to find out how they operate without asking. Most providers make you ask.
This page collects the answers. Nothing here is marketing — it is the set of documents and commitments a procurement officer, an auditor or a cautious owner would want before signing anything.
Privacy and your information
What we collect, what happens to it, how long we keep it, and who else is involved. Written specifically for this business rather than adapted from a template — including exactly which analytics tools run on this site, what they set, and how the enquiry form is kept out of them.
How we secure our own systems
It would be difficult to recommend controls we do not apply ourselves, so we apply them: multi-factor authentication on every account that matters, managed endpoint protection, patching on a schedule rather than when someone remembers, and backups that are monitored and test-restored rather than assumed to work.
Administrative access to client systems is limited to the people who need it for the work in front of them. Access is granted for a purpose and removed when that purpose ends — including when a staff member leaves, which is the case most providers handle badly.
We hold no security certification and do not claim one. Where a client needs evidence of controls for their own audit, we provide documentation of what is actually in place.
Remote support
Remote sessions run through Zoho Assist, begin only with your permission for that session, and are visible on your screen while they happen. You can end one at any point.
Sessions are not routinely recorded. If a session needs to be recorded, you are told before it starts and it does not proceed without your agreement.
Data protection in client environments
Managing a business's IT means holding access to systems containing personal information — staff records, and in several sectors information about the people our clients support. We access those systems to do the work engaged, and for nothing else.
Meeting your own sector obligations remains yours. Our role is to make sure the technology supports that rather than obstructing it, and to give you the documentation when someone asks you to demonstrate it.
Responsible disclosure
If you believe you have found a security vulnerability in this website or in a system we operate, we would rather hear from you than not, and you will not be treated as hostile for telling us.
Email hello@geeks360.com.au with enough detail to reproduce the issue. We will acknowledge it, investigate, and tell you what we found and what we did. Please give us a reasonable opportunity to fix it before disclosing publicly.
We ask that testing stays proportionate: no denial of service, no social engineering of staff or clients, no accessing or altering data that is not yours, and no testing against client systems. We do not run a paid bug bounty.
How we decide what to publish
Everything published on this site is written to be checkable. That means naming what we do rather than what we would like you to assume, and leaving out any claim we cannot stand behind — which is why you will not find partner badges, uptime figures or client counts anywhere on this website.
Terms and disclaimers
The terms covering use of this website, and where the line sits between general information and advice for your specific situation.