Skip to content
  • Home
  • Services
  • Method
  • About
  • Tools
  • Intelligence
Book a conversation
  • Home
  • Services
  • Method
  • About
  • Tools
  • Intelligence

Security

How SP Optima protects the personal and client information it holds
Last updated: 8 July 2026

1. Our approach

Security at SP Optima is proportionate and practical. We are a professional services firm, not a data-centre operator, so we run our website, tools and services on reputable enterprise cloud platforms and rely on the security controls and certifications those platforms maintain. Alongside that, we limit what we collect, restrict who can access it, and apply the controls described below. We keep this statement general and do not publish our specific vendors or internal configuration, so as not to hand anyone a map of our systems. Clients and prospective clients can request further detail (see section 9).

2. Encryption

Information is encrypted in transit and at rest.

  • In transit: connections to our website and tools use HTTPS/TLS, so data is encrypted while it travels over the internet.
  • At rest: the cloud platforms we use encrypt stored data at rest by default, and company devices used to access personal or client information are protected with full-disk encryption, so a lost or stolen device does not expose readable data.

This is platform-managed encryption. It protects against theft of storage media or a device; it is not end-to-end or zero-knowledge encryption, and access to information still depends on the account and access controls described in section 3.

3. Access control and authentication

  • Access to personal and client information is granted on a need-to-know basis and removed when it is no longer required.
  • Multi-factor authentication is enforced on accounts that can access stored data.
  • Accounts use unique, individual credentials, and shared logins are avoided.
  • Our AI capability assessment tool verifies control of the email address provided before results are displayed or sent.

4. Data storage and location

We host our website, tools and business systems on established cloud platforms. Submission data from our AI capability assessment tool is stored in the European Union. Some of the providers we use operate in the United Kingdom, the European Economic Area or the United States, so some information may be stored or processed outside Australia. Where information is processed outside its region of origin, including information originating in the EEA or UK, we rely on recognised transfer safeguards such as Standard Contractual Clauses or the EU-US Data Privacy Framework and its UK extension.

5. Sub-processors

We use a small number of vetted third-party providers, for functions such as hosting, email, analytics and customer relationship management, that process information on our behalf under data processing agreements or their published terms. A list of the sub-processors and service providers we rely on is available to clients and prospective clients on request.

6. Data minimisation and AI tools

We aim to collect and retain only what we need. Where we use AI-enabled tools in our own work, we seek to minimise what is uploaded, apply human review, and de-identify or redact names and other unnecessary identifiers where reasonably practicable. Unless otherwise agreed with a client, we do not intentionally use client confidential information to train public AI models, and we prefer AI tools whose terms preclude training on customer content where reasonably possible.

7. Data breach response

If we become aware of unauthorised access to, or disclosure of, personal information that is likely to result in serious harm, we assess it promptly and notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), where applicable. Where a breach affects information we handle on behalf of a client, we also notify that client without undue delay so they can meet their own obligations.

8. Confidentiality and retention

Our people and delivery partners are bound by confidentiality obligations. We keep information only for as long as reasonably necessary for the purpose for which it was collected and for legal, accounting and record-keeping obligations, after which we delete or de-identify it.

9. Client engagements

For consulting engagements, we follow the security and confidentiality requirements agreed with each client. Where appropriate, we enter confidentiality agreements and data processing agreements, and we handle client data as a processor acting on the client's instructions. If you need our sub-processor list, further security detail, or a data processing agreement for due diligence, contact us using the details below.

10. Limitations

No method of transmission or storage is completely secure. While we take reasonable steps to protect information, we cannot guarantee absolute security, and any transmission of information over the internet carries inherent risk.

11. Reporting a security concern

If you believe you have found a security vulnerability, or you have a security question, please contact us at enquiries@spoptima.com. We welcome responsible disclosure and will investigate reports we receive.

12. Contact

SP Optima
Website: www.spoptima.com
Email: enquiries@spoptima.com

Independent AI support and business optimisation.

Terms of Use Privacy Statement Security

Melbourne, Australia  ·  ABN 39 697 333 850

SP Optima provides advisory, optimisation, and AI partner services. Information on this website is general in nature and does not constitute legal, financial, tax, or professional advice. Specific engagements are governed by separate agreements.

© 2026 SP Optima. All rights reserved.