Cybersecurity & Data Protection Policy
At ODE FOR YOU PTY LTD (ABN 79 682 123 806) ("we", "us" or the "Company" or “business”), we take the security of your personal information seriously. This Cybersecurity & Data Protection Policy outlines the steps we take to safeguard your data and ensure secure transactions across our website and digital platforms.
This policy works respectively in conjunction with and forms part of our:
- Privacy Policy (located at https://www.odeforyou.com/privacy)
- Returns Policy (located at https://odeforyou.com/shipping-returns)
- Website Terms of Use (located at https://odeforyou.com/termsofuse)
Website & Transaction Security
We use Shopify as our ecommerce platform, which incorporates:
- Secure Sockets Layer (SSL) encryption on all pages
- PCI-compliant payment processing via trusted third-party gateways
- Ongoing vulnerability scanning and automatic patching
- HTTPS secure hosting across the entire domain
When you make a purchase or enter personal information on our site, your data is encrypted during transmission to prevent interception or tampering.
Payment & Account Protection
We do not store your full payment details. All credit card and debit card payments are processed securely by external providers.
Your customer account is protected by a username and password combination. We encourage all users to create strong, unique passwords and to update them regularly.
Internal Data Handling
Only authorised team members with legitimate business purposes can access your personal information (such as order fulfilment, customer service, and marketing).We enforce:
- Role-based access controls
- Device passcode protection
- Multi-factor authentication (MFA) on business tools where available
- Cloud-based, encrypted storage systems
Third-Party Systems
We integrate with secure, industry-standard platforms to operate our business effectively. These include (and may not be limited to):
- Shopify (storefront, order management, payments)
- Klaviyo (email marketing and customer segmentation)
- Skutopia (inventory and order fulfilment)
- Google Workspace and Microsoft Office (emails, internal documents)
- Xero and A2X (accounting software)
- Yotpo (reviews and user-generated content)
- Gorgias (customer support)
We only use services that meet appropriate data security and privacy compliance standards.
Breach Response Procedure
If we suspect a data breach involving your personal information, we will:
- Investigate the issue immediately
- Take steps to contain and assess the risk
- Notify affected individuals if there is a risk of serious harm
- Report the breach to the Office of the Australian Information Commissioner (OAIC), if legally required.
You will always be contacted directly via the email address you provided to us if there is any relevant risk to your data.
Data Retention & Disposal
We only retain your personal information for as long as necessary to fulfil the purposes outlined in our Privacy Policy and to comply with legal and regulatory obligations. When data is no longer needed, it is securely deleted or anonymised.
Contact Us
If you have questions or concerns about how we protect your data, you can contact our Data Protection Officer at:
Email: hello@odeforyou.com
Post: 3 Belinda Road, Alfords Point NSW 2234