Privacy Policy

OT Associates (“OT Associates”, “we”, “us” or “our”) is committed to protecting the privacy of everyone who visits our website, engages our services, or interacts with our platform, OTMATIX. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, and the rights available to you.

This policy applies to our website at otassociates.com, our OTMATIX platform, and the wider services we provide as an operational technology (OT) cybersecurity practice.

Who We Are

OT Associates is a pure play OT cybersecurity firm headquartered at Unit 4.15, 29-31 Lexington Drive, Bella Vista, NSW 2153, Australia, providing governance, assurance, capability, intelligence and continuity services to critical infrastructure operators across Australia, the Gulf and other regions.

For any privacy-related query, you can reach us at:

Email: info@otassociates.com

Phone: +61 2 9189 1560

Post: Unit 4.15, 29-31 Lexington Drive, Bella Vista, NSW 2153, Australia

Information We Collect

We collect information in the following ways:

Information you provide directly. This includes details submitted through our contact and demo request forms, such as your name, job title, organisation, email address, phone number, and the content of your enquiry. It also includes information shared when you engage us for an assessment, advisory engagement, or platform deployment.

Information collected through OTMATIX. Where a client deploys OTMATIX, the platform processes operational governance data on the client’s behalf, including asset records, control mappings, scenario findings, and advisor notes. This data is owned and controlled by the client organisation, and we act as a data processor in this context unless otherwise agreed in a service contract.
Information collected automatically. When you visit our website, we may automatically collect technical information such as your IP address, browser type, device information, pages visited, and the date and time of your visit, generally through cookies and similar technologies.

Information from third parties.

We may receive information about you from business partners, publicly available sources, or referrals, where this is necessary to assess a potential engagement.

How We Use Your Information

We use the information we collect to:

  • respond to enquiries, scope engagements, and provide requested demonstrations of OTMATIX;
  • deliver, manage and improve our advisory, assurance, training and managed services;
  • communicate with you about our services, including regulatory or sector updates where you have agreed to receive these;
  • maintain the security, integrity and proper functioning of our website and platform;
  • meet our legal, regulatory and contractual obligations, including obligations that arise from working with critical infrastructure operators; and
  • understand how our website is used, so that we can improve its content and performance.

We do not sell personal information to third parties, and we do not use client operational governance data held within OTMATIX for any purpose beyond delivering the agreed services.

Legal Basis for Processing

Where applicable, we rely on one or more of the following legal bases to process personal information: your consent, the necessity of processing to perform a contract with you or your organisation, our legitimate interests in operating and improving our business, and compliance with a legal obligation. Where we operate in jurisdictions with specific data protection requirements, such as the Australian Privacy Act 1988 or applicable Gulf data protection frameworks, we process personal information in accordance with those requirements.

How We Share Information

We may share personal information with:

Service providers who support our operations, such as hosting providers, email and communication platforms, and IT support providers, under appropriate confidentiality and data protection terms;

Technology partners, such as Microsoft, Tenable, Verimatrix, Cyble, Rapid7, KnowBe4, Guardware and Horizon AI, only where this is necessary to deliver an integrated service you have engaged us for, and never as a commercial referral arrangement;
Regulators and authorities, where we are legally required to do so, or where disclosure is necessary to protect critical infrastructure or public safety; and

Professional advisers, such as our legal or financial advisers, where necessary for the proper conduct of our business.
We do not share client operational governance data, scenario findings, or advisor notes held within OTMATIX with any third party without the client’s authorisation, except where required by law.

International Data Transfers

Given our operations span Australia, the Gulf region and other jurisdictions, personal information may be transferred to, stored, or processed in countries other than the one in which it was originally collected. Where this occurs, we take reasonable steps to ensure the information continues to receive an appropriate level of protection, consistent with this policy and applicable law.

Data Retention

We retain personal information for as long as necessary to fulfil the purposes outlined in this policy, including any legal, accounting, or reporting requirements. Operational governance data held within OTMATIX is retained in accordance with the terms agreed with each client, and is typically retained for the duration of the engagement plus any period required for audit, regulatory or contractual purposes.

Data Security

We maintain administrative, technical and physical safeguards designed to protect personal information against unauthorised access, disclosure, alteration or destruction. Given our work in critical infrastructure, security is treated as a foundational requirement rather than an afterthought, and OTMATIX deployments are configured to the security posture required by each client, including air-gapped, on-premises, or Azure cloud environments.

No method of transmission or storage is entirely secure, and while we work to protect personal information, we cannot guarantee absolute security.

Cookies

Our website may use cookies and similar technologies to support core functionality, remember preferences, and understand how visitors interact with our site. You can control or disable cookies through your browser settings; please note that disabling cookies may affect certain features of the website.

Marketing and Promotional Communications

Where you have provided your details through a contact form, demo request, or similar enquiry, we may use your contact information to send you marketing and promotional communications, such as regulatory updates, sector insights, event invitations, or information about our services, including OTMATIX. We will only do this where permitted by applicable law, such as where you have given consent or where an existing business relationship allows it.

You can opt out of receiving marketing communications from us at any time by:

  • using the unsubscribe link included in any marketing email we send;
  • contacting us directly at info@otassociates.com; or
  • notifying your Resident Advisor or primary point of contact, if you are an existing client.

Opting out of marketing communications will not affect service-related communications necessary for an active engagement, such as advisory updates, OTMATIX platform notices, or contractual correspondence.

Your Rights

Depending on your location, you may have rights in relation to the personal information we hold about you, including the right to:

  • request access to the personal information we hold about you;
  • request correction of inaccurate or incomplete information;
  • request deletion of your personal information, subject to our legal and contractual obligations;
  • object to or restrict certain processing of your information; and
  • withdraw consent at any time, where processing is based on consent.

To exercise any of these rights, please contact us at info@otassociates.com. We will respond to legitimate requests within a reasonable timeframe and in accordance with applicable law.

Children’s Privacy

Our website and services are intended for business and professional audiences. We do not knowingly collect personal information from children, and our services are not directed at individuals under the age of 18.

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. The “Last updated” date at the top of this policy indicates when it was last revised. We encourage you to review this policy periodically.

Contact us

If you have questions, concerns, or requests relating to this Privacy Policy or how we handle your personal information, please contact us at:

OT AssociatesUnit 4.15, 29-31 Lexington Drive, Bella Vista, NSW 2153, Australia

Email: info@otassociates.com

Phone: +61 2 9189 1560

  • About Us
  • Capabilities
  • OTMATIX
  • Partners
  • Industries
  • Blogs