SAH Studios Privacy Policy


Last updated: 3 September 2026 · SAH Studios · Australia + 日本



Read this first: template notice


This document is a starting template only. It has been prepared to help [Legal entity name] draft a privacy policy and has not been reviewed by a lawyer. Before it is published or relied on, it must be reviewed by a qualified lawyer admitted in Australia (and, for the Japan section, a lawyer qualified in Japan). Privacy law changes often and the correct wording depends on facts about the business that this template does not have.


Everything in square brackets, for example [Legal entity name], [ABN], [Registered address], [State/Territory], [Effective date], [Contact email] and [Website URL], is a placeholder to be completed or confirmed. Retention periods, provider locations and the list of tools should also be checked against what the business actually uses on the day this is published.


Note for the reviewer: some small businesses with an annual turnover under A$3 million are exempt from parts of the Privacy Act 1988 (Cth). This template is written on the basis that SAH Studios chooses to handle personal information in line with the Australian Privacy Principles regardless, because it processes personal information on behalf of clients and operates across borders. The lawyer should confirm whether the exemption applies and whether any wording below should change as a result.



1. Who we are


SAH Studios (also known as Stay at Home Studios) is operated by [Legal entity name] (ABN [ABN]) of [Registered address], [State/Territory], Australia. In this policy, “SAH Studios”, “we”, “us” and “our” refer to that entity.


We are a digital agency for small businesses in Australia and Japan. We design and build websites and online presences, run managed marketing (SEO, Google and Meta advertising, Google Business Profile, LINE and social media), build AI integrations and automations (AI receptionists and chatbots, AI lead capture and qualification, workflow automations connecting bookings, CRMs and invoicing, and AI-assisted content), and provide ongoing account management and fractional digital team retainers. Our signature offer is a free working demo of a client’s website before they pay. Clients own their domain, site and accounts.


This policy explains how we collect, use, store and share personal information. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and, for individuals in Japan, Japan’s Act on the Protection of Personal Information (APPI). It applies to our website at [Website URL], our outreach, our services, and our dealings with prospects, clients, website visitors and our clients’ customers. Nothing in this policy limits any rights you have under the Australian Consumer Law.


Effective date: [Effective date].



2. What personal information we collect


The personal information we collect depends on how you deal with us. We collect the following.


Prospects and leads (businesses we think could benefit from our services): business name, contact name and role, business email address, phone number, business address, website address, social media and Google Business Profile links, industry, publicly visible facts about the business (for example whether it has a website, its opening hours, its reviews), and notes from any conversations we have with you.


Clients: everything above plus billing and payment details (we never store full card numbers, these are handled by Stripe), ABN, contracts, invoices and payment history, project communications, the content, images and brand assets you give us for your site and marketing, the details needed to set up or manage accounts in your name (for example domain, hosting, Google, Meta, LINE, booking, CRM and invoicing accounts), and feedback or testimonials you provide.


Website visitors: technical information such as IP address, device and browser type, pages viewed, time on page, referring site and approximate location, together with anything you enter into a form on our site (name, email, phone, business name, message). See section 11 on cookies and analytics.


Client-customer data we process on our clients’ behalf: when we build or manage a client’s website, forms, booking system, chatbot, AI receptionist or automation, the client’s own customers’ information passes through systems we set up. This can include names, contact details, booking details, enquiry content, chat or call transcripts, and order or payment status (never full card numbers). We handle this information as a service provider acting on the client’s instructions. The client remains responsible for its own privacy obligations and its own privacy policy, and requests about that information should be made to the client in the first instance (see section 9).


Sensitive information: we do not seek sensitive information (such as health, racial or ethnic origin, religious beliefs, sexual orientation or criminal record). Some clients operate in fields where their customers share such information (for example allied health or NDIS providers). Where that happens we handle it only as instructed by the client, only with the protections the client and the law require, and we ask that you do not include sensitive information in enquiries to us unless it is necessary.



3. How we collect it


Directly from you: when you fill in a form on our website, request a free demo, email, call or message us (including via WhatsApp or LINE), book a meeting, sign a proposal, complete onboarding, or give us content for your project.


Through outreach and lead tools: we identify small businesses that may benefit from our services and collect publicly available business contact details from sources such as business websites, Google Business Profile and Google Maps listings, online directories, social media pages and industry listings, and from lead data providers such as Apollo. We collect only what we reasonably need to make contact about our services. When we first contact you we will tell you who we are and, if you ask, where we obtained your details. You can ask us to stop contacting you or to delete your details at any time.


By phone: where we call businesses, we do so in accordance with the Do Not Call Register Act 2006 (Cth) and we respect any request not to be called again.


Automatically: through cookies, analytics and similar technologies on our website and on demo sites we host (section 11).


From third parties: from platforms we manage for you (for example Google, Meta or LINE reporting), from Stripe when you pay us, from referrers who introduce you, and from publicly available sources.


On behalf of clients: through the websites, forms, booking tools, chatbots, AI receptionists and automations we build and manage for clients, in line with the client’s instructions.


Unsolicited information: if we receive personal information we did not ask for and could not lawfully have collected ourselves, we will destroy or de-identify it as soon as practicable where it is lawful and reasonable to do so.



4. Why we use it


We collect, hold and use personal information to:


• provide our services, including preparing your free demo, designing, building, hosting and maintaining websites, running marketing campaigns and setting up accounts in your name, • communicate with you about enquiries, proposals, projects, support and account management, • set up, run and improve AI receptionists, chatbots, lead qualification and automations (section 7), • invoice you, process payments, manage contracts and keep business records, • tell prospects and clients about our services, offers and updates that we think are relevant (section 5), • understand how our website and services are used so we can improve them, • comply with our legal obligations, resolve disputes, prevent fraud or misuse, and protect our rights and the rights of others, • in the case of client-customer data, only for the purposes the client instructs us to carry out on its behalf.


We use personal information only for the purpose for which it was collected, for a related purpose you would reasonably expect, with your consent, or where the law requires or permits it. We do not sell personal information, and we do not use client-customer data for our own marketing.



5. Direct marketing and the Spam Act


We market our services to businesses, mostly by phone and by email, and occasionally by SMS, LINE or social media messages. We comply with the Spam Act 2003 (Cth) and Australian Privacy Principle 7.


Consent: we send commercial electronic messages only where we have your consent. Consent may be express (you asked for information, requested a demo, subscribed, or agreed during a conversation) or inferred (for example, you have an existing business relationship with us, or your business email address is published conspicuously for your role without a statement that you do not want to receive unsolicited commercial messages, and our message is relevant to that role). Where consent is inferred we keep our messages relevant, brief and easy to stop.


Identification: every marketing message we send clearly identifies SAH Studios as the sender and includes accurate contact details.


Unsubscribe: every marketing message includes a functional unsubscribe option (for example a reply or link). We action unsubscribe requests within five business days and do not charge for them. You can also opt out at any time by contacting [Contact email], and we will not contact you for marketing again unless you ask us to.


Source of your details: if we contact you using details obtained from a third party (such as a lead data provider) or a public source, we will tell you the source when you ask.


Phone: we respect requests not to be called and comply with the Do Not Call Register where it applies.


Client campaigns: when we run email, SMS or LINE campaigns for clients, we do so on the client’s instructions and using the client’s own customer consents. The client is responsible for having that consent. We will not send a campaign for a client if we believe it would breach the Spam Act.



6. Who we share it with, including overseas


We do not sell or rent personal information. We share it only as described here.


Service providers and processors: we use third-party tools to run our business and deliver our services. These providers process personal information on our behalf under their own contractual terms and security commitments. Our main providers, and where they are based or store data, are:


• Framer (website builder and hosting) - the Netherlands, with hosting on global infrastructure including the United States, • Resend (email delivery for transactional and system emails) - United States, • Apollo (business lead data and outreach) - United States, • Anthropic (Claude AI models we use to help deliver services) - United States, • Google (Workspace email and documents, Analytics, Ads, Business Profile and related tools) - United States and global, • Meta (Facebook and Instagram pages, advertising, WhatsApp) - United States and global, • Stripe (payment processing and invoicing) - United States, with regional operations including Australia, • Notion (project management and client records) - United States, • LINE (messaging and official accounts for Japanese clients) - Japan, • booking, CRM, invoicing and automation tools we set up for individual clients (for example Calendly, Square, Xero, ServiceM8 or similar), as agreed with each client.


[Confirm this list and each provider’s data location at publication.]


Other recipients: contractors who work with us (such as designers, developers or translators) under confidentiality obligations, our accountants, lawyers and insurers, anyone you direct us to share with (such as your domain registrar or a platform you own), a buyer or successor if our business is sold or restructured, and courts, regulators, law enforcement or other parties where the law requires or authorises disclosure.


Overseas disclosure: because the providers above are located, or store data, in the United States, the European Union, Japan and other countries, personal information we collect will be disclosed to and stored overseas. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle personal information in a way consistent with the APPs. We do this by using established providers with published security and privacy commitments, agreeing to their data processing terms, limiting what we send to what is needed, and controlling who on our team can access each tool. You should be aware that overseas providers are not bound by the Privacy Act 1988 (Cth), and you may not be able to seek redress under Australian law if they mishandle your information. By providing personal information to us, you acknowledge that it will be handled in this way. [Lawyer to confirm whether reliance on APP 8.2(b) consent wording is appropriate here.]



7. How we use AI


We use artificial intelligence tools to help deliver our services. Our main AI provider is Anthropic (Claude), and we also use AI features built into tools such as Google, Meta, Framer and Notion. We use AI to draft website copy and marketing content, summarise and categorise enquiries, draft outreach and replies for our team to review, build and run AI receptionists, chatbots and lead qualification for clients, and build workflow automations.


What this means for your information: personal information may be processed by these tools in the course of delivering a service. For example, an enquiry you send us may be summarised by an AI tool, a conversation with a chatbot we built for a client will be processed by an AI model to generate replies, and a lead’s business details may be used to draft a first message. We send AI tools only the information needed for the task.


Human oversight: our team reviews AI-generated outputs before they are relied on for anything significant, and a person is always responsible for the work we deliver. We do not make decisions that have a legal or similarly significant effect on you solely by automated means. AI receptionists and chatbots we deploy are configured to make clear that they are automated where that is required or appropriate, to collect only what the client needs, and to hand over to a person when asked or when a matter is outside their scope.


Model training: we do not train our own AI models on your personal information. We use business or API services whose terms state that the provider does not use customer inputs or outputs to train its models. [Confirm the current terms of each AI provider at publication.]


Client-customer data: when we build AI tools for a client, the client’s customers’ information is processed on the client’s instructions. Clients should disclose their use of AI tools in their own privacy policy and, where relevant, at the point of interaction. We can help clients with that wording, but it is their responsibility.


Accuracy: AI tools can make mistakes. If you believe an AI-generated communication or decision involving you is wrong, you can ask us for a person to review it by contacting [Contact email].



8. Security and retention


Security: we take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include: password managers and multi-factor authentication on our accounts, encryption in transit (HTTPS) and, through our providers, at rest, giving team members and contractors access only to the tools and client accounts they need, sharing account access with clients through secure methods rather than plain email, confidentiality obligations for everyone who works with us, and periodic review of who has access to what. [Adjust to match actual practices.] Because clients own their own accounts, we remove our access when an engagement ends if you ask us to. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.


Data breaches: if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme. If a breach involves client-customer data we hold on a client’s behalf, we will notify the client promptly so it can meet its own obligations.


Retention: we keep personal information only for as long as we need it for the purposes in this policy or as the law requires. As a guide:


• prospect and lead information: deleted or de-identified if there has been no engagement for [12] months, or sooner if you ask, • client information: for the life of the engagement and then for [7] years, because Australian tax and corporate law requires us to keep financial records for that period, • project files, content and communications: [X] years after the engagement ends, unless you ask us to delete them sooner, • client-customer data: as the client instructs. When an engagement ends we return or delete it within [30] days, except copies in routine backups (which are overwritten on rotation) and anything the law requires us to keep, • website analytics data: per the retention settings of the analytics tool, currently [14] months.


When we no longer need personal information we securely destroy or de-identify it.



9. Access, correction and deletion


You have the right to ask for access to the personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. You can also ask us to delete your information or to stop using it for a particular purpose.


How to ask: email [Contact email] with your name, how you have dealt with us and what you are asking for. We may need to verify your identity before we act.


Timeframe and cost: we will respond within a reasonable period, and aim to do so within 30 days. Access is usually free. If a request is unusually complex we may charge a reasonable fee to cover our costs, and we will tell you before doing anything.


Refusals: in limited cases the law allows or requires us to refuse access or correction (for example where it would unreasonably affect someone else’s privacy). If we refuse, we will give you written reasons and tell you how to complain.


Corrections we pass on: if we correct information we have shared with a third party, we will tell that third party where it is reasonable to do so.


Deletion: we will delete your information when you ask unless we need to keep it to complete a service you have requested, to comply with a legal obligation, or to resolve a dispute. Where we cannot delete something we will tell you why.


Client-customer data: if your information is held by us because you are a customer of one of our clients, please contact that client directly. We will help the client respond to you and will act on the client’s instructions. If you are not sure who the client is, contact us and we will point you in the right direction.



10. Complaints


If you have a concern about how we have handled your personal information, or about a marketing message or call from us, please contact us first at [Contact email] or by post at [Registered address]. Please give us enough detail to investigate.


We will acknowledge your complaint within [5] business days, investigate it, and aim to give you a written response within 30 days. If we need longer we will tell you why and when to expect a response.


If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):


Website: www.oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5288, Sydney NSW 2001


Complaints about spam or unwanted calls can also be made to the Australian Communications and Media Authority (ACMA) at www.acma.gov.au.


If you are in Japan, you may also contact Japan’s Personal Information Protection Commission (PPC) at www.ppc.go.jp.



11. Cookies and analytics


Our website is built and hosted on Framer and uses cookies and similar technologies (such as pixels and local storage). These fall into four groups:


• essential cookies that make the site work, for example remembering a form you started, • analytics cookies (Framer Analytics and Google Analytics) that tell us which pages are visited, how visitors arrive and how they move through the site, using anonymised or pseudonymised identifiers and, where enabled, IP anonymisation, • advertising cookies and pixels (Google Ads and the Meta Pixel) that measure whether our advertising works and may show you relevant ads on Google or Meta platforms after you have visited our site, • business-visitor identification (Apollo website visitor tracking, if enabled) that attempts to identify the company, not the individual, behind a visit using the visitor’s network information. [Remove if not used.]


Consent: where the law of your location requires it (including for visitors from the European Union, the United Kingdom and Japan), we ask for your consent before setting non-essential cookies, and the site works without them.


Your choices: you can block or delete cookies through your browser settings, although some parts of the site may not work as intended. You can also opt out of Google Analytics using Google’s browser add-on (tools.google.com/dlpage/gaoptout), manage Google ad personalisation at adssettings.google.com, manage Meta ad preferences in your Facebook or Instagram settings, and opt out of many advertising networks at www.youronlinechoices.com.au.


Demo sites and client sites: the free demo sites we host, and the client websites we build, may use their own cookies and analytics. Once a site is handed over, the client’s privacy policy governs it.



12. If you are in Japan


We work with businesses in Japan, and some of our clients’ customers are in Japan. Where we handle the personal information of individuals in Japan, we also comply with Japan’s Act on the Protection of Personal Information (APPI) and the guidelines of the Personal Information Protection Commission (PPC).


Purpose of use: the purposes for which we use personal information are set out in section 4. We will not use personal information beyond those purposes without your consent.


Cross-border transfers: personal information collected in Japan will be transferred to Australia, where we are based, and to the overseas providers listed in section 6. Australia is not currently designated by the PPC as a country with a personal information protection system equivalent to Japan’s. We therefore either obtain your prior consent to the transfer (having told you the destination country, its personal information protection system, and the measures the recipient takes) or ensure the recipient has put in place safeguards that meet the APPI standards. You can ask us for this information at any time.


Third-party provision: we do not provide personal information to third parties except to our service providers acting on our behalf, with your consent, or as required by law. We do not use the APPI “opt-out” method of third-party provision.


Your rights: you may request disclosure of your retained personal data, correction, addition or deletion, suspension of use or erasure, and cessation of provision to third parties. Requests can be made in Japanese or English to [Contact email]. We may verify your identity and, for disclosure requests, may charge a reasonable fee.


LINE: where we manage a LINE Official Account for a client or use LINE to communicate with you, LINE’s own terms and privacy policy also apply.


Language: [If a Japanese-language version of this policy is published, state which version prevails in the event of inconsistency.]


[Japan-qualified lawyer to review this section, and to advise whether a Japanese representative or entity must be named.]



13. Changes to this policy and how to contact us


We may update this policy from time to time to reflect changes in our services, tools or the law. The current version will always be available at [Website URL]/privacy with its effective date. If we make a material change that affects how we handle your personal information, we will notify current clients by email before it takes effect. Continuing to use our services after a change takes effect means you accept the updated policy.


Contact us: for anything about this policy, your personal information or your privacy rights, contact our Privacy Officer.


[Legal entity name] (ABN [ABN]) Attention: Privacy Officer [Registered address], [State/Territory], Australia Email: [Contact email] Phone: [Phone]


This policy is version [1.0], effective [Effective date].

SAH Studios Privacy Policy


Last updated: 3 September 2026 · SAH Studios · Australia + 日本



Read this first: template notice


This document is a starting template only. It has been prepared to help [Legal entity name] draft a privacy policy and has not been reviewed by a lawyer. Before it is published or relied on, it must be reviewed by a qualified lawyer admitted in Australia (and, for the Japan section, a lawyer qualified in Japan). Privacy law changes often and the correct wording depends on facts about the business that this template does not have.


Everything in square brackets, for example [Legal entity name], [ABN], [Registered address], [State/Territory], [Effective date], [Contact email] and [Website URL], is a placeholder to be completed or confirmed. Retention periods, provider locations and the list of tools should also be checked against what the business actually uses on the day this is published.


Note for the reviewer: some small businesses with an annual turnover under A$3 million are exempt from parts of the Privacy Act 1988 (Cth). This template is written on the basis that SAH Studios chooses to handle personal information in line with the Australian Privacy Principles regardless, because it processes personal information on behalf of clients and operates across borders. The lawyer should confirm whether the exemption applies and whether any wording below should change as a result.



1. Who we are


SAH Studios (also known as Stay at Home Studios) is operated by [Legal entity name] (ABN [ABN]) of [Registered address], [State/Territory], Australia. In this policy, “SAH Studios”, “we”, “us” and “our” refer to that entity.


We are a digital agency for small businesses in Australia and Japan. We design and build websites and online presences, run managed marketing (SEO, Google and Meta advertising, Google Business Profile, LINE and social media), build AI integrations and automations (AI receptionists and chatbots, AI lead capture and qualification, workflow automations connecting bookings, CRMs and invoicing, and AI-assisted content), and provide ongoing account management and fractional digital team retainers. Our signature offer is a free working demo of a client’s website before they pay. Clients own their domain, site and accounts.


This policy explains how we collect, use, store and share personal information. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and, for individuals in Japan, Japan’s Act on the Protection of Personal Information (APPI). It applies to our website at [Website URL], our outreach, our services, and our dealings with prospects, clients, website visitors and our clients’ customers. Nothing in this policy limits any rights you have under the Australian Consumer Law.


Effective date: [Effective date].



2. What personal information we collect


The personal information we collect depends on how you deal with us. We collect the following.


Prospects and leads (businesses we think could benefit from our services): business name, contact name and role, business email address, phone number, business address, website address, social media and Google Business Profile links, industry, publicly visible facts about the business (for example whether it has a website, its opening hours, its reviews), and notes from any conversations we have with you.


Clients: everything above plus billing and payment details (we never store full card numbers, these are handled by Stripe), ABN, contracts, invoices and payment history, project communications, the content, images and brand assets you give us for your site and marketing, the details needed to set up or manage accounts in your name (for example domain, hosting, Google, Meta, LINE, booking, CRM and invoicing accounts), and feedback or testimonials you provide.


Website visitors: technical information such as IP address, device and browser type, pages viewed, time on page, referring site and approximate location, together with anything you enter into a form on our site (name, email, phone, business name, message). See section 11 on cookies and analytics.


Client-customer data we process on our clients’ behalf: when we build or manage a client’s website, forms, booking system, chatbot, AI receptionist or automation, the client’s own customers’ information passes through systems we set up. This can include names, contact details, booking details, enquiry content, chat or call transcripts, and order or payment status (never full card numbers). We handle this information as a service provider acting on the client’s instructions. The client remains responsible for its own privacy obligations and its own privacy policy, and requests about that information should be made to the client in the first instance (see section 9).


Sensitive information: we do not seek sensitive information (such as health, racial or ethnic origin, religious beliefs, sexual orientation or criminal record). Some clients operate in fields where their customers share such information (for example allied health or NDIS providers). Where that happens we handle it only as instructed by the client, only with the protections the client and the law require, and we ask that you do not include sensitive information in enquiries to us unless it is necessary.



3. How we collect it


Directly from you: when you fill in a form on our website, request a free demo, email, call or message us (including via WhatsApp or LINE), book a meeting, sign a proposal, complete onboarding, or give us content for your project.


Through outreach and lead tools: we identify small businesses that may benefit from our services and collect publicly available business contact details from sources such as business websites, Google Business Profile and Google Maps listings, online directories, social media pages and industry listings, and from lead data providers such as Apollo. We collect only what we reasonably need to make contact about our services. When we first contact you we will tell you who we are and, if you ask, where we obtained your details. You can ask us to stop contacting you or to delete your details at any time.


By phone: where we call businesses, we do so in accordance with the Do Not Call Register Act 2006 (Cth) and we respect any request not to be called again.


Automatically: through cookies, analytics and similar technologies on our website and on demo sites we host (section 11).


From third parties: from platforms we manage for you (for example Google, Meta or LINE reporting), from Stripe when you pay us, from referrers who introduce you, and from publicly available sources.


On behalf of clients: through the websites, forms, booking tools, chatbots, AI receptionists and automations we build and manage for clients, in line with the client’s instructions.


Unsolicited information: if we receive personal information we did not ask for and could not lawfully have collected ourselves, we will destroy or de-identify it as soon as practicable where it is lawful and reasonable to do so.



4. Why we use it


We collect, hold and use personal information to:


• provide our services, including preparing your free demo, designing, building, hosting and maintaining websites, running marketing campaigns and setting up accounts in your name, • communicate with you about enquiries, proposals, projects, support and account management, • set up, run and improve AI receptionists, chatbots, lead qualification and automations (section 7), • invoice you, process payments, manage contracts and keep business records, • tell prospects and clients about our services, offers and updates that we think are relevant (section 5), • understand how our website and services are used so we can improve them, • comply with our legal obligations, resolve disputes, prevent fraud or misuse, and protect our rights and the rights of others, • in the case of client-customer data, only for the purposes the client instructs us to carry out on its behalf.


We use personal information only for the purpose for which it was collected, for a related purpose you would reasonably expect, with your consent, or where the law requires or permits it. We do not sell personal information, and we do not use client-customer data for our own marketing.



5. Direct marketing and the Spam Act


We market our services to businesses, mostly by phone and by email, and occasionally by SMS, LINE or social media messages. We comply with the Spam Act 2003 (Cth) and Australian Privacy Principle 7.


Consent: we send commercial electronic messages only where we have your consent. Consent may be express (you asked for information, requested a demo, subscribed, or agreed during a conversation) or inferred (for example, you have an existing business relationship with us, or your business email address is published conspicuously for your role without a statement that you do not want to receive unsolicited commercial messages, and our message is relevant to that role). Where consent is inferred we keep our messages relevant, brief and easy to stop.


Identification: every marketing message we send clearly identifies SAH Studios as the sender and includes accurate contact details.


Unsubscribe: every marketing message includes a functional unsubscribe option (for example a reply or link). We action unsubscribe requests within five business days and do not charge for them. You can also opt out at any time by contacting [Contact email], and we will not contact you for marketing again unless you ask us to.


Source of your details: if we contact you using details obtained from a third party (such as a lead data provider) or a public source, we will tell you the source when you ask.


Phone: we respect requests not to be called and comply with the Do Not Call Register where it applies.


Client campaigns: when we run email, SMS or LINE campaigns for clients, we do so on the client’s instructions and using the client’s own customer consents. The client is responsible for having that consent. We will not send a campaign for a client if we believe it would breach the Spam Act.



6. Who we share it with, including overseas


We do not sell or rent personal information. We share it only as described here.


Service providers and processors: we use third-party tools to run our business and deliver our services. These providers process personal information on our behalf under their own contractual terms and security commitments. Our main providers, and where they are based or store data, are:


• Framer (website builder and hosting) - the Netherlands, with hosting on global infrastructure including the United States, • Resend (email delivery for transactional and system emails) - United States, • Apollo (business lead data and outreach) - United States, • Anthropic (Claude AI models we use to help deliver services) - United States, • Google (Workspace email and documents, Analytics, Ads, Business Profile and related tools) - United States and global, • Meta (Facebook and Instagram pages, advertising, WhatsApp) - United States and global, • Stripe (payment processing and invoicing) - United States, with regional operations including Australia, • Notion (project management and client records) - United States, • LINE (messaging and official accounts for Japanese clients) - Japan, • booking, CRM, invoicing and automation tools we set up for individual clients (for example Calendly, Square, Xero, ServiceM8 or similar), as agreed with each client.


[Confirm this list and each provider’s data location at publication.]


Other recipients: contractors who work with us (such as designers, developers or translators) under confidentiality obligations, our accountants, lawyers and insurers, anyone you direct us to share with (such as your domain registrar or a platform you own), a buyer or successor if our business is sold or restructured, and courts, regulators, law enforcement or other parties where the law requires or authorises disclosure.


Overseas disclosure: because the providers above are located, or store data, in the United States, the European Union, Japan and other countries, personal information we collect will be disclosed to and stored overseas. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle personal information in a way consistent with the APPs. We do this by using established providers with published security and privacy commitments, agreeing to their data processing terms, limiting what we send to what is needed, and controlling who on our team can access each tool. You should be aware that overseas providers are not bound by the Privacy Act 1988 (Cth), and you may not be able to seek redress under Australian law if they mishandle your information. By providing personal information to us, you acknowledge that it will be handled in this way. [Lawyer to confirm whether reliance on APP 8.2(b) consent wording is appropriate here.]



7. How we use AI


We use artificial intelligence tools to help deliver our services. Our main AI provider is Anthropic (Claude), and we also use AI features built into tools such as Google, Meta, Framer and Notion. We use AI to draft website copy and marketing content, summarise and categorise enquiries, draft outreach and replies for our team to review, build and run AI receptionists, chatbots and lead qualification for clients, and build workflow automations.


What this means for your information: personal information may be processed by these tools in the course of delivering a service. For example, an enquiry you send us may be summarised by an AI tool, a conversation with a chatbot we built for a client will be processed by an AI model to generate replies, and a lead’s business details may be used to draft a first message. We send AI tools only the information needed for the task.


Human oversight: our team reviews AI-generated outputs before they are relied on for anything significant, and a person is always responsible for the work we deliver. We do not make decisions that have a legal or similarly significant effect on you solely by automated means. AI receptionists and chatbots we deploy are configured to make clear that they are automated where that is required or appropriate, to collect only what the client needs, and to hand over to a person when asked or when a matter is outside their scope.


Model training: we do not train our own AI models on your personal information. We use business or API services whose terms state that the provider does not use customer inputs or outputs to train its models. [Confirm the current terms of each AI provider at publication.]


Client-customer data: when we build AI tools for a client, the client’s customers’ information is processed on the client’s instructions. Clients should disclose their use of AI tools in their own privacy policy and, where relevant, at the point of interaction. We can help clients with that wording, but it is their responsibility.


Accuracy: AI tools can make mistakes. If you believe an AI-generated communication or decision involving you is wrong, you can ask us for a person to review it by contacting [Contact email].



8. Security and retention


Security: we take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include: password managers and multi-factor authentication on our accounts, encryption in transit (HTTPS) and, through our providers, at rest, giving team members and contractors access only to the tools and client accounts they need, sharing account access with clients through secure methods rather than plain email, confidentiality obligations for everyone who works with us, and periodic review of who has access to what. [Adjust to match actual practices.] Because clients own their own accounts, we remove our access when an engagement ends if you ask us to. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.


Data breaches: if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme. If a breach involves client-customer data we hold on a client’s behalf, we will notify the client promptly so it can meet its own obligations.


Retention: we keep personal information only for as long as we need it for the purposes in this policy or as the law requires. As a guide:


• prospect and lead information: deleted or de-identified if there has been no engagement for [12] months, or sooner if you ask, • client information: for the life of the engagement and then for [7] years, because Australian tax and corporate law requires us to keep financial records for that period, • project files, content and communications: [X] years after the engagement ends, unless you ask us to delete them sooner, • client-customer data: as the client instructs. When an engagement ends we return or delete it within [30] days, except copies in routine backups (which are overwritten on rotation) and anything the law requires us to keep, • website analytics data: per the retention settings of the analytics tool, currently [14] months.


When we no longer need personal information we securely destroy or de-identify it.



9. Access, correction and deletion


You have the right to ask for access to the personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. You can also ask us to delete your information or to stop using it for a particular purpose.


How to ask: email [Contact email] with your name, how you have dealt with us and what you are asking for. We may need to verify your identity before we act.


Timeframe and cost: we will respond within a reasonable period, and aim to do so within 30 days. Access is usually free. If a request is unusually complex we may charge a reasonable fee to cover our costs, and we will tell you before doing anything.


Refusals: in limited cases the law allows or requires us to refuse access or correction (for example where it would unreasonably affect someone else’s privacy). If we refuse, we will give you written reasons and tell you how to complain.


Corrections we pass on: if we correct information we have shared with a third party, we will tell that third party where it is reasonable to do so.


Deletion: we will delete your information when you ask unless we need to keep it to complete a service you have requested, to comply with a legal obligation, or to resolve a dispute. Where we cannot delete something we will tell you why.


Client-customer data: if your information is held by us because you are a customer of one of our clients, please contact that client directly. We will help the client respond to you and will act on the client’s instructions. If you are not sure who the client is, contact us and we will point you in the right direction.



10. Complaints


If you have a concern about how we have handled your personal information, or about a marketing message or call from us, please contact us first at [Contact email] or by post at [Registered address]. Please give us enough detail to investigate.


We will acknowledge your complaint within [5] business days, investigate it, and aim to give you a written response within 30 days. If we need longer we will tell you why and when to expect a response.


If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):


Website: www.oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5288, Sydney NSW 2001


Complaints about spam or unwanted calls can also be made to the Australian Communications and Media Authority (ACMA) at www.acma.gov.au.


If you are in Japan, you may also contact Japan’s Personal Information Protection Commission (PPC) at www.ppc.go.jp.



11. Cookies and analytics


Our website is built and hosted on Framer and uses cookies and similar technologies (such as pixels and local storage). These fall into four groups:


• essential cookies that make the site work, for example remembering a form you started, • analytics cookies (Framer Analytics and Google Analytics) that tell us which pages are visited, how visitors arrive and how they move through the site, using anonymised or pseudonymised identifiers and, where enabled, IP anonymisation, • advertising cookies and pixels (Google Ads and the Meta Pixel) that measure whether our advertising works and may show you relevant ads on Google or Meta platforms after you have visited our site, • business-visitor identification (Apollo website visitor tracking, if enabled) that attempts to identify the company, not the individual, behind a visit using the visitor’s network information. [Remove if not used.]


Consent: where the law of your location requires it (including for visitors from the European Union, the United Kingdom and Japan), we ask for your consent before setting non-essential cookies, and the site works without them.


Your choices: you can block or delete cookies through your browser settings, although some parts of the site may not work as intended. You can also opt out of Google Analytics using Google’s browser add-on (tools.google.com/dlpage/gaoptout), manage Google ad personalisation at adssettings.google.com, manage Meta ad preferences in your Facebook or Instagram settings, and opt out of many advertising networks at www.youronlinechoices.com.au.


Demo sites and client sites: the free demo sites we host, and the client websites we build, may use their own cookies and analytics. Once a site is handed over, the client’s privacy policy governs it.



12. If you are in Japan


We work with businesses in Japan, and some of our clients’ customers are in Japan. Where we handle the personal information of individuals in Japan, we also comply with Japan’s Act on the Protection of Personal Information (APPI) and the guidelines of the Personal Information Protection Commission (PPC).


Purpose of use: the purposes for which we use personal information are set out in section 4. We will not use personal information beyond those purposes without your consent.


Cross-border transfers: personal information collected in Japan will be transferred to Australia, where we are based, and to the overseas providers listed in section 6. Australia is not currently designated by the PPC as a country with a personal information protection system equivalent to Japan’s. We therefore either obtain your prior consent to the transfer (having told you the destination country, its personal information protection system, and the measures the recipient takes) or ensure the recipient has put in place safeguards that meet the APPI standards. You can ask us for this information at any time.


Third-party provision: we do not provide personal information to third parties except to our service providers acting on our behalf, with your consent, or as required by law. We do not use the APPI “opt-out” method of third-party provision.


Your rights: you may request disclosure of your retained personal data, correction, addition or deletion, suspension of use or erasure, and cessation of provision to third parties. Requests can be made in Japanese or English to [Contact email]. We may verify your identity and, for disclosure requests, may charge a reasonable fee.


LINE: where we manage a LINE Official Account for a client or use LINE to communicate with you, LINE’s own terms and privacy policy also apply.


Language: [If a Japanese-language version of this policy is published, state which version prevails in the event of inconsistency.]


[Japan-qualified lawyer to review this section, and to advise whether a Japanese representative or entity must be named.]



13. Changes to this policy and how to contact us


We may update this policy from time to time to reflect changes in our services, tools or the law. The current version will always be available at [Website URL]/privacy with its effective date. If we make a material change that affects how we handle your personal information, we will notify current clients by email before it takes effect. Continuing to use our services after a change takes effect means you accept the updated policy.


Contact us: for anything about this policy, your personal information or your privacy rights, contact our Privacy Officer.


[Legal entity name] (ABN [ABN]) Attention: Privacy Officer [Registered address], [State/Territory], Australia Email: [Contact email] Phone: [Phone]


This policy is version [1.0], effective [Effective date].

SAH Studios Privacy Policy


Last updated: 3 September 2026 · SAH Studios · Australia + 日本



Read this first: template notice


This document is a starting template only. It has been prepared to help [Legal entity name] draft a privacy policy and has not been reviewed by a lawyer. Before it is published or relied on, it must be reviewed by a qualified lawyer admitted in Australia (and, for the Japan section, a lawyer qualified in Japan). Privacy law changes often and the correct wording depends on facts about the business that this template does not have.


Everything in square brackets, for example [Legal entity name], [ABN], [Registered address], [State/Territory], [Effective date], [Contact email] and [Website URL], is a placeholder to be completed or confirmed. Retention periods, provider locations and the list of tools should also be checked against what the business actually uses on the day this is published.


Note for the reviewer: some small businesses with an annual turnover under A$3 million are exempt from parts of the Privacy Act 1988 (Cth). This template is written on the basis that SAH Studios chooses to handle personal information in line with the Australian Privacy Principles regardless, because it processes personal information on behalf of clients and operates across borders. The lawyer should confirm whether the exemption applies and whether any wording below should change as a result.



1. Who we are


SAH Studios (also known as Stay at Home Studios) is operated by [Legal entity name] (ABN [ABN]) of [Registered address], [State/Territory], Australia. In this policy, “SAH Studios”, “we”, “us” and “our” refer to that entity.


We are a digital agency for small businesses in Australia and Japan. We design and build websites and online presences, run managed marketing (SEO, Google and Meta advertising, Google Business Profile, LINE and social media), build AI integrations and automations (AI receptionists and chatbots, AI lead capture and qualification, workflow automations connecting bookings, CRMs and invoicing, and AI-assisted content), and provide ongoing account management and fractional digital team retainers. Our signature offer is a free working demo of a client’s website before they pay. Clients own their domain, site and accounts.


This policy explains how we collect, use, store and share personal information. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Spam Act 2003 (Cth), the Do Not Call Register Act 2006 (Cth) and, for individuals in Japan, Japan’s Act on the Protection of Personal Information (APPI). It applies to our website at [Website URL], our outreach, our services, and our dealings with prospects, clients, website visitors and our clients’ customers. Nothing in this policy limits any rights you have under the Australian Consumer Law.


Effective date: [Effective date].



2. What personal information we collect


The personal information we collect depends on how you deal with us. We collect the following.


Prospects and leads (businesses we think could benefit from our services): business name, contact name and role, business email address, phone number, business address, website address, social media and Google Business Profile links, industry, publicly visible facts about the business (for example whether it has a website, its opening hours, its reviews), and notes from any conversations we have with you.


Clients: everything above plus billing and payment details (we never store full card numbers, these are handled by Stripe), ABN, contracts, invoices and payment history, project communications, the content, images and brand assets you give us for your site and marketing, the details needed to set up or manage accounts in your name (for example domain, hosting, Google, Meta, LINE, booking, CRM and invoicing accounts), and feedback or testimonials you provide.


Website visitors: technical information such as IP address, device and browser type, pages viewed, time on page, referring site and approximate location, together with anything you enter into a form on our site (name, email, phone, business name, message). See section 11 on cookies and analytics.


Client-customer data we process on our clients’ behalf: when we build or manage a client’s website, forms, booking system, chatbot, AI receptionist or automation, the client’s own customers’ information passes through systems we set up. This can include names, contact details, booking details, enquiry content, chat or call transcripts, and order or payment status (never full card numbers). We handle this information as a service provider acting on the client’s instructions. The client remains responsible for its own privacy obligations and its own privacy policy, and requests about that information should be made to the client in the first instance (see section 9).


Sensitive information: we do not seek sensitive information (such as health, racial or ethnic origin, religious beliefs, sexual orientation or criminal record). Some clients operate in fields where their customers share such information (for example allied health or NDIS providers). Where that happens we handle it only as instructed by the client, only with the protections the client and the law require, and we ask that you do not include sensitive information in enquiries to us unless it is necessary.



3. How we collect it


Directly from you: when you fill in a form on our website, request a free demo, email, call or message us (including via WhatsApp or LINE), book a meeting, sign a proposal, complete onboarding, or give us content for your project.


Through outreach and lead tools: we identify small businesses that may benefit from our services and collect publicly available business contact details from sources such as business websites, Google Business Profile and Google Maps listings, online directories, social media pages and industry listings, and from lead data providers such as Apollo. We collect only what we reasonably need to make contact about our services. When we first contact you we will tell you who we are and, if you ask, where we obtained your details. You can ask us to stop contacting you or to delete your details at any time.


By phone: where we call businesses, we do so in accordance with the Do Not Call Register Act 2006 (Cth) and we respect any request not to be called again.


Automatically: through cookies, analytics and similar technologies on our website and on demo sites we host (section 11).


From third parties: from platforms we manage for you (for example Google, Meta or LINE reporting), from Stripe when you pay us, from referrers who introduce you, and from publicly available sources.


On behalf of clients: through the websites, forms, booking tools, chatbots, AI receptionists and automations we build and manage for clients, in line with the client’s instructions.


Unsolicited information: if we receive personal information we did not ask for and could not lawfully have collected ourselves, we will destroy or de-identify it as soon as practicable where it is lawful and reasonable to do so.



4. Why we use it


We collect, hold and use personal information to:


• provide our services, including preparing your free demo, designing, building, hosting and maintaining websites, running marketing campaigns and setting up accounts in your name, • communicate with you about enquiries, proposals, projects, support and account management, • set up, run and improve AI receptionists, chatbots, lead qualification and automations (section 7), • invoice you, process payments, manage contracts and keep business records, • tell prospects and clients about our services, offers and updates that we think are relevant (section 5), • understand how our website and services are used so we can improve them, • comply with our legal obligations, resolve disputes, prevent fraud or misuse, and protect our rights and the rights of others, • in the case of client-customer data, only for the purposes the client instructs us to carry out on its behalf.


We use personal information only for the purpose for which it was collected, for a related purpose you would reasonably expect, with your consent, or where the law requires or permits it. We do not sell personal information, and we do not use client-customer data for our own marketing.



5. Direct marketing and the Spam Act


We market our services to businesses, mostly by phone and by email, and occasionally by SMS, LINE or social media messages. We comply with the Spam Act 2003 (Cth) and Australian Privacy Principle 7.


Consent: we send commercial electronic messages only where we have your consent. Consent may be express (you asked for information, requested a demo, subscribed, or agreed during a conversation) or inferred (for example, you have an existing business relationship with us, or your business email address is published conspicuously for your role without a statement that you do not want to receive unsolicited commercial messages, and our message is relevant to that role). Where consent is inferred we keep our messages relevant, brief and easy to stop.


Identification: every marketing message we send clearly identifies SAH Studios as the sender and includes accurate contact details.


Unsubscribe: every marketing message includes a functional unsubscribe option (for example a reply or link). We action unsubscribe requests within five business days and do not charge for them. You can also opt out at any time by contacting [Contact email], and we will not contact you for marketing again unless you ask us to.


Source of your details: if we contact you using details obtained from a third party (such as a lead data provider) or a public source, we will tell you the source when you ask.


Phone: we respect requests not to be called and comply with the Do Not Call Register where it applies.


Client campaigns: when we run email, SMS or LINE campaigns for clients, we do so on the client’s instructions and using the client’s own customer consents. The client is responsible for having that consent. We will not send a campaign for a client if we believe it would breach the Spam Act.



6. Who we share it with, including overseas


We do not sell or rent personal information. We share it only as described here.


Service providers and processors: we use third-party tools to run our business and deliver our services. These providers process personal information on our behalf under their own contractual terms and security commitments. Our main providers, and where they are based or store data, are:


• Framer (website builder and hosting) - the Netherlands, with hosting on global infrastructure including the United States, • Resend (email delivery for transactional and system emails) - United States, • Apollo (business lead data and outreach) - United States, • Anthropic (Claude AI models we use to help deliver services) - United States, • Google (Workspace email and documents, Analytics, Ads, Business Profile and related tools) - United States and global, • Meta (Facebook and Instagram pages, advertising, WhatsApp) - United States and global, • Stripe (payment processing and invoicing) - United States, with regional operations including Australia, • Notion (project management and client records) - United States, • LINE (messaging and official accounts for Japanese clients) - Japan, • booking, CRM, invoicing and automation tools we set up for individual clients (for example Calendly, Square, Xero, ServiceM8 or similar), as agreed with each client.


[Confirm this list and each provider’s data location at publication.]


Other recipients: contractors who work with us (such as designers, developers or translators) under confidentiality obligations, our accountants, lawyers and insurers, anyone you direct us to share with (such as your domain registrar or a platform you own), a buyer or successor if our business is sold or restructured, and courts, regulators, law enforcement or other parties where the law requires or authorises disclosure.


Overseas disclosure: because the providers above are located, or store data, in the United States, the European Union, Japan and other countries, personal information we collect will be disclosed to and stored overseas. Under Australian Privacy Principle 8 we take reasonable steps to ensure overseas recipients handle personal information in a way consistent with the APPs. We do this by using established providers with published security and privacy commitments, agreeing to their data processing terms, limiting what we send to what is needed, and controlling who on our team can access each tool. You should be aware that overseas providers are not bound by the Privacy Act 1988 (Cth), and you may not be able to seek redress under Australian law if they mishandle your information. By providing personal information to us, you acknowledge that it will be handled in this way. [Lawyer to confirm whether reliance on APP 8.2(b) consent wording is appropriate here.]



7. How we use AI


We use artificial intelligence tools to help deliver our services. Our main AI provider is Anthropic (Claude), and we also use AI features built into tools such as Google, Meta, Framer and Notion. We use AI to draft website copy and marketing content, summarise and categorise enquiries, draft outreach and replies for our team to review, build and run AI receptionists, chatbots and lead qualification for clients, and build workflow automations.


What this means for your information: personal information may be processed by these tools in the course of delivering a service. For example, an enquiry you send us may be summarised by an AI tool, a conversation with a chatbot we built for a client will be processed by an AI model to generate replies, and a lead’s business details may be used to draft a first message. We send AI tools only the information needed for the task.


Human oversight: our team reviews AI-generated outputs before they are relied on for anything significant, and a person is always responsible for the work we deliver. We do not make decisions that have a legal or similarly significant effect on you solely by automated means. AI receptionists and chatbots we deploy are configured to make clear that they are automated where that is required or appropriate, to collect only what the client needs, and to hand over to a person when asked or when a matter is outside their scope.


Model training: we do not train our own AI models on your personal information. We use business or API services whose terms state that the provider does not use customer inputs or outputs to train its models. [Confirm the current terms of each AI provider at publication.]


Client-customer data: when we build AI tools for a client, the client’s customers’ information is processed on the client’s instructions. Clients should disclose their use of AI tools in their own privacy policy and, where relevant, at the point of interaction. We can help clients with that wording, but it is their responsibility.


Accuracy: AI tools can make mistakes. If you believe an AI-generated communication or decision involving you is wrong, you can ask us for a person to review it by contacting [Contact email].



8. Security and retention


Security: we take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps include: password managers and multi-factor authentication on our accounts, encryption in transit (HTTPS) and, through our providers, at rest, giving team members and contractors access only to the tools and client accounts they need, sharing account access with clients through secure methods rather than plain email, confidentiality obligations for everyone who works with us, and periodic review of who has access to what. [Adjust to match actual practices.] Because clients own their own accounts, we remove our access when an engagement ends if you ask us to. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.


Data breaches: if a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme. If a breach involves client-customer data we hold on a client’s behalf, we will notify the client promptly so it can meet its own obligations.


Retention: we keep personal information only for as long as we need it for the purposes in this policy or as the law requires. As a guide:


• prospect and lead information: deleted or de-identified if there has been no engagement for [12] months, or sooner if you ask, • client information: for the life of the engagement and then for [7] years, because Australian tax and corporate law requires us to keep financial records for that period, • project files, content and communications: [X] years after the engagement ends, unless you ask us to delete them sooner, • client-customer data: as the client instructs. When an engagement ends we return or delete it within [30] days, except copies in routine backups (which are overwritten on rotation) and anything the law requires us to keep, • website analytics data: per the retention settings of the analytics tool, currently [14] months.


When we no longer need personal information we securely destroy or de-identify it.



9. Access, correction and deletion


You have the right to ask for access to the personal information we hold about you and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. You can also ask us to delete your information or to stop using it for a particular purpose.


How to ask: email [Contact email] with your name, how you have dealt with us and what you are asking for. We may need to verify your identity before we act.


Timeframe and cost: we will respond within a reasonable period, and aim to do so within 30 days. Access is usually free. If a request is unusually complex we may charge a reasonable fee to cover our costs, and we will tell you before doing anything.


Refusals: in limited cases the law allows or requires us to refuse access or correction (for example where it would unreasonably affect someone else’s privacy). If we refuse, we will give you written reasons and tell you how to complain.


Corrections we pass on: if we correct information we have shared with a third party, we will tell that third party where it is reasonable to do so.


Deletion: we will delete your information when you ask unless we need to keep it to complete a service you have requested, to comply with a legal obligation, or to resolve a dispute. Where we cannot delete something we will tell you why.


Client-customer data: if your information is held by us because you are a customer of one of our clients, please contact that client directly. We will help the client respond to you and will act on the client’s instructions. If you are not sure who the client is, contact us and we will point you in the right direction.



10. Complaints


If you have a concern about how we have handled your personal information, or about a marketing message or call from us, please contact us first at [Contact email] or by post at [Registered address]. Please give us enough detail to investigate.


We will acknowledge your complaint within [5] business days, investigate it, and aim to give you a written response within 30 days. If we need longer we will tell you why and when to expect a response.


If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC):


Website: www.oaic.gov.au Phone: 1300 363 992 Post: GPO Box 5288, Sydney NSW 2001


Complaints about spam or unwanted calls can also be made to the Australian Communications and Media Authority (ACMA) at www.acma.gov.au.


If you are in Japan, you may also contact Japan’s Personal Information Protection Commission (PPC) at www.ppc.go.jp.



11. Cookies and analytics


Our website is built and hosted on Framer and uses cookies and similar technologies (such as pixels and local storage). These fall into four groups:


• essential cookies that make the site work, for example remembering a form you started, • analytics cookies (Framer Analytics and Google Analytics) that tell us which pages are visited, how visitors arrive and how they move through the site, using anonymised or pseudonymised identifiers and, where enabled, IP anonymisation, • advertising cookies and pixels (Google Ads and the Meta Pixel) that measure whether our advertising works and may show you relevant ads on Google or Meta platforms after you have visited our site, • business-visitor identification (Apollo website visitor tracking, if enabled) that attempts to identify the company, not the individual, behind a visit using the visitor’s network information. [Remove if not used.]


Consent: where the law of your location requires it (including for visitors from the European Union, the United Kingdom and Japan), we ask for your consent before setting non-essential cookies, and the site works without them.


Your choices: you can block or delete cookies through your browser settings, although some parts of the site may not work as intended. You can also opt out of Google Analytics using Google’s browser add-on (tools.google.com/dlpage/gaoptout), manage Google ad personalisation at adssettings.google.com, manage Meta ad preferences in your Facebook or Instagram settings, and opt out of many advertising networks at www.youronlinechoices.com.au.


Demo sites and client sites: the free demo sites we host, and the client websites we build, may use their own cookies and analytics. Once a site is handed over, the client’s privacy policy governs it.



12. If you are in Japan


We work with businesses in Japan, and some of our clients’ customers are in Japan. Where we handle the personal information of individuals in Japan, we also comply with Japan’s Act on the Protection of Personal Information (APPI) and the guidelines of the Personal Information Protection Commission (PPC).


Purpose of use: the purposes for which we use personal information are set out in section 4. We will not use personal information beyond those purposes without your consent.


Cross-border transfers: personal information collected in Japan will be transferred to Australia, where we are based, and to the overseas providers listed in section 6. Australia is not currently designated by the PPC as a country with a personal information protection system equivalent to Japan’s. We therefore either obtain your prior consent to the transfer (having told you the destination country, its personal information protection system, and the measures the recipient takes) or ensure the recipient has put in place safeguards that meet the APPI standards. You can ask us for this information at any time.


Third-party provision: we do not provide personal information to third parties except to our service providers acting on our behalf, with your consent, or as required by law. We do not use the APPI “opt-out” method of third-party provision.


Your rights: you may request disclosure of your retained personal data, correction, addition or deletion, suspension of use or erasure, and cessation of provision to third parties. Requests can be made in Japanese or English to [Contact email]. We may verify your identity and, for disclosure requests, may charge a reasonable fee.


LINE: where we manage a LINE Official Account for a client or use LINE to communicate with you, LINE’s own terms and privacy policy also apply.


Language: [If a Japanese-language version of this policy is published, state which version prevails in the event of inconsistency.]


[Japan-qualified lawyer to review this section, and to advise whether a Japanese representative or entity must be named.]



13. Changes to this policy and how to contact us


We may update this policy from time to time to reflect changes in our services, tools or the law. The current version will always be available at [Website URL]/privacy with its effective date. If we make a material change that affects how we handle your personal information, we will notify current clients by email before it takes effect. Continuing to use our services after a change takes effect means you accept the updated policy.


Contact us: for anything about this policy, your personal information or your privacy rights, contact our Privacy Officer.


[Legal entity name] (ABN [ABN]) Attention: Privacy Officer [Registered address], [State/Territory], Australia Email: [Contact email] Phone: [Phone]


This policy is version [1.0], effective [Effective date].