PRIVACY POLICY
Effective date: 29 September 2026
1. About this policy
Shakewell Agency Pty Ltd (ABN 57 634 812 865) (Shakewell, we, us, our) is a digital agency that designs, builds and supports websites, apps and digital platforms.
This policy explains how we collect, hold, use and disclose personal information. It applies to all personal information we handle, whether it comes through our website at shakewell.agency, our client work, recruitment or any other dealings with us.
We are bound by the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). When we deliver services under a contract with a government agency, we also comply with the privacy obligations in that contract.
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable. Sensitive information is a subset of personal information, such as health information, racial or ethnic origin, political opinions, religious beliefs or criminal record.
2. Personal information we collect
What we collect depends on how you deal with us.
- Clients and prospective clients: name, job title, organisation, email, phone number, billing details, and records of our communications and meetings.
- Users of websites and systems we build or support for clients: whatever personal information is held in those systems, which we access only to deliver our services (see section 5).
- Website visitors: information you submit through forms, plus technical data such as IP address, browser type and pages visited (see section 9).
- Suppliers, contractors and partners: name, business contact details, ABN, bank details for payment, and contract records.
- Job applicants: CV, work history, qualifications, referee details and interview notes.
We generally do not collect sensitive information. If we need to, for example a security clearance or police check required by a client contract, we will only collect it with your consent or where the law allows.
You can deal with us anonymously or under a pseudonym where that is practical, such as a general enquiry. We usually need your name and contact details to provide services or engage you.
3. How we collect personal information
We collect personal information directly from you where we reasonably can, for example when you:
- contact us, fill in a form on our website or sign up to our mailing list
- meet with us, or engage us to deliver services
- apply for a role or submit a proposal to work with us
Sometimes we collect it from others, such as your employer, a client that engages us, a recruiter, a referee you nominate, or public sources like LinkedIn. If we collect personal information about you from someone else, we take reasonable steps to let you know, unless it is obvious from the circumstances.
If we receive personal information we did not ask for, we check whether we could have collected it lawfully. If not, we destroy or de-identify it as soon as practicable.
4. Why we collect, use and disclose personal information
We collect, use and disclose personal information to:
- provide, manage and improve our services
- communicate with clients, suppliers and contractors, and manage those relationships
- invoice, process payments and keep financial records
- assess job applicants and engage contractors
- respond to enquiries, requests and complaints
- send marketing about our services, where permitted (see section 9)
- meet our legal, tax, audit and contractual obligations, including security vetting a client requires
We use and disclose personal information only for the purpose we collected it, a related purpose you would reasonably expect, with your consent, or where the law requires or allows it.
5. Information we handle for clients, including government agencies
When we build, host, maintain or support a website or system for a client, we may be able to access personal information held in it. In that role we act on the client’s behalf, and the client’s own privacy policy governs how that information is handled.
When we do this work, we:
- access and use the information only to deliver the services the client has engaged us for
- follow the client’s instructions and the privacy and security terms in our contract
- do not use it for our own purposes, including marketing
- limit access to personnel who need it, and remove access when they no longer do
- return or securely destroy it at the end of the engagement, as the contract requires
Australian Government agencies. Where we are a contracted service provider to an Australian Government agency, we comply with the APPs as if we were that agency, and with any privacy, security and data location requirements in the contract. We will not access, store or transfer agency data outside Australia without the agency’s prior approval. We will not do any act or engage in any practice that would breach an APP if the agency itself did it.
If a client asks us to handle personal information in a way that does not comply with the law, we will tell them and will not proceed.
6. Who we disclose personal information to
We may disclose personal information to:
- our employees and contractors, including team members located overseas (see section 7), where they need it to do their work
- service providers who help us run our business, such as cloud hosting, email, project management, accounting, payroll and IT support providers
- our professional advisers, such as accountants, lawyers and insurers
- a client, where the information relates to services we are delivering for them
- government agencies and regulators, where the law requires it or a client contract requires security vetting
- a prospective buyer or investor, if we are involved in a merger, acquisition or sale of assets, under confidentiality obligations
We require our service providers and contractors to protect personal information and to use it only for the services they provide to us.
We do not sell or rent personal information.
7. Disclosure outside Australia
We are likely to disclose personal information to recipients outside Australia. This happens in two ways.
- Our team. Some of our employees and contractors work from outside Australia, currently in India, the Philippines and Türkiye.
- Our service providers. Some of our cloud and software providers store or process data overseas, including in the United States and other countries where those providers operate.
Before disclosing personal information overseas, we take reasonable steps to make sure the recipient handles it consistently with the APPs. This includes contractual confidentiality and privacy obligations, access controls, and giving overseas team members access only to what they need.
This section does not apply to information we handle for Australian Government agencies. We will not send that information outside Australia, or allow it to be accessed from outside Australia, without the agency’s prior approval, whether or not our contract restricts offshore access (see section 5). For state, territory and local government clients, the offshore terms in our contract with them apply.
8. How we store and protect personal information
We hold personal information mainly in electronic form, in cloud-based systems. We take reasonable steps to protect it from misuse, interference, loss, and unauthorised access, change or disclosure. These steps include:
- multi-factor authentication and role-based access controls on our systems
- giving staff and contractors access only to the information they need
- confidentiality obligations in employment and contractor agreements
- encryption of data in transit, and reputable providers with recognised security certifications
We keep personal information only as long as we need it for the purposes in section 4, or as long as the law or a client contract requires. Business and financial records are generally kept for 7 years. After that, we take reasonable steps to destroy or de-identify the information.
9. Direct marketing, cookies and analytics
Marketing. We may send you information about our services if you have given us your contact details and would reasonably expect to hear from us, or you have consented. Every marketing email includes an unsubscribe link, or you can ask us to stop at any time using the contact details in section 12. We comply with the Spam Act 2003 (Cth). We never use sensitive information for marketing.
Cookies, analytics and advertising. Our website uses cookies and tags from Google Analytics, Google Ads and LinkedIn. Google Analytics helps us understand how visitors use the site so we can improve it. The Google Ads and LinkedIn tags measure how our advertising performs, and may be used to show our ads to people who have visited the site. These tools collect technical data such as IP address, device and browser type, and pages visited, and Google and LinkedIn may link it to an account you hold with them. Our forms also use Cloudflare Turnstile, which checks browser and device signals to block spam. You can control how Google uses this data for ads in My Ad Center, and opt out of LinkedIn retargeting in LinkedIn’s settings. You can also block or delete cookies in your browser settings, although some parts of the site may not work as intended.
10. Accessing and correcting your personal information
You can ask for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact our Privacy Officer using the details in section 12.
We will respond within 30 days. We may need to verify your identity first. Making a request is free. If giving you access means retrieving a large volume of information, we may charge a reasonable fee to cover that cost, and we will tell you before any fee applies.
If we refuse access or correction, we will tell you why in writing, and how to complain. If we don’t correct the information, you can ask us to attach a statement to it saying you believe it is incorrect.
For information we hold on behalf of a client (section 5), we will refer your request to that client, as they are responsible for it.
11. Data breaches
If we suspect a data breach, we act quickly to contain it and assess whether it is likely to cause serious harm. If it is an eligible data breach under the Notifiable Data Breaches scheme, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC).
If a breach involves information we hold for a client, we notify that client promptly and within any timeframe set in our contract, and we cooperate with their response.
12. Complaints, contact and changes to this policy
Complaints. If you think we have mishandled your personal information, contact our Privacy Officer in writing with details of your concern. We will acknowledge your complaint within 5 business days, investigate it, and give you a written response within 30 days.
If you are not satisfied with our response, you can complain to the OAIC:
- Website: oaic.gov.au
- Phone: 1300 363 992
Contact us.
Privacy Officer, Shakewell Agency Pty Ltd
Email: [email protected]
Post: 223/111 Harrington Street, The Rocks NSW 2000
Changes to this policy. We review this policy regularly and may update it. The current version is always published at shakewell.agency/privacy-policy, with its effective date at the top.