Legal

Comprehensive Privacy Policy

Governed by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and South Australian data governance standards. Last updated: April 2026.

1. About This Policy & Our Identity

10by10 Digital (ABN available upon request) is a digital marketing and web development agency operating from South Australia. We are bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) contained under Schedule 1 of that Act. This policy describes how we collect, use, hold, disclose, protect and give you access to your personal information.

This policy applies to all individuals who engage with our website, inquire about our services, or become clients. By using our website or services, you consent to the collection and use of your information as described here.


2. What Personal Information We Collect (APP 3)

We collect only the minimum personal information necessary to deliver our services. This includes:

  • Identity Information: Full name, job title, company name, ABN/ACN.
  • Contact Information: Email address, phone number, business address, billing address.
  • Financial Information: Invoice history and payment records processed through compliant third-party gateways (e.g., Stripe). We do not store full card details.
  • Technical Data: IP address, browser type, device type, time zone, operating system, and referring URLs collected via server logs and analytics tools.
  • Usage Data: Pages visited, time on site, click-through paths, and conversion events tracked via Google Analytics 4 and Meta Conversions API (CAPI).
  • Communication Records: Emails, contact form submissions, and notes from telephone or meeting engagements.

We collect personal information directly from you wherever practicable (APP 3.5). Where information is collected from third parties we take reasonable steps to notify you of this collection.


3. How We Use Your Information (APP 6)

We use your personal information for the primary purpose for which it was collected, or a related secondary purpose you would reasonably expect. These include:

  • Providing, managing, and delivering web development, SEO, GEO/AEO, digital marketing, and ecommerce services.
  • Processing payments and managing accounts receivable.
  • Communicating with you about your project, proposals, or account status.
  • Sending relevant marketing communications where you have consented (unsubscribe option always available).
  • Improving our website performance, user experience, and content relevance.
  • Meeting legal and regulatory obligations under South Australian and federal law.
  • Fraud prevention, security auditing, and internal business analytics.

4. Disclosure of Personal Information (APP 6)

We do not sell, rent, or trade your personal information. We may disclose your information to:

  • Service Providers: Cloud hosting providers (AWS, Google Cloud, Vercel), CRM systems, email platforms, payment processors, and analytics tools — all under strict data processing agreements.
  • Legal Authorities: Police, courts, the ATO, or other government agencies when required by law, court order, or regulatory demand.
  • Business Transfers: In the event of a merger, acquisition, or business sale, personal data may be transferred as a business asset, subject to equivalent privacy protections.
  • Your Consent: Any other disclosures will only occur with your explicit consent.

5. Cross-Border Data Transfers (APP 8)

Some of our service providers are located overseas (e.g., United States or European Union). Before any overseas transfer, we take reasonable steps to ensure the recipient is bound by enforceable privacy obligations substantially similar to the APPs. We may rely on contractual clauses, certification schemes, or adequacy determinations. By using our services, you acknowledge that data may be transferred and processed internationally under these protections.


6. Data Security & Storage (APP 11)

We take reasonable steps to protect your personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. Our security measures include:

  • TLS/SSL encryption on all web traffic.
  • Encrypted cloud storage hosted in ISO 27001-certified data centres.
  • Role-based access controls limiting access to authorised team members only.
  • Regular security assessments and software patching cycles.
  • Secure destruction or de-identification of records no longer required for any purpose.

7. Notifiable Data Breaches (NDB Scheme)

We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. If we become aware of a data breach that is likely to result in serious harm to any affected individual, we will notify the affected individual(s) and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. Our breach response plan includes immediate containment, risk assessment, notification, and remediation steps.


8. Direct Marketing (APP 7 & Spam Act 2003)

We may send you marketing communications if you have consented or if there is an existing client relationship (as permitted under the Spam Act 2003 (Cth)). All commercial electronic messages include a clear, functional unsubscribe mechanism. We will process opt-out requests within 5 business days. We do not use your information for unsolicited third-party advertising.


9. Anonymity & Pseudonymity (APP 2)

Where lawful and practicable, we give you the option to interact with us anonymously or using a pseudonym. You may browse our website without identifying yourself. However, for service delivery, contractual obligations, and invoicing, we require accurate identifying information.


10. Your Privacy Rights (APP 12 & 13)

As an individual whose personal information we hold, you have the right to:

  • Access (APP 12): Request access to the personal information we hold about you. We will respond within 30 days and provide the information in a readable format, free of charge in most cases.
  • Correction (APP 13): Request correction of inaccurate, outdated, incomplete, irrelevant or misleading personal information. We will action corrections promptly.
  • Deletion: Request deletion of your data where there is no legal obligation requiring its retention.
  • Complaint: Lodge a privacy complaint with us or directly with the OAIC.

To exercise any of these rights, please contact us via the Contact Page. We will acknowledge your request within 5 business days.


11. Cookies & Website Analytics

Our website uses cookies and tracking technologies. Please refer to our dedicated Cookies Policy for full details on what we collect, why, and how you can control these technologies.


12. Children's Privacy

Our services are not directed at individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us immediately and we will delete it without delay.


13. Policy Updates

We reserve the right to revise this Privacy Policy at any time to reflect changes in our practices, technology, legal requirements, or business operations. Updated versions will be published on this page with a revised "Last Updated" date. Continued use of our services after an update constitutes acceptance of the revised policy.


14. Complaints & Contact

If you have a concern or complaint about how we have handled your personal information, please contact us in the first instance via our Contact Page. We will investigate and respond within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992
  • GPO Box 5218, Sydney NSW 2001

Effective Date: April 2026  |  Jurisdiction: South Australia, Australia  |  Governing Law: Privacy Act 1988 (Cth), Australian Privacy Principles