H.
Work
Services

What we do

01Digital marketing↗02Website design↗03Shopify web design↗04Social media marketing↗05Practical AI↗06UGC creation & coaching↗07Drone photo & video↗08Meta Business Suite setup↗
View all services overview
AboutJournal
Services

What we do

01Digital marketing↗02Website design↗03Shopify web design↗04Social media marketing↗05Practical AI↗06UGC creation & coaching↗07Drone photo & video↗08Meta Business Suite setup↗
View all services overview
Get in touch

Privacy · Data · Trust

Privacy,plainly put.

What we collect, why we need it, how we protect it and what happens to client information when our work together ends.

Effective 17 August 2026Last updated 17 August 2026
PRIVATE

On this page

01Scope02What we collect03How we use it04Sharing & storage05Security & payments06When our work ends07Your choices08Data breaches09Contact us

01

Who this policy covers

This Privacy Policy explains how HATCH. Digital Marketing (HATCH., we, us or our), based in Tamworth NSW, handles personal information through our website, enquiries and digital marketing services.

We aim to manage personal information responsibly and in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. We follow the practical safeguards in this policy as part of the way we work with every client.

02

Information we may collect

Depending on how you work with us, we may collect:

  • names, business details, contact details and enquiry information;
  • project briefs, correspondence, approvals, contracts and meeting notes;
  • billing details, invoices and payment transaction records;
  • account identifiers, access invitations, credentials or tokens needed to deliver agreed work;
  • content, images, video, customer lists, lead data, analytics and other information a client gives us access to;
  • website usage information such as device, browser, referring page and approximate location where analytics tools collect it; and
  • any other information you choose to provide.

If a client gives us personal information about its customers, staff or suppliers, the client is responsible for having the right to share that information and for giving any notices or obtaining any consents required for the agreed work.

03

Why we use information

We use personal information only where reasonably needed to:

  • respond to enquiries, prepare proposals and manage client relationships;
  • deliver websites, content, campaigns, advertising, training and related services;
  • administer accounts, obtain approvals, issue invoices and process payments;
  • operate, secure and improve our website and services;
  • meet legal, tax, insurance and record-keeping obligations; and
  • send marketing updates where you have consented or where the law otherwise permits, with an option to unsubscribe.

We do not sell client or customer personal information. We do not use confidential client data to market another business.

04

Sharing and storage

We may share information with service providers that help us run HATCH. or deliver the work, such as website hosting, cloud storage, email, accounting, project management, analytics, advertising and payment platforms. We limit access to what is reasonably needed and expect providers to protect the information they handle.

Some providers, including major digital and social platforms, may process or store information outside Australia. Their locations and privacy practices can change, so we encourage you to review the relevant provider’s privacy terms when your project uses that service.

We may also disclose information where you direct or authorise us, where required by law, or where reasonably necessary to protect a person, our rights or the security of our services.

05

Security and payment details

We use reasonable technical and organisational safeguards suited to the information we handle. These may include access controls, multi-factor authentication, reputable service providers, secure transfer methods, software updates and limiting access to people who need the information for the work.

Credit and debit cards

HATCH. does not intentionally retain full card numbers, PINs or card security codes (CVV/CVC). Where a payment provider processes a card payment, that provider handles the card details under its own security and privacy terms. We may retain a receipt, invoice, transaction reference and limited card information such as the last four digits for reconciliation and legal records.

If full card details are sent to us by email, message or document, we will avoid copying them, use an approved payment method where needed, and securely delete the details as soon as they are no longer required. Card security codes are not retained after a transaction is authorised.

No system is completely secure. Please do not send passwords or full payment card details by ordinary email. We can arrange a safer handover method when sensitive access is genuinely required.

06

Client offboarding

What happens when our work together ends

When a project or ongoing engagement finishes, we separate what must be handed back, what should be deleted and what we are legally entitled or required to retain. Unless a contract, law or agreed transition plan requires something different, we will take the following steps promptly and normally within 30 days of the engagement ending:

  1. Return and transfer. We provide or transfer agreed final files, assets and account information, and reasonably assist the client to confirm its ownership and administrator access.
  2. Remove access. We remove HATCH. users, revoke active sessions, tokens and delegated permissions that we control, and ask the client or platform owner to remove any access that only they can revoke.
  3. Delete working data. We securely delete working copies that are no longer needed, including exported contact lists, lead or customer data, advertising audiences, unpublished content, temporary files and saved credentials held in our systems.
  4. Close payment access. Full card numbers and security codes are not retained. Any recurring payment authority or provider-held payment token that HATCH. controls will be cancelled or removed when no longer needed, subject to final charges authorised under the agreement.
  5. Limit retained records. We may retain contracts, invoices, transaction records, essential correspondence, approvals and evidence of work where reasonably needed for tax, legal, insurance, professional or dispute-resolution purposes. Australian business records are commonly required to be kept for five years. Retained records remain protected and are not used for unrelated purposes.
  6. Allow backups to cycle out. Residual copies may remain in encrypted or access-controlled backups for up to 90 days, or a provider’s standard backup cycle, before being overwritten. We will not restore or use those copies except for disaster recovery, security or legal reasons.

We may keep de-identified reporting or aggregated performance information that cannot reasonably identify an individual or reveal confidential client information. We only use a former client’s name, logo, testimonial or work as a case study where it is already public, permitted by our agreement or separately approved.

Clients should change passwords that were shared during the engagement and confirm the removal of HATCH. access from their own systems. A client can request written confirmation of our reasonable offboarding steps by emailing us. A request cannot require us to delete a record we must retain by law or reasonably need to establish or defend a legal claim.

07

Access, correction and deletion

You may ask what personal information we hold about you, request access to it, ask us to correct it, or ask us to delete information we no longer need. We may need to verify your identity and may refuse or limit a request where the law permits or requires us to do so. We will explain the reason where appropriate.

You can unsubscribe from marketing emails using the link in the message or by contacting us. Browser settings can also be used to manage cookies, although parts of a website may work differently if cookies are disabled.

08

Data incidents and breaches

If we become aware of a suspected data incident, we will take reasonable steps to contain it, assess what happened and reduce possible harm. Where the Notifiable Data Breaches scheme applies and an eligible data breach has occurred, we will notify affected people and the Office of the Australian Information Commissioner as required.

09

Questions or complaints

If you have a privacy question, want to make a request or believe we have mishandled personal information, contact us first so we can investigate and respond.

HATCH. Digital MarketingTamworth NSW 2340, Australiahello@hatchgroup.au

If you are not satisfied with our response and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.

We may update this policy when our services, systems or legal obligations change. The current version and its effective date will always appear on this page.

H.
Tamworth NSW 2340
hello@hatchgroup.au
PrivacyTermsInstagramFacebook