01
Who this policy covers
This Privacy Policy explains how HATCH. Digital Marketing (HATCH., we, us or our), based in Tamworth NSW, handles personal information through our website, enquiries and digital marketing services.
We aim to manage personal information responsibly and in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. We follow the practical safeguards in this policy as part of the way we work with every client.
02
Information we may collect
Depending on how you work with us, we may collect:
- names, business details, contact details and enquiry information;
- project briefs, correspondence, approvals, contracts and meeting notes;
- billing details, invoices and payment transaction records;
- account identifiers, access invitations, credentials or tokens needed to deliver agreed work;
- content, images, video, customer lists, lead data, analytics and other information a client gives us access to;
- website usage information such as device, browser, referring page and approximate location where analytics tools collect it; and
- any other information you choose to provide.
If a client gives us personal information about its customers, staff or suppliers, the client is responsible for having the right to share that information and for giving any notices or obtaining any consents required for the agreed work.
03
Why we use information
We use personal information only where reasonably needed to:
- respond to enquiries, prepare proposals and manage client relationships;
- deliver websites, content, campaigns, advertising, training and related services;
- administer accounts, obtain approvals, issue invoices and process payments;
- operate, secure and improve our website and services;
- meet legal, tax, insurance and record-keeping obligations; and
- send marketing updates where you have consented or where the law otherwise permits, with an option to unsubscribe.
We do not sell client or customer personal information. We do not use confidential client data to market another business.
05
Security and payment details
We use reasonable technical and organisational safeguards suited to the information we handle. These may include access controls, multi-factor authentication, reputable service providers, secure transfer methods, software updates and limiting access to people who need the information for the work.
Credit and debit cards
HATCH. does not intentionally retain full card numbers, PINs or card security codes (CVV/CVC). Where a payment provider processes a card payment, that provider handles the card details under its own security and privacy terms. We may retain a receipt, invoice, transaction reference and limited card information such as the last four digits for reconciliation and legal records.
If full card details are sent to us by email, message or document, we will avoid copying them, use an approved payment method where needed, and securely delete the details as soon as they are no longer required. Card security codes are not retained after a transaction is authorised.
No system is completely secure. Please do not send passwords or full payment card details by ordinary email. We can arrange a safer handover method when sensitive access is genuinely required.
06
Client offboarding
What happens when our work together ends
When a project or ongoing engagement finishes, we separate what must be handed back, what should be deleted and what we are legally entitled or required to retain. Unless a contract, law or agreed transition plan requires something different, we will take the following steps promptly and normally within 30 days of the engagement ending:
- Return and transfer. We provide or transfer agreed final files, assets and account information, and reasonably assist the client to confirm its ownership and administrator access.
- Remove access. We remove HATCH. users, revoke active sessions, tokens and delegated permissions that we control, and ask the client or platform owner to remove any access that only they can revoke.
- Delete working data. We securely delete working copies that are no longer needed, including exported contact lists, lead or customer data, advertising audiences, unpublished content, temporary files and saved credentials held in our systems.
- Close payment access. Full card numbers and security codes are not retained. Any recurring payment authority or provider-held payment token that HATCH. controls will be cancelled or removed when no longer needed, subject to final charges authorised under the agreement.
- Limit retained records. We may retain contracts, invoices, transaction records, essential correspondence, approvals and evidence of work where reasonably needed for tax, legal, insurance, professional or dispute-resolution purposes. Australian business records are commonly required to be kept for five years. Retained records remain protected and are not used for unrelated purposes.
- Allow backups to cycle out. Residual copies may remain in encrypted or access-controlled backups for up to 90 days, or a provider’s standard backup cycle, before being overwritten. We will not restore or use those copies except for disaster recovery, security or legal reasons.
We may keep de-identified reporting or aggregated performance information that cannot reasonably identify an individual or reveal confidential client information. We only use a former client’s name, logo, testimonial or work as a case study where it is already public, permitted by our agreement or separately approved.
Clients should change passwords that were shared during the engagement and confirm the removal of HATCH. access from their own systems. A client can request written confirmation of our reasonable offboarding steps by emailing us. A request cannot require us to delete a record we must retain by law or reasonably need to establish or defend a legal claim.
07
Access, correction and deletion
You may ask what personal information we hold about you, request access to it, ask us to correct it, or ask us to delete information we no longer need. We may need to verify your identity and may refuse or limit a request where the law permits or requires us to do so. We will explain the reason where appropriate.
You can unsubscribe from marketing emails using the link in the message or by contacting us. Browser settings can also be used to manage cookies, although parts of a website may work differently if cookies are disabled.
08
Data incidents and breaches
If we become aware of a suspected data incident, we will take reasonable steps to contain it, assess what happened and reduce possible harm. Where the Notifiable Data Breaches scheme applies and an eligible data breach has occurred, we will notify affected people and the Office of the Australian Information Commissioner as required.
09
Questions or complaints
If you have a privacy question, want to make a request or believe we have mishandled personal information, contact us first so we can investigate and respond.
HATCH. Digital MarketingTamworth NSW 2340, Australiahello@hatchgroup.auIf you are not satisfied with our response and the Privacy Act applies, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.
We may update this policy when our services, systems or legal obligations change. The current version and its effective date will always appear on this page.