About this Privacy Policy
Cloak Digital (“we”, “us”, “our”) is a partnership operating under ABN 27 479 651 610. This Privacy Policy explains how we collect, use, store and disclose personal information when you:
- visit our website (www.cloakdigital.com.au)
- contact us, request a quote, or purchase services
- use any software, portals, dashboards, websites or platforms we build or provide (including SaaS/subscription software)
To the extent we are required to comply with the Privacy Act 1988 (Cth) (including the Australian Privacy Principles and the Notifiable Data Breaches scheme), we will do so.
What is “personal information”?
Personal information is information about an identified individual, or an individual who is reasonably identifiable.
When you can deal with us anonymously
Where practicable, you can browse our website without identifying yourself. If you contact us, request a quote, sign up for a service, or use a platform login, we will need certain information to provide services.
What personal information we collect
4.1Information you provide to us
We may collect personal information when you enquire, request a quote, buy services, subscribe, or communicate with us. This may include:
- name, email address, phone number, and address (if provided)
- business name and business details (including ABN/ACN where provided)
- project requirements, briefs, content you provide, brand assets, and communications
- account details you create for our platforms (e.g., login email/username)
- billing information (invoice details, payment status, transaction references)
- any other information you choose to provide
Payments: We may use third-party payment processors to process card payments/subscriptions. We do not store full card details on our systems.
4.2Information we collect automatically (website + platforms)
When you use our website or any platform we operate, we may collect:
- IP address
- device and browser information (type, version, OS)
- pages/screens viewed, timestamps, referring pages, clicks and interactions
- security and diagnostic logs (for example, access logs, error logs)
4.3Information we receive from others
We may receive personal information from:
- your team members or representatives
- third-party services you choose to connect to our work (depending on what you enable)
- our clients where we build/host/maintain systems that contain end-user data (see section 12)
How we collect personal information
We collect personal information through:
- website contact forms and enquiry channels
- emails, phone calls, SMS, and other communications
- proposals/scopes and onboarding documentation
- account sign-ups/logins for platforms we build or provide
- project delivery tools (where used)
- billing/invoicing/payment systems
Why we collect and use personal information
We use personal information to:
- provide and deliver our services and support
- communicate with you, respond to enquiries, and manage projects
- set up and administer accounts for websites, portals, dashboards or SaaS
- issue invoices, process payments, manage subscriptions, and address non-payment (including suspension where applicable)
- maintain security, prevent fraud, and protect our systems
- improve our services, workflows, and customer experience
- comply with legal obligations and enforce our agreements
- send service and administrative communications
- send marketing communications where permitted (see section 10)
When we disclose personal information
We do not sell personal information.
We may disclose personal information to third parties where reasonably necessary to operate our business and deliver services, including:
- payment and billing providers (to process payments and manage subscriptions)
- hosting, cloud infrastructure and storage providers (to host websites/apps, store files, run backups, and deliver content)
- domain/DNS and technical service providers (where we configure domains/DNS on your behalf)
- email and communications providers (to send emails and service notices)
- support and operations tools (e.g., helpdesk, document storage, collaboration tools)
- analytics tools (only if/when enabled — see section 9)
- professional advisers (accountants, insurers, legal advisers)
- contractors/subcontractors we engage to perform work (under confidentiality obligations)
- law enforcement/regulators/courts where required or authorised by law
We only disclose the information that is reasonably necessary for the purpose.
Where your information is stored (Australia + overseas)
8.1Australia (current setup)
We currently host key production systems and databases in Australia (Sydney) where applicable, including cloud database and application infrastructure configured for Sydney-region operation.
8.2Overseas processing/storage may still occur
Some information may be stored or processed outside Australia depending on the service used, including:
- personal Google accounts (e.g., Gmail/Drive) which may store/process data in multiple countries
- some hosting providers (parts of hosting, backups, or support operations may be located in Australia and/or overseas, including the United States)
- email delivery, content delivery networks, and software tools that may route or process data via overseas servers
- future tools you enable (e.g., CRM systems, analytics platforms, advertising platforms)
Where practicable, we take reasonable steps to ensure overseas recipients handle personal information appropriately.
Cookies, analytics, and advertising
9.1Cookies (website functionality)
We may use cookies and similar technologies that support basic website functionality and performance (for example, session handling, security, and load balancing).
You can control cookies through your browser settings. Disabling cookies may affect some parts of the website.
9.2Analytics and ad tracking (current status + future)
Currently: We do not use Google Analytics, Meta Pixel, or advertising conversion tracking on our website.
Future: If we enable analytics or advertising tools (for example Google Analytics, Google Ads conversion tracking, Meta Pixel), we will update this Privacy Policy and, where required, provide appropriate notice/choices.
Marketing communications
We may send marketing communications where permitted by law. You can opt out at any time by using the unsubscribe function (where available) or contacting us.
Even if you opt out of marketing, we may still send important administrative or service-related communications.
Security
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. This may include:
- access controls and least-privilege practices
- authentication controls (including MFA where available)
- encryption in transit where supported (e.g., HTTPS)
- logging/monitoring and backups
- internal process controls and confidentiality obligations for contractors
No system is completely secure. If a security incident occurs, we will take reasonable steps to investigate and reduce harm. Where the Notifiable Data Breaches scheme applies and an eligible data breach occurs, we will handle notifications in line with legal requirements.
Client projects and end-user data (where we act as a service provider)
Some services involve handling personal information that belongs to our clients (for example, a client's customers, staff, or end users) where we build/host/maintain systems or provide SaaS.
In those cases:
- the client controls what is collected and how it is used, and is responsible for providing notices/obtaining consents from their end users; and
- we handle that data to provide and maintain the services (including hosting, security, support, backups, and data export where applicable).
AI tools
We may use AI tools to assist with producing some deliverables (for example drafts of copy, code suggestions, design ideation, or assisting with media creation).
We take reasonable steps not to input sensitive personal information or confidential client information into publicly available AI tools where doing so is not necessary to provide the services.
If you require that no AI tools be used for your project, you must notify us in writing before work begins (this may affect pricing, timelines, or feasibility).
Data retention
We retain personal information only for as long as necessary to fulfil the purposes outlined in this policy, including legal, accounting, dispute resolution, enforcement, and security needs.
Examples:
- SaaS/subscription platform data: If a SaaS subscription is cancelled/terminated, you may request a data export within 30 days, and we may retain account data for up to 90 days before deleting or de-identifying it (subject to legal requirements, dispute handling, and backups).
- Business records: We may retain invoices and business records for legally required periods.
Backups may persist for a limited time after deletion in accordance with our backup procedures.
Access and correction
You can request access to, or correction of, personal information we hold about you by contacting us (see section 18). We may need to verify your identity before responding. We will respond within a reasonable timeframe in accordance with applicable law.
Complaints
If you have a privacy complaint, please contact us first and we will try to resolve it. If you are not satisfied, you may be able to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Children
Our services are not directed to children, and we do not knowingly collect personal information from children without appropriate consent. If you believe a child has provided us personal information, contact us and we will take reasonable steps to remove it.
Contact us
Email: cloakdigital.co@gmail.com Phone: +61 451 206 027 / +61 497 734 448 Location: Perth, Western Australia
Changes to this Privacy Policy
We may update this Privacy Policy from time to time. We will post the updated policy on our website and update the “Last updated” date.