Privacy Policy
Last updated: Version 2026-06-23-v5
Privacy Policy
Last updated: 23 June 2026
This Privacy Policy explains how True North Innovations Pty Ltd (ABN 34 677 383 149) ("TNI", "we", "us" or "our") collects, uses, discloses and protects personal information.
Contact:
- General enquiries: info@truenorthinnovations.com.au
- Accounts and billing: accounts@truenorthinnovations.com.au
- Phone: 03 4158 4444
1. Who this policy applies to
This policy applies to personal information we handle about:
- website visitors;
- people who contact us;
- prospective clients;
- clients and their staff;
- suppliers and contractors;
- individuals who submit forms or enquiries through websites, landing pages or digital channels we create, host, manage or support for clients;
- people who interact with campaigns, advertising, analytics, CRM or automation systems that we manage or support; and
- other people we deal with in the course of our business.
2. Our role
For our own website, enquiries, client management, billing and business operations, we usually collect and handle personal information for our own business purposes.
For client websites, lead forms, advertising, analytics, CRM and marketing systems, our client is usually the business collecting information from its own customers, leads or website visitors. In those cases, we handle information as a service provider so we can deliver marketing, reporting, CRM, automation and related services.
3. Personal information we collect
We may collect:
- name;
- email address;
- phone number;
- business name;
- job title;
- postal or business address;
- enquiry details;
- messages, form submissions and support requests;
- billing and payment records;
- Stripe customer, subscription, payment and invoice references;
- website usage data;
- IP address, device, browser and user-agent information;
- advertising, analytics and attribution data;
- CRM and lead-status information;
- business account access details where required to provide services;
- records of acceptance of terms, privacy notices, service agreements and direct debit authorities;
- call, email or meeting notes connected with the Services; and
- information contained in client-provided content or systems.
We do not intentionally store full bank account details on our own systems. Bank account details for BECS Direct Debit are collected and processed by Stripe.
4. Lead and enquiry data
If we create, host, manage, support, optimise or report on your website, landing pages, forms, advertising campaigns, CRM or digital channels, we may access lead and enquiry data generated through those channels.
We use this information only for purposes connected with the Services, including:
- responding to enquiries where authorised;
- sending enquiries to the client;
- checking lead quality;
- monitoring spam or irrelevant enquiries;
- attribution and source tracking;
- campaign optimisation;
- conversion tracking;
- CRM workflow;
- reporting;
- troubleshooting forms, tracking and integrations;
- improving the performance of services we provide to the client; and
- meeting legal, accounting or record-keeping requirements.
We do not sell, rent or trade lead data.
We do not use a client's lead data to market unrelated TNI services to those leads unless the individual has separately consented or the law permits it.
5. Sensitive information
Sensitive information includes health information, racial or ethnic origin, political opinions, religious beliefs, philosophical beliefs, union membership, sexual orientation, biometric information and criminal record information.
We do not ask clients to collect sensitive information through general website forms unless it is genuinely required, lawful and agreed in writing.
If sensitive information is accidentally submitted to us or to a system we manage, we may delete, de-identify or restrict access to it unless it is necessary and lawful to keep it.
6. How we collect information
We may collect information:
- when you contact us by form, email, phone, SMS, meeting, social media or other communication;
- when you request a quote;
- when you accept a proposal or sign up for a plan;
- when you provide access to business systems;
- through Stripe, our website forms, analytics and automation systems;
- from third-party platforms you authorise us to manage or access;
- from your website, landing pages, campaigns, CRM or digital channels where we provide services;
- from public business sources where relevant to our services; and
- from contractors, staff or service providers involved in delivering services.
7. Why we use information
We use personal information to:
- respond to enquiries;
- provide quotes and proposals;
- onboard clients;
- deliver digital marketing, website, CRM, AI, reporting and related services;
- process payments and manage subscriptions;
- issue invoices and keep business records;
- manage direct debit authorisations;
- provide support;
- monitor and improve service quality;
- check lead quality and campaign performance;
- manage advertising, SEO, analytics, website, CRM and automation work;
- communicate about service matters;
- meet legal, tax, accounting and compliance obligations;
- protect our systems, clients, staff and business;
- investigate suspected fraud, misuse, spam, security issues or payment issues; and
- send marketing communications where permitted.
8. Marketing communications
We may send marketing emails or messages only where we have consent or are otherwise permitted by law.
Marketing messages will identify us and include a way to unsubscribe where required.
A person can unsubscribe from marketing messages at any time.
Service, billing, invoice, payment, support, direct debit, security and contract-related messages are not treated as marketing where they are sent to provide or administer services.
9. Who we disclose information to
We may disclose personal information to:
- staff, contractors and subcontractors who help deliver services;
- Stripe and payment processors;
- our customer, billing and accounting systems;
- website hosting providers;
- email and SMTP providers;
- analytics and tracking providers;
- Google, Meta and other advertising or analytics platforms where needed for the Services;
- call tracking, form, booking, chat, automation or reporting tools;
- AI, automation or productivity tools where appropriate and reasonably necessary;
- IT, security, backup and support providers;
- professional advisers such as accountants, lawyers, insurers and brokers;
- government, regulators or law enforcement where required or permitted by law; and
- another party where you have authorised the disclosure.
We require service providers to handle information appropriately and use it only for the purpose of providing services to us or to our clients.
10. Overseas disclosure
Some service providers may store or process information outside Australia.
Likely service provider categories include hosting and cloud infrastructure, email and SMTP, CRM and ERP systems, analytics and tracking, advertising platforms, call tracking and form tools, payment processors, AI-assisted productivity and reporting tools, security, backup and support tools, and professional advisers.
Likely overseas processing locations may include Australia, the United States, the European Union, the United Kingdom, Singapore and other locations used by the relevant provider.
Where overseas disclosure occurs, we take reasonable steps to protect personal information, such as using reputable providers, contractual protections, access controls, security settings, data minimisation and limiting disclosure to what is reasonably required.
11. Cookies, analytics and tracking
Our website and client websites we support may use cookies, pixels, tags, scripts, analytics tools, advertising tools or similar technologies.
These may be used to make the website work, measure traffic, attribute enquiries, improve advertising, detect spam and support reporting.
You can usually control cookies through your browser settings. Some features may not work properly if cookies are disabled.
12. Security
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.
These steps may include access controls, password management, multi-factor authentication where available, limiting access, secure hosting, encryption where appropriate, logging, backups, confidentiality obligations and secure payment processing through Stripe.
No internet, email, cloud or payment system can be guaranteed to be completely secure.
We will not intentionally submit sensitive information, bank account details, passwords or unnecessary personal information into AI tools. Where AI-assisted tools are used, we will use minimised, de-identified or business-level information where practical.
13. Data retention
We keep personal information only for as long as reasonably needed for service delivery, support, reporting, legal, accounting, tax, insurance, dispute, audit and business record purposes.
We may keep invoices, payment records, contract and acceptance records, lead/campaign/reporting data, and de-identified or aggregated analytics and reporting data.
When information is no longer needed, we will take reasonable steps to destroy or de-identify it.
14. Access and correction
You may ask us to provide access to personal information we hold about you or to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading.
We may need to verify your identity before responding. Some exceptions may apply.
If information is held on behalf of one of our clients, we may refer your request to that client or coordinate with them.
15. Data breaches
If we become aware of unauthorised access, unauthorised disclosure or loss of personal information, we will assess the situation and take reasonable steps to contain and remediate the issue.
Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, affected individuals and the Office of the Australian Information Commissioner may need to be notified.
Where we handle information for a client, we will notify the client without undue delay after becoming aware of an actual or suspected eligible data breach affecting their data and reasonably assist with assessment and response.
16. Client privacy responsibilities
Clients are responsible for their own privacy compliance and collection notices for their websites, landing pages, forms, advertising, CRM, booking systems and customer communications.
Clients must ensure individuals are told, where required, that their information may be disclosed to service providers such as digital marketing agencies, website developers, hosting providers, CRM providers, analytics providers, advertising platforms, payment providers and other relevant suppliers.
17. Complaints
If you have a privacy concern, contact us first so we can try to resolve it.
Email: info@truenorthinnovations.com.au
Phone: 03 4158 4444
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
18. Changes to this policy
We may update this Privacy Policy from time to time.
The current version will be available on our website.
19. Contact
True North Innovations Pty Ltd
ABN: 34 677 383 149
Email: info@truenorthinnovations.com.au
Phone: 03 4158 4444