Privacy Policy
Version 1.0, in force from 28 September 2026
Part A: privacy policy
1. Who we are and how to reach us
Agency Astro (ABN 63 157 710 910) is a digital, video and marketing agency in Townsville, Queensland. It is run by Agency Astro Pty Ltd (ACN 684 607 789) as trustee for the Agency Astro Trust (the trust established on 18 February 2025 as the Web Astro Trust). We make video and marketing work for businesses and hire out our studio and equipment. We are also building a client portal; section 14 covers it, and applies only once it launches.
This policy explains how we handle personal information across our business, including our website. It is our policy under Australian Privacy Principle (APP) 1.3, published at agencyastro.com/privacy. Our website privacy notice at agencyastro.com/privacy-policy adds website detail; if the two ever differ, this policy applies.
Privacy contact: the owner of Agency Astro, privacy@agencyastro.com, Level 1, 33-35 Palmer Street, South Townsville QLD 4810.
You can make a general enquiry without giving your name, or using a pseudonym, where that is practicable. We need your details for bookings, equipment hire, client work and billing, as each form explains.
2. We follow the Privacy Act
Agency Astro's annual turnover is under $3 million, so as a small business the Privacy Act 1988 does not currently apply to us by law (s 6D). We follow it anyway: we handle the personal information we hold in line with the Act and the Australian Privacy Principles (APPs), including telling people if a data breach puts them at risk (section 12). We may later opt in through the Office of the Australian Information Commissioner's (OAIC) Privacy Opt-In Register, which would make the Act apply to us by law. If we do, we will update this policy.
3. The kinds of personal information we hold (APP 1.4(a))
- Our clients' people: names, work email addresses, phone numbers and roles.
- Our clients' customers and enquirers, where a client asks us to handle them: names, contact details, enquiry details, call and email records, form responses and booking details. For a client that provides health services, an enquiry can include health information, which is sensitive information.
- Billing contacts: names, email addresses and invoice lines.
- People who appear in the work: faces, voices and names in photos, video and documents we produce for a client.
- Studio and equipment hire customers: names, contact details, company name and ABN, and, for equipment hire, date of birth and a note of the identity documents we sight (a licence number only if you used your licence). We do not keep copies of identity documents and we do not collect tax file numbers. We keep payment records, but never card numbers or card security codes. We record whether you asked to join our mailing list.
- Visitors to our website (agencyastro.com): what you type into the contact form (name, email, business, phone, the service you are interested in, how you heard about us and your message), the page you sent it from and how you first found our site; and, through cookies and similar tools, your device and browser details, IP address, approximate location, the pages you visit and how you use them, and how you interact with our ads. If you send us a form or become a customer, we may also share a scrambled (hashed) copy of your email address or phone number with ad platforms, to measure our ads (section 5).
- Our own team: names, contact details, time entries and work records.
Sensitive information. Where the law requires consent to collect sensitive information, such as health information, we collect it only with the person's consent and only where it is reasonably necessary for our work, unless a lawful exception applies. A client asking us to handle its enquiries does not by itself give that consent; the client's forms and notices must ask for it (Part B).
4. How we collect and hold it (APP 1.4(b))
We collect personal information directly: when you contact us, fill in a form, book a meeting, send us files, or apply to hire our studio or equipment. We also collect it indirectly: from our clients (for example a customer list they give us or an enquiry sent to their website), and through the email, calendar and call services a client asks us to use for it. A service that belongs to a client runs under the client's own privacy arrangements. Part B sets out our collection notices.
Where we hold it today: in Google Workspace (email, the agency's master Google Drive and Google Sheets), in Xero (accounting), in Stripe (card payments), and on our own editing computers in Townsville. Section 8 lists every service and where it is.
Our website. The contact form has a spam check (Cloudflare Turnstile). Your enquiry, including your message, is emailed to us through Resend and logged in our enquiry sheet in Google Sheets. We use, or may switch on at any time, these tracking tools on the site, mostly through Google Tag Manager: Google Analytics, Google Ads, the Meta Pixel, the LinkedIn Insight Tag, the TikTok Pixel, Microsoft Clarity and our own first-party analytics. Some of them also work from our server: the Meta, Google and LinkedIn conversion services, which receive a scrambled (hashed) copy of the email address or phone number you give us. These tools use cookies and similar technology to measure visits, to show our ads to people who have visited, to measure which ads lead to enquiries, and to record how pages are used (Clarity can replay a visit's clicks and scrolling). Section 8 lists each one, and we add any new tool to it by name. Section 5 explains how to opt out. Our search and monitoring tools (such as Google Search Console, Semrush and UptimeRobot) look at our website and search results, not at individual visitors.
5. Why we collect, hold, use and disclose it (APP 1.4(c))
- Client work: producing and reviewing content, getting approvals, delivering finished work, answering enquiries on a client's behalf, booking meetings, billing and reporting.
- Studio and equipment hire: confirming who you are before we lend equipment, taking payment, and recovering amounts owed or the cost of damage.
- Running the business safely: keeping our systems secure and meeting our legal obligations.
- Email marketing, only if you subscribe: news and specials by email. Every marketing email identifies Agency Astro, gives our contact details and has an unsubscribe that works for at least 30 days after we send it. We act on an unsubscribe within 5 working days.
- Advertising and ad measurement: the tracking tools in section 8 (Google Ads, the Meta Pixel, the LinkedIn Insight Tag and the TikTok Pixel) let us show our ads to people who have visited agencyastro.com and measure how the ads perform. Where you have given us your email address or phone number (for example in a form, or as a customer), we may send a scrambled (hashed) copy to Meta, Google or LinkedIn so they can match it to their own users and tell us which ads worked. The platforms cannot turn the scrambled copy back into your details, but they can match it to an account they already hold. To stop it:
- block or delete cookies in your browser;
- opt out of Google Analytics at tools.google.com/dlpage/gaoptout;
- change your ad settings in your Facebook or Instagram account, in Google's My Ad Center, in your LinkedIn advertising settings and in your TikTok ad settings;
- or email privacy@agencyastro.com and we will stop using your details for our advertising, including sending your scrambled email or phone to ad platforms.
We do not sell personal information.
6. AI assistants
We do not put personal information (names, contact details, enquiry details, faces or voices) into cloud AI assistants such as Claude or ChatGPT.
- A client may ask us in writing to let a cloud assistant work on its other material, such as scripts, drafts or plans. We do that only after a written check of the provider (its terms, whether it trains on the material, and where it processes it), which requires a business contract with the provider. A personal or consumer subscription does not pass. We record the client's request.
- Where we use AI on anything containing personal information, we use models that run on our own computers; nothing from them leaves our machines.
- A client's request never replaces any consent the law requires from the people concerned.
7. Client folders are shared by public link
The agency keeps every client's finished production files in its own master Google Drive, and shares each client's folder with that client by a public link. Anyone who has a folder's link can open that folder and every file in it without signing in, and we cannot reliably tell who has opened it. This is the owner's decision: the agency owns and manages that Drive itself.
The safeguards: only versions a person on our team has released go into a client's folder, and we replace a folder's link when a client leaves us, or straight away if we suspect the link has leaked. If you think a folder link has reached someone it should not have, tell us (section 1) and we will replace it.
8. Services that receive personal information, and where (APP 1.4(f) and (g), APP 8)
Before we disclose personal information to a recipient overseas, we take the reasonable steps APP 8 requires, and we remain accountable for how it handles that information (Privacy Act s 16C). Some services also use information for their own purposes under their own privacy policies: Google, Meta, LinkedIn and TikTok for advertising and measurement, and Stripe for fraud prevention.
| Service | What it receives | Where |
|---|---|---|
| Google Workspace (email, the master Drive, Sheets) | our email, every client's released production files (which can include personal information; shared with each client by public link, section 7), and website enquiries | Google's data centres, which include the United States, Europe and Asia; Google does not fix the country on our plan |
| Stripe, card payments | the card details you enter and the payment amount; we never see or store the full card number or security code | United States and other countries where Stripe operates |
| Xero, accounting | billing contacts, invoice lines and hire payment records | mainly the United States (Xero hosts on Amazon Web Services and copies data between data centres) |
| Resend, email delivery | website enquiries, including your message, and the emails we send through it | Japan and the United States |
| Google Analytics and Google Tag Manager (website) | device, browser, IP address, approximate location and site usage | United States and other countries where Google operates |
| Google Ads, including enhanced conversions (website and server) | device and browser details, site usage, ad interactions and, from our server, a hashed email address or phone number | United States and other countries where Google operates |
| Meta Pixel and Meta Conversions API (website and server) | device and browser details, site usage, ad interactions and, from our server, a hashed email address or phone number | United States |
| LinkedIn Insight Tag and LinkedIn Conversions API (website and server) | device and browser details, site usage, ad interactions and, from our server, a hashed email address | United States |
| TikTok Pixel (website) | device and browser details, site usage and ad interactions | Singapore, the United States and other countries where TikTok operates |
| Microsoft Clarity (website) | how pages are used, including recorded clicks and scrolling | United States |
| Vercel, website hosting | the website's traffic, including IP addresses | United States and Vercel's global network |
| Cloudflare Turnstile (website form spam check) | device and browser signals | Cloudflare's global network |
| Our own first-party analytics (website) | visits, pages viewed and how you first found our site, recorded by our own site | our own systems (section 4) |
| Claude (Anthropic) and ChatGPT (OpenAI), AI assistants | no personal information; only client material a client has asked for in writing (section 6) | United States |
Section 14 lists the further services the portal will use once it launches.
9. How we protect it (APP 11.1)
- Our Google Workspace, Xero and Stripe accounts use two-step sign-in.
- Only our team can open our records, and each person has only the access their work needs.
- We take card payments through Stripe and never write card details down.
- We sight identity documents without copying them.
- Anything with personal information that needs AI goes to models on our own computers (section 6).
10. How long we keep it (APP 11.2)
We keep personal information only while we need it or the law requires it, then delete or de-identify it. Once a year we do a clean-up and clear out what we no longer need.
| Kind of record | How long |
|---|---|
| Billing records, time entries, approvals and sign-offs | 7 years after the transaction or approval (tax law requires billing records for 5 years; we keep 7 to cover the time a claim can be made) |
| A client's customers and enquirers (contacts, enquiries, call and email records, form responses) | while we need them for the client's work; cleared in our yearly clean-up, and when the client leaves us |
| Website enquiries to Agency Astro | while we need them; cleared in our yearly clean-up |
| Finished production files | while the client stays with us and for as long as they are useful afterwards; reviewed in our yearly clean-up |
| Raw footage and project files | kept in our archive for as long as we have a use for them (re-edits, future work for the client and our portfolio). If you appear in footage and want it removed, ask us and we will consider it |
| Hire customers' identity check notes | while you hire from us; cleared in our yearly clean-up |
| Website analytics and recordings | as each tool keeps them: Google Analytics up to 14 months; Microsoft Clarity recordings about 30 days; Meta under its own policy |
A client can ask us to delete its records sooner, except for records the law requires us to keep.
11. Access, correction and complaints (APP 1.4(d) and (e))
Access and correction. You can ask to see the personal information we hold about you, or ask us to correct it. Contact us (section 1).
- We check who you are before we give you anything.
- We reply within 30 days.
- Asking is free, and so is a correction. For access, we may charge a reasonable cost of giving it to you, and we will tell you the amount first.
- If we refuse access or a correction, we tell you why in writing, and how to complain. The law allows a refusal only on limited grounds.
- If we do not agree to a correction, you can ask us to attach a statement saying you think the information is wrong, and we will.
- If we correct information we had given to someone else, you can ask us to tell them.
Deletion. You can also ask us to delete your information. We will, unless we need to keep it for the reasons in section 10, and we will tell you if so.
Complaints. If you have a complaint about how we handled your personal information, contact us first. We look into it, and reply within 30 days with what we found, anything we will do to fix it, and your options if you are not satisfied. If we need longer, we tell you why and when to expect our answer. If you are not satisfied, or we have not replied within 30 days, you can contact the OAIC: oaic.gov.au, 1300 363 992. Because the Act does not currently apply to us by law, the OAIC may not be able to investigate a complaint about us.
12. Data breaches
If we suspect a data breach, including one at a service in section 8, we contain it straight away and assess it promptly, finishing within 30 days. As soon as there are reasonable grounds to believe it is likely to cause serious harm, we tell the people affected and the client concerned as soon as practicable, without waiting for the 30 days to run out.
13. Changes to this policy
A change is a new version, approved by the owner and published at agencyastro.com/privacy with its version and date. Earlier versions stay available on request.
14. When our client portal launches
This section applies only once our client portal is live, and only to people who use it. We will update this policy with the date it starts.
- What the portal holds: portal accounts and sign-in records, comments, approvals, uploaded files, review videos and notes, and the client records a client asks us to move into it.
- Where: the portal's database and sign-in service (Supabase, Sydney); review videos in Cloudflare R2 (we ask for its Oceania region, but Cloudflare does not guarantee Australia, so they may be stored overseas); portal emails through Resend; error reporting and the portal itself on the agency's own machine in Townsville; an audit record archived in Sydney.
- Security: every team member and administrator signs in with a second factor; a session lasts at most 12 hours, with no sign-out after a short idle break; actions that involve money ask for the second factor again after 60 minutes (an administrator can switch this off, and the switch is recorded); each signed-in client sees only its own records; a tamper-evident audit record; backups with a tested restore.
- Client folders: the portal flags anything in a client's folder that nobody released, never stores or logs a folder's link, and reaches the Drive through one credential limited to the client-folders area.
- AI setting: each client's record carries its AI setting (section 6), off by default.
- Retention: portal account profiles 90 days after closure; security sign-in logs 12 months; comments and review videos while the client stays with us, then 90 days; the audit record 7 years; our copies of AI conversations, error traces and backups 30 days.
Part B: collection notices (APP 5)
We give these notices at or before the time we collect personal information, or, where that is not practicable, as soon as practicable afterwards. Where we collect for a client, the client may give its people the notice for us.
15. Short notices
On our website contact form:
Agency Astro collects these details to answer your enquiry. They are emailed to us (through Resend) and logged in our enquiry sheet (Google). We may send a scrambled (hashed) copy of your email or phone to Meta, Google or LinkedIn to measure our ads; email privacy@agencyastro.com to stop that. Optional fields can be left blank. See agencyastro.com/privacy.
On our website (footer or cookie notice):
We use cookies and tools from Google, Meta, LinkedIn, TikTok and Microsoft, and our own analytics, to measure visits and show our ads to people who have visited. See agencyastro.com/privacy to opt out.
On a form, booking or enquiry we run for a client:
Agency Astro collects these details on behalf of <client business> to answer your enquiry or booking, and shares them with <client business>. Fields marked optional can be left blank. See agencyastro.com/privacy.
A form that may collect health or other sensitive information also asks for the person's consent to that.
When we first contact someone whose details came from elsewhere:
Agency Astro got your details from <source: the client business, or the email, calendar or call service it asked us to use> because we work for <client business>. We use them to <purpose>. See agencyastro.com/privacy.
On the studio and equipment hire application:
Agency Astro collects your name, contact details, company and ABN, and, for equipment hire, your date of birth and identity details, to confirm who you are, take payment and recover any amount owed. We sight your identity documents and note what we checked; we do not keep copies. We never write down or store your card number or security code. We share your details with the services we use to run the hire (Stripe for payment, Xero for invoices, Google Workspace for our records) and, if we need to recover a debt, our lawyer or a collection agency. If you do not give us the identity details, we cannot hire equipment to you, but you can still hire the studio. Joining our mailing list is optional and does not affect your hire. See agencyastro.com/privacy.
Each form carries its own notice, reviewed with the form's version.
16. The matters APP 5 requires
- Who we are and how to contact us (APP 5.2(a)): section 1.
- How we collect it, and from whom (APP 5.2(b)): section 4. If we collect your details from someone else, the source is the client business we work for or a service that business asked us to use, and we name it in our first message to you or in the client's notice.
- Whether a law requires it (APP 5.2(c)): no Australian law requires us to collect this information, but tax law requires us to keep billing records for 5 years.
- Why (APP 5.2(d)): section 5.
- If you do not give it to us (APP 5.2(e)): we may not be able to answer your enquiry, book your meeting, hire equipment to you or, for a client, deliver or bill the work. You can make a general enquiry anonymously where practicable (section 1). Optional fields are marked.
- Who we usually give it to (APP 5.2(f)): the client business your information relates to; the services in section 8 (and section 14 once the portal launches); anyone who has a client folder's link (section 7); and, to recover a debt, our lawyer or a collection agency.
- Access, correction and complaints (APP 5.2(g) and (h)): section 11.
- Overseas (APP 5.2(i) and (j)): we are likely to send personal information to the United States (Google, Stripe, Xero, Resend, Meta, LinkedIn, TikTok, Microsoft, Vercel), Japan (Resend), Singapore (TikTok), and other countries where Google, Stripe, TikTok, Vercel and Cloudflare operate, which they do not fix (section 8). Once the portal launches, review videos may also be stored outside Australia (section 14).