Privacy Policy
Who we are
This policy explains how SHARP Marketing Group Pty Ltd (ABN [ABN]), referred to here as Sharp, we or us, handles personal information.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable.
What this policy covers
Two different things happen under the Sharp name, and they are worth separating:
- This website. What we collect when you browse sharp.com.au, which is very little. Covered in sections 3 to 6.
- Our services. Information we handle on behalf of client businesses when we run their advertising, websites and follow-up systems. Covered in section 7.
Booking a call takes you to a separate page at sharp-co.ai.studio. What that page collects is described in section 6.
What this website collects
Server logs
This site is hosted on Google Cloud Run. Like any web server, it records a log entry for each request containing your IP address, the page requested, the time, your browser's user-agent string and the referring page. An IP address can be personal information. We use these logs to keep the site running and to investigate faults or abuse. They are not used to build a profile of you.
Stored in your browser
This site sets no cookies. It uses two small browser storage entries instead, neither of which is sent to us automatically:
sharp:acq |
Session storage. Holds campaign parameters from the link you arrived on, so that if you book a call we can tell which advertisement brought you. Deleted when you close the tab. Explained further in section 4. |
|---|---|
theme |
Local storage, on the dashboard demo only. Remembers whether you chose light or dark mode. Contains no information about you. |
What we do not do here
At the date above, this website runs no analytics, no advertising pixels, no tag manager and no third-party trackers. It loads no fonts, scripts or images from other companies' servers. There are no forms on this site. If that changes, we will update this policy and the date at the top of it.
Advertising parameters and click identifiers
If you reach this site from an advertisement, the link usually carries parameters identifying the campaign. We read and pass on the following, and only these:
- Campaign tags:
utm_source,utm_medium,utm_campaign,utm_term,utm_content,utm_id - Click identifiers:
gclid,gbraid,wbraid(Google),fbclid(Meta),msclkid(Microsoft),ttclid(TikTok)
These are held in your browser for the length of your visit and added to the booking link if you click through. Their purpose is to attribute an enquiry to the advertisement that produced it. The click identifiers are generated by the advertising platforms, and those platforms may use them to connect your enquiry to your interaction with an ad on their systems, under their own privacy policies.
How we use website information
We use the information described above to:
- deliver and secure the website;
- understand which advertising produces enquiries, so we do not waste client budget on campaigns that do not work;
- respond to you if you contact us.
We do not sell personal information. We do not use it for automated decision-making that produces a legal or similarly significant effect on you.
Booking a call
The booking buttons take you to sharp-co.ai.studio/aplicar, where you may provide your name, contact details and information about your business. We use that to contact you, assess whether we can help, and prepare for the call.
If you telephone us, we may keep a record of the call and what was discussed. We do not record calls without telling you first.
[Confirm which scheduling or CRM provider operates that page, and list it here as a disclosure recipient, including whether it stores data outside Australia.]
Information we handle for client businesses
When a business engages us, we work inside systems that hold personal information about their customers and enquirers: advertising accounts, website form submissions, call and SMS records, and CRM records. This can include names, phone numbers, email addresses, service addresses and the details of a job someone is asking about.
In that work the client business decides what is collected and why; we act on their instructions. We use that information only to provide the services they have engaged us for. We do not use one client's data to benefit another, and we do not use it for our own marketing.
Where we set up automated SMS or email follow-up, the client business is responsible for having a lawful basis to contact those people, including consent and a functioning unsubscribe under the Spam Act 2003 (Cth). We will configure systems to support that, but we cannot supply the consent.
[If you offer a data processing agreement to clients, reference it here.]
Who we disclose information to
We disclose personal information to:
- Advertising platforms such as Google and Meta, in the course of running campaigns and reporting conversions;
- Infrastructure and software providers we use to run the site and deliver services, including Google Cloud for hosting;
- Professional advisers such as accountants and lawyers, where needed;
- Anyone else where you have consented, or where we are required or authorised by law.
[List your actual sub-processors: scheduler, CRM, email and SMS providers, call tracking, reporting tools.]
Overseas disclosure
Some of these providers store or process information outside Australia, including in the United States. Google Cloud, Google Ads and Meta all operate internationally. Under APP 8 we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs, but you should be aware that overseas laws may differ from Australian law.
[Confirm the Cloud Run region. If it is australia-southeast1, say that website hosting and logs stay in Australia, which is a genuine advantage worth stating.]
Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. This site is served over HTTPS. Access to client advertising and CRM systems is limited to the people who need it.
No method of transmission or storage is completely secure. If we suffer a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.
How long we keep information
We keep personal information only as long as we need it for the purpose it was collected, or as long as the law requires. Server logs are kept for [retention period]. Enquiry and client records are kept for [retention period]. When information is no longer needed and we are not required to keep it, we destroy or de-identify it.
Accessing and correcting your information
You can ask us what personal information we hold about you and request access to it, and you can ask us to correct anything inaccurate, out of date or incomplete. Contact us using the details in section 14.
We will respond within a reasonable time, normally within 30 days. If we refuse access or correction we will tell you why in writing, and how to complain about that decision. We may need to verify your identity first.
If your information sits inside a client business's systems rather than ours, we will point you to that business, since it controls that data.
Complaints
If you think we have mishandled your personal information, contact us first using the details below and we will investigate.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
Changes to this policy
We may update this policy as our services or systems change. The current version is always at this address, with the effective date at the top. Material changes will be flagged on this page.
Contact us
Privacy enquiries: [privacy@yourdomain]
Phone: [phone]
Post: [registered address]