Privacy Policy

Last updated: 11 October 2026

Brandatize is a marketing agency based in Moreton Bay, Queensland. This policy explains what personal information we collect, why we collect it and what we do with it. We handle personal information in line with the Australian Privacy Principles (APPs).

In this policy, “we”, “us” and “our” mean Brandatize. “You” means anyone whose personal information we handle.

1. Who this policy covers

This policy applies to:

  • people who visit brandatize.com or our landing pages
  • people who contact us, book a call or join our email list
  • our clients and the people who work for them
  • people whose information a client asks us to handle as part of our work (see section 9)

2. The personal information we collect

The kinds of personal information we collect and hold are:

  • Contact details. Your name, email address, phone number, business name and role.
  • Enquiry and project information. Anything you tell us in a form, an email or a call. This includes recordings, transcripts and notes of video calls.
  • Billing information. Business and billing details, invoices and payment records. Stripe processes card payments, and we never see or store your full card number.
  • Website and advertising data. Your IP address, device and browser type, the pages you visit, how you found us and what you do on our pages. Cookies and pixels collect this (see section 6).
  • Email engagement. Whether you open our marketing emails and which links you click.

We don’t ask for sensitive information such as health details. If you include it in a message, we use it only to respond to you.

3. How we collect and hold it

Most of the time, you give us the information yourself. You might fill in a form on our website or landing pages, email us, book a time through Google Calendar or join a video call on Google Meet.

We also collect some information automatically through cookies, Google Analytics and the Meta Pixel when you visit our website or landing pages.

Sometimes we receive information from other people. A client may give us access to their customer data so we can run their marketing. We may also research public sources, such as published online reviews and business listings, as part of client work.

We hold personal information in the cloud services listed in section 7, and we protect it as described in section 10.

4. Why we collect, use and disclose it

We use personal information to:

  • respond to enquiries and book calls
  • deliver our services, including strategy, campaigns, content and reporting
  • invoice clients and keep financial and tax records
  • send marketing emails (see section 8)
  • measure how our website and ads perform, and show our ads to people who have visited our website or landing pages
  • meet our legal obligations

We disclose personal information to:

  • the service providers listed in section 7, so they can run the tools we use
  • contractors who help us deliver client work. They are bound by confidentiality and see only what they need for the account they work on
  • our accountant and other professional advisers
  • anyone else the law requires us to disclose it to

We don’t sell personal information. We only name a client or publish their results in a case study or testimonial with their permission.

5. Calls, transcripts and AI tools

We run client calls on Google Meet and use Gemini to transcribe and summarise them. We use these notes to deliver the work we’ve agreed to do.

We also use AI tools, including Anthropic’s Claude, to help us draft, research, analyse and summarise. Information you or a client give us may be processed by these tools when we use them for your work.

6. Cookies and tracking

Our website and landing pages use:

  • Google Analytics, which tells us how many people visit and what they look at.
  • The Meta Pixel, on our website, our landing pages and our GoHighLevel pages. It measures how our Facebook and Instagram ads perform and lets us show ads to people who have visited.

These tools set cookies and send data about your visit to Google and Meta.

You can opt out in a few ways:

  • Set your browser to block or delete cookies. Our website still works if you do.
  • Install Google’s opt-out add-on at tools.google.com/dlpage/gaoptout.
  • Change your ad settings in your Facebook or Instagram account to limit ads based on your activity on other websites.

7. Overseas disclosure

Some of the services we use store or process personal information outside Australia. They are:

SERVICEWHAT WE USE IT FORWHERE DATA IS LIKELY HELD
GoDaddyWebsite hosting, including contact form submissions stored in our WordPress databaseUnited States
CloudflareWebsite delivery and securityUnited States and other countries in Cloudflare’s network
Google Workspace (Gmail, Calendar, Meet, Gemini, Drive)Email, bookings, calls, filesUnited States and other countries where Google operates
Google AnalyticsWebsite measurementUnited States
Meta (Facebook, Instagram)Advertising and the Meta PixelUnited States and Ireland
GoHighLevelLanding pagesUnited States
Kit (ConvertKit)Email marketingUnited States
StripePaymentsUnited States
XeroAccountingUnited States
HnryInvoicing and taxNew Zealand and Australia
ClickUpProject managementUnited States
Anthropic (Claude)AI assistanceUnited States
ApifyResearch on public web dataUnited States and Czech Republic
ComposioConnecting our toolsUnited States

So we are likely to disclose personal information to recipients in the United States, Ireland, New Zealand and the Czech Republic. Some providers also use data centres in other countries. We choose established providers that publish their own privacy and security commitments.

8. Direct marketing

If you join our email list or become a client, we may send you emails about our services, articles and offers. We send these through Kit.

Every marketing email has an unsubscribe link. You can also email chris@brandatize.com and ask us to stop. We act on unsubscribe requests within five business days. After you unsubscribe, we keep your email address on a suppression list so we don’t contact you again.

9. When we handle a client’s customer data

Some clients give us access to information about their own customers. Examples include contacts in a client’s CRM, leads from their campaigns, and customer lists we upload to Meta to build advertising audiences for that client. Meta’s upload tool scrambles (hashes) these lists before matching them to accounts.

When we handle this information, we act as a service provider on that client’s behalf. We use it only to deliver the services that client has engaged us for, and the client’s own privacy policy governs it. The client is responsible for how they collected it and for their own systems, including their CRM.

If you are a customer of one of our clients and have a question about your information, contact that business first. If you contact us, we’ll pass your request to them.

10. Security

We take reasonable steps to protect personal information from misuse, loss and unauthorised access. These include:

  • multi-factor authentication on the accounts that hold personal information
  • access limited to the people working on the relevant account
  • using only software from established companies that publish their own privacy and security policies

No system is completely secure, and we can’t guarantee that information will never be accessed without permission.

11. Data breaches

If we suspect a data breach, we assess it promptly. Where required, we notify the people affected and the clients involved. If a breach involves a client’s data, we notify that client within 72 hours of becoming aware of it.

12. How long we keep information

We delete or return personal information we handle on a client’s behalf, such as their customer lists, leads and CRM records, within 60 days of an engagement ending, or sooner if the client asks us to, unless the law requires us to keep it.

We keep records of each engagement, including our correspondence and the contact details of the client’s staff, for 6 years after it ends. We keep invoices and financial records for as long as tax law requires.

We may keep our own research, working files and reference material about a client’s industry after an engagement ends. Before we do, we remove or de-identify any personal information in them, such as customers’ names, contact details, reviews and call recordings, and we keep the material confidential.

13. Accessing and correcting your information

You can ask for a copy of the personal information we hold about you, and ask us to correct anything that is wrong, out of date or incomplete. Email chris@brandatize.com.

We’ll check your identity before we release anything. We aim to respond within 30 days. We don’t charge for access requests.

If we refuse a request, we’ll tell you why in writing and explain how to complain. If we don’t agree to correct something, you can ask us to keep a note with the information saying you believe it’s wrong.

14. Complaints

If you think we’ve mishandled your personal information, email chris@brandatize.com with the details. We’ll acknowledge your complaint within 7 days, look into it and give you a written response within 30 days.

15. Automated decisions

We don’t use computer programs to make decisions that significantly affect individuals. Advertising platforms such as Meta and Google use their own automated systems to decide which ads people see. Those systems belong to the platforms, and their privacy policies cover them.

16. Dealing with us anonymously

You can browse our website without telling us who you are, and you can make a general enquiry under a different name. If we work together, we’ll need your real details to deliver the work and invoice you.

17. Changes to this policy

We’ll update this policy when our practices change. The date at the top shows when we last changed it.

18. Contact

Chris Dawal, Brandatize Moreton Bay, Queensland chris@brandatize.com