Privacy Policy
Last updated: 11 October 2026
Brandatize is a marketing agency based in Moreton Bay, Queensland. This policy explains what personal information we collect, why we collect it and what we do with it. We handle personal information in line with the Australian Privacy Principles (APPs).
In this policy, “we”, “us” and “our” mean Brandatize. “You” means anyone whose personal information we handle.
1. Who this policy covers
This policy applies to:
- people who visit brandatize.com or our landing pages
- people who contact us, book a call or join our email list
- our clients and the people who work for them
- people whose information a client asks us to handle as part of our work (see section 9)
2. The personal information we collect
The kinds of personal information we collect and hold are:
- Contact details. Your name, email address, phone number, business name and role.
- Enquiry and project information. Anything you tell us in a form, an email or a call. This includes recordings, transcripts and notes of video calls.
- Billing information. Business and billing details, invoices and payment records. Stripe processes card payments, and we never see or store your full card number.
- Website and advertising data. Your IP address, device and browser type, the pages you visit, how you found us and what you do on our pages. Cookies and pixels collect this (see section 6).
- Email engagement. Whether you open our marketing emails and which links you click.
We don’t ask for sensitive information such as health details. If you include it in a message, we use it only to respond to you.
3. How we collect and hold it
Most of the time, you give us the information yourself. You might fill in a form on our website or landing pages, email us, book a time through Google Calendar or join a video call on Google Meet.
We also collect some information automatically through cookies, Google Analytics and the Meta Pixel when you visit our website or landing pages.
Sometimes we receive information from other people. A client may give us access to their customer data so we can run their marketing. We may also research public sources, such as published online reviews and business listings, as part of client work.
We hold personal information in the cloud services listed in section 7, and we protect it as described in section 10.
4. Why we collect, use and disclose it
We use personal information to:
- respond to enquiries and book calls
- deliver our services, including strategy, campaigns, content and reporting
- invoice clients and keep financial and tax records
- send marketing emails (see section 8)
- measure how our website and ads perform, and show our ads to people who have visited our website or landing pages
- meet our legal obligations
We disclose personal information to:
- the service providers listed in section 7, so they can run the tools we use
- contractors who help us deliver client work. They are bound by confidentiality and see only what they need for the account they work on
- our accountant and other professional advisers
- anyone else the law requires us to disclose it to
We don’t sell personal information. We only name a client or publish their results in a case study or testimonial with their permission.
5. Calls, transcripts and AI tools
We run client calls on Google Meet and use Gemini to transcribe and summarise them. We use these notes to deliver the work we’ve agreed to do.
We also use AI tools, including Anthropic’s Claude, to help us draft, research, analyse and summarise. Information you or a client give us may be processed by these tools when we use them for your work.
6. Cookies and tracking
Our website and landing pages use:
- Google Analytics, which tells us how many people visit and what they look at.
- The Meta Pixel, on our website, our landing pages and our GoHighLevel pages. It measures how our Facebook and Instagram ads perform and lets us show ads to people who have visited.
These tools set cookies and send data about your visit to Google and Meta.
You can opt out in a few ways:
- Set your browser to block or delete cookies. Our website still works if you do.
- Install Google’s opt-out add-on at tools.google.com/dlpage/gaoptout.
- Change your ad settings in your Facebook or Instagram account to limit ads based on your activity on other websites.
7. Overseas disclosure
Some of the services we use store or process personal information outside Australia. They are:
| SERVICE | WHAT WE USE IT FOR | WHERE DATA IS LIKELY HELD |
|---|---|---|
| GoDaddy | Website hosting, including contact form submissions stored in our WordPress database | United States |
| Cloudflare | Website delivery and security | United States and other countries in Cloudflare’s network |
| Google Workspace (Gmail, Calendar, Meet, Gemini, Drive) | Email, bookings, calls, files | United States and other countries where Google operates |
| Google Analytics | Website measurement | United States |
| Meta (Facebook, Instagram) | Advertising and the Meta Pixel | United States and Ireland |
| GoHighLevel | Landing pages | United States |
| Kit (ConvertKit) | Email marketing | United States |
| Stripe | Payments | United States |
| Xero | Accounting | United States |
| Hnry | Invoicing and tax | New Zealand and Australia |
| ClickUp | Project management | United States |
| Anthropic (Claude) | AI assistance | United States |
| Apify | Research on public web data | United States and Czech Republic |
| Composio | Connecting our tools | United States |
So we are likely to disclose personal information to recipients in the United States, Ireland, New Zealand and the Czech Republic. Some providers also use data centres in other countries. We choose established providers that publish their own privacy and security commitments.
8. Direct marketing
If you join our email list or become a client, we may send you emails about our services, articles and offers. We send these through Kit.
Every marketing email has an unsubscribe link. You can also email chris@brandatize.com and ask us to stop. We act on unsubscribe requests within five business days. After you unsubscribe, we keep your email address on a suppression list so we don’t contact you again.
9. When we handle a client’s customer data
Some clients give us access to information about their own customers. Examples include contacts in a client’s CRM, leads from their campaigns, and customer lists we upload to Meta to build advertising audiences for that client. Meta’s upload tool scrambles (hashes) these lists before matching them to accounts.
When we handle this information, we act as a service provider on that client’s behalf. We use it only to deliver the services that client has engaged us for, and the client’s own privacy policy governs it. The client is responsible for how they collected it and for their own systems, including their CRM.
If you are a customer of one of our clients and have a question about your information, contact that business first. If you contact us, we’ll pass your request to them.
10. Security
We take reasonable steps to protect personal information from misuse, loss and unauthorised access. These include:
- multi-factor authentication on the accounts that hold personal information
- access limited to the people working on the relevant account
- using only software from established companies that publish their own privacy and security policies
No system is completely secure, and we can’t guarantee that information will never be accessed without permission.
11. Data breaches
If we suspect a data breach, we assess it promptly. Where required, we notify the people affected and the clients involved. If a breach involves a client’s data, we notify that client within 72 hours of becoming aware of it.
12. How long we keep information
We delete or return personal information we handle on a client’s behalf, such as their customer lists, leads and CRM records, within 60 days of an engagement ending, or sooner if the client asks us to, unless the law requires us to keep it.
We keep records of each engagement, including our correspondence and the contact details of the client’s staff, for 6 years after it ends. We keep invoices and financial records for as long as tax law requires.
We may keep our own research, working files and reference material about a client’s industry after an engagement ends. Before we do, we remove or de-identify any personal information in them, such as customers’ names, contact details, reviews and call recordings, and we keep the material confidential.
13. Accessing and correcting your information
You can ask for a copy of the personal information we hold about you, and ask us to correct anything that is wrong, out of date or incomplete. Email chris@brandatize.com.
We’ll check your identity before we release anything. We aim to respond within 30 days. We don’t charge for access requests.
If we refuse a request, we’ll tell you why in writing and explain how to complain. If we don’t agree to correct something, you can ask us to keep a note with the information saying you believe it’s wrong.
14. Complaints
If you think we’ve mishandled your personal information, email chris@brandatize.com with the details. We’ll acknowledge your complaint within 7 days, look into it and give you a written response within 30 days.
15. Automated decisions
We don’t use computer programs to make decisions that significantly affect individuals. Advertising platforms such as Meta and Google use their own automated systems to decide which ads people see. Those systems belong to the platforms, and their privacy policies cover them.
16. Dealing with us anonymously
You can browse our website without telling us who you are, and you can make a general enquiry under a different name. If we work together, we’ll need your real details to deliver the work and invoice you.
17. Changes to this policy
We’ll update this policy when our practices change. The date at the top shows when we last changed it.
18. Contact
Chris Dawal, Brandatize Moreton Bay, Queensland chris@brandatize.com