Legal

Privacy policy.

How Shockwave Media Pty Ltd (ABN 26 606 414 493) handles personal information — in plain English.

Last updated: 8 October 2026 · Consistent with our Privacy Policy v1.0 (October 2026).

The short version

  • We collect only what we need to reply to you and run our business — mainly what you type into our enquiry form.
  • We don’t sell personal information, and this website sets no advertising or tracking cookies.
  • For NSW and Australian Government work, client systems and data are hosted in Australia and handled by Australian-based staff.
  • We never use client data for our own purposes, including training AI models for us or anyone else.
  • You can ask to see or correct your information, or make a complaint, through our enquiry form.

We manage personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). When we work for NSW public sector agencies, we also follow the NSW privacy laws their contracts require. Our Managing Director is our privacy officer.

What we collect

When you send an enquiry: your name, work email, organisation, the topic you choose, an optional timeframe and your message. The form also asks you to confirm consent.

When you visit the website: our web server records standard technical information such as your IP address, browser type and the pages requested, in server logs. To stop spam, our server also keeps a one-way (hashed) form of your IP address to limit repeated submissions, and deletes it within 30 days of your last submission.

When you work with us: business contact details and correspondence for clients and suppliers; and, for job applicants, staff and contractors, the information needed for recruitment and employment.

We don’t ask for sensitive information (such as health details), so please don’t include it in your message. Where practical, you can deal with us without giving your name or by using a pseudonym, although we will need a way to reply.

How we use it

  • To respond to your enquiry and arrange a consultation.
  • To prepare proposals, tender responses or agreements you’ve asked for, and to deliver our services.
  • To manage client, supplier and staff relationships and meet our legal obligations.
  • To keep our website and systems secure, including preventing spam and abuse.

We send marketing only where the law allows, and every message includes a way to opt out.

Who we share it with

Enquiries from this website are delivered by email through our business email provider, Google Workspace. We also use service providers and software tools that help us run our business, under confidentiality and security obligations. We otherwise disclose personal information only with your consent or where the law requires or authorises it.

Where it’s stored

For NSW and Australian Government engagements, the client systems and data we build, host or support, including backups, are hosted in Australia, and the work is delivered by Australian-based staff. We don’t store or process that data outside Australia unless the client agrees in writing.

We handle client data in line with Australian regulations, and client data relating to Australians is kept on Australian servers.

Our business email runs on Google Workspace, whose data centres may be located outside Australia.

Security & retention

We protect personal information with the controls in our Information Security Policy, including access control, multi-factor authentication, encryption, logging and staff training. When we no longer need information, we destroy or de-identify it, subject to legal and contractual record-keeping requirements. We keep enquiry emails for up to 2 years and server logs for up to 90 days, then delete them.

Cookies & analytics

This website sets no advertising or tracking cookies, and it loads no third-party scripts, fonts or embeds. The only information it keeps for spam prevention is the hashed IP address described above.

AI systems we build

When we build, host or support systems for clients, we handle any personal information in them only on the client’s instructions and for that engagement. We don’t use client data, including government data, for any purpose of our own, including training AI models for ourselves or other clients. We train or fine-tune a model on a client’s data only when that client engages us to, and only for that client. The client stays responsible for its own privacy obligations to the people concerned, and we help it meet them. We don’t use personal information to make automated decisions that significantly affect people in our own business.

Data breaches

We assess any suspected data breach promptly, within 30 days at most. If it is an eligible data breach under the Notifiable Data Breaches scheme, we notify the people affected and the Office of the Australian Information Commissioner (OAIC). If a breach involves a client’s data, we tell the client within 24 hours of becoming aware of it.

Access & correction

You can ask to see or correct the personal information we hold about you through our enquiry form. We’ll confirm your identity and respond within 30 days. If we refuse, we’ll explain why in writing and tell you how to complain. If we hold the information for a client, we’ll pass your request to that client and help them respond.

Complaints

If you have a privacy concern, tell us through the enquiry form. Our Managing Director will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you’re not satisfied, you can complain to the OAIC at oaic.gov.au. If your complaint is about information we handle for a NSW public sector agency, you can also contact that agency or the NSW Information and Privacy Commission at ipc.nsw.gov.au.

Changes & full policy

We review our privacy practices every year and when privacy law changes. The current version is always on this page. Our full Privacy Policy, which also covers staff, suppliers and client data, is available as a PDF on our policies page.