What we collect, why we collect it, who sees it, and what you can ask us to do about it. Written to be read, not to be skimmed past.
First Touch Studio (ABN 27 059 706 024) is a creative marketing studio based in Brisbane, working with clients across Queensland, the ACT and nationally. In this policy, "we" and "us" mean First Touch Studio.
We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where we work for a government agency, we also work to the privacy obligations that agency is subject to, which are often stricter than our own.
When you contact us or work with us, we collect what you give us: your name, email address, phone number, the business you work for, and whatever you tell us about what you need. That is it. We do not ask for more than we need to answer you properly.
When you visit this website, our hosting and analytics tools record technical information such as your IP address, browser and device type, the pages you visit and how long you stay. This is standard for any website and is not used to identify you personally.
During a client engagement, we may receive material that contains personal information belonging to other people, for example customer lists, community feedback or contact databases. We treat that material as yours, not ours, and section 5 sets out specific limits on what we do with it.
We do not collect sensitive information as defined by the Privacy Act, including health, biometric, racial or ethnic, political, religious or sexual orientation information. If a client engagement would require it, we discuss that with you first and document why.
To reply to your enquiry, to scope and deliver work, to send you things you have asked for, to invoice you, to keep our own records, and to meet legal obligations such as tax and record keeping.
We send marketing emails only to people who have asked for them. Every one has an unsubscribe link that works immediately. We do not add enquiry contacts to a mailing list because they contacted us once.
We do not sell, rent or trade personal information. Not to anyone, for any price.
This site uses cookies to keep it working properly and to understand how people use it, so we can make it better. Our cookie policy sets out which cookies are set, what each one does and how long it lasts.
You can block or delete cookies through your browser settings at any time. Essential cookies keep the site functioning, so blocking those may break parts of it.
We use AI tools in our work, and we are specific about what they are allowed to touch. Personal information, official information, commercial-in-confidence material, unpublished consultation submissions and anything marked confidential are not entered into AI tools.
Our full position, including the tools we use, the terms they operate under and what we will provide to an auditor, is published separately.
Service providers who help us run the business, such as website hosting, email, file storage, accounting and project management. They only get what they need to do their job, and they are bound by their own privacy obligations.
Subcontractors we bring in for specialist work on your project, who are bound by written agreement before they touch anything of yours.
Legal or regulatory authorities, where the law requires it.
That is the complete list. We do not share your information with anyone else, and we do not pass your details to other clients or partners as introductions unless you have asked us to.
Some of the tools we use to run the business store data outside Australia. That is normal for cloud software and applies to most Australian businesses. Where it happens, we use providers with recognised data protection standards and contractual protections.
We do not transfer client, community or citizen information provided to us during an engagement offshore without your written approval. If a piece of work would require it, we raise it with you before it happens, not after.
Enquiries that do not turn into work are kept for 30 days and then deleted. Client records are kept for the life of the engagement and then for as long as our legal and tax obligations require, which is generally seven years. Material you provide for a specific project is returned or deleted at the end of the engagement if you ask us to.
Material we deliver to a government agency may become a public record, and we treat it accordingly from the outset.
We use access controls, multi-factor authentication, reputable business tier software and encrypted storage. Access to client material is limited to the people working on that engagement.
No system is perfectly secure and we will not claim otherwise. If a breach occurs that affects your information, we will tell you promptly and in writing, and where it is a notifiable data breach we will meet our obligations under the scheme and support you in meeting yours.
You can ask us what personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it where we are not legally required to keep it, and withdraw consent to marketing at any time.
Email us and we will respond within thirty days. There is no charge, and you do not need to explain why you are asking.
If you think we have mishandled your personal information, tell us first. Email hello@firsttouchstudio.com.au with the detail and we will investigate and respond in writing within thirty days.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. You do not need our permission to do that, and we will not treat you differently for doing it.
We update this policy when our practices or the law change. The current version is always here with the date it was last updated. Material changes will be flagged on the site rather than made quietly.
First Touch Studio, ABN 27 059 706 024
hello@firsttouchstudio.com.au · 02 6190 7977
Brisbane, Queensland