Your privacy

Privacy Policy

This policy explains what personal information DesignEpic collects, why we use it, who we may share it with and the choices available to you.

Last updated: 14 August 2026 Applies to our website, enquiries, bookings and services

Privacy in plain language

We collect only the information reasonably needed to operate our website, respond to you and deliver our services. We do not sell personal information. Where practical, you may contact us anonymously or using a pseudonym.

01

Scope and commitments

This Privacy Policy describes how DesignEpic manages personal information when you visit our website, contact us, book a meeting, become a client, work with us as a supplier or otherwise interact with our business.

We aim to handle personal information consistently with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other privacy laws that apply to our activities. Some services may also be governed by a proposal, confidentiality agreement, data-processing terms or our Terms of Service .

“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable. This policy does not apply to information that has been effectively de-identified.

02

Information we collect

The information we collect depends on how you interact with us and may include:

  • Identity and contact details: name, organisation, role, email address, phone number and business address.
  • Enquiry and booking details: the information you enter into contact or booking forms, meeting preferences, messages and correspondence.
  • Client and project information: proposals, instructions, feedback, content, access details, support requests and information contained in systems or materials made available for a project.
  • Commercial and transaction information: service selections, contracts, invoice details, payment status and business records. Payments may be processed by a payment provider; we do not intend to retain complete payment-card details.
  • Website and technical information: IP address, browser and device information, approximate location, referring page, pages viewed, interaction events, timestamps and cookie identifiers.
  • Marketing preferences: subscriptions, consent records, campaign interactions and opt-out requests.
  • Supplier or recruitment information: professional history, qualifications, references, tax or payment details and other information needed to assess or manage the relationship.

We do not ordinarily seek sensitive information. Please do not provide it unless it is reasonably necessary and we have asked for it or the law otherwise permits its collection.

03

How we collect and hold information

We usually collect personal information directly from you when you complete a form, schedule a meeting through our booking page, send an email, speak with us, sign a proposal, use our services or interact with our website.

We may also collect information from:

  • your employer, colleagues or authorised representatives;
  • referrals, project partners and service providers involved in an engagement;
  • publicly available business sources and professional profiles;
  • website analytics, security tools, cookies and similar technologies; and
  • third-party platforms you authorise us to access for a project.

Information may be held in business systems operated by us or trusted providers, including website hosting, booking, email, cloud storage, project management, customer relationship management, accounting and security systems.

Choices when contacting us: where lawful and practical, you may interact with us anonymously or using a pseudonym. We may need your identity and accurate contact details to provide a quote, enter a contract, process payment, secure systems or deliver requested services.
04

How we use personal information

We collect, hold, use and disclose personal information for purposes reasonably connected with our business, including to:

  • respond to enquiries, arrange meetings and prepare proposals;
  • verify instructions and manage client, supplier and professional relationships;
  • design, deliver, support and improve our services and project outcomes;
  • administer accounts, invoices, payments, records and contractual obligations;
  • communicate service information, project updates and support notices;
  • operate, personalise, measure, troubleshoot and secure our website and systems;
  • conduct internal planning, quality assurance, analysis and reporting;
  • send marketing where we have consent or are otherwise permitted to do so;
  • manage disputes, protect our rights and prevent fraud, abuse or security incidents; and
  • meet legal, regulatory, insurance, tax and record-keeping obligations.

We may create aggregated or de-identified insights for business analysis and service improvement. We do not currently use personal information to make solely automated decisions that could reasonably be expected to significantly affect a person’s rights or interests. If this practice changes, we will update this policy and provide any additional information required by law.

05

Website data, cookies and analytics

Our website and service providers may use cookies, pixels, local storage, server logs and similar technologies to keep the site functioning, remember preferences, understand site use, measure performance and protect against malicious activity.

  • Essential technologies support security, forms, bookings and core website functions.
  • Preference technologies remember choices that improve your experience.
  • Analytics technologies help us understand aggregated traffic and how visitors use the website.

You can manage many cookies through your browser settings and, where available, our cookie controls. Blocking some technologies may affect form, booking or website functionality. Third-party content or links may be governed by the privacy practices of their providers.

06

Who we disclose information to

We may disclose personal information where reasonably necessary for the purposes described in this policy to:

  • personnel, contractors and professional advisers who need the information and are subject to appropriate obligations;
  • technology providers supporting hosting, bookings, communications, analytics, security, storage, project delivery and customer management;
  • payment, accounting, banking and debt-recovery providers;
  • delivery partners and suppliers involved in an agreed client project;
  • a potential purchaser, investor or adviser in connection with a genuine business transaction, subject to confidentiality protections;
  • regulators, courts, law-enforcement bodies or other parties where required or authorised by law; and
  • other recipients where you direct us or give valid consent.

We do not sell personal information or disclose it to third parties for their independent direct marketing. Service providers may process information for us only for authorised purposes and under their applicable contractual and privacy obligations.

07

Overseas storage and disclosure

DesignEpic serves clients across the APAC region and uses online service providers whose personnel, infrastructure or subprocessors may be located outside Australia. Depending on the provider and project configuration, likely locations may include Australia, New Zealand, Singapore, the United States, the United Kingdom and member states of the European Economic Area.

Before disclosing personal information to an overseas recipient, we take reasonable steps appropriate to the circumstances, such as reviewing privacy and security terms, limiting the information shared and using contractual controls. We may also rely on an exception permitted by law. Overseas privacy protections and enforcement rights may differ from those available in Australia.

Project-specific locations: if a client selects or requires a particular hosting region, platform or overseas delivery partner, additional locations may apply. Relevant arrangements should be recorded in the proposal or project documentation where practicable.
08

Direct marketing and your choices

We may send relevant news, insights or service information when you have consented or when the communication is otherwise permitted by law and reasonably expected in the context of our relationship.

  • Marketing communications will identify DesignEpic and provide a simple way to unsubscribe.
  • You may opt out at any time by using the unsubscribe method in the message or contacting us.
  • We will process an opt-out request within the period required by law and do not charge for it.
  • Even after you opt out of marketing, we may send non-promotional messages needed to deliver services, manage an account or meet legal obligations.

We do not use sensitive information for direct marketing unless valid consent and applicable law permit it.

09

Personal information in client projects

When delivering website, CRM, automation, analytics, reporting, support or work-management services, we may access personal information that a client controls. In those circumstances, the client generally decides why and how that information is handled, while DesignEpic handles it only as needed to provide the agreed services and follow lawful instructions.

  • Clients are responsible for ensuring they have appropriate authority, notices and consents for the information they provide or make accessible.
  • We apply access restrictions and confidentiality obligations appropriate to the engagement.
  • We do not use client-controlled personal information for our own marketing or unrelated purposes.
  • Requests from individuals about client-controlled information may be referred to the relevant client unless we are legally required to respond directly.

Project-specific security, retention, deletion or data-location requirements should be documented in the proposal or a separate data-processing agreement.

10

Security, retention and data incidents

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, multi-factor authentication, encryption in transit, backups, software maintenance, provider reviews and limiting access to people who need it.

No internet transmission or storage method is completely secure. If we become aware of a suspected data incident, we will contain and assess it, take reasonable remediation steps and notify affected individuals and regulators where required by applicable law, including the Notifiable Data Breaches scheme.

We retain personal information only for as long as reasonably necessary for the purposes in this policy, the engagement, dispute management and legal or professional record-keeping. Retention periods vary by record type, contractual requirement and provider capability. When information is no longer required, we take reasonable steps to delete, destroy or de-identify it, subject to lawful backups and required records.

11

Access, correction and privacy choices

You may ask to access personal information we hold about you or request that inaccurate, out-of-date, incomplete, irrelevant or misleading information be corrected. You may also ask about your marketing preferences or raise a concern about how information is used.

  • Send your request to our Privacy Contact using the details below and describe the information or correction sought.
  • We may take reasonable steps to verify your identity and authority before acting.
  • We will respond within a reasonable period and will not charge for making a request. Where permitted, reasonable access costs may apply after advance notice.
  • Access or correction may be refused where the law allows or requires it. If so, we will generally explain the reason and available complaint options.

Some information may also be updated directly in the relevant account or third-party platform. Requests concerning information controlled by one of our clients should be directed to that client.

12

Complaints, contact and policy updates

If you have a privacy question, want another accessible copy of this policy or believe we have mishandled personal information, contact us with enough detail to investigate.

Privacy Contact DesignEpic
Brisbane, Queensland, Australia
Email hello@designepic.com.au
Subject: Privacy request

We will acknowledge a complaint, investigate fairly and aim to provide a response within 30 days. If you are not satisfied with our response, or we do not respond within 30 days, you may be able to complain to the Office of the Australian Information Commissioner .

We may update this policy when our practices, services or legal obligations change. The latest version will be published on this page with a revised “Last updated” date. If a change materially affects how we handle information already collected, we will provide additional notice where reasonably practicable or required by law.

Questions about your data?

Talk to DesignEpic.

Ask about the information we hold, request a correction or raise a privacy concern.

Contact our privacy team

Important updates waiting for you!

Practical ideas for connected customer journeys, digital systems and better work across APAC.