Skip to content
Fixed Point Labs
Legal

Privacy Policy

How this site collects, uses, stores and discloses personal information, and how to access, correct or complain about it.

Effective
1 September 2026
Entity
Clayton Ty Waldock
Trading as
Fixed Point Labs
ABN
69 950 878 375
Contact
clayton@fixedpointlabs.com.au

Who this policy covers

This policy explains how Clayton Ty Waldock (ABN 69 950 878 375), trading as Fixed Point Labs ("we", "us", "our"), handles personal information collected through https://fixedpointlabs.com.au and in the course of providing web design, development, hosting and maintenance services.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). "Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable.

What we collect

We only collect personal information that is reasonably necessary for our business. In practice, that is:

  • Enquiry details — your name, email address, business name, the type of project you're after, your indicative budget range, and anything you choose to write in the message field of our contact form.
  • Client and billing details — the contact, billing and business details we need to quote, invoice and deliver a project, including your ABN where applicable.
  • Project material you give us — logos, copy, images, credentials for services we need to configure, and any content you ask us to publish on your site.
  • Technical information — our hosting provider records server logs including IP address, browser type and the pages requested, for security and reliability purposes.

How we collect it

We collect personal information directly from you: through the contact form on this site, by email or phone, and during the course of a project. We do not buy contact lists and we do not scrape personal information from third parties.

You can deal with us anonymously or under a pseudonym for a general enquiry, but we will not be able to quote, contract or invoice without your real details.

Why we collect it and how we use it

We use personal information to:

  • Respond to your enquiry and prepare a quote or proposal.
  • Deliver, host, support and maintain the services you have engaged us for.
  • Issue invoices, take payment and keep the financial records the law requires us to keep.
  • Communicate with you about a live project or an active care plan.
  • Meet our legal and tax obligations.

We do not use your information for any unrelated purpose without your consent, unless we are permitted or required to by law.

Direct marketing

If you contact us about a project, we will reply to you about that project — that is the reason you got in touch.

We will only send you marketing or promotional messages if you have asked us to, and every such message will identify us and include a working unsubscribe option, as required by the Spam Act 2003 (Cth). You can opt out at any time by using the unsubscribe link or by emailing us, and we will action it promptly.

Who we disclose it to

We do not sell personal information. We disclose it only where it is necessary to run the business, and only to:

  • Service providers who operate the infrastructure behind this site and our client work — currently Vercel (hosting) and Resend (contact-form email delivery).
  • Professional advisers such as our accountant or lawyer, where reasonably required.
  • Anyone else you have authorised, or where disclosure is required or permitted by law.

If we sell or transfer the business

If all or part of the business is sold, merged, restructured or otherwise transferred, your personal information may be disclosed to and used by the incoming owner for the same purposes described in this policy, and this policy continues to apply to it.

Where reasonably practicable, we will notify affected clients of a change in ownership. Before any sale completes, we will only share personal information with a prospective buyer during due diligence where they have agreed to keep it confidential and use it solely to evaluate the transaction.

Health information on client projects

Some of the sites we build collect health information — a gym intake form, a physiotherapy booking, a clinic's patient enquiry. We do not collect that information for our own purposes. We handle it only as required to build, host or support the client's site, on that client's instructions.

Where we hold or have access to health information in New South Wales, we handle it in accordance with the Health Privacy Principles in the Health Records and Information Privacy Act 2002 (NSW), in addition to the Australian Privacy Principles.

If you are a client engaging us to build something that will collect health information, tell us during discovery. It changes how the forms, storage and access controls need to be built, and we will put a written data-handling arrangement in place before any of it goes live.

Work for NSW government agencies and councils

If we are engaged by a NSW government agency or a local council, we may be bound by the Privacy and Personal Information Protection Act 1998 (NSW) as a contracted service provider. Where that applies, we comply with the Information Protection Principles and with the agency's own privacy management plan for the duration of the engagement.

Overseas disclosure

Some of the providers we rely on store or process data outside Australia, currently the United States (Vercel and Resend).

Before disclosing personal information to an overseas recipient we take reasonable steps to satisfy ourselves that the recipient handles it in a way consistent with the Australian Privacy Principles, as required by APP 8.

Cookies and analytics

This site sets no cookies at all. It uses no analytics, no advertising and no cross-site tracking, so nothing about your visit is recorded beyond the server logs described above.

If analytics are added later, this section will be updated before they go live to name the tool, say what it records and how long that is kept, and — for anything that is not strictly necessary — explain how to refuse it.

Your browser can be configured to refuse cookies. Doing so will not stop this site from working.

How we store and protect it

Personal information is held in access-controlled systems operated by us and by the providers listed above, protected by encryption in transit, multi-factor authentication and least-privilege access.

No system is perfectly secure. If we suffer a data breach that is likely to result in serious harm, we will assess it and, where the Notifiable Data Breaches scheme applies, notify you and the Office of the Australian Information Commissioner as soon as practicable.

We keep personal information only while we have a business or legal reason to. Financial records are kept for at least five years as required by the ATO; enquiry records that do not become projects are deleted once they are no longer useful.

Accessing and correcting your information

You can ask us for a copy of the personal information we hold about you, and ask us to correct anything that is inaccurate, out of date or incomplete. Email clayton@fixedpointlabs.com.au and we will respond within 30 days.

We do not charge for making a request. If we refuse access or correction we will tell you why in writing and explain how to complain.

Complaints

If you think we have mishandled your personal information, email clayton@fixedpointlabs.com.au with the details. We will acknowledge your complaint within five business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you can escalate the complaint to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001.

Complaints about health information held in New South Wales, or about a NSW government agency or council engagement, can instead be made to the Information and Privacy Commission NSW at ipc.nsw.gov.au or by phone on 1800 472 679.

Third-party links

This site links to other websites. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their policies before providing them with personal information.

Changes to this policy

We may update this policy from time to time. The current version is always published on this page, and the effective date above tells you when it last changed.