Limited: Free $2,500 growth audit for the next 8 businesses — claim yours →
Legal

Privacy Policy

This policy explains how Whitehat Agency handles your personal information across our website and our client portal, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Last updated: 15 July 2026

1. About this policy

Whitehat Agency is a Sydney-based digital marketing agency providing SEO, Google Ads, Meta Ads, web design and development, and AI services. Whitehat Agency is operated by 484 Digital Pty Ltd (ABN 81 651 974 006) (“Whitehat”, “we”, “us” or “our”). We respect your privacy and are committed to protecting your personal information.

This policy explains how we collect, use, hold and disclose personal information, and how we comply with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). It applies to:

  • Our public website at whitehatagency.com.au;
  • Our client portal at portal.whitehatagency.com.au (where engaged clients sign in to view performance reports, manage billing, refer new business, complete satisfaction check-ins and chat with Halo, our AI agent);
  • All services we provide to clients, including SEO, paid media, web design and development, web hosting, AI services, reporting and consulting.

2. What information we collect

We only collect personal information that is reasonably necessary for our business (APP 3). The information we collect falls into these categories:

  • Information you give us via the website — when you submit an enquiry, request a free audit, subscribe to our newsletter, apply for a role, or otherwise contact us. This may include your name, email address, phone number, business name and website, marketing budget, goals and any other details you choose to share. For job applications this also includes your résumé (uploaded as a file attachment) and the contents of any cover note.
  • Information we capture automatically when you submit a form — the page you submitted from, your IP address, your country (resolved at our edge from your IP), the browser user-agent string, and the date and time of submission. We use this for fraud prevention, lead-source analytics and to comply with our own Australian-only contact policy.
  • Information about engaged clients — if you engage Whitehat, we collect business and billing details needed to deliver and invoice for our services, including ABN, contact details, the names and email addresses of nominated portal users on your account, billing email, and payment information (card payments are handled securely by our payment provider; we do not store full card numbers).
  • Performance data we collect on your behalf — with your authorisation we read data from your connected analytics, advertising and SEO accounts (Google Analytics 4, Google Search Console, Google Ads, Google Business Profile, Google Merchant Center, Meta Ads, Bing Webmaster Tools, Ahrefs and similar) for the purpose of producing your reports and managing your campaigns. This is data about your business; it may include limited personal information (for example, customer identifiers in your CRM).
  • Customer lists clients provide for advertising audiences — where you ask us to build an advertising audience for your Meta campaigns, you may provide a list of your customers’ contact details (such as email addresses and phone numbers). We process these transiently: each value is normalised and one-way hashed (SHA-256) in memory before it is sent to Meta for matching, we do not keep a copy of the list, and the raw details are never written to our systems or our audit logs — only the count of contacts uploaded is recorded.
  • Enquiries from lead ads we manage — where we run lead-generation advertising for a client, people who submit the ad’s enquiry form (typically their name, phone number, email address and selected options) have those details collected by Meta and made available to us so we can deliver them to that client. We handle these enquiries as the client’s data: we pass them to the client, use them only to provide our services to that client, and do not use them for any other purpose.
  • Website availability data for hosting clients — where we host your website, we continuously monitor its availability and response time (uptime monitoring) so we can respond to outages and report hosting performance to you. This is data about your website, not about individuals.
  • Website security and backup data for hosting clients — where we host your website or provide website security as part of your engagement, we run malware scanning, firewall protection and automated backups on the site. This produces malware scan results, security logs (including the IP addresses of requests to your website that were blocked as malicious), encrypted backup copies of your website and its database — which may include personal information your website itself stores (for example, user accounts or form entries) — and a log of the routine software updates we apply to the site. We access this data only to protect and maintain your website and to report that work to you.
  • Portal account information — when you sign in to portal.whitehatagency.com.au we record your email address (used as your identifier), display name, role within your account (owner, admin, member), session activity (sign-in times and which portal features you use) and your notification preferences. We use magic-link sign-in — we do not store passwords for portal users.
  • Portal interactions — messages and questions you send to Halo (our AI agent), survey responses you submit to our quarterly Pulse satisfaction check-in (Pulse responses are tied to your client account, but who from your team submitted is not surfaced to teammates), referrals you submit, and internal notes about your account written by our team.
  • Information collected automatically when you browse — cookies, analytics events, IP address, device and browser type, the pages you view and how you interact with the site. See “Cookies and analytics” below for the specific tools.
  • Information from third parties — to qualify and prepare for business enquiries, we may collect publicly available information about you or your business (for example, your company website, professional networks, news, Google search results and the Australian business registers).

3. How we use your information

We use personal information (APP 6) to:

  • respond to your enquiry, send you an acknowledgement, and follow up about your enquiry or free audit;
  • provide, manage, report on and improve our services to you (including monitoring the uptime of websites we host, protecting them with malware scanning, firewall protection and automated backups, keeping their software current through routine monthly maintenance — plugin and theme updates applied with a backup taken before every update — and sending hosting clients a monthly hosting report);
  • give you secure access to your client portal, deliver your scheduled performance reports (by email and in the portal), let you chat with Halo, run the quarterly Pulse check-in, and process referrals you submit;
  • build advertising audiences you request from customer lists you provide (one-way hashed before matching — see “What information we collect”), and receive and deliver to you the enquiries generated by lead ads we run for you;
  • assess job applications and manage recruitment (your résumé is forwarded to our careers inbox; we do not publish or share it externally);
  • process billing and payments, issue invoices, apply referral discounts where earned, and meet our accounting and tax obligations under Australian law;
  • operate, secure, analyse and improve our website, portal and services (including portal product analytics, server-side aggregate analytics, error monitoring and rate limiting to detect abuse);
  • use AI tools (most notably Halo, powered by Anthropic’s Claude API) to qualify enquiries, score referrals for fit, draft outreach emails, analyse your performance data and write your reports. AI tools also assist our team inside our own business systems — reading and drafting in our own email, calendar and document accounts, which naturally include correspondence with you and files about your account; any email drafted this way is reviewed and approved by a person at Whitehat before it is sent. A person at Whitehat reviews material decisions before they reach you, and you can ask your account manager to disable AI-generated content for your account at any time;
  • send you marketing communications and our newsletter where you have requested them or where otherwise permitted by law (see “Direct marketing” below); and
  • comply with our legal obligations, enforce our terms, and protect our and your legal rights.

4. When we disclose your information

We do not sell your personal information. We disclose it only as set out in this policy — mainly to the service providers we use to run the business, to your account manager, to your professional advisers where relevant, and where required by law.

Specifically, we may disclose your information to:

  • Whitehat staff — your account manager and the team supporting your account;
  • Service providers — hosting, database, email delivery, payment processing, authentication, analytics, uptime monitoring, website security and backup, error monitoring and AI providers, under arrangements that require them to protect your information and use it only for the services they provide to us (the full list is in the next section);
  • Professional advisers — our lawyers and accountants where reasonably necessary;
  • Government agencies, regulators or law enforcement where required or authorised by law (see “Requests from public authorities” below);
  • A purchaser or successor in the event of a sale, merger or restructure of our business (your information would transfer with the business and remain protected by this policy or an equivalent).

5. Service providers and overseas disclosure (APP 8)

Some of the service providers we use store or process data outside Australia. We take reasonable steps to ensure these providers handle personal information consistently with the Australian Privacy Principles, including by using providers with appropriate certifications (such as SOC 2 Type II and ISO 27001) and contractual commitments to data protection.

Primary database — in Australia:

  • Supabase (Sydney, ap-southeast-2) — our primary database. Stores your portal account, your client record, your performance reports, your referrals, your Pulse responses, your goals, and the leads submitted through our website. Data sovereignty is preserved — this data does not leave Australia at rest.

6. Overseas service providers we use

The following providers may store or process personal information outside Australia. Each is contractually bound to protect that information and has its own published privacy and security commitments, linked below.

  • Vercel, Inc. (USA) — hosts and serves the website and portal. Traffic is served from edge locations including Sydney, but processing infrastructure is operated globally. vercel.com/legal/privacy-policy
  • Anthropic, PBC (USA) — processes data submitted to Halo, our AI agent, for the purpose of generating your reports, scoring referrals, drafting outreach emails and answering chat questions, and powers the AI tools that assist our team with correspondence and documents held in our own business email, calendar and document systems (which may include correspondence with you). Under Anthropic’s commercial terms, your data is not used to train Anthropic’s models. anthropic.com/legal/privacy
  • Stripe Payments Australia Pty Ltd / Stripe, Inc. (Australia, USA, Ireland) — processes card and direct-debit payments and stores billing-related personal information. PCI-DSS Level 1 certified. We do not see or store your full card number. stripe.com/au/privacy
  • Xero Limited (New Zealand) — our accounting platform. For clients billed by invoice, invoices are raised and managed in Xero, and we read invoice status from our Xero account to show billing history in the portal. xero.com/au/legal/privacy
  • Resend (USA) — delivers transactional and notification emails from our website and portal (lead acknowledgements, portal invites, reminders, scheduled performance reports). SOC 2 Type II. resend.com/legal/privacy-policy
  • Clerk, Inc. (USA) — authenticates portal users (issues magic-link sign-in emails, manages sessions). SOC 2 Type II. clerk.com/legal/privacy
  • Google LLC (USA / Ireland) — Google Analytics 4 (website usage analytics), Google Tag Manager (tag management), Google Search Console (organic search performance), Google Ads API (paid campaign data), Google Business Profile API (local search and profile performance), Google Merchant Center API (Shopping feed and performance for online stores) and Google PageSpeed Insights (performance audits of web pages — data about the page, not about individuals). Our own business email, calendar and documents run on Google Workspace. policies.google.com/privacy
  • Ahrefs Pte. Ltd. (Singapore) — SEO data and backlink intelligence used in client reports, and Ahrefs Web Analytics on our website. ahrefs.com/privacy
  • PostHog, Inc. (USA) — product analytics for the client portal: which portal pages and features are used and how (page views, clicks, feature usage), tied to your portal sign-in, so we can improve the portal experience and support you. Not used on the public website. posthog.com/privacy
  • Microsoft Corporation (USA) — Microsoft Clarity provides anonymised session replays and heatmaps of website visits so we can improve the site experience. We also read Bing Webmaster Tools (Bing organic search performance) for client reports, and may submit client pages to Bing for crawling as part of SEO work. privacy.microsoft.com
  • UptimeRobot s.r.o. (Czech Republic, EU) — monitors the availability and response times of websites we host for clients, around the clock, so we can respond to outages and report hosting performance. Holds the monitored website addresses and their availability history — data about the website, not about individuals. uptimerobot.com/privacy-policy
  • Inactiv.com Media Solutions Pvt. Ltd. / BlogVault Inc. (India / USA, servers in the USA and EU) — operates the WP Remote, MalCare and BlogVault platform we use to protect and back up websites we host or secure for clients: malware scanning, firewall protection and automated backups. Holds encrypted backups of those websites and their databases (which may include personal information the website itself stores, such as user accounts or form entries), malware scan results, and firewall logs including the IP addresses of blocked requests. Backups are encrypted and stored in EU data centres and on Amazon S3. wpremote.com/privacy
  • LinkedIn Corporation (USA) — the LinkedIn Insight Tag measures the effectiveness of our LinkedIn advertising. linkedin.com/legal/privacy-policy
  • Meta Platforms Ireland Limited / Meta Platforms, Inc. (Ireland / USA) — for clients who run Meta Ads with us, we read Facebook and Instagram advertising performance (spend, results, reach, campaign breakdowns) and manage their advertising (creating and adjusting campaigns, audiences, enquiry forms and ads) through Meta’s Marketing API, using access granted to our agency’s Meta Business Manager. Where a client provides a customer list for audience matching, each contact detail is one-way hashed before it reaches Meta and the raw list is not retained by us. Where we run lead ads, Meta collects the enquiry details submitted on the form and makes them available to us to deliver to that client. Data we receive from Meta is shown only to the client whose advertising it is, is never sold or shared with any other client, and is handled and deleted in accordance with this policy. facebook.com/privacy/policy
  • Tina Cloud (USA) — lets our marketing team edit content on the public website. Does not handle client portal data. tina.io/legal/privacy-policy
  • GitHub, Inc. (USA) — source-code repository for the website and portal. Holds the application code, not client data. GitHub Privacy Statement

7. Cookies and analytics

Our website uses cookies and similar technologies, loaded through Google Tag Manager, to understand how visitors use the site, measure our advertising and improve the experience. The tools we run are: Google Analytics 4 (site usage analytics), Google Ads conversion tracking (measures enquiries generated by our advertising), Microsoft Clarity (anonymised session replays and heatmaps showing how visitors interact with pages), the LinkedIn Insight Tag (advertising measurement) and Ahrefs Web Analytics (aggregate usage statistics). These tools may collect information such as your IP address (anonymised where supported), the pages you visit, the buttons you click and the time you spend on the site.

Our client portal uses cookies set by Clerk to keep you signed in securely (these are essential and cannot be disabled while you are signed in), and PostHog product analytics to understand how portal features are used (tied to your portal account) so we can improve the portal.

You can control or disable non-essential cookies through your browser settings. Disabling cookies may affect how the website functions. For more on how Google handles data, see Google’s privacy policy.

8. How AI is used (Halo)

We use AI (most notably Halo, our AI agent built on Anthropic’s Claude API) to make reporting and account management faster and more useful. Specifically, Halo:

  • writes your scheduled performance report from your connected analytics, advertising and SEO data, judged against the goals your account manager has recorded for you;
  • answers questions you ask in the “Ask Halo” chat panel in your portal, using the same data your latest report was written from;
  • scores incoming referrals 0–100 for fit and drafts a first outreach email to the referred prospect (your account manager reviews and edits before sending — nothing is sent automatically);
  • tags Pulse survey comments with sentiment and theme labels to help our leadership team spot patterns across clients;
  • assists our team inside our own business systems — AI tools can read and draft in our own email, calendar and document accounts, which naturally include correspondence with you and files about your account. Any email drafted this way is reviewed and approved by a person at Whitehat before it is sent, and the same no-training commitment applies.

9. AI safeguards

You should know:

  • AI outputs are advisory — a person at Whitehat reviews and is responsible for material decisions that reach you (proposals, contracts, outreach to referred prospects, scope changes);
  • Anthropic does not train its models on data submitted via the Claude API under their commercial terms;
  • you can ask us to disable AI-generated content for your account at any time — email hello@whitehatagency.com.au;
  • Halo’s context is limited to your own data — it does not share your numbers, goals or notes with any other Whitehat client.

10. Direct marketing

We may send you marketing communications (such as our newsletter, relevant case studies or service updates) where you have opted in, or where you are an existing contact and we are permitted to under the Spam Act 2003 (Cth).

Every marketing email includes an unsubscribe link, and you can opt out at any time by using that link or by emailing us at hello@whitehatagency.com.au. We will action your request promptly. Unsubscribing from marketing does not stop transactional or service emails (such as your scheduled performance reports, monthly hosting reports or billing notifications) — those continue while you are an engaged client.

11. How we hold and protect your information (APP 11)

We hold personal information in secure systems and take reasonable steps to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure. The specific measures we use include:

  • Encryption in transit — TLS 1.3 is enforced on every request to our website and portal (HSTS with includeSubDomains and preload).
  • Encryption at rest — our database (Supabase, Sydney) encrypts stored data at rest.
  • Authentication — portal access uses magic-link sign-in (no passwords for clients), with multi-factor authentication available for agency staff accounts.
  • No credential collection — we never ask for, collect or store passwords to your accounts. Access to your platforms is granted to our agency accounts instead (for example, adding our team as a user in Google, linking via our Google Ads manager account, or partner access in Meta Business Manager), and our portal onboarding never asks for credentials.
  • Row-Level Security — our database enforces per-client isolation at the database layer, so one client cannot read another’s data even if other controls fail.
  • Audit logging — sensitive administrative actions (status changes, content edits, report generation) are logged with the actor and timestamp.
  • Geo-fencing — public contact and application forms only accept submissions originating in Australia or New Zealand, reducing offshore spam and abuse vectors.
  • Input validation — every form submission is server-validated; file uploads (job application résumés) are content-sniffed to confirm file type, not just trusted on the browser-supplied MIME header.
  • Vulnerability disclosure — security researchers can contact us via /.well-known/security.txt.

12. Security — what you should know

No method of transmission or storage is completely secure. While we work hard to protect your information, we cannot guarantee absolute security. You play an important part too: keep your portal sign-in email private, sign out from shared devices, and tell us straight away if you suspect any unauthorised activity on your account.

13. Notifiable Data Breach scheme

If a data breach is likely to result in serious harm to individuals whose personal information is involved, we will notify those individuals and the Office of the Australian Information Commissioner as soon as practicable, as required by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).

14. Requests from public authorities

If a government agency or public authority requests personal information we hold, we follow a set process:

  • we review the legality of every request before acting on it;
  • we challenge requests we consider unlawful;
  • we disclose only the minimum information necessary to comply with a valid request; and
  • we document every request, our legal reasoning and our response.

15. How long we keep it

We keep personal information only for as long as we need it for the purposes described in this policy, or as required to meet legal, accounting, billing or reporting obligations (typically 7 years for financial records under Australian tax law).

  • Active client data — retained for the duration of our engagement plus 7 years for tax and audit purposes;
  • Lead and enquiry data — retained for up to 24 months from your last contact with us, then deleted or de-identified;
  • Job application data — retained for up to 12 months after the role is filled or withdrawn, unless you ask us to delete it sooner;
  • Performance reports and analytics caches — retained for the duration of our engagement and a reasonable period after for reference;
  • Audit logs — retained for at least 12 months for security and accountability purposes.

16. Accessing and correcting your information (APP 12 and APP 13)

You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete or misleading. You can also request that we delete personal information about you, subject to our legal obligations to retain certain records.

To make a request, email us at hello@whitehatagency.com.au. We will respond within a reasonable time (generally within 30 days). There is generally no charge for making a request, though we may charge a reasonable fee for giving access in some circumstances. We may need to verify your identity before acting on a request.

If you are an active client, much of your personal and account information is also available directly in your portal under Settings.

17. Complaints

If you have a concern or complaint about how we have handled your personal information, please contact us first at hello@whitehatagency.com.au so we can try to resolve it. We will acknowledge your complaint and respond within a reasonable time.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

18. Children

Our website and services are intended for businesses and are not directed at children. We do not knowingly collect personal information from children under 16. If you believe we have, please contact us and we will delete it.

19. Third-party links

Our website and portal may contain links to third-party websites and tools. We are not responsible for the privacy practices or content of those sites. We encourage you to read their privacy policies before providing them with any personal information.

20. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, the services we offer, or our legal obligations. The current version will always be available on this page, with the “last updated” date shown above. Significant changes will be made prominent where appropriate (for example, by notifying portal users by email or by an in-portal banner).

21. Contact us

For any privacy question or request, contact us:

Whitehat Agency (484 Digital Pty Ltd, ABN 81 651 974 006)
136 Epsom Rd, Zetland NSW 2017, Australia
Email: hello@whitehatagency.com.au
Security disclosures: security@whitehatagency.com.au
Phone: 1800 465 300

This policy is current as at the date shown above.