Privacy Policy
What we collect, why, and what we do with it.
Last updated 30 August 2026
Hazzard Communications (ABN 82 645 381 172) is a one-person IT consultancy based on Stradbroke Island, Queensland. This policy explains what personal information we collect through this website and in the course of client work, how it is used, and who else can see it.
We are a small business, and small businesses under the turnover threshold are generally exempt from the Privacy Act 1988. We handle personal information in line with the Australian Privacy Principles anyway, because clients trust us with access to their systems and that trust is the actual product.
Information you give us
The contact form on this site asks for your name, email address and a message. That is all it collects. Submissions are delivered to us by Netlify, who host this website, and are stored in their form dashboard as well as forwarded to our email.
If you email or phone us instead, we keep that correspondence in the ordinary way any business keeps its correspondence.
Information collected automatically
- Google Analytics. This site uses Google Analytics 4 to count visits and see which pages get read. It records things like the pages you viewed, roughly where in the world you are, your device and browser, and how you arrived. IP addresses are handled by Google and are not exposed to us — we see aggregate numbers, not individuals.
- Web fonts. Pages load fonts from Google Fonts, which means Google's servers see your IP address as part of serving the font files.
- Server logs. Netlify keeps standard web server logs for the site.
We do not use advertising pixels, remarketing tags, session recording or heat-mapping tools on this site.
Cookies
The only cookies this site sets are Google Analytics ones, used to tell one visit from another. There is no advertising cookie, and nothing here follows you to other websites. If you would rather not be counted, browser settings or an ad blocker will stop it, and the site works normally without it.
Client information
Consulting work means we are often given access to a client's systems — email accounts, servers, hosting, business software, and the data inside them. That access is used only to do the work we were engaged to do.
- We do not read, copy or extract client data beyond what the task requires.
- We do not sell, share or disclose client information to anyone else, except where the client asks us to or the law requires it.
- Credentials are held in an encrypted password manager, not in plain files or email.
- Backups of client systems we manage are encrypted, and are kept only as long as the engagement and any agreed retention period require.
- When an engagement ends, a client can ask us to remove their credentials and any copies of their data, and we will.
Google account data and our internal tools
We build and run our own small internal tools that connect to Google services using Google's official APIs — for example to read Google Analytics and Search Console figures, or Google Business Profile statistics, so we can produce a monthly visibility report for a client about their own listing and website.
These tools sign in with the account of the person operating them, or with an account a client has explicitly granted access to. Google account data obtained this way is used only to produce that reporting for the account holder. It is not sold, not transferred to anyone else, not used for advertising, and not used to build any profile or dataset beyond the report itself. Access tokens are stored on our own machines and can be revoked at any time by the account holder from their Google account security settings.
Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Who else sees your information
We use a small number of established service providers to run the business, and your information may pass through them:
- Netlify — website hosting and contact form submissions.
- Google — website analytics, and our business email and documents.
- Our email and invoicing systems — used to correspond with you and, if you become a client, to bill you.
Some of these providers store data outside Australia, which is normal for internet services. We do not sell personal information to anyone, and we do not pass it to marketing companies or data brokers.
How long we keep it
Enquiries that do not turn into work are kept while they might still be useful and cleared out periodically. Client records, correspondence and invoices are kept for as long as the engagement runs and then for the period Australian tax and business record-keeping rules require — generally seven years.
Security
Accounts are protected with strong, unique passwords and multi-factor authentication where the service supports it. Credentials live in an encrypted password manager. Backups are encrypted. No system is perfect, and we would rather say that plainly than promise otherwise — but if something did go wrong in a way that put your information at risk, we would tell you.
Getting at your information, or complaining about it
You can ask us what personal information we hold about you, ask for it to be corrected, or ask us to delete it. Email paul@hazzard.com.au and we will respond within a reasonable time, normally a few days.
If you are not happy with how we have handled your information, tell us first and we will try to sort it out. If that does not resolve it, you can take the matter to the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this policy
If this policy changes, the updated version will appear on this page with a new date at the top.
Contact
Hazzard Communications
ABN 82 645 381 172
Stradbroke Island, Queensland
paul@hazzard.com.au