PRIVACY POLICY

Archie James Group Pty Ltd Last updated: 30 March 2026 · Version 1.2 · archiejamesgroup.com.au

Overview

Archie James Group Pty Ltd (ABN 36 454 950 089) ('we', 'us', 'our') is committed to protecting your privacy. This Privacy Policy explains what personal information we collect, why we collect it, how we use it, how long we keep it, and your rights in relation to it.

We operate archiejamesgroup.com and provide the following services:

  • Business Builders Library — policy, process and procedure document templates

  • Cost comparison and EFTPOS advisory services

  • Archie James Investments — cost reduction advisory and referral services

  • Other services as offered from time to time

This policy applies to all visitors to our website, customers, subscribers and anyone who contacts us. Our services are currently available to Australian and New Zealand residents. We do not actively market to EU, UK or California residents at this time, however we have included information about their rights as a courtesy where they access our website.

1. What Information We Collect

In plain English: We only collect information you give us directly, or that your browser shares automatically when you visit our site.

1.1 Information you give us directly

When you use our website, contact us, make a purchase or create an account, you may provide us with:

  • Name and contact details (email address, phone number)

  • Business information (business name, ABN, address, industry, state)

  • Account login credentials (email and password — passwords are hashed and never stored in plain text)

  • Payment information (processed securely by Stripe — we do not store card details)

  • Information entered into calculator tools or enquiry forms

  • Communications you send to us via contact forms or email

  • Marketing preferences and newsletter subscriptions

1.2 Information collected automatically

When you visit our website, we automatically collect:

  • IP address and approximate location

  • Browser type and version

  • Pages visited and time spent on each page

  • Referring website or source

  • Device type and operating system

  • Cookie data (see Section 6 — we only set non-essential cookies after you have given consent)

1.3 Information from third parties

We may receive information from:

  • Google Analytics — website usage data (only after cookie consent)

  • Stripe — payment confirmation and transaction data

  • Email marketing platforms — open and click data

  • Squarespace — form submissions and website analytics

2. Why We Collect Your Information

In plain English: We collect your information to provide our services and communicate with you. Marketing communications require your separate consent — submitting a contact form does not constitute marketing consent.

PurposeDetailTo provide our servicesCreating and managing your account, delivering purchased templates, providing portal access, and delivering advisory services.To process paymentsProcessing purchases and subscriptions through Stripe. We do not store card details.Service communicationsResponding to enquiries, sending purchase confirmations, customer support, and subscription updates. These do not require separate marketing consent.Marketing (separate consent required)Newsletters, product updates and promotional offers — only where you have ticked a marketing opt-in checkbox. Unsubscribe at any time.To improve our servicesAnalysing how our website is used. Aggregated and de-identified where possible.To meet legal obligationsTax and financial records, and responding to lawful requests from regulators or courts.To protect our businessDetecting and preventing fraud and unauthorised access.

3. Legal Basis for Processing

In plain English: We only process your information when we have a legitimate legal reason.

  • Consent — where you have given clear, specific and freely given consent, such as opting in to our mailing list via a checkbox, or accepting non-essential cookies via our cookie banner

  • Contract — where processing is necessary to perform a contract with you, such as delivering a purchased template or managing your subscription

  • Legal obligation — where required by law, such as tax and financial record-keeping under the Income Tax Assessment Act

  • Legitimate interests — where we have a genuine business reason that does not override your rights, such as fraud prevention or improving our services

4. How We Share Your Information

In plain English: We don't sell your information. We only share it with service providers we need to operate our business.

  • Stripe — to process payments securely (PCI-DSS compliant)

  • Google — for website analytics (Google Analytics, only after consent) and email (Google Workspace)

  • Email marketing platforms — to send communications you have subscribed to

  • Squarespace — our website platform, which processes form submissions and visitor data

  • Lovable and cloud hosting providers — our portal platform and associated cloud infrastructure

  • Professional advisers — accountants, lawyers or consultants under confidentiality obligations

  • Regulators and government agencies — where required by law

We do not sell, rent or trade your personal information to third parties for their own marketing purposes.

5. Data Storage, Security & Retention

In plain English: Your data is stored securely. We keep it only as long as necessary, then delete it. If there's ever a data breach that could harm you, we'll notify you and the OAIC as required by law.

5.1 Security measures

We take reasonable technical and organisational steps to protect your information, including:

  • Encrypted data transmission (HTTPS/TLS)

  • Password hashing — passwords are never stored in plain text

  • Access controls limiting who can access personal data

  • Regular security reviews of our platforms and third party providers

  • Secure payment processing via Stripe (PCI-DSS compliant)

5.2 Data retention schedule

Data TypeRetention PeriodReasonCustomer account & transaction data7 years from last transactionATO record-keeping requirementsSubscription records7 years from subscription endTax and financial recordsEmail marketing dataUntil unsubscribe + 30 daysConsent-based — deleted on withdrawalContact form enquiries2 years from date of enquiryReasonable business recordsCalculator tool inputs90 days (aggregated analytics only)Improvement purposes onlyWebsite analytics data26 months (Google Analytics default)Industry standard retentionSecurity logs12 monthsFraud prevention and security review

5.3 Data breach notification

In the event of a data breach that is likely to result in serious harm to any affected individuals, we will:

  • Notify affected individuals as soon as practicable

  • Notify the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988

  • Take immediate steps to contain the breach and prevent further unauthorised access

  • Conduct a post-breach review and implement remediation measures

If you believe your personal information held by us has been compromised, please contact us immediately via our contact form.

6. Cookies & Tracking

In plain English: We use cookies to make our website work. We only set analytics and marketing cookies after you give consent via our cookie banner. Essential cookies are set automatically as the site cannot function without them.

When you first visit our website, a cookie consent banner will ask for your consent before any non-essential cookies are set.

Cookie TypeConsent RequiredPurposeExamplesEssentialNo — required for site functionLogin, checkout, securitySession cookies, security tokensAnalyticsYes — opt-in via cookie bannerUnderstand how visitors use siteGoogle Analytics (loads after consent only)FunctionalYes — opt-in via cookie bannerRemember your preferencesDisplay settings, language preferencesMarketingYes — opt-in via cookie bannerAd effectiveness trackingAd pixels — only if used in future

You can change your cookie preferences at any time by clicking the cookie settings link in our website footer. You can also control cookies through your browser settings, however disabling essential cookies may affect your ability to use our portal or complete purchases.

7. Your Rights

In plain English: You have the right to access, correct or delete your information, opt out of marketing, and withdraw consent at any time. Contact us and we'll respond within 30 days.

  • Access — request a copy of the personal information we hold about you

  • Correction — ask us to correct inaccurate or incomplete information

  • Deletion — request that we delete your personal information, subject to our legal retention obligations in Section 5.2

  • Opt-out of marketing — unsubscribe at any time using the link in any email, or by contacting us

  • Data portability — request your information in a portable, machine-readable format

  • Withdrawal of consent — withdraw any consent you have given at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.

To exercise any of these rights, contact us via archiejamesgroup.com/contact. We will acknowledge your request within 5 business days and respond in full within 30 days.

8. Jurisdiction-Specific Rights

In plain English: Our services are primarily for Australian and New Zealand residents. If you're located elsewhere and access our website, we've noted your applicable rights below.

8.1 Australia — Australian Privacy Act 1988 (Cth)

We comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 and the Notifiable Data Breaches scheme. If you believe we have breached your privacy, contact us first. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or call 1300 363 992.

8.2 New Zealand — Privacy Act 2020

New Zealand residents have rights under the Privacy Act 2020, including the right to access and correct personal information we hold, and the right to complain about a breach of the Information Privacy Principles. If your complaint is not resolved to your satisfaction, you may contact the Office of the Privacy Commissioner at www.privacy.org.nz or call 0800 803 909.

8.3 European Union & United Kingdom — GDPR / UK GDPR

Our services are not actively marketed to EU or UK residents. If you are located in the EU or UK and access our website, we acknowledge your rights under the GDPR or UK GDPR, including the right to access, rectify, erase, restrict or object to processing of your data, and the right to lodge a complaint with your local supervisory authority. If you are an EU/UK resident and wish to exercise your rights, please contact us via our website contact form.

8.4 California, USA — CCPA / CPRA

Our services are not actively marketed to California residents. If you are a California resident and access our website, you have rights under the CCPA and CPRA, including the right to know what personal information is collected, the right to delete personal information, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your California privacy rights, contact us via our website contact form.

9. Children's Privacy

In plain English: Our services are for businesses and adults only. We do not knowingly collect information from anyone under 18.

Our website and services are directed at businesses and individuals aged 18 years and over. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected information from a minor, please contact us immediately and we will delete it without delay.

10. Changes to This Policy

In plain English: We'll update this policy as our services grow or as laws change. For significant changes, we'll email subscribers at least 14 days before they take effect.

We may update this Privacy Policy from time to time. The 'Last updated' date and version number at the top of this page will reflect when it was most recently changed.

For significant changes — such as new types of data collection, new third party sharing, or changes that materially affect your rights — we will notify active subscribers by email at least 14 days before the change takes effect.

For minor updates — such as clarifications or adding new service providers that do not change how your data is used — the date will be updated without email notification.

Continued use of our website or services after a change constitutes acceptance of the updated policy.

11. Contact Us

In plain English: Privacy questions or complaints? Use our contact form and we'll respond within 30 days.

Archie James Group Pty Ltd ABN: 36 454 950 089 Website: archiejamesgroup.com Contact form: archiejamesgroup.com/contact

We aim to acknowledge privacy enquiries within 5 business days and respond in full within 30 days. If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner at www.oaic.gov.au.