Skip to main content
Legacy Creators logo: gold wings mark Legacy Creators
Why it matters Services Questions Free audit

Privacy Policy

Last updated: 1 August 2026

The short version

  • We collect only what we need to answer you, prepare the free audit you asked for, and deliver work to clients.
  • We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
  • Analytics cookies stay switched off until you accept them.
  • You can ask us for a copy of your data, ask us to correct or delete it, or tell us to stop contacting you — at any time, free of charge.
  • To do any of that, email [email protected].

This policy explains how Legacy Creators handles personal information. It applies to this website, to the free AI visibility audit, to discovery calls, to our client work, and to our business outreach.

  1. Who we are and how to contact us
  2. Which privacy laws apply
  3. What we collect
  4. Where we get it from
  5. What we use it for, and our legal basis
  6. Marketing and business outreach
  7. Who we share it with
  8. International transfers
  9. How long we keep it
  10. How we protect it
  11. Your rights
  12. How to exercise your rights
  13. Cookies and tracking
  14. Children
  15. Automated decisions and AI tools
  16. Data breaches
  17. Changes to this policy
  18. Complaints

1. Who we are and how to contact us

Legacy Creators is the trading name of Arthur de Paula Filiberto, a sole trader registered in Australia under ABN 42 627 319 380, based in Melbourne, Victoria. We serve clients in Australia and internationally.

For data protection purposes, Legacy Creators is the controller of the personal information described in this policy — meaning we decide why and how it is handled. When we deliver services to a client and handle personal information on their behalf and under their instructions, we act as a processor for that client instead, and the client's own privacy policy governs that information.

Contact for all privacy matters: [email protected]. We aim to respond within 5 business days, and within the timeframes required by law in all cases.

2. Which privacy laws apply

We are based in Australia and work with clients in multiple countries, so more than one privacy regime can apply depending on where you are. We have written this policy to meet the strictest of them, and we apply the same standards to everyone regardless of location.

  • Australia. The Privacy Act 1988 (Cth) and the Australian Privacy Principles. As a small business operator we may currently fall within the small business exemption in that Act, but we do not rely on it: we handle personal information as though the Australian Privacy Principles apply to us in full.
  • European Economic Area. The General Data Protection Regulation (EU) 2016/679, where we offer services to, or monitor people in, the EEA.
  • United Kingdom. The UK GDPR and the Data Protection Act 2018.
  • California. The California Consumer Privacy Act as amended by the California Privacy Rights Act, where it applies to us.
  • Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA), where it applies.

Where a law that applies to you gives you stronger rights than this policy describes, that law prevails and we will honour it.

3. What we collect

We collect only what we need. We do not ask for, and do not want, sensitive information — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric or genetic data, precise geolocation, or government identifiers. Please do not send it to us.

CategoryExamples
Identity and contact Name, email address, phone number if you give it, job title, employer or business name
Business information Your website address, industry, approximate size, the questions your customers ask, competitors you name
Correspondence Emails, form messages, notes we take during a discovery call, and anything you type into a free-text field
Booking information The time slot you select, your time zone, and anything you enter when booking a call
Technical and usage IP address, approximate location derived from it, browser and device type, pages viewed, referring site, time on page
Client engagement records Contracts, scope documents, deliverables, invoices and payment records, access credentials you choose to share with us

A note on audits. The free AI visibility audit examines publicly available information about a business — its website, its listings, its reviews, and what AI assistants say about it. Where that public information happens to include a person's name, for example a founder named on an "about" page, it forms part of the audit record.

4. Where we get it from

  • Directly from you — when you submit a form, book a call, email us, or become a client.
  • Automatically — through cookies and similar technologies when you use this site, subject to your consent choice.
  • From public sources — company websites, public business directories, professional networking profiles, review platforms and search results, when we research a business we may be able to help.
  • From your organisation — if a colleague books a call or shares your details as a contact for a project.

5. What we use it for, and our legal basis

Where the GDPR or UK GDPR applies, we must have a lawful basis for each use. This table sets out ours. Where those laws do not apply, the purposes still describe everything we do with your information.

What we doWhyLegal basis
Prepare and send the free audit Because you asked us to Steps taken at your request before entering a contract; consent
Reply to enquiries, hold discovery calls To answer you and work out whether we can help Steps taken at your request before entering a contract; legitimate interests in responding to enquiries
Deliver services to clients To do the work and manage the engagement Performance of a contract
Send invoices, keep tax and accounting records To get paid and to meet record-keeping obligations Performance of a contract; legal obligation
Contact businesses we think we can help To offer a relevant service, with a completed audit attached Legitimate interests in business development, balanced against your interests — see section 6
Send marketing emails To share useful material and offers Consent, or legitimate interests where you are an existing client and can opt out at any time
Measure how the website is used To understand what people read and improve the site Consent
Keep the site secure and available To prevent abuse, spam and attacks Legitimate interests in protecting our systems
Establish, exercise or defend legal claims To protect our position if a dispute arises Legitimate interests; legal obligation

Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not for the limited, business-context uses described. You can object to any of it — see section 11 — and we will stop unless we have compelling grounds to continue.

6. Marketing and business outreach

We contact businesses that we believe we can genuinely help, usually with a completed visibility audit already attached so the message has value whether or not you reply. We use business contact details obtained from public sources or given to us directly.

  • Every marketing message identifies who we are and how to reach us.
  • Every marketing message contains a working unsubscribe mechanism, honoured promptly and at no cost to you.
  • Tell us to stop and we stop — including by simply replying and saying so.
  • We do not buy marketing lists, and we do not send bulk untargeted mail.

We comply with the Spam Act 2003 (Cth) in Australia, the CAN-SPAM Act in the United States, Canada's Anti-Spam Legislation, and the consent requirements of the GDPR and the Privacy and Electronic Communications Regulations where those apply. Where the law requires prior consent for electronic marketing, we obtain it before sending.

7. Who we share it with

We do not sell personal information, and we have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months. We disclose it only to the service providers we need to run the business, each bound to protect it and to use it only for the service they provide to us.

ProviderWhat it doesWhere it processes data
CloudflareWebsite hosting, delivery and securityGlobal network, including the United States
Web3FormsDelivers website form submissions to our inboxUnited States
CalendlyAppointment booking and schedulingUnited States
Google WorkspaceEmail, documents and file storageGlobal, including the United States
Google AnalyticsWebsite usage measurement, only after you consentGlobal, including the United States

We may also disclose personal information:

  • to professional advisers such as accountants and lawyers, under a duty of confidentiality;
  • where we are required to by law, court order or a regulator;
  • to protect our rights, property or safety, or those of others;
  • to a buyer or successor if the business is sold or restructured, subject to this policy continuing to apply.

8. International transfers

We are in Australia, and our providers operate globally. Your information will therefore be transferred across borders, including to the United States.

Where personal information is transferred out of the EEA or the UK, we rely on appropriate safeguards under the GDPR — most commonly the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a finding of adequacy for the receiving country. Where personal information is disclosed outside Australia, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.

You may request details of the safeguards that apply to a particular transfer by emailing us.

9. How long we keep it

We keep personal information only as long as we need it, then delete or anonymise it. These are our standard periods.

RecordKept for
Audit request or enquiry that does not become a client24 months from last contact
Marketing contact detailsUntil you unsubscribe, then a minimal suppression record kept indefinitely so we do not contact you again
Client files, contracts and correspondence7 years after the engagement ends
Invoices and financial records7 years, to meet Australian tax record-keeping requirements
Booking records24 months
Website analytics14 months
Server and security logsUp to 12 months

We may keep information longer where we need it for a legal claim, or where the law requires it. If you ask us to delete your information we will do so unless one of those applies, and we will tell you if it does.

10. How we protect it

We take reasonable technical and organisational measures appropriate to the risk, including encrypted connections to this website, multi-factor authentication on our business accounts, access limited to those who need it, reputable providers with their own security programmes, and deletion of information we no longer need.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you share credentials or access to your systems with us for a project, we will handle them confidentially and ask that you revoke that access when the work ends.

11. Your rights

These rights are available to everyone we deal with, wherever you live. Some of them come from a specific law, and where that law adds conditions we will explain them when you ask.

  • Know and access. Ask what personal information we hold about you, where we got it, what we use it for, who we share it with, and get a copy.
  • Correct. Ask us to fix anything inaccurate, incomplete or out of date.
  • Delete. Ask us to erase your personal information.
  • Portability. Ask for the information you gave us in a structured, commonly used, machine-readable format, or ask us to send it to someone else.
  • Restrict. Ask us to pause how we use your information while a question about it is resolved.
  • Object. Object to uses based on legitimate interests, including our business outreach. Object to direct marketing and we will stop, always and without exception.
  • Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect anything done before you withdrew it.
  • Non-discrimination. We will not treat you differently, refuse you service, or charge you more for exercising any of these rights.

If you are in the EEA or the UK

All of the above are statutory rights under the GDPR and UK GDPR. You also have the right to lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office at ico.org.uk. We would ask that you raise it with us first so we can put it right.

If you are in California

You have the rights to know, delete, correct, and to opt out of the sale or sharing of personal information. As stated in section 7, we do not sell or share personal information, so there is nothing to opt out of, and we do not use or disclose sensitive personal information for purposes that require a right to limit. We honour Global Privacy Control signals sent by your browser as a valid opt-out request. You may use an authorised agent to make a request on your behalf, with proof of their authority.

If you are in Australia

You may access and correct your personal information, and complain to us about how we have handled it. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

12. How to exercise your rights

Email [email protected] and tell us what you want. There is no form to fill in and no fee.

We may need to verify your identity before acting, particularly for access or deletion requests, and will ask only for what is necessary to do that. We respond within 30 days for requests under the GDPR or UK GDPR, within 45 days for requests under the CCPA, and within 30 days for requests under the Australian Privacy Act — extending only where the law permits and telling you if we do.

13. Cookies and tracking

Analytics cookies do not run until you accept them, and nothing non-essential is set if you decline or ignore the banner. The full detail, including how to change your mind, is in our Cookie Policy.

14. Children

This is a business-to-business service and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.

15. Automated decisions and AI tools

We do not make decisions producing legal or similarly significant effects about you by automated means alone, and we do not profile you in that way.

Our work necessarily involves querying AI assistants and search engines about businesses, and we use AI tools to help analyse and draft. A human reviews the output before it reaches you. We do not enter client confidential information or personal information into public AI tools in a way that would allow it to be used to train third-party models.

16. Data breaches

If a breach occurs that is likely to result in serious harm or a risk to your rights, we will notify the relevant regulator and affected individuals within the timeframes the applicable law requires — including 72 hours to a supervisory authority under the GDPR, and as soon as practicable under the Notifiable Data Breaches scheme in Australia.

17. Changes to this policy

We may update this policy. The current version is always on this page with the date it was last updated. If a change materially affects your rights, we will take reasonable steps to tell you directly.

18. Complaints

Email [email protected] with the detail of your concern. We will acknowledge it, investigate, and write back with the outcome. If you are not satisfied you can escalate to the regulator for your jurisdiction, as set out in section 11.

This policy is written to be genuinely useful and to reflect current practice under the privacy laws named in section 2. It is not legal advice, and it is not a substitute for a review by a qualified practitioner in your jurisdiction.

Legacy Creators: gold wings above the words Legacy Creators in script and small caps

Legacy Creators

Answer engine optimisation and search engine optimisation, from Melbourne, Australia, for businesses anywhere.

ABN 42 627 319 380

Contact

  • [email protected]
  • Book a discovery call
  • Free AI visibility check

Legal

  • Privacy Policy
  • Cookie Policy
  • Terms of Use & Disclaimer

We respectfully acknowledge the Traditional Custodians of the lands on which we work and pay our respects to the elders past, present and emerging.

© 2026 Legacy Creators. Legacy Creators is the trading name of Arthur de Paula Filiberto, ABN 42 627 319 380.

We use analytics cookies to understand how this site is used. They are switched off until you accept. Read our Cookie Policy.