Privacy Policy
Last updated: 1 August 2026
The short version
- We collect only what we need to answer you, prepare the free audit you asked for, and deliver work to clients.
- We do not sell your personal information, and we do not share it for cross-context behavioural advertising.
- Analytics cookies stay switched off until you accept them.
- You can ask us for a copy of your data, ask us to correct or delete it, or tell us to stop contacting you — at any time, free of charge.
- To do any of that, email [email protected].
This policy explains how Legacy Creators handles personal information. It applies to this website, to the free AI visibility audit, to discovery calls, to our client work, and to our business outreach.
- Who we are and how to contact us
- Which privacy laws apply
- What we collect
- Where we get it from
- What we use it for, and our legal basis
- Marketing and business outreach
- Who we share it with
- International transfers
- How long we keep it
- How we protect it
- Your rights
- How to exercise your rights
- Cookies and tracking
- Children
- Automated decisions and AI tools
- Data breaches
- Changes to this policy
- Complaints
1. Who we are and how to contact us
Legacy Creators is the trading name of Arthur de Paula Filiberto, a sole trader registered in Australia under ABN 42 627 319 380, based in Melbourne, Victoria. We serve clients in Australia and internationally.
For data protection purposes, Legacy Creators is the controller of the personal information described in this policy — meaning we decide why and how it is handled. When we deliver services to a client and handle personal information on their behalf and under their instructions, we act as a processor for that client instead, and the client's own privacy policy governs that information.
Contact for all privacy matters: [email protected]. We aim to respond within 5 business days, and within the timeframes required by law in all cases.
2. Which privacy laws apply
We are based in Australia and work with clients in multiple countries, so more than one privacy regime can apply depending on where you are. We have written this policy to meet the strictest of them, and we apply the same standards to everyone regardless of location.
- Australia. The Privacy Act 1988 (Cth) and the Australian Privacy Principles. As a small business operator we may currently fall within the small business exemption in that Act, but we do not rely on it: we handle personal information as though the Australian Privacy Principles apply to us in full.
- European Economic Area. The General Data Protection Regulation (EU) 2016/679, where we offer services to, or monitor people in, the EEA.
- United Kingdom. The UK GDPR and the Data Protection Act 2018.
- California. The California Consumer Privacy Act as amended by the California Privacy Rights Act, where it applies to us.
- Canada. The Personal Information Protection and Electronic Documents Act (PIPEDA), where it applies.
Where a law that applies to you gives you stronger rights than this policy describes, that law prevails and we will honour it.
3. What we collect
We collect only what we need. We do not ask for, and do not want, sensitive information — health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric or genetic data, precise geolocation, or government identifiers. Please do not send it to us.
| Category | Examples |
|---|---|
| Identity and contact | Name, email address, phone number if you give it, job title, employer or business name |
| Business information | Your website address, industry, approximate size, the questions your customers ask, competitors you name |
| Correspondence | Emails, form messages, notes we take during a discovery call, and anything you type into a free-text field |
| Booking information | The time slot you select, your time zone, and anything you enter when booking a call |
| Technical and usage | IP address, approximate location derived from it, browser and device type, pages viewed, referring site, time on page |
| Client engagement records | Contracts, scope documents, deliverables, invoices and payment records, access credentials you choose to share with us |
A note on audits. The free AI visibility audit examines publicly available information about a business — its website, its listings, its reviews, and what AI assistants say about it. Where that public information happens to include a person's name, for example a founder named on an "about" page, it forms part of the audit record.
4. Where we get it from
- Directly from you — when you submit a form, book a call, email us, or become a client.
- Automatically — through cookies and similar technologies when you use this site, subject to your consent choice.
- From public sources — company websites, public business directories, professional networking profiles, review platforms and search results, when we research a business we may be able to help.
- From your organisation — if a colleague books a call or shares your details as a contact for a project.
5. What we use it for, and our legal basis
Where the GDPR or UK GDPR applies, we must have a lawful basis for each use. This table sets out ours. Where those laws do not apply, the purposes still describe everything we do with your information.
| What we do | Why | Legal basis |
|---|---|---|
| Prepare and send the free audit | Because you asked us to | Steps taken at your request before entering a contract; consent |
| Reply to enquiries, hold discovery calls | To answer you and work out whether we can help | Steps taken at your request before entering a contract; legitimate interests in responding to enquiries |
| Deliver services to clients | To do the work and manage the engagement | Performance of a contract |
| Send invoices, keep tax and accounting records | To get paid and to meet record-keeping obligations | Performance of a contract; legal obligation |
| Contact businesses we think we can help | To offer a relevant service, with a completed audit attached | Legitimate interests in business development, balanced against your interests — see section 6 |
| Send marketing emails | To share useful material and offers | Consent, or legitimate interests where you are an existing client and can opt out at any time |
| Measure how the website is used | To understand what people read and improve the site | Consent |
| Keep the site secure and available | To prevent abuse, spam and attacks | Legitimate interests in protecting our systems |
| Establish, exercise or defend legal claims | To protect our position if a dispute arises | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is overridden by your rights, and concluded it is not for the limited, business-context uses described. You can object to any of it — see section 11 — and we will stop unless we have compelling grounds to continue.
6. Marketing and business outreach
We contact businesses that we believe we can genuinely help, usually with a completed visibility audit already attached so the message has value whether or not you reply. We use business contact details obtained from public sources or given to us directly.
- Every marketing message identifies who we are and how to reach us.
- Every marketing message contains a working unsubscribe mechanism, honoured promptly and at no cost to you.
- Tell us to stop and we stop — including by simply replying and saying so.
- We do not buy marketing lists, and we do not send bulk untargeted mail.
We comply with the Spam Act 2003 (Cth) in Australia, the CAN-SPAM Act in the United States, Canada's Anti-Spam Legislation, and the consent requirements of the GDPR and the Privacy and Electronic Communications Regulations where those apply. Where the law requires prior consent for electronic marketing, we obtain it before sending.
7. Who we share it with
We do not sell personal information, and we have not sold or shared personal information for cross-context behavioural advertising in the preceding twelve months. We disclose it only to the service providers we need to run the business, each bound to protect it and to use it only for the service they provide to us.
| Provider | What it does | Where it processes data |
|---|---|---|
| Cloudflare | Website hosting, delivery and security | Global network, including the United States |
| Web3Forms | Delivers website form submissions to our inbox | United States |
| Calendly | Appointment booking and scheduling | United States |
| Google Workspace | Email, documents and file storage | Global, including the United States |
| Google Analytics | Website usage measurement, only after you consent | Global, including the United States |
We may also disclose personal information:
- to professional advisers such as accountants and lawyers, under a duty of confidentiality;
- where we are required to by law, court order or a regulator;
- to protect our rights, property or safety, or those of others;
- to a buyer or successor if the business is sold or restructured, subject to this policy continuing to apply.
8. International transfers
We are in Australia, and our providers operate globally. Your information will therefore be transferred across borders, including to the United States.
Where personal information is transferred out of the EEA or the UK, we rely on appropriate safeguards under the GDPR — most commonly the European Commission's Standard Contractual Clauses, the UK International Data Transfer Addendum, or a finding of adequacy for the receiving country. Where personal information is disclosed outside Australia, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles.
You may request details of the safeguards that apply to a particular transfer by emailing us.
9. How long we keep it
We keep personal information only as long as we need it, then delete or anonymise it. These are our standard periods.
| Record | Kept for |
|---|---|
| Audit request or enquiry that does not become a client | 24 months from last contact |
| Marketing contact details | Until you unsubscribe, then a minimal suppression record kept indefinitely so we do not contact you again |
| Client files, contracts and correspondence | 7 years after the engagement ends |
| Invoices and financial records | 7 years, to meet Australian tax record-keeping requirements |
| Booking records | 24 months |
| Website analytics | 14 months |
| Server and security logs | Up to 12 months |
We may keep information longer where we need it for a legal claim, or where the law requires it. If you ask us to delete your information we will do so unless one of those applies, and we will tell you if it does.
10. How we protect it
We take reasonable technical and organisational measures appropriate to the risk, including encrypted connections to this website, multi-factor authentication on our business accounts, access limited to those who need it, reputable providers with their own security programmes, and deletion of information we no longer need.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If you share credentials or access to your systems with us for a project, we will handle them confidentially and ask that you revoke that access when the work ends.
11. Your rights
These rights are available to everyone we deal with, wherever you live. Some of them come from a specific law, and where that law adds conditions we will explain them when you ask.
- Know and access. Ask what personal information we hold about you, where we got it, what we use it for, who we share it with, and get a copy.
- Correct. Ask us to fix anything inaccurate, incomplete or out of date.
- Delete. Ask us to erase your personal information.
- Portability. Ask for the information you gave us in a structured, commonly used, machine-readable format, or ask us to send it to someone else.
- Restrict. Ask us to pause how we use your information while a question about it is resolved.
- Object. Object to uses based on legitimate interests, including our business outreach. Object to direct marketing and we will stop, always and without exception.
- Withdraw consent. Where we rely on consent, withdraw it at any time. This does not affect anything done before you withdrew it.
- Non-discrimination. We will not treat you differently, refuse you service, or charge you more for exercising any of these rights.
If you are in the EEA or the UK
All of the above are statutory rights under the GDPR and UK GDPR. You also have the right to lodge a complaint with your national supervisory authority, or with the UK Information Commissioner's Office at ico.org.uk. We would ask that you raise it with us first so we can put it right.
If you are in California
You have the rights to know, delete, correct, and to opt out of the sale or sharing of personal information. As stated in section 7, we do not sell or share personal information, so there is nothing to opt out of, and we do not use or disclose sensitive personal information for purposes that require a right to limit. We honour Global Privacy Control signals sent by your browser as a valid opt-out request. You may use an authorised agent to make a request on your behalf, with proof of their authority.
If you are in Australia
You may access and correct your personal information, and complain to us about how we have handled it. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
12. How to exercise your rights
Email [email protected] and tell us what you want. There is no form to fill in and no fee.
We may need to verify your identity before acting, particularly for access or deletion requests, and will ask only for what is necessary to do that. We respond within 30 days for requests under the GDPR or UK GDPR, within 45 days for requests under the CCPA, and within 30 days for requests under the Australian Privacy Act — extending only where the law permits and telling you if we do.
13. Cookies and tracking
Analytics cookies do not run until you accept them, and nothing non-essential is set if you decline or ignore the banner. The full detail, including how to change your mind, is in our Cookie Policy.
14. Children
This is a business-to-business service and is not directed at children. We do not knowingly collect personal information from anyone under 16. If you believe a child has given us information, email us and we will delete it.
15. Automated decisions and AI tools
We do not make decisions producing legal or similarly significant effects about you by automated means alone, and we do not profile you in that way.
Our work necessarily involves querying AI assistants and search engines about businesses, and we use AI tools to help analyse and draft. A human reviews the output before it reaches you. We do not enter client confidential information or personal information into public AI tools in a way that would allow it to be used to train third-party models.
16. Data breaches
If a breach occurs that is likely to result in serious harm or a risk to your rights, we will notify the relevant regulator and affected individuals within the timeframes the applicable law requires — including 72 hours to a supervisory authority under the GDPR, and as soon as practicable under the Notifiable Data Breaches scheme in Australia.
17. Changes to this policy
We may update this policy. The current version is always on this page with the date it was last updated. If a change materially affects your rights, we will take reasonable steps to tell you directly.
18. Complaints
Email [email protected] with the detail of your concern. We will acknowledge it, investigate, and write back with the outcome. If you are not satisfied you can escalate to the regulator for your jurisdiction, as set out in section 11.
This policy is written to be genuinely useful and to reflect current practice under the privacy laws named in section 2. It is not legal advice, and it is not a substitute for a review by a qualified practitioner in your jurisdiction.