How we collect, use, and protect your personal information
Legal Document
Effective Date: 31 July 2026 | Version: 2.1 | Last Updated: 31 July 2026
Supersedes version 2.0 (last updated 5 February 2026) and version 1.0 (effective 1 July 2025).
1. Introduction
Rapid Developments Business Solutions (ABN 38 377 925 811) ("we," "us," "our") is committed to protecting the privacy and security of your personal information.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you:
Engage our business consulting or technology services
Visit our website at rapid-developments.com.au
Subscribe to our communications
Use our free online tools (such as the Undertow Check) or download our resources
Contact us through any channel
As a small sole-trader business, we fall within the small business exemption under the Privacy Act 1988 (Cth), which means we are not legally required to comply with the Australian Privacy Principles (APPs). We voluntarily align our practices with the APPs anyway, because we think it is the right way to run a business. We have not opted in to coverage under section 6EA of the Privacy Act, so this commitment is voluntary rather than something the OAIC regulates us on.
2. Information We Collect
2.1 Personal Information
We may collect the following types of personal information:
Contact Information: Email address, telephone numbers, business address
Business Information: Company details, business processes, operational data relevant to our services
Financial Information: Payment details, billing addresses, bank account details for invoicing
Technical Information: IP address, browser type, device information, website usage data
Professional Information: Professional history, qualifications, business relationships
Communication Records: Emails, meeting notes, phone call records related to our services
2.2 Information Collected Automatically
When you visit our website, we automatically collect:
IP address and approximate geographic location
Browser type and version
Operating system
Pages visited and time spent on pages
Referring website
Date and time of visits
2.3 Sensitive Information
Important Note
We do not actively collect sensitive information (such as health information, racial or ethnic origin, political opinions, religious beliefs, or sexual orientation) unless specifically required for a consulting engagement and with your explicit consent.
2.4 Information About Our Clients' Staff (On-Site Assessments)
During on-site assessments and interviews we collect limited personal information about our client's staff, such as names, roles, and notes from interviews and workplace observations about how processes are performed. With consent, we may also take photographs or recordings that incidentally capture staff.
Purpose: This information is used solely to prepare findings, reports, and recommendations for the client. Our reports focus on processes and systems rather than individuals, and we de-identify observations about individual staff members where practicable.
Notifying staff: We rely on our client to tell their staff that an assessment is taking place and that we may collect this information, and we recommend clients do so before the on-site work begins.
Retention: Photographs and recordings made on site are consent-based, stored securely with access restricted to the business owner, retained for up to 24 months after the engagement (aligned to the claims window in our engagement terms), and then deleted.
2.5 Free Tools and Downloadable Resources
When you use our free Undertow Check tool, we collect the business details you enter along with your name and email address. Your report is emailed to you, and a copy of that email is retained by us. When you request a downloadable resource (such as our example assessment report), we collect the email address you provide in order to send it.
Details collected this way are stored in our cloud-hosted customer relationship management system (Twenty CRM) and treated as a prospective client enquiry - retained for 2 years from last contact (see section 9) - unless you separately subscribe to marketing communications. Using a free tool or requesting a resource does not subscribe you to marketing.
3. How We Collect Information
We collect information through:
Direct interactions: When you contact us, engage our services, complete forms, or correspond with us
Service delivery: During assessments, on-site visits, and project work
Contracts and agreements: Through proposals, service agreements, and invoicing
Website: Through contact forms, enquiry submissions, and automated technologies (cookies)
Third-party referrals: From referrers who introduce you to us - where we receive your details this way, we will tell you where we got them when we first contact you
Publicly available sources: Business directories, company registers, LinkedIn, and other public sources
You can deal with us anonymously, or under a pseudonym, for general enquiries where that is practicable.
4. How We Use Your Information
4.1 Primary Purposes
We use your information to:
Provide business consulting and technology services
Conduct assessments and prepare reports and recommendations
Communicate with you about our services and your engagement
Process payments, invoicing, and maintain financial records
Comply with legal, regulatory, and professional obligations
Respond to enquiries and provide customer support
4.2 Secondary Purposes
With your consent, we may use information to:
Send updates about business insights, articles, and industry information
Invite you to events, workshops, or webinars
Develop case studies and testimonials (anonymised or with express permission)
Improve our services, methodologies, and website
Conduct business analytics and reporting (in aggregate, non-identifying form)
5. Information Sharing and Disclosure
5.1 Who We Share Information With
The Business Owner and Contractors: The business owner, and any contractors engaged from time to time under written confidentiality obligations, on a need-to-know basis for service delivery
Subcontractors: Specialist contractors engaged to assist with service delivery, under strict confidentiality agreements
Service Providers: Third-party service providers who support our operations (see section 6)
Professional Advisors: Our legal, accounting, and insurance advisors where necessary
Government Authorities: When required by law, regulation, or legal process
5.2 What We Do NOT Do
We Do NOT:
Sell your personal information to third parties
Share your information with competitors
Use your data for purposes unrelated to our services without consent
Share your confidential business information with other clients
6. Third-Party Services and Overseas Disclosure
6.1 Service Providers We Use
We use the following categories of third-party services to operate our business:
Service Type
Purpose
Data Location
Cloud Hosting
Website hosting, form processing, and data storage
Global CDN/edge network (Cloudflare) - data may be processed outside Australia
Font delivery (Google Fonts) - loading fonts transmits your IP address to Google
United States
6.2 Overseas Disclosure
Some of our service providers operate servers outside Australia. We take reasonable steps to ensure overseas recipients handle your information in accordance with the Australian Privacy Principles, including:
Using providers with appropriate privacy certifications (e.g., ISO 27001, SOC 2)
Selecting Australian data regions where available
Entering into data processing agreements with key providers
6.3 AI and Automation Tools
We use artificial intelligence tools to assist with service delivery - including document analysis, process mapping, drafting, and report generation - and in the administration of our business, including alongside our CRM. When using such tools:
We use AI tools (currently Anthropic's Claude) under commercial terms that prohibit the provider from training its models on our data
We do not enter client-confidential material into free or consumer AI services that lack those protections
Final outputs are reviewed by the business owner before delivery
If you have concerns about how AI is used in your engagement, raise it with us and we will agree limits and accommodate them where practicable
7. Cookies and Website Tracking
7.1 What Are Cookies
Cookies are small text files placed on your device when you visit a website. They help the website function, remember your preferences, and provide analytics.
7.2 Cookies We Use
Essential Cookies
Required for core website functionality. These cannot be disabled without affecting site operation.
Session management
Security features
Form submissions
Analytics and Conversion Cookies
Help us understand how visitors use our website and whether our advertising leads to enquiries.
Pages visited and time on site
Traffic sources and referrers
Geographic region (approximate)
Device and browser information
Whether a visit resulted in an enquiry (Google Ads conversion measurement)
We use Google Analytics 4, which does not store full IP addresses, and Google Ads conversion measurement. Data from these services is processed by Google in the United States.
Session Replay (Microsoft Clarity)
We use Microsoft Clarity, a session replay and heatmap tool provided by Microsoft Corporation. Clarity records individual browsing sessions on our website - including mouse movement, clicks, scrolling, and how you interact with each page - and produces session replays and heatmaps that we use to improve the site. This is not aggregate-only data: each recorded session can be replayed individually.
Clarity sets the cookies _clck and _clsk on your device
Microsoft receives this data as our service provider and processes it on US servers
You can opt out by blocking or deleting these cookies in your browser settings (see section 7.3), or by using a tracking-protection feature or browser extension
Cookies We Do NOT Use
Social media tracking pixels
Third-party advertising or retargeting networks (the Google Ads cookies described above are used for conversion measurement only)
7.3 Managing Cookies
You can control cookies through your browser settings:
Block all cookies (may affect website functionality)
We implement appropriate technical and organisational measures to protect your information, including:
Encryption of data in transit (SSL/TLS) and at rest where appropriate
Password-protected systems with multi-factor authentication
Access controls limiting information access to authorised personnel
Regular security assessments and updates
Secure handling and storage of any physical documents we hold
Written confidentiality obligations for any contractors engaged
Regular data backups
8.2 Data Breach Response
In the event of a data breach that is likely to result in serious harm, we will:
Take immediate steps to contain the breach and mitigate harm
Assess the breach to determine the risk of serious harm, aiming to complete that assessment within 30 days
Notify affected individuals as soon as practicable if serious harm is likely
Notify the Office of the Australian Information Commissioner (OAIC) if required
Document the breach and our response
8.3 No Guarantee
While we take security seriously, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security of data transmitted to us or stored in our systems.
9. Data Retention
We retain personal information for the following periods:
Category
Retention Period
Reason
Active client records
Duration of engagement + 7 years
Legal, professional, reference
Financial records
7 years
Tax and accounting requirements
Project deliverables
7 years post-completion
Professional liability, reference
On-site photographs and recordings
Up to 24 months after the engagement, then deleted
Aligned to the claims window in our engagement terms
Prospective client enquiries
2 years from last contact
Follow-up, business development
Marketing subscribers
Until unsubscribe + 1 year
Honour unsubscribe requests
Website analytics
Event-level data: up to 14 months (Google Analytics 4); session replays: approximately 30 days (Microsoft Clarity); aggregated statistics may be kept indefinitely in de-identified form
Trend analysis
After the retention period, we securely delete or de-identify information so it can no longer be associated with you.
10. Your Rights
10.1 Rights Under Australian Privacy Law
Under the Australian Privacy Principles you can:
Access: Request access to personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Complain: Lodge a complaint with us or the OAIC if you believe we have mishandled your information
In addition, as a matter of practice rather than statutory right, we offer to:
Deletion: Honour requests to delete your information where practicable, subject to legal and professional retention requirements
Opt-out: Remove you from marketing communications at any time
10.2 How to Exercise Your Rights
To Make a Request
Email: info@rapid-developments.com.au
We will respond to access or correction requests within 30 days. We may need to verify your identity before processing your request.
10.3 Access Requests
We will provide access to your personal information unless:
Access would pose a serious threat to life, health, or safety
Access would unreasonably impact the privacy of others
The request is frivolous or vexatious
The information relates to existing or anticipated legal proceedings between us and you, and would not be accessible through the discovery process in those proceedings
Access would be unlawful
Denying access is authorised by law
If we deny access, we will provide reasons in writing.
11. Marketing Communications
11.1 Consent-Based Marketing
We only send marketing communications (newsletters, articles, event invitations) with your express consent. Service-related communications (invoices, project updates, support responses) are not considered marketing.
11.2 Unsubscribe
You can opt out of marketing communications at any time by:
Clicking the "unsubscribe" link in any marketing email
Emailing info@rapid-developments.com.au
Contacting us directly
We will action unsubscribe requests within 5 business days.
11.3 Spam Act Compliance
All commercial electronic messages comply with the Spam Act 2003, including:
Consent obtained before sending
Clear sender identification
Functional unsubscribe facility
Accurate contact information
12. Third-Party Links
Our website and communications may contain links to third-party websites. We are not responsible for the privacy practices of these sites. We encourage you to read the privacy policies of any third-party sites you visit.
13. Changes to This Policy
We may update this Privacy Policy to reflect changes in:
Legal or regulatory requirements
Our business practices and services
Technology and security measures
Material changes will be posted on this page on 30 days' notice, with the version and date block updated. Changes do not apply retrospectively to signed agreements, which pin the version current when they were signed. We will also notify active clients by email where a change materially affects them.
We encourage you to review this policy periodically.
14. Complaints
14.1 Internal Complaints
If you have concerns about how we handle your personal information:
Contact the business owner (details below)
Describe your concern in as much detail as possible
We will investigate and respond within 30 days
If you are not satisfied with our response, you can escalate internally
14.2 External Complaints
If you are not satisfied with our response, you may lodge a complaint with:
Office of the Australian Information Commissioner (OAIC)
Privacy Officer: The business owner Email: info@rapid-developments.com.au
This policy is available in an alternative format on request.
About This Policy
This Privacy Policy is a notice explaining our practices, not a contract. Continued use of our services or website indicates you have had the opportunity to read it.