Version  1.0
Effective  26 August 2026
New South Wales

underseage.studio

Privacy
policy.

Joshua Seage, trading as UNDER SEAGE. ABN 24 715 756 276.
Version
1.0
Effective
26 August 2026
We never
Sell your
information
Contact
josh@
underseage.studio

Privacy policy  路  version 1.0

The short version.

Who holds it
Joshua Seage, trading as UNDER SEAGE. ABN 24 715 756 276. Ballina, New South Wales, Australia.
Contact
josh@underseage.studio
Effective
26 August 2026. Version 1.0.
Not legal advice. This is an underseage.studio template. It is written for Australian law and reflects our own practice. It is not legal advice. If your situation is unusual, or the amount at stake is large, have a lawyer look at it before you sign.

The commitments, with dates on them

What we promise, and how fast.

What we promiseHow fastClause
We stop emailing you when you ask 5 business days, usually the same day 9.6
The unsubscribe route stays open at least 30 days after the email was sent 9.7
We assess a suspected data breach started immediately, finished in 5 business days 16.2
We tell an affected client about an incident 2 business days, finished assessment or not 16.3
We answer a request for access or correction 30 days, free 17.2
We acknowledge a privacy complaint 5 business days 18.2
We answer a privacy complaint in writing 30 days 18.2

Contents

Appendix A: why we follow the Privacy Act when it does not bind us  路  Version history

  1. What this policy covers

    1. Who holds your information. The legal entity is Joshua Seage, an individual, ABN 24 715 756 276, trading as UNDER SEAGE. underseage.studio is the trading name used everywhere in this policy, and they are the same person. It is a one-person design and software studio in the Northern Rivers of New South Wales. There are no employees. Some work is subcontracted, and clause 11 explains what that means for your information.
    2. What "personal information" means. Information or an opinion about an identified individual, or an individual who is reasonably identifiable. Your name, your email address, your mobile number and your photograph are all personal information. A registered ABN or a company name on its own generally is not.
    3. This policy explains what personal information we collect, why we collect it, where we keep it, how long we keep it, who else can see it, and what you can do about it.
    4. It applies to underseage.studio, to tradies.underseage.studio, to every enquiry and intake form we run, to emails you send us, and to the work we do for our clients.
    5. Websites we build for clients are governed by that client's own privacy policy, not this one. The business named on the site is responsible for what it does with your enquiry. Where we host that site on our own account, we also hold the server logs, including your IP address, on that business's behalf. We handle them under clause 15.
  2. Our position under the Privacy Act

    1. The Privacy Act 1988 (Cth) does not legally bind a business our size. We follow it anyway. Appendix A explains exactly why, and what that commits us to.
    2. When this policy refers to the Australian Privacy Principles, it means the 13 rules in the Privacy Act about collecting, keeping, using and handing over personal information.
    3. These commitments are contractual, not decorative. Clauses 4, 12, 13, 14, 15, 16 and 17 are incorporated into every underseage.studio engagement. A client can enforce them against us as contract terms, in the courts of New South Wales, whether or not the Office of the Australian Information Commissioner accepts jurisdiction over us.
    4. One exception works project by project. If we deliver work connected to a Commonwealth government funding contract, that contract can extend Privacy Act obligations to us for that project. The rest of the business stays exempt. We ask about this before any government-funded work starts, and we do not assume either way.
  1. What we collect

    1. From enquiry and intake forms. Your name, email address, phone number, business name, trade or sector, service area, website address, ABN, budget range, and whatever you write in the free-text fields about your project. Some forms invite you to share links to logos, photos and brand files.
    2. From the chat assistant on tradies.underseage.studio. Whatever you type into it, plus our replies. Clause 4 sets out how that works, how long we keep it, and how to have a transcript deleted.
    3. From working with you. Meeting notes, discovery answers, feedback, correspondence, and the account details you give us so we can do the work.
    4. From payments. Billing name, billing email, ABN and payment records. Card numbers go to Stripe and never reach us. We see the last 4 digits and the payment status, nothing more.
    5. Automatically, when you visit. IP address, browser and device type, pages viewed, the page you arrived from, and the time of your visit. Clause 5 covers cookies and analytics.
    6. From public sources, for outreach. Business name, business email address, business phone number, website address and the name of the owner or contact person, taken from a business's own website or a public listing. Always by hand, and never bought. Clause 9 sets out the rules we follow.
    7. We do not collect sensitive information about you. We do not ask for your health information, racial or ethnic origin, religious or political views, sexual orientation, criminal record, tax file number or government identifiers. Please do not send them to us. If you do send something, we will delete it, unless it has already become part of a tax or financial record we are legally required to keep. In that case we restrict access to it and delete it as soon as that obligation ends.
    8. Please do not send us passwords by email. When we need access to your systems we will give you a safe channel to send credentials through. Live passwords sitting in an email thread are the single most common way a small business gets hurt.
    9. If your business holds sensitive information about your own customers, and the work needs us to touch it, tell us before we start. Health and injury records, disability or NDIS records, and anything similar all count. We will put a written Data Handling Schedule in place first (see clause 12.4). Then we limit access to the one person doing the work, and delete our copy at the end of the engagement. Health service providers are covered by the Privacy Act at any size, so this matters for your compliance as much as ours.
  1. The chat assistant on tradies.underseage.studio

    1. tradies.underseage.studio runs a chat assistant. It answers questions about what we do and helps you describe the job you want done.
    2. We keep transcripts for 90 days, then delete them. That is long enough to answer a follow-up and to fix the assistant when it gets something wrong.
    3. Joshua Seage reads them. Not every one, but any of them. That is how we learn what people actually ask for. Nobody else sees them.
    4. They are not used to train an AI model. We do not do it. Anthropic PBC, whose model powers the assistant, does not train on the traffic our assistant sends it. If either of those ever changes, we will update this policy before it takes effect.
    5. The conversation is not linked to you unless you type your details into it. The assistant does not ask for your name and it does not know who you are.
    6. Please do not type sensitive information into it. No injuries, no medical detail, no legal dispute, no bank or card numbers, no passwords. If the job involves any of that, email josh@underseage.studio instead and we will set up a safe way to handle it.
    7. To have a transcript deleted before the 90 days is up, email josh@underseage.studio and tell us roughly when you used the chat. We will find it and delete it.
  2. Cookies and analytics

    1. underseage.studio uses Google Analytics 4. It sets cookies and reports on how people find and move through the site: pages viewed, approximate location, device, and the source that referred you.
    2. We use it to see which pages actually help people, not to identify you. We have not linked it to advertising, we do not run advertising pixels, and we do not build profiles of visitors.
    3. Our pages load fonts from Google Fonts. That request tells Google your IP address, in the same way any request to any server does.
    4. Our forms record your IP address briefly to rate-limit spam submissions.
    5. There is no cookie consent banner, because Australian law does not require one and we would rather explain what happens than make you dismiss a pop-up. If you want out, you can block or clear cookies in your browser, use private mode, or install the Google Analytics opt-out browser add-on at tools.google.com/dlpage/gaoptout. Or just email josh@underseage.studio and say you would rather not be counted, and we will exclude your IP address. The site works normally either way.
  1. Cookies and analytics, continued

    1. If we ever add advertising or retargeting tracking, we will update this policy first and say so clearly.
    2. Visiting from outside Australia. This policy is written for Australian law. If you are in the EU or the UK, different rules apply to you. Email josh@underseage.studio and we will delete anything the analytics collected about your visit. We do not target or market outside Australia.
  1. Why we collect it

    1. To answer your enquiry and work out whether we can help.
    2. To quote, scope, build, launch, support and invoice the work.
    3. To keep our own records: the client relationship, the deal history, what was agreed, what was delivered.
    4. To meet our tax and record-keeping obligations. Tax invoices and financial records are kept for at least 5 years, as the ATO requires.
    5. To improve how we work, using what we learn rather than who said it.
    6. We do not sell personal information. We do not trade it, rent it, or hand it to a data broker. We never will. That is not a slogan. It is the specific thing that would drag us inside the Privacy Act's exception for businesses that trade in personal information, and we have no interest in going there.
  2. Dealing with us anonymously or under a business name

    1. You can ask us a general question by email without telling us who you are, and we will answer it.
    2. You can also deal with us under your business name or a work alias for anything short of a contract or an invoice. A sole trader who would rather be "Northside Plumbing" than a personal name is welcome to be.
    3. We only need your legal name at the point we issue a tax invoice or sign an agreement. The ATO requires it, and a contract needs a real party. There is no way to build a website for someone we cannot identify or bill.
  3. What happens if you do not give it to us

    1. Giving us information is voluntary. Every field on our forms that is not marked required can be left blank.
    2. If you leave out the essentials, the consequence is practical rather than punitive: we cannot quote accurately, or we cannot reach you to reply. Nothing else follows from it.
  1. Outreach emails, and how to stop them

    1. We run a daily pipeline that rebuilds a small number of Northern Rivers business websites as a free demonstration, and emails the business to show them. If you received one of these, here is exactly where it came from.
    2. We take business contact details from a business's own website or a public directory listing, by hand, one at a time. We do not buy lists and we do not use address-harvesting software.
    3. We do not email an address where the page it is published on says the business does not want unsolicited commercial email. If you say no on your own website, that is a no, and we treat it as one.
    4. We only send to a business address that has been published openly, and only about something relevant to that person's business role. Those two tests, plus the one in clause 9.3, are the three things the Spam Act 2003 (Cth) requires before consent can be inferred from a published address. It is not the same as you opting in, and we do not pretend it is.
    5. Every outreach email identifies underseage.studio and Joshua Seage by name, gives working contact details, and carries an unsubscribe option that costs you nothing and asks you for nothing.
    6. Reply with "unsubscribe", or "stop", or anything else that plainly says no. We action it within 5 business days, and usually the same day. You will not be asked why, and you will not be emailed again.
    7. The unsubscribe route stays open for at least 30 days after the email was sent, which is what the Spam Act requires. In practice it never closes, because it is a reply to a real mailbox read by one person.
    8. If you would rather not be contacted at all, email josh@underseage.studio and say so. We will add you to a do-not-contact list and keep only what is needed to honour that. We do not run a marketing newsletter. If we ever start one it will be opt-in, and this policy will be updated before the first send.
  2. Who we disclose it to

    1. We disclose personal information only to the service providers listed below, to a subcontractor under clause 11, to you, or where we are required to by Australian law.
    2. These are the third-party services we use, what they hold, where they hold it, and how long. This list is current at the effective date of this policy and we update it when our tools change.

The clause 10.2 table runs over the next two pages. Clauses 10.3 to 10.5 follow it.

Clause 10.2  路  part one of two

Who we disclose it to, continued.

Service provider What it holds Where How long
Vercel Inc. (our account) Hosting for underseage.studio, tradies.underseage.studio, and client sites hosted on our account. Server logs including IP addresses. United States Vercel's own log retention, which we do not set. We keep no separate copy.
Vercel Inc. (your own account) Nothing of ours. Where a client site runs on the client's own Vercel account, the client holds the logs and we hold only the access they give us. United States Set by the client, not by us.
Notion Labs, Inc. Enquiries submitted through the underseage.studio contact form. United States Per clause 14: 12 months if the enquiry went nowhere, 7 years if it became a job.
Resend, Inc. Sends us the alert email that says a new enquiry has arrived. It carries the alert, not the enquiry record. United States Delivery logs only, held by Resend. The enquiry record lives in Notion.
FormSubmit Passes intake form and tradie intake form submissions through to our inbox. It is the delivery pipe, not a store. United States Our copy is the email in Gmail, covered by clause 14.
Google LLC (Workspace and Gmail) The josh@underseage.studio mailbox: every email you send us and we send you. United States Per clause 14: 12 months for a dead enquiry, 7 years for a client thread.
Google LLC (Analytics) Site usage data, including a truncated IP address. See clause 5. United States 14 months. That is the retention setting we have chosen.

Clause 10.2  路  part two of two

Service provider What it holds Where How long
Google LLC (Fonts) Your IP address, at the moment a page requests a font. United States Set by Google. We receive nothing back and store nothing.
Google LLC (Calendar and Search Console) Calendar holds meetings, including your name and email if we booked one with you. Search Console holds search statistics about our own site, not personal information about you. United States Calendar entries sit inside the client record, per clause 14.
Anthropic PBC Powers the chat assistant on tradies.underseage.studio. Holds what you type while the conversation runs. United States Our transcript copy: 90 days, per clause 4.
Stripe (Stripe Payments Australia Pty Ltd and Stripe, Inc.) Payment processing, billing records, tax invoices. Australia and the United States 7 years. These are financial records we are required to keep.
Cal.com, Inc. Booking an intro call: your name, email and chosen time. United States 12 months, then deleted with the enquiry it belongs to.

Where a provider sets its own retention and we cannot change it, we say so rather than quote a number we do not control. In those cases we keep no separate copy of our own.

  1. Who we disclose it to, continued

    1. Your client records also sit in our own customer record system, which runs locally on Joshua Seage's own computer in Australia, backed up to encrypted storage.
    2. We may disclose personal information where an Australian law, a court or a regulator requires it. If that ever happens and we are permitted to tell you, we will.
    3. If underseage.studio is ever sold or transferred, we will tell every person whose information would pass to the buyer at least 30 days before completion, not just current clients. We will require the buyer in writing to be bound by this policy. You can ask us to delete your information before the transfer and we will, subject to clause 17.6.
  1. Subcontractors

    1. We are one person and sometimes bring in a subcontractor: a developer, a copywriter, a photographer.
    2. A subcontractor signs a written confidentiality and data handling agreement before they are given any access to your systems or your information. It binds them to the same standard set out in this policy.
    3. We stay responsible to you for what a subcontractor does with your information. That responsibility is not passed down the chain.
  2. Overseas disclosure

    1. Most of the services in clause 10 store information outside Australia, mainly in the United States. Using them is a disclosure of personal information overseas.
    2. Before we adopt a tool that will hold personal information, we check three things. Does the provider publish its own security and privacy commitments? Does it have a credible track record? Is it a reputable operator rather than the cheapest option available?
    3. We are straight about the limit of that. One person cannot audit a large overseas platform, and we are not going to claim otherwise. What we can do is name every provider we use, tell you what it holds and where it sits, and let you make your own assessment. That is what the table in clause 10 is for. Nothing in this clause reduces the rights you have under clause 19.
    4. If you are a client covered by the Privacy Act and you need this documented for your own compliance file, ask us. We will issue a current Data Handling Schedule for your engagement, naming the specific tools used on your project.
  3. How we hold and protect it

    1. Devices are encrypted at rest, password protected, and locked when unattended.
    2. Accounts use unique passwords held in a password manager, with multi-factor authentication turned on wherever the platform offers it.
    3. Access is limited to what is needed to do the work. A subcontractor gets access to one project, not to everything.
    4. Client credentials are never sent or stored in plain email.
    5. Backups are encrypted.
    6. No system is perfectly secure, and we will not pretend otherwise. What we commit to is reasonable, current care, and honest disclosure if something goes wrong. On top of that sit the rights in clause 19. We do not limit them, and we could not limit them if we tried.

Clause 14

How long we keep it.

14.1   Information that is no longer needed gets destroyed or de-identified. Here is what that means in practice, with real numbers rather than "as long as necessary".

What it is How long we keep it Why that length
An enquiry or intake form that went nowhere 12 months from the last message between us Long enough for you to come back to us, short enough not to hoard
A chat transcript from tradies.underseage.studio 90 days Enough to answer a follow-up and fix the assistant. See clause 4
Prospect contact details taken from a public source, where you never replied Deleted at the next quarterly sweep There is nothing to keep
The do-not-contact list Indefinitely, and only the address plus the date Deleting it would put you back on the list, which defeats the point
Client records: contract, project record, correspondence, meeting notes, discovery answers 7 years from the end of the engagement Covers the 5-year ATO record-keeping period and the 6-year limitation period in NSW for a contract claim
Tax invoices and financial records At least 5 years, held inside the 7-year client record The ATO requires it
Your credentials and our access to your systems Deleted immediately at the end of the engagement We should not be able to get in once the work is done
Google Analytics 4 data 14 months That is the retention setting we have chosen in GA4
Server logs on sites we host Vercel's own retention. We keep no separate copy We do not control it, so we do not claim a number
  1. How long we keep it, continued

    1. The quarterly sweep is a real task with a real date. It is a recurring reminder in Joshua Seage's calendar on the first business day of January, April, July and October. It clears expired enquiries, expired transcripts and unanswered prospect records. It is not a promise nobody keeps.
    2. When we delete something it goes from live systems straight away, and from our encrypted backups within 90 days, because the backups roll on a 90-day cycle.
    3. If a record is caught by a legal hold, a dispute, or a tax obligation, we keep it until that ends and then delete it. We do not use that as a reason to keep everything else.
    4. You can ask us to delete sooner than any of these. Clause 17.6 is how.
  2. Information we handle for our clients

    1. When we build or maintain something for a client, we often touch personal information belonging to that client's own customers. That means enquiry records, mailing list subscribers, e-commerce customer and order data, and the server logs of any site we host for them.
    2. In that situation the client is the business responsible for that information. We handle it only to deliver the work.
    3. We do not use it for our own purposes and we do not market to it. We do not keep it after the engagement ends, beyond what the client asks us to keep.
    4. If you are one of our client's customers and you want your information accessed, corrected or deleted, contact that business directly. If you contact us instead, we will pass your request to them promptly and tell you we have done so.
    5. When an engagement ends, we hand back anything you ask for and delete your credentials and our access immediately. We keep your own contact details and project record for 7 years under clause 14, unless you ask us to delete them sooner. Clause 17.6 is how you ask.
  1. If something goes wrong: our data breach commitment

    1. The data breach reporting rules in the Privacy Act do not currently bind us, for the reason set out in Appendix A. We commit to acting as though they do.
    2. If we become aware of grounds to suspect that personal information we hold has been accessed, disclosed or lost without authorisation, we start assessing immediately. We finish that assessment within 5 business days. The Act allows a covered entity 30 days. We chose 5 because that is what one person with a short client list can genuinely do, and because a covered client needs to hear from us well inside their own 30-day clock.
    3. If the information belongs to a client, we tell that client within 2 business days of becoming aware of the incident. We do that whether or not the assessment is finished, and we say what happened and what information was involved.
    4. If the breach is likely to cause serious harm, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable. We will tell you:
      • what happened
      • what information was involved
      • what we have done about it
      • what we recommend you do
    5. We will not wait to be asked, and we will not quietly fix it and say nothing.
  2. Getting access to your information, and correcting it

    1. You can ask us for a copy of the personal information we hold about you. Email josh@underseage.studio.
    2. It is free. We respond within 30 days, and usually much sooner.
    3. We may ask you to confirm your identity first, so that we do not hand your information to someone else.
    4. If anything we hold is wrong, out of date, incomplete or misleading, tell us and we will correct it.
    5. We can only refuse access in narrow circumstances. An example is where giving it to you would unreasonably affect someone else's privacy, or where we are legally required to withhold it. If we ever refuse, we tell you in writing which reason applies, and clause 18 tells you what to do about it. We do not get to be the final word on our own refusal.
    6. You can ask us to delete personal information we hold about you, at any time, and we will unless we are legally required to keep it. Tax invoices and financial records are the main thing we cannot delete on request, because the ATO requires us to keep them for 5 years. Where that applies we restrict access to the record and delete it as soon as the obligation ends.
  1. Complaints

    1. Start with us. Email josh@underseage.studio with "Privacy complaint" in the subject line, or email us and ask for a postal address if you would rather write. It comes to Joshua Seage directly. There is no queue and no ticket number.
    2. We acknowledge your complaint within 5 business days and give you a written response within 30 days, telling you what we found and what we are doing about it.
    3. If you are not satisfied, you can take it to the Office of the Australian Information Commissioner. You do not need our permission, and nothing in this policy limits that right or any other right you have to pursue this elsewhere.
      • Website: www.oaic.gov.au
      • Phone: 1300 363 992
      • Post: OAIC, GPO Box 5218, Sydney NSW 2001
    4. The OAIC will generally ask you to raise the complaint with us first and give us 30 days to respond, which is why clause 18.1 comes first. That is their process, not a barrier we are putting up.
    5. If the OAIC turns you away, you still have a route. The OAIC may decline a complaint about an exempt small business operator on jurisdictional grounds. We point you there anyway, because you are entitled to test it. If it does decline, the commitments in this policy are contract terms under clause 2.3 and are enforceable against us in the courts of New South Wales. Your rights under clause 19 are unaffected either way.
  1. Changes to this policy

    1. We change this policy for three reasons only: the law changes, we change a tool or a supplier, or we can improve the protections in it. We do not rewrite it to give ourselves rights we did not have when you first dealt with us.
    2. The version number and effective date at the top tell you which version you are reading. Every change is listed in the version history at the end, with a date and a plain description.
    3. If a change materially affects how we handle your personal information, we will not do it quietly. We email every affected person we have an address for before it takes effect, not only current clients. We publish the change in the version history on the same day.
    4. If a material change is not acceptable to you and you are a current client, you may end the engagement. Give us written notice within 30 days of the change taking effect. There is no termination fee, and we refund pro rata for work not yet delivered. You do not have to choose between your privacy position and your project.
    5. If you are not a client, you can ask us to delete your information under clause 17.6 instead. Superseded versions of this policy stay available on request so you can see exactly what changed.
  2. Contact us

    Name
    Joshua Seage
    Trading as
    underseage.studio
    ABN
    24 715 756 276
    Email
    josh@underseage.studio

    Email is the fastest way to reach us and it is read by one person. If you would prefer to write to us by post, email us and we will give you a postal address.

Appendix A

Why we follow the Privacy Act when it does not bind us.

    1. The Privacy Act 1988 (Cth) exempts most small business operators with an annual turnover of $3 million or less. underseage.studio is well under that threshold. So we are an exempt small business operator, on our current turnover and on the facts as at the effective date of this policy. The Australian Privacy Principles do not legally bind us.
    2. We are telling you that rather than hiding it. A privacy policy that implies a legal obligation we do not actually have would be misleading, and misleading you about our own compliance would be a poor start.
    3. We comply anyway. This is a commitment we are making to you, not a legal claim about our status. We handle personal information as if the Australian Privacy Principles applied to us, for three reasons.
      • (a) Many of our clients are covered by the Privacy Act, and they cannot meet their own obligations if their supplier does not hold the same line.
      • (b) People hand us the contents of their business. The right standard is the one we would want applied to us.
      • (c) The small business exemption is under active review. Removing it has been proposed in the Commonwealth's second tranche of privacy reform. If it goes, we do not want to be starting from nothing.
    4. The exemption can also stop applying to one project on its own. Clause 2.4 covers that, and it is the reason we ask about government funding before we start.
    5. If our turnover ever passes $3 million, or the exemption is removed, or we take on an employee, this policy stays exactly as it is. The obligations in it simply become legally binding as well as promised.

Version history

VersionDateWhat changed
1.0 26 August 2026 First published version.

underseage.studio Privacy Policy, version 1.0, effective 26 August 2026. Governed by the law of New South Wales, Australia. Nothing in this policy excludes, restricts or modifies any guarantee, right or remedy you have under the Australian Consumer Law, the Privacy Act 1988 (Cth), or any other law that cannot be excluded.