ENTERPRISE STRATEGY + INTEGRATION
Calm Agency · Information handling

Data security and privacy.

We ask for the information we need, use it for the work agreed and take care with who can access it.

Effective 29 September 2026 · Public statement · Reviewed as our services and systems change

What this website collects

Our contact form asks for your first and last name, email address and message. Your organisation name is optional. We use these details to read and respond to your enquiry and, if appropriate, discuss potential work. Form submissions are held in Wix Forms & Submissions and may also generate email notifications to our business mailbox. Wix and our email provider process information needed to operate these services. Website services may also process technical information, such as device and connection data, to deliver and protect the site.

Please do not enter identity documents, passwords, health information, protected government information, client case records or other sensitive material in the contact form. We will arrange a suitable exchange method if the work requires such information. The public website is not a repository for client files, regulatory case records or project datasets. It does, however, retain the personal details you choose to submit in an enquiry.

How we use and share information

We use enquiry information to respond, arrange discussions, administer potential or agreed engagements and meet applicable legal obligations. We do not sell contact details. Access may be needed by our authorised people, relevant specialists engaged for the work, and service providers operating the website, email or agreed project systems. We limit access and sharing to the purpose for which the information is needed, subject to law and the engagement terms. We do not assume that a contact-form enquiry gives permission to send marketing messages.

Our website and communications providers may process or store information outside Australia. We check the relevant provider arrangements and any client restrictions before using a service for project information. We do not promise Australian-only storage unless an engagement specifically establishes and verifies it.

Client and project information

Before receiving substantive project information, we agree the scope, approved systems, permitted users, classification and handling requirements, subcontractor arrangements, reporting duties and what happens to records at the end of the engagement. We follow the client’s lawful information-handling requirements and the applicable contract. Trusted specialists receive only the information needed for their agreed role and are subject to appropriate confidentiality and security requirements. Client information is not published or used for unrelated work without authority.

Security and retention

We manage access to information, use the controls available in the approved services, and review access when an engagement or role changes. We keep enquiry and project information only while there is a legitimate business, contractual or legal reason to do so. We then delete, return or securely dispose of it as appropriate, taking account of any lawful records or evidence-preservation requirement. An engagement may set more specific controls and retention periods.

If something goes wrong

Everyone working with us must promptly report suspected loss, mistaken disclosure, unauthorised access or misuse of information. We respond in four steps:

  1. Contain: limit further access or disclosure, secure affected accounts and systems, preserve evidence and involve the provider or client where needed.
  2. Assess: identify what happened, whose information is affected, the risk of harm, the relevant law and contract terms, and steps that reduce that risk.
  3. Notify: inform an affected client in line with our contract, and notify individuals, the Office of the Australian Information Commissioner or other authorities where required. We explain what happened, what we are doing and what affected people can do to protect themselves.
  4. Recover and review: address the cause, restore safe operations, record decisions and improve controls and procedures.

Where the Australian Notifiable Data Breaches scheme applies, we assess a suspected eligible breach promptly and within the statutory assessment period. If we reasonably believe an eligible breach has occurred, we notify the Commissioner and affected individuals as soon as practicable. Other client or government reporting timeframes may be shorter and are handled under the relevant agreement.

Access, correction and concerns

To ask what personal information we hold about you, request a correction or raise a privacy or security concern, email info@calmagency.com. We will review the request, verify identity where needed and respond in accordance with applicable law and our contractual duties. If you are dissatisfied with our response and the Privacy Act applies to the matter, you may contact the Office of the Australian Information Commissioner.

Our approach is informed by the Australian Privacy Principles and the OAIC’s data breach response guidance. The legal duties that apply depend on the organisation, information and engagement.