N J Shaw & J R Harder (ABN 69 566 897 562), trading as Ostley
This Privacy Policy covers J.R Harder & N.J Shaw (ABN 69 566 897 562), trading as Ostley (“Ostley”, “we”, “us”). We build and run business systems — websites, automations and internal tools — for Australian businesses. We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (the “APPs”).
This policy covers personal information we handle as our own — about people who enquire, book a call, or enter an engagement with us, and visitors to this website. It is different from data held inside a system we build or run for a client: there, the business is responsible for the information and we act on its behalf, as clause 8 sets out. “Personal information” means information about an identified individual, or one who is reasonably identifiable.
Information you give us directly: your name, contact details and business information when you enquire, book a call, or enter an engagement with us. Payment details are collected and processed by Stripe — we never see or store your card numbers. When you visit this website, our hosting infrastructure produces the minimal technical logs ordinarily generated by a web server — such as IP address, approximate location, browser type and the pages requested — used to keep the site running securely.
We collect personal information directly from you wherever we reasonably can — through the enquiry form, email, phone, and the course of an engagement. Sometimes we receive it indirectly: for example, when someone you deal with passes on your details, or when information reaches a system we run on a client’s behalf. Where we collect your information from someone other than you, we handle it under this policy just the same.
This website runs no third-party analytics, advertising or tracking cookies, and loads no third-party scripts — it sets only what is strictly needed to serve the page securely. We do not build advertising profiles or follow you across other sites. If this ever changes, we will say so here first.
To respond to enquiries, scope and deliver engagements, invoice and collect payment, meet our legal and tax obligations, and keep records of agreements. We do not sell personal information, and we do not use your information for third-party marketing.
Some systems we build call an AI model at runtime — to read, sort or draft. Two rules are permanent: nothing is sent to a customer without human approval, and the system never sets a price. We do not permit the AI providers we use to train their models on your data, and where personal information is processed by a general-purpose AI service we de-identify it or use on-shore processing first. Identifiable health or other sensitive data is never sent to an overseas general-purpose AI service (clause 15). This site itself uses no AI to process visitor data.
Where we build or operate a system for your business, the customer and business data inside that system is yours. We process it only to run the system you are paying for, host it in Australia where practicable, and never use it for our own purposes. Anything involving regulated or health data is processed on-shore with a human in the loop.
We share information only with the service providers needed to operate: payment processing (Stripe), hosting and infrastructure (such as Vercel and Supabase), and email. We disclose personal information otherwise only where the law requires or permits it — for example, to comply with a court order or a regulator. We do not disclose your information to anyone for their own marketing.
Some of the providers we use process a limited amount of data outside Australia — for example, Stripe, which processes payment information in the United States. We choose providers with recognised security practices, share only what the service requires, and take reasonable steps to ensure your information is handled consistently with the APPs. Data inside systems we run for clients is hosted in Australia where practicable (clause 8).
Data is encrypted in transit, access is limited to the people who need it, and credentials are never stored in shared or public code. No system is perfectly secure, but we treat your information with the same discipline we sell.
If a data breach that is likely to result in serious harm occurs and we cannot prevent that harm, we will notify the individuals affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires. Where a breach concerns a system we run for a client, we will work with that client to respond.
We keep personal information for as long as needed for the engagement and our legal obligations (such as tax records), then delete or de-identify it.
You may deal with us anonymously or under a pseudonym for general enquiries. We will usually need your real name and contact details to quote, contract, invoice or deliver an engagement — where that is the case, we will tell you.
We do not seek sensitive information (including health information) unless it is necessary for a service and you have consented. Where a client engagement involves health or other regulated data, it is processed on-shore with a human in the loop and never sent to an overseas general-purpose AI service.
Our website and services are directed at business owners and operators, not children, and we do not knowingly collect personal information from anyone under 16. Where a system we run for a client may receive information about young people, we handle it under that client’s instructions and the same protections in this policy. If we learn we have collected a child’s personal information without a parent or guardian’s consent where it was required, we delete it.
Where a system we run sends messages on your behalf, it is designed to comply with the Spam Act 2003 (Cth), including functioning opt-outs. Any direct communication from us includes a way to opt out.
You can ask for a copy of the personal information we hold about you, or ask us to correct it, by emailing info@ostley.com. If you have a privacy concern, contact us first and we will respond promptly, and in any case within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
We may update this policy as our services change; the current version always lives at this address with its version date above.
Questions, requests and privacy notices: info@ostley.com.