Privacy Policy
Last updated: 26 May 2026
CloudyWP (“we”, “our”, “us”) is an AI-driven digital agency providing WordPress, Shopify, and automation services. We are based in Melbourne, Australia, and we operate in line with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).
Your privacy matters to us. This policy explains, in plain language, what information we collect, how we use it, who can see it, and the rights you have.
1. Who this policy applies to
This policy applies to:
- Visitors to cloudywp.com.au and any related sites we operate
- People who contact us through forms, email, chat, phone, or social channels
- Clients we work with on WordPress, Shopify, automation, or AI integration projects
- Anyone whose personal information we receive while delivering those services
2. Information we collect
Information you give us directly
- Name, email address, phone number, and business details
- Information submitted via contact forms, quote requests, chat, or enquiries
- Project requirements, brand assets, content, and any files you share with us
- Billing and tax details where relevant (e.g. company name, ABN, address)
Information collected automatically when you visit our site
- IP address and approximate location
- Browser type, device, operating system, and screen size
- Pages visited, time spent, and referring URLs
- Cookie and analytics identifiers (see Cookies below)
Information we receive during client projects
When we deliver services, you may give us access to:
- Website admin accounts, hosting panels, DNS, and similar credentials
- API keys, tokens, and integration credentials
- Customer data sitting inside your website, store, or CRM
- Business documents, brand materials, and other commercially sensitive content
We treat all of this as confidential project data — see Client project data below.
We do not intentionally collect sensitive personal information (health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, biometric or genetic data). If you send us anything like this without us asking, please don’t.
3. How we use your information
We use the information we collect to:
- Respond to enquiries and prepare quotes or proposals
- Deliver the services you’ve engaged us for
- Communicate about projects, support, invoices, and important updates
- Maintain and improve our website, services, and client experience
- Meet legal, tax, and regulatory obligations
- Protect against fraud, abuse, and security threats
We will only use your information for the purpose it was collected, or for a directly related purpose you would reasonably expect.
4. Our promise: we do not sell or share your data
We do not sell, rent, trade, or otherwise share your personal information or your project data with third parties for their own purposes. Full stop.
The only times your information leaves our systems are:
- To run the specific tools needed to deliver your project (hosting, email, analytics, etc.) — and these are documented in advance, as explained below.
- When you ask us to (e.g. “please send this file to my designer”).
- When we are legally required to (e.g. a valid court order or regulatory request).
We do not use client project data to train AI models, build mailing lists, share case studies, or for any purpose outside delivering the work you hired us for.
5. Third-party tools and sub-processors — disclosed upfront
We use trusted third-party platforms to operate our business and deliver projects. These may include hosting providers, email and CRM tools, analytics services, payment processors, automation platforms, and AI providers.
Our commitment to you:
- Documented in advance. Before a project starts, we provide a written list of every third-party tool and service that will touch your data, what it is used for, and where it is hosted. This forms part of your project documentation.
- Need-to-know basis. We only share the minimum information each tool requires to do its job.
- Vetted providers. We choose providers with their own published privacy and security commitments, and we review them periodically.
- Your approval. If a new tool needs to be added partway through a project, we will tell you and get your sign-off before connecting it.
- No on-selling. Our providers are contractually required to handle your data securely and may not use it for their own marketing or training purposes.
If you would like a current list of the sub-processors we use, email us and we will send it through.
6. AI tools and your data
Because we’re an AI-driven agency, we use AI tools (such as code assistants, content tools, and workflow automations) to deliver work more efficiently. When we do:
- We use business or enterprise tiers wherever available, which contractually exclude your data from being used to train public models.
- We avoid sending sensitive credentials, customer PII, or commercially sensitive content into AI tools unless it is strictly necessary and you have approved it.
- The specific AI providers used on your project are listed in your project documentation, as described above.
If you would prefer us not to use any AI tools on your project, let us know and we will work without them.
7. Client project data and access credentials
When you give us access to your systems, we:
- Store credentials in a dedicated password manager with multi-factor authentication
- Limit access to team members directly working on your project
- Use unique admin accounts where possible (rather than sharing your own)
- Remove or rotate our access at the end of the engagement, on request, or after a defined period of inactivity
- Keep all project data, files, and communications confidential, both during and after the project
We will not access systems or data outside the scope of what we have been asked to work on.
8. Cookies and tracking
Our website may use cookies and similar technologies to:
- Keep the site working correctly (essential cookies)
- Understand how visitors find and use the site (analytics cookies)
- Measure the effectiveness of marketing campaigns (marketing cookies, where applicable)
You can disable or delete cookies in your browser settings at any time. Some site features may not work as expected if you do.
We currently use analytics tools that aggregate and anonymise visitor data wherever possible.
9. International data transfers
Some of the tools we use are hosted outside Australia (commonly in the United States or European Union). Where this is the case:
- We only use providers with appropriate data protection commitments
- The transfer is limited to what is needed to provide the service
- Your information remains protected by the same standards we apply locally
By using our services, you consent to your information being processed in these locations as part of those tools’ normal operation.
10. Data security
We take reasonable, industry-standard steps to protect your information, including:
- Encrypted connections (HTTPS) across our website and tools
- Multi-factor authentication on team accounts that hold client data
- Role-based access — team members only see what they need to see
- Regular software updates, backups, and access reviews
- Secure password management for all credentials
No method of online transmission or storage is 100% secure. If we ever believe your personal information has been compromised in a way likely to cause serious harm, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required under the Notifiable Data Breaches scheme.
11. Data retention
We keep personal information only for as long as we need it to:
- Provide and support the services you’ve engaged us for
- Meet our legal, accounting, and tax obligations (typically up to 7 years for financial records under Australian law)
- Resolve disputes and enforce our agreements
When information is no longer needed, we securely delete or de-identify it. You can request earlier deletion at any time (see Your rights below).
12. Your rights
Under the Australian Privacy Principles, you have the right to:
- Access the personal information we hold about you
- Correct information that is inaccurate, out of date, or incomplete
- Request deletion of your personal data where we no longer need it and are not required to keep it by law
- Withdraw consent for optional uses of your data (e.g. marketing emails) at any time
- Lodge a complaint if you believe we have mishandled your information
To make a request, email us at the address below. We will respond within 30 days.
If you are not satisfied with how we have handled your request or complaint, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
13. Children’s privacy
Our services are designed for businesses and are not directed at children under 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can remove it.
14. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our services, the tools we use, or legal requirements. The “Last updated” date at the top of this page will always show the latest version. Significant changes will be communicated to active clients directly.
15. Contact us
For any questions, requests, or concerns about this policy or your information:
CloudyWP Melbourne, Australia Email: [email protected]
We aim to respond to privacy-related enquiries within 5 business days.