Privacy Policy
This policy explains how DONT CHASE COOL collects, holds, uses, and discloses personal information across all of its services - from digital advertising campaigns to app development, creative production, and beyond. We take our obligations seriously and have written this to be read, not filed away.
About This Policy
This Privacy Policy governs the personal information handling practices of DONT CHASE COOL (“DCC”, “we”, “us”, “our”). It applies to all personal information we collect through our website, services, client engagements, digital products, competitions, and any other interaction with us.
We are primarily subject to Australia's Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act. Where we engage with individuals in other jurisdictions, we also comply - to the extent applicable - with the EU/UK General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA), Singapore's Personal Data Protection Act (PDPA), and other applicable data protection laws.
By using our website, engaging our services, entering a competition, or otherwise providing us with personal information, you acknowledge this policy. If you are accessing our services on behalf of an organisation, you confirm you have authority to provide personal information about individuals within that organisation.
Words like “personal information” and “sensitive information” carry the meanings given under the Privacy Act 1988 (Cth). In GDPR contexts, “personal data” is used equivalently.
Who We Are
DONT CHASE COOL is an Australian digital marketing and creative services agency. We provide services including - but not limited to - digital advertising strategy and management, creative production (graphic design, motion graphics, UI/UX), content strategy, brand identity, app development, consultancy, and lead generation services.
For the purposes of the Privacy Act 1988 (Cth) and the APPs, DCC is the entity that decides the purpose and means of collecting and handling personal information - that is, we are the “controller” in GDPR terminology. For personal information processed solely on behalf of our clients (for example, running advertising campaigns against client-supplied audience lists), we may also act as a “processor” or “service provider”, and our obligations in that capacity are governed by our agreement with the relevant client.
Our principal place of business is in Australia. Contact details for privacy matters are set out in the Contact section of this policy.
What Personal Information We Collect
The personal information we collect depends on how you interact with us. Below is a comprehensive account, organised by the context in which collection occurs.
When you complete a contact, enquiry, quote request, or other form on our website or on a page we manage on behalf of a client, we collect: your name, email address, phone number, company or organisation name, the nature of your enquiry, any message content you provide, and metadata about the submission (timestamp, IP address, browser/device type where technically captured). For lead generation forms operated on behalf of clients, the information collected is specified in the relevant form's disclosure statement.
Where we operate platforms, portals, or digital products that require account registration, we collect: email address, username or display name, password (stored as a cryptographic hash - never in plain text), account preferences and settings, usage history and activity within the platform, and any additional profile information you choose to provide. For platforms developed for clients where DCC acts as a processor, the data we collect is defined by the client's own product requirements.
When you enter a competition, prize draw, or promotional activity we run - either for DCC directly or on behalf of a client - we collect: your name, email address, phone number, residential address (where a prize requires delivery), date of birth (where age verification is legally required), consent confirmations, entry content (if applicable), and all information required to administer the promotion in compliance with Australian State and Territory permit requirements.
Competition data is collected in accordance with the relevant promotional terms and conditions published at the time of the competition. We are required to retain certain competition records under State and Territory gaming and racing legislation.
When we engage with you as a client for creative services, we collect and handle: contact details of your personnel and stakeholders (names, email addresses, phone numbers, roles); creative briefs, brand guidelines, strategic documents, and any proprietary business information you share with us in the course of a project; feedback records, approval histories, and revision logs; and the creative assets you provide to us, which may include photographs, illustrations, brand assets, and other materials in which third parties' personal information may appear (see also the Photography section).
We treat all client-provided business information shared in a creative context as confidential. Our handling of such information is also governed by any confidentiality or non-disclosure provisions in our engagement agreement.
In providing digital advertising services - across platforms including Meta (Facebook and Instagram), Google, LinkedIn, TikTok, Pinterest, and programmatic display networks - we may collect and process: campaign performance data and reporting metrics; audience parameters and targeting criteria (which may include hashed customer lists, custom audiences, and lookalike audience seeds derived from client first-party data); lead information generated through advertising forms (name, email, phone, company, job title, and any custom fields specified by the client); analytics data from advertising pixels, tracking tags, and UTM parameters; conversion and attribution data; and platform identifiers assigned by advertising networks.
Where we operate lead generation campaigns, leads collected become the property of our client. We act as a processor for that data and handle it strictly in accordance with the client's instructions and our service agreement. Clients are responsible for ensuring their own privacy policies and consent mechanisms cover the collection of leads through campaigns we manage on their behalf.
When we provide marketing, strategy, or business consultancy, we may be given access to: internal business data, analytics, revenue figures, and forecasts; contact details and personal information of the client's employees, contractors, and customers (shared as examples or for analysis); strategic plans and competitive intelligence; and meeting notes, recordings (where consented), and correspondence. All such information is treated as confidential and used solely for the purpose of delivering the agreed consultancy scope.
When we develop apps - mobile, web, or otherwise - on behalf of clients, the data collected through those apps is defined by the product requirements agreed with the client. The client is the data controller for end-user data in those apps, and we operate as a processor. Each app we develop will carry its own privacy notice tailored to its specific data practices.
Where DCC operates its own apps or digital tools, we collect from users: device information (device type, operating system version, device identifiers); usage data (features accessed, session duration, in-app actions, error and crash reports); push notification tokens (only where you grant permission); account credentials for apps that require sign-in; and analytics data processed via services including Firebase, Mixpanel, Amplitude, or equivalent (specified per app).
When you pay for our services, we collect: billing contact name and address, company name and ABN or equivalent tax identifier, invoice and transaction history, and payment method information. We do not store full payment card details. Card and bank payment processing is handled by a PCI-DSS compliant third-party payment processor (currently Stripe). We retain the transaction record and a tokenised payment reference. Where payment is made by bank transfer, we collect and retain bank account or BSB/account number details as necessary to process the transaction.
When photographs or video footage of identifiable individuals are taken or supplied for use in creative assets, campaigns, or content: we collect signed model release and consent documentation (including the individual's name, signature, and contact details); we record the scope of the usage rights granted; and we handle the visual assets together with the associated rights documentation. See the dedicated Photography & Image Rights section for full detail.
Where DCC uses AI-assisted tools - whether internal tools or services provided to clients - inputs submitted to those tools may contain personal information. This includes prompts, briefs, and instructions; uploaded documents, images, or data files; and any personal information that appears in content generated, analysed, or transformed by AI. See the dedicated Artificial Intelligence section for full detail on our AI data practices.
How We Collect Information
We collect personal information through the following means:
- Directly from you: when you contact us, submit a form, sign up for a service, hire us, participate in a competition, or upload materials to any platform we operate.
- Through your use of our services: automatically, via cookies, tracking pixels, server logs, analytics SDKs, and similar technologies embedded in our website, apps, and digital products.
- From third-party advertising platforms: Meta, Google, LinkedIn, and other platforms provide us with performance and audience data relating to campaigns we manage. This data is subject to each platform's own privacy terms.
- From our clients: clients may provide us with first-party data - including customer lists, CRM exports, or audience segments - for the purpose of executing campaigns or analytics work on their behalf.
- From publicly available sources: we may collect professional contact details (such as LinkedIn profiles, company websites, or business directory listings) for the purpose of business development or verifying stakeholder information.
- From referrals: a current client or contact may refer you to us, in which case we may receive your name and contact details as part of that referral.
In accordance with APP 5, at or before the time of collection (or as soon as practicable afterwards), we take reasonable steps to notify you of: who we are and how to contact us, the purpose of collection, any third parties to whom we ordinarily disclose the information, any relevant overseas disclosures, and your right to access and correct your information.
How We Use Personal Information
We use the personal information we collect only for the purposes for which it was collected, for related purposes that you would reasonably expect, or for other purposes with your consent. Our primary purposes are:
- Providing and managing our services, including responding to enquiries, delivering creative work, executing advertising campaigns, and performing consultancy.
- Communicating with you about active projects, proposals, invoices, and account matters.
- Processing payments and managing billing relationships.
- Administering competitions and promotions, including notifying winners and distributing prizes.
- Operating, improving, and troubleshooting our apps and digital products, including crash reporting and usage analytics.
- Sending direct marketing communications where you have consented or where we have a legitimate basis to do so under applicable law.
- Conducting research and analysis to improve our services and inform our business decisions.
- Complying with our legal obligations, including tax record-keeping, responding to regulatory inquiries, and meeting our obligations under the Notifiable Data Breaches scheme.
- Protecting the security of our systems, detecting and preventing fraud or misuse, and defending or exercising legal claims.
We do not use your personal information for any purpose materially different from those listed above without first obtaining your consent, except where permitted or required by law.
Disclosure & Third Parties
We do not sell personal information. We disclose personal information only to the extent necessary and in the following circumstances:
We engage third-party providers who assist in operating our business and delivering services. These include cloud infrastructure (AWS, Vercel, Google Cloud); email and communications tools (Mailchimp, Klaviyo, Google Workspace); analytics services (Google Analytics 4, Hotjar, Microsoft Clarity, Firebase); advertising platforms (Meta, Google Ads, LinkedIn, TikTok); payment processing (Stripe - PCI-DSS Level 1 compliant); project management and CRM tools (Asana, Notion, HubSpot); and file storage services (Google Drive, Dropbox, Frame.io). All providers are required to handle personal information confidentially and in accordance with applicable law.
In our capacity as a service provider to clients, we may share lead data, campaign results, or reporting that contains personal information with the relevant client as the data controller. We do not share one client's data with another client.
Our lawyers, accountants, insurers, and other professional advisors may access personal information as necessary in the course of providing their services to us. They are bound by professional confidentiality obligations.
We will disclose personal information to government agencies, law enforcement bodies, or regulatory authorities where we are required to do so by law, or where we are permitted to do so under the Privacy Act 1988 (Cth) - for example, in connection with an investigation of suspected unlawful activity, or to protect the health or safety of any individual.
If we merge with, are acquired by, or sell all or part of our business to another entity, personal information we hold may be transferred to the successor entity, subject to that entity agreeing to handle the information consistently with this policy or providing equivalent notice.
Cross-Border Data Transfers
DCC operates in Australia and works with clients and service providers globally. As a result, personal information we collect may be transferred to, stored in, or processed in countries other than Australia - including the United States, the European Union, the United Kingdom, Singapore, and other jurisdictions where our service providers operate infrastructure.
Before disclosing personal information to an overseas recipient, we take reasonable steps (consistent with APP 8) to ensure the recipient is subject to a law, binding scheme, or contract that provides substantially the same protections as the APPs. Where relevant, we implement Standard Contractual Clauses (SCCs) for transfers concerning EU/EEA or UK data subjects, Data Processing Agreements (DPAs) with all overseas service providers, and adequacy assessments where a destination country has been recognised as providing adequate protection.
By providing your personal information to us, you acknowledge that it may be transferred to and processed in countries outside Australia. Where such transfers occur, we take the steps described above to protect your information, but note that laws in those countries may differ from Australian law.
Data Retention
We retain personal information only for as long as necessary to fulfil the purpose for which it was collected, or as required by law.
| Data Category | Retention Period | Basis |
|---|---|---|
| Client engagement records | 7 years after engagement ends | Tax Act / corporate record-keeping obligations |
| Financial transactions & invoices | 7 years | Income Tax Assessment Act / GST Act |
| Lead generation data (client-controlled) | As directed by client; default 2 years | Client instructions / contractual obligation |
| Marketing opt-in records | Life of subscription + 2 years after opt-out | Spam Act 2003 (Cth) compliance evidence |
| Competition records | 12 months after promotion conclusion | State/Territory permit conditions |
| Creative project files & assets | Duration of engagement + 3 years | Dispute resolution / IP protection |
| Model releases & consent documents | While images are in active use, then 7 years | Copyright Act 1968 (Cth) / risk management |
| App usage & analytics data | As specified per app; typically 26 months | Product improvement / support obligations |
| Website analytics | 14 months (GA4 default); server logs 90 days | Analytics configuration |
| AI prompt logs (where retained) | 90 days for QA review, then deleted | Safety & quality review |
| General correspondence | 3 years after last contact | Business continuity / dispute resolution |
When the applicable retention period expires, we take reasonable steps to destroy or permanently de-identify the personal information in a secure manner.
Security
We implement technical and organisational measures consistent with APP 11 to protect personal information from misuse, interference, loss, unauthorised access, modification, or disclosure. Our security practices include:
- Encryption in transit: all web traffic uses TLS 1.2 or higher. Sensitive data in transit is encrypted end-to-end.
- Encryption at rest: databases and storage volumes containing personal information are encrypted at rest using industry-standard algorithms.
- Access controls: access to personal information is restricted to personnel who require it to perform their role. Multi-factor authentication is required for access to systems holding personal data.
- Password security: passwords are never stored in plain text. We use modern key-derivation functions (bcrypt, Argon2, or equivalent) to store password hashes.
- Vendor security assessments: we select service providers partly based on their published security practices and, where applicable, their compliance certifications (SOC 2, ISO 27001, PCI-DSS).
- Incident response: we maintain an internal incident response procedure. In the event of a data breach that triggers our obligations under the Notifiable Data Breaches (NDB) scheme (Part IIIC of the Privacy Act 1988 (Cth)), we will notify the OAIC and affected individuals as required.
No method of internet transmission or electronic storage is completely secure. If you suspect a security issue relating to your personal information, please contact us immediately at arin@dontchasecool.co.
Cookies & Tracking
Our website and the digital properties we manage use cookies, tracking pixels, and similar technologies. These fall into four categories:
- Strictly necessary: required for the site to function - session management, security tokens, load balancing. These cannot be disabled without breaking the site.
- Functional: remember your preferences so you don't have to re-enter them on each visit.
- Analytics: tools including Google Analytics 4, Hotjar, and Microsoft Clarity help us understand how people use our website. Analytics data is aggregated and anonymised where possible.
- Advertising: pixels and tags from Meta, Google, LinkedIn, TikTok, and similar platforms track conversions and allow us to measure campaign effectiveness. These tools may associate your on-site behaviour with a profile held by the advertising platform, subject to the platform's own terms.
Where required by applicable law, we will seek your consent before placing non-essential cookies. You can manage cookie preferences through your browser settings or any consent management tool we deploy. For advertising pixels operating under our clients' properties and managed by us: clients are responsible for their own cookie consent mechanisms, and we configure tags in accordance with consent signals from the client's consent management platform.
Creative Work & Intellectual Property
Where you provide us with brand assets, photography, copy, data, or other materials to incorporate into creative work, you warrant that you own or are licensed to use those materials, and that their use by DCC will not infringe any third party's rights - including intellectual property rights, privacy rights, or image rights. We do not claim ownership of materials you provide; our use is limited to the scope of the engagement.
Unless otherwise agreed in writing in our engagement agreement, intellectual property in original creative work produced by DCC (including designs, motion graphics, UI/UX output, code, and copy) remains with DCC until full payment is received, at which point it transfers to the client as specified in the agreement. Where no written agreement addresses IP, the default position under the Copyright Act 1968 (Cth) applies.
Where creative outputs are produced using AI-assisted tools, the intellectual property position may be uncertain under current Australian law. Copyright subsists in works created by human authors; the status of AI-generated works without sufficient human creative input is not settled. We recommend clients obtain independent legal advice regarding ownership and usage rights for AI-generated content. We will always disclose to clients when AI tools have been a material part of the creative process, unless otherwise agreed.
Unless you request otherwise in writing, we may include work we produce for clients in our portfolio, case studies, social media, and marketing materials. We will exercise discretion where work contains commercially sensitive information, and will honour any confidentiality restrictions you specify.
Photography & Image Rights
Where we commission, direct, or use photography or video footage that features identifiable individuals for use in advertising, social media, or any other commercial context, we obtain a signed model release or equivalent consent document from each identifiable subject. This records: the individual's name and signature, the scope of the consent (media types, platforms, territory, duration), any compensation agreed, and the date of consent. Where the subject is under 18, consent is obtained from a parent or legal guardian.
Where clients supply photography or video for use in campaigns or creative work, the client warrants that all necessary model releases and usage rights have been obtained and remain valid for the intended use. We may request copies of model releases for assets that will be used in paid advertising, as platform policies and risk management require.
Model release documents and associated identity information are stored securely in access-controlled systems, accessible only to personnel with a need to verify rights clearance. We retain model release records for as long as the associated imagery is in active use, and for a minimum of 7 years thereafter - consistent with the limitation period for civil claims under Australian law.
The scope of rights for any image or footage is determined by the model release or licensing agreement in place. Usage outside the agreed scope - for example, extending to additional territories, media types, or durations - requires fresh consent or a new licence. We track usage rights against each asset and will flag when a right is approaching expiry or when proposed usage would exceed the granted scope.
Where we source imagery from stock libraries (Adobe Stock, Getty, Shutterstock, Unsplash, or similar), we use assets under the relevant licence and retain proof of licence. We do not use stock imagery beyond the scope of the applicable licence.
Artificial Intelligence & Large Language Models
We may use AI tools across categories including: large language models for drafting, ideation, research, and content assistance; generative image tools for creative concepts and visual exploration; AI-assisted code generation; speech-to-text and meeting transcription tools; analytics and optimisation tools that use machine learning; and AI features embedded in platforms such as Google Workspace, Meta Ads, and others. The specific tools we use may change as the landscape evolves.
When personal information is submitted as part of an input to an AI tool - whether intentionally or as part of broader content - that information is processed by the relevant AI provider in accordance with their own data processing terms. Before using AI tools on tasks involving client personal information or sensitive business data, we assess the relevant provider's data practices and, where required, implement safeguards such as data anonymisation or use of enterprise API access that excludes input data from model training.
We do not use identifiable client or customer personal data to train third-party AI models without the express written consent of the relevant controller. When using API-based AI services in enterprise or data-processing mode, we ensure that our usage does not contribute to model training where the provider's terms permit this to be excluded.
We do not make decisions about individuals that produce significant legal or similarly significant effects using solely automated means without human review. Where AI tools contribute to decisions - for example, AI-assisted audience segmentation or scoring of marketing leads - a human team member reviews and approves the decision before it is acted upon. Individuals who believe an automated process has produced an outcome that affects them may contact us to request human review.
Where we build AI-powered features into apps or digital products for clients, we specify the AI components and data flows in our engagement documentation. Clients are responsible for ensuring their end-user privacy notices accurately disclose the AI features and their data implications.
Children's Privacy
Our website and general services are not directed at, and are not intended for, children under the age of 16. We do not knowingly collect personal information from children under 16 without the consent of a parent or legal guardian.
If we become aware that we have inadvertently collected personal information from a child under 16 without appropriate consent, we will take prompt steps to delete that information from our systems. If you are a parent or guardian and believe we have collected information from your child without appropriate consent, please contact us at arin@dontchasecool.co.
Where we run competitions or promotions accessible to minors, or where we develop apps intended for audiences that include minors, we implement appropriate age verification or consent mechanisms and specify these in the relevant promotional terms or app-specific privacy notice.
Your Rights
Your rights depend on where you are located and which laws apply to you. We honour the rights summarised below for all individuals whose personal information we hold, to the extent applicable under law.
- Access your personal information (APP 12)
- Request correction of inaccurate information (APP 13)
- Opt out of direct marketing (APP 7.2)
- Lodge a complaint with the OAIC
- Request anonymity or pseudonymity where practicable (APP 2)
- Receive notice of collection (APP 5)
- Access (Article 15)
- Rectification (Article 16)
- Erasure / “right to be forgotten” (Article 17)
- Restriction of processing (Article 18)
- Data portability (Article 20)
- Object to processing (Article 21)
- Withdraw consent at any time
- Lodge a complaint with your supervisory authority
- Know what personal information is collected
- Know if information is sold or disclosed
- Opt out of sale or sharing
- Delete personal information
- Correct inaccurate information
- Limit use of sensitive personal information
- Non-discrimination for exercising your rights
To exercise any of the rights above, please contact us using the details in the Contact section. We will respond within the timeframes required by law - generally 30 days for GDPR requests and a reasonable period (typically 30 days) for Australian APP requests. We may need to verify your identity before we can action a request.
We do not charge a fee for access or correction requests unless they are excessive or repetitive. Where we decline all or part of a request, we will explain the reason in writing. You may then escalate to the relevant authority (see Complaints).
For individuals in the EU or UK, we process personal data on the following legal bases: contract (processing necessary to deliver services you've engaged us for); legal obligation (tax and regulatory compliance); legitimate interests (business development, fraud prevention, network security, portfolio display - always weighed against your interests); and consent (direct marketing, certain cookies, AI processing of sensitive data). Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of prior processing.
Marketing
We may use your personal information to send you marketing communications about our services, insights, case studies, and events where we have a lawful basis to do so. In Australia, our email marketing practices comply with the Spam Act 2003 (Cth), which requires that commercial electronic messages carry an unsubscribe facility and not be sent without consent (express or inferred).
You can opt out of marketing communications at any time by clicking the unsubscribe link in any marketing email we send you, or by contacting us at arin@dontchasecool.co. We process unsubscribe requests within 5 business days. Opting out of marketing does not affect our ability to send you transactional or service-related communications such as invoices, project updates, or security notices.
We do not sell, rent, or share your personal information with third parties for the purpose of their direct marketing without your express consent.
Complaints
If you have a complaint about our handling of your personal information, please contact us first so we can attempt to resolve the matter directly. Send your complaint in writing to arin@dontchasecool.co. We will acknowledge your complaint within 5 business days and aim to provide a substantive response within 30 days.
If you are dissatisfied with our response, you may escalate your complaint to the relevant authority:
- Australia: Office of the Australian Information Commissioner (OAIC) - oaic.gov.au - or by phone on 1300 363 992.
- European Union: your local Data Protection Authority (DPA).
- United Kingdom: Information Commissioner's Office (ICO) - ico.org.uk.
- California: California Privacy Protection Agency (CPPA) or the California Attorney General.
- Canada: Office of the Privacy Commissioner of Canada (OPC) - priv.gc.ca.
Contact
For all privacy-related enquiries, requests, or complaints, please contact our Privacy Officer:
EU/UK individuals may contact us in relation to GDPR matters at the address above. We will work with you directly in the first instance.
Policy Changes
We may update this Privacy Policy from time to time to reflect changes in our services, applicable law, or our data handling practices. When we make material changes, we will update the “Effective” date at the top of this policy, post a notice on our website for a reasonable period, and - where the changes materially affect individuals with whom we have an ongoing relationship - notify those individuals by email or through the relevant platform.
We encourage you to review this policy periodically. Your continued use of our services after the effective date of a revised policy constitutes acceptance of the changes, to the extent permitted by applicable law. Previous versions are available on request.
DONT CHASE COOL · Privacy Policy · Version effective 15 September 2026
Governed by the Privacy Act 1988 (Cth) and the Australian Privacy Principles