Legal
Privacy Policy
This policy explains what personal information Digital Attitudes collects through digitalattitudes.com.au, why we collect it, who else touches it and how long we keep it. We have chosen to handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth), whether or not a business of our size is required to. Health information is also handled under the Health Privacy Principles in the Health Records Act 2001 (Vic).
Who you are dealing with
Digital Attitudes (ABN 88 989 534 755) is a business name of a sole trader based in Melbourne, Victoria, working nationally. When you book, your contract is with the holder of that ABN.
Digital Attitudes plans to become a company. Before it takes any booking as a company, we will update this page with the company’s name and ACN. A booking you made before then stays with the business you contracted with, unless you agree otherwise in writing.
Contact us, including for any written notice, by email at hello@digitalattitudes.com.au. Privacy questions go to privacy@digitalattitudes.com.au.
What this policy covers
This policy covers this website and the consulting and training work we sell through it: browsing the site, sending an enquiry, joining a waitlist, booking and paying for a workshop or program, and taking part in one.
It does not cover the custom software Digital Attitudes has built and hosted for schools. Those products are provided under separate written agreements with each school, the school controls the staff and student information in them, and they are described in our product privacy policy.
What we collect, and when
When you send an enquiry
The contact form on this site records what you type (your name, your work email address, your organisation, your role, the topic you select and your message) and, alongside it, two things you did not type: the page you sent the enquiry from and your browser’s user-agent string. We keep those two so we can tell which page prompted an enquiry and reproduce problems people report with the form. The contact page says this before you submit, and this policy says it because a disclosure you only see once is not much of a disclosure.
Enquiries are stored in our database and a copy is emailed to us as a notification.
When you book training
As the person paying, we collect:
- your name, email address, phone number and organisation, so we can confirm the booking and reach you if a session changes;
- what you bought, the amount, the currency, any discount code or credit applied, and a booking reference;
- payment identifiers issued by Stripe, and whether and when payment succeeded or was refunded.
We never see or store your card details. Card capture happens on Stripe’s own hosted payment page. Full card numbers, expiry dates and security codes go to Stripe and never reach our servers or our database.
About the person attending
A booking can be made for someone other than the purchaser. For each participant we record a first name, and where relevant a surname, an email address and a phone number, plus whether they turned up. That is the whole of it for an adult workshop.
Where a program needs more than that
Some programs, principally the student programs described below, need information we would not ask for otherwise. For those, we collect:
- a parent or guardian’s name, relationship and contact details, and a record of the consent they gave;
- an emergency contact;
- confirmation that the participant will be 15 or over on the day, and a rough year level. We do not ask for a date of birth: an attestation tells us what we actually need to know, and a birth date would tell us more than that;
- allergies, dietary requirements, and any accessibility or support needs we have to plan for;
- a yes or no answer to whether there is a medical condition or medication we need to know about on the day.
Note what is not in that list. If the answer to the last question is yes, the detail is given to the facilitator in person and is not written down or stored by us. We keep only the fact that the conversation happened, and at most a short logistical note such as “guardian will brief the facilitator at drop-off”. We do not hold medical notes or a list of medications.
Health information is sensitive information under the Privacy Act. What little of it we do hold is collected only with a parent or guardian’s consent, stored separately from the rest of the booking with tighter access, and deleted on the schedule set out under How long we keep it.
When you join a waitlist
We record the session you are waiting for and how to reach you, so we can offer you a place when one comes up.
Records of consent
Every consent you give or withdraw is stored as its own record: which consent it was, whether it was granted, when, who gave it, and which version of this policy was in force at the time. That is how we can tell you later exactly what you agreed to.
What we collect automatically
Our hosting provider records standard server information for every request, including IP address and browser details, and keeps it for a short period for security and reliability. We also use Google Analytics (see Cookies and analytics, which explains that it is loaded, and sets cookies, only if you accept).
When you give us your details: our collection notice
Digital Attitudes collects your name, email address and the details you enter so we can do the thing you asked: answer an enquiry, take and confirm a booking, hold your place on a waitlist, or send you something you requested. If you do not give us these details, we cannot do that.
We share them only with the service providers listed under Who else handles it, some of which are in the United States. We do not sell your information and we do not use it to train AI.
You can ask to see or correct what we hold, or complain about how we have handled it, using the contact details on this page. The same notice, in short form, appears on every form that collects your details.
Student programs and participants aged 15 and over
Our student programs are not yet open for online booking. Until we have confirmed that every facilitator holds a current Working with Children Check and our child-safety arrangements are in place, you can only join an interest list for them. An interest-list entry holds a name and an email address and nothing about a child’s health. How we keep young people safe in our programs is set out in our child safety and wellbeing statement.
Our student programs are for participants aged 15 and over. Our public workshops are for adults aged 18 and over. We do not run programs for younger children and we do not set out to collect information about them.
A participant under 18 is a minor, and we treat information about them differently from information about an adult customer. Five principles govern it, and they are the things to hold us to:
- A parent or guardian consents. A student under 18 cannot register themselves for one of our programs. A parent or guardian provides consent, and we record who gave it, when, and by what method. Where a school runs a program with us, the school and the guardians agree between them how consent is obtained, and we record what we are told.
- Least data. We ask for the smallest set of information that lets us run the program safely and reach a guardian if we need to. If a field is not needed to do that, we should not be asking for it, and you should tell us if you think we are.
- Photo and video are off by default. No photograph or video of a student participant is used for any purpose unless a parent or guardian has explicitly opted in. Silence is not consent, a general registration tick is not consent, and the default is no. See How we treat consent.
- Twelve months, then gone. Records about a student participant are kept for 12 months from their last participation and then deleted or de-identified. See How long we keep it.
- Separately held, tightly reached. Guardian, emergency-contact, health and accessibility information sits in its own store, reachable only by Digital Attitudes staff who need it to run the session. It is not published to the website, not sent to analytics, and not shared with other participants or their families.
Health information. Allergies, accessibility needs and the yes-or-no medical flag are health information. We collect them only with a parent or guardian’s consent, only for a program that needs them, and only to keep the participant safe on the day. We handle them under the Australian Privacy Principles and the Health Privacy Principles in the Health Records Act 2001 (Vic). If the answer to the medical question is yes, the detail is given to the facilitator in person and is not written down or stored by us, and facilitators do not write it on attendance lists. You can ask to see or correct health information we hold using the contact details on this page, or complain to the Victorian Health Complaints Commissioner (hcc.vic.gov.au) as well as, or instead of, the OAIC.
If the description above is ever broader than what a particular program actually collects, the narrower one is what happens. If you want the exact list for a program your child is enrolled in, ask us and we will send it.
How we treat consent
We keep these apart from each other, so that agreeing to one never means agreeing to another.
- Agreeing to the Terms of Sale. Required to book. This is your agreement to the contract, including the cancellation terms. It is not a privacy consent: we use your booking details to run your booking because that is why you gave them to us.
- Marketing. Optional, asked separately, never pre-ticked. Saying no has no effect on your booking.
- Photos and video of adults. Optional, never pre-ticked. We only include you in photos or video of a session if you tick the box, and you can change your mind at any time. We do not name people in published images without asking them.
- Photos and video of students. Never used unless a parent or guardian has explicitly opted in. Silence is not consent.
Registration consent is never treated as marketing consent, and marketing consent is never inferred from a booking. Buying a workshop does not put you on a mailing list.
To withdraw any consent, email privacy@digitalattitudes.com.au, or use the unsubscribe link in any marketing email. Withdrawing consent does not undo what was already done with it, but it stops anything further.
Emails we send, and unsubscribing
We send marketing emails (news about workshops and programs, and any newsletter) only to people who asked for them. Booking a session or using a free tool does not sign you up. Those are separate choices, and the forms ask them separately.
Every marketing email identifies Digital Attitudes and our ABN, tells you how to contact us, and has an unsubscribe link that works. We act on an unsubscribe within 5 business days, and usually straight away. After you unsubscribe we keep your email address and the date you left, only so we do not add you again by mistake.
Booking confirmations, reminders and similar emails about something you bought are not marketing, and we will still send those.
Why we use it
- To answer your enquiry.
- To take a booking, confirm a place, issue a receipt, apply a credit, process a refund and tell you if a session changes.
- To run a session safely, including reaching a guardian or emergency contact and accommodating access needs.
- To issue certificates of participation where a program includes one.
- To send you marketing, only if you separately asked for it.
- To understand how the website is used, at the level of aggregate traffic rather than individuals.
- To keep the site secure and to meet our legal obligations.
We do not sell personal information. We do not use it to train AI models, and we do not send participant or enquiry data to an AI service as part of running the site.
The one exception is the assessment AI stress test: the task and rubric you paste are sent to Anthropic to produce the report. Do not paste student names or confidential information.
Automated decisions
We do not make decisions about you using automated processes. People at Digital Attitudes make every decision about bookings, refunds, credits and enquiries.
Who else handles it, and where
We use a small number of service providers to run the business. They handle information on our instructions, for the purpose listed and no other.
| Provider | What it does | Where your information is held or processed |
|---|---|---|
| Supabase | Our database: enquiries, bookings, participants, consent records | Sydney, Australia |
| Vercel | Website hosting, and the server functions behind the forms and checkout | Pages are served from Vercel’s global network (the Sydney edge for visitors in Australia). The server functions that process enquiries, bookings and email may run in Australia (Sydney) or the United States (Washington DC) |
| Stripe | Payments. Stripe takes your card details directly | Stripe Payments Australia, with processing in the United States and other countries where Stripe operates |
| Resend | Sending booking emails and, if you ask for them, updates | United States |
| Google Cloud (Firebase) | Runs the assessment AI stress test and keeps a daily usage count against a one-way hash of your IP address | United States (Iowa) |
| Anthropic | Analyses the assessment task and rubric you paste into the AI stress test. We do not store the text | United States |
| Google (Google Analytics) | Website measurement, only if you accept analytics (see “Cookies and analytics”) | United States |
Because some of these providers are in the United States, using them is a disclosure of personal information overseas. We choose providers that commit in their contracts to protect personal information, and we take reasonable steps to make sure they handle it in line with the Australian Privacy Principles. We remain responsible for how they handle it on our behalf.
We may also disclose personal information where the law requires it, or to establish or defend a legal claim.
Cookies and analytics
This site uses Google Analytics 4, and only if you agree. Until you accept, Google’s analytics script is not loaded at all: nothing is sent to Google, not even a cookieless ping, and no analytics or advertising cookie is set on your device. Google Consent Mode v2 also starts with both analytics_storage and ad_storage set to denied.
Every page shows a small banner where you can accept or decline analytics cookies. If you accept, Google Analytics is loaded, may set analytics cookies, and records the pages you visit. It is given the page’s address without any query string, and without the booking reference in a booking confirmation address. We also record a few anonymous events, such as an enquiry, waitlist or subscription form being sent or checkout being started, without your name, email or anything you typed. If you decline, Google Analytics is not loaded. Advertising storage stays denied either way. Your choice is remembered in your browser’s local storage. You can change or withdraw it at any time with the “Cookie settings” link at the foot of every page, or by clearing this site’s data.
The site also uses your browser’s local storage for ordinary functional things, such as remembering a choice you made on a page. You can clear or block all of this through your browser settings, though some parts of the site may then behave oddly.
Keeping it secure
Traffic to this site is encrypted in transit. Access to the database is restricted, sensitive participant information is separated from the booking record and reachable only through a server-side route rather than from the browser, and card data never reaches us at all. No system is perfectly secure and we will not pretend otherwise; if something goes wrong that is likely to cause serious harm, we will notify affected people and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.
How long we keep it
We keep personal information only as long as we need it, then delete it or remove anything that identifies you. The periods below are enforced by our database automatically, not left to memory.
| Information | How long we keep it |
|---|---|
| Purchaser details and booking and payment records | 7 years after your last booking, credit or other activity with us, then anonymised. Tax law requires at least 5 years; we keep 7 so the records meet the company-law rule as well when the business becomes a company. |
| A checkout that was never completed | 90 days |
| An adult attendee’s email and phone (where they are not the purchaser) | 12 months after the session |
| An adult attendee’s name | 24 months after the session, so we can confirm attendance or reissue a certificate |
| Student participant, parent or guardian, emergency contact and health details | 12 months after the participant’s last session, then deleted or anonymised |
| Waitlist entries | 30 days after you take a place; 90 days after the entry closes for any other reason |
| “Tell me when dates are announced” requests | Until we email you about new dates, or 12 months, whichever comes first; then 90 days |
| Ticket transfer details (the person you sent in your place) | 90 days after the session |
| Website enquiries | 24 months after the last activity on the enquiry; an unsent draft of the form, 90 days; your browser’s user-agent, 90 days |
| School enquiries that do not go ahead | 24 months |
| School engagements that go ahead | 7 years after the last activity, including payment |
| The IP address and browser details recorded when a school accepts a quote | 24 months |
| Consent records | As long as the information they relate to |
| Marketing subscription | Until you unsubscribe. If you are also a past customer and have opted in to marketing, we keep your name and email for that purpose only, and delete them when you unsubscribe and the periods above have passed |
We keep information longer only if an incident, a claim or a legal requirement needs it, and only while that lasts.
Access, correction and complaints
Under the Australian Privacy Principles you can ask us to show you the personal information we hold about you (APP 12) and to correct it if it is wrong, incomplete or out of date (APP 13). You can also ask us to delete it, withdraw a consent, or stop sending you marketing.
How to ask: email privacy@digitalattitudes.com.au and tell us what you want. For a student participant, a parent or guardian can make the request. We may need to confirm who you are before we hand anything over. We aim to respond within 30 days; if we refuse a request we will tell you why in writing and how to challenge it.
If you want to complain about how we have handled your personal information, write to the same address and we will look into it and respond. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au, by phone on 1300 363 992, or in writing to GPO Box 5288, Sydney NSW 2001. You do not have to come to us first, but it is usually faster.
Other sites
This site links to other organisations’ websites. We are not responsible for what they do with your information, and their policies apply once you leave here.
Changes to this policy
When we change this policy we update the version and date at the top. The version in force when you gave a consent is recorded against that consent, so a later change to this page does not quietly rewrite what you agreed to.