/Legal
Privacy Policy
Last updated: 13 June 2026
1. Introduction
At Arkhi Pty Ltd (A.B.N. 68 117 774 071) (“we”, “us”, “our”), we respect your privacy and are committed to handling personal information responsibly, transparently, and in compliance with applicable privacy laws.
Arkhi is a commerce agency based in Australia, providing strategy, marketing, design, and development services. This policy covers personal information we collect online, offline, and through our service delivery activities.
We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For individuals in the European Economic Area (EEA) and the United Kingdom, we also comply with the General Data Protection Regulation (GDPR).
2. Information We Collect
2.1 Information you provide directly
- —Contact details such as name, job title, employer, email address, phone number, and business address.
- —Account or profile information created when you register for services or communications.
- —Information shared during client onboarding, project briefs, and service delivery.
- —Payment and billing details for processing invoices and transactions.
- —Communications via email, contact forms, telephone, video conferencing, or messaging.
- —Survey responses, feedback, or research participation information.
- —Job application information.
2.2 Information collected automatically
- —Technical identifiers such as IP address, browser type and version, operating system, and device type.
- —Usage data such as pages visited, links clicked, time on pages, and navigation paths.
- —Referring website or search terms.
- —General location data derived from your IP address (city or country level).
2.3 Information received from third parties
- —Personal information from clients about their customers, employees, or stakeholders.
- —Data from public sources such as company registers or social media.
- —Information from commercial partners or referral sources.
3. How We Use Your Information
We use personal information for the following purposes:
- —Service delivery — delivering our services, communicating with clients, and managing proposals, contracts, invoices, and suppliers.
- —Business development — responding to prospective clients, sending updates and newsletters, and running events.
- —Website operations — operating our platforms, monitoring performance, and conducting analytics.
- —Legal and compliance — meeting our legal obligations, protecting against fraud, and enforcing our rights.
- —Internal operations — recruitment, financial administration, reporting, and quality assurance.
We do not sell personal information to third parties.
4. Legal Bases for Processing (GDPR)
Where the GDPR applies, we rely on the following legal bases to process your personal information:
- —Performance of a contract — where processing is necessary to deliver services you or your organisation have requested.
- —Legitimate interests — where processing is necessary for our legitimate business interests and does not override your rights.
- —Legal obligation — where we are required to process information to comply with the law.
- —Consent — where you have given us consent to process your information for a specific purpose.
- —Vital interests — where processing is necessary to protect someone’s life.
5. Disclosure of Your Information
We may disclose personal information to:
- —Service providers — cloud infrastructure, project management, communication tools, financial software, analytics, and cybersecurity solutions.
- —Contractors and freelancers — specialists involved in service delivery, under confidentiality obligations.
- —Professional advisers — legal, financial, and insurance advisers, as needed.
- —Clients — project outputs and reports, in line with our contractual arrangements.
- —Business transfers — prospective purchasers in a merger or acquisition, with confidentiality protections.
- —Legal requirements — where disclosure is required by law, court order, or a regulatory authority.
6. International Transfers of Personal Information
Some of our service providers may store or process personal information outside Australia. Where we transfer personal information internationally, we use appropriate safeguards such as Standard Contractual Clauses, adequacy decisions, or other approved mechanisms.
We take reasonable steps to ensure your information is handled consistently with the Australian Privacy Principles and applicable law.
7. Data Retention
We retain personal information for as long as is necessary to fulfil the purposes for which it was collected, or as required by law or legitimate business needs.
When deciding how long to retain information, we consider:
- —The nature and purpose of the information.
- —Your reasonable expectations.
- —Our legal and contractual obligations.
- —The risk of harm from retention or deletion.
- —Any deletion requests you make.
- —Applicable regulatory guidance.
As a general guide:
- —Client engagement data — retained in line with contract law limitation periods and regulatory requirements.
- —Financial and tax records — retained as required by Australian tax and corporate law.
- —Website analytics — retained for a limited period for analytics and security monitoring.
- —Marketing contacts — retained until you ask to be removed or the information is no longer relevant.
- —Unsuccessful recruitment applications — retained for a reasonable period unless earlier deletion is requested.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it securely.
8. Security
We implement administrative, technical, and organisational measures to protect personal information from unauthorised access, disclosure, alteration, or destruction. These include access restrictions, encryption, and secure storage.
No method of transmission over the internet or electronic storage is completely secure, so we cannot guarantee absolute security.
9. AI-Assisted Tools and Automated Processing
9.1 Our use of AI-powered tools
We use AI-assisted tools in the course of our business operations. These tools support activities such as drafting and editing content, summarising information, conducting research, assisting with analysis, and improving workflows. Human oversight is maintained over their use.
9.2 Personal data and AI tools
We apply data minimisation principles when using AI-powered tools, and avoid inputting unnecessary personal information into these systems.
9.3 Automated decision-making
We do not currently make decisions about individuals that are solely based on automated processing and that produce legal or similarly significant effects, without human involvement.
10. Your Privacy Rights
10.1 Rights under the Australian Privacy Act
- —The right to access the personal information we hold about you.
- —The right to request correction of inaccurate information.
- —The right to make a complaint about how we handle your information.
- —The right to opt out of direct marketing.
10.2 Rights under the GDPR (EEA and UK individuals)
- —Right of access: to receive a copy of the personal information we hold about you.
- —Right to rectification: to have inaccurate or incomplete personal information corrected.
- —Right to erasure: to request deletion of your personal information in certain circumstances.
- —Right to restriction of processing: to request that we limit how we use your information.
- —Right to data portability: to receive your personal information in a structured, machine-readable format.
- —Right to object: to object to processing based on our legitimate interests.
- —Right to withdraw consent: to withdraw consent at any time where processing is based on consent.
- —Rights regarding automated decision-making, including the right to request human review.
10.3 How to exercise your rights
To exercise any of these rights, contact our Privacy Officer using the details below. We aim to respond within 30 days.
10.4 Complaints
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au, the UK Information Commissioner’s Office (ICO), or your relevant EEA data protection authority.
11. Cookies and Tracking Technologies
We use cookies and similar tracking technologies on our website. The types we use include:
- —Strictly necessary cookies — required for the website to function; these cannot be disabled without disrupting functionality and do not collect marketing data.
- —Performance and analytics cookies — collect usage information such as pages visited and error messages; this aggregated data helps us improve the website and does not identify individuals.
- —Functionality cookies — remember your choices, such as language preferences, to provide enhanced, personalised features.
- —Marketing and targeting cookies — set by advertising and analytics providers to track browsing across websites and deliver relevant advertising; these are placed only with your consent.
You can manage your cookie preferences through your browser settings.
12. Contact Us
If you have any questions about this policy or wish to exercise your privacy rights, please contact our Privacy Officer:
Privacy Officer — Arkhi Pty Ltd
4/46 Junction Road, Burleigh Heads QLD 4220, Australia
Email: info@arkhi.com.au · Telephone: 07 5634 9593
13. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, legal obligations, or the services we provide. The latest version will always be available on this page, and material changes will be noted with an updated effective date.