Legal
Version 4.1 - Last updated 11 September 2026
Noknok Studios Privacy Policy
Version 4.1
1. About this policy
Noknok Studios Pty Ltd (Noknok, we, us or our), ABN 53 653 256 547, ACN 653 256 547, is based in Doncaster East, Victoria, Australia.
This policy explains how we handle personal information when you use our website or portal, make an enquiry, deal with us for a project or service, interact with our Referral Partner Programme, receive communications or make a privacy request or complaint. Personal information includes information or an opinion about an identified or reasonably identifiable person. Business information can be personal information, including information about a sole trader or business contact.
We handle personal information in accordance with laws applying to our activities and the practices described here. This includes Australian and New Zealand privacy requirements where they apply. A particular law’s application depends on the entity, activity and circumstances.
This policy is a public notice. It does not form part of a customer or Referral Partner agreement merely because it is published or linked. A specified provision forms part of an agreement only if an accepted agreement document deliberately incorporates it.
2. Personal information we handle
Depending on the interaction, we may handle:
- contact and business information, such as your name, email address, telephone number, role, organisation, business identity, billing address and website;
- enquiry and qualification information, including your needs, objectives, website requirements, form answers, referral information and messages;
- customer and project information, including representative authority, briefs, content, files, feedback, scope decisions, approvals and support requests;
- account and technical information, including account identifiers, access records, IP addresses, browser or device information, security signals and logs;
- contract and transaction information, including exact accepted documents, acceptance evidence, invoices, payment identifiers, billing, payment and refund records;
- information in client websites, files, databases, forms, media, backups and migration or recovery material handled to supply services;
- Referral Programme information, including applicant and partner identity, referral identifiers and evidence, customer confirmation, competing claims and necessary payment and tax records; and
- communications, preferences, consent and unsubscribe records, privacy requests, complaints and proportionate verification evidence.
Please do not send passwords, payment-card details, sensitive information or unnecessary information about another person through an ordinary enquiry form or email. If such information is needed for a service, arrange an appropriate method with us first. Our standard Referral Partner payment-readiness process is not intended to collect an individual’s Tax File Number.
Where card payment is offered through Stripe’s hosted checkout, you provide the card details to Stripe. Our portal receives payment status and transaction identifiers rather than your full card details.
3. How we collect information
3.1 Information you provide and other sources
We usually collect information directly through our website and forms, email and other communications, project and support channels, portals, and contracting, payment or acceptance processes.
We may also receive relevant information from an authorised representative, a customer supplying project content or access, a Referral Partner where you requested or authorised an introduction, public business sources, or providers supporting communications, forms, security, payments or service delivery.
If you provide information about another person, you should have authority to do so and, where appropriate, make the relevant notice available to them. Where applicable law requires us to notify someone about information obtained indirectly, we take the required reasonable steps unless an exception applies. A public privacy policy does not replace a collection-specific notice where one is required.
You may make a general enquiry anonymously or using a pseudonym where practical and lawful. We may need your identity, contact details or business authority to respond, enter an agreement, provide an account or service, process a payment or handle a request. If necessary information is not provided, we may be unable to complete that interaction.
3.2 Forms and browser storage
Website enquiries may be sent through Web3Forms to Noknok email. The website fit-check may instead send your contact details and relevant answers to our portal to prepare the next step. The relevant form explains the purpose of collection and links to this policy.
The fit-check can save unfinished answers, including entered contact details, in your browser so you can return to them. Saving a draft does not itself submit an enquiry to Noknok. You can remove it using the form’s clear control or your browser’s site-data controls. Avoid entering private information on a shared device.
Referral links and codes may use browser storage to remember a possible introduction. You can review and correct a proposed referral before submitting it. Clearing the site’s stored data may remove the saved referral or unfinished answers. The contextual referral notice explains the relevant handling; a stored marker does not itself establish a reward or change your price.
3.3 Analytics and security technologies
We use Google Analytics to understand how people use our website and portal. This can involve cookies or similar identifiers, page visits and interactions, browser or device information and approximate location. Google processes this information through its international infrastructure. Google’s information about partner sites and apps explains its handling. You can use browser privacy controls or Google’s Analytics opt-out browser add-on, where supported, to limit collection.
We use Cloudflare for domain services and may use its Turnstile service on protected forms. Turnstile processes browser and security signals, such as IP address and device or browser characteristics, to help distinguish legitimate use from abuse. Cloudflare describes this in its Turnstile Privacy Addendum.
Essential account, session, security and form functions may use cookies or similar technology. Browser controls can limit storage or scripts, although doing so may affect a function. An enquiry or acceptance of customer terms is not consent to unrelated marketing or every use of browser information.
4. Why we handle personal information
We handle personal information where reasonably needed to:
- respond to enquiries and provide recommendations or proposals;
- assess suitability, identity, authority or an application and administer customer or Referral Partner arrangements;
- design, build, test, host, maintain, support, secure, migrate, restore or hand over websites and related work;
- administer projects, accounts, access, communications, billing, accounting, tax, payments and referral records;
- operate, secure, diagnose and improve our website, systems and services;
- send marketing where the required permission exists and maintain consent and unsubscribe records;
- investigate complaints, security matters, fraud, payment diversion or disputes; and
- protect lawful interests and comply with applicable legal and record-keeping requirements.
We do not sell personal information. We do not use personal information from client websites or databases for our own unrelated marketing or profiling.
5. Client websites and service delivery
When we build, host, maintain, support, migrate, restore or hand over a client’s website, we may access or hold personal information in its files, databases, forms, accounts, backups or related material where reasonably needed for the agreed service. Client-uploaded material can contain information about other people.
The client is responsible for its collection purposes, customer-facing notices and required consent or authority. Noknok remains responsible for its own access, use, disclosure, security and other handling when supplying services. Our access is ordinarily limited to what is reasonably needed for the service. Tell us before providing information that requires special safeguards.
6. Referral Programme information
We collect information at the relevant stage of a referral relationship, including minimal application information, partner identity and acceptance records, referral identifiers and proportionate evidence, limited customer linkage and dispute information, and payment-destination and necessary tax information when payment readiness is relevant.
A code, tagged link, QR route, browser record or partner claim may be evidence. It does not by itself establish a Referral Reward, alter a customer’s price or prevent contract formation. A customer may confirm, reject or correct a proposed referral. A privacy correction does not necessarily change a contractual entitlement.
We ordinarily disclose to a Referral Partner only the customer information reasonably needed to administer or explain a reward, payment or genuine dispute. We do not ordinarily provide customer contact details, correspondence or project scope unless authorised, required or reasonably necessary.
Collection-specific notices accompany the relevant application, referral technology and payment-readiness process. The Referral Partner Agreement governs contractual eligibility and payment rights.
7. Service providers and overseas handling
We use providers for hosting, storage, backups, forms, security, analytics, email, collaboration, project administration, authentication, electronic acceptance, payments, banking, accounting, AI-assisted software and professional support. We make information available only to the extent reasonably needed for the provider’s function and assess appropriate arrangements according to the service and information involved.
Some providers handle information outside Australia. Overseas locations identified for our form and email arrangements and their published infrastructure include the United States, Japan, India, Germany and Finland. Other providers use international processing, support or subprocessor networks; the locations depend on the product and service involved. Australian hosting of our own website or portal does not mean that all related information stays in Australia.
Examples of the provider arrangements relevant to your interaction are:
| Service | Handling relevant to you |
|---|---|
| Hosting, uploaded files and backups | We use Conetix hosting in Queensland and select Onidel storage in Sydney for portal uploads. Backblaze provides United States storage for selected website and portal backups. Associated account, billing, support and other provider services may involve overseas handling. |
| Forms and email | Web3Forms relays website enquiries to Noknok email using United States infrastructure; its business is in India and its published infrastructure providers also include Germany and Finland. Resend handles portal email through Japan and stores account information, including email metadata and logs, in the United States. |
| Payments and accounts | Stripe and Xero handle information for their payment and accounting functions through international infrastructure. An Australian account does not establish Australian-only processing. |
| Analytics and security | Google Analytics and Cloudflare use distributed international infrastructure for measurement, domain and security functions. |
| Collaboration and project work | Google Workspace, ClickUp, Notion and AI-assisted business software may handle information used for communication, project administration and working records outside Australia. |
| Optional business-information prefill | If used for your enquiry or project, Google Places receives a business search query and Anthropic receives relevant public website text for the purpose described in section 8. These services can process that information overseas, including in the United States. |
Where applicable privacy law governs an overseas disclosure, we take the required steps. Internet routing alone is not necessarily an overseas disclosure. Contact privacy@noknokstudios.com for current provider and location information relevant to your interaction. Providers’ own notices describe additional handling for which they are responsible, including Web3Forms, Resend, Onidel, Stripe, Xero, Google, Cloudflare, ClickUp, Notion and Anthropic.
8. AI-assisted tools and business-information prefill
We use business software with AI-assisted features for drafting, analysis, design or administration. Information supplied to an AI-assisted function may include personal information where reasonably necessary for the task. We seek to minimise that information, avoid unnecessary sensitive information and use appropriate controls and oversight. A project or service may impose additional restrictions.
Where we use automated prefill, we may read relevant public pages on the business website you identify, use Google Places to find business information, and use Anthropic’s commercial API to interpret public website text. Public business material may contain personal information such as an owner’s name or contact details. Suggested information may be recorded for review and confirmation during preparation of your project brief. A suggested answer is not a confirmed fact or your approval.
We remain responsible for our own handling and decisions. A fit-check recommendation or prefilled brief does not itself accept a project, form an agreement, authorise a payment or make a final material decision about your rights. You can correct information with us. Provider retention and legal or security exceptions may apply even where we do not need a separate copy of a prompt or response.
9. Marketing and service communications
We do not treat an enquiry, customer interaction or Referral Partner application as consent to unrelated marketing.
If we send marketing, we use the applicable permission, identify the sender and provide a functional unsubscribe method. We maintain appropriate consent and unsubscribe records. Withdrawing from marketing does not prevent a response to an enquiry or a factual project, account, billing, security, service, legal or Referral Programme communication that is otherwise permitted.
10. Security and incidents
We take reasonable technical and organisational steps appropriate to the circumstances to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures depend on the system, provider, sensitivity and risk. No internet or software service is completely secure.
If we become aware of a suspected incident, we assess it and take reasonable containment, investigation and remediation steps. We notify affected people or a regulator where applicable law requires notification or where notification is otherwise reasonably needed for protective action. This is not a promise to notify every attempted, suspected or immaterial event.
11. Retention and deletion
How long we keep information depends on its purpose and whether it is still reasonably needed. We consider the enquiry, application, project, service, referral or payment stage; applicable record-keeping requirements; the need for accepted-contract, authority, payment or substantive-decision evidence; complaints, disputes, incidents and legal claims; and provider, archive and backup lifecycles.
We retain protected contract and financial records for the applicable seven-year period, or longer where an active dispute, claim or legal hold requires it. This does not impose a seven-year period on every enquiry, website user, working copy or item in a client website. We delete or de-identify other information when it is no longer reasonably needed and seek provider deletion where available.
Deletion from an active system may not immediately remove an item from a secure backup or provider archive where it cannot reasonably be isolated. Access remains restricted until removal or overwriting through the applicable cycle. Provider periods and exceptions differ; we do not promise immediate deletion everywhere, a universal retention period, backup availability or recovery capability.
We review uploaded files and working copies according to their project or service purpose. Information restored from backup remains subject to applicable retention, deletion and access restrictions.
12. Access, correction and deletion requests
You may ask for access to, or correction of, personal information we hold about you. You may also ask us to delete or de-identify information that is no longer reasonably needed. We may need to verify your identity or authority proportionately before acting.
Access or deletion may be limited where applicable law permits or requires it, another person’s privacy or rights would be affected, or information must be retained for legal, accounting, security, contract, dispute or evidential reasons. Where appropriate, we explain a refusal or limitation and available complaint options. We preserve required accepted-contract and financial evidence when dealing with surrounding account information.
We consider requests to correct referral information. Correcting personal information does not by itself establish a new Referral Reward, change an accepted agreement or alter another person’s legal rights.
13. Privacy questions and complaints
Send a privacy question, request or complaint to privacy@noknokstudios.com, or use our contact form. Please provide enough information to understand the matter, but do not send identity documents or sensitive information unless we arrange an appropriate method.
Our target is to acknowledge a request or complaint within seven calendar days and provide a substantive response within 30 calendar days. If more time is needed, we explain why and the next steps, subject to any applicable legal time limit. We review the matter, make relevant enquiries and explain the outcome or proposed resolution.
Where the regulator has jurisdiction, you can contact the Office of the Australian Information Commissioner or the New Zealand Office of the Privacy Commissioner. You should ordinarily give us a reasonable opportunity to address the matter first. This does not restrict a right to contact a regulator or seek a remedy under applicable law.
14. Changes to this policy
We may update this policy when our services, systems, providers or legal obligations change. The current version and effective date will be published with the policy.
Where applicable law requires direct notice, or a material change makes direct notice appropriate, we take reasonable steps to notify affected people. Continued browsing does not itself consent to a materially different handling purpose. We retain earlier versions where reasonably needed for governance, a complaint or an accepted record.
Noknok Studios Pty Ltd
ABN 53 653 256 547 | ACN 653 256 547
Doncaster East, Victoria, Australia
privacy@noknokstudios.com