Legal
Noknok Studios Privacy Policy
Entity: Noknok Studios Pty Ltd, ABN 53 653 256 547, ACN 653 256 547
Last updated: 14 August 2026
Privacy email: privacy [at] noknokstudios.com
Contact form: https://noknokstudios.com/contact/
Noknok Studios Pty Ltd (Noknok, we, us or our) is based in Doncaster East, Victoria, Australia.
This policy explains how we handle personal information when a person visits our website, contacts us, deals with our Referral Partner Programme or uses our services. We comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other privacy laws where they apply to us. We also comply with the New Zealand Privacy Act 2020 where it applies to relevant activities.
Whether a particular privacy law applies can depend on Noknok’s turnover, activities and statutory exceptions. We use this policy as our operational standard even where a particular provision is not legally mandatory.
1. Information we collect
Depending on the interaction, we may collect:
- name, email address, telephone number, role and business details;
- legal entity, ABN, billing and contact information;
- website address, business objectives, project requirements and responses to enquiry or recommendation forms;
- project briefs, content, images, feedback, approvals, correspondence and support requests;
- account, domain, hosting and technical access needed to provide agreed services;
- quote, contract, invoice, payment, refund and transaction records;
- Referral Partner names, codes, tagged-route and confirmation information;
- evidence relevant to an introduction, competing claim, correction or reward;
- IP address, browser, device, referring page, page views, interaction events and technical form-delivery or security metadata; and
- other information a person chooses to give us.
Business information may be personal information when it identifies an individual, including a sole trader, director, officer, employee or identifiable business contact.
Please do not send sensitive personal information unless we have agreed that it is necessary and arranged an appropriate handling method.
2. How we collect information
We usually collect information directly through:
- our website and enquiry or recommendation forms;
- email, telephone, meetings and project communications;
- quotes, Project Details, Statements of Work, contracts and acceptance records;
- project, support, accounting, payment and electronic-signature systems; and
- cookies and technical systems used to operate, secure, diagnose or administer our services.
We may also receive relevant information from:
- another authorised person in the individual’s organisation;
- a Referral Partner where the prospect asked for or agreed to an introduction;
- publicly available business sources;
- a customer, professional adviser or service provider involved in the work; or
- technical services that transmit, secure or log a website interaction.
A Referral Partner should ordinarily provide a tagged link or Referral Code and allow the prospect to contact us directly. It must not pass a prospect’s personal details to us unless the prospect requested or agreed to the introduction, or another clear lawful basis applies.
3. How we use information
We use information where reasonably needed to:
- respond to enquiries and provide a package recommendation;
- verify customer and contracting details and prepare proposals;
- plan, create, deliver, test, launch, maintain and support our work;
- manage projects, accounts, quotes, contracts, invoices, payments and refunds;
- authenticate users and administer access to websites and systems;
- operate, secure, troubleshoot and improve our website and services;
- administer Referral Partner attribution, disputes, adjustments and rewards;
- communicate about work, service changes, incidents and security matters;
- send marketing where permitted and maintain consent and unsubscribe records;
- protect our legal rights and resolve complaints or disputes; and
- meet tax, insurance, accounting, legal and recordkeeping obligations.
We do not sell personal information.
4. Client websites
When we host, maintain, support or work on a client’s website, we may have access to information submitted through that website where reasonably needed to provide the agreed service.
The client remains responsible for the purposes for which its website collects information, the notices and choices it provides, and any consent or other authority required for the client’s activities. Our access does not make us responsible for every aspect of the client’s privacy compliance.
5. Referral Partner information
5.1 First-party referral marker in browser storage
A valid partner-tagged link or QR route may create a first-party referral marker in the visitor’s browser storage (a local-storage entry), not an HTTP cookie. The marker records a minimal Referral Code reference and an expiry timestamp reasonably needed to manage provisional attribution. It is written and read only by the website’s own JavaScript in the visitor’s browser, and it is not transmitted to us automatically. The stored Referral Code reaches Noknok only if and when the person submits an enquiry form that carries it.
The referral marker operates as follows:
- merely viewing a general sponsor page, partner profile, directory or untagged partner page does not create or refresh it;
- its default retention is 90 days;
- following a later valid partner-tagged route replaces the earlier provisional code;
- it is provisional only and does not prove a referral by silence; and
- blocking or deleting cookies and site data does not prevent a person from providing a Referral Code or identifying a genuine referrer by contacting us before contract acceptance.
The implementation stores only the Referral Code and an expiry timestamp. It does not store a person’s name, email address or other direct identifier in the browser marker.
5.2 Positive confirmation before contract
Before a customer accepts a Noknok contract, we confirm the proposed Referral Partner, if any, as part of our contract acceptance process. We ask the customer to positively confirm whether that partner, or an authorised communication from it, introduced, recommended or directed the customer to Noknok, and we do not assume the answer. The website does not present an automated referral confirmation. Any referral captured through the website is provisional only, and a person may confirm, identify or correct the referrer by contacting Noknok before accepting a contract.
If the customer does not confirm the referral, we remove provisional attribution unless we already hold other reliable contemporaneous evidence of the same genuine referral. Where no Referral Code exists, a customer may identify a referrer by contacting us before acceptance, for example by email or a recorded statement.
The customer has a final opportunity to correct the attribution before acceptance, and the attribution is fixed once the customer accepts the contract in writing, such as by a signed document, an e-signature or a clear email acceptance. We do not add or substitute a partner afterwards merely to confer a financial benefit.
A later request to correct inaccurate personal information will still be considered, but a privacy correction does not by itself create a new post-contract Referral Reward entitlement.
5.3 Referral records
Referral information may include:
- partner name and Referral Code;
- tagged-route, referral-marker, manual-code or source information;
- the customer’s confirmation, free text, email or recorded verbal statement;
- a brief ambiguity, rejection, correction or competing-claim record;
- the accepted customer-document versions and acceptance time;
- reward eligibility, calculation, GST, adjustment and payment records; and
- related questions, complaints or disputes.
A Referral Code or referral marker may become personal information when linked, or reasonably linkable, to an identifiable enquiry or customer.
5.4 Information provided to a Referral Partner
We ordinarily provide a Referral Partner only information reasonably needed to explain and pay an earned reward, such as the reward amount, calculation basis, payment period and adjustments.
We do not ordinarily provide customer contact details, correspondence, project scope or other unnecessary customer information unless the disclosure is necessary, authorised or required by law.
6. Website forms, technologies and analytics
Our website and service systems may use technologies for operation, security, form delivery, analytics, referral attribution, diagnostics and service improvement. Depending on the configured service, these technologies may process IP address, browser and device information, referring page, pages viewed, interaction events and form-delivery metadata.
We deliver website form submissions through Web3Forms, and a form-delivery notification we receive may include the visitor’s IP address. We do not state a fixed storage period or storage country for submissions handled by Web3Forms, as these depend on the provider’s configuration.
We review the technologies and providers we use, and we update this policy if the provider, purpose or handling materially changes. The referral marker is governed by section 5 and is not created merely by viewing a partner page.
A person can control browser cookies and site data through browser settings. Blocking or clearing cookies or site data may affect parts of the website, but a person may still identify a genuine referrer by contacting us.
7. Service providers and overseas handling
We may use providers for:
- hosting, domains and content delivery;
- email and communications;
- cloud storage, project management and collaboration;
- form delivery, spam prevention, analytics and security;
- payment processing, accounting and electronic signatures;
- backups and technical support; and
- approved business software, including AI-assisted features.
We give providers only the information reasonably needed for the function and use proportionate access, account, contractual, security and deletion controls.
Some providers may store or process information outside Australia or New Zealand. The countries depend on the provider, account configuration, data type and service route. Where a cross-border disclosure is subject to privacy law, we take the steps required by that law. We do not state a fixed provider location or retention period where these depend on a provider’s configuration that may change.
8. AI-assisted tools
We may use approved business software with AI-assisted features to reduce repetitive work, analyse project material or help prepare content. Experienced people lead and review our work.
We limit personal information to what is reasonably necessary, avoid unnecessary sensitive information, apply available account and data controls and review outputs before relying on or publishing them. A project may impose additional restrictions in its Project Details or Statement of Work.
9. Marketing and electronic messages
We send commercial electronic messages only where permitted. Covered messages identify the sender, include current contact details and provide a functional unsubscribe facility. We maintain appropriate consent and unsubscribe records and action unsubscribe requests within the legally required period.
We enable a direct marketing channel only where the required consent and unsubscribe controls are in place.
10. Security
We take reasonable technical and organisational steps to protect information from loss, misuse and unauthorised access, alteration or disclosure. Measures are proportionate to the information and may include:
- role-based access and account security;
- multi-factor authentication where supported and appropriate;
- restricted project and matter files;
- secure transfer and credential-handling methods;
- logging, backups, updates and anti-abuse controls;
- minimisation of data stored in cookies and forms; and
- removal or de-identification when information is no longer reasonably needed.
No internet service is completely secure. If we become aware of a suspected incident, we assess it, take reasonable containment and remediation steps and make any notification required by applicable law.
11. Retention and deletion
The referral marker is a first-party browser-storage item retained for up to 90 days. Unlike an HTTP cookie, it does not expire automatically in the browser. Noknok’s website stamps each marker with a 90-day expiry and discards a marker that has passed that expiry the next time the site reads it, or when the person clears it or their site data earlier.
We delete or de-identify unused enquiry and provisional referral information when it is no longer reasonably needed, subject to security logs, backups, legal holds and records needed to resolve an issue.
Accepted customer contracts, exact accepted versions, final referral-attribution evidence, reward calculations, tax documents, invoices and payment records are ordinarily retained together for seven years, subject to a longer legal hold, dispute or statutory requirement.
Project files, correspondence, access records, security logs and backups are retained only for as long as reasonably needed for their operational, contractual, security or legal purpose. Backup deletion follows the normal secure rotation cycle of the relevant system.
12. Access, correction and deletion requests
A person may ask to access or correct personal information we hold, or ask us to delete information that is no longer reasonably needed. We may need to verify identity or authority.
The law may allow or require us to refuse access, preserve a record or withhold information affecting another person. Where permitted, we will explain the reason.
A customer should correct Referral Partner attribution before accepting the final customer contract, using the correction route shown in the Project Details or by contacting Noknok. After acceptance, we will still consider a privacy correction request, but we will not use that process to create a new reward based on a post-contract nomination.
13. Privacy questions and complaints
Privacy questions, access or correction requests and complaints may be sent to:
Privacy email: privacy [at] noknokstudios.com
Contact form: https://noknokstudios.com/contact/
We will review the matter and respond within a reasonable period. Where applicable law provides an external complaint route, a person may contact the relevant privacy regulator after giving us a reasonable opportunity to respond.
14. Changes to this policy
We may update this policy when our services, systems or legal obligations change. A new version applies from its stated date. We retain earlier versions where relevant to an accepted contract, complaint or record.
15. Contact
Noknok Studios Pty Ltd
ABN 53 653 256 547 | ACN 653 256 547
privacy [at] noknokstudios.com
https://noknokstudios.com/contact/