LEGAL

Privacy Policy

How Marlwood Consulting collects, holds, uses and discloses personal information, aligned to the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply. We do not sell personal information.

Effective 24 September 2026 · Version 1.3. Binding on use of the site, a discovery request, a seat, or payment of an invoice.

1. About this policy

This Privacy Policy describes how William Gaule, trading as Marlwood Consulting, of Brisbane, Queensland, Australia (“Marlwood”, “we”, “us”) collects, holds, uses, discloses and otherwise handles personal information.

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) to the extent they apply to us. If we are not an APP entity in a particular respect, we nevertheless treat this policy as the standard we will meet for information collected through the Platform.

This policy applies to personal information collected through our websites (including marlwoodconsulting.com and Product sites we operate), Discovery bookings, enquiries, accounts, Marlwood Billing, Agents, calendar administration, and handoff to Property Intelligence or Construction after collection clears. It also describes personal information the Labour Hire Business holds on its crew phone and in its own book (names, trades, tickets, pay, sites, and availability). That business is separate. The same people operate both.

It does not apply to the handling of information by third parties with their own policies (for example Google, if you use Google sign-in or add an event to Google Calendar), except to the extent we collect information back from that third party.

2. Meanings

“Personal information” has the meaning in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in a material form or not.

“Sensitive information” has the meaning in the Privacy Act and includes information about health, racial or ethnic origin, political opinions, membership of a professional or trade association, and criminal record. We do not seek a diagnosis or a medical history. A crew-phone mark of “Sick” is an availability flag only — not a diagnosis. Do not write symptoms or a condition into a form.

Other capitalised terms have the meaning in the Terms of Service.

3. What we collect

We collect the following classes of personal information, where you (or your authorised representative) provide them, or they are generated by your use of the Platform:

3.1 Identity and contact

  1. name, email address, telephone number, company or practice name, role, ABN if you supply it, and location;
  2. the content of enquiries, Discovery briefs, Mandate correspondence, intake answers (including, where you volunteer them, business stage, turnover band, region, investment criteria, capital available, expected return, and desired term), and notes you submit;
  3. portraits and biographies if you are a member of the practice and consent to publication.

3.2 Account and security

  1. login email, password hash (we do not store the password in reversible form), session tokens, bearer tokens used in preview environments, and email-verification status;
  2. sign-in method (email/password or federated Google identity);
  3. IP address, approximate location derived from IP, browser and device type, and security logs.

3.3 Billing

Invoice amounts, GST, description of supply, payment rail (card, BECS Direct Debit, Apple Pay, Google Pay), masked account identifiers (card last four, BSB mask, wallet label), house tokens, Direct Debit Request mandate identifiers, collection status, failure codes, and refund records.

We do not store full primary account numbers, card verification values, or full bank account numbers after tokenisation. PAN and CVC are used only in memory to validate and issue a house token, then discarded. We are the merchant of record. We are not a card-scheme acquirer and we are not a bank.

3.4 Calendar and Discovery

Appointment kind, duration, proposed and confirmed times in Australian Eastern Standard Time (Brisbane), attendee name, email, telephone, company, brief, and status (requested, held, declined, completed).

If the principal connects a secret iCal feed or Appointment schedule, we may read busy/free times (not necessarily event titles or descriptions, depending on the feed) solely to avoid double-booking.

3.5 Product usage

Pages viewed, feature events, Agent queries at a professional (not intimate) level of detail, deal and contact records you create, and telemetry needed to operate and secure the service.

3.6 Handoff

If a Planning or Construction Seat is paid, we disclose to that Product: your name, email, company, plan identifier, a one-time handoff token, and that collection has cleared. That Product then holds its own account record subject to its privacy terms.

3.7 Practice book

If you enquire or book, we file a client record, a company record, a mandate, a written brief, an assignment of a consultant, a fit assessment, and an activity tape. Those records are held so we can decide whether to take the work, prepare for a discovery, and keep a professional file. They are not visible to any account other than the principal of the practice.

3.8 Labour hire and the crew phone

For a worker on the Labour Hire Business we may hold: name, telephone, email, trade, tickets, region, pay and charge rates, the site they are placed on, and dates they have marked themselves unavailable (including “Sick” or “Leave”).

The crew phone is a private link for that worker. It shows their jobs and lets them mark unavailable. It is not the office and it is not a consulting file. The link is a credential. Forwarding it lets someone else see that worker’s jobs.

Where the person is our employee, the employee-records exemption in the Privacy Act may apply to records we hold for that employment. We still do not sell those records, and we do not keep a sick mark as a health file.

4. How we collect

We collect personal information directly from you when you submit a form, book a Discovery, create an account, pay an invoice, email us, or use a Product. A short collection notice appears on those forms (APP 5).

We may collect personal information from a person you authorise (for example an assistant who books on your behalf).

We may collect information from publicly available sources and business listing sources when you instruct an Agent to originate targets. That collection is of business-related information. If it identifies an individual (for example a proprietor named on a listing), we handle it as personal information under this policy and use it only for origination and underwriting on a Seat or Mandate.

If we receive unsolicited personal information and we could not have collected it under APP 3, we will destroy or de-identify it as soon as practicable, unless we are required by law to retain it.

5. Purposes of collection, use and disclosure

We collect, hold, use and disclose personal information for purposes that include:

  1. deciding whether to accept a Discovery or Mandate, and performing that work;
  2. creating and administering accounts, Seats, entitlements and the house console;
  3. operating Agents, origination, feasibility tools and construction pricing, including retrieval over the house book;
  4. automated assignment of a consultant and preparation of a written brief from your intake (in-house software, not a public consumer chatbot) — this is not a consumer-credit decision and it is not a decision whether you will be employed;
  5. issuing tax invoices, collecting amounts due, retrying failed payments, processing refunds, and meeting taxation record-keeping duties;
  6. rostering labour hire workers, showing a host the name, trade and tickets required on that site, and keeping pay records — pay is not shown to the host through this Platform;
  7. handoff to a Product after collection clears, so that an account is not created before payment is good;
  8. scheduling, preventing double-booking, and communicating about appointments;
  9. securing the Platform, preventing fraud and abuse, and investigating incidents;
  10. complying with law, a court order, or a regulator;
  11. improving the Platform in aggregated or de-identified form.

We do not sell personal information. We do not use personal information to train a public third-party model. In-house Agents operate on the house book for the Mandate or Seat. We do not use personal information for unrelated direct marketing without a lawful basis and a simple opt-out.

6. Lawful basis and consent

Where the Privacy Act requires consent, we will seek it. Use of the Platform, submission of a form, or payment of an invoice is a request that we handle information as described in this policy. You may refuse to provide information; if you do, we may be unable to provide a Discovery, Mandate, Seat, or invoice.

Sensitive information (if you choose to supply it) will be handled only with your consent or as otherwise permitted by the Privacy Act, and only for the purpose you supplied it.

7. Who we disclose to

We disclose personal information only as follows:

  1. Processors who host the Platform, database, email, error logging and file storage, under contract, only to operate the service;
  2. Product sites we operate (Property Intelligence, Construction) for handoff after cleared collection;
  3. payment rails and tokenisation providers, to the extent required to collect, refund, or retry;
  4. professional advisers (lawyers, accountants) under confidentiality;
  5. a purchaser or successor of the practice, on terms no less protective;
  6. a court, regulator, or law-enforcement body if required or authorised by law;
  7. a person you have asked us to copy on correspondence;
  8. a host, limited to the worker’s name, trade and the tickets that site requires — not pay, and not a diagnosis.

We will not disclose your brief to another client. We will not disclose house-console analytics to any account other than the principal.

8. Overseas disclosure (APP 8)

Our hosting, database, email or error-logging providers may store or access personal information outside Australia (including in the United States or other regions where those providers operate).

By using the Platform you consent to that disclosure. We take reasonable steps to ensure that an overseas recipient does not breach the APPs in relation to the information, including by using reputable providers and contractual protections where practicable. Those steps cannot guarantee that an overseas recipient is subject to the same legal remedies as in Australia.

9. Direct marketing (APP 7)

We may send you service messages (invoices, booking confirmations, security notices, material changes to Terms) without separate consent; these are not marketing.

We may send you practice updates or Product-launch notices related to a Seat or enquiry you made, where we have a lawful basis (including where you ticked a consent, or where you would reasonably expect the message given the enquiry). You may opt out using the link in the message or by writing to us. We will not sell your address to a third-party list. Commercial electronic messages comply with the Spam Act 2003 (Cth).

10. Cookies, sessions and analytics

We use first-party cookies and similar storage that are necessary to operate sign-in (including `__Host-` session cookies), to keep you signed in, to remember a preview bearer token in session storage where cookies are partitioned, and to protect against cross-site request forgery.

We use first-party telemetry of pages and feature events to operate and secure the service. We do not use third-party advertising cookies or sell browsing behaviour.

You may block cookies in your browser. If you block necessary cookies, sign-in and checkout may fail.

11. Quality, security and retention (APPs 10, 11)

We take reasonable steps to ensure that personal information we collect is accurate, up to date and complete, having regard to the purpose of use. You must keep your account email current.

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Those steps include access control on the house console, hashed passwords, encrypted transport, and least-privilege handoff tokens. No method of transmission or storage is completely secure.

We retain: (a) invoices, payment records and GST records for at least five years or any longer period required by taxation law; (b) Mandate files for at least seven years after the Mandate ends, unless a longer professional-retention period applies; (c) Discovery and enquiry records for as long as reasonably required to administer the practice and manage disputes; (d) account records for the life of the account and a reasonable period after closure; (e) security logs for a shorter operational period unless needed for an investigation; (f) employee and labour hire worker records for at least seven years, as required by the Fair Work Act 2009 (Cth) section 535.

When personal information is no longer required for a purpose and we are not legally required to keep it, we will take reasonable steps to destroy or de-identify it.

12. Eligible data breaches

If we experience an eligible data breach as defined in the Privacy Act, we will assess it and, where required, notify affected individuals and the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme, and take reasonable steps to contain and remediate.

13. Access and correction (APPs 12, 13)

You may request access to personal information we hold about you, or request a correction, by writing to williamc@cmlpropertygroup.com.au. We will respond within a reasonable period (ordinarily 30 days). We may refuse in the circumstances the Privacy Act allows (for example, where access would unreasonably affect another person’s privacy, or is frivolous). If we refuse, we will tell you why (unless it is unreasonable to do so) and how to complain.

We will not charge for lodging a request. We may charge a reasonable amount for producing copies if the volume is substantial.

14. Anonymity and pseudonymity (APP 2)

You may browse public pages without identifying yourself. You cannot book a Discovery, open a Seat, or receive a tax invoice anonymously, because we must know who we are meeting, contracting with, and invoicing.

15. Children

The Platform is not directed at children under 18. We do not knowingly collect personal information from children. If you believe we have, write to us and we will take reasonable steps to delete it.

16. Complaints

If you have a privacy complaint, write to William Gaule at williamc@cmlpropertygroup.com.au with “Privacy” in the subject line, describing the issue and the outcome you seek. We will acknowledge the complaint and investigate. We aim to resolve privacy complaints within 30 days.

If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, enquiries@oaic.gov.au, GPO Box 5218 Sydney NSW 2001, telephone 1300 363 992.

17. Changes to this policy

We may update this policy by publishing a new version at https://marlwoodconsulting.com/legal/privacy. The effective date will change. Material changes will be notified to account emails where practicable. Continued use after the effective date is acceptance of the updated policy.

18. Contact

Privacy contact: William Gaule, Marlwood Consulting, Brisbane, Queensland, Australia. Email: williamc@cmlpropertygroup.com.au.