Last updated: 16 September 2026
1. About this Privacy Policy
IMExpert, ABN 54 696 692 160 (IMExpert, we, us or our), respects the privacy of individuals whose personal information we handle.
This Privacy Policy explains how we collect, use, disclose, store and protect personal information in connection with our website, digital marketing, website development, hosting, support and related services.
Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply to us or to particular information we handle, we will comply with those requirements. We also aim to follow these principles as a matter of good practice where they do not strictly apply.
2. Scope
- imexpert.au and forms submitted through the website;
- enquiries, proposals, quotes and client onboarding;
- provision of SEO, paid media, analytics, content, website development, hosting and support services;
- email, telephone and other communications with us;
- billing, accounting and payment administration;
- events, marketing and business development activities; and
- dealings with suppliers, contractors and other business contacts.
Where we handle personal information solely on behalf of a client as part of services provided to that client, the client may also have its own privacy obligations and privacy policy.
3. Personal information we may collect
Depending on how you interact with us, we may collect:
- name, job title, organisation and contact details;
- billing and transaction information;
- information contained in enquiries, briefs, proposals, support requests and correspondence;
- information and files you provide to us for website, advertising, analytics or content work;
- website, hosting, advertising platform and other account identifiers or access information where required to provide the Services;
- marketing preferences and consent records;
- technical information such as IP address, browser type, device information, referral source, pages visited and interaction data;
- cookie identifiers, analytics identifiers and similar online data; and
- any other personal information you choose to provide to us.
We do not ask you to provide sensitive information unless it is reasonably necessary for a specific purpose. If you provide sensitive information to us, we will handle it in accordance with applicable law and the purpose for which it was provided.
4. How we collect personal information
- directly from you;
- from your employer, organisation or authorised representative;
- through our website, forms and communication systems;
- through analytics, advertising and cookie technologies;
- from platforms or systems you authorise us to access;
- from service providers acting on our behalf; and
- from publicly available sources where reasonably necessary for our business activities.
5. Why we use personal information
- respond to enquiries and prepare proposals or quotes;
- provide, manage and support our Services;
- administer client accounts and projects;
- configure, monitor and maintain websites, advertising, analytics and related systems where included in scope;
- communicate with clients, suppliers and business contacts;
- issue invoices, process payments and manage accounts;
- maintain security, detect misuse and investigate technical or security incidents;
- measure and improve our website and Services;
- comply with legal, regulatory, insurance and professional obligations;
- establish, exercise or defend legal claims; and
- send marketing communications where permitted by law and subject to your opt-out rights.
We will not use personal information for an unrelated purpose where doing so would be inconsistent with applicable privacy law.
6. Website analytics, cookies and advertising technologies
Our website uses cookies and similar technologies for functions such as site operation, security, preferences, analytics and advertising measurement.
We currently use technologies that may include Google Tag Manager, Google Analytics, advertising platform tags and CookieScript or similar consent-management tools. Depending on your consent choices, these technologies may collect information about your device, browser and interactions with our website.
You can manage cookie preferences through the consent controls made available on our website. You can also control cookies through your browser settings, although disabling some cookies may affect website functionality.
Third-party analytics and advertising providers may process information under their own privacy terms.
7. Marketing communications
We may send you information about our services, updates or other material we reasonably think may be relevant to you where permitted by law.
You can opt out of marketing emails at any time by using the unsubscribe mechanism in the message or contacting us. We may still send service, billing, security or other non-marketing communications where required for an existing relationship.
8. Service providers and disclosures
We may disclose personal information to service providers and contractors where reasonably necessary to operate our business or provide the Services. These may include providers of:
- website hosting, content delivery, security, backup and infrastructure services;
- email, productivity and cloud storage services;
- analytics, advertising and marketing platforms;
- website forms, automation and integration services;
- accounting, invoicing and payment services, including Xero and connected payment providers where used;
- professional advice, insurance and claims support;
- software development, technical support and specialist contracting services; and
- data storage, communications and business administration systems.
We may also disclose information where required or authorised by law, to protect legal rights or security, in connection with a business sale or restructure, or with your consent.
We do not sell personal information as a standalone commercial product.
9. Overseas processing and disclosure
Some service providers we use operate or store data outside Australia. Depending on the service, personal information may therefore be processed or accessible in countries including the United States, United Kingdom, European Union and other locations in which our technology providers operate.
Where Australian privacy law requires us to take particular steps in relation to an overseas disclosure, we will take reasonable steps appropriate to the circumstances.
Because cloud and technology providers may change their infrastructure and subprocessors over time, the exact location of processing may vary.
10. Client data processed on behalf of clients
In providing digital marketing, analytics, website, hosting or support services, we may access personal information that a client controls.
Where we handle that information solely on the client’s instructions, the client remains responsible for determining the lawful basis for its collection and use, providing required privacy notices and obtaining any required consents.
We will use client-controlled personal information only as reasonably necessary to provide the agreed Services, comply with law, protect systems or as otherwise authorised by the client.
If your enquiry concerns personal information held by one of our clients, we may refer you to that client where appropriate.
11. Account credentials and access information
Where clients provide us with credentials or access to websites, hosting accounts, advertising platforms, analytics systems or other business systems, we use that access only for purposes reasonably connected with the agreed Services.
Clients should use individual user accounts where available, enable multi-factor authentication and avoid sharing personal passwords where a delegated access method is available.
12. Security
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
Measures may include access controls, multi-factor authentication where available, secure hosting and cloud services, backups, software updates and limiting access to people who reasonably need it.
No internet, cloud or electronic storage system can be guaranteed to be completely secure. If you believe information or an account relevant to our Services has been compromised, please contact us promptly.
13. Data breaches
If we become aware of a suspected data breach involving personal information we control, we will assess and respond to the incident in accordance with applicable law and our contractual obligations.
Where the Notifiable Data Breaches scheme under the Privacy Act applies and a breach is likely to result in serious harm, we will take the steps required by that scheme, including notification where applicable.
Where an incident affects data we process on behalf of a client, we will work with the client in accordance with the applicable service arrangements and legal responsibilities.
14. Retention
We retain personal information for as long as reasonably necessary for the purpose for which it was collected, to provide Services, maintain business and accounting records, resolve disputes and comply with legal, regulatory or insurance requirements.
When information is no longer reasonably required, we may delete, destroy or de-identify it where appropriate and practicable.
Backup systems may retain copies for a limited period after information has been deleted from active systems.
15. Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
We may need to verify your identity before responding. In some circumstances permitted by law, access may be limited or refused. If that occurs, we will explain the reason where required.
16. Privacy complaints
If you have a concern about how we have handled personal information, please contact us using the details below and provide enough information for us to investigate.
We will aim to acknowledge and respond to privacy complaints within a reasonable period.
Where the Privacy Act applies and you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
17. Third-party websites and platforms
Our website and Services may link to or interact with third-party websites, platforms and services. We are not responsible for the privacy practices of those third parties, and their own terms and privacy policies apply when you interact with them.
18. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our Services, technology, business practices or legal obligations.
The current version will be published on this page with the date it was last updated. Where a change is material and it is reasonable to do so, we may also notify affected clients or users directly.
19. Contact us
For privacy questions, access or correction requests, or privacy complaints, contact:
IMExpert
Email: [email protected]
Phone: 02 7908 2430
Website: imexpert.au