Legal & Compliance

Privacy Policy

Spiderbox Design Pty Ltd — spiderbox.design

Version 1.0 — June 2026Applies to: Australia & United States

1. Our Commitment to Privacy

Spiderbox Design Pty Ltd ("Spiderbox", "we", "us", "our") is committed to protecting the privacy and security of personal information we collect in connection with our website, services, products, and business operations.

This Privacy Policy ("Policy") describes how we collect, use, disclose, store, and protect personal information when you:

  • Visit our website at spiderbox.design;
  • Submit any form on our website, including the System Friction Audit request form or general enquiry forms;
  • Download any gated content asset (whitepapers, guides, frameworks) from our website;
  • Engage with us as a client, prospect, partner, or business contact.

This Policy applies to all Spiderbox operations in Australia and the United States. Where applicable law in the United States requires additional disclosure, those requirements are addressed in Section 12.

This Policy should be read together with our Website Terms of Use.

2. Who This Policy Applies To

This Policy applies to:

  • Individuals who visit our website;
  • Individuals who submit enquiry, audit request, or gated content forms on our website;
  • Clients and their representatives (organisations and individuals);
  • Business partners, contractors, and suppliers;
  • Prospective clients and contacts acquired through business development activities.

This Policy does not apply to the personal information of Spiderbox's current or former employees in their capacity as employees.

3. Legal Framework

3.1 Australia

Spiderbox is bound by the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles ("APPs") contained therein. We are committed to compliance with our obligations as an APP entity.

3.2 United States

For individuals located in the United States, we take into account applicable federal and state privacy laws, including:

  • The California Consumer Privacy Act 2018 as amended by the California Privacy Rights Act 2020 ("CCPA/CPRA") — for California residents;
  • Other applicable US state privacy laws, including the Virginia Consumer Data Protection Act, Colorado Privacy Act, Texas Data Privacy and Security Act, and equivalent laws in force from time to time;
  • The CAN-SPAM Act 2003 in relation to commercial electronic communications.

Where an individual's rights under US state privacy law are broader than those provided under Australian law, we will honour those rights to the extent reasonably practicable.

3.3 Other Jurisdictions

If you access our website from outside Australia or the United States, your personal information will be transferred to and processed in Australia. We take reasonable steps to ensure such transfers comply with applicable law.

4. Personal Information We Collect

4.1 Information You Provide Directly

We collect personal information that you provide to us voluntarily, including through forms on this website. This includes:

  • Name and job title;
  • Organisation name and industry;
  • Email address and telephone number;
  • Business address;
  • Information you provide in free-text fields in our forms (including descriptions of your system challenges or workforce requirements);
  • Communications you send to us by email or other means.

4.2 Information Collected Automatically

When you visit our website, we and our analytics and advertising service providers may automatically collect:

  • IP address and approximate location (country, state, city);
  • Browser type, version, and language settings;
  • Device type and operating system;
  • Pages visited, links clicked, time spent on pages, and navigation paths;
  • Referral source (i.e. how you arrived at our website);

4.3 Information from Third Parties

We may also collect personal information about you from third-party sources, including:

  • LinkedIn and other professional networks, where you have made your profile publicly available;
  • Business referrals from existing clients or partners;
  • Public company and professional registries.

Where we collect personal information about you from a third party, we will take reasonable steps to notify you of that collection as required under APP 5.

5. How We Use Your Personal Information

Spiderbox uses personal information only for the purposes for which it was collected or for directly related purposes. Primary purposes include:

5.1 Delivering and Managing Services

  • Responding to enquiries, audit requests, and form submissions;
  • Providing consulting, design, and development services to clients;
  • Managing and administering client engagements and accounts;
  • Communicating with you about project status, deliverables, and outcomes.

5.2 Marketing and Business Development

  • Sending you information about Spiderbox services, insights, case studies, and resources that we reasonably believe may be of interest to you, based on your industry and expressed interests;
  • Following up on gated content downloads for business development purposes;
  • Inviting you to events, webinars, or workshops;
  • Improving our marketing communications and website content.

You may opt out of marketing communications at any time by following the unsubscribe link in any marketing email or by contacting us at partners@spiderbox.design.

5.3 Website Improvement and Analytics

  • Analysing website usage patterns to improve user experience and content;
  • Diagnosing and resolving technical issues;
  • Measuring the performance of our content and conversion pathways.

5.4 Legal and Compliance Purposes

  • Complying with applicable laws, regulations, and legal obligations;
  • Protecting the rights, property, or safety of Spiderbox, our clients, or others;
  • Enforcing our Terms of Use and other agreements.

6. Disclosure of Personal Information

We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

We may disclose your personal information to:

6.1 Service Providers

Trusted third-party service providers who assist us in operating our website and business, including:

  • Cloud hosting and infrastructure providers;
  • Website analytics providers (e.g. Google Analytics);
  • Email marketing and CRM platforms;
  • Customer support tools;
  • Document management and workflow platforms.

All service providers are contractually required to use personal information only for the purpose of providing services to Spiderbox and to maintain appropriate security safeguards.

6.2 Professional Advisors

Our legal, accounting, and financial advisors, where necessary for their professional services.

6.3 Legal Requirements

We may disclose personal information where required or authorised by law, including:

  • In response to a court order, subpoena, or other legal process;
  • To prevent, detect, or investigate fraud, criminal activity, or a serious threat to safety;
  • As required by a regulatory or law enforcement authority.

6.4 Business Transfers

In the event of a merger, acquisition, sale of assets, or other business restructuring, personal information held by Spiderbox may be transferred to a successor entity, subject to equivalent privacy protections.

7. Cross-Border Data Transfers

Spiderbox is headquartered in Australia. We engage service providers and operate across Australia and the United States. As a result, your personal information may be transferred to and stored in servers or systems located in Australia, the United States, and potentially other countries.

Before transferring personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles personal information in accordance with the APPs, or is subject to a law or binding scheme that provides substantially similar protections (APP 8.1).

For transfers to the United States, we rely on standard contractual protections and our service providers' compliance with applicable US privacy frameworks.

8. Security of Personal Information

Spiderbox takes reasonable technical, physical, and administrative measures to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure. These measures include:

  • Encrypted storage for all personal information in our systems;
  • Role-based access controls limiting access to personal information to authorised personnel;
  • Secure transmission protocols (HTTPS/TLS) for all website data exchange;
  • Regular review and testing of security controls;
  • Staff training on privacy and data handling obligations.

No method of data transmission or storage is completely secure. In the event of a data breach that is likely to result in serious harm to affected individuals, we will comply with the Notifiable Data Breaches ("NDB") scheme under Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner ("OAIC") as required.

9. Data Retention

We retain personal information for as long as reasonably necessary to fulfil the purpose for which it was collected, unless a longer retention period is required or permitted by law.

Retention guidelines:

  • Form submissions and enquiries: retained for a minimum of 3 years from the date of last contact;
  • Client engagement records: retained for 7 years from the end of the engagement, consistent with Australian taxation and business records obligations;
  • Marketing consent records: retained for the duration of the consent and for a period of 3 years following unsubscription or withdrawal of consent;
  • Website analytics data: retained in accordance with the retention policies of the applicable analytics platform (typically 14–26 months).

When personal information is no longer required, we will take reasonable steps to destroy or de-identify it securely.

10. Your Rights: Access, Correction, and Complaints

10.1 Access and Correction (All Individuals)

You have the right to request access to personal information Spiderbox holds about you, and to request correction of any information that is inaccurate, incomplete, or out of date. To make such a request, please contact us in writing at partners@spiderbox.design.

We will respond to access and correction requests within 30 days. We may require you to verify your identity before processing a request. Where we deny access, we will provide written reasons as required under APP 12.

10.2 Additional Rights — California Residents (CCPA/CPRA)

If you are a California resident, in addition to the rights above you have the following rights under the CCPA/CPRA:

  • Right to Know: The right to know the categories and specific pieces of personal information we have collected about you, the categories of sources, the business or commercial purposes for collection, and the categories of third parties to whom we disclose it;
  • Right to Delete: The right to request deletion of personal information we have collected about you, subject to applicable exceptions;
  • Right to Correct: The right to request correction of inaccurate personal information;
  • Right to Opt-Out of Sale or Sharing: Spiderbox does not sell or share personal information for cross-context behavioural advertising purposes. We have no "Do Not Sell or Share My Personal Information" mechanism because we do not engage in such activity;
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA/CPRA rights;
  • Right to Limit Use of Sensitive Personal Information: We do not collect sensitive personal information as defined by the CCPA/CPRA in the ordinary course of our website operations.

To exercise your California rights, submit a verifiable consumer request to partners@spiderbox.design with the subject line "California Privacy Request". We will respond within 45 days.

10.3 Additional Rights — Other US State Residents

Residents of Virginia, Colorado, Texas, and other states with comprehensive privacy legislation may have similar rights to access, correct, delete, and obtain a portable copy of their personal information. To exercise these rights, contact us at partners@spiderbox.design.

10.4 Complaints (Australia)

If you believe we have breached the APPs or this Policy, you may lodge a privacy complaint with us at partners@spiderbox.design. We will acknowledge receipt within 5 business days and endeavour to resolve your complaint within 30 days.

If you are not satisfied with our handling of your complaint, you may refer the matter to the Office of the Australian Information Commissioner ("OAIC") at www.oaic.gov.au.

11. Children's Privacy

This Website is directed exclusively at business users and is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors. If we become aware that we have inadvertently collected personal information from a minor, we will take prompt steps to delete it.

12. Additional Disclosures for United States Residents

12.1 Categories of Personal Information Collected (CCPA)

In the preceding 12 months, Spiderbox has collected the following categories of personal information from US residents:

  • Identifiers (name, email, IP address, organisation);
  • Professional or employment-related information (job title, company, industry);
  • Internet or network activity (browsing history on our website, form interactions);
  • Geolocation data (approximate location based on IP address).

12.2 Commercial Communications

Our commercial email communications comply with the CAN-SPAM Act 2003. Every marketing email we send includes: our physical mailing address; a clear and conspicuous unsubscribe mechanism; and accurate header and subject line information.

13. Changes to This Policy

Spiderbox reserves the right to amend this Policy at any time. Material changes will be notified by posting an updated Policy on our website with a revised effective date. We may also notify you directly where required by applicable law. Your continued use of our website or services after the effective date constitutes acceptance of the revised Policy.

14. Contact and Privacy Enquiries

For all privacy enquiries, access requests, correction requests, complaints, or to exercise any rights described in this Policy, please contact:

This Policy was last updated in (Version 1.0).