What we collect, why we hold it, who else touches it, and what our AI tooling is not allowed to do with it. Every third party is named. Nothing here is padding.
didodot is the trading name of Rhys Timothy Nolan, a sole trader registered in New South Wales, ABN 80 144 081 170. In this policy, "didodot", "we" and "us" mean that entity, and "you" means anyone who uses this website, sends us an enquiry, or engages us to do work.
didodot operates Australia-wide. The business is based in New South Wales and has delivered paid work on site in New South Wales and Victoria. We take engagements anywhere in Australia, and this policy applies the same way in every state and territory.
This policy covers personal information we handle as a business. It does not cover the separate written data terms that sit inside a client engagement, which are more specific and take priority for that client's own material.
Privacy contact
rhys@didodot.com
Postal
Available on request by email
Entity
Rhys Timothy Nolan
Trading as
didodot
02
Our position under the Privacy Act
didodot's annual turnover is under $3 million, so under section 6D of the Privacy Act 1988 (Cth) we are a small business operator and would ordinarily be exempt from the Act.
The exemption also stops applying by law in several situations we can genuinely find ourselves in, so the practical position and the legal one are the same. The Act applies to a small business operator that provides a health service and holds health information, that trades in personal information for a benefit, or that provides services under a Commonwealth contract.
If we cross the $3 million turnover threshold, the Act applies to us directly and nothing in this policy changes, because it was written to that standard from the start.
03
What we collect, and when
We collect only what a job needs. Each item below names the point of collection, so you can see exactly what handing us something involves.
Contact form
Your name, your email address, and the message you write. Nothing else. The form is capped at 100 characters for a name, 254 for an email and 2,000 for a message.
Email and calls
Whatever you choose to tell us, plus the ordinary metadata of an email or a calendar invitation.
Billing
Your name or business name, billing email, billing address, invoice amounts and payment status. We never receive, see or store your card number.
Website logs
IP address, browser user agent, requested page and timestamp, captured by our hosting and security layer and held briefly for security and fault diagnosis.
Engagement material
During a diagnostic or a build, a client gives us documents, process descriptions and system exports. These sometimes contain personal information about that client's staff or customers.
We do not run analytics on this website. There is no Google Analytics, no advertising pixel, no session recording, no heat mapping and no third-party tracker of any kind. We do not build profiles of visitors, and we do not sell, rent or trade personal information to anyone, ever.
04
Cookies
This website sets one cookie. It is called __cf_bm, it is set by Cloudflare, it distinguishes a human visitor from an automated one, and it expires after about thirty minutes. It is strictly necessary for the security of the site and it does not track you across other websites.
There are no advertising cookies, no analytics cookies and no preference cookies on this site. Because the only cookie we set is strictly necessary, we do not show a consent banner, which is also why you are not being asked to click one.
You can block cookies in your browser. Blocking this one may cause Cloudflare to challenge or slow your requests, but the site will still work.
05
Why we hold it
To answer your enquiry and work out whether we are a fit for the job
To scope, quote and deliver work you have engaged us for
To invoice you and collect payment
To keep the business records the Australian Taxation Office requires us to keep
To keep the website and our systems secure and working
To meet a legal obligation, or to establish or defend a legal claim
We do not use your information for any other purpose without asking you first. We do not send marketing email to people who filled in the contact form. If we ever start a mailing list it will be opt in, it will identify us, and it will carry a working unsubscribe link, as the Spam Act 2003 (Cth) requires.
06
Who else touches it
We use a small number of service providers to run the business. Each one is named here with what it actually handles, because a policy that says "trusted third parties" is telling you nothing.
Formspree
Receives and forwards contact form submissions. Holds your name, email and message. United States.
Stripe
Issues and processes invoices. Holds billing details and card data directly, under its own terms. United States, with Australian processing.
Cloudflare
Serves and protects this website. Sees IP addresses and request metadata. Global network, including Sydney.
Lovable
Builds and deploys this website. Holds the site's source code, not your personal information.
Google Workspace
Email and calendar. Holds correspondence with you. United States and elsewhere.
Anthropic
The AI platform we use in our own work, on a commercial plan whose terms exclude training on customer data. See clause 07.
We disclose personal information outside that list only where you ask us to, where the law requires it, or where it is needed to establish, exercise or defend a legal claim.
07
AI, and what it is not allowed to do with your information
didodot implements AI systems and uses AI tools in its own work. We are open about that, and the rules below are the ones we hold ourselves to. They are the same rules we build into a client's system.
Client material is not used to train anyone's models. We work on commercial plans whose terms exclude training on customer data, and we do not paste client material into consumer chat products.
AI output is a draft, never a decision. A person reads and approves anything that leaves the business.
No system we build contacts a client's customers. Anything customer facing is a draft, and a person sends it or bins it.
Connections into a client's systems start read only. Write access is a separate decision the client makes in writing, per system.
Nothing we build certifies anything. A checking skill flags gaps against the client's own checklist. It refuses to declare a file complete, compliant or audit ready.
What stays out of an AI system entirely is decided with the client before anything is connected.
We do not use AI to make an automated decision about you. Nothing on this website decides whether to engage you, what to charge you, or anything else affecting your rights or interests, and no such decision is made about you without a person making it.
08
Security
The whole site is served over HTTPS with HSTS, so a browser will not connect to it insecurely.
Card details never reach our systems. The payment page hands you to Stripe, and Stripe holds the card.
Our Stripe key is a restricted, read-only key held server side, and it never reaches your browser.
This website holds no client database and no client data. There is nothing on it to breach.
Accounts that reach email, files or client systems are protected by multi-factor authentication.
No system is perfect and we will not pretend otherwise. If a data breach happens that is likely to cause you serious harm, we will contain it, tell the people affected, and notify the Office of the Australian Information Commissioner, on the timeframes the Notifiable Data Breaches scheme sets. We will do that whether or not the scheme legally binds us at the time, for the reason given in clause 02.
09
How long we keep it
Enquiry that goes nowhere
Deleted within 12 months of the last contact.
Client records and correspondence
Seven years, which covers the five years of business records the ATO requires and the six year limitation period for a contract claim in New South Wales.
Invoices and payment records
Seven years, for the same reason.
Website logs
Kept only as long as our hosting and security providers keep them, which is a matter of days to weeks.
Client engagement material
Returned or destroyed at the end of the engagement on request, other than what we must keep to meet a legal obligation.
When a retention period ends we delete or de-identify the information.
10
Your rights, and how to use them
You can ask us for a copy of the personal information we hold about you, ask us to correct it if it is wrong, ask us to delete it, or ask how we got it. Email the address in clause 01 and say what you want.
We will acknowledge your request within five business days.
We will answer it within 30 days.
We do not charge for access requests.
If we refuse, we will tell you why in writing, and how to complain about it.
We may need to verify who you are before handing over information about you, which is a protection for you rather than an obstacle.
11
Complaints
If you think we have mishandled your personal information, email the address in clause 01 with "Privacy complaint" in the subject line. We will acknowledge it within five business days and give you a written answer within 30 days.
If you are not satisfied with that answer, you can take it to the Office of the Australian Information Commissioner at oaic.gov.au, on 1300 363 992, or by writing to GPO Box 5218, Sydney NSW 2001. You do not need our permission to do that and you do not need to wait for us to finish.
12
Changes to this policy
We update this policy when what we actually do changes. Every version carries a version number and an effective date in the title block at the top of this page, so you can tell whether the copy you read last time is the one in force now.
If a change materially reduces the protection you get under this policy, we will say so at the top of the page for at least 30 days after it takes effect rather than changing it quietly.
Questions about this policy go to rhys@didodot.com. Read alongside the terms of service, which governs the use of this website and the shape of an engagement.