Effective Date: Updated 1 April 2026
Last Updated: 1 April 2026
1.0 INTRODUCTION & GOVERNING LAW
1.1 Our Commitment to Privacy
Nat Gatt Brand Studio (hereinafter referred to as the “Studio”, “we”, “us”, or “our”) is committed to providing quality design and branding services while strictly protecting your privacy. This policy outlines our ongoing obligations to you in respect of how we manage your Personal Information.
1.2 Governing Law
We have adopted and are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act). The APPs govern the way in which we collect, use, disclose, store, secure, and dispose of your Personal Information. A complete copy of the Australian Privacy Principles may be obtained from the website of The Office of the Australian Information Commissioner at www.oaic.gov.au.
2.0 INFORMATION WE COLLECT & HOW WE COLLECT IT
2.1 What is Personal Information?
Personal Information is information or an opinion that identifies an individual. The types of personal information we collect depend on the nature of your engagement with the Studio.
2.2 Active Data Collection
We collect Personal Information directly from you when you interact with us. This includes, but is not limited to: names, business names, Australian Business Numbers (ABNs), physical addresses, email addresses, phone numbers, payment details, and specific project briefs. This information is obtained via direct correspondence, telephone, email, and forms submitted through our website (www.natgatt.com.au).
2.3 Passive Data Collection (Digital Analytics)
When you visit our website, we may also passively collect digital information about your visit. This may include your IP address, browser type, operating system, pages viewed, and geographical location. We use “cookies” to gather this data, which helps us analyse website traffic and improve user experience. You may configure your web browser to refuse cookies; however, this may limit your ability to fully utilize our website.
2.4 Sensitive Information
Sensitive information is defined in the Privacy Act to include information about an individual’s racial or ethnic origin, political opinions, religious beliefs, criminal record, or health information. The Studio does not actively solicit or require Sensitive Information to perform its design services. If you inadvertently provide Sensitive Information, it will be used solely for the primary purpose for which it was obtained and with your explicit consent.
2.5 Unsolicited Information
If we receive Personal Information that we have not taken active steps to collect (such as unsolicited portfolios or vendor pitches), we will determine if we could have lawfully collected it under the APPs. If not, we will destroy or de-identify the information as soon as practicable, provided it is lawful and reasonable to do so.
2.6 Third-Party Links
Our website may contain links to external websites that are not operated by us. Please be aware that we have no control over the content and privacy practices of these sites, and cannot accept responsibility or liability for their respective privacy policies once you leave our domain.
3.0 HOW WE USE & DISCLOSE YOUR DATA
3.1 Primary Purpose
We collect your Personal Information strictly for the primary purpose of executing our commercial services. This includes project quoting, design execution, account management, invoicing, and direct client communication.
3.2 Secondary Purpose & Marketing
We may also use your Personal Information for secondary purposes closely related to the primary purpose, such as Studio updates, portfolio marketing, or service announcements. You may opt out of our marketing mailing lists at any time by contacting us in writing or utilizing the ‘unsubscribe’ link in our communications.
3.3 Disclosure to Third-Party Vendors
To operate efficiently as a modern digital studio, we utilize industry-standard third-party vendors and software platforms. By engaging our services, you consent to the necessary sharing of your Personal Information with these trusted partners, which may include:
Administrative Platforms: Accounting software (e.g., Xero) and CRM databases.
Operational Platforms: Cloud storage and file delivery services (e.g., Adobe Creative Cloud, Google Workspace, Dropbox).
Manufacturing Partners: Third-party printers or production houses strictly for the purpose of manufacturing your approved physical deliverables.
Business Transfers: In the event that the Studio is acquired, merged, or undergoes a change of control, Client data and Personal Information will be considered a transferable business asset and shared with the acquiring entity, subject to the same privacy commitments outlined in this policy.
Independent Contractors & Sub-contractors: Freelance specialists (such as copywriters, web developers, or virtual assistants) engaged by the Studio to assist in executing your project. All contractors are bound by strict confidentiality agreements prior to accessing any Client data.
Where reasonable and practicable to do so, we will collect your Personal Information only from you. If we are provided with information by third parties, we will take reasonable steps to ensure that you are made aware of the information provided to us.
3.4 Case Studies & Testimonials
While the Studio retains the intellectual property rights to display completed design work (as outlined in our Terms of Service), we strictly separate visual portfolio rights from your Personal Information. We will never publish your Personal Information (such as full names, direct quotes, or private business metrics) in public case studies or testimonials without your prior explicit written consent.
4.0 CROSS-BORDER DATA DISCLOSURE
4.1 Overseas Servers & Cloud Infrastructure
In the course of providing our services, the Studio utilizes global, industry-leading cloud infrastructure, software-as-a-service (SaaS) platforms, and web hosting facilities. Consequently, your Personal Information may be transferred to, stored in, or processed on servers located outside of Australia (commonly including the United States, the European Union, and Singapore).
4.2 Client Consent
By providing your Personal Information to the Studio, you expressly consent to this cross-border transfer. We take all reasonable steps to ensure that any overseas third-party service providers have robust privacy and data protection frameworks in place that align with the general intent of the Australian Privacy Principles.
5.0 DATA SECURITY & RETENTION
5.1 Security Measures
Your Personal Information is stored in a manner that reasonably protects it from misuse, interference, loss, and from unauthorized access, modification, or disclosure. We utilize strict operational protocols including password-protected hardware, multi-factor authentication (MFA) on core administrative platforms, and encrypted cloud storage.
5.2 Data Retention & Destruction
When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify it.
Creative Assets: General project files, briefs, and creative assets will be archived and retained for a commercially reasonable period following project completion to facilitate future client requests, after which they may be securely deleted.
Financial Records: To comply with Australian Taxation Office (ATO) requirements, standard administrative and financial records (such as signed contracts and invoices containing your Personal Information) will be securely retained for a minimum of seven (7) years.
6.0 MANDATORY DATA BREACH PROTOCOL
6.1 The NDB Scheme
The Studio strictly complies with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988. A data breach occurs when Personal Information held by the Studio is lost, or subjected to unauthorized access or disclosure.
6.2 Incident Response
In the highly unlikely event of a suspected data breach, the Studio will immediately take all reasonable steps to contain the breach and conduct a rapid risk assessment.
6.3 Notification
If our assessment determines that the data breach is likely to result in “serious harm” to any individual whose information was involved, we will formally notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, detailing the nature of the breach and the recommended steps individuals should take to protect themselves.
7.0 CLIENT ACCESS, CORRECTIONS & COMPLAINTS
7.1 Accessing & Correcting Your Data
You have the right to access the Personal Information we hold about you and to update and/or correct it, subject to certain exceptions outlined in the Privacy Act. If you wish to access your Personal Information, please contact us in writing.
We will take reasonable steps to ensure your Personal Information is accurate, complete, and up-to-date. The Studio will not charge any fee for an access request, but may charge a reasonable administrative fee for the time required to collate and provide a copy of your Personal Information. In order to protect your data, we will require formal identification before releasing any requested information.
7.2 Privacy Complaints & Enquiries
If you have any queries, concerns, or complaints regarding our Privacy Policy or our data handling practices, please contact our Privacy Officer:
Email: hello@natgatt.com.au
Mailing Address: PO Box 8139, Glenmore Park, NSW, 2745
We take all complaints seriously and will aim to respond and resolve your concern within a commercially reasonable timeframe (typically within 30 days).
7.3 Revoking Consent & Data Erasure
Where you have provided explicit consent for the Studio to use your Personal Information for specific purposes (such as public case studies or marketing lists), you maintain the right to withdraw this consent at any time. Upon receiving a formal written request to revoke consent or erase your data, the Studio will take all reasonable steps to remove the specified Personal Information from our active digital platforms within thirty (30) days, unless we are legally required to retain it for administrative or tax compliance purposes.