Privacy Policy
DD Consulting Pty Ltd · ABN 65 646 596 867 · Last updated 29 September 2026
We respect your privacy and handle personal information in accordance with the Australian Privacy Principles. This policy sets out what we collect, why, who we share it with and how you can access or correct it.
1. Who we are
DD Consulting Pty Ltd (ABN 65 646 596 867) (“DD Consulting”, “we”, “us”) is an Australian strategic engineering consultancy headquartered in Norwest, New South Wales, servicing clients across Australia and through satellite offices overseas. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy explains how we collect, use, disclose and protect personal information through our website ddconsult.com.au and in the course of our consulting engagements.
2. What personal information we collect
We collect only what we need to respond to you and deliver our services. Depending on how you interact with us, this may include:
- Contact details you give us — name, business email, company, role and phone number (contact and inquiry forms, briefing requests).
- Assessment data — your answers to the AI & Digital Maturity Assessment, your scores and the context you provide (company size, sector).
- Engagement data — information you share with us as a client or prospective client, including business, technical and operational information needed to scope and deliver work.
- Technical and usage data — IP address, browser and device information, pages visited and interactions, collected through cookies and similar technologies (see section 7).
- Conversational data — messages you exchange with our website assistant (AskDD), used to respond to you and improve the assistant.
We do not knowingly collect sensitive information (such as health or biometric information) through the website. If an engagement requires it, we will agree the handling with you in writing first.
3. How we collect it
Directly from you when you complete a form, take the assessment, email or call us, or engage us; automatically through cookies and analytics when you browse; and from publicly available business sources or referrals where reasonable and lawful.
4. Why we collect, hold, use and disclose it
- To respond to enquiries and provide the information, briefing or assessment report you requested.
- To scope, deliver, manage and improve our consulting and engineering services.
- To send you relevant insights or updates where you have opted in (you can unsubscribe at any time).
- To operate, secure and improve our website and understand how it is used.
- To meet our legal, regulatory, accounting and professional obligations.
5. Who we share it with
We do not sell personal information. We share it only with service providers that help us operate, under contracts that restrict their use of it:
- Cloud hosting and infrastructure — Amazon Web Services (Sydney Region, ap-southeast-2) for our website and client platforms.
- CRM and marketing — HubSpot, for managing contacts, enquiries and consented communications.
- Productivity and storage — Google Workspace (including Google Sheets and Apps Script) for enquiry and assessment records.
- Analytics and protection — Google Analytics and Google reCAPTCHA, to measure site usage and prevent spam.
- Professional advisers, insurers and regulators where required by law.
6. Overseas disclosure
Our website and client data are hosted in Australia. Some providers listed above (for example HubSpot and Google) may process data in other countries, including the United States. Our satellite offices in Sri Lanka, India, Singapore, Vietnam, Fiji and the United States may access engagement information where needed to deliver work for you. Where personal information is disclosed overseas, we take reasonable steps consistent with APP 8 to ensure it is handled in accordance with the APPs.
8. How we protect it
We apply secure-by-design practices to our own systems: encryption in transit and at rest, least-privilege access, logging and monitoring, and data residency in the AWS Sydney Region. Our governance approach is aligned to ISO/IEC 27001 and ISO/IEC 42001 practices. No method of transmission or storage is completely secure; if we become aware of an eligible data breach we will act in accordance with the Notifiable Data Breaches scheme.
9. How long we keep it
We keep personal information only as long as needed for the purposes above or as required by law (for example, financial records for seven years). Assessment and enquiry records are reviewed periodically and de-identified or deleted when no longer needed.
10. Access, correction and complaints
You may request access to, or correction of, the personal information we hold about you by emailing info@ddconsult.tech. We will respond within 30 days. If you have a complaint about how we have handled your information, contact us first; if you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
11. AI systems and automated processing
Some website features (the maturity assessment scoring and the AskDD assistant) use rules-based and AI-assisted processing to generate guidance. These outputs are informational and are not decisions with legal or similarly significant effects. We do not use your enquiry data to train third-party foundation models.
12. Changes to this policy
We may update this policy from time to time. The current version is always published at ddconsult.com.au/privacy-policy/ with the date of the last update.
