Privacy policy

What we collect, why, and how to ask about it.

We audit other websites for missing privacy policies. Ours is real, written specifically for what SDG Services actually does, and current.

Last updated: 2026-05-19

Who we are

SDG Services is operated by Scott Gilbert, Avalon Beach NSW 2107, Australia. ABN [pending registration]. We're a Northern Beaches consultancy providing website audits and managed care for small Australian businesses.

What personal information we collect

SDG Services collects personal information in three contexts:

1. When you contact us

If you email us, fill out our contact form, or commission an audit, we collect:

  • Your name
  • Your email address
  • Your business name and website domain
  • Any other information you choose to provide (phone number, role, the specific concern that prompted you to contact us)

We store this in our records so we can respond to you, prepare the audit, and (if relevant) manage an ongoing care relationship.

2. When we audit your website

The audit process gathers data about your website — it doesn't gather personal information about your customers or staff from your website. Specifically, we consume:

  • What your servers return to any visitor (HTML, HTTP response headers, DNS records)
  • Public registry data (Certificate Transparency logs, RDAP, archive.org snapshots)
  • Australian public registers where applicable (ABN, ACECQA, AHPRA, etc. — only ever to verify your own business)

If your website happens to publicly display the names of your staff (a "team" page), we may extract those names as part of identifying the right decision-maker to address findings to. We never store personal information about your customers.

3. When you visit this website (sdgservices.com.au)

We don't use cookies for tracking. We don't run analytics tools that profile you. We don't load Google Analytics or Facebook Pixel or anything similar.

Our server may keep standard request logs (IP address, user agent, requested URL, response status) for up to 90 days for operational and security purposes. We don't use these for marketing or share them with third parties.

How we use your information

We use the information you provide solely to:

  • Deliver the audit or service you commissioned
  • Communicate with you about that work
  • Maintain records required for tax and accounting purposes
  • Improve our service (in aggregate, anonymised form)

We don't send marketing emails to people who haven't asked for them. We don't sell your data. We don't share it with anyone we don't have to.

Who we share information with

The short list:

  • Anthropic — we use Anthropic's Claude API to help generate audit text. The information sent to Anthropic includes the data we've gathered about your website (HTML, findings) plus the business name and domain. Anthropic's privacy and data-retention practices are at anthropic.com/legal/privacy.
  • Email infrastructure — we use [provider TBD] for transactional email. They process the emails we send and receive on our behalf.
  • Payment processor — if you pay us we use Stripe to process the payment. Stripe receives the payment information directly; we never see your full card details.
  • Australian Taxation Office — we keep records as required by tax law and may need to provide information to the ATO if requested.

How long we keep your information

We keep records of audit deliveries and managed-care relationships for seven years after the engagement ends, as required for Australian tax and business record-keeping. After that we delete the records.

Server access logs are kept for up to 90 days.

Your rights

Under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, you have the right to:

  • Ask what personal information we hold about you
  • Ask us to correct anything incorrect
  • Ask us to delete information we're not required to keep
  • Make a complaint about how we've handled your information

Email [email protected] with any of those requests. We respond within 30 days.

If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au.

Notifiable data breaches

We maintain reasonable security around the data we hold. If we ever experience an eligible data breach under the Notifiable Data Breaches scheme, we'll notify affected individuals and the OAIC promptly, as required by the Privacy Act 1988 Part IIIC.

Changes to this policy

We'll update this policy if the way we handle data changes — adding a new tool, changing infrastructure, etc. The "last updated" date at the top reflects the most recent change. Substantial changes will be communicated by email to active clients.

Contact

Privacy questions to [email protected]. Or write to Scott Gilbert, Avalon Beach NSW 2107, Australia.