Who we are
NextLead Digital builds managed outbound systems and AI supported roles for professional services firms. We are the controller of the personal information described in this policy, which in Australian and New Zealand terms means we are the organisation responsible for it.
- Trading name: NextLead Digital
- ABN: 20 751 550 245
- Registered address: 3 Loftus Street, West Leederville WA 6007, Australia
- Privacy contact: hello@nextleaddigital.com.au
If you want to make a privacy request, ask a question or raise a complaint, email the address above and put the word Privacy in the subject line. That is the fastest way to get it in front of the right person.
Which privacy laws apply
We work across four markets, and the rules are not identical in each one. Rather than apply the weakest standard everywhere, we apply the protections that fit the person we are dealing with.
Australia
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth), and we treat those principles as binding on us regardless of whether the small business exemption would otherwise apply. Commercial electronic messages are governed by the Spam Act 2003 (Cth).
New Zealand
We handle personal information in line with the Information Privacy Principles in the Privacy Act 2020. Commercial electronic messages are governed by the Unsolicited Electronic Messages Act 2007.
United Kingdom
We handle personal data in line with the UK GDPR and the Data Protection Act 2018. Cookies, similar technologies and electronic marketing are governed by the Privacy and Electronic Communications Regulations, known as PECR.
Ireland and the European Economic Area
We handle personal data in line with the EU General Data Protection Regulation and the Data Protection Act 2018 (Ireland). Cookies, similar technologies and electronic marketing are governed by the ePrivacy Regulations, S.I. 336 of 2011.
In the United Kingdom and Ireland, sole traders and partnerships are treated as individuals rather than as businesses for electronic marketing. We apply the stricter individual standard to those contacts, which means we do not send them unsolicited marketing email without consent or an existing relationship.
The information we collect
If you contact us or become a client
- Name, work email address, phone number, business name, role and location
- What you tell us about your business, such as size, revenue band, services and what is currently holding growth back
- Meeting details, notes, recordings where you have agreed to them, actions and follow up correspondence
- Contract and billing records. Card and bank payments are handled by our payment provider rather than stored by us
If we contact you as a prospective client
- Name, business name, role, work email address and business phone number
- Publicly available business information such as website, location, headcount range, industry and recent announcements
- Whether a message was delivered, opened, clicked or replied to, and whether you asked us to stop
When you visit this website
- IP address, approximate location derived from it, browser and device type, operating system and referring page
- Pages viewed, time on page and the links you follow, where analytics are switched on and you have consented
- Security and server logs kept by our hosting provider
Information we do not want
We do not ask for sensitive information such as health, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation or criminal records, and we ask that you do not send it to us. If you do send it, we will delete it unless we are legally required to keep it. This website and our services are not directed at children, and we do not knowingly collect information about anyone under 16.
Where we get your information
Most of the time we get information directly from you, when you email us, book a call, reply to a message or work with us. We also collect business contact information from other places, and you have a right to know where.
- Publicly available business sources, such as company websites, public company registers and published contact pages
- Professional and business networking platforms, where a person has published their role and employer
- Reputable business data providers who license business contact data, and who confirm they have a lawful basis for supplying it
- Publicly reported business news, awards, directories and industry listings
- Referrals, where someone passes on your details. We will tell you who referred you if you ask
We collect business contact details in a professional capacity, such as a work email address at a company domain. We do not buy or use personal email addresses, home addresses or personal mobile numbers for outreach, and we do not sell personal information to anyone.
If we contacted you and you did not give us your details yourself, you can email us and ask exactly where they came from. We will tell you the source, what we hold and how to have it removed. In the United Kingdom and Ireland we will do this within one month.
How we use it, and our lawful bases
In the United Kingdom and Ireland we must have a lawful basis for every use of personal data. The table below sets out what we do and why. In Australia and New Zealand we use personal information only for the purpose it was collected for, or for a related purpose you would reasonably expect.
Replying to you, arranging a call, assessing whether our services suit your business and keeping a record of what was discussed.
Steps taken at your request before a contract, and our legitimate interests in running the businessScoping, building, running and reviewing the systems we are engaged to deliver, and managing the commercial relationship.
Performance of a contract with you or your organisationContacting decision makers at businesses that match the profile we work with, about a specific and relevant offer.
Our legitimate interests in promoting relevant services to relevant businessesUnderstanding which pages are read, measuring advertising, and showing our advertising to people who have visited this website.
Your consent, which you can withdraw at any timeProtecting the website and our systems from misuse, unauthorised access, spam and fraud.
Our legitimate interests in keeping our systems and information safeKeeping business, tax and accounting records, responding to lawful requests and handling disputes.
Compliance with a legal obligation, and our legitimate interests in defending legal claimsWhere we rely on legitimate interests, we have weighed our interest in growing the business against your rights, and we keep that assessment on file. You can ask us for a summary of it, and you can object at any time. If you object to direct marketing, we stop. There is no balancing test for that one.
We do not make decisions about you using automated processing alone that produce legal or similarly significant effects. We use software to help select and prioritise who we contact, and a person stays responsible for the decision to send.
Business to business outreach
Outbound email is part of what we sell, so we hold ourselves to the standard we would want a supplier to meet. This section explains exactly how we do it.
Who we contact and why
We contact decision makers at businesses that match the profile we work with, which is owner led professional services firms with roughly 2 to 50 people. We use business contact details in a professional capacity, and we write about a specific, relevant offer rather than sending untargeted bulk mail. We do not contact private individuals about personal matters, and we do not contact anyone at a personal email address.
Every message we send
- Identifies NextLead Digital clearly as the sender
- Gives accurate sender details and a working reply address that a person monitors
- Includes a simple way to opt out, in the message itself, with no account or login needed
- Is sent from our own sending domains, never from a client domain
When you opt out
We action opt outs promptly and in any case within five working days, which is the outer limit set by Australian and New Zealand law. In practice it is faster. Replying with the word unsubscribe, or remove me, or anything to that effect, counts. You do not need to use the link.
We then add your address to a suppression list so you are not contacted again. We keep suppression records for as long as we operate, because keeping a record of your opt out is the only reliable way to honour it. That record holds the minimum needed, which is the address and the date.
How this works in each market
- Australia. Under the Spam Act 2003, consent can be inferred where a work address is published publicly, is not accompanied by a statement that unsolicited messages are not wanted, and the message is relevant to that person's role. We rely on inferred consent on that basis, and we honour every opt out.
- New Zealand. The Unsolicited Electronic Messages Act 2007 works in a similar way, and we apply the same approach, including accurate sender information and a functional unsubscribe facility.
- United Kingdom. Under PECR we email corporate subscribers, meaning limited companies and limited liability partnerships. The UK GDPR still applies to the data, and our lawful basis is legitimate interests. You have an absolute right to object.
- Ireland. Under the ePrivacy Regulations we email business addresses at corporate subscribers, we identify ourselves, we provide an opt out in every message and we do not send to anyone who has objected.
- Sole traders and partnerships in the UK and Ireland. These are treated as individuals, so we do not send them unsolicited marketing email without consent or an existing relationship.
Phone contact
Where we call businesses in Australia, we screen against the Do Not Call Register in line with the Do Not Call Register Act 2006, and we apply the equivalent screening in the other markets we work in.
Advertising and remarketing
We advertise our own services. When our advertising is running, the platforms below may place cookies or similar identifiers on your device so that our ads can be measured and shown to relevant audiences. Where consent is required, none of this happens until you give it.
What remarketing actually does
Remarketing means that if you visit this website, we can ask an advertising platform to show our ads to you again on that platform. The platform recognises the visit through an identifier set in your browser. We do not learn your identity from this, and we do not see a list of the individual people who saw an ad. We see counts and aggregate performance.
The platforms we use or expect to use
- Google Ads and Google Analytics. Conversion measurement and remarketing audiences. Where required we operate Google consent mode, so no advertising identifiers are set until you consent. You can manage your Google ad settings at adssettings.google.com.
- Meta, covering Facebook and Instagram. The Meta pixel for conversion measurement, plus custom and lookalike audiences. You can manage your Meta ad preferences at facebook.com/adpreferences.
- LinkedIn. The LinkedIn Insight Tag for conversion measurement and matched audiences. You can manage this in your LinkedIn account under advertising data.
Customer lists and matched audiences
Advertising platforms allow an advertiser to upload a list of contacts so that ads can be shown to those people, or so that similar audiences can be built. Where we do this, the contact details are hashed before they are sent, which converts them into a scrambled value that the platform matches against its own hashed records.
We only include business contacts in those lists, we exclude anyone who has opted out, and we exclude contacts in the United Kingdom, Ireland and the European Economic Area unless we have the consent that applies there. You can ask us to exclude you from all advertising audiences at any time, and we will action it.
Joint responsibility
For some advertising tools, we and the platform are jointly responsible for the collection and transmission of data from this website. The platform is separately responsible for what it does with that data afterwards, under its own terms and privacy notice. We will link to those notices in our consent banner so you can read them before you decide.
Industry opt outs
You can use youronlinechoices.com.au in Australia, youronlinechoices.eu in Ireland and the European Economic Area, and youronlinechoices.com in the United Kingdom to opt out of interest based advertising from participating companies.
Sending information overseas
We are based in Australia, and we work with clients and providers in New Zealand, the United Kingdom, Ireland, the European Economic Area and the United States. That means personal information may be stored or processed outside the country you are in.
Before we send personal information overseas, or let a provider do so, we take reasonable steps to make sure it stays protected. Depending on where it goes, that means one or more of the following.
- Choosing providers in countries recognised as offering adequate protection
- Standard contractual clauses approved by the European Commission, and the international data transfer agreement or addendum approved in the United Kingdom
- Contract terms that require overseas providers to handle the information consistently with the Australian Privacy Principles, and with comparable safeguards under New Zealand's Privacy Act 2020 where that applies
- Checking the provider's security position, and limiting what is sent to what is needed
You can email us for details of the safeguards used for a particular transfer.
How long we keep information
We keep information only while we need it, then delete it or de-identify it. These are our standard periods.
- Enquiries that do not proceed. Up to 24 months from the last contact, so we have context if you come back to us.
- Prospect details we have not engaged with. Up to 12 months, then reviewed and removed if there is no interest.
- Client records. For the engagement, then seven years, which reflects Australian tax, accounting and corporate record keeping requirements.
- Opt out and suppression records. Kept indefinitely, because that is what makes an opt out stick. We hold only the address and the date.
- Website and security logs. Generally up to 12 months.
- Analytics and advertising data. As set by the platform, typically between 2 and 26 months.
If a legal claim, investigation or regulatory request is on foot, we keep the relevant records until it is resolved.
Security and data breaches
We use reasonable technical and organisational measures to protect personal information. That includes encryption in transit, access controls and multi-factor authentication on business systems, limiting access to people who need it, keeping software patched, and checking the security position of providers before we use them.
No system is completely secure, so we also reduce risk by collecting less and keeping it for less time.
If a data breach happens that is likely to cause serious harm, we will act on it and notify people and regulators as the law requires. In Australia that is the Notifiable Data Breaches scheme and the Office of the Australian Information Commissioner. In New Zealand it is the Office of the Privacy Commissioner. In the United Kingdom and Ireland it means notifying the relevant supervisory authority within 72 hours where the breach meets the threshold, and telling affected people where the risk to them is high.
Your privacy rights
Wherever you are, you can ask us to stop sending you marketing, and you can ask what we hold about you. Beyond that, your rights depend on where you are.
Australia and New Zealand
- Access the personal information we hold about you
- Ask us to correct it if it is wrong or out of date
- Ask us to stop using it for direct marketing
- Ask us how we got it, and complain if you think we have mishandled it
- Deal with us anonymously or under a pseudonym where that is lawful and practical
United Kingdom, Ireland and the European Economic Area
- Access a copy of your personal data
- Have inaccurate data corrected
- Have data erased in certain circumstances
- Restrict how we use it while a concern is looked into
- Receive data you gave us in a portable format, and have it sent to another provider where that is technically feasible
- Object to processing based on legitimate interests, and object to direct marketing at any time with no reason needed
- Withdraw consent at any time, which does not affect what we did before you withdrew it
How to make a request
Email hello@nextleaddigital.com.au. Requests are free. We may need to verify your identity before we act, and we will only ask for what is needed to do that.
We respond within 30 days in Australia, within 20 working days in New Zealand, and within one month in the United Kingdom and Ireland. If a request is complex we may extend that period, and we will tell you if we do. If we cannot do what you have asked, we will explain why and tell you how to take it further.
Complaints and regulators
Please come to us first, because most things are quickest to fix directly. Email us with the detail and we will investigate and respond. If you are not satisfied with our answer, you can complain to the regulator where you are.
Changes and contact
We update this policy when our practices change, including when we switch on analytics or advertising technologies. The date at the top shows when it last changed. If a change materially affects how we use information you have already given us, we will tell you directly where we reasonably can.
For anything in this policy, email hello@nextleaddigital.com.au or write to NextLead Digital, 3 Loftus Street, West Leederville WA 6007, Australia.