- Entity
- CDT Solutions Pty Ltd
- ACN
- 702 491 978
- ABN
- 44 702 491 978
- Address
- C/- Kappatos Consulting & Advisory, 1 Sussex St, Barangaroo NSW 2000, Australia
- Contact
- conor@cdtsolutions.net.au
Who this policy covers
CDT Solutions Pty Ltd (“CDT”, “we”, “us”, “our”) provides websites and automation systems for Australian service businesses. This policy covers information we collect through this website and in the course of providing our services.
Where applicable, we handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, and comply with other laws that apply to our activities, including the Spam Act 2003 (Cth).
What we collect
Information you give us
When you submit the audit booking form, use the chat, or contact us directly, we collect:
- Your name and business name
- Email address and phone number
- Your trade or industry
- Anything you tell us about your business or its challenges
We may also source prospect business contact details from public directories and prospecting tools to identify and contact Australian service businesses, subject to applicable law.
Information collected automatically
This site does not currently use analytics, advertising or tracking cookies. We do not run Google Analytics, advertising pixels or session-recording tools.
The site loads fonts, animation libraries, and booking and contact forms through third-party hosting, domain, content-delivery, Google and CRM providers, which may include Netlify, GoDaddy, Google and GoHighLevel. As a technical necessity those providers receive your IP address and basic browser information when the page loads.
Automated AI chat assistant. If you use the chat on our site, it is answered by an automated assistant. The conversation and any contact details you provide may be stored in CDT’s CRM for enquiry follow-up. It is handled the same way as any other enquiry.
Call transcription and phone assistants. With your permission, we may transcribe calls with you to help us take accurate notes. Transcripts are deleted within 7 days. Calls to some businesses we work with may be answered by an automated assistant, and those calls are only transcribed with the caller’s permission.
Client business information
If you become a client, we collect and hold information needed to set up and operate your system. This includes:
- Your business details, ABN and contact information
- Your service list, pricing information and business hours
- Your Google Business Profile and website credentials, where you ask us to manage them
We may temporarily receive identity documents, such as a driver’s licence or proof of address, where needed for telecommunications or other provider verification. We hold those documents only temporarily, restrict access to them, and securely delete them as soon as reasonably practicable, with a target maximum retention period of 7 days unless a longer period is required by law or by the relevant provider.
Your customers’ information
Through systems we build or operate for clients, CDT may collect, hold, use, disclose and otherwise process information about clients’ customers, including names, telephone numbers, email addresses, job and quote information, and message history.
Clients are responsible for their instructions to CDT, their customer relationships, and ensuring that information and contact lists they provide may lawfully be collected, used and disclosed for the instructed purposes; CDT remains responsible for complying with legal obligations that apply directly to it. Clients must ensure that their messaging instructions, sender identification, contact details and lists are accurate and comply with applicable law. CDT generally handles client-customer information on the relevant client’s instructions, does not acquire ownership of client or client-customer data, and does not use client customer lists for CDT’s own marketing; this does not limit any obligation imposed directly on CDT by law.
Why we collect it
- To respond to your enquiry and arrange your audit
- To provide, support and improve our services
- To set up telecommunications services and complete provider verification on your behalf
- To operate, support and secure the websites, CRM, telecommunications, messaging and automation systems you engage us to provide
- To send information about our services in accordance with your preferences and applicable law
- To meet our legal, compliance and record-keeping obligations
We do not sell your personal information to anyone, and we do not buy contact lists.
Marketing and how to opt out
We may send marketing communications about our services where permitted by law, taking account of the recipient’s preferences and any consent or existing relationship on which we rely.
Every marketing email includes an unsubscribe link. Our SMS messages include opt-out instructions: reply STOP to opt out. You can also email us at any time to opt out, and we will update the relevant marketing and suppression records. We action unsubscribe requests within five working days, as required under the Spam Act.
Operational messages relating to work we are actually doing for you — such as replying to your enquiry or updating you on a project — are not marketing and continue regardless.
Messages sent on behalf of a client. Where we operate a messaging system for one of our clients, the message identifies that client as the sender and includes an unsubscribe or opt-out facility. Opt-out requests received through a system CDT operates are recorded and actioned in that system in accordance with CDT’s agreement and arrangements with the client. If you have received a message from a business we work with and want to opt out, you can use the opt-out facility in the message, or contact us and we will pass the request on.
Who we share it with
We use third-party service providers to run our business. Material categories and current providers include:
| Provider | What it’s used for | Where data is stored |
|---|---|---|
| GoHighLevel | CRM and automation platform — contact records, message history | United States (support access from India) |
| Twilio | Telephone numbers, SMS and call delivery, including where Twilio services are accessed through GoHighLevel | United States |
| Stripe | Payment processing | United States |
| Google Workspace | Email and document storage | United States |
| Mailgun | Email delivery for messages sent through GoHighLevel | United States |
| OpenAI, Anthropic and xAI | AI tools used to help prepare content and internal documents | United States |
| Netlify, GoDaddy, content delivery networks and Google services | Website and domain hosting, page delivery and fonts | United States; European Union (GoDaddy) |
Categories of provider we may use. Our tools change over time. We use providers for CRM and marketing automation; telecommunications and messaging; payment processing; website and domain hosting and content delivery; email and document storage; workflow automation and integrations; artificial intelligence and language-model features; and analytics and reporting. Current material providers include GoHighLevel; Twilio, including through GoHighLevel; Stripe; Netlify; Google Workspace and other Google services; GoDaddy; and AI providers or models used directly or through embedded platform features, including OpenAI, Anthropic and xAI where applicable.
A current list of CDT’s material specific service providers is available at cdtsolutions.net.au/subprocessors.
The providers used for a particular client may depend on that client’s services, configuration and approved workflows.
Artificial intelligence. We use AI tools to help draft content, build systems and prepare documents. We do not submit identifiable client-customer personal information to general-purpose AI tools unless the relevant workflow and provider have been specifically approved and configured for that purpose. Client business information, such as service descriptions, pricing or job information, may be processed by approved AI providers directly or through embedded platform features, subject to the applicable service arrangements and provider controls. CDT does not use identifiable client or client-customer personal information to train general-purpose AI models, but third-party processing remains subject to the relevant provider’s configured terms and controls.
Some providers process or store personal information outside Australia, including in the United States, India and the European Union; this may mean the information is subject to foreign laws and handled in jurisdictions whose privacy protections differ from Australia’s. Where Australian privacy law requires CDT to take steps in relation to an overseas disclosure, CDT will take reasonable steps required by law and will rely on an applicable consent, contractual or technical safeguard, or other lawful basis appropriate to the circumstances rather than treating provision of information alone as consent. Overseas recipients may not be subject to the Australian Privacy Principles, and CDT may remain accountable for their handling of personal information where the Privacy Act requires.
We may also disclose information where we are required to by law.
How we keep it secure
We take reasonable steps appropriate to our size, activities and the information held to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including role-appropriate access controls, multi-factor authentication where supported, and reasonable selection and configuration of service providers.
No system is completely secure. If a data incident occurs, CDT will assess and respond to it in accordance with applicable law, including the Notifiable Data Breaches scheme where applicable. CDT will make notifications where it has a legal obligation or is the entity required to notify, and will reasonably cooperate with a client where that client is primarily responsible for assessment or notification.
How long we keep it
We keep enquiry information for as long as needed to respond and for a reasonable period afterwards in case you get back in touch. CDT retains client records for the engagement and afterwards only for as long as reasonably required for the purposes for which they are held, including applicable tax, corporate, legal, compliance and dispute requirements; different records may have different retention periods.
Client data on termination. When an engagement ends, CDT will, on request and subject to the applicable agreement, export client data in a reasonably available standard format within 30 days after receiving an export request made within 30 days after termination. CDT will delete or de-identify active client data within 60 days after termination, subject to exceptions for law, compliance, disputes, backups, provider limitations, and security or forensic records. CDT will retain unsubscribe and suppression (do-not-contact) records as required to preserve opt-outs, prevent further marketing, and comply with applicable law.
When personal information is no longer reasonably required for a permitted purpose, CDT takes reasonable steps to delete or de-identify it, subject to applicable legal requirements and reasonable backup, provider, dispute, compliance, security and forensic limitations.
Accessing, correcting or deleting your information
You can ask us to:
- Tell you what personal information we hold about you
- Correct anything that is wrong or out of date
- Request deletion of your information, subject to applicable legal and operational grounds for retaining it
Email conor@cdtsolutions.net.au and we will respond within a reasonable period, generally within 30 days. We do not charge for making a request or correcting information, although a reasonable access charge may apply where permitted by law and notified in advance. We may need to verify your identity first.
If your information is held in a system CDT operates for a client, CDT may refer or coordinate your request with that client because the client may control the relevant customer relationship and instructions. CDT will also assess and comply with any access, correction or other obligation that applies directly to CDT and will reasonably assist the client where appropriate.
Making a complaint
If you think we have mishandled your personal information, contact us first at conor@cdtsolutions.net.au. We will acknowledge and investigate your complaint, keep you reasonably informed, and aim to provide an outcome within 30 days; if more time is reasonably required, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
Changes to this policy
We may update this policy from time to time. The current version will always be available on this page, with the last updated date shown at the top.