1. About this policy
This Privacy Policy explains how Ben Waldeck (“we”, “us” or “our”) collects, uses, discloses, transfers and protects personal information in connection with the website at benwaldeck.com (the “Website”), enquiries made through the Website, and the provision of consulting services.
For the purposes of the EU General Data Protection Regulation (“EU GDPR”) and the UK General Data Protection Regulation (“UK GDPR”), Ben Waldeck is the controller of the personal data described in this policy.
Legal services are provided only through Rubicon Law, where Ben Waldeck is Special Counsel. If you engage Rubicon Law, or if your enquiry is referred to Rubicon Law, Rubicon Law’s own privacy policy and terms of engagement will govern its handling of your personal information.
In this policy, “personal information” includes “personal data”, “personal information” and equivalent terms as defined under the laws that apply to you.
2. Laws this policy addresses
We are based in Australia and work with clients in Australia, New Zealand, the United States, Canada, the United Kingdom and Europe. This policy is intended to meet the requirements of, to the extent they apply:
- Australia: the Privacy Act 1988 (Cth), including the Australian Privacy Principles (“APPs”), and the Spam Act 2003 (Cth).
- New Zealand: the Privacy Act 2020, including the Information Privacy Principles (“IPPs”), and the Unsolicited Electronic Messages Act 2007.
- European Union and European Economic Area: the EU GDPR and applicable national laws implementing the ePrivacy Directive.
- United Kingdom: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations 2003 (“PECR”).
- Canada: the Personal Information Protection and Electronic Documents Act (“PIPEDA”), Canada’s Anti-Spam Legislation (“CASL”) and substantially similar provincial laws, including Québec’s Act respecting the protection of personal information in the private sector.
- United States: applicable federal law, including the CAN-SPAM Act, and state consumer privacy laws, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA”).
Some of these laws apply only above certain thresholds or in certain circumstances. Where a law does not strictly apply to us, we nonetheless aim to handle personal information consistently with its principles.
3. Information we collect
Depending on how you interact with us, we may collect:
- Identity and contact information: your name, email address, organisation, job title, telephone number and postal address.
- Enquiry information: the service you are interested in and the content of any message you send us.
- Engagement information: information needed to deliver consulting services, including information about your organisation’s systems, processes and personnel.
- Financial information: billing details and payment records, where we provide services to you.
- Technical information: IP address, browser type and version, device information, operating system, referring pages, and the date and time of your visit, collected through server logs.
- Communications: records of correspondence and your communication preferences.
Sensitive information. We do not seek to collect sensitive information (sometimes called “special category data”), such as information about health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal records or biometric data. Please do not include sensitive or confidential information in the Website’s contact form. If we need sensitive information to provide a service, we will collect it only with your consent or where otherwise permitted by law.
Anonymity. You may browse the Website without identifying yourself. Where practicable, you may deal with us anonymously or using a pseudonym, although we will generally need your name and contact details to respond to an enquiry or provide services.
4. How we collect it
- Directly from you, when you complete the contact form, email us, speak with us, attend a presentation or engage our services.
- Automatically, when you visit the Website, through server logs and strictly necessary technologies (see section 6).
- From third parties, such as your colleagues, referrers, event organisers, and publicly available sources, including professional networking sites and company registers.
If you provide personal information about another person, you should ensure that you are entitled to do so and that the person is aware of this policy.
5. Purposes and lawful bases
We use personal information only for the purposes for which it was collected, related purposes you would reasonably expect, or purposes permitted or required by law. Where the EU GDPR or UK GDPR applies, we rely on the lawful bases set out below.
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may request details of that assessment. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
6. Cookies and similar technologies
The Website uses only technologies that are strictly necessary to deliver and secure the Website. We do not use advertising cookies, cross-site tracking or behavioural profiling.
The Website loads typefaces from Google Fonts. When your browser requests these files, Google receives your IP address and browser information. Google’s handling of that information is described in Google’s privacy policy.
If we introduce analytics or other non-essential technologies, we will update this policy and, where required by law (including under the ePrivacy Directive and PECR), ask for your consent before those technologies are used.
7. Disclosure
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We may disclose personal information to:
- service providers who support our operations, including website hosting, email, cloud storage, IT support, and accounting providers, who act on our instructions and are bound by confidentiality and data protection obligations;
- Rubicon Law, where your enquiry relates to legal services;
- professional advisers, including lawyers, accountants and insurers;
- regulators, law enforcement, courts and government authorities, where required or authorised by law;
- a purchaser or successor, in connection with a sale, restructure or transfer of the business, subject to equivalent confidentiality protections; and
- any other person with your consent.
8. International transfers
We are based in Australia. Personal information you provide may be processed in Australia and in other countries where we or our service providers operate, which may include the United States, the United Kingdom, member states of the European Union, New Zealand and Canada.
Where we disclose personal information outside Australia, we take reasonable steps under APP 8 to ensure the recipient handles it consistently with the APPs. Where we disclose personal information outside New Zealand, we do so in accordance with IPP 12.
Where personal data is transferred from the European Economic Area or the United Kingdom to a country that has not been recognised as providing an adequate level of protection, including Australia, we rely on appropriate safeguards. These include the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or UK Addendum, the EU–US Data Privacy Framework (and UK Extension) for certified US recipients, or, where applicable, a derogation under Article 49 of the EU GDPR or UK GDPR, such as a transfer necessary to respond to your enquiry. You may request a copy of the relevant safeguards by contacting us.
Where personal information is transferred from Canada, it may be subject to the laws of the destination country, including lawful access by courts, law enforcement and national security authorities of that country.
9. Retention
We keep personal information only for as long as needed for the purposes described in this policy, including to meet legal, accounting, tax and professional obligations, and to establish or defend legal claims. As a guide:
- enquiries that do not proceed to an engagement are generally deleted within 24 months of our last contact;
- engagement and financial records are generally retained for seven years after the engagement ends; and
- server logs are generally retained for no longer than 12 months.
When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it.
10. Security and data breaches
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These include encryption in transit, access controls, multi-factor authentication, reputable service providers and limiting access to those who need it.
No method of transmission or storage is completely secure. Please do not send confidential information through the Website’s contact form.
If a data breach occurs, we will assess and respond to it promptly. Where required, we will notify affected individuals and the relevant regulator, including under Australia’s Notifiable Data Breaches scheme, New Zealand’s notifiable privacy breach requirements, Articles 33 and 34 of the EU GDPR and UK GDPR, PIPEDA’s breach of security safeguards requirements, and applicable US state breach notification laws.
11. Your rights
Subject to the law that applies to you, you may have the right to:
- access the personal information we hold about you;
- request correction of inaccurate, incomplete or out-of-date information;
- request deletion of your personal information;
- restrict or object to certain processing, including processing based on legitimate interests and direct marketing;
- receive your personal information in a portable format;
- withdraw consent at any time, where we rely on consent; and
- lodge a complaint with a privacy regulator (see section 16).
To exercise a right, email bw@benwaldeck.com. We may need to verify your identity before responding. We will respond within the time required by applicable law, which is generally 30 days (or one month under the EU GDPR and UK GDPR, and 45 days under the CCPA), and may extend this where permitted. We do not charge a fee unless a request is manifestly unfounded or excessive, or a fee is otherwise permitted by law.
If we refuse a request, we will explain our reasons in writing, unless it would be unlawful or unreasonable to do so, and tell you how to complain.
12. Jurisdiction-specific information
You may request access to and correction of your personal information under APPs 12 and 13. If we decline to correct information, you may ask us to attach a statement to it. You may also contact the Office of the Australian Information Commissioner (OAIC) if you are not satisfied with our response to a complaint.
You have the right to access and request correction of your personal information under IPPs 6 and 7. You may complain to the Office of the Privacy Commissioner.
In addition to the rights in section 11, you have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects. You may complain to the supervisory authority in the country where you live or work, or where an alleged infringement occurred. In the United Kingdom, this is the Information Commissioner’s Office (ICO). Where required by Article 27 of the EU GDPR or UK GDPR, we will appoint a representative in the European Union or United Kingdom and publish their details in this policy.
We collect, use and disclose personal information with your knowledge and consent, except where otherwise permitted by law. You may withdraw consent at any time, subject to legal or contractual restrictions and reasonable notice. You may access and challenge the accuracy of your personal information, and complain to the Office of the Privacy Commissioner of Canada or the relevant provincial commissioner, including the Commission d’accès à l’information du Québec. Ben Waldeck is the person responsible for the protection of personal information and can be contacted using the details in section 18.
Depending on your state of residence, including California, Colorado, Connecticut, Virginia, Texas and other states with consumer privacy laws, you may have the right to know what personal information we collect, use and disclose; to access, correct and delete it; to obtain a portable copy; and to opt out of the sale or sharing of personal information, targeted advertising and certain profiling.
In the preceding 12 months, we have collected the categories of personal information described in section 3 (identifiers, professional or employment-related information, commercial information and internet or network activity information) from the sources in section 4, for the purposes in section 5, and disclosed them to the categories of recipients in section 7 for business purposes. We have not sold or shared personal information, and we do not use or disclose sensitive personal information for purposes that would give rise to a right to limit.
You may make a request yourself or through an authorised agent. We will not discriminate against you for exercising your rights. If we decline your request, you may appeal by emailing bw@benwaldeck.com with the subject line “Privacy appeal”. If your appeal is denied, you may contact your state Attorney General. California residents may also contact the California Privacy Protection Agency.
13. Automated decisions
We do not make decisions about you based solely on automated processing, including profiling, that produce legal or similarly significant effects. If this changes, we will update this policy and describe the kinds of personal information used and the kinds of decisions made, as required by law.
14. Children
The Website and our services are intended for businesses and professionals. They are not directed to children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. Direct marketing
We send marketing communications only where permitted by law, including the Spam Act 2003 (Cth), the Unsolicited Electronic Messages Act 2007 (NZ), PECR, the ePrivacy Directive, CASL and the CAN-SPAM Act. Every marketing message will identify us and include a functional way to unsubscribe. You can also opt out at any time by emailing bw@benwaldeck.com.
16. Complaints
If you have a concern about how we have handled your personal information, please contact us first using the details in section 18. We will acknowledge your complaint promptly and aim to resolve it within 30 days.
If you are not satisfied with our response, you may contact the relevant regulator:
- Australia: Office of the Australian Information Commissioner (oaic.gov.au)
- New Zealand: Office of the Privacy Commissioner (privacy.org.nz)
- United Kingdom: Information Commissioner’s Office (ico.org.uk)
- European Economic Area: your local data protection authority (listed at edpb.europa.eu)
- Canada: Office of the Privacy Commissioner of Canada (priv.gc.ca) or your provincial commissioner
- United States: your state Attorney General or, in California, the California Privacy Protection Agency (cppa.ca.gov)
17. Changes to this policy
We may update this policy from time to time. The current version will always be available on the Website, with the date it was last updated. If we make material changes, we will take reasonable steps to notify you, including by email where appropriate.
18. Contact
For privacy questions, requests or complaints, please contact: