Privacy Policy

Last updated: 16 April 2026

Holistic Governance ("we", "us", "our") is committed to protecting your personal information in accordance with the Australian Privacy Act 1988 and the Australian Privacy Principles (APPs).

1. Information We Collect

CategoryData CollectedHow
Governance enquiriesOrganisation name, contact name, email, phone, governance challenge, accreditation statusWebsite enquiry form
ProposalsClient name, email, proposal content, engagement notesCreated by Holistic Governance during engagement
NewsletterEmail addressNewsletter sign-up form
BookingName, email (provided to Calendly)Kickoff meeting booking

2. How We Use Your Information

We do not sell, rent, or trade your personal information to third parties.

3. How We Store and Protect Your Data

MeasureDetail
Encryption at restGoogle Cloud default encryption (AES-256)
Encryption in transitTLS 1.2+ with HSTS
Data locationSydney, Australia (australia-southeast1)
Access controlAuthenticated administrator access only
Input validationServer-side sanitisation, Content Security Policy, rate limiting
Log redactionPersonal information is masked in all server logs

4. Data Retention

Data TypeRetention Period
Governance enquiries12 months from submission
Proposals (active)24 months from last update
Proposals (accepted — frozen copy)7 years from acceptance, or as required by law, for contractual and legal record-keeping purposes
Proposals (declined/archived)6 months after status change
Newsletter subscribersUntil you unsubscribe, or 24 months of inactivity

When a proposal is accepted, a protected read-only copy is stored as a permanent record of the agreed terms. This snapshot cannot be edited after acceptance.

After the retention period, your data is reviewed and deleted unless there is a legal or contractual reason to retain it.

5. Third-Party Services

ServicePurposeData Shared
Google Cloud (Firestore)Data storageAll collected data (encrypted, stored in Australia)
ResendEmail deliveryRecipient email, email content
CalendlyMeeting schedulingOnly a link — you provide your details directly to Calendly
Google AnalyticsWebsite usage insightsAnonymised browsing data (IP anonymisation enabled)

Each service operates under its own privacy policy. We encourage you to review them.

6. Cookies

Our main website uses Google Analytics cookies to understand how visitors use the site. These cookies collect anonymised data only.

Our proposal management system uses a single session cookie for administrator authentication. This cookie contains no personal information, is HttpOnly and Secure, and expires after 7 days or on logout.

We do not use advertising or tracking cookies beyond Google Analytics.

7. Your Rights

Under the Australian Privacy Act, you have the right to:

8. Data Breach Response

In the event of a data breach that is likely to result in serious harm, we will:

9. Contact

Privacy enquiries and data requests:

Naomi Alefelder — Founding Director, Holistic Governance

Email: naomi@hg-au.com

Phone: 0405 515 300

We will respond to all privacy-related requests within 30 days.

10. Changes to This Policy

We may update this policy from time to time. The "Last updated" date at the top reflects the most recent revision. Continued use of our services after changes constitutes acceptance of the updated policy.