Privacy Policy

Last updated: 2 September 2026

Ozlin Info (ABN 89 277 213 296) is a Sydney-based Australian IT services business. This policy explains how we collect, hold, use and disclose personal information through our corporate website, enquiries and services.

We aim to handle personal information consistently with the Australian Privacy Principles. Where the Privacy Act 1988 (Cth) applies to us, we comply with its requirements. This wording should be revisited if Ozlin Info formally opts in to the Privacy Act or becomes subject to it through turnover, contracts or another statutory exception.

1. Scope

This policy applies to the Ozlin Info corporate website at ozlin.info, contact and email communications, and personal information handled while assessing or delivering commercial client work. It does not apply to Ozlin Gaming or other community services, which require separate notices for their own data flows.

2. Information we may collect

Depending on how you interact with us, we may collect:

  • your name, email address, telephone number, business name and role;
  • enquiry, project, support and correspondence details;
  • billing, transaction and accounting records, but not full payment-card numbers processed by a payment provider;
  • website and security data such as IP address, browser and device information, requested URLs, referrer, timestamps, cookie or similar identifiers, login and security events;
  • when Google AdSense is enabled on eligible blog pages, advertising-related information such as page URL and content context, IP address and IP-derived general location, browser and device information, timestamps, cookie or similar identifiers, whether an advertisement was displayed, and interactions with an advertisement;
  • comments, subscription choices and content you choose to submit; and
  • client project information that may contain personal information under agreed project terms.

Financial information is personal information. Statutory sensitive information includes categories such as health information, racial or ethnic origin, political or religious beliefs, union membership, sexual orientation, criminal record and certain biometric information.

Please do not send passwords, API keys, government identifiers, sensitive information or confidential incident data through the public Contact form or ordinary email. We can agree on a more appropriate transfer method where a project requires confidential material.

3. How we collect information

We may collect information:

  • directly from you when you submit a form, email or call us, subscribe, comment, request support or engage us;
  • automatically through WordPress, server logs, cookies, analytics, anti-spam and security services;
  • automatically through Google AdSense advertising tags, cookies, local storage, web beacons and similar technologies on pages where advertising is enabled;
  • from a client or authorised contact where we provide services on their behalf; and
  • from referral partners or public sources where reasonably necessary and lawful.

Where lawful and practicable, you may enquire anonymously or using a pseudonym. We may need accurate identity and contact information to provide a service, manage access, investigate abuse, issue an invoice or meet a legal obligation.

4. Why we use and disclose information

We may use or disclose personal information to:

  • respond to enquiries and assess requested work;
  • provide, secure, support and improve our services;
  • administer client relationships, projects, billing and records;
  • operate websites, forms and subscriptions;
  • display and measure non-personalised advertising, limit how often an advertisement is shown, produce aggregated advertising reports, and detect invalid traffic, fraud and abuse;
  • detect spam, fraud, abuse, security incidents and unauthorised access;
  • maintain backups, logs, business continuity and legal records;
  • send service-related communications;
  • send marketing only where we have an appropriate consent or other lawful basis; and
  • comply with legal obligations or establish, exercise or defend legal claims.

We use or disclose information for the primary purpose of collection, a related purpose you would reasonably expect, with consent, or where required or authorised by law. We do not sell personal information.

5. Contact forms and email

Contact-form submissions may be stored in the Ozlin Info WordPress database and forwarded to a monitored Google Workspace/Gmail mailbox through the site SMTP connection. The form collects only the fields needed to understand and answer an enquiry and uses Cloudflare Turnstile and other anti-spam controls.

The visitor email address is used as Reply-To and is not impersonated as the authenticated From address. Enquiry records are retained only while reasonably needed to respond, manage a potential or active business relationship, meet accounting or legal requirements, resolve disputes and maintain security.

6. Client data, cybersecurity work and AI services

Where we handle personal information to deliver a client project, project-specific terms should identify responsibilities, authorised users, material service providers, security requirements, retention and deletion arrangements.

Client confidential information must not be submitted to a public or shared AI service, used for model training, or disclosed to an AI provider unless the use has been expressly agreed, is lawfully permitted and the applicable data-handling terms have been reviewed. Public Contact forms are not an approved channel for confidential datasets, credentials or incident evidence.

7. Comments and subscriptions

If comments are enabled, the display name and comment may be public. WordPress may also collect the commenter email, website, IP address and browser information. Akismet may process comment and anti-spam signals, and Gravatar may receive a hash derived from an email address to check for an avatar. Newsletter or update subscriptions use a separate, clear choice and provide a functional unsubscribe method.

8. Cookies, analytics and visitor choices

The website may use essential WordPress login, session and preference cookies; Cloudflare security and Turnstile technologies; Google Analytics through Site Kit; Google AdSense advertising where enabled; Jetpack Stats and WordPress.com functions; and cookies used for comments or subscriptions where those functions are enabled.

Analytics reports are generally pseudonymous or aggregated, but the underlying collection may include online identifiers, IP-derived location, device and browser data, visited pages, referrers and interaction events that can be personal information. Ozlin Info does not attempt to identify visitors from analytics reports. You can use browser controls to limit cookies. Non-essential analytics is loaded in accordance with the site consent configuration and applicable visitor-region requirements.

Advertising and Google AdSense

Ozlin Info uses Google AdSense to display advertising on eligible blog articles. Google may use cookies, local storage, web beacons, IP addresses and other online identifiers to request, deliver, limit the frequency of, secure, measure and report on advertisements. An advertising tag may communicate with Google even where a visible advertisement is not ultimately displayed. Displaying an advertisement does not mean that Ozlin Info recommends or endorses the advertiser, product or service.

Ozlin Info requests non-personalised advertising for all visitors. Non-personalised advertising is selected using contextual information, such as the content being viewed, the visitor general location and current device or browser information, rather than an advertising profile based on prior visits. Non-personalised advertising can still involve cookies, device storage, identifiers and personal-information processing for frequency capping, fraud prevention, security, aggregated reporting and legal compliance.

Where required, visitors in the European Economic Area, the United Kingdom and Switzerland are shown a Google-certified consent-management message before Ozlin Info permits non-essential advertising storage. The message offers separate choices to consent, not consent, or manage individual purposes and vendors. Rejecting advertising consent does not prevent access to editorial content. Ozlin Info has disabled user-based ads and programmatic limited ads at the AdSense account level. The site policy is that advertisements do not load after rejection, withdrawal or where a required permission is unavailable.

You can later revisit or withdraw a choice using the Privacy and cookie settings control below. Withdrawing consent has the same effect on future advertising requests as rejecting consent. Withdrawal does not by itself require Google or another provider to erase information that it is independently required or permitted to retain.

Google explains how it uses information from sites and apps that use its services at How Google uses information from sites or apps that use our services. You can manage Google advertising choices at Google Ads Settings. If Ozlin Info enables another advertising network or advertising vendor, this policy and the consent interface will be updated before that provider is used.

9. Service providers and disclosure

We may disclose or make information available to providers that help us operate the business, subject to their terms and our configurations. Current categories include:

  • OVHcloud and infrastructure providers: website, database, backup and server hosting; content, account and log data.
  • Cloudflare: DNS, CDN, web-application firewall and Turnstile; traffic, device and security signals.
  • Google AdSense / Google Advertising Products: non-personalised contextual advertising, frequency capping, aggregated measurement, security and invalid-traffic prevention; page context, IP address and general location, browser/device information, identifiers, consent signals and advertisement interaction data.
  • Google Analytics/Site Kit and Google Workspace: website analytics, Search Console integration and email delivery according to the relevant service and configuration.
  • Automattic/WordPress.com: Jetpack, site statistics, subscriptions, Akismet and Gravatar where enabled.
  • Defiant/Wordfence: website security monitoring, threat intelligence, IP and security-event data.
  • Fluent Forms: contact-form rendering, local submission records and notification workflow.
  • Professional advisers and authorities: accounting, legal, insurance, dispute handling and lawful requests.

The current advertising technology provider list is presented through the consent interface where required. We review the list when Google or the advertising configuration changes.

10. Overseas processing

Our primary website and database are hosted in Sydney, Australia. Website traffic and information may also be processed in the United States, the European Economic Area and other locations where Google, Cloudflare, Automattic, Defiant and other providers operate. Advertising-related information may be processed in countries where Google operates. Provider locations and subprocessors may change.

Where Australian privacy law requires it, we take reasonable steps in relation to overseas disclosures.

11. Direct marketing

We do not treat a service enquiry as automatic consent to a newsletter. A marketing subscription uses a separate, clear and unticked choice. Commercial electronic messages identify Ozlin Info, use the recipient consent or another lawful basis and include a functional unsubscribe method. Unsubscribe requests are actioned within the period required by the Spam Act 2003 (Cth), generally five business days.

12. Security and retention

We use reasonable technical and organisational measures appropriate to the nature and risk of the information, which may include access controls, encryption in transit, patching, backups, logging, malware and threat monitoring, and recovery procedures. No website, email or online system is completely secure.

We retain information only while reasonably needed for the collection purpose, an active or potential client relationship, security and abuse prevention, backup recovery, accounting, legal obligations and dispute resolution. Information that is no longer required is deleted or de-identified where reasonably practicable and lawful. Contact-form entries use an initial 180-day resolved-enquiry retention target with monthly manual review; accounting, legal-hold, dispute or active-client records may need longer retention.

13. Access, correction and other choices

Subject to applicable law and exceptions, you may ask us to:

  • provide access to personal information we hold about you;
  • correct information that is inaccurate, out of date, incomplete, irrelevant or misleading;
  • stop direct marketing;
  • change or withdraw advertising and cookie choices through the privacy-and-cookie-settings control;
  • continue to access editorial content after rejecting advertising consent, subject to essential security and site-operation technologies; or
  • delete personal information where required by law or reasonably practicable, subject to legal, accounting, security and dispute-resolution retention requirements.

Australia’s Australian Privacy Principles do not create a general, unconditional right to erasure. We may need to verify identity before handling an access, correction or deletion request. We aim to respond within a reasonable period; 30 days is a general target rather than a guaranteed statutory deadline for every request.

14. Contact and complaints

For privacy questions, access or correction requests, marketing opt-out or complaints, contact:

Ozlin Info
Sydney, New South Wales, Australia
Email: [email protected]
Website: ozlin.info/contact/

We will acknowledge and investigate a complaint and aim to provide a response within a reasonable period. If the Privacy Act 1988 applies and you are dissatisfied after giving us a reasonable opportunity to respond, you may contact the Office of the Australian Information Commissioner at oaic.gov.au/privacy/privacy-complaints or by telephone on 1300 363 992.

15. Data breaches

We assess suspected data breaches and take containment and remediation steps appropriate to the circumstances. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we will notify affected individuals and the OAIC as required by law.

16. Changes to this policy

We may update this policy when our services, providers, legal obligations or data practices change. We will update the date on this page and, where a change materially affects how we handle information, provide additional notice where appropriate.