Client Privacy Notice

Effective date: 20 January 2026
Last updated: 17 September 2026

This Client Privacy Notice explains how Bigwig Advertising & Digital (“Bigwig”, “we”, “us”) collects, uses, discloses and protects personal information about our clients and their representatives. It describes our approach under the Australian Privacy Principles (APPs) and, where applicable, the UK General Data Protection Regulation (UK GDPR) and EU General Data Protection Regulation (EU GDPR). It should be read together with our Privacy Policy. Our Client Service Terms and the arrangements agreed for each engagement separately address service scope and responsibilities.

Scope

This notice applies to current and prospective clients, their employees and representatives, suppliers involved in client delivery, and individuals who interact with us in relation to our services. It covers personal information in Bigwig’s own client relationship, commercial and service-administration records, such as contact details, quotations, invoices, project correspondence and support requests.

Where the UK GDPR or EU GDPR applies, Bigwig acts as a controller for these activities because we determine why and how this information is used for our own business purposes.

This is distinct from personal information we host or otherwise process solely on a client’s behalf, such as customer, patient, member or website-user records within a client’s systems. That processing is governed by the applicable service arrangements, any data-processing agreement and relevant law. The client’s own privacy notice explains its collection and use of that information. This distinction does not remove Bigwig’s own applicable privacy obligations.

Personal information we collect

  • Identification and business contact details, such as name, role, organisation, email, phone and address
  • Account and billing information, such as ABN/ACN details, purchase orders, invoices and payment records, where these identify an individual
  • Project communications and artefacts, such as briefs, feedback, approvals and meeting notes
  • Interactions with Bigwig’s website and services, such as enquiries, support requests and analytics information described in our Privacy Policy
  • Stakeholder and preference information relevant to project delivery and relationship management

We generally collect this information directly from you through enquiries, meetings, correspondence, forms and service interactions. We may also receive relevant information from your organisation, its authorised representatives or providers involved in an engagement. Please provide only personal information needed for the relevant purpose and use an agreed secure channel for sensitive material.

You may choose not to provide information, but we may be unable to prepare a quote, administer an account or deliver a requested service without the details reasonably needed for that activity.

How we use your information

  • To respond to enquiries and plan, deliver and support our services and projects
  • To manage client relationships, accounts, billing and payments
  • To communicate operational updates, approvals and service-related notices
  • To maintain security and quality assurance, meet applicable obligations and manage complaints or disputes
  • To improve our services and client experience

Any direct marketing is handled as described in our Privacy Policy, subject to applicable consent and opt-out requirements. Opting out of marketing does not prevent necessary account, security or service communications.

Legal basis for processing

Where the UK GDPR or EU GDPR applies, the relevant basis depends on the activity:

  • Contractual necessity: where processing is necessary for a contract with you as an individual, or for steps you request before entering into one
  • Legitimate interests: where necessary for managing business relationships, communicating with representatives of organisational clients, administering services, maintaining security, improving services or managing legal claims, provided those interests are not overridden by your rights and interests
  • Legal obligations: where necessary to comply with an obligation recognised as a valid basis under the applicable UK or EU data protection law
  • Consent: where required for a particular activity; we explain the purpose when requesting it, and you may withdraw it at any time

A contract with your employer does not, by itself, make contractual necessity the basis for processing your personal information. Where we rely on legitimate interests, we consider the effect on individuals and their reasonable expectations. Withdrawing consent does not affect processing that was lawful before withdrawal.

Sharing and disclosures

Where reasonably needed for the purposes above, we may disclose relevant information to authorised people in your organisation, providers involved in delivering the engagement, and service providers supporting our business, such as hosting, email, project administration, analytics and finance systems. We apply appropriate confidentiality, access and security requirements to providers handling information on our behalf.

We may also disclose information where required or permitted by law, or where lawfully necessary to obtain professional advice, deal with a complaint or claim, or protect legal rights. We limit disclosures to information relevant to the purpose.

We do not sell personal information. Further information about our general handling practices is available in our Privacy Policy.

Storage and retention

We retain personal information only for as long as reasonably necessary for the purposes for which it is held, or as required by applicable law.

Financial and accounting records are retained for the periods required by law, which may include retention for at least 7 years.

Digital client project files are generally archived for up to 2 years from the last modification for current clients, in accordance with our Client Service Terms. This is not a guaranteed storage service and clients remain responsible for retaining their own copies of deliverables and business records.

Where Bigwig hosts or otherwise processes personal information on behalf of a client, the client is responsible for determining its lawful retention requirements and communicating those requirements to Bigwig. Hosting or routine website maintenance does not, by itself, include determining retention periods, reviewing individual records or implementing automatic deletion. Any technical implementation of retention or deletion requirements must form part of the agreed service or be separately requested and approved.

Security

We apply reasonable administrative, technical and physical safeguards appropriate to the information and risks involved. Measures include access controls, audit logging, encryption in transit, change management and staff training. The controls relevant to a particular system depend on its purpose and the information it handles.

No system or transmission method can be guaranteed completely secure. This does not remove our applicable security obligations. We assess and respond to personal information breaches in accordance with applicable law, including notifying affected individuals and regulators where required. For further information, see our Privacy Policy.

International transfers

Bigwig uses reputable cloud and software service providers, some of which may store, process, support or provide access to personal information from locations outside Australia.

Where personal information is disclosed or made accessible overseas, we take reasonable steps to ensure that it is handled in accordance with applicable privacy laws and appropriate contractual and security safeguards.

Further information about the service providers we use and overseas handling of personal information is available in our Privacy Policy.

Your rights

Your rights depend on the law applicable to the information and processing. They may include:

  • Access to personal information we hold about you
  • Correction of information that is inaccurate, incomplete, out of date, irrelevant or misleading
  • Where applicable, deletion, restriction of processing, or receipt or transfer of certain information in a portable format
  • Where applicable, objection to processing based on legitimate interests, and objection to use of your information for direct marketing
  • Withdrawal of consent where we rely on it
  • Making a complaint to us or a relevant privacy regulator

These rights are subject to applicable legal conditions and exceptions. For example, a deletion request may not require removal of records we must lawfully retain. We will explain any refusal or limitation and the available complaint options, unless the law prevents us from doing so.

How to make a request

Contact us by email, phone or post using the details below. We may request information reasonably needed to verify your identity or an authorised representative’s authority, without collecting unnecessary identification documents.

For Australian access and correction requests, we aim to respond within 30 days and will meet applicable requirements. Where the UK GDPR or EU GDPR applies, we respond without undue delay and ordinarily within one month, subject only to extensions or other timing rules permitted by the applicable law. We will explain any permitted extension and the reason for it within the required period.

There is no charge for making a request. Any charge for providing access will only be imposed where lawful and will be explained in advance. We do not charge for correcting information.

For requests concerning information held solely on a client’s behalf, contact that organisation in the first instance. If you contact Bigwig, we will assess our role and, where appropriate, refer the request to the client or assist it under the applicable arrangement, without disregarding any obligation Bigwig has directly.

Questions and complaints

Please contact us using the details below if you have a question or complaint about our handling of personal information. We will acknowledge complaints promptly and within 30 days, investigate without undue delay, keep you informed where needed and communicate the outcome. We aim to provide a substantive response within 30 days; if more time is reasonably needed, we will explain why and provide an expected response timeframe.

If you are dissatisfied with our response, or we have not responded within a reasonable period, you may contact the Office of the Australian Information Commissioner (OAIC). Where applicable, you may also complain to the UK Information Commissioner’s Office (ICO) or a relevant EU supervisory authority. Nothing in this notice limits your right to approach a regulator as provided by law.

Updates to this notice

We may update this notice to reflect changes in our practices or applicable requirements. The latest revision date is shown above. We will give additional notice where required. Publishing an update does not, by itself, provide consent for a new use of personal information or change agreed service responsibilities.

Contact us

Privacy Officer — Bigwig Advertising & Digital
Email: [email protected]
Phone: +61 8 8363 6124
Postal: 59 North Tce, Hackney, South Australia 5069