Privacy Policy

Effective date: 20 January 2026
Last updated: 18 September 2026

Bigwig Advertising & Digital (“Bigwig”, “we”, “our”, “us”) respects your privacy. This Privacy Policy explains how we collect, use, store and disclose personal information in connection with our website, marketing activities, business operations and direct interactions with Bigwig, in accordance with the Australian Privacy Principles (APPs) and, where applicable, the UK and EU General Data Protection Regulation (GDPR).

1. Who we are

Bigwig Advertising & Digital is a creative, advertising, digital and technology services agency based in South Australia, Australia. We operate primarily in Australia but may work with clients, suppliers and service providers in other countries.

2. Scope of this policy

This Privacy Policy applies to personal information collected or controlled directly by Bigwig through our website, marketing activities, business operations, enquiries and other direct interactions with us.

Information relating to current and prospective clients and their representatives is also addressed in our Client Privacy Notice.

Where Bigwig processes personal information on behalf of a client as part of providing website, application, hosting, CRM, marketing, integration or other services, that information may include personal information belonging to the client’s customers, members, patients, users, employees or other stakeholders.

In those circumstances, the client generally determines the purpose for which the information is collected, used and retained, and Bigwig processes the information as required to provide the agreed services and in accordance with applicable law and our Client Service Terms or other applicable written arrangements.

This Privacy Policy does not establish a general retention period for personal information held within client websites, applications, databases or other systems.

3. What information we collect

We may collect personal information including:

  • Name
  • Email address
  • Phone number
  • Job title and organisation
  • Business and postal address
  • Information contained in enquiries, briefs, correspondence and support requests
  • Billing, transaction and account information
  • IP address, browser and device information
  • Website usage information, such as pages visited and actions taken
  • Marketing preferences
  • Any other information you choose to provide to us

We generally do not seek to collect sensitive personal information about individuals unless it is reasonably necessary for our activities, provided voluntarily, or required in connection with an agreed service.

4. How we collect information

We may collect information through:

  • Forms submitted through our website
  • Email, phone and other correspondence
  • Meetings, project communications and support requests
  • Quotes, proposals, agreements, invoices and other business records
  • Cookies and similar technologies
  • Analytics and advertising platforms
  • Third-party business systems used by Bigwig
  • Publicly available business information where appropriate

5. Why we collect and use personal information

We may use personal information to:

  • Respond to enquiries and business communications
  • Prepare proposals, quotes and service arrangements
  • Provide, manage and support our services
  • Manage client, supplier and business relationships
  • Manage billing, payments and financial records
  • Provide operational, support and service-related communications
  • Understand how visitors use our website
  • Improve our website, systems, services and client experience
  • Maintain security, quality assurance and business continuity
  • Send marketing communications where permitted by law
  • Meet legal, regulatory, insurance, accounting and compliance obligations
  • Establish, exercise or defend legal rights

6. Legal basis for processing where the GDPR applies

Where the UK or EU GDPR applies, the legal basis for processing personal information may include:

  • Consent, including for certain marketing communications and non-essential cookies where required
  • Contractual necessity, where processing is necessary to enter into or perform a contract with an individual
  • Legitimate interests, including business administration, client relationship management, security, service improvement and appropriate business communications
  • Legal obligations, including financial, regulatory and record-keeping requirements

Where we rely on legitimate interests, we consider those interests against the rights and reasonable expectations of affected individuals.

7. Cookies and third-party tracking

We use cookies and third-party technologies to operate our website, measure its use and support our marketing activities.

These may include:

  • Google Analytics
  • Google advertising and measurement services
  • Meta technologies, including the Meta Pixel
  • LinkedIn Insight Tag
  • Email marketing and campaign measurement tools

The technologies in use may change from time to time as our website and marketing activities evolve.

You can manage cookies through your browser settings and, where available, through our website cookie preferences. Where required by applicable law, non-essential cookies and similar technologies are not activated until the required consent has been obtained.

We do not use personal information for automated decision-making that produces legal or similarly significant effects on individuals.

8. Service providers and data sharing

We may disclose or provide access to personal information to trusted service providers where reasonably necessary to operate our business or provide our services.

These providers may include:

  • Hosting and cloud infrastructure providers
  • Business management and project management systems, including WorkflowMax
  • Accounting and financial systems, including Xero
  • Email, document storage and collaboration systems, including Google Workspace
  • Google Cloud and Firebase services where used
  • Analytics, advertising and marketing platforms
  • Email delivery and communication providers
  • Professional advisers, insurers and auditors
  • Suppliers and contractors involved in delivering approved services

We may also disclose personal information:

  • Where required or authorised by law
  • To government, regulatory or law enforcement bodies where legally required
  • Where reasonably necessary to protect our legal rights or respond to a legal claim
  • With your consent or as otherwise authorised by you

We do not sell personal information.

9. Data storage and security

Bigwig uses administrative, technical and physical safeguards designed to protect personal information against misuse, interference, loss, unauthorised access, modification and disclosure.

Measures may include:

  • Access controls and authentication
  • Role-based access where appropriate
  • Multi-factor authentication on supported systems
  • Encryption in transit and other encryption controls where applicable
  • System and software maintenance
  • Logging and monitoring appropriate to the relevant environment
  • Backup and recovery processes for systems within our management scope
  • Change management and security procedures
  • Staff security awareness and training

No website, storage system, transmission method, software platform or digital service can be guaranteed to be completely secure. Our safeguards are applied according to the nature of the information, the systems involved, the services being provided and the risks reasonably identified.

10. International processing and overseas service providers

Bigwig is based in Australia and uses a combination of Australian and international cloud and software service providers.

Some providers, including WorkflowMax, Xero, Google Workspace, Google Cloud, Firebase, analytics platforms, advertising platforms and other business systems, may store, process, support or provide access to information from locations outside Australia.

The countries involved may vary depending on the provider, its infrastructure, subprocessors, support arrangements and the particular service being used.

Where personal information is disclosed or made accessible outside Australia, we take reasonable steps appropriate to the circumstances to ensure that the information is handled consistently with applicable privacy requirements and appropriate contractual, organisational and security safeguards.

Where the UK or EU GDPR applies, international transfers may also be subject to recognised transfer mechanisms or contractual safeguards where required.

11. Retention

We retain personal information only for as long as reasonably necessary for the purposes for which it is held, or as required by applicable law, regulatory requirements, contractual obligations or legitimate business requirements.

Retention periods vary according to the type of information.

  • Financial and accounting records: retained for at least 7 years where required by law.
  • Digital client project files: generally archived for up to 2 years from the last modification for current clients, in accordance with our Client Service Terms. This is not a guaranteed storage service and clients remain responsible for retaining their own copies of final deliverables, source materials and business records.
  • Enquiries and prospective client information: retained for as long as reasonably required to manage the enquiry, potential engagement and related business relationship. Information that is no longer reasonably required may be deleted, de-identified or retained where another lawful requirement applies.
  • Website analytics and advertising data: retained according to our settings and the applicable platform or provider arrangements.

Where Bigwig hosts or processes personal information on behalf of a client, the client is responsible for determining the lawful retention requirements that apply to its business records and personal information and for communicating any retention, deletion, legal hold or disposal requirements that Bigwig is required to implement.

Hosting or routine website maintenance does not, by itself, include determining client retention periods, routinely reviewing individual records, or implementing automatic deletion or de-identification.

Where Bigwig is required to implement retention settings, automated deletion, historical data clean-up or other retention controls on behalf of a client, that work must form part of the agreed services or be separately requested and approved.

Retention and deletion may need to take account of information contained in backups, system logs, archives, exports and other technical copies. Bigwig remains responsible for meeting any privacy or data-handling obligations that apply directly to Bigwig.

12. Access, correction and other privacy rights

Depending on the laws that apply to you, you may have rights to:

  • Request access to personal information we hold about you
  • Request correction of inaccurate, incomplete or out-of-date information
  • Request deletion where applicable
  • Withdraw consent where processing is based on consent
  • Object to certain processing, including direct marketing
  • Request restriction of processing where applicable
  • Request data portability where applicable
  • Lodge a privacy complaint with Bigwig or an applicable privacy regulator

Some rights are subject to exceptions, legal requirements and circumstances in which information must or may lawfully be retained.

We may ask you to verify your identity before providing access to personal information or acting on a request.

We aim to respond to privacy requests within a reasonable period and within any timeframe required by applicable law.

13. Direct marketing

We may send business or marketing communications where permitted by law.

You may opt out of marketing communications at any time by using the unsubscribe mechanism provided in the communication or by contacting us.

Service, billing, security and other operational communications are not treated as marketing communications and may still be sent where reasonably necessary.

14. Anonymity and pseudonyms

Where lawful and practical, you may interact with us anonymously or by using a pseudonym.

For example, you may generally browse our website without identifying yourself. However, we may require accurate identification where it is reasonably necessary to provide services, manage an account, process a transaction, meet legal obligations or protect security.

15. Privacy complaints

If you have a concern or complaint about the way Bigwig has handled your personal information, please contact our Privacy Officer using the details below.

We will acknowledge and investigate privacy complaints and respond within a reasonable period. We may contact you for additional information where necessary to investigate the matter.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) or, where applicable, a relevant privacy or data protection authority in the UK or EU.

16. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes to our services, systems, providers, practices or legal requirements.

The current version will be published on this page together with the date it was last updated. Where a change is material and it is appropriate to do so, we may also notify affected individuals directly.

17. Contact us

If you have questions about this Privacy Policy, wish to exercise a privacy right or would like to make a privacy complaint, please contact:

Privacy Officer — Bigwig Advertising & Digital
Email: [email protected]
Phone: +61 8 8363 6124
Postal: 59 North Tce, Hackney, South Australia 5069

You may also contact the Office of the Australian Information Commissioner for information about Australian privacy rights or to lodge a complaint.