Privacy policy

Last updated: 7 Sept 2026

1. Our Commitment to Privacy

At ntegrity, integrity is in our name and it runs through everything we do. That includes how we handle personal information.

We are committed to protecting the privacy of our clients, their supporters and donors, prospective clients, website visitors, job applicants, and our team. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) contained in Schedule 1 of that Act.

This Privacy Policy explains what personal information we collect, why we collect it, how we use and disclose it, and how you can access, correct, or raise concerns about it.

2. Who We Are

ntegrity Pty Ltd ACN 164 239 409 is a purpose-driven digital marketing and fundraising agency. We partner with not-for-profit organisations and purpose-driven businesses to help them grow their impact, raise funds, inspire action, and delight supporters.

Our services include digital audit and strategy, social media management, digital campaign management, search marketing services, risk and digital management, reporting and forecasting, training and mentoring, and fundraising and supporter engagement strategy.

References in this Policy to "ntegrity", "we", "us", or "our" are references to ntegrity Pty Ltd ACN 164 239 409 and any related entities.

ntegrity is a purpose-driven digital marketing and fundraising agency. We partner with not-for-profit organisations and purpose-driven businesses to help them grow their impact, raise funds, inspire action, and delight supporters.

Business name: ntegrity Pty Ltd

Website: www.ntegrity.com.au

Contact email: people@ntegrity.com.au

Postal address: L3/162 Collins St, Melbourne VIC 3000


3. What Personal Information We Collect

About our clients and prospective clients, we may collect:

  • Name, job title, and organisation name

  • Business contact details (email, phone, address)

  • Information about your organisation's fundraising, marketing, and supporter data practices

  • Financial information necessary to process invoices and payments

  • Communications and correspondence with us

About individuals whose data our clients entrust to us (such as donors, supporters, and subscribers), we may process:

  • Name and contact details

  • Donation history and transaction records

  • Communication preferences and engagement history

  • Demographic information provided to the client organisation

Note

When we process supporter and donor data on behalf of a client, we do so as a data processor acting under the instructions of that client (the data controller). Individuals whose data is held in this way should direct their privacy inquiries to the relevant client organisation in the first instance. We will assist clients in meeting their obligations.


About website visitors, we may collect:

  • IP address and browser information (via cookies and analytics tools)

  • Pages visited, time on site, and referring URLs

  • Information you submit via contact forms or newsletter sign-ups

About job applicants, we may collect:

  • Resume, cover letter, and work samples

  • Contact details and employment history

  • References and reference check information

  • Right to work documentation

We do not collect sensitive information (such as health information, racial or ethnic origin, or religious beliefs) unless it is reasonably necessary and you have consented, or collection is required or authorised by law.

4. How We Collect Personal Information

We collect personal information:

  • Directly from you (via forms, emails, calls, meetings, or our website)

  • From your organisation when you engage us as a client

  • From publicly available sources (such as LinkedIn, company websites, or ACNC records)

  • From third-party platforms where you have connected your accounts (such as CRM systems, email platforms, or advertising accounts you grant us access to)

  • Automatically via cookies and analytics tools when you visit our website

We will always take reasonable steps to collect information directly from you where practicable.

5. Why We Collect and Use Personal Information

We collect and use personal information for the following purposes:

Client and project delivery

  • To deliver contracted services and manage client relationships

  • To communicate about project status, deliverables, and invoicing

  • To fulfil our obligations under client agreements

Marketing and business development

  • To respond to enquiries from prospective clients

  • To send our newsletter, insights, or event invitations (with your consent or where there is a legitimate interest)

  • To improve our service offerings based on client feedback

Operations and compliance

  • To maintain our business records and meet tax and accounting obligations

  • To comply with our legal obligations under Australian law

  • To protect the rights, property, or safety of ntegrity, our clients, or others

Recruitment

  • To assess suitability for roles at ntegrity

  • To conduct reference checks and verify work rights

We will not use your personal information for any purpose that is unrelated to why it was collected without your consent.

6. Disclosure of Personal Information

We do not sell personal information. We may share personal information with:

Service providers and subcontractors who assist us in delivering our services, including:

  • Cloud platforms and software tools (such as project management, CRM, email marketing, and analytics platforms)

  • Accounting and payment processing providers

  • IT support and security providers

Clients in the context of delivering services on their behalf, to the extent necessary and as agreed in our service agreement.

Professional advisers including lawyers, accountants, and insurers, where necessary.

Regulators and government bodies where required or authorised by law (including the Office of the Australian Information Commissioner (OAIC) in the event of a notifiable data breach).

Where we share personal information with third-party service providers, we take reasonable steps to ensure those providers handle information in accordance with the APPs and maintain appropriate security standards.

7. Overseas Disclosure

Some of the third-party platforms and tools we use may store or process data on servers located outside Australia, including in the United States, European Union, or other countries.

Where we disclose personal information to overseas recipients, we take reasonable steps to ensure those recipients handle it in a manner consistent with the APPs. This may include relying on the recipient's binding corporate rules, standard contractual clauses, or verified compliance with comparable privacy frameworks (such as the EU GDPR or UK GDPR).

Note

By using our services or providing us with your personal information, you acknowledge that it may be transferred to and stored or processed in countries outside Australia.


8. Data Security

We take the security of personal information seriously. Our security measures include:

  • Role-based access controls limiting who can access personal data

  • Use of reputable, enterprise-grade cloud platforms with encryption at rest and in transit

  • Multi-factor authentication requirements for systems holding personal data

  • Staff training on data handling and privacy obligations

  • A formal Data Retention Policy governing how long we keep data and how we securely dispose of it

  • An Information Security and Data Breach Response Policy governing incident detection and response

No method of data transmission or storage is completely secure. If you have reason to believe that your personal information has been compromised, please contact us immediately at [FILL: privacy@ntegrity.com.au].

9. Use of AI Tools

ntegrity uses AI-powered tools to support our work. Where we use AI tools that process personal information, we take the following steps:

  • We only use approved tools that meet our security and privacy standards

  • We do not input identifiable client supporter or donor data into AI tools unless the tool is expressly approved and operates under a data processing agreement

  • We review AI tool outputs before use to ensure accuracy and appropriateness

  • Team members are trained on the appropriate and responsible use of AI in the context of client data

10. Cookies and Website Analytics

Our website uses cookies and similar tracking technologies to improve your experience and understand how visitors use our site.

Types of cookies we use:

  • Essential cookies - Required for the website to function correctly

  • Analytics cookies - Help us understand how visitors interact with our site (e.g. Google Analytics)

  • Marketing cookies - Track visits for the purpose of delivering relevant advertising (where applicable)

You can control cookies through your browser settings. Disabling certain cookies may affect your experience of our website.

We use Google Analytics with IP anonymisation enabled. We do not use this data to identify individuals.

11. Your Privacy Rights

Under the Privacy Act 1988 and the APPs, you have the right to:

Access your personal information You may request a copy of the personal information we hold about you. We will respond within a reasonable timeframe (generally 30 days). We may charge a reasonable fee for access requests that are complex or require significant effort.

Correct your personal information If you believe the information we hold about you is inaccurate, out of date, incomplete, or misleading, you may ask us to correct it. We will take reasonable steps to correct the information.

Make a complaint If you believe we have interfered with your privacy, you may make a complaint to us using the contact details in Section 13. We will respond within 30 days.

If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):

  • Website: www.oaic.gov.au

  • Phone: 1300 363 992

  • Post: GPO Box 5218, Sydney NSW 2001

12. Notifiable Data Breaches

We are bound by the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988. If we experience a data breach that is likely to result in serious harm to any individual whose information is involved, we will:

  1. Contain the breach and assess the likely harm

  2. Notify affected individuals as soon as practicable

  3. Notify the OAIC within 30 days of becoming aware of the eligible data breach

We maintain an internal incident register and a formal breach response procedure. For any suspected breaches involving your personal information, please contact us immediately.

13. Contact Us

For any privacy-related questions, requests, or complaints, please contact:

Privacy Officer ntegrity Pty Ltd ACN 164 239 409

Email: people@ntegrity.com.au

Post: Hub @ Collins, 3/162 Collins St, Melbourne VIC 3000

We aim to respond to all privacy inquiries within 10 business days.

For any privacy-related questions, requests, or complaints, please contact:

14. Changes to This Policy

We review this Privacy Policy at least annually and whenever there are material changes to our practices or applicable law. The current version will always be available on our website.

Where changes are material, we will take reasonable steps to notify affected individuals (for example, via email or a notice on our website).

15. Definitions

  • Personal information - Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in a material form or not (as defined in the Privacy Act 1988)

  • Sensitive information - A subset of personal information including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, and criminal records

  • APP - Australian Privacy Principle, as set out in Schedule 1 of the Privacy Act 1988

  • OAIC - Office of the Australian Information Commissioner

  • NDB - Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988

  • Data processor - An entity that processes personal information on behalf of another entity (the data controller), under that entity's instructions