This Privacy Policy explains how ExpandIQ Pty Ltd (ABN 47 691 656 649) (we, us, our) collects, holds, uses and discloses personal information, and how you can access and correct your personal information or make a privacy complaint.
We manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This policy applies to personal information we collect through:
The types of personal information we may collect include:
We do not usually collect sensitive information (as defined in the Privacy Act). If we need to collect sensitive information, we will only do so where permitted by law and, where required, with your consent.
In some cases, we may handle personal information contained in materials provided to us in the course of delivering services (for example, documents or datasets shared by a client). Where this occurs, we handle that information for the purpose of providing the relevant services and in line with any contractual obligations.
We collect personal information in a range of ways, including:
We collect, use and disclose personal information for purposes including:
We may send marketing communications where you have requested information from us, subscribed to updates, downloaded resources, attended an event or otherwise indicated interest.
You can opt out at any time by using the unsubscribe link in an email or by contacting us using the details in section 13.
We may disclose personal information to:
We do not sell personal information.
Some of our service providers may store or process personal information outside Australia. This can occur where providers use overseas infrastructure, support teams or subprocessors to deliver their services.
Where we disclose personal information to overseas recipients, we take reasonable steps to ensure it is handled in a manner consistent with Australian privacy requirements, where applicable.
Depending on the providers we use from time to time, overseas recipients may be located in the United States and other locations where major technology service providers operate.
We use cookies and similar technologies to:
We use Google Analytics to help us understand website traffic and usage. Google Analytics may collect information such as your IP address, device identifiers, browser type, pages visited, time spent on pages and referral information.
You can control cookies through your browser settings. If you disable cookies, parts of the website may not function as intended.
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. We use a combination of administrative, technical and physical safeguards appropriate to the nature of the information we hold.
We keep personal information only for as long as needed for the purposes set out in this policy, unless we are required or authorised by law to retain it for longer. Where appropriate, we take steps to delete or de-identify information.
You may request access to the personal information we hold about you and request corrections if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
To make a request, contact us using the details in section 13. We may ask you to verify your identity before we action your request.
We aim to respond within 30 days, unless the request is complex or we need additional information.
If you believe we have mishandled your personal information, you can make a complaint by contacting us (see section 13). Please include enough detail for us to understand the issue and any relevant dates or interactions.
We will acknowledge your complaint and respond within a reasonable timeframe. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
We are not currently bound by a registered APP code.
For enquiries or complaints about this Privacy Policy, please visit our Contact page.
If we experience an eligible data breach, we will take steps to comply with the Notifiable Data Breaches scheme, including notifying affected individuals and the OAIC where required.
We may update this policy from time to time. The updated version will be published on our website with a new "Last updated" date.
Last updated: March 2026