Twin Lakes Studio

Legal

Privacy policy

Last updated 10 October 2026

This policy explains what personal information The IT Dept Pty Ltd (ABN 12 665 405 505), trading as Twin Lakes Studio (Twin Lakes, we, us) collects, why, how we store it, and what you can ask us to do with it. We follow the Privacy Act 1988 (Cth) and the Australian Privacy Principles, whether or not the law strictly requires a business our size to.

What we collect

  • When you ask for a draft or email us: your name, business name, email, phone number if you give it, suburb, your current website, and whatever you tell us about your business.
  • When you become a customer: billing details. Card and bank details are handled by our payment provider; we never see or store full card numbers.
  • Content for your site: whatever you send us, which may include names, photos and contact details of your staff.
  • Support: the emails and messages we exchange while we work together.
  • Technical: when you visit twinlakes.au, our servers log your IP address, browser type and the pages requested, for security and to keep the site running.
  • Analytics: we use Google Analytics to count visits and see which pages people read. It sets cookies in your browser and sends Google the pages you view, basic device and browser details, and an approximate location worked out from your IP address, which Google does not store. We don't use it for advertising and we don't link it to anything you type into a form. You can stop it with your browser's cookie settings or Google's opt-out browser add-on, and the site works the same either way.

Why we collect it

  • To reply to you and build your draft.
  • To build, host and support your site, booking system, form or app.
  • To bill you and keep the records the tax office requires.
  • To keep our systems secure.
  • To meet legal obligations.

We do not sell personal information and we do not put you on marketing lists. We may occasionally email existing customers about the service itself, and you can opt out of anything that is not essential to running your site.

Who we share it with

Only the providers we need to run the service:

  • Our support desk, which we host ourselves in Australia. Your enquiry becomes a ticket there so we can reply from hello@twinlakes.au.
  • Our email provider, Microsoft 365.
  • Our hosting providers in Australia, where your site and its data live.
  • Domain registrars and the .au registry, which require registrant details for your domain. Some of these details appear in public registry records, as the registry rules require.
  • Our payment provider, for billing.
  • Google, for Google Analytics, as described above.
  • App stores, if we publish an app for you.
  • Our accountant, lawyer or insurer where needed, and law enforcement or regulators where the law requires it.

We do not share your information with anyone else without your consent.

Overseas

Your site, its data and our support desk are in Australia. Some providers we rely on, such as our email and payment providers and Google Analytics, are global companies and may process information outside Australia, including in the United States. We choose providers with strong security and contractual commitments to protect it.

Your customers' information

If your site collects bookings or enquiries, we handle that information on your behalf. You own it. We store it in Australia, use it only to run your site, give it to you whenever you ask, and delete it when you leave us. You are responsible for telling your own customers how you use their details, and we will help you with a plain-English privacy notice for your site.

How we protect it

Encrypted connections everywhere, access limited to the people who need it, daily backups, and systems kept up to date. Nick Pratley runs Twin Lakes and is the only person with routine access; any contractor we use signs a confidentiality agreement first. If a data breach happens that is likely to cause you serious harm, we will tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.

How long we keep it

  • Enquiries that do not become customers: up to 2 years, then deleted.
  • Customer records: for as long as you are a customer, then 7 years for the financial records the law requires. Site content and data are deleted 60 days after you leave, or sooner on request.
  • Server logs: 90 days.

Access, correction and complaints

You can ask to see the personal information we hold about you, ask us to correct it, or ask us to delete it. Email hello@twinlakes.au. We will respond within 30 days and there is no charge, unless a request is unusually large.

If you think we have mishandled your information, email us first and we will try to fix it quickly. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Changes and contact

We will update this policy when something changes, and the date at the top will tell you when. Questions go to hello@twinlakes.au. The privacy contact is Nick Pratley, The IT Dept Pty Ltd, Budgewoi NSW.

See also: Terms of service, Acceptable use policy.