Privacy Policy

Last Updated: June 2026

1. Introduction

Richos Agency (ABN 72 177 648 646) respects your privacy and is committed to handling personal information responsibly.

This Privacy Policy explains how Richos Agency (“Richos Agency”, “we”, “us” or “our”) collects, holds, uses, discloses and protects personal information when you visit our website, contact us, book an appointment, become a client, use our services or otherwise interact with us.

It also explains how we may handle personal information on behalf of our business clients when providing CRM, automation, website, appointment-booking, communication, lead-management and related services.

We aim to handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply to us. Even where an exemption may apply, we aim to follow reasonable privacy practices.

2. Meaning of personal information

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in a material form.

Some information may also be sensitive information under Australian privacy law. We do not intentionally collect sensitive information unless it is reasonably necessary for our services and the individual has consented, or collection is otherwise permitted by law.

3. Personal information we may collect

Depending on how you interact with us, we may collect:

Name, email address, telephone number, business name, job title and other contact details.

Information you submit through website, contact, discovery-call, onboarding, access or support forms.

Appointment details, calendar information and attendance records.

Information discussed or provided during discovery calls, onboarding calls, support calls, meetings or other communications.

Business information, service requirements, goals, customer journeys, pipeline stages, appointment rules, frequently asked questions, internal processes and preferences.

Emails, SMS messages, support requests, form responses, notes, communication history and customer-service records.

Proposal, agreement, invoice, payment-status and transaction information. Payment card details are generally handled directly by payment providers such as Stripe, and we do not ordinarily store complete payment card numbers.


Account, software, integration, domain and technical information that a client provides so we can perform our services.

Website and device information such as IP address, browser type, device type, referring pages, pages viewed, time spent on pages, approximate location and cookie or analytics data.

Information from referrals, social media, public business directories, publicly available sources and third-party platforms where lawful.

Any other information you choose to provide to us.

If you do not provide information we reasonably need, we may be unable to respond to your enquiry, arrange an appointment or provide some or all of our services.

4. How we collect personal information

We may collect personal information:

Directly from you through our website, forms, calendar, email, SMS, telephone calls, meetings, social media or other communications.

From our clients when they engage us to provide services or give us access to their systems, files or accounts.

Automatically through cookies, analytics tools, log files and similar technologies.

From third-party platforms and service providers used to operate our business or deliver services.

From referrals, public business directories, social media profiles and other publicly available sources.

From another person where you have authorised them to provide the information, or where collection from you directly would be unreasonable or impracticable.

5. How we use personal information

We may use personal information to:

Respond to enquiries and communicate with prospective clients, clients, suppliers and other contacts.

Arrange, confirm, remind, reschedule and manage discovery calls, onboarding calls, appointments and meetings.

Assess business needs, prepare proposals and service agreements and provide quotations.

Set up, deliver, maintain, support and improve our CRM, automation, website, appointment, communication, lead-management and consulting services.

Create and manage contact records, pipelines, calendars, forms, workflows, reminders, internal notifications, reports and related systems.

Process payments, issue invoices, maintain business and accounting records and manage overdue amounts.

Provide support, troubleshoot problems and maintain system security.

Personalise and improve our website, services, communications and customer experience.

Send service-related notices, onboarding information, appointment messages and other operational communications.

Send marketing communications where permitted by law and manage opt-out requests.

Prevent fraud, misuse, security incidents and unlawful activity.

Comply with our agreements, legal obligations, court orders and lawful requests.

Establish, exercise or defend legal claims and protect our rights, property, users, clients and systems.

Carry out another purpose disclosed when the information is collected, or a related purpose that would reasonably be expected.

6. Client data and information processed on behalf of clients

When Richos Agency provides services to a client, we may access or process personal information controlled by that client. This can include information about the client’s leads, customers, appointment attendees, employees, contractors and other contacts.

Depending on the services, client data may include contact details, enquiry information, form responses, appointment information, communication history, pipeline status, lead source, notes, customer preferences, transaction status and other information placed in the client’s systems.

For this information, the client generally decides why and how the information is collected and used. Richos Agency handles it to provide the agreed services and in accordance with the client’s lawful instructions, our agreement and applicable law.

Each client is responsible for:

Ensuring it has a lawful basis and any required notices or consents for collecting and providing personal information to Richos Agency and connected service providers.

Maintaining an accurate privacy policy and collection notices for its own business.

Ensuring its instructions and use of the systems comply with applicable privacy, marketing, spam, telecommunications and other laws.

Responding to privacy requests or complaints from its own customers, unless Richos Agency has expressly agreed to assist.

If your information has been collected by one of our clients through a system we support, you should usually direct your privacy request to that client first. We will reasonably assist the client where required by our agreement or applicable law.

We do not use client data for our own unrelated marketing purposes or sell it.

7. SMS, email and other communications

If you submit an enquiry, book an appointment, become a client or otherwise provide your contact details, we may send communications relating to your enquiry, appointment, proposal, onboarding, services, account, support or other business relationship.

Where permitted by law, we may also send marketing communications about Richos Agency’s services. You can unsubscribe from marketing emails using the unsubscribe option included in the message or by contacting us. You can opt out of SMS marketing by replying STOP. For SMS assistance, reply HELP. Message and data rates may apply.

Opting out of marketing does not prevent us from sending communications that are reasonably necessary to provide services, manage an appointment, administer an account, address security or legal matters or complete a transaction.

8. Disclosure of personal information

We do not sell or rent personal information.

We may disclose personal information where reasonably necessary to:

Our employees, contractors and professional advisers who need the information to perform their roles.

Our CRM, automation, website, hosting, cloud-storage, email, calendar, communications, telecommunications, analytics, payment, accounting, support, integration and artificial-intelligence service providers.

Platforms used to deliver services, which may include GoHighLevel or LeadConnector, Stripe, Google services, Make, Voiceflow, OpenAI, and other providers selected for a project.

A client whose information relates to that client, its systems or services.

Government bodies, regulators, law-enforcement agencies, courts, tribunals or other parties where required or authorised by law.

A purchaser, adviser or relevant party in connection with a proposed or completed sale, restructure, merger or transfer of all or part of our business, subject to appropriate confidentiality and privacy safeguards.

Other parties with your consent or at your direction.

Third-party providers handle information under their own terms and privacy policies. We take reasonable steps to select reputable providers and limit disclosure to what is reasonably required.

9. Overseas storage and disclosure

Some service providers we use operate, store information or allow support access outside Australia. As a result, personal information may be stored in or disclosed to recipients in countries including the United States and other countries in which our service providers or their subcontractors operate.

The exact locations can change as providers update their infrastructure and subcontractors. Where Australian privacy law applies, we take reasonable steps appropriate to the circumstances to protect personal information and address overseas handling.

10. Cookies and analytics

Our website may use cookies, pixels, analytics tools and similar technologies to operate the website, remember preferences, understand website use, measure performance and improve our services and marketing.

These technologies may collect IP address, device and browser details, pages viewed, referring website, approximate location, dates and times of visits and interactions with website content.

You can usually control or disable cookies through your browser settings. Disabling some cookies may affect website functionality. Where required, we will request consent before using non-essential cookies.

11. Artificial intelligence and automated systems

We may use artificial-intelligence tools and automated systems to assist with tasks such as drafting, summarising, categorising enquiries, routing leads, producing workflow content, providing chatbot responses or supporting service delivery.

We take reasonable steps to avoid submitting unnecessary personal or sensitive information to these tools and to configure their use appropriately for the relevant service.

We do not currently intend to use personal information to make solely automated decisions that have a significant legal or similarly significant effect on an individual. If our practices change, we will update this Privacy Policy and provide any additional information required by law.

12. Data quality

We take reasonable steps to ensure the personal information we hold is accurate, complete, and up to date where required for its intended use. Please contact us if your information changes or you believe our records are incorrect.

13. Data security

We take reasonable technical, organisational and administrative measures to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

Measures may include access controls, passwords, multi-factor authentication where available, reputable service providers, restricted permissions, staff or contractor confidentiality requirements, software updates and reasonable backup and security practices.

No electronic transmission or storage system is completely secure, and we cannot guarantee absolute security.

14. Data retention and deletion

We retain personal information only for as long as reasonably required to provide services, manage our business, maintain records, resolve disputes, enforce agreements, meet accounting or tax requirements, address security matters and comply with law.

Retention periods vary depending on the type of information, the services involved, contractual requirements, legal requirements, and technical limitations.

When personal information is no longer required for a lawful purpose, we will take reasonable steps to delete or de-identify it. Information may remain temporarily in secure backups or provider systems until it is deleted through normal retention cycles.

Following termination of a client service, the client is responsible for exporting any information it needs within the period stated in the service agreement. We may delete or restrict access to client data after the service ends, subject to our agreement, legal obligations and reasonable backup cycles.

15. Access and correction

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading.

Requests should be sent to [email protected] and should provide enough information for us to identify you, locate the relevant records, and understand the request. We may ask you to verify your identity before providing access or making changes.

We will respond within a reasonable period. We may refuse or limit a request where permitted by law, including where access would unreasonably affect another person’s privacy, reveal commercially sensitive information or be unlawful. Where required, we will explain the reason for refusal and available complaint options.

You may request deletion of personal information. Deletion is not an absolute right, and we may retain information where reasonably required to provide services, keep legitimate business records, resolve disputes, meet legal obligations, or exercise legal rights.

16. Privacy complaints

If you believe we have mishandled personal information or breached an applicable privacy obligation, please contact us at [email protected].

Please include your name, contact details, a description of the issue and any relevant documents or information. We will acknowledge the complaint, investigate it and aim to respond within 30 days. If we need more time, we will explain why and provide an updated timeframe.

We will work with you in good faith to resolve the complaint. If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner through www.oaic.gov.au.

17. Data breaches

We maintain reasonable processes for responding to suspected data breaches. If a breach occurs, we will take reasonable steps to contain it, assess its impact, and reduce possible harm.

Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify affected individuals and the relevant regulator as required.

Where a breach affects information we process for a client, we may notify and assist that client in accordance with our agreement and applicable law.

18. Third-party websites and services

Our website and services may contain links to or integrate with third-party websites and services. Those third parties control their own privacy practices, and their privacy policies and terms apply to their handling of information. We are not responsible for third-party privacy practices outside our control.

19. Changes to this Privacy Policy

We may update this Privacy Policy when our services, systems, providers or legal obligations change.

The updated policy will be published on our website with a revised “Last updated” date. Material changes may also be communicated through other reasonable channels where appropriate.

20. Contact us

Richos Agency

ABN: 72 177 648 646

Address: 18 Wurrook Circuit, North Geelong VIC 3215, Australia

Email: [email protected]

Website: richosagency.com

Richos Agency

Helping businesses capture more leads, book more appointments, and streamline their operations through smart automation systems.

FOLLOW US

Copyright 2026. Richos Agency. All Rights Reserved.