Legal

Privacy Policy

Effective and last updated: 10 August 2026 · Questions? [email protected]

Scope and our commitment

Richard Baldwin, ABN 62 619 046 362, trading as Scroll Ready is responsible for the personal information described here. This policy covers our website, applications, managed service and support operations. We follow the Australian Privacy Principles where they apply and use them as our baseline privacy standard.

Information we collect

We may collect account and contact details; business, brand and onboarding answers; billing status and transaction references (not full card numbers); uploaded content and media; connected-channel identifiers, tokens, posts, comments, messages and performance data; enquiries and leads submitted through hosted forms; support communications; consent and unsubscribe records; and device, log, cookie, security and usage data.

How we collect it

We collect information directly from you and your authorised team, from people who use a Scroll Ready form, automatically when the service is used, from connected social platforms and integrations, from payment and email providers, and from public or business sources where lawful. If you give us another person’s information, you must have authority and provide any required notice.

Why we use it

We use information to create and administer accounts; provide, personalise, secure and troubleshoot the service; create, schedule and publish content; manage authorised interactions; capture and route leads; process subscriptions and refunds; send account, billing, trial and support messages; measure performance; prevent misuse; comply with law; and improve our products and operations.

Legal basis and choices

Australian privacy law does not use one universal ‘legal basis’ framework. We collect and use information where reasonably necessary for our functions, with consent where required, to perform our agreement, meet legal obligations and operate the service. If necessary information is not provided, some features may not work.

Marketing and trial emails

We send commercial electronic messages only with express consent or another form of consent permitted by law. Messages identify us and provide a simple unsubscribe method. We action electronic opt-outs immediately in our system and in all cases within five working days. Opting out does not stop essential security, billing, transactional or legally required communications.

Cookies, analytics and advertising

We use necessary cookies and similar storage for sign-in, security, preferences and core functionality. We may use analytics and advertising technologies to understand visits and measure campaigns. Providers may receive device identifiers, IP address, page activity and campaign information. Browser controls and available consent tools can limit non-essential technologies, but blocking necessary cookies may prevent sign-in.

Who receives information

We disclose information only as reasonably needed to authorised staff and contractors; hosting, database, security, communications, email, analytics, support, payment, automation and AI providers; social platforms you connect; professional advisers; a buyer in a proposed business transaction under confidentiality; and regulators, courts or law enforcement where required or authorised. We do not sell personal information or customer lead lists.

AI processing

Content, prompts, brand information and relevant media may be sent to contracted AI providers to generate or analyse material. We limit data to what the task needs and use available provider controls to protect it. Do not upload sensitive personal information unless it is necessary, authorised and appropriate for the requested service.

Overseas handling

Some providers and social platforms operate infrastructure or support outside Australia, including in the United States and other countries where they or their subprocessors operate. Protections may differ. Where the Australian Privacy Principles apply, we take the reasonable steps required by APP 8 before overseas disclosure, subject to lawful exceptions.

Security

We use safeguards appropriate to the information and risk, including access controls, encryption for sensitive connection tokens, signed time-limited links, provider authentication, audit and security logging, rate limits and restricted administrative access. No internet service is completely secure; notify us immediately if you suspect unauthorised use.

Retention and deletion

We retain information only while needed for the purposes above, account recovery, disputes, fraud prevention, legal and tax duties, and secure backups. Retention varies by record. When no longer required, we take reasonable steps to delete or de-identify it. Account deletion disconnects integrations and schedules active data for deletion, but limited records may remain where legally required and in backups until they cycle out.

Access and correction

Ask for access to or correction of information by emailing [email protected]. We may verify identity. We normally respond within 30 days and will explain any lawful refusal and complaint avenue. Many account details can also be updated in the service.

Deletion, objection and portability

You may ask us to delete information, restrict optional use, stop direct marketing or provide an export. These requests depend on applicable law and may be limited by security, contractual, recordkeeping or legal requirements. We will explain the outcome. Email [email protected]; no login is required to unsubscribe.

Children

The service is for businesses and is not directed to children under 16. Do not create an account or provide a child’s information without appropriate authority and a lawful business need. Contact us if you believe a child has provided information improperly.

Privacy incidents

We investigate suspected data breaches, contain and remediate them, and assess notification duties. Where the Notifiable Data Breaches scheme applies and a breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as required.

Complaints

Email a privacy complaint to [email protected] with enough detail to investigate. We will acknowledge it and aim to respond within 30 days. If unresolved and the Privacy Act applies, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. Spam complaints may be made to the Australian Communications and Media Authority at acma.gov.au.

Changes to this policy

We may update this policy as the service, providers or law changes. We will post the new effective date and give reasonable notice where a change materially affects how we handle information.

Contact

Richard Baldwin, NSW 2867, Australia. [email protected].