Back to the site

Last updated 29 July 2026

Privacy policy

Frac Consulting is a registered business name of Talent Hustler Pty Ltd (ABN 59 680 740 247). In this policy, “we”, “us” and “our” mean that company.

This policy explains what personal information we collect through this website and in the course of our consulting work, what we do with it, who else sees it, and how you can get at it or complain about it.

We have adopted the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). The APPs govern how we collect, use, disclose, store, secure and dispose of personal information, and a copy is available from the Office of the Australian Information Commissioner at oaic.gov.au (opens in a new tab).

What we collect

When you send an enquiry

The enquiry form on this site asks for your name, work email address and company, and gives you an optional box for what is front of mind and a choice between booking the audit and asking a question first. We also record the time of the submission and the IP address it came from.

Everything except the IP address is information you type. The IP address is collected automatically and used to limit how many submissions can come from one source in an hour, which is how we keep automated junk out of the form.

When you browse the site

We use Google Analytics to understand how the site is used: pages viewed, how you arrived, roughly where in the world you are (derived from your IP address), and what device and browser you used. We also use an error monitoring service that records technical details when something on the site breaks, which can include your IP address, the page you were on and your browser.

We do not run advertising, we do not use tracking for advertising, and we do not build profiles of individual visitors.

When we work with you

Delivering an audit or a build means looking at how your business actually runs. Depending on the engagement, that can include documents, process descriptions, system and tool inventories, commercial information, exports or samples of your data, and access to systems you nominate. Some of that material contains personal information about your staff, your customers or your suppliers.

When it does, you remain the organisation responsible for that information and we handle it on your behalf, under the confidentiality terms of the engagement. We ask for the least we need to answer the question you have hired us to answer, and we prefer redacted or sample data wherever it will do the job.

Sensitive information

Sensitive information is defined in the Privacy Act to include things like racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, criminal record and health information. We do not seek it and this website does not ask for it. If it appears in material you share with us during an engagement, we use it only for the purpose it was given to us, for a directly related purpose you would expect, with your consent, or where the law requires it.

Why we collect it

We use personal information to:

  • reply to your enquiry and arrange a conversation or an audit;
  • deliver, invoice and support the work you have engaged us for;
  • keep the business records that Australian tax and corporate law require us to keep;
  • understand how this site is used, so it can be made clearer; and
  • find and fix faults in the site.

We do not run a mailing list and we will not add you to one from a form submission. If we ever start sending marketing email, it will say who it is from and how to stop it, and you can tell us to stop at any time.

We do not sell personal information, and we do not disclose it to data brokers or advertisers.

Cookies and analytics

Google Analytics sets cookies in your browser (such as _ga) to tell repeat visits from new ones and to measure how people move through the site. This site shows no cookie banner: it is aimed at Australian businesses, and under Australian privacy law analytics cookies of this kind require disclosure rather than opt-in consent. This section is that disclosure. If you visit from the EU or the UK, note that we have not implemented consent management for those regimes.

You can block or clear these cookies in your browser settings, or install Google's opt-out browser add-on (opens in a new tab). The site works normally either way, because nothing here depends on a cookie.

Our error monitoring sends data over the network and does not set cookies or store anything in your browser. This site has no login and no accounts, so there are no session or authentication cookies.

Who else sees it

We run the site and the business on a small number of systems. Each holds only what it needs:

  • Microsoft Azure: hosts this website, and hosts the systems we build and run on it. Anything we store, we store there.
  • Close: our customer relationship manager. Enquiries are recorded here so they can be followed up.
  • Sentry: error monitoring. As well as fault diagnostics, Sentry receives a copy of every enquiry submitted through this site. That is deliberate, and it means an enquiry is not lost if our CRM is unavailable at the moment you send it.
  • Google: two separate things. Google Analytics measures how this website is used, as described above. Google Workspace runs our email, calendars and documents, so our correspondence with you, and anything you send us by email or attach to it, is held there.
  • Talent Hustler: the platform we use to run consulting engagements, covering things like consultant profiles, proposals and engagement documents. We build and operate it ourselves, and it is a product of the same company that trades as Frac Consulting, so material held there has not been handed to an outside party. We are naming it anyway, because you should know what your material sits in. It has its own privacy policy at talenthustler.io (opens in a new tab).

At present this website stores nothing itself. An enquiry passes straight through to the systems above rather than being kept on the site. That may change as we build more of the business onto it, and if it does, what we keep will live in the Azure hosting described above and this policy will be updated to say so before it happens.

Beyond those, we disclose personal information only where you consent to it, where it is needed to deliver work you have engaged us for, to our professional advisers under obligations of confidence, or where the law requires or authorises it.

Information processed outside Australia

Under APP 8 you should know this before you send us anything: the information collected through this website is processed outside Australia.

Microsoft, Close, Sentry and Google are all based in the United States, and all of them run on global infrastructure. Talent Hustler is Australian, but it runs on that same infrastructure, so the same applies to it. Your information may be handled in the United States or in any other country those providers operate from. We choose the providers, not the individual data centres they route and store through, and those can change without us being told. We cannot guarantee that the countries involved have privacy laws equivalent to Australia's.

What we can do is choose providers carefully. We take reasonable steps to ensure they handle personal information consistently with the Australian Privacy Principles, relying on their published data protection commitments and security certifications. If the location of your information matters to your organisation, tell us before an engagement starts and we will agree in writing what may be held where.

Client material during an engagement

Material you give us to do the work is yours. We use it for that engagement and nothing else. We do not use it to market to your staff or customers, and we do not pass it to another client.

Which tools and systems are used to do the work, including any AI services and what may be sent to them, is agreed with you in writing before the engagement starts, and is part of the engagement terms rather than this policy. If you want a restriction, that is the point to set it.

At the end of an engagement we will return or destroy client material on request, other than the copies we are required to retain as business records. Anything we build for you, you own outright.

Security

Personal information is stored in a way that reasonably protects it from misuse, loss, and unauthorised access, modification or disclosure. Traffic to this site is encrypted in transit, and access to client material is limited to the people doing the work.

Wherever a service supports it, our systems prove who they are to each other using identities the hosting platform issues and expires on our behalf, rather than a stored password or key. A credential that does not exist cannot be leaked, guessed or left behind in someone's notes. Where a key is genuinely unavoidable, it is created for that one purpose, held only by the system that needs it, and never shared between systems or people.

No system is perfectly secure. If a data breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

How long we keep it

Enquiries and client records are kept as business records for a minimum of seven years, which is what Australian tax and corporate record-keeping obligations require of us. When personal information is no longer needed for the purpose it was collected for, and we are not required to retain it, we take reasonable steps to destroy it or permanently de-identify it.

Analytics data is retained under Google Analytics' own retention settings, and error monitoring data is kept for a short period and then discarded.

Getting at your information, and correcting it

You can ask for the personal information we hold about you, and ask us to correct it if it is wrong or out of date. Write to privacy@frac.consulting and we will respond within a reasonable period.

There is no fee for making a request, though we may charge a reasonable administrative fee for providing a copy. We may ask you to identify yourself before releasing anything; that protection exists for you. In limited circumstances the Privacy Act allows us to refuse access; if that happens we will tell you why in writing.

If you are an employee or customer of one of our clients and your information reached us through them, contact that organisation first, since it is their record. We will work with them on any request.

Complaints

If you think we have mishandled your personal information, email privacy@frac.consulting. We will acknowledge your complaint, tell you when to expect a response, and try to resolve it directly.

If we cannot resolve it between us, or you are unhappy with our response, you can refer the matter to the Office of the Australian Information Commissioner at enquiries@oaic.gov.au or oaic.gov.au (opens in a new tab).

Changes to this policy

We update this policy as the business and the site change. The current version always lives at this address, and the date at the top tells you when it last moved.