Legal
Privacy policy.
How this website collects, uses, stores and discloses personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Who we are
This website is operated by Dot Product Pty Ltd, based in Brisbane, Australia. This policy covers this website and the information you give us through it. It explains what we collect, why, who we share it with, how long we keep it, and how you can see, correct or remove it.
It sits alongside our terms, which cover your use of the site.
2. What we collect
We collect only what we need to answer an enquiry and to understand how the site is used.
- Contact details. Your name, your email address and, if you give it, your company name.
- Your answers. The options you choose in the form, such as the size of your team and what you would want first.
- How the site is used. Which pages are viewed, how far down each page is read, which buttons are pressed, how far through the form people get, and how long each page is open.
- Technical details. Your IP address and the approximate location it resolves to, your time zone, your browser’s language, and the network the connection came from.
We do not ask for sensitive information, such as health, racial or ethnic origin, political or religious beliefs, or criminal record, and ask that you do not send it.
3. How we collect it
Most of it comes directly from you, when you fill in the form or email us. The rest is recorded by the one script on every page while you use the site.
You can read the whole site without telling us who you are. If you choose not to give the details the form asks for, we may not be able to arrange a call.
4. Why we use it
- to reply to your enquiry and arrange the call you asked for;
- to send you a confirmation that your request arrived;
- to protect the form from automated abuse; and
- to understand which pages are useful and where people stop, so we can improve the site.
We do not sell personal information, and we do not use it for automated decisions that have a legal or similarly significant effect on you.
5. Identifiers and measurement
To tell one visit from another, the site stores two random identifiers in your browser: one that lasts until you close the tab, and one in local storage that lasts between visits. It also computes a device fingerprint, a hash of characteristics such as your browser, screen and graphics hardware, so that the same browser can be recognised on a later visit even if storage has been cleared.
The fingerprint on its own does not identify you. If you have given us your details, it may be matched to them so we can understand, in aggregate, who is reading the site. It never changes what a page shows you. There is no third-party advertising or tracking on this site.
6. Who we disclose to
We disclose personal information only to the service providers we need to run the site, and only for that purpose:
- Cloudflare hosts the site, stores form submissions and usage records, and provides the bot protection on the form (Turnstile).
- Resend sends your confirmation email and our notification of your enquiry, and receives email sent to this domain. Our emails may include an open-tracking image and tracked links, so we can tell whether the confirmation arrived.
- professional advisers, such as accountants and lawyers, where required; and
- a government agency or court, where we are compelled by law.
We do not pass your information to anyone else for their own marketing.
7. Overseas disclosure
Some of these providers store or process data outside Australia, mainly in the United States. Where we disclose personal information overseas, we take reasonable steps to make sure it is handled consistently with the Australian Privacy Principles, including through the provider’s data protection terms.
8. Storage, security and retention
Information is held in access-controlled cloud services, encrypted in transit and at rest by those providers, and only the people who need it can see it. No method of storage or transmission is completely secure, but we take reasonable steps to protect information from misuse, interference, loss, and unauthorised access, change or disclosure.
We keep your contact details until you ask us to delete them, or until we no longer need them to answer your enquiry, whichever is sooner. Usage records are kept in aggregate and are not linked to your name unless you complete the form.
If a data breach is likely to cause serious harm, we will notify the people affected and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
9. Emails we send
We send a confirmation when you ask for a call, and then the emails needed to arrange it. We do not add you to a newsletter. If you would rather not hear from us, reply and say so, or email hello@hourglassaudit.com.
10. Access and correction
You can ask for a copy of the personal information we hold about you, and ask us to correct anything wrong, out of date or incomplete, or to delete it. Email hello@hourglassaudit.com. We will confirm who you are and respond within 30 days, at no charge.
You can clear the two browser identifiers at any time by clearing this site’s data in your browser.
11. Complaints
If you think we have breached the Australian Privacy Principles, email hello@hourglassaudit.com with the details. We will acknowledge your complaint within five business days and respond in writing within 30 days.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.
12. Changes to this policy
We will publish any updated version on this page with a new effective date. The version on this page is always the current one.
13. Contact us
For any privacy question, request or complaint, email hello@hourglassaudit.com.
This privacy policy was last updated on 10 October 2026. Read it with our terms.
A call
Talk to us about your company brain.
One 30-minute call with Michael or Finlay, our co-founders. If we are a fit, your audit can start the same week.