GDPR & Australian Privacy Act Compliant

Privacy & Compliance

How we collect, process, and protect your data, in full compliance with GDPR (EU Regulation 2016/679) and the Australian Privacy Act 1988.

Last updated: April 2026

1. Who We Are

Excel Consultancy is operated by Wali Nori, trading as Excel, based in Perth, Western Australia. We provide digital marketing consultancy services to businesses in Australia and internationally, including the European Union.

Data Controller: Wali Nori, trading as Excel
Contact: excel@theexcelagency.com
LinkedIn: linkedin.com/in/wali-nori

2. What Data We Collect

2.1 Information You Provide Directly

When you use our contact forms, booking forms, or registration forms, we collect:

  • Your name and email address
  • Company name and website URL
  • Phone number (where provided voluntarily)
  • Messages and enquiry content you submit
  • Service preferences and budget information

2.2 Information Collected Automatically

When you visit our website, we may collect technical information including:

  • IP address (anonymised before storage where required by law)
  • Browser type and version
  • Pages visited and time spent on each page
  • Referring URL (how you found us)
  • Device type and operating system

This data is collected via Google Analytics 4 with IP anonymisation enabled. We implement Google Consent Mode v2, analytics only run with your explicit consent where required by law.

3. Legal Basis for Processing (GDPR)

For users in the European Union and European Economic Area, we process your personal data under the following legal bases:

  • Consent (Art. 6(1)(a) GDPR): For analytics cookies and marketing communications
  • Contract performance (Art. 6(1)(b) GDPR): For processing enquiries and delivering services
  • Legitimate interests (Art. 6(1)(f) GDPR): For security, fraud prevention, and service improvement, where not overridden by your rights
  • Legal obligation (Art. 6(1)(c) GDPR): Where processing is required by applicable law

4. How We Use Your Data

  • To respond to your enquiries and provide the services you've requested
  • To send you information about our services that you've requested
  • To improve our website and service delivery
  • To comply with legal obligations
  • To prevent fraud and ensure website security

We will never sell your data. We do not share your personal data with third parties for their own marketing purposes.

5. Cookies and Tracking

5.1 Essential Cookies

These cookies are necessary for the website to function and cannot be turned off. They include session management and security cookies.

5.2 Analytics Cookies (Consent Required)

We use Google Analytics 4 to understand how visitors interact with our website. These cookies are only set after you have given explicit consent via our cookie banner. You may withdraw consent at any time.

5.3 Marketing Cookies (Consent Required)

Where applicable, advertising pixels (Google Ads, Meta) may be loaded after consent. These are subject to Google Consent Mode v2, no data is sent to advertising platforms without valid consent.

5.4 Managing Cookies

You can manage your cookie preferences at any time by clicking the "Cookie Settings" link in the footer, or by adjusting your browser settings. Please note that disabling analytics cookies will not affect your ability to use the website.

6. Data Retention

We retain personal data for the following periods:

  • Enquiry and contact form submissions: 2 years from last contact
  • Client project data: 7 years (legal/accounting obligation)
  • Analytics data: 14 months (Google Analytics default)
  • Website server logs: 30 days

After retention periods expire, data is securely deleted or anonymised.

7. International Data Transfers

Excel is based in Australia and works with clients in the EU. When we transfer personal data from the EU to Australia, this is governed by standard contractual clauses (SCCs) as approved by the European Commission, given that Australia does not have an EU adequacy decision.

Where we use third-party services (Google Analytics, etc.) that transfer data to the United States, these transfers are governed by Google's Data Processing Terms and applicable SCCs. We configure all tools to minimise data transfer scope and enable EU-based processing where available.

8. Your Rights (GDPR)

If you are in the EU/EEA, you have the following rights under GDPR:

  • Right of access: Request a copy of the personal data we hold about you
  • Right to rectification: Request correction of inaccurate data
  • Right to erasure ("right to be forgotten"): Request deletion of your data in certain circumstances
  • Right to restrict processing: Request that we limit how we use your data
  • Right to data portability: Receive your data in a structured, machine-readable format
  • Right to object: Object to processing based on legitimate interests
  • Right to withdraw consent: Withdraw any previously given consent at any time

To exercise any of these rights, contact us at excel@theexcelagency.com. We will respond within 30 days.

If you believe we have not handled your data correctly, you have the right to lodge a complaint with your national data protection authority. In Germany, this is the Bundesdatenschutzbeauftragter (BfDI); in Italy, the Garante per la protezione dei dati personali.

9. Your Rights (Australian Privacy Act)

If you are in Australia, you have rights under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), including the right to access and correct your personal information. To make a request, contact excel@theexcelagency.com.

10. Security

We implement appropriate technical and organisational measures to protect your personal data against unauthorised access, alteration, disclosure, or destruction. This includes encrypted data transmission (HTTPS), access controls, and regular security reviews of our systems and processes.

11. Changes to This Policy

We may update this policy to reflect changes in our practices or applicable law. We will notify you of material changes via email (if we have your contact details) and by updating the "Last updated" date above.

12. Contact

For any privacy-related questions, requests, or complaints:

GDPR and compliance questions? If you're a client needing guidance on GDPR-compliant tracking implementation, see our Privacy & Compliance resources or book a consultation.