Client Culture Pty Ltd (ABN 88 619 177 132) (“Client Culture”, “we”, “us”, “our”) provides client and employee experience measurement and analytics services to business customers worldwide. This Privacy Policy explains how we collect, use, disclose and protect personal information (also called personal data) when we act as either data controller or data processor/service provider across:
This Policy applies to our websites, SaaS platform, professional services and marketing activities. Local addenda in Section 16 set out country‑specific rights and obligations.
“Personal information / personal data” – information about an identified or reasonably identifiable individual.
“Processing” – any operation performed on personal data such as collection, storage, use or disclosure.
“Controller” – the entity that determines the purposes and means of processing.
“Processor / Service Provider” – the entity that processes personal data on behalf of a controller.
We do not intentionally collect special‑category or sensitive information unless a client instructs us and appropriate safeguards are in place.
Purpose | Legal Basis (UK/EU) | APP Compliance
Deliver SaaS platform & surveys | Contract performance (Art 6‑1‑b) | APP 3, 6
Improve and secure our services | Legitimate interests (Art 6‑1‑f) | APP 11
Marketing our products to B2B prospects | Consent or legitimate interests | APP 7 (opt‑out)
Legal & compliance, fraud prevention | Legal obligation (Art 6‑1‑c) | APP 6, 11
Where we rely on legitimate interests, we have conducted balancing tests to ensure your interests and fundamental rights are not overridden.
We only share personal data:
We do not sell personal information.
We host data in Australia and the EEA. If we must transfer personal data internationally we use one or more of:
We retain personal data only for as long as necessary to fulfil the purposes described in this Policy or to comply with legal obligations. Client survey data is retained while you remain an active customer plus 24 months, unless an earlier deletion request is received. Archived and backup copies are securely destroyed within 90 days thereafter.
We maintain technical and organisational security aligned with ISO 27001/SOC 2 controls, including:
Our websites and platform use cookies, SDKs and pixels to:
You can manage cookies through your browser.
EU / UK (GDPR): Access, rectification, erasure, restriction, portability, object, withdraw consent, complaint to DPA
Australia (APPs): Access, correction, anonymity / pseudonymity, complaint to OAIC
To exercise any right, email privacy@clientculture.com. We respond within 30 days (21 days for APP access requests).
Our services are directed to business users. We do not knowingly collect data from anyone under 16 years of age.
We do not use personal data for solely automated decisions that have legal or similarly significant effects.
This Policy does not cover third‑party sites linked from our platform. Please review their privacy notices.
We may update this Policy from time to time. Material changes will be notified via email or platform banner and posted on our website with a revised “updated date”.
Privacy Officer / Data Protection Officer
Client Culture Pty Ltd
Email: privacy@clientculture.com
If you believe we have not resolved your concern, you may contact:
16.1 Australia
16.2 European Economic Area & Switzerland
16.3 United Kingdom
End of Policy