1. Who we are
CostrixIQ is operated by Sequoia Advisory Pty Ltd (ABN 16 662 688 048, ACN 662 688 048) of Level 12, 121 Castlereagh Street, Sydney NSW 2000, Australia. In this policy, "CostrixIQ", "we", "us" and "our" refer to Sequoia Advisory Pty Ltd in connection with the CostrixIQ website and related communications. We are the controller of the personal information described in this policy.
This policy applies to personal information we handle as controller through this website and our related sales, launch, insight and enquiry activities. It does not apply to personal information that a customer of the CostrixIQ software platform uploads to the platform. We handle that information on the customer’s behalf and on its instructions, under the customer’s own agreement with us; the customer is responsible for telling the individuals concerned how it is handled.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where the General Data Protection Regulation (Regulation (EU) 2016/679) (GDPR) or the United Kingdom GDPR applies to our handling of your personal information, the additional information in clauses 5, 6, 12 and 13 also applies to you.
Our representative in the European Union for the purposes of Article 27 of the GDPR is Euverify Ltd (Ireland), Unit 3D North Point House, North Point Business Park, New Mallow Road, Cork T23 AT2P, Ireland, gdpr@euverify.com. Our representative in the United Kingdom for the purposes of Article 27 of the UK GDPR is Euverify Ltd (UK), 3rd Floor, 86-90 Paul Street, London, EC2A 4NE United Kingdom, gdpr@euverify.com. You may contact either representative on any matter relating to our processing of your personal information.
We are not required to appoint a data protection officer under Article 37 of the GDPR and have not done so. Privacy enquiries should be directed to our Privacy Officer using the details in clause 17.
2. Personal information we collect
The information we collect depends on how you interact with us and may include:
- Identity and contact information: name, work email address, telephone number, job title, company, country or region and company size.
- Enquiry and relationship information: information you provide about your objectives, current processes, priorities, interests, demonstration requests and communications with us.
- Subscription and preference information: your registration, insight or product update preferences, consent records and unsubscribe status.
- Technical and usage information: internet protocol address, device and browser information, approximate location, referral source, pages viewed, interactions, dates and times of access, cookie identifiers and conversion events. Our hosting platform also records visitor numbers and page views automatically at platform level, outside the choices you make in our cookie banner.
- CRM information: records of enquiries, communications and relationship activity held in our customer relationship management system.
- Security and anti-fraud information: where you submit a form, a security token and your internet protocol address are sent to our anti-automation provider to confirm that the submission is genuine, and a one-way hash derived from your internet protocol address and the form type is held for ten minutes to limit repeated submissions. We do not store your raw internet protocol address for that purpose.
- Marketing and campaign information: the source, campaign, referral and search information associated with your visit or enquiry, the content you view or download, and your engagement with our emails.
We do not ask you to provide sensitive information through our public website forms. Please do not include confidential project information, sensitive personal information or personal information about another person unless you are authorised to do so.
We do not seek to collect special category data within the meaning of Article 9 of the GDPR, or sensitive information within the meaning of the Privacy Act 1988 (Cth), through the website.
3. How we collect information
We generally collect personal information directly from you when you submit a form, subscribe, communicate with us, request a demonstration or otherwise engage with CostrixIQ. We may also collect information automatically through cookies and similar technologies, or receive it from service providers, professional contacts, referrals and publicly available business sources where lawful.
If you submit one of our forms, the information you enter, together with the page you submitted it from and your current cookie choices, is sent to our own server and then to our customer relationship management system whether or not you have accepted optional cookies, because you have asked us to respond to you. Accepting optional cookies is never a condition of using the website or of contacting us.
4. Why we collect, use and disclose information
We may handle personal information to:
- respond to enquiries and arrange personalised demonstrations;
- manage registrations, insight subscriptions and product updates;
- understand your organisation’s interests and maintain our business relationship with you;
- operate, secure, measure and improve the website, content and user experience;
- perform analytics, attribution and conversion tracking;
- administer our CRM, communications and internal business operations;
- detect misuse, protect our rights and maintain security;
- comply with legal obligations and respond to lawful requests; and
- carry out other purposes that we explain at the time of collection or that you authorise.
Where required, we rely on your consent for marketing communications and non-essential tracking. You can withdraw your marketing consent at any time using the unsubscribe facility in a message or by contacting us, and you can withdraw your cookie consent through the cookie settings on the website. Withdrawing consent does not affect the lawfulness of anything we did in reliance on that consent before it was withdrawn, and does not prevent us from responding to a request you have made or from sending you service or transactional messages.
5. Legal bases for processing (EEA and United Kingdom)
Where the GDPR or the UK GDPR applies, we rely on the following legal bases. Where more than one basis is listed, we rely on whichever applies to the particular processing.
- Responding to enquiries and arranging demonstrations: performance of a contract or steps taken at your request before entering into one (Article 6(1)(b)), and our legitimate interests in responding to business enquiries (Article 6(1)(f)).
- Marketing emails, insight subscriptions and product updates: your consent (Article 6(1)(a)) or, where permitted by the direct marketing law that applies to you, our legitimate interests in marketing our products to business contacts (Article 6(1)(f)).
- Non-essential cookies, analytics, attribution and conversion tracking: your consent (Article 6(1)(a)), obtained through the cookie banner before those technologies are used.
- Operating, securing and improving the website: our legitimate interests in maintaining a secure, functional and effective website (Article 6(1)(f)).
- Administering our CRM, communications and internal business operations: our legitimate interests in managing, resourcing and developing our business (Article 6(1)(f)).
- Detecting misuse, protecting our rights and maintaining security: our legitimate interests in protecting our business, systems, users and legal position (Article 6(1)(f)).
- A proposed sale, investment or other business transaction: our legitimate interests in evaluating, negotiating and completing a corporate transaction (Article 6(1)(f)).
- Complying with legal obligations and responding to lawful requests: compliance with a legal obligation to which we are subject (Article 6(1)(c)) and, where the obligation arises outside the EEA or the UK, our legitimate interests in complying with it (Article 6(1)(f)).
Where we rely on legitimate interests, we have assessed those interests against your interests, rights and freedoms. You may ask us for a summary of that assessment using the contact details in clause 17.
Providing your personal information to us is not a statutory requirement. Where a field on one of our forms is marked as required, providing that information is necessary for us to respond to your enquiry, arrange a demonstration or provide the subscription you have asked for; if you do not provide it, we may be unable to do so. Providing any other information is voluntary.
6. Automated decision-making and profiling
We use our customer relationship management system to segment and prioritise enquiries — for example by industry, organisation size, stated interest, region and engagement with our communications — so that we can route an enquiry to the right person and tailor the information we send. That activity involves profiling.
It does not produce legal effects concerning you or similarly significantly affect you, and we do not make decisions about you based solely on automated processing within the meaning of Article 22 of the GDPR. If that changes, we will update this policy and provide meaningful information about the logic involved and the significance and envisaged consequences of the processing.
From 10 December 2026, Australian Privacy Principle 1.7 requires an entity bound by the Privacy Act 1988 (Cth) to describe in its privacy policy any computer program it uses to make, or to do a thing substantially and directly related to making, a decision that could reasonably be expected to significantly affect an individual’s rights or interests. We do not use any such program in connection with the website. We will update this clause if that changes.
7. Direct marketing
We send commercial electronic messages only where you have consented or where we are otherwise permitted to do so by the law that applies to you. Every marketing message we send identifies us as the sender, includes contact details that remain valid for at least 30 days, and contains a functional unsubscribe facility that is free to use. We action unsubscribe requests within five business days.
When you send us an enquiry, register your interest or ask for a demonstration, we send you an acknowledgement confirming that we have received it. That acknowledgement is sent whether or not you have asked to receive marketing, because it confirms something you asked us to do. It is not a marketing message, and receiving it does not subscribe you to anything. Promotional messages are sent only to people who have asked for them.
You can withdraw your consent to marketing at any time by using the unsubscribe link in any message or by contacting us at privacy@costrixiq.com. We keep records of the marketing consents we obtain, including the date, the method and the wording of the consent.
8. Who we may share information with
We may disclose personal information where reasonably necessary to:
- technology providers supporting website hosting, infrastructure, security, forms, email, analytics and conversion measurement;
- HubSpot, which supports our CRM, enquiry, subscription and website tracking activities;
- professional advisers, insurers, auditors and contractors who assist our operations;
- a purchaser, investor or adviser involved in a proposed business transaction, subject to appropriate confidentiality controls; and
- regulators, courts, law enforcement agencies or other parties where required or permitted by law.
We do not sell personal information for money. Where we use advertising, retargeting or conversion technologies, the sharing of information with the providers of those technologies may be treated as a "sale" or a "share" under some United States privacy laws — see clause 15.
Other than our hosting platform, which is dealt with below, we require each provider that handles personal information on our behalf to do so only on our documented instructions, to keep it confidential, to protect it with appropriate technical and organisational security measures and to engage sub-processors only on equivalent terms. A current list of our providers is available on request.
Our principal providers and what they do
- Hosting — OpenAI Sites: the website is hosted on OpenAI Sites. Every request to the website necessarily involves your internet protocol address, the time of the request, the page requested and your browser information. The platform also records visitor and page view counts for its own analytics view, outside the choices you make in our cookie banner. OpenAI does not publish the fields it records, the method it uses or how long it keeps them, and has not confirmed them to us. We will update this policy if it does.
- Security — Cloudflare: Cloudflare operates in two places. At the hosting layer it provides bot protection and security challenges for the website itself, which involves your internet protocol address and browser information on every request and is in place before you make any choice in our cookie banner. On our forms it provides the Turnstile check: when you open a page that contains one of our forms, the check loads and Cloudflare receives your internet protocol address, browser information and a security token so that it can confirm the submission is genuine. Cloudflare acts on our behalf when it uses those signals to protect our website, and on its own account when it uses them to improve its bot detection service. It does not receive the content of your form.
- CRM and forms — HubSpot: HubSpot acts on our behalf for the information you submit through a form and for our contact records. If you accept Analytics cookies, its website tracking code also collects website activity, your internet protocol address, timestamps, the pages you view, the elements you click and the size of your screen and browser window, and HubSpot uses some of that information for its own purposes as well as ours. We have turned off Intent data sharing, we do not use HubSpot’s data enrichment products, and we have opted out of our data being used to train HubSpot’s artificial intelligence models.
- Analytics — Google Analytics and Google Tag Manager: if you accept Analytics cookies, Google measures visits, sessions, approximate location, browser and device information and the pages and actions you complete. Our tag management container is currently published empty and deploys no further technology of its own. Google’s own explanation of how it handles information from sites that use its services is at https://policies.google.com/technologies/partner-sites. You can opt out of Google Analytics entirely using the browser add-on at https://tools.google.com/dlpage/gaoptout.
- Advertising — Google Ads: if you accept Advertising cookies, Google receives your internet protocol address, the full page address including any advertising click identifier, browser context and conversion events, and uses them for attribution, audience building and conversion measurement. You can manage Google’s advertising personalisation at https://adssettings.google.com.
- Advertising — LinkedIn Insight Tag: if you accept Advertising cookies, LinkedIn receives the page address, the referring page, your internet protocol address, device and browser characteristics and a timestamp, and uses them for conversion reporting, building advertising audiences and aggregate professional demographic reporting. LinkedIn states that it removes direct identifiers within seven days and deletes the remaining pseudonymised information within 180 days. You can manage LinkedIn’s advertising settings in your LinkedIn account.
Each of these providers operates under its own terms. HubSpot, Google, Cloudflare and LinkedIn each apply published data processing terms to our use of their services. Our hosting platform does not, and we do not currently have a separate data processing agreement with it. Changing a provider is a material change: we will update this policy and, where the purposes or categories change materially, ask for your consent again.
9. Overseas processing and disclosure
Some service providers store, process or access personal information outside Australia. Our principal providers are: OpenAI (hosting of this website) — United States; Cloudflare (bot protection and security challenges at the hosting layer, and the anti-automation check on our forms) — global edge network; HubSpot (customer relationship management, forms, subscriptions and website activity) — hosted in HubSpot’s Australian region, with support and sub-processor access from other locations including the United States; Google (analytics, tag management and advertising measurement) — United States and other locations; and LinkedIn (campaign measurement and audiences) — United States. The countries involved can change as providers update their infrastructure, and we will update this clause when they do.
The CostrixIQ software platform is hosted separately from this website, on Google Cloud Platform — in Sydney for Australian customers, and in London in the United Kingdom for customers established in the European Economic Area or the United Kingdom. Where we host a customer’s data on that platform we do so on that customer’s instructions under its own agreement with us, which sets out the safeguards that apply.
Where Australian privacy law applies to an overseas disclosure, we take reasonable steps appropriate to the circumstances to address how the recipient handles personal information. We review our providers, and the locations in which they process personal information, whenever we change a provider and at least every twelve months, and we update this policy when those locations change.
Where we transfer personal information out of the European Economic Area or the United Kingdom to a country that is not the subject of an adequacy decision, then for each provider with which we have a data processing agreement we rely on the European Commission’s standard contractual clauses (Commission Implementing Decision (EU) 2021/914) or, for transfers from the United Kingdom, on the International Data Transfer Agreement or the International Data Transfer Addendum issued by the Information Commissioner, in each case supported by a documented transfer risk assessment and any additional safeguards it identifies. Australia is not the subject of an adequacy decision by the European Commission or by the United Kingdom Secretary of State. You may request a copy of the safeguards we rely on by contacting us using the details in clause 17.
10. Cookies and similar technologies
We use cookies and similar technologies — including pixels, tags, scripts, software development kits and local storage — to operate the website, remember choices, understand usage and measure enquiries and other conversions. Where consent is required, we obtain it before those technologies are used. More information about these technologies, the specific technologies we use and the choices available to you is set out in our Cookie Policy (https://www.costrixiq.com/cookies). We record the consent you give and keep it until you change or clear it. We do not ask again on a fixed cycle, but we will ask again if the technologies we use change materially.
11. How we protect and retain information
We use administrative, technical and organisational safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. No internet transmission or storage system can be guaranteed to be completely secure.
We retain personal information only for as long as reasonably necessary for the purposes described in this policy and to meet our legal, accounting and recordkeeping obligations. In setting retention periods we consider the amount, nature and sensitivity of the information, the potential risk of harm from unauthorised use or disclosure, the purposes for which we hold it and whether those purposes can be achieved by other means, and any applicable legal requirement. As a guide:
- enquiry and demonstration records: 12 years from our last substantive contact with you;
- marketing subscription and consent records: for as long as you remain subscribed and for 12 years afterwards, so that we can evidence the consent you gave;
- unsubscribe and suppression records: indefinitely, so that we can continue to honour your opt-out;
- website analytics, cookie and conversion data: for the periods stated by each provider below;
- records we are required to keep by law: for the period required by that law.
When information is no longer required, we take reasonable steps to delete or de-identify it, subject to backup, recordkeeping and legal requirements.
Retention operates at several levels, and the expiry date of a cookie is not the same as the period for which a provider keeps the information it collected through it:
- information stored on your device: the periods set out in our Cookie Policy;
- Google Analytics: event level data is retained on our property for 2 months and user level data for 14 months; aggregated reports are not affected by those settings;
- Google advertising logs: Google states that it removes part of the internet protocol address after 9 months and cookie information after 18 months. Those are steps that reduce identifiability rather than deletion of the whole record;
- Google Tag Manager: Google states that standard request logs are deleted within 14 days;
- LinkedIn Insight Tag: direct identifiers removed within 7 days and the remaining pseudonymised information deleted within 180 days; advertising audience membership uses a rolling window of between 30 and 180 days;
- hosting and security logs: our hosting provider does not publish a retention period for the records it keeps about visits to this website and has not confirmed it to us. We will state the period here if it does.
If a data breach occurs that is likely to result in serious harm, we will assess and notify it in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth) and, where the GDPR or the UK GDPR applies, in accordance with Articles 33 and 34 of that regulation.
12. Your rights and choices
You may ask us to give you access to the personal information we hold about you, or to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Where the GDPR or the UK GDPR applies to our processing, you also have the right to: obtain confirmation of, and access to, your personal information; have inaccurate information rectified; have your information erased in the circumstances set out in Article 17; restrict our processing in the circumstances set out in Article 18; object to processing carried out on the basis of our legitimate interests, and to object at any time and without giving reasons to processing for direct marketing; receive the personal information you provided to us in a structured, commonly used and machine-readable format and have it transmitted to another controller where Article 20 applies; withdraw your consent at any time; and lodge a complaint with a supervisory authority.
To make a request, email privacy@costrixiq.com or write to us at the address in clause 17. We may need to verify your identity before acting on a request. There is no fee for making a request. We will respond within one month where the GDPR or the UK GDPR applies and within 30 days where the Privacy Act 1988 (Cth) applies, and we will tell you if we need longer and why. If we refuse a request in whole or in part, we will explain why and tell you how to complain.
13. Privacy complaints
If you have a privacy concern, please contact our Privacy Officer at privacy@costrixiq.com and describe the issue. We will acknowledge your complaint within five business days, investigate it, and aim to give you a substantive response within 30 days. If we need longer, we will tell you why and when you can expect a response.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (GPO Box 5288, Sydney NSW 2001; 1300 363 992; www.oaic.gov.au).
If you are in the European Economic Area, you may lodge a complaint with the supervisory authority in the Member State of your habitual residence, your place of work or the place of the alleged infringement.
If you are in the United Kingdom, you may make a complaint to us under section 164A of the Data Protection Act 2018 and, if you are not satisfied with our response, to the Information Commissioner’s Office (www.ico.org.uk; 0303 123 1113).
14. Children
The CostrixIQ website is intended for business users and is not directed to children. We do not knowingly collect personal information from a person under 18 years of age through the website. Where the GDPR or the UK GDPR applies, we do not knowingly collect personal information from a child who is below the age at which that child can consent to information society services in the relevant jurisdiction. If you believe we hold information about a child, please contact us and we will delete it.
15. Additional information for United States residents
If you are a California resident, the California Consumer Privacy Act may give you the right to know what personal information we collect, use and disclose; to have it deleted or corrected; to opt out of its "sale" or "sharing"; to limit the use of sensitive personal information; and not to be discriminated against for exercising those rights. Those rights apply to individuals acting in a business capacity as well as to consumers.
We do not sell personal information for money. Where you accept advertising cookies, the information shared with our advertising and conversion providers may be treated as a "sale" or a "share" under the California Consumer Privacy Act. You can prevent that by declining the advertising category, and you can change your choice at any time through the cookie settings on the website. The cookie settings are the mechanism we provide for that choice; the website does not currently read browser-level opt-out preference signals. To exercise a right, contact us at privacy@costrixiq.com.
16. Changes to this policy
We may update this policy to reflect changes to CostrixIQ, our providers, our information handling practices or applicable requirements. The latest version will be published on this page with its updated date. Where a change is material, we will take reasonable steps to notify you before it takes effect.
17. Contact
Privacy Officer, Sequoia Advisory Pty Ltd trading as CostrixIQ
ABN 16 662 688 048
ACN 662 688 048
Level 12, 121 Castlereagh Street, Sydney NSW 2000, Australia
privacy@costrixiq.com
