Privacy
Privacy Policy
Last updated:
This policy covers personal data we collect through wildbunchmedia.com, in particular the Free Visual Audit.
Who we are
The Trustee for Wild Bunch Media (ABN 70 845 250 238), trading as Wild Bunch Media (“we”, “us”), is the data controller for the personal data described in this policy.
Postal address: c/o Thyme Tax, 35 Ramsey Rd, Southside QLD 4570, Australia.
Email: [email protected]
No GST or VAT number is shown: the entity is not currently registered for GST.
What we collect, and why
When you request a Free Visual Audit:
| Data | Why | Legal basis |
|---|---|---|
| Your email address | To send you the audit you requested | Performance of a service you asked for (Art. 6(1)(b) GDPR) |
| The URL you submitted | To produce the audit | Same |
| What you told us you want it to achieve | To judge the asset against its intended purpose | Same |
| The audit we produced | So we can re-send it and improve the service | Legitimate interests (Art. 6(1)(f)) — improving a service we offer |
| Date and time of the request | Record-keeping and retention management | Legitimate interests |
If you tick the marketing box:
| Data | Why | Legal basis |
|---|---|---|
| Your consent status and the time you gave it | To send occasional ideas about video and visual work, and to prove consent was given | Consent (Art. 6(1)(a)) |
Requesting an audit does not subscribe you to marketing. These are deliberately separate. If you do not tick the box, you receive your audit and nothing else.
We do not collect special category data. We do not ask for your name, phone number, company or job title. We do not use tracking cookies or advertising pixels.
We do measure how the site itself is used — page views, roughly where in the world a visit came from, which page referred it, and how quickly pages loaded. This runs through Cloudflare Web Analytics, which is cookieless: it sets nothing on your device, does not follow you between sites, and does not build a profile of you. That is why this site has no cookie banner.
Who processes it
We use three processors, all under data processing agreements:
- Cloudflare, Inc. — hosting, storage of audit records and reports, and opening the web page you submit in a browser so we can see it the way a visitor would. Cloudflare’s network is global; see “International transfers” below.
- Resend (Plus Five Five, Inc.) — sending the audit email. Configured to send from the EU region.
- Google — analysing the page or video you submit. For a video, we send Google the URL so its Gemini service can watch it. For a web page, we open the page in a browser, photograph it, and send Google that picture together with the page’s text and the URL. Only publicly available content is involved. We do not send Google your email address, and it plays no part in delivering the audit to you.
They process this data only on our instructions.
International transfers
All three processors are US-incorporated. Resend is configured to send from its EU region, so audit emails are processed inside the European Economic Area.
Cloudflare’s network is global by design. Audit reports are held in a distributed store that replicates across Cloudflare locations worldwide, and the contact database is hosted in a Cloudflare region we have not restricted to the EEA. So some of this data is processed outside Europe. We would rather say so plainly than claim European-only processing that we cannot stand behind.
The analysis step is the same. What we send Google — the URL, and for a web page a picture of it and its text — may be processed outside the EEA. Only that URL and the publicly available content it points to are involved — never your email address.
Those transfers rely on the European Commission’s Standard Contractual Clauses, which form part of Cloudflare’s data processing addendum, and, where applicable, the EU–US Data Privacy Framework.
How long we keep it
Audit reports are deleted automatically 90 days after they are created. The private link stops working at that point.
Your contact record — email, the URL you audited and the date — is kept while it may still be commercially relevant, and reviewed periodically. Our current policy is to delete or anonymise records that have been inactive for 12–24 months. This retention period is provisional and under review.
Marketing consent records are kept for as long as you remain subscribed, and for a reasonable period afterwards as evidence that consent was properly obtained and withdrawn.
Your rights
Under the GDPR you have the right to:
- access the personal data we hold about you
- rectify it if it is wrong
- erase it (“right to be forgotten”)
- restrict or object to our processing
- data portability — receive your data in a usable format
- withdraw consent at any time, where processing is based on consent
Withdrawing consent does not affect processing carried out before you withdrew it.
How to exercise them
Email [email protected]. We handle these requests manually and will respond within 30 days. Say what you would like us to do and we will confirm in writing when it is done.
Every marketing email also carries a one-click unsubscribe link. Unsubscribing stops marketing immediately and requires no explanation.
Complaints
If you believe we have handled your data improperly you may complain to the data protection supervisory authority in the country where you live or work. If you are in the EU or EEA, a list is maintained by the European Data Protection Board (edpb.europa.eu). In Australia, the relevant body is the Office of the Australian Information Commissioner (oaic.gov.au).
Audit reports are private
Individual audit reports are never indexed by search engines, never linked publicly, and never shared with anyone other than the person who requested them. Each has an unguessable address and expires after 90 days.
Changes
If this policy changes materially we will update the date above. For changes affecting how we use data you have already given us, we will contact you.