1. Who Mirrory is
Mirrory is a sole-trader studio based in Melbourne, Victoria (ABN 55 276 225 052). This policy explains how Mirrory handles information about website visitors, prospective clients, and clients.
Information handling
Effective date: 12 August 2026
Plain-English information about the data this website and studio actually handle—without treating a project enquiry as a marketing subscription.
Mirrory is a sole-trader studio based in Melbourne, Victoria (ABN 55 276 225 052). This policy explains how Mirrory handles information about website visitors, prospective clients, and clients.
Mirrory respects the privacy of website visitors, prospective clients, and clients and handles personal information in accordance with applicable Australian privacy law. Where a particular activity is not required to comply with the Privacy Act 1988 (Cth), Mirrory aims to use the Australian Privacy Principles as a practical standard for responsible information handling.
Depending on how you interact with Mirrory, this may include:
Please do not send sensitive personal information, customer databases, or live credentials through the general enquiry form. If a project requires sensitive material or account access, Mirrory will agree on a more appropriate transfer method.
Information is collected directly when you submit an enquiry, email or call the studio, accept a proposal, provide project materials, attend a meeting, or work with Mirrory on a project. Limited technical data is also generated when a browser requests pages, fonts, or other website assets from the providers described below.
Mirrory uses information reasonably necessary to:
Mirrory does not sell or rent personal information.
The current public website uses the following providers:
Other providers may be used for a particular client project—such as a domain registrar, hosting platform, CMS, payment service, collaboration tool, or specialist contractor—only where relevant to that engagement. Material project-specific arrangements should be set out in the proposal or discussed with the client.
Mirrory may disclose information to a service provider, adviser, or contractor where reasonably needed for the purposes above; where authorised by the person concerned; or where required or permitted by law. Access should be limited to what the recipient needs for its role.
Netlify, Google, email infrastructure, and future project providers may process or store information outside Australia using infrastructure in locations that can change. Mirrory does not state a fixed country list where the repository and provider configuration do not establish one. Provider privacy terms and the agreed project architecture may give more specific information for a particular service.
The current Mirrory application does not enable Google Analytics or another visitor analytics product, and its application code does not set advertising or marketing cookies. Hosting and security providers may still process standard request data or use strictly operational mechanisms under their own services.
If Mirrory later introduces analytics, advertising technology, or a material new cookie, the implementation, consent approach where required, and this policy should be updated together before or when that change takes effect.
Sending an enquiry does not subscribe you to a marketing list. Mirrory may contact you as reasonably needed to respond to the enquiry, prepare a proposal, perform a project, provide support, or administer the relationship.
Promotional messages are separate and will only be sent where consent or another lawful basis permits. When marketing is sent, it will include a functional way to unsubscribe. Opting out of marketing does not prevent necessary service or project communication.
The current website uses HTTPS in production, a restrictive Content Security Policy, limited form fields, a spam honeypot, and provider access controls. Mirrory aims to limit access to client and enquiry information to people and providers who need it for the relevant purpose.
No internet transmission or storage system is completely secure. If you believe information sent to Mirrory has been compromised, contact the studio promptly and avoid sending further sensitive information through the enquiry form.
Mirrory keeps information only for as long as reasonably needed for the enquiry, project, support relationship, business records, dispute handling, or legal and tax obligations. When information is no longer reasonably needed, Mirrory aims to delete or de-identify it, subject to legal requirements, legitimate recordkeeping needs, provider retention cycles, and backup limitations. Retention can differ by record type and provider.
You may ask what personal information Mirrory holds about you or request correction by using the contact details below. Mirrory may need to verify identity and may decline or limit a request where the law permits or requires, in which case the reason will be explained where appropriate.
Please contact Mirrory first with a privacy question or complaint so the issue can be investigated and addressed. If applicable law gives you a right to take the matter to a regulator, that right remains available. The Office of the Australian Information Commissioner provides information about Australian privacy rights and complaint pathways.
Mirrory may update this policy when practices, providers, or legal requirements change. The current version will be published here with a new effective date. A material change will not be used to rewrite an accepted client agreement retrospectively.
Privacy contact: mirrorystudio@gmail.com
You can also use the contact form.