Privacy Policy

Last updated 25 August 2026

Zephyr One respects your privacy. This policy explains what personal information we collect, how we handle it, and how you can access it, correct it or complain.

We handle personal information in accordance with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

1. Who we are

Zephyr One (formerly Zephyr Social) is the trading name of Zephyr Empire Pty Ltd (ABN 50 656 314 662), an Australian marketing agency.

We work with businesses on advertising, analytics, search and commercial reporting. We are not a consumer business, so most of the personal information we handle belongs to people we deal with in a business capacity, or to customers of our clients where we act on that client’s instructions.

2. The kinds of personal information we collect and hold

People at our clients and suppliers. Name, business email address, telephone number, job title and employer. We also hold correspondence and meeting records, including notes and transcripts of meetings you attend with us.

People at businesses we approach. Where we contact a business about our services, we hold the name, business email address, job title and employer of the relevant person. We obtain this from business contact databases and publicly available professional sources, not from you directly.

Visitors to our website. Our website uses Google Tag Manager, Google Analytics, the Google tag, and the Meta advertising pixel and Meta’s Conversions API. These record your visit and actions on the site, including where you arrived from, which pages you viewed, your IP address and your device and browser details, and send that information to Google and Meta. Section 5 explains this and how to control it. If you complete an enquiry form we collect the details you provide, which typically include your name, email address, telephone number and company.

Job candidates. We do not operate our own recruitment process and we do not maintain a candidate database. Hiring is handled by third party recruiters, who hold candidate information under their own privacy policies. Where a recruiter provides us with candidate details during a search, we use them only to assess that candidate for that role and do not retain them once the search is complete.

Customers of our clients. When a client engages us to report on their business, we may hold records of their customers’ transactions. We do not hold names, email addresses, telephone numbers or street addresses of those customers. What we hold is a coded reference that we cannot reverse, together with what was purchased, when, for how much, and the country of the order. Only the client can connect that coded reference to a person.

Where a client’s systems do not support an automated connection and the client instructs us in writing, we may handle customer contact lists on their behalf for advertising purposes. In those cases we delete our copy once the task is complete.

We do not seek sensitive information as defined in the Privacy Act, and we ask clients not to provide it. Our services are directed at businesses, not children, and we do not knowingly collect personal information from children.

3. How we collect and hold personal information

We collect information directly from you when you contact us, meet with us, complete a form on our website, engage our services or subscribe to something we send.

We collect information about people at businesses we approach from business contact databases and publicly available professional sources.

We collect information about our clients’ customers from the client’s own systems, through connections the client authorises and can withdraw at any time. Those connections are read only. We cannot change anything in a client’s systems through them.

We hold personal information in access controlled systems. Our reporting platform stores data in a database hosted in Sydney, Australia. Access is limited to authorised personnel, and to each client’s own nominated people for their own data only.

We protect personal information with measures including restricted access, multi-factor authentication, encryption of stored credentials, and separation of each client’s data from every other client’s. We do not describe these measures in detail here, because doing so would weaken them.

We do not keep personal information longer than we need it. Client reporting data is deleted at the end of an engagement plus thirty days, or earlier on request. Enquiry and outreach records are kept while there is an active commercial conversation and for a reasonable period afterwards, then deleted. Records we are required to keep for tax and corporate purposes are kept for seven years.your product, and whether the market wants more of it
your budget, and how long you sustain ityour website, your offer, and how well they convert the traffic we send
how quickly your team makes decisions, approves work and ships creative
the advertising platforms themselves: auction pricing, policy changes, measurement changes and account standing

We influence some of these. We do not control most of them, and no agency does.

4. Why we collect, hold, use and disclose personal information

To provide our services and report to our clients.
To communicate with people at our clients and suppliers about work in progress.
To let businesses know about our services, and to stop when they ask us to.
To operate, measure and improve our website and our own advertising.
To meet our legal, tax and record keeping obligations.

We do not sell personal information. We do not use one client’s customer data to benefit another client. We do not use a client’s customer data to build advertising audiences unless that client has instructed us to in writing.
Reported figures also depend on platform attribution, which is modelled rather than exact, differs between platforms, and will not tie exactly to your own accounts. We report from commercial data where it is available, and we name the source when it is not.

5. Cookies and tracking on our website

Our website uses cookies and similar technologies. There are three kinds.

Necessary. Required for the site to work, to keep it secure and to remember your cookie choices. These are always on.

Analytics. Google Analytics and Google Tag Manager, which tell us how many people visit, which pages they read and where they arrived from, so we can improve the site.

Advertising. The Meta advertising pixel, Meta’s Conversions API and the Google tag, which measure whether our own advertising works and let us show ads to people who have visited the site. Meta and Google handle that information under their own privacy policies and for their own purposes as well as ours.

You can control this in three ways. Use the consent banner shown on your first visit, which loads no analytics or advertising cookies until you accept them and lets you change your mind at any time. Change your browser settings to block or delete cookies, which every major browser allows. Or change your ad and data preferences directly with Meta and Google, using the controls in your account with each of them.

Blocking analytics and advertising cookies will not stop you using the site.

6. Direct marketing and how to opt out

We send marketing communications to people at businesses, about services relevant to their work. We do this in line with the Spam Act 2003 (Cth).

Every marketing email we send carries an unsubscribe link that works. You can also reply and tell us to stop, or email the address in section 12. We action opt outs promptly and permanently, and we keep a suppression record so you are not contacted again by mistake.

Opting out of marketing does not stop operational messages about work we are doing for you.

7. Who we disclose personal information to

We use the following service providers. They act on our instructions, or under their own published terms, and only for the purposes described above.

Email, documents and file storage: Google Workspace (United States)
Website hosting, forms and analytics: Automattic (WordPress), Framer, Gravity Forms, Google, Meta (United States, Netherlands)
Reporting platform hosting: Supabase, database located in Sydney, and Vercel (Australia; provider entities United States)
Artificial intelligence analysis: Anthropic (United States)
Advertising and analytics platforms: Meta, Google, TikTok, LinkedIn, Pinterest (United States)
Client commerce and marketing platforms: Shopify, Klaviyo (United States, Canada)
Business contact data and outreach: Apollo.io, Instantly (United States)
Scheduling: Calendly (United States)
Internal communication and meeting notes: Slack, Granola (United States)
Project management: Productive.io (European Union)
Accounting and invoicing: Xero (Australia, New Zealand)
Recruitment: third party recruiters engaged from time to time (Australia)

We also disclose personal information where you have consented, or where we are required or permitted by law.

If our business is sold or merged, personal information may transfer with it. We would require the buyer to keep handling it under a policy at least as protective as this one, and we would tell you.

On written request, a client may obtain a summary of the material platforms and tools used in their specific engagement.

8. Overseas disclosure

We are likely to disclose personal information to recipients located overseas.

Those recipients are located principally in the United States, and also in Canada, New Zealand, the Netherlands and the European Union, as set out above.

Some providers store data in Australia even though the provider itself is a foreign company. Our reporting database is hosted in Sydney.

Where we use an artificial intelligence service to help draft analysis of a client’s results, we send aggregate figures only. We do not send names, contact details, customer records or coded customer references. Our AI provider’s commercial terms state that customer content is not used to train models.terms and conditions and privacy policy.

9. Data breaches

We have a plan for responding to a data breach, and we test our ability to run it.

If a breach happens that is likely to result in serious harm, we will contain it, assess it, and notify the people affected and the Office of the Australian Information Commissioner, as required by the Notifiable Data Breaches scheme.

Where the breach involves a client’s data, we will notify that client without undue delay so they can meet their own obligations.

10. Accessing and correcting your personal information

You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is wrong.

Contact us using the details below. We will respond within thirty days. We do not charge for making a request.

We may need to verify who you are before we release information.

If we refuse access or correction, we will tell you why in writing and explain how to complain.

If you are a customer of one of our clients, we will not be able to identify you in our records, because we do not hold names or contact details for our clients’ customers. Please contact that business directly. If you tell us which business it is, we will help them respond.

11. Complaints

If you think we have breached the Australian Privacy Principles, tell us. Put your complaint in writing to the contact below.

We will acknowledge your complaint within five business days and respond within thirty days. If we need longer we will tell you why and when to expect an answer.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner.

Website: oaic.gov.au

Telephone: 1300 363 992

Post: GPO Box 5218, Sydney NSW 2001

12. Contact us

Chris Faulkner, Privacy Officer

Zephyr One

Email: chrisf@zephyrone.co

Telephone: +61 416 892 782

Post: 3/75 Pitt Street, Sydney NSW 2000

13. Dealing with us anonymously

Where it is lawful and practicable, you can deal with us without identifying yourself or by using a pseudonym. This will not usually be practicable where we are delivering services to you or your business.

14. Changes to this policy

We review this policy at least annually and whenever our practices change. The current version is always available at zephyrone.co/privacy, and the date it was last updated appears at the top.

Services

Meta Ads

Google Ads

TikTok Ads

Creative

Email & SMS

SEO & AI Search

CRO & Landing Pages

Subscribe

Sharp growth thinking, straight to your inbox.

Certified partners
klaviyo

© 2026 Zephyr Empire Pty Ltd trading as Zephyr One (formerly Zephyr Social). ABN 50 656 314 662.

Level 3, 75 Pitt St, Sydney NSW 2000, Australia