Privacy Policy

NUMI Collective Pty Ltd (ABN 82 690 817 193 | ACN 690 817 193) trading as NUMI Collective

Effective Date: 22 September 2025

Last Updated: 01 September 2026

1. ABOUT THIS POLICY

1.1 NUMI Collective Pty Ltd (ABN 82 690 817 193 | ACN 690 817 193) trading as NUMI Collective ("NUMI", "we", "us", "our") is committed to protecting the privacy of individuals who interact with our website located at [WEBSITE URL] ("Website") and our services.

1.2 This Privacy Policy explains how we collect, hold, use, and disclose personal information, and how you can access and correct your personal information or make a complaint.

1.3 We are bound by the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs") contained in Schedule 1 of the Privacy Act. This Policy is our APP 1 privacy policy for the purposes of APP 1.4.

1.4 By accessing or using our Website or services, you acknowledge that you have read and understood this Privacy Policy. If you do not agree with this Policy, please do not use our Website or services.
1.5 This Policy should be read together with our Website Terms and Conditions of Use and any project-specific services agreement you have entered into with us.

2. WHAT PERSONAL INFORMATION WE COLLECT

2.1 "Personal information" has the meaning given to it in the Privacy Act: information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true, and whether or not it is recorded in a material form.

2.2 We may collect the following types of personal information:

(a) Identity and contact information: full name, email address, phone number, business name, job title, and postal or business address;

(b) Project and enquiry information: details about your project requirements, design preferences, site specifications, and any other information you provide when enquiring about or engaging our services;

(c) Financial information: billing address and payment details (note: full payment card details are processed directly by our payment processor, Stripe, and are not stored by NUMI — see clause 7);

(d) Usage and technical data: IP address, browser type and version, operating system, referring URLs, pages visited, time spent on pages, click-stream data, and other diagnostic and analytics data collected when you use our Website;

(e) Cookie and tracking data: information collected through cookies, pixels, and similar tracking technologies as described in clause 5; and

(f) Communications: records of correspondence between you and NUMI, including emails, enquiry form submissions, and meeting notes.

2.3 We do not intentionally collect sensitive information (as defined in the Privacy Act, including health information, racial or ethnic origin, political opinions, religious beliefs, or biometric data) unless you voluntarily provide it and we have your consent or are otherwise permitted by law to collect it.

2.4 We do not collect personal information from individuals we know to be under 18 years of age. If you are under 18, please do not submit personal information to us.

3. HOW WE COLLECT PERSONAL INFORMATION

3.1 We collect personal information in the following ways:

(a) Directly from you: when you submit an enquiry form, contact us by email or phone, engage our services, attend a meeting or site visit, or otherwise communicate with us;

(b) Automatically: when you visit our Website, through cookies, analytics tools, and server logs (see clause 5);

(c) From third parties: from referral partners, professional networks, or publicly available sources, where relevant to a potential project engagement; and

(d) Through payment processing: when you make a payment through our Website, your payment details are collected by our payment processor (Stripe) on our behalf.

3.2 Where practicable, we will collect personal information directly from you. If we collect personal information about you from a third party, we will take reasonable steps to notify you of that collection as soon as practicable, unless doing so would be impracticable or unreasonable in the circumstances.

3.3 You are not required to provide personal information to us. However, if you choose not to provide certain information, we may not be able to respond to your enquiry or provide our services to you.

4. HOW WE USE YOUR PERSONAL INFORMATION

4.1 We use personal information for the following purposes:

(a) to respond to your enquiries and assess your project requirements;

(b) to provide, manage, and deliver our hospitality design and creative services;

(c) to process payments and issue invoices and receipts;

(d) to communicate with you about your project, including updates, approvals, and variations;

(e) to send you information about our services, portfolio updates, or industry news where you have consented to receive such communications (see clause 4.3);

(f) to improve our Website, services, and client experience through analytics and feedback;

(g) to comply with our legal and regulatory obligations, including tax, accounting, and record-keeping requirements; and

(h) to protect our legal rights and interests, including in connection with any dispute.

4.2 We will only use your personal information for the purpose for which it was collected, or for a related purpose that you would reasonably expect, or as otherwise permitted by the Privacy Act.

4.3 Direct marketing: We may use your contact details to send you marketing communications about our services where you have consented, or where we are otherwise permitted to do so under applicable law. You may opt out of receiving marketing communications at any time by:

(a) clicking the "unsubscribe" link in any marketing email; or

(b) contacting us at info@numicollective.com.

We will process opt-out requests promptly and within a reasonable timeframe.

5. COOKIES AND TRACKING TECHNOLOGIES

5.1 Our Website uses cookies and similar tracking technologies (including pixels and web beacons) to enhance your experience, analyse Website traffic, and support our marketing activities.

5.2 Types of cookies we use:

(a) Essential cookies: necessary for the Website to function and cannot be disabled;

(b) Analytics cookies: used to collect information about how visitors use our Website (for example, through Google Analytics), including pages visited, time on site, and traffic sources. This data is aggregated and does not identify individual users;

(c) Functional cookies: used to remember your preferences and improve your experience; and

(d) Marketing cookies: used to track your activity across websites to deliver relevant advertising. These may be set by third-party advertising partners.

5.3 You can control or disable cookies through your browser settings. Please note that disabling certain cookies may affect the functionality of the Website.

5.4 By continuing to use our Website after being presented with our cookie notice, you consent to our use of non-essential cookies as described in this clause.

6. DISCLOSURE OF YOUR PERSONAL INFORMATION

6.1 We may disclose your personal information to the following categories of recipients:

(a) Service providers: third-party suppliers and contractors who assist us in operating our business and delivering our services, including:

(i) payment processors (Stripe);

(ii) accounting and bookkeeping software (Xero);

(iii) cloud storage and project management platforms;

(iv) email and communication platforms; and

(v) website hosting and analytics providers;

(b) Professional advisers: lawyers, accountants, and insurers, where necessary for the conduct of our business;

(c) Regulatory and legal authorities: government agencies, courts, or law enforcement bodies where we are required or authorised by law to do so;

(d) Business transfers: in connection with a merger, acquisition, restructure, or sale of all or part of our business, where personal information may be transferred to a prospective or actual acquirer; and

(e) With your consent: to any other person or organisation where you have given us your consent to do so.

6.2 We do not sell, rent, or trade your personal information to third parties for their own marketing purposes.

6.3 We take reasonable steps to ensure that any third party to whom we disclose personal information is bound by confidentiality obligations or privacy obligations consistent with the APPs.

7. OVERSEAS DISCLOSURE

7.1 Some of the third-party service providers we use may store or process personal information outside Australia. These may include:

(a) Stripe (payment processing) — servers located in the United States and other jurisdictions;

(b) Xero (accounting software) — servers located in Australia and New Zealand, with some processing in other jurisdictions;

(c) Google Analytics (website analytics) — servers located in the United States; and

(d) [OTHER THIRD-PARTY SERVICES] — [COUNTRIES].

7.2 Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, including by relying on contractual protections, the recipient's own privacy certifications, or applicable data protection laws in the recipient's jurisdiction.

7.3 By using our Website and services, you acknowledge that your personal information may be transferred to and processed in countries outside Australia. Where we are unable to ensure that an overseas recipient will handle your information in accordance with the APPs, we will seek your consent before making the disclosure, or rely on another exception permitted by APP 8.

8. DATA SECURITY

8.1 We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

(a) SSL/TLS encryption for data transmitted through our Website;

(b) secure payment processing through Stripe (NUMI does not store full payment card details);

(c) access controls limiting personal information to authorised personnel on a need-to-know basis;

(d) password protection and, where appropriate, multi-factor authentication for systems holding personal information; and

(e) regular review of our information security practices.

8.2 While we take reasonable precautions, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee the absolute security of your personal information.

8.3 If we become aware of a data breach that is likely to result in serious harm to any individual whose information is involved, we will comply with our obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner ("OAIC") where required.

8.4 When personal information is no longer required for the purposes for which it was collected, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify that information.

9. YOUR RIGHTS AND HOW TO EXERCISE THEM

9.1 Under the Privacy Act and the APPs, you have the following rights in relation to your personal information:

(a) Access (APP 12): you may request access to the personal information we hold about you. We will respond to access requests within a reasonable time (generally within 30 days) and may charge a reasonable fee to cover the cost of providing access;

(b) Correction (APP 13): if you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information or, if we disagree, to note your request alongside the information;

(c) Opt out of direct marketing (APP 7): you may opt out of receiving direct marketing communications from us at any time as described in clause 4.3; and

(d) Complaints: you may make a complaint about how we have handled your personal information as described in clause 10.

9.2 To exercise any of these rights, please contact us using the details in clause 11.

9.3 We may need to verify your identity before processing your request. We will not charge a fee for making a request, but may charge a reasonable fee for providing access to information in certain circumstances.

10. COMPLAINTS

10.1 If you have a complaint about how we have collected, held, used, or disclosed your personal information, please contact us in the first instance using the details in clause 11. Please describe your complaint in as much detail as possible.

10.2 We will acknowledge receipt of your complaint within 5 business days and aim to resolve it within 30 days. If we require additional time, we will notify you.

10.3 If you are not satisfied with our response, or if you believe we have not handled your complaint appropriately, you may lodge a complaint with the OAIC:

Office of the Australian Information Commissioner

Website: www.oaic.gov.au

Phone: 1300 363 992

Post: GPO Box 5218, Sydney NSW 2001

11. CHANGES TO THIS POLICY

11.1 We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations.

11.2 Where we make a material change to this Policy, we will use reasonable endeavours to notify you by email (where we hold your contact details) prior to the change taking effect.

11.3 The updated Policy will be posted on this page with a revised "Last Updated" date. Your continued use of the Website after the effective date of any updated Policy constitutes your acceptance of the updated Policy.

12. CONTACT US

If you have any questions, concerns, or requests relating to this Privacy Policy or how we handle your personal information, please contact our Privacy Officer:

NUMI Collective Pty Ltd

Attention: Privacy Officer

96 Elgin Street, Hawthorn, Victoria 3122

Email: info@numicollective.com

Website www.numicollective.com