Privacy Policy
Last updated: 3 July 2026
The short version.
- We collect only what we need to reply, deliver a service, or invoice you.
- We never sell, rent or trade your personal information.
- Your tender documents are never used to train AI models.
- Files sit in Microsoft SharePoint, encrypted, and are deleted 30 days after delivery.
- You can request a copy, correction or deletion at any time via our contact form.
Strategic Sales Support (ABN 58 284 598 677) ("we", "us", "our") is committed to protecting personal information. This policy explains how we collect, use, store, share and delete data. It is aligned to the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, for visitors and clients outside Australia, to the EU General Data Protection Regulation (GDPR), UK GDPR, and the California Consumer Privacy Act (CCPA / CPRA).
1. Who this policy applies to
This policy covers visitors to strategicsalessupport.com and clients who engage us through any channel: the contact form, the Bid/No-Bid Scorecard, the AI Tender Support (Industry Bid Packs) order form, the Sustainability Reporting intake, email, LinkedIn or a booked call.
2. Information we collect and why
2.1 Website visitors (no form submitted)
We do not set analytics, advertising or profiling cookies. Standard server logs (IP address, browser user-agent, requested URL, timestamp) are captured by our hosting provider Netlify for a short retention window (30 days) for security and operational purposes only. This data is not used to identify or profile individuals.
2.2 Contact form submitters
When you complete the website contact form we collect your name, email address, company, phone number (if provided), the message you send, and the timestamp. We use this to respond to your enquiry.
2.3 Bid/No-Bid Scorecard users
When you use the Bid/No-Bid Scorecard we collect your name, email, phone, LinkedIn URL, company name (optional), tender or opportunity name (optional), your answers to the ten scorecard questions and the timestamp. We use this to email you your result and to follow up only if you ask us to.
2.4 AI Tender Support (Industry Bid Pack) order
When you order a bid pack we collect:
- Customer identity: name, email, phone (optional), company.
- Order details: industry, unbranded or branded option, notes.
- Billing details: billing country, tax ID / ABN / VAT (optional), billing address (optional).
- Tender documents: the RFP, addenda, attachments, templates and optional context files (previous winning tenders, capability statement, past-performance write-ups, key personnel CVs) that you place in the shared SharePoint folder created for the order.
Payment card details are handled entirely by Stripe. We do not see, receive or store card numbers.
2.5 Sustainability Reporting intake
When you complete the Sustainability Reporting intake we collect your name, email, company, business size, sector, existing ESG activity and any additional information you volunteer. We use this to prepare an initial conversation.
2.6 Booked calls
If you book a call via Microsoft Bookings we collect your name, email, phone (optional) and the time slot. Booking records are stored inside Microsoft 365.
3. Legal basis (visitors in the EU, UK and EEA)
Our legal bases for processing under GDPR / UK GDPR are:
- Consent — where you voluntarily submit any form on the site.
- Contract — to deliver a service you have ordered (bid pack, engagement).
- Legitimate interests — website security, responding to your enquiries, invoicing, business records.
- Legal obligation — Australian tax records (7 years) and other statutory records.
4. Data processors and sub-processors
We rely on trusted providers to operate the website and deliver services. Each processes personal data only on our instructions and under their own privacy policies:
| Provider | Purpose | Data location |
|---|---|---|
| Netlify | Website hosting; receipt of contact, bid pack and sustainability forms | United States |
| Formspree | Receipt of Bid/No-Bid Scorecard submissions | United States |
| Stripe | Payment processing for bid pack invoices | United States and Australia |
| Anthropic | AI model provider (Claude API) used to draft bid packs | United States |
| Microsoft (365, SharePoint, Bookings, Outlook) | Bid pack file sharing, email, calendar bookings | Australia and international |
| Google Fonts | Web fonts loaded on every page | United States (global CDN) |
| Tailwind Labs (CDN) | CSS framework loaded on every page | Global CDN |
| GoDaddy | Domain registrar and DNS | United States |
| Where you contact us through the LinkedIn platform | United States and international |
5. Cross-border data transfers
Several of the processors above are located outside Australia (primarily the United States and the European Union). By using our website and services you consent to your personal information being transferred to and processed in those jurisdictions. Where our processors handle personal data of EU / UK residents we rely on the recipient's own compliance measures (Standard Contractual Clauses, adequacy findings, or approved binding corporate rules) as appropriate.
6. Cookies and similar technologies
We do not use tracking, advertising or profiling cookies.
- Essential first-party storage: a small localStorage entry may be set to remember that you have dismissed the privacy notice bar. Not shared with anyone.
- Third-party CDN requests: loading Google Fonts and the Tailwind CSS CDN causes your browser to contact those services and disclose your IP address. This is technical/functional in nature and no advertising identifiers are set by us.
- No analytics installed today. If we introduce cookieless analytics (for example Cloudflare Web Analytics or Plausible) in future, this policy will be updated before it is enabled.
7. Data retention
We keep personal information only as long as we need it:
| Data | How long |
|---|---|
| Contact-form enquiries | 24 months from last contact |
| Bid/No-Bid Scorecard submissions | 24 months |
| Bid pack order and billing records | 7 years (Australian tax law) |
| Bid pack tender documents (SharePoint) | Deleted 30 days after pack delivery |
| Bid pack outputs (drafted files) | Deleted 30 days after pack delivery |
| Content sent to Anthropic (Claude API) | Max 30 days on Anthropic's systems; not used for model training |
| Microsoft Bookings history | 24 months |
| Website server logs (Netlify) | 30 days |
8. Your rights
Regardless of jurisdiction, you can ask us to:
- Access — provide a copy of the personal information we hold about you.
- Rectify — correct any information that is inaccurate.
- Erase — delete your personal information ("right to be forgotten").
- Restrict — limit how we use it.
- Portability — receive a machine-readable copy for transfer to another provider.
- Object — object to processing based on legitimate interests.
- Withdraw consent — where consent was the basis, at any time, without affecting the lawfulness of prior processing.
California residents (CCPA / CPRA) additionally have the right to know what categories of personal information we sell (answer: we do not sell any personal information) and to opt out of that non-sale.
To exercise any right, please contact us. We respond within 30 days.
If you are not satisfied you can complain to the relevant regulator:
- Australia: Office of the Australian Information Commissioner (oaic.gov.au).
- European Union: your local Data Protection Authority (list at edpb.europa.eu).
- United Kingdom: the Information Commissioner's Office (ico.org.uk).
- California: the California Attorney General (oag.ca.gov/privacy).
9. AI processing and confidentiality of tender content
Bid pack content is drafted using Anthropic's Claude API. Your tender documents and generated outputs are:
- Never used to train AI models. Anthropic does not train on customer API content.
- Retained by Anthropic for a maximum of 30 days before automatic deletion, per Anthropic's published data-handling policy for API customers.
- Processed in isolated per-order sessions, not commingled with other clients.
We can sign a mutual non-disclosure agreement on request before any tender data is exchanged. Please contact us to arrange one.
10. Security
We take reasonable steps to protect personal information:
- HTTPS / TLS 1.3 encryption in transit across every page and every form submission.
- Encryption at rest on all cloud storage (Microsoft SharePoint, Netlify, Stripe).
- Two-factor authentication on all administrator accounts.
- Access limited to Brent Smith and vetted personnel engaged on a specific order.
- Regular review of processors and their sub-processor lists.
- Virus scanning on files uploaded to Microsoft SharePoint.
No system is perfectly secure. If we become aware of a data breach affecting your personal information we will notify you and (where required) the applicable regulator without undue delay.
11. Children
Our services are for business use and are not directed at anyone under 18. We do not knowingly collect information from children. If you believe a child has provided personal information, please contact us and we will delete it.
12. Changes to this policy
We may update this policy from time to time. The "last updated" date at the top of this page reflects the most recent revision. Where an update materially changes how we use your information, we will notify you (for example by email or a homepage notice) before the change takes effect.
13. Contact
Privacy questions or requests: please use our contact form. We respond within five business days.