Privacy
Privacy and how we handle your data
Two separate things are covered here: what this website collects about you, and what would happen to a customer mailing list if you sent us one. The second matters far more.
Last updated 23 August 2026.
What this website collects
We record page views and interactions — which pages were visited, which calculator settings were used, where the visit came from — using our own first-party measurement rather than sending it all to a third party. A random identifier is stored in your browser to distinguish one visit from another. It is not linked to your name and it cannot be used to identify you.
We do not store your IP address. Where an address is needed to stop abuse of the enquiry form, it is salted and hashed immediately and only the hash is kept, in a table that is pruned regularly.
If Google Analytics is enabled on this site, it operates with IP anonymisation and is subject to Google’s own terms. You can block it with any standard content blocker and the site will work exactly the same.
What the enquiry form collects
The details you type, plus the campaign parameters you configured in the calculator, plus how you arrived at the site (referrer, UTM parameters, landing page and device type). We keep the attribution because it tells us which of our own pages are worth writing more of.
It is used to answer your enquiry and to understand demand for the service. It is not sold, not shared with third parties for their own marketing, and not added to any mailing list without you asking.
If you send us a customer list
This is the part worth reading carefully.
- Purpose limitation. Your list is used to produce and address your mail, and for nothing else. It is never merged with another client’s data, never used to build our own list, never enriched against external sources and never sold.
- Access. Only people working on your job can see it.
- Retention. Held while the campaign is in production and for a reasonable period afterwards so we can reprint or reconcile. Returned or securely destroyed on request, with written confirmation.
- Transfer. Send it by a method you are comfortable with. If your organisation requires a specific secure transfer mechanism, tell us at quote stage.
- Health and sensitive information. Please do not send it. A recall letter needs a name and an address, not a diagnosis. More on healthcare mail.
What we do not claim
We do not hold ISO 27001, SOC 2 or any equivalent certification, and nothing on this site should be read as implying otherwise. If your procurement process requires a certified data processor, we do not currently meet that bar, and we would rather you knew in the first conversation.
Your obligations as the sender
When you send us a list, you remain the entity responsible for that personal information under the Privacy Act 1988 (Cth). You are confirming that you collected it lawfully, that using it for this mailing is consistent with what people were told, and that anyone who has opted out has been removed. What the Australian rules require.
Your rights
You can ask what we hold about you, ask for it to be corrected, or ask for it to be deleted. Email hello@autopenaustralia.com and we will action it. If you are unhappy with how we handle a privacy matter you can complain to the Office of the Australian Information Commissioner.
Cookies and storage
This site uses browser storage for a random visitor identifier, a session identifier and the campaign parameters you set in the calculator, so the enquiry form can be pre-filled. Clearing your browser storage removes all of it. Nothing here is used for advertising or cross-site tracking.
Keep reading
About
Who we are, what we will and will not claim yet, how we handle your customer data, and what y…
Contact
Send us the shape of your campaign — volume, length, envelopes, timing — and we will come bac…
Australian rules
Privacy Act obligations, the Spam Act boundary, the ADMA code and the Do Not Mail service — w…