Privacy Policy
- Effective date: 15 August 2026
- Version: 1.0
- Contact: michael@wheatland.com.au
My commitment: Your privacy is my highest priority. I will protect it under all circumstances within my control and will stop only where protection has become physically impossible. I will not surrender personal information merely because a government agency, police force, company or other party asks, pressures or threatens me. I will use every lawful and practical measure available to resist unlawful, disproportionate or overbroad access.
No system can promise perfect secrecy. A device can be stolen, seized, exploited or hijacked. An account or service provider can be compromised. Encryption can fail if an endpoint, password or key is compromised. A final and binding legal obligation may compel limited disclosure. This policy is a commitment about how I will act, not a claim that exposure is impossible.
1. Who and what this policy covers
“I”, “me” and “my” mean Michael Wheatland acting personally or in a self-directed professional capacity.
“Personal information” means information or an opinion about an identified person, or a person who is reasonably identifiable, in any form.
This policy applies to:
- any website, domain, online service, account, project or activity I operate or control that links to this page
- direct communications with me, including email and messaging
- personal information I control while undertaking professional, technical, community or other online activities in my own capacity.
This policy follows the information rather than being limited to this website. A service-specific notice may explain additional operational details, but will not quietly reduce these protections.
This policy does not control information held independently by an employer, client, university, partner, social platform, external website or other organisation. Their privacy terms apply to their systems, even where I use them or participate in their activities.
I use the Australian Privacy Principles as the foundation for this policy whether or not the Privacy Act 1988 (Cth) applies to a particular activity. Any stronger right available under applicable law remains unaffected.
2. The rules I work by
- Collect less. I will not collect information merely because it may become useful.
- Use it only for its stated purpose. A new purpose requires a proper legal basis and, where appropriate, your informed consent.
- Allow anonymity. You may use a pseudonym or remain anonymous where identification is not legally required and the activity can work without it.
- Do not monetise people. I do not sell, rent, trade or broker personal information.
- No surveillance advertising. I do not build behavioural profiles or share information with advertising networks.
- Protect first. Privacy and security are design requirements, not settings added later.
- Delete what is no longer needed. Information that has served its purpose should not become permanent inventory.
3. Information I may handle
The information involved depends on the service or activity. It may include:
- your name, pseudonym, email address and other contact details you choose to provide
- account identifiers, authentication records and service preferences
- messages, files, submissions and other content you send or store
- enquiries, support history, project records and records of consent
- transaction or billing records where an activity involves payment
- technical and security data such as IP address, timestamp, requested address, protocol information, user agent, failed sign-in events and diagnostic logs
- public professional information where it is directly relevant to a genuine interaction.
I do not intentionally collect sensitive information unless it is necessary for a specific activity, you have knowingly provided it, or law permits or requires it. If you send sensitive information that is not needed, I will avoid using it and delete it when practical.
This website is static. It has no sign-in, user profile, contact form, advertising or first-party analytics. Its web server may create limited technical logs needed to deliver and secure the site. Email addresses on the site are links, not stored form submissions.
4. How information is collected
Information may be collected:
- directly from you when you communicate, register, create an account or use a service
- automatically where a server must process connection, delivery or security data
- from another person where they include you in a legitimate communication or activity
- from a public source where doing so is relevant, proportionate and reasonably expected.
5. Why information is used
I use personal information only as needed to:
- provide, maintain and secure the service or activity you chose
- communicate with you and respond to requests
- authenticate access, diagnose faults and prevent abuse
- keep necessary administrative, transaction and consent records
- meet a binding legal obligation or protect someone from a serious and immediate threat
- support a purpose for the common good, including research, education, open knowledge or community work, where you requested or authorised that use, or where it is otherwise lawful and reasonably expected
- perform another purpose you specifically requested or authorised.
I do not make solely automated decisions that have a significant legal or similarly important effect on a person. If that changes, the relevant service will explain the decision, the information used and how to request meaningful human review.
6. Sharing, service providers and overseas handling
I disclose personal information only:
- to a provider needed to operate a service, limited to what that provider needs
- to a recipient you selected or clearly expected
- with your informed consent
- to address a serious and immediate threat where disclosure is necessary and permitted
- where a final, valid and binding law or court order requires it.
I choose and configure providers to minimise their access, restrict independent use and require appropriate security. I do not treat provider access as permission to advertise, profile or resell.
Internet routing, email and federated services can cross borders. Information sent to a recipient becomes available to the systems that recipient chose. Where I deliberately use an overseas provider to hold personal information, I will assess necessity and safeguards and identify likely locations in a service-specific notice where reasonably practical.
7. Security and the limits of technology
I use safeguards appropriate to the sensitivity and risk of the information. Depending on the service, these include data minimisation, access controls, multi-factor authentication, encryption in transit, encryption at rest, prompt security updates, protected backups, audit logs and separation of services.
Encryption is not magic. It protects data only while its keys, endpoints and surrounding systems remain secure. An unlocked or compromised device may expose decrypted information. A stolen password, coerced credential, software vulnerability, malicious provider or physical seizure may bypass otherwise sound protection.
If protection becomes physically impossible, I will still act to minimise the information exposed, revoke access where possible, preserve evidence, repair the weakness and help affected people reduce harm.
8. Government, police and other compulsory demands
A badge, request, policy, threat or assertion of authority is not by itself legal compulsion. The fact that privacy law may permit a disclosure does not require me to make it.
I will not voluntarily disclose personal information to a government or enforcement body merely for convenience, intelligence gathering or speculative investigation. For any demand, I will, as appropriate:
- require it in writing and require the requesting body to identify its authority, jurisdiction and scope
- verify its validity and seek independent legal advice
- reject informal requests and requests without adequate authority
- challenge, appeal, narrow or seek a stay of a demand I reasonably believe is unlawful, disproportionate or overbroad
- notify the affected person before disclosure unless notification is prohibited or would create a serious and immediate risk
- disclose only the minimum information finally required
- disclose every demand to the affected person and publicly wherever legally possible. If law prohibits disclosure, take every lawful action available to challenge, narrow or overturn that prohibition and disclose the demand as soon as it is lifted, especially where secrecy could curtail free speech.
I will not voluntarily build a backdoor, weaken encryption, disclose a password or encryption key, or retain information “just in case” an authority later wants it.
This is a commitment to lawful resistance, not unlawful obstruction. If every reasonable and lawful avenue has been exhausted and a final binding obligation remains, I will comply only to the minimum extent required.
9. Retention and deletion
I keep personal information only while it is needed for the purpose described, for security and dispute resolution, or for a binding legal obligation. Retention depends on the service, the sensitivity of the information and the consequences of deleting it.
When information is no longer needed, I will delete it, de-identify it or put it beyond use. Deletion from active systems may not immediately remove protected backup copies. Those copies will remain inaccessible for ordinary use and age out through the normal backup cycle unless preservation is legally required.
10. Data breaches
If I become aware of a suspected breach, I will act promptly to contain it, secure affected systems, determine what happened and reduce likely harm.
Where the Notifiable Data Breaches scheme applies and a breach is likely to cause serious harm, I will notify affected people and the Office of the Australian Information Commissioner as required. Even where mandatory notification does not apply, I will ordinarily tell affected people when doing so would help them protect themselves, unless notification is unlawful or would itself create a serious risk.
11. Questions and complaints
Send a privacy question or complaint to michael@wheatland.com.au. Please describe what happened, when it happened and the outcome you want. I will acknowledge the concern, investigate it fairly and aim to provide a written response within 30 days.
If you are not satisfied, you may be able to lodge a privacy complaint with the Office of the Australian Information Commissioner.
12. Changes to this policy
I will keep this policy current as services and law change. The effective date and version will change when the policy changes. A material change will not be used quietly to justify a new use of information already collected. Where the change materially affects you, I will give notice through the relevant service where practical and seek consent where required.