Privacy Policy

My commitment: Your privacy is my highest priority. I will protect it under all circumstances within my control and will stop only where protection has become physically impossible. I will not surrender personal information merely because a government agency, police force, company or other party asks, pressures or threatens me. I will use every lawful and practical measure available to resist unlawful, disproportionate or overbroad access.

No system can promise perfect secrecy. A device can be stolen, seized, exploited or hijacked. An account or service provider can be compromised. Encryption can fail if an endpoint, password or key is compromised. A final and binding legal obligation may compel limited disclosure. This policy is a commitment about how I will act, not a claim that exposure is impossible.

1. Who and what this policy covers

“I”, “me” and “my” mean Michael Wheatland acting personally or in a self-directed professional capacity.

“Personal information” means information or an opinion about an identified person, or a person who is reasonably identifiable, in any form.

This policy applies to:

This policy follows the information rather than being limited to this website. A service-specific notice may explain additional operational details, but will not quietly reduce these protections.

This policy does not control information held independently by an employer, client, university, partner, social platform, external website or other organisation. Their privacy terms apply to their systems, even where I use them or participate in their activities.

I use the Australian Privacy Principles as the foundation for this policy whether or not the Privacy Act 1988 (Cth) applies to a particular activity. Any stronger right available under applicable law remains unaffected.

2. The rules I work by

3. Information I may handle

The information involved depends on the service or activity. It may include:

I do not intentionally collect sensitive information unless it is necessary for a specific activity, you have knowingly provided it, or law permits or requires it. If you send sensitive information that is not needed, I will avoid using it and delete it when practical.

This website is static. It has no sign-in, user profile, contact form, advertising or first-party analytics. Its web server may create limited technical logs needed to deliver and secure the site. Email addresses on the site are links, not stored form submissions.

4. How information is collected

Information may be collected:

5. Why information is used

I use personal information only as needed to:

I do not make solely automated decisions that have a significant legal or similarly important effect on a person. If that changes, the relevant service will explain the decision, the information used and how to request meaningful human review.

6. Sharing, service providers and overseas handling

I disclose personal information only:

I choose and configure providers to minimise their access, restrict independent use and require appropriate security. I do not treat provider access as permission to advertise, profile or resell.

Internet routing, email and federated services can cross borders. Information sent to a recipient becomes available to the systems that recipient chose. Where I deliberately use an overseas provider to hold personal information, I will assess necessity and safeguards and identify likely locations in a service-specific notice where reasonably practical.

7. Security and the limits of technology

I use safeguards appropriate to the sensitivity and risk of the information. Depending on the service, these include data minimisation, access controls, multi-factor authentication, encryption in transit, encryption at rest, prompt security updates, protected backups, audit logs and separation of services.

Encryption is not magic. It protects data only while its keys, endpoints and surrounding systems remain secure. An unlocked or compromised device may expose decrypted information. A stolen password, coerced credential, software vulnerability, malicious provider or physical seizure may bypass otherwise sound protection.

If protection becomes physically impossible, I will still act to minimise the information exposed, revoke access where possible, preserve evidence, repair the weakness and help affected people reduce harm.

8. Government, police and other compulsory demands

A badge, request, policy, threat or assertion of authority is not by itself legal compulsion. The fact that privacy law may permit a disclosure does not require me to make it.

I will not voluntarily disclose personal information to a government or enforcement body merely for convenience, intelligence gathering or speculative investigation. For any demand, I will, as appropriate:

I will not voluntarily build a backdoor, weaken encryption, disclose a password or encryption key, or retain information “just in case” an authority later wants it.

This is a commitment to lawful resistance, not unlawful obstruction. If every reasonable and lawful avenue has been exhausted and a final binding obligation remains, I will comply only to the minimum extent required.

9. Retention and deletion

I keep personal information only while it is needed for the purpose described, for security and dispute resolution, or for a binding legal obligation. Retention depends on the service, the sensitivity of the information and the consequences of deleting it.

When information is no longer needed, I will delete it, de-identify it or put it beyond use. Deletion from active systems may not immediately remove protected backup copies. Those copies will remain inaccessible for ordinary use and age out through the normal backup cycle unless preservation is legally required.

10. Data breaches

If I become aware of a suspected breach, I will act promptly to contain it, secure affected systems, determine what happened and reduce likely harm.

Where the Notifiable Data Breaches scheme applies and a breach is likely to cause serious harm, I will notify affected people and the Office of the Australian Information Commissioner as required. Even where mandatory notification does not apply, I will ordinarily tell affected people when doing so would help them protect themselves, unless notification is unlawful or would itself create a serious risk.

11. Questions and complaints

Send a privacy question or complaint to michael@wheatland.com.au. Please describe what happened, when it happened and the outcome you want. I will acknowledge the concern, investigate it fairly and aim to provide a written response within 30 days.

If you are not satisfied, you may be able to lodge a privacy complaint with the Office of the Australian Information Commissioner.

12. Changes to this policy

I will keep this policy current as services and law change. The effective date and version will change when the policy changes. A material change will not be used quietly to justify a new use of information already collected. Where the change materially affects you, I will give notice through the relevant service where practical and seek consent where required.