Privacy Policy

Last updated: 27 August 2026

Nephology (ABN 25951397965) (“Nephology”, “we”, “us”, “our”) is committed to protecting the privacy and personal information of our clients, website visitors, and other individuals we interact with. This Privacy Policy explains how we collect, use, store, disclose, and protect personal information in accordance with applicable privacy laws across the jurisdictions in which we operate.

This Policy applies to all personal information we hold about individuals in connection with our AWS consulting services, website at https://nephology.net.au, and any other interactions with Nephology.


1. Applicable Laws

We operate internationally and comply with privacy and data protection laws across multiple jurisdictions, including:

  • Australia: Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs)
  • United Kingdom: UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018
  • European Union: Regulation (EU) 2016/679 (GDPR) — applicable to individuals in France, Germany, Italy, and other EU member states
  • United States: Applicable federal and state laws, including (where relevant) the California Consumer Privacy Act (CCPA) / California Privacy Rights Act (CPRA), the Children’s Online Privacy Protection Act (COPPA), and sector-specific laws
  • Canada: Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation

Where there is a conflict between the requirements of different laws, we apply the more protective standard.


2. Who We Are and How to Contact Us

Data Controller / Privacy Contact:

Nephology Email: info@nephology.net.au
Website: https://nephology.net.au

For privacy inquiries, requests to exercise your rights, or complaints, please contact us at the email address above with the subject line “Privacy Enquiry”.

UK Representative: Where required under UK GDPR, we will appoint and maintain a UK representative. Details will be provided upon request.

EU Representative: Where required under EU GDPR Article 27, we will appoint and maintain an EU representative. Details will be provided upon request.


3. Personal Information We Collect

We may collect and hold the following categories of personal information:

Identity and contact information

  • Name, job title, and employer organisation
  • Email address, phone number, and postal address
  • LinkedIn profile and other professional contact details

Engagement and service information

  • Details of enquiries, meeting bookings (via Calendly), and communications
  • Information you provide in the course of engaging our consulting services
  • Project-related information, including technical and business context you share with us

Technical and website information

  • IP address, browser type, device information, and operating system
  • Pages visited, referral URLs, and time spent on our website
  • Cookies and similar tracking technologies (see Section 10)

Financial information

  • Billing contact details and invoice information (we do not store payment card details directly)

We collect only the minimum personal information necessary for the stated purpose. We do not knowingly collect personal information from individuals under 16 years of age. If you believe a minor has provided us with personal information, please contact us immediately.


4. How We Collect Personal Information

We collect personal information:

  • Directly from you when you contact us by email, LinkedIn, or Calendly booking
  • When you visit our website and interact with it
  • In the course of providing consulting services to your organisation
  • From publicly available professional sources (e.g., LinkedIn, company websites)

5.1 Purposes

We use personal information for the following purposes:

  • Responding to enquiries and providing information about our services
  • Delivering AWS consulting, advisory, and related professional services
  • Managing our client and business relationships
  • Processing bookings and scheduling meetings
  • Sending relevant professional communications and service updates
  • Compliance with legal obligations
  • Improving our website and understanding how it is used
  • Pursuing or defending legal claims

For individuals in the EU (including France, Germany, and Italy) and the United Kingdom, we process personal information on the following legal bases:

Purpose Legal Basis
Responding to enquiries and providing services Performance of a contract (Art. 6(1)(b)) or pre-contractual steps
Sending professional communications you have requested Consent (Art. 6(1)(a)) or Legitimate Interests (Art. 6(1)(f))
Legal compliance Legal obligation (Art. 6(1)(c))
Improving our services and website analytics Legitimate interests (Art. 6(1)(f))
Pursuing or defending legal claims Legitimate interests (Art. 6(1)(f))

Where we rely on legitimate interests, we balance these against your rights and interests. You may request information about this balancing assessment by contacting us.

Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.

5.3 Australian Privacy Principles

For individuals in Australia, we handle personal information in accordance with the APPs under the Privacy Act 1988 (Cth). We collect, use, and disclose personal information only for the primary purpose for which it was collected, or for related secondary purposes that you would reasonably expect.

5.4 Canadian PIPEDA

For individuals in Canada, we rely on your implied or express consent for the collection, use, and disclosure of personal information. You may withdraw consent at any time, subject to legal and contractual constraints, by contacting us.


6. Disclosure of Personal Information

We do not sell your personal information. We may share personal information with:

Service providers and processors: Third-party vendors who assist us in operating our business (e.g., email hosting, calendar scheduling via Calendly, website hosting). These parties are contractually obligated to protect personal information and only process it on our instructions.

AWS and cloud platform providers: In the course of delivering consulting services, we may interact with AWS environments you make available to us, as well as AWS Representatives.

Professional advisers: Lawyers, accountants, and insurers where necessary for professional or legal purposes.

Regulatory and legal authorities: Where required by law, court order, or regulatory request in any jurisdiction in which we operate.

Business transfers: In the event of a merger, acquisition, or sale of business assets, personal information may be transferred to a successor entity, subject to equivalent privacy protections.

We do not disclose personal information to third parties for their own marketing purposes.


7. International Transfers of Personal Information

Nephology is based in Australia. If you are located in the UK, EU (including France, Germany, Italy), the US, or Canada, your personal information may be transferred to, stored in, and processed in Australia and potentially other countries where our service providers operate.

We take the following steps to ensure adequate protection for such transfers:

  • EU and UK individuals: Transfers are made subject to appropriate safeguards, including standard contractual clauses (SCCs) approved by the European Commission or the UK Information Commissioner’s Office, or on the basis of an adequacy decision where applicable.
  • Canadian individuals: Transfers are made in accordance with PIPEDA’s accountability principle, ensuring equivalent protections apply.
  • US individuals: Transfers comply with applicable US federal and state requirements.

You may request details of the safeguards applicable to your personal information by contacting us.


8. Your Rights

Depending on your location, you have the following rights regarding your personal information:

8.1 All Individuals

  • Access: Request a copy of the personal information we hold about you.
  • Correction: Request correction of inaccurate or incomplete personal information.
  • Complaint: Lodge a complaint with us and (if unresolved) with the relevant supervisory authority.

8.2 EU (GDPR) and UK (UK GDPR) — France, Germany, Italy, and other EU/UK residents

In addition to the above:

  • Erasure (“right to be forgotten”): Request deletion of your personal information where it is no longer necessary, or where you have withdrawn consent.
  • Restriction: Request that we restrict processing of your personal information in certain circumstances.
  • Portability: Receive your personal information in a structured, machine-readable format and transfer it to another controller.
  • Object: Object to processing based on legitimate interests or for direct marketing purposes.
  • Automated decision-making: Not be subject to solely automated decisions that significantly affect you, including profiling.

To exercise these rights, contact us at info@nephology.net.au. We will respond within 30 days (extendable to 60 days for complex requests, with notice).

Supervisory authorities:

8.3 Australian Residents

Under the Privacy Act 1988 (Cth), you have the right to access and correct your personal information. If you believe we have breached the APPs, you may complain to us first, and if unresolved, to the Office of the Australian Information Commissioner (OAIC) at https://www.oaic.gov.au.

8.4 Canadian Residents (PIPEDA)

You have the right to access your personal information and to challenge its accuracy. You may withdraw consent at any time (subject to legal and contractual constraints). Unresolved complaints may be referred to the Office of the Privacy Commissioner of Canada (OPC) at https://www.priv.gc.ca.

8.5 US Residents (California CCPA/CPRA)

If you are a California resident, you have the following rights under the CCPA/CPRA:

  • Know and access: Know what personal information we collect, use, disclose, and sell.
  • Delete: Request deletion of your personal information, subject to certain exceptions.
  • Correct: Request correction of inaccurate personal information.
  • Opt-out of sale/sharing: We do not sell or share personal information for cross-context behavioural advertising.
  • Limit use of sensitive personal information: We do not use sensitive personal information beyond what is necessary for our services.
  • Non-discrimination: We will not discriminate against you for exercising your privacy rights.

To exercise your California rights, contact us at info@nephology.net.au. We will verify your identity before processing requests. You may designate an authorised agent to submit requests on your behalf.

Shine the Light (California Civil Code § 1798.83): We do not share personal information of California residents with third parties for their own direct marketing purposes.

For residents of other US states with enacted privacy laws (e.g., Virginia, Colorado, Texas), please contact us and we will respond in accordance with your applicable state law.


9. Retention of Personal Information

We retain personal information only for as long as necessary to fulfil the purposes set out in this Policy, or as required by law. Our general retention approach is:

  • Enquiries and contact records: Up to 2 years after last contact, unless a client relationship develops
  • Client and engagement records: For the duration of the engagement plus 7 years (to meet Australian and other jurisdictions’ legal and tax record-keeping requirements)
  • Website analytics data: Up to 13 months (in line with CNIL guidance for analytics cookies)
  • Financial records: As required by applicable tax and corporate law (typically 7 years)

When personal information is no longer required, we securely delete or anonymise it.


10. Cookies and Website Analytics

Our website at https://nephology.net.au may use cookies and similar technologies for website operation and analytics purposes.

Types of cookies we may use:

  • Strictly necessary: Required for the website to function (no consent required)
  • Analytics: To understand how visitors use our site and improve it

We do not currently use advertising or tracking cookies for behavioural profiling purposes.

Your choices: You may control or disable cookies through your browser settings. Disabling strictly necessary cookies may affect website functionality.

For visitors from the EU, UK, and other jurisdictions requiring prior consent for non-essential cookies, we will seek your consent before placing such cookies where required by law (including under the EU ePrivacy Directive, UK PECR, French CNIL guidelines, German TTDSG, and Italian Cookie Law).


11. Security

We implement reasonable technical and organisational measures to protect personal information from unauthorised access, disclosure, alteration, loss, or destruction. These measures include:

  • Use of encrypted communications (TLS/HTTPS)
  • Access controls and authentication measures
  • Secure handling of client credentials and cloud environment access
  • Regular review of our security practices

No method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security, but we will notify you and applicable authorities of any data breach as required by law (including the Australian NDB scheme, UK GDPR 72-hour notification requirement, EU GDPR, and applicable US state breach notification laws).


12. Children’s Privacy

Our services are directed at business professionals and organisations. We do not knowingly collect personal information from individuals under the age of 16 (or under 13 in the US under COPPA). If we become aware that we have inadvertently collected personal information from a child, we will promptly delete it. Contact us at info@nephology.net.au if you have concerns.


Our website may contain links to third-party websites (including LinkedIn and Calendly). This Privacy Policy does not apply to those sites. We encourage you to review the privacy policies of any third-party sites you visit.


14. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will post the updated Policy on our website with a revised “Last updated” date. For material changes, we will take additional steps to notify affected individuals where required by law.


15. Jurisdiction-Specific Notes

France (Conformité RGPD / CNIL)

En application du Règlement Général sur la Protection des Données (RGPD) et des recommandations de la CNIL, nous nous engageons à ne pas déposer de cookies analytiques sans votre consentement préalable, à vous informer clairement de vos droits, et à répondre à vos demandes dans les délais légaux. Pour toute demande relative à vos données personnelles ou pour exercer vos droits, veuillez nous contacter à info@nephology.net.au.

(In compliance with the GDPR and CNIL recommendations, we commit to not placing analytics cookies without your prior consent, clearly informing you of your rights, and responding to your requests within legal timeframes.)

Germany (Datenschutz / DSGVO / TTDSG)

Gemäß der DSGVO und dem TTDSG verarbeiten wir personenbezogene Daten nur auf der Grundlage einer gültigen Rechtsgrundlage. Sie haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch. Bei Fragen zum Datenschutz wenden Sie sich bitte an info@nephology.net.au.

(In accordance with the GDPR and TTDSG, we process personal data only on a valid legal basis. You have the right to access, rectification, erasure, restriction of processing, data portability, and objection.)

Italy (Protezione dei dati / GDPR / Garante)

In conformità al RGPD e alle linee guida del Garante per la Protezione dei Dati Personali, trattiamo i dati personali solo per le finalità indicate nella presente informativa e sulla base di idonei presupposti giuridici. Per esercitare i Suoi diritti o per qualsiasi domanda relativa alla protezione dei dati personali, La invitiamo a contattarci all’indirizzo info@nephology.net.au.

(In accordance with the GDPR and the Italian Data Protection Authority’s guidelines, we process personal data only for the purposes indicated in this policy and on appropriate legal grounds.)


16. Contact Us

For any questions, concerns, or requests relating to this Privacy Policy or our handling of your personal information, please contact:

Nephology Pty Ltd
Email: info@nephology.net.au
Website: https://nephology.net.au

We are committed to resolving any privacy concerns promptly and fairly. If you are not satisfied with our response, you have the right to escalate to the relevant supervisory authority for your jurisdiction as listed in Section 8 of this Policy.


This Privacy Policy was last reviewed and updated on 27 August 2026.