Privacy Policy
What personal data we process, why, and your rights
Last updated: 27 July 2026
Hello Tham Pty Ltd (ABN 44 617 279 115) of Sydney NSW, Australia (“Hello Tham”, “we”, “us”) operates the website www.hellotham.com (the “Site”). We are the data controller for the personal data described in this policy.
We handle personal data in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, and — for visitors in the European Economic Area and the United Kingdom — the General Data Protection Regulation (GDPR and UK GDPR).
You can contact us about anything in this policy at info@hellotham.com.
The short version
- This Site sets no cookies and uses no analytics, advertising or tracking scripts, so it needs no cookie banner.
- The only personal data we receive is what you choose to send us (through the contact form or by email) and the standard server logs kept by our hosting providers.
- Your theme choice (light or dark) and our site search work entirely on your device — nothing is transmitted to us.
- We never sell personal data, and we do not profile you or make automated decisions about you.
What we process, why, and on what legal basis
1. Server logs (hosting)
The Site is a static website deployed to GitHub Pages (GitHub, Inc.) and Netlify (Netlify, Inc.). Like almost every web host, these providers automatically record basic request data when you visit: your IP address, browser type and version, the pages requested, and the date and time of the request.
- Purpose: delivering the Site to you, keeping it secure, and preventing abuse.
- Legal basis (GDPR): our legitimate interests in operating a secure, reliable website (Article 6(1)(f)).
- Retention: these logs are held by the hosting providers for short periods under their own policies — see the GitHub Privacy Statement and the Netlify Privacy Policy. We do not combine them with any other data.
2. Contact form and email
If you use the form on our Contact page, we receive the details you enter: your name, email address, subject, message, and optionally your phone number. The form is processed by Netlify Forms on our behalf. If you email us directly, we receive your email address and whatever you include in the message.
- Purpose: responding to your enquiry and any follow-up you ask for.
- Legal basis (GDPR): taking steps at your request prior to entering a contract (Article 6(1)(b)) where your enquiry concerns our services; otherwise our legitimate interest in answering messages sent to us (Article 6(1)(f)).
- Retention: we retain enquiries and related correspondence for the period Australian law requires us to keep business records. Where correspondence relates to an engagement or transaction, that is generally seven years after the relevant transactions are completed, under section 286 of the Corporations Act 2001 (Cth), with Australian tax law separately requiring at least five years. Where no legal retention obligation applies to an enquiry, we keep it only as long as needed to handle it, then delete it.
3. Map tiles on the Contact page
The map on our Contact page loads its imagery from the OpenStreetMap Foundation (UK). When the map displays, your browser requests those tiles directly, which discloses your IP address and standard request headers to OpenStreetMap. See the OSMF Privacy Policy. No other page on the Site loads third-party content.
What we do not do
- We set no cookies of any kind — no session, preference, advertising or third-party cookies.
- We run no analytics or measurement tools and embed no social media plugins, pixels or beacons.
- Fonts, icons and illustrations are self-hosted, so pages (other than the Contact page map) make no requests to third-party servers.
- We do no profiling and no automated decision-making within the meaning of Article 22 GDPR.
- We never sell or rent personal data, and we do not share it for marketing.
Data stored on your device only
Two features store data locally in your browser; nothing is sent to us:
- Theme preference — choosing light or dark mode saves a single value in your browser’s local storage so the Site remembers your choice. It identifies nothing about you.
- Site search — search runs entirely in your browser against a locally downloaded index (Pagefind). Your search terms never leave your device.
You can clear both at any time by clearing your browser’s site data for this Site.
Processors and international transfers
We use a small number of service providers (“processors”) to run the Site: GitHub, Inc. (United States) and Netlify, Inc. (United States) for hosting and form processing, and the OpenStreetMap Foundation (United Kingdom) serves map tiles as an independent controller. We are based in Australia, so data you send us is processed in Australia.
Where the GDPR applies to a transfer outside the EEA or UK, it takes place under appropriate safeguards — an adequacy decision, the EU–U.S. Data Privacy Framework where the provider is certified, or Standard Contractual Clauses under Article 46 GDPR. Details are in each provider’s privacy documentation linked above.
Security
The Site is served exclusively over HTTPS (TLS). It is a static-first website with no user accounts and no database of visitor data operated by us — the most effective protection we apply is simply collecting as little as possible. Where we hold correspondence, we protect it with access controls and delete it when no longer needed. No transmission or storage method is completely secure, but we take reasonable technical and organisational measures appropriate to the low volume and sensitivity of the data we handle.
Your rights
If the GDPR or UK GDPR applies to you, you have the right to:
- access the personal data we hold about you (Article 15);
- rectify inaccurate data (Article 16);
- erasure — have your data deleted (Article 17);
- restrict processing (Article 18);
- data portability (Article 20);
- object to processing based on legitimate interests (Article 21); and
- withdraw consent at any time, where processing is based on consent, without affecting prior processing.
To exercise any of these rights, email info@hellotham.com. We will respond within one month, and we will not charge a fee unless a request is manifestly unfounded or excessive. We may need to verify your identity before acting on a request. These rights are subject to the conditions and exceptions in the GDPR — in particular, we may decline to erase records that Australian law requires us to keep (Article 17(3)) for as long as that obligation lasts, and we will tell you if that is the case.
You also have the right to lodge a complaint with a supervisory authority — in the EEA, the authority in your country of residence; in the UK, the Information Commissioner’s Office; and in Australia, the Office of the Australian Information Commissioner. We would appreciate the chance to address your concern first.
Children
The Site is directed at businesses and professionals, not children. We do not knowingly collect personal data from anyone under 18. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
When we change this policy we will publish the new version on this page and update the date at the top. Material changes will be noted prominently on the Site. Earlier versions are available in the Site’s public source repository.
Contact us
Questions, requests or complaints about privacy:
- Email: info@hellotham.com
- This policy: www.hellotham.com/privacy