Privacy policy

Last updated 28 August 2026

Who we are

This site is operated by TWOFOLD TT PTY LTD (ACN 701 276 137), trading as Two Fold TT, based in Melbourne, Australia. Thomas Tjahjadi is responsible for how personal information is handled and is the contact for any privacy question about it.

Two Fold TT is a separate business from Dino Elements. If you are looking for that company's privacy policy, this is not it.

The law we work to

The Privacy Act 1988 (Cth) and the Australian Privacy Principles (opens in a new tab) set the standard for handling personal information in Australia.

The Act binds businesses with more than $3 million in annual turnover, and it binds some smaller businesses regardless of size, including health service providers and any business that trades in personal information. Two Fold TT does not trade in personal information and is not a health service provider.

Where the Act does not bind a business of our size, the Australian Privacy Principles are still the standard we hold ourselves to. This policy describes what we actually do, not the minimum we could get away with.

The kinds of information we handle

Personal information
Your name, business email address, phone number, employer, role, and what you told us about the problem you are trying to solve. Almost always given to us by you, in a booking or an email.
Technical information
The IP address and request details that reach our infrastructure when a browser loads a page. Held by our providers as short-term logs, not compiled by us into a record about you.
Sensitive information
We do not collect it. Health information, racial or ethnic origin, political opinions, religious beliefs, trade union membership, sexual orientation, criminal record and biometric data have no place in this business, and there is nowhere on this site to give them to us.
Government identifiers
We do not ask for tax file numbers, Medicare numbers, driver's licence numbers or passport details. Where an engagement requires an ABN to raise an invoice, we hold that and nothing else of the kind.

What this website collects

Until 28 August 2026 this site set no cookies and ran no analytics. That changed, and this section says exactly what changed and what it means for you.

The site now runs HubSpot analytics. A HubSpot script loads on every page. It records that a page was viewed, which page, which links and buttons were clicked on it, roughly where in the world the request came from, and which site you arrived from. It sets cookies in your browser so that repeat visits are recognised as the same person rather than counted as new ones.

What it sets
Four HubSpot cookies: hubspotutk, which holds a random identifier for your browser, and __hstc, __hssrc and __hssc, which count and time your visits. They carry no name, no email address, and nothing you have typed into a form.
Why
To see which pages are read and which are ignored. That is the whole purpose. There is no advertising pixel, no remarketing audience, and no session recording watching what you click.
How to refuse it
Block cookies for this site in your browser settings, or use its private browsing mode. Every page works normally without them, and nothing is withheld from you for saying no.

The identifier is anonymous on its own. It only becomes connected to you personally if you later subscribe to the blog or book a call, at which point HubSpot can link the earlier anonymous visits to the contact record it creates. If that is not something you want, decline the cookies before you fill either one in.

What the site still does not do: there is no Google Analytics, no Google Tag Manager, and no advertising or conversion pixel. Click tracking records that a link or button was pressed; it is not session recording, so nothing replays your mouse movements, your scrolling or your keystrokes. Nothing collected is sold. Fonts are served from our own server rather than Google Fonts, so no request goes to Google when a page loads.

Forms. There is one, on the blog, to subscribe. It is described below and it is the only form on the site.

The only outbound links are to the booking page, LinkedIn, WhatsApp, and two news articles cited as sources. Following a link takes you to that company's site, where their own policy applies.

Server and network logs

Like any website, requests pass through infrastructure that keeps short-term technical logs. These are held by our providers, not compiled by us into anything about you, and not used for marketing:

Cloudflare
Handles DNS and sits in front of the site for security and speed. It processes your IP address and request details to do that. See Cloudflare's privacy policy (opens in a new tab).
NameHero
Hosts the files. Standard web server logs. See NameHero's privacy policy (opens in a new tab).

Search Console

The site is registered with Google Search Console, which reports which search queries led people here. That data reaches us aggregated and anonymised. It does not identify individual visitors.

When you book a call

The booking page is hosted by HubSpot, not by us. When you book, you give HubSpot your name, email address, and whatever you write in the question field, and that information comes to us as a meeting request and a contact record.

We use it to run the call and to follow up on it. That is the whole purpose. It is not sold, rented, or shared with anyone marketing to you.

HubSpot's own handling is governed by HubSpot's privacy policy (opens in a new tab).

When you subscribe to the blog

The subscribe form on the blog asks for your first name, last name and email address. All three are required. It sends them straight to HubSpot, where they become a contact record.

They are used to send you the blog, and for nothing else. No sales sequence follows, we do not pass the list to anyone, and we do not use it to advertise to you elsewhere.

Every issue carries a working unsubscribe link, and using it stops the mail. You can also email us and we will take you off by hand.

The form carries a hidden field that a person never sees and never fills in. If it comes back filled, the submission is treated as automated and discarded. It exists to catch bots and it records nothing about you.

When you email, message or connect with us

Email reaches a Google-hosted mailbox by way of Cloudflare Email Routing, and outbound mail is relayed through Brevo. Messages sent over WhatsApp or LinkedIn sit on those platforms under their own terms, and we hold only what we copy out of them into our own records.

You are not obliged to give us any of this. If you would rather ask a general question without identifying yourself, email us from an address that does not name you and we will still answer. Booking a call is the point at which we necessarily learn who you are.

Why we use your information

  • To answer an enquiry and hold the call you booked.
  • To send you the blog, if you asked for it.
  • To scope, quote, deliver and invoice consulting work.
  • To meet tax, corporate and record-keeping obligations.
  • To keep the site available and defended against abuse.
  • To see which pages are read, in aggregate.

We do not use it to build a profile of you.

Who else handles your information

A short list, and it stays short deliberately:

HubSpot (opens in a new tab)

Booking, contact records, blog subscriptions, and website analytics.

Cloudflare (opens in a new tab)

DNS, security and delivery for the website, and email routing.

Google

Mailbox, and aggregated Search Console reporting.

Brevo

Outbound mail relay.

Our accountants

Where an engagement produces financial records they need in order to do their work.

Your information is never sold, rented, or shared for anyone else's marketing.

We also disclose information where the law requires it, such as a court order or a regulator's lawful request. We will tell you if that happens, unless telling you is itself prohibited.

When your information goes overseas

Several of the services above are operated outside Australia, so information handled through them is stored or processed overseas. Practically, that means the United States (HubSpot, Google, NameHero, and Cloudflare's global network) and the European Union (Brevo, in France).

We choose providers that publish binding commitments about how they handle personal information, but we cannot guarantee an overseas recipient is subject to a law substantially similar to the Australian Privacy Principles. If that matters to you, tell us before you send us anything and we will work out another way.

Marketing

We do not run a mailing list, and booking a call does not subscribe you to anything. If that ever changes it will be opt-in, and every message will carry a working unsubscribe link.

Direct follow-up about work you asked us about is not marketing, and you can stop it by saying so.

Artificial intelligence

Advising on AI systems is the business, so our own use of it should be explicit rather than assumed. We use AI tools in our work, including for drafting and analysis. We do not put your personal information into consumer AI tools, and we do not permit it to be used to train a third party's model.

No decision that affects you is made automatically. There is no chatbot, no automated triage, and no scoring of enquiries. A person reads what you send and a person answers it.

How we keep it safe

The site is served over HTTPS and holds no database, because it collects nothing to put in one. What we do hold sits in the accounts listed above, and access is restricted to the people who need it to do the work.

No system is perfect. If a breach occurs that is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner, applying the Notifiable Data Breaches scheme whether or not it binds a business of our size.

How long it is kept, and how it is destroyed

Client engagement and financial records
Seven years. Section 286 of the Corporations Act 2001 (Cth) requires a company to retain financial records for seven years after the transactions they cover are complete, so this one is not our choice to make.
Enquiries that do not become engagements
Kept only while there is a reason to keep them, then deleted. Ask us to delete yours sooner and we will, unless a record has to be retained for the reason above.
Blog subscribers
Until you unsubscribe, then deleted within 30 days.
Analytics cookies
Held in your browser on HubSpot's own expiry, and cleared whenever you clear cookies for this site.
Server and network logs
Held by our providers on their own retention schedules. We do not extend them and we do not copy them.

Where information is held electronically and cannot be destroyed without compromising records we are required to keep, we put it beyond use instead: we stop using it, we do not disclose it, we restrict access to it, and we destroy it when that becomes possible.

Your rights: access and correction

You can ask what we hold about you, ask for a copy, ask us to correct it, and ask us to delete it. Email [email protected]. There is no charge, and you do not need to explain why.

We answer within 30 days, the period Australian Privacy Principle 12 sets for an access request. If we cannot do what you asked, for example because a record has to be kept under the Corporations Act, we will tell you which part we can do, which part we cannot, and the reason.

Complaints

Raise it with us first, at [email protected], and we will answer within 30 days.

If the answer does not satisfy you, you can take it to the Office of the Australian Information Commissioner, which will assess whether it is able to act. Phone 1300 363 992, email [email protected], or see oaic.gov.au (opens in a new tab).

Changes to this policy

Any change is reflected in the date at the top, and this page is reviewed at least every twelve months. Material changes affecting people we already hold information about will be told to them directly rather than quietly published.

Contact

Privacy contact
Thomas Tjahjadi
Email
[email protected]
Post
TWOFOLD TT PTY LTD, Melbourne, Victoria, Australia
Back to twofoldtt.com.au