

Privacy Policy
Effective date: 13/07/2026 Version: 1.0
Deep Media Pty Ltd | www.deepmedia.com.au
1. Introduction
Deep Media Pty Ltd (“Deep Media”, “we”, “us” or “our”) is an Australian digital advertising company. We provide media strategy, campaign planning, programmatic and platform media buying, audience and geospatial targeting, optimisation, measurement and reporting services to our business clients.
We respect your privacy and are committed to managing personal information in an open and transparent way. This Privacy Policy explains how we collect, hold, use, disclose and protect personal information, how you can access or correct the information we hold about you, and how you can make a privacy complaint.
This policy is designed to meet our obligations under the Privacy Act 1988 (Cth) (“Privacy Act”) and the 13 Australian Privacy Principles (“APPs”), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth). Where we handle the personal information of individuals located overseas, additional laws may apply, as described in section 21.
2. Who we are and how this policy applies
This policy applies to all personal information Deep Media collects and holds, whether through our website at www.deepmedia.com.au (“Website”), through our dealings with clients, suppliers and business contacts, through recruitment, or in the course of planning and delivering advertising campaigns on behalf of our clients.
Our role under Australian privacy law
An organisation that handles personal information — including where it does so on behalf of a client — is generally an “APP entity” with its own obligations under the Privacy Act. Accordingly, this policy addresses personal information we handle both for our own business purposes and in the course of providing services to our clients.
In delivering campaigns we act in different capacities. In some cases we determine how personal information is handled (for example, information about our own clients and website visitors). In other cases we handle information under the instruction of, and on behalf of, a client (for example, audience lists or store and location data a client provides for targeting). Where we handle information on a client’s behalf, that client is generally also responsible for that information under its own privacy policy, and our handling is governed by our agreement with them.
The advertising platforms we use (such as demand-side platforms, publishers and social platforms) independently collect and process personal information under their own privacy policies and as separate APP entities or overseas controllers. We are not responsible for those independent practices, but we do take reasonable steps to work with partners that maintain appropriate privacy and security standards.
3. What we mean by personal information
“Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
Importantly, technical identifiers used in digital advertising — such as IP addresses, cookie IDs, device identifiers, mobile advertising IDs and hashed email addresses — can be personal information where they can reasonably be linked to an individual, whether on their own or when combined with other information. We treat such identifiers as personal information where that is the case.
“Sensitive information” is a special category of personal information that attracts higher protection under the Privacy Act. It includes information about a person’s health, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and biometric information. See section 14.
“De-identified” information is information that is no longer about an identifiable individual, or an individual who is reasonably identifiable. Where we use aggregated or de-identified campaign data, it is not personal information and this policy does not restrict its use — provided it cannot reasonably be re-identified.
4. The kinds of personal information we collect and hold
The personal information we collect depends on the nature of our dealings with you. It may include:
Website visitors and enquirers
-
Contact details you provide — name, email address, phone number, business name and role.
-
The content of enquiries, messages and correspondence you send us.
-
Technical and usage data collected automatically when you visit the Website — IP address, device and browser type, pages viewed, referring URLs, and interactions — through cookies and similar technologies (see section 6).
Clients, prospective clients and business contacts
-
Names, job titles, business contact details and communications.
-
Records of meetings, proposals, engagements, billing and payment information.
Suppliers, contractors and partners
-
Names, contact details, and information necessary to manage the relationship and payments.
Job applicants
-
Information in applications, résumés, cover letters, references and interview notes, and the results of any background or work-rights checks we are permitted to conduct.
Campaign, audience and targeting data
-
Audience or customer data a client provides to us for a campaign — which may include hashed email addresses or other identifiers used for audience matching on advertising platforms.
-
Location and geospatial data used for geo-targeting, such as store coordinates, postcodes and catchment areas.
-
Campaign delivery, measurement and attribution data, including online identifiers and interaction data received from advertising platforms and measurement partners.
Wherever possible, we work with aggregated, de-identified or pseudonymised data, and we apply data minimisation — collecting only what is necessary for a clearly defined purpose.
We do not ordinarily receive information that directly identifies individuals from advertising platforms. Campaign reporting is generally provided in aggregated or pseudonymised form unless a client specifically provides customer information for audience matching or measurement.
5. How we collect personal information
We collect personal information by lawful and fair means, and generally collect it directly from you — for example when you contact us, engage our services, correspond with us, apply for a role, or interact with our Website.
Where it is not practicable or reasonable to collect information only from you, we may collect it from other sources, including:
-
our clients, where they provide audience, customer or location data for a campaign;
-
advertising, measurement and analytics platforms that provide campaign delivery and performance data;
-
our partners, data providers and publicly available sources, such as business directories and professional networking sites; and
-
referrals from other individuals or organisations.
Where we collect personal information about you from someone other than you, we take reasonable steps to ensure you are made aware of the matters set out in APP 5 (including who we are, why we collected it, and to whom we may disclose it), unless an exception applies. Where a client provides us with audience or customer data, the client is responsible for ensuring it has a proper basis — including any necessary consent — to provide that data to us for the agreed purpose.
6. Cookies, pixels and tracking technologies
Our Website uses cookies and similar technologies (such as pixels, tags and local storage) to enable core functionality, remember your preferences, understand how the Website is used, and measure the performance of our own marketing.
Some of these technologies are set by third parties (for example, analytics and advertising providers) and may allow those parties to collect information about your activity over time and across websites. Where we deploy such technologies, we take reasonable steps to configure them to collect only the data necessary for a defined purpose, and we review them periodically rather than leaving them on a “set and forget” basis.
You can control or disable cookies through your browser settings, and you can opt out of many interest-based advertising cookies through the industry tools listed in section 9. Blocking some cookies may affect how the Website functions. Where required by applicable law, we obtain consent before placing non-essential cookies.
7. Why we collect, hold, use and disclose personal information
We use and disclose personal information for the purposes for which it was collected, for reasonably related purposes you would expect, and for other purposes where you have consented or where the use or disclosure is otherwise permitted under the Privacy Act. These purposes include:
-
providing, planning, delivering, optimising and reporting on advertising campaigns and related services for our clients;
-
performing audience matching, geo-targeting and measurement using platforms and partners;
-
managing our relationships with clients, suppliers, partners and contacts, including billing and account administration;
-
responding to your enquiries and providing support;
-
operating, maintaining, securing and improving our Website and services;
-
marketing our own services to businesses, subject to section 8;
-
recruitment and assessing job applications;
-
meeting our legal, regulatory, insurance and record-keeping obligations; and
-
protecting our lawful interests, and detecting and preventing fraud, misuse and security incidents.
-
8. Direct marketing
We may use your business contact details to send you information about our services, insights and updates. We do this consistently with APP 7 of the Privacy Act and with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) where those laws apply.
Every commercial electronic message we send will identify us and include a simple way to unsubscribe. You can opt out of our marketing at any time by using the unsubscribe function or by contacting our Privacy Officer (section 22). We will action opt-out requests promptly. We do not sell personal information.
9. Advertising platforms and the digital advertising ecosystem
As part of delivering campaigns, we plan and buy media through third-party advertising platforms. These may include, but are not limited to:
-
Amazon Advertising (including Amazon DSP and Sponsored Ads)
-
The Trade Desk
-
Google Ads and the Google advertising platforms
-
Meta (Facebook and Instagram)
-
TikTok Ads
-
LinkedIn Ads
These platforms may collect and process personal information — such as device identifiers, IP addresses, cookies and online activity — for purposes including ad delivery, audience building, frequency capping and measurement. They do so as independent organisations under their own privacy policies and legal obligations, not under Deep Media’s policy. We encourage you to review their privacy policies:
Managing interest-based advertising
To manage or opt out of interest-based advertising delivered through many of these platforms, you can use:
10. Automated decision-making
Programmatic advertising involves automated systems that decide, in real time, which ads to serve and to which audiences, based on data including online identifiers and behavioural signals. Deep Media configures and manages campaigns on advertising platforms, but the automated bidding and ad-delivery decisions are made by those platforms’ systems.
We do not use automated processes to make decisions that produce legal or similarly significant effects on individuals (such as decisions about credit, employment or access to services). If this changes, we will update this policy to explain the kinds of personal information used in those decisions and the nature of the decisions, consistent with the automated decision-making transparency requirements of the Privacy Act, which take effect from 10 December 2026.
11. When we disclose personal information
We may disclose personal information to:
-
our clients, in connection with campaigns we deliver for them;
-
advertising, publishing, measurement, analytics and data platforms and partners engaged to deliver or measure campaigns;
-
our service providers — including IT, cloud hosting, data storage, CRM, payment, professional advisory and administrative providers — who handle personal information on our behalf;
-
our professional advisers, such as lawyers, accountants and auditors;
-
a purchaser or prospective purchaser in connection with a sale or restructure of our business; and
-
law enforcement, regulators or other parties where required or authorised by law.
When we engage service providers to handle personal information on our behalf, we take reasonable steps — including through contractual terms — to ensure they protect it and only use it for the purposes we permit. We do not disclose personal information to third parties for their own independent marketing without a lawful basis to do so.
12. Overseas disclosure
Some of the platforms, partners and service providers we use are located outside Australia, or store data outside Australia. This means personal information we handle may be disclosed to, or accessible from, overseas recipients.
Where we disclose personal information overseas, we take reasonable steps in the circumstances to ensure the recipient handles it consistently with the APPs, except where an exception under APP 8 applies (for example, where the recipient is subject to a substantially similar law or scheme, or where you have consented after being informed that APP 8.1 will not apply).
13. How we keep personal information secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Consistent with APP 11, these steps include both technical and organisational measures, such as:
-
access controls, so that personal information is only accessible to those who need it;
-
encryption of data in transit and, where appropriate, at rest;
-
secure, reputable cloud infrastructure and vetted service providers;
-
network and endpoint security controls, and regular software updates;
-
staff training on privacy and data security; and
-
policies and procedures governing how personal information is handled and how incidents are managed.
No method of transmission or storage is completely secure. While we work to protect personal information, we cannot guarantee absolute security.
14. Sensitive information
We do not seek to collect sensitive information in the ordinary course of our business. Where we do need to collect sensitive information, we will only do so with your consent (or where otherwise permitted by law) and where it is reasonably necessary for our functions or activities. We do not use sensitive information for targeting or direct marketing without consent.
15. Keeping information accurate
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant. If you believe information we hold about you is inaccurate, please contact us so we can correct it (see sections 17 and 22).
16. How long we keep personal information
We retain personal information only for as long as reasonably necessary for the purposes for which it was collected, unless a longer retention period is required or permitted by law.
When personal information is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we take reasonable steps to destroy it or de-identify it.
17. Accessing and correcting your information
You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact our Privacy Officer using the details in section 22.
We will respond within a reasonable period and will generally provide access in the manner you request where it is reasonable to do so. We may need to verify your identity first. In limited circumstances we may decline a request — for example where the law permits or requires us to, or where the information relates to another person — and if we do, we will explain why in writing and how you can complain.
Where the personal information relates to a campaign we handled on a client’s behalf, we may need to refer your request to that client, or ask you to contact them directly, as they may be better placed to respond.
18. How to make a privacy complaint
If you have a concern or complaint about how we have handled your personal information, please contact our Privacy Officer (section 22) with details of your complaint. We will acknowledge your complaint, investigate it, and aim to respond within a reasonable time — usually within 30 days.
If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):
-
Website: www.oaic.gov.au
-
Phone: 1300 363 992
19. Data breaches
We maintain procedures to identify, contain, assess and respond to data breaches. If a data breach involving personal information we hold is likely to result in serious harm to affected individuals, we will notify those individuals and the OAIC as required by the Notifiable Data Breaches scheme under the Privacy Act.
20. Children’s privacy
Our Website and services are directed at businesses and are not intended for children. We do not knowingly collect personal information from children. We monitor developments in this area, including the Children’s Online Privacy Code being developed by the OAIC, and will adjust our practices as required.
21. Other laws and overseas individuals
In addition to the Privacy Act, our handling of personal information may be affected by other laws, including the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth). Individuals also now have a direct right to bring court action for serious invasions of privacy under the statutory tort introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth).
Where we handle the personal information of individuals located in other jurisdictions, additional laws may apply, such as the EU/UK General Data Protection Regulation (GDPR) or US state privacy laws (including the California Consumer Privacy Act). Where such laws apply to our activities, we will comply with them in respect of the relevant individuals.
22. Contact us
If you have any questions about this policy or the personal information we hold about you, please contact:
Privacy Officer, Deep Media Pty Ltd
Email: adops@deepmedia.com.au
23. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our services, or the law. The current version will always be available on our Website, and the effective date at the top shows when it was last updated. We encourage you to review it periodically.