Plain English, no legal fog. This page covers what happens to your information when you visit www.zovermedia.com or send us an enquiry, who we share it with, where it lives, and how to get it back or have it deleted — whether you're in Australia, New Zealand or the UK.
Zover Media is a website and social media agency based in Woollahra, Sydney, working with clients across Australia and, increasingly, New Zealand and the United Kingdom. Zover Media is a trading name of Neurodiversity Unravelled Pty Ltd, ABN 68 680 254 282. When this page says "we", "us" or "our", that's who it means.
We're the organisation responsible for the personal information described here — the "APP entity" under Australian law, the "agency" under New Zealand law, and the "controller" under UK law.
This page covers this website only. If you're a client using the Zover Portal, your service agreement sets out how we handle your business's data on top of what's here.
Please don't put sensitive information — health details, government identifiers, anything about other people — in the message box. We don't need it and we'd rather not hold it.
We do not take payments through this website, so it never sees a card number.
We use your information for the reasons below and nothing else. The last column is the legal basis we rely on under the UK GDPR, which asks for one; Australian and New Zealand law ask that a use be reasonable and expected, which each of these is.
| What we do | What we use | UK legal basis |
|---|---|---|
| Reply to your enquiry and scope the work | Enquiry form, email, phone | Steps at your request before a contract; our legitimate interest in answering people who contact us |
| Run the website and keep it secure | Server logs | Legitimate interests (security, fraud and abuse prevention) |
| Understand how the site is used and improve it | Analytics, session recordings | Your consent |
| Send you marketing, if you've said yes | Name, email | Your consent |
| Meet legal obligations, resolve disputes | Whatever is relevant | Legal obligation; legitimate interests |
We don't sell personal information, and we don't use it to make automated decisions about you.
The only cookies this site sets are from the two analytics tools above:
| Cookie | Set by | Purpose | Lasts |
|---|---|---|---|
_ga, _ga_* | Google Analytics | Tells one visitor from another and links pages in the same visit | Up to 2 years |
_clck | Microsoft Clarity | Identifies a visitor across visits | 1 year |
_clsk | Microsoft Clarity | Links pages viewed in one session into a single recording | 1 day |
Opting out. You can stop these entirely by blocking third-party cookies or scripts in your browser, or with the Google Analytics opt-out add-on. Both tools also honour your browser's cookie settings. We are adding a consent prompt so that visitors from the UK and the European Economic Area can choose before any analytics runs; until it's live, the tools above are the way to say no.
We use a small number of service providers to run this site and handle enquiries. Each can only use your information to provide their service to us, under their own contract and privacy terms.
| Provider | What they do for us | Where |
|---|---|---|
| Cloudflare | Hosts and serves the website, protects it from attacks, keeps server logs | Global network; US company |
| Resend | Delivers your enquiry to our inbox by email | United States |
| Railway | Runs the Zover Portal, where your enquiry is recorded so the team can act on it | Singapore |
| Neon | The database behind the Zover Portal | Sydney, Australia |
| Google Analytics; Google Fonts | United States and other Google regions | |
| Microsoft | Microsoft Clarity session recording; our email and calendar | United States, Europe and other Microsoft regions |
Beyond those, we'll only disclose your information if the law requires it, to protect someone's safety, or with your permission. If Zover Media is ever sold or merged, your information would go with the business, and this page would still apply to it.
Enquiries are stored in Australia (the database is in Sydney) and processed in Singapore (the portal's application server). Email delivery and analytics run in the United States. Cloudflare serves the site from whichever of its data centres is closest to you.
If you're in the UK: that means your information leaves the UK. Australia and Singapore don't have a UK adequacy decision, so for those transfers, and for the US providers, we rely on the safeguards written into each provider's terms — the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, or the provider's certification under the UK Extension to the EU–US Data Privacy Framework where they have one. You can ask us for details of the safeguard that applies to a specific provider.
If you're in New Zealand: your information is held outside New Zealand by the providers above, each of which is contractually required to protect it to a standard comparable to the Privacy Act 2020.
The site is served over HTTPS only. Cloudflare sits in front of it to absorb attacks and block bots, and the enquiry form has bot protection built in. Everything stored by our providers is encrypted at rest and in transit. Only the people who work on your enquiry can see it, and access is by named accounts with two-factor authentication.
No system is perfectly secure. If you think something's wrong — you've received an email from us that looks off, say — tell us at hello@zovermedia.com and we'll look into it straight away.
Wherever you are, you can ask us what personal information we hold about you, ask us to correct it, ask us to delete it, and complain if you think we've got something wrong. Email hello@zovermedia.com — we'll usually need to confirm it's you, and we'll respond within 20 working days, or sooner where the law requires. There's no charge.
Depending on where you live, you also have the following.
The Privacy Act 1988 and the Australian Privacy Principles give you the right to access and correct your personal information and to complain about how we've handled it. If you're not happy with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
The Privacy Act 2020 applies to us when we deal with people in New Zealand, even though we're based in Australia. You have the right to access and correct your personal information (Information Privacy Principles 6 and 7). If you're not satisfied with how we handle a request or complaint, you can contact the Office of the Privacy Commissioner at privacy.org.nz.
Under the UK GDPR and the Data Protection Act 2018 you have the right to access your personal information, have it corrected or erased, restrict or object to how we use it, receive a copy in a portable format, and withdraw consent at any time where consent is what we rely on (withdrawing consent doesn't affect anything done before you withdrew it). You can complain to the Information Commissioner's Office at ico.org.uk, though we'd appreciate the chance to fix things first.
We don't have an office or a representative in the UK — we're based in Sydney and currently serve clients in Australia and New Zealand. If you're in the UK and want to exercise any of the rights above, email us directly at hello@zovermedia.com and we'll handle it ourselves. We'll appoint a UK representative under Article 27 of the UK GDPR, and name them here, before we begin offering services to UK customers.
We'll only send you marketing email if you've asked for it, or if you're an existing client and it's about services like the ones you already use. Every marketing email has an unsubscribe link, and unsubscribing takes effect straight away. Replying to your enquiry isn't marketing — that's just us answering you.
This is how we comply with the Spam Act 2003 (Australia), the Unsolicited Electronic Messages Act 2007 (New Zealand) and the Privacy and Electronic Communications Regulations (UK).
This site is for businesses and the people who run them. It isn't aimed at anyone under 16, and we don't knowingly collect information from them. If you think a child has sent us their details, let us know and we'll delete them.
If personal information we hold is lost, accessed or disclosed in a way that's likely to cause serious harm, we'll tell the relevant regulator and the people affected as the law requires — the OAIC under Australia's Notifiable Data Breaches scheme, the Office of the Privacy Commissioner in New Zealand, and the ICO within 72 hours for UK residents.
We'll update this page when what we do changes — a new tool, a new provider, a new country. The date at the top tells you when. If a change materially affects how we use your information, we'll flag it clearly here and, where we can, let you know directly.
Questions, requests, complaints — all to the same place: