[ Legal ] — Privacy

Privacy Policy

This policy explains how Sandbox Labs ("we", "us", "our") handles personal information. It is written to meet our obligations under the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs) set out in Schedule 1 of that Act.

Last updated: 1 August 2026

[ 01 ]

Who we are

Sandbox Labs recruits and sources elite project engineering talent for businesses in Australia. We are the entity responsible for the personal information collected through www.sandboxlabs.au and through our client intake and booking process.

Even where we are not an "APP entity" required to comply with the Privacy Act, we apply this policy and the Australian Privacy Principles as our standard of practice.

[ 02 ]

What personal information we collect (APP 3)

We only collect personal information that is reasonably necessary for our functions and activities. That includes:

  • Identity and contact details — your name, company, role, email address and phone number.
  • Meeting details — the business address you nominate for a face-to-face review, and your preferred date and time.
  • Project information — the problem statement, indicative budget range, and any documents, files or supporting material you choose to upload.
  • Technical information — limited information generated when you use the site, such as your browser type and general request data used to keep the site secure and operational.

We do not seek sensitive information (as defined in the Privacy Act), such as health information, or information about your race, religion, political opinions, sexual orientation or criminal record. Please do not include it in uploads or free-text fields. If you do, we will handle it in accordance with APP 3.3 and delete it where it is not required.

[ 03 ]

How we collect it (APP 3 & APP 5)

We collect personal information directly from you when you complete the intake form, upload documents, book a review, email us, or speak with us. Where practicable we collect only from you. If we receive information about you from a third party (for example, a colleague who refers you), we will take reasonable steps to notify you.

You may deal with us anonymously or under a pseudonym where it is lawful and practicable to do so (APP 2) — however we cannot arrange or attend a face-to-face review, or source an engineer, without contact details.

[ 04 ]

Why we collect it and how we use it (APP 6)

We use personal information to:

  • assess your problem statement and determine the engineering capability required;
  • arrange, confirm and attend your obligation-free face-to-face review;
  • prepare a scope, timeline and budget proposal for you;
  • source, brief and match suitable engineers to your project;
  • contact you about your enquiry or engagement, including a courtesy confirmation call; and
  • meet our legal, record-keeping and dispute-resolution obligations.

We will not use or disclose your personal information for an unrelated secondary purpose unless you would reasonably expect it, you consent, or the use is otherwise permitted or required by law. We do not sell personal information, and we do not use your information for direct marketing without a clear opt-out.

[ 05 ]

Who we disclose it to (APP 6 & APP 8)

We may disclose personal information to:

  • Candidate engineers and specialists — only to the extent needed to scope your project, and generally after we have discussed it with you;
  • Service providers — our website hosting, database, email delivery and file-storage providers, who process information on our instructions;
  • Professional advisers, insurers and regulators — where reasonably required; and
  • Any person where disclosure is required or authorised by Australian law, or is necessary to prevent a serious threat to life, health or safety.

Overseas disclosure: some of our technology providers store or process data on servers located outside Australia, including in the United States and the European Union. Before disclosing personal information overseas we take reasonable steps under APP 8.1 to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, including through contractual data-protection terms.

[ 06 ]

Quality of information (APP 10)

We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date, complete and relevant. Please tell us if any of your details change or are wrong.

[ 07 ]

Security, storage and destruction (APP 11)

Personal information and uploaded documents are stored in access-controlled systems, transmitted over encrypted (HTTPS/TLS) connections, and accessible only to personnel who need them for the purposes described above.

We take reasonable steps to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Where we no longer need personal information for any purpose for which it may be used or disclosed, and we are not required by law to retain it, we destroy it or ensure it is de-identified. Booking and project records are generally retained for up to seven years for legal, tax and dispute-resolution purposes.

If an eligible data breach occurs, we will assess and respond in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

[ 08 ]

Cookies and website analytics

Our website uses only the cookies and local storage necessary to operate the site, keep it secure, and remember your progress through the intake and booking process. You can block or delete cookies in your browser settings, though parts of the site may stop working correctly.

[ 09 ]

Access and correction (APP 12 & APP 13)

You may request access to the personal information we hold about you, and ask us to correct it. Contact us using the details below. We will respond within a reasonable period — usually within 30 days — and will not charge you for making a request (although a reasonable charge may apply for giving access in some circumstances).

We may need to verify your identity first. If we refuse access or correction, we will tell you why in writing and explain how you can complain.

[ 10 ]

Complaints

If you believe we have breached the Australian Privacy Principles, please contact us first using the details below. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner: online at oaic.gov.au, by phone on 1300 363 992, or by post at GPO Box 5218, Sydney NSW 2001.

[ 11 ]

Changes to this policy

We may update this policy from time to time to reflect changes in our practices or the law. The current version is always available at www.sandboxlabs.au/privacy, with the date it was last updated shown at the top of this page.

[ 12 ]

Contact us

Privacy enquiries, access requests and complaints:

  • Nick Xenos — Director, Sandbox Labs
  • Phone: 0400 999 647
  • Web: www.sandboxlabs.au

You can also raise a privacy matter at your face-to-face review, or by replying to any email we have sent you.

This policy is a plain-English summary of how we handle personal information under the Privacy Act 1988 (Cth). It is provided for information only and is not legal advice.