Privacy Policy

Last updated: 8 July 2026

Sovereign Identity (“we”, “us”, “our”) provides coaching services to clients in Australia. This policy explains what personal information we collect, why we collect it, how we use and store it, who we share it with, and how you can access, correct, or complain about the handling of your information.

Note: While a business of our size may fall under the small business exemption in the Privacy Act 1988 (Cth), we have chosen to handle personal information in line with the Australian Privacy Principles (APPs) as best practice — and because that exemption is under active review by the Office of the Australian Information Commissioner (OAIC) and expected to narrow over time. If our turnover, structure, or services change such that the exemption no longer applies (or ceases to exist), this policy already reflects the standard we hold ourselves to.

1. Who we are

Sovereign Identity is a coaching business trading as Sovereign Identity, ABN 30 228 058 700. This policy applies to personal information collected through our website sovereignidentity.com.au, our coaching programs, discovery calls, email communications, and any other interaction you have with us.

2. What personal information we collect

Depending on how you interact with us, we may collect:

Identity and contact details — name, email address, phone number, postal address.

Payment information — processed by our third-party payment provider (we do not store full card details ourselves).

Coaching-related information — goals, intake responses, session notes, progress notes, and any information you choose to share during coaching sessions or through intake forms.

Communications — emails, messages, and call/meeting records related to bookings and support.

Technical and website information — IP address, browser type, pages visited, and cookies (see Section 8).

Marketing preferences — whether you have subscribed to our newsletter or opted into promotional content.

We do not intentionally collect sensitive information (as defined under the Privacy Act, e.g. health records, sexual orientation, religious beliefs) as a standard part of our intake process. If you choose to disclose sensitive information to us during coaching — for example, in the context of discussing your goals — we will only use it for the purpose of supporting your coaching and will not disclose it without your consent unless required by law.

3. How we collect your information

Directly from you — via our website contact/intake forms, booking forms, email, phone, or in coaching sessions.

Through our service providers — our payment processor, scheduling tool, email marketing platform, CRM, and course/membership platform collect and pass information to us as part of delivering our services (see Section 5).

Automatically — through cookies and analytics tools when you visit our website.

4. Why we collect, use, and disclose your information

We collect and use personal information to:

Provide, manage, and personalise coaching services and programs.

Process payments and manage invoicing.

Schedule and manage bookings, sessions, and reminders.

Communicate with you about your coaching engagement, including administrative updates.

Send marketing communications, where you have opted in, and which you may unsubscribe from at any time.

Maintain business records, including for accounting and tax purposes.

Improve our services, website, and client experience.

Meet our legal and regulatory obligations.

We do not sell personal information to third parties.

5. Who we share your information with

We run our business on a small, deliberately consolidated set of platforms rather than a large stack of separate tools:

Ivorey (Ivorey Pty Ltd, ACN 682 606 702, Adelaide SA) — our single all-in-one business platform. Ivorey hosts our CRM and client records, calendar/booking system, course and client portal content, email marketing and communications, our website, and website analytics. Because everything runs through one platform, all of these functions sit with the one provider.

Stripe — our payment processor, used to process card and other payments. We do not store your full card details ourselves.

Professional advisers (e.g. accountant, bookkeeper, legal counsel) where required.

Government or regulatory bodies where required by law.

Ivorey itself is built on infrastructure supplied by HighLevel, Inc. (a US software provider), which acts as Ivorey's own sub-processor for CRM, automation, and communication functions. This means information you give us is handled by Ivorey directly, and in turn processed through HighLevel's systems on Ivorey's behalf.

6. Sending information overseas

Ivorey is an Australian company, but its platform runs on infrastructure provided by HighLevel, Inc. (United States) and hosted via Google Cloud Platform and Amazon Web Services. This means personal information processed through Ivorey — including CRM records, booking details, course access, and email communications — may be transferred to, and stored on servers located in, the United States (and potentially other countries where these providers operate data centres).

Stripe, our payment processor, similarly processes and may store payment-related data in the United States and other jurisdictions in which it operates.

Before disclosing personal information to these overseas recipients, we rely on the data protection and security commitments each platform makes in its own privacy policy and data processing agreements — see Ivorey's Privacy Policy and Stripe's Privacy Policy for details of how each handles cross-border data flows.

Ivorey: ivorey.io/privacy-policy   |   Stripe: stripe.com/privacy

7. Direct marketing

We will only send you marketing communications (such as newsletters or promotional offers) if you have opted in, or where permitted by law. Every marketing email includes an unsubscribe option, and you can also opt out at any time by contacting us directly (see Section 11).

8. Cookies and website analytics

Our website is built and hosted on the Ivorey platform. Ivorey's platform supports Google Analytics and Google Ads remarketing/AdWords tracking, but we do not currently have these enabled on our site. Ivorey may still use essential, functional cookies to operate core site and booking features (for example, remembering session state or securing forms). If we switch on analytics or remarketing tracking in future, we will update this section accordingly. You can control or disable cookies through your browser settings, though this may affect site functionality.

9. Data security

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, unauthorised access, modification, or disclosure. This includes using reputable, password-protected platforms, limiting access to personal information to what is necessary, and reviewing our practices periodically. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.

We retain personal information only for as long as necessary to fulfil the purposes described in this policy, or as required by law (e.g. tax and financial record-keeping obligations typically require records to be kept for five years).

10. Data breaches

If we experience a data breach that is likely to result in serious harm to individuals, we will notify affected individuals and the OAIC in line with the Notifiable Data Breaches (NDB) scheme, even if strict application of the scheme's turnover threshold does not require it of us. We treat this as a baseline commitment rather than a legal minimum.

11. Access and correction

You can ask us for access to the personal information we hold about you, or ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant, or misleading. To make a request, contact us using the details in Section 13. We will respond within a reasonable period (typically 30 days) and will not charge you for making a request, though reasonable costs may apply for providing access in some circumstances.

We may need to verify your identity before actioning a request, and there may be limited circumstances in which we are permitted to refuse access or correction (for example, where required by law) — if so, we will explain why.

12. Complaints

If you believe we have breached the Australian Privacy Principles or otherwise mishandled your personal information, please contact us first using the details in Section 13 so we can investigate and respond. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Website: www.oaic.gov.au  |  Phone: 1300 363 992

13. Contact us

For any questions about this policy, or to make an access, correction, or complaint request, contact:

Business: Sovereign Identity

ABN: 30 228 058 700

Email: [email protected]

Website: sovereignidentity.com.au

14. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on our website, with the effective date shown at the top of this document.

View our Privacy Policy here. © 2026 All Rights Reserved.