Privacy
Privacy Policy
What Somerset collects, why, who has access to it, how long it is kept, and what you can ask to have changed or deleted.
1 · About Somerset Business Advisory
1.1 Somerset Business Advisory (“Somerset”) provides business coaching, facilitation and training to owner-managed businesses in Australia.
1.2 Somerset Business Advisory is a registered business name. The entity currently trading under it is Jay Singh Ahluwalia, ABN 55 040 183 469, of T2A Nirimba Education Precinct, Warawara Cct, Quakers Hill NSW 2763. If that entity changes — on incorporation or restructure — this clause is updated and clause 15 governs what happens to information already held.
1.3 In this policy, Somerset personnel means the people who carry out Somerset’s work: its principal, and any employees, contractors, associate coaches, trainers and operational staff engaged by Somerset from time to time.
1.4 This policy covers somersetbusinessadvisory.com.au and the personal information Somerset handles in the course of its work — enquiries, Scorecards, diagnostics and client engagements alike.
2 · Somerset’s position under the Privacy Act
2.1 Somerset is a small business operator under section 6D of the Privacy Act 1988 (Cth) — annual turnover of $3 million or less — and none of the exceptions in that section apply to its work. Somerset is not a health service provider, does not trade in personal information, and is not a credit reporting body or Commonwealth contractor. On the law as it stands, Somerset is not bound by the Act or by the Australian Privacy Principles.
2.2 Somerset applies the Australian Privacy Principles as its own standard regardless. Clients hand over profit and loss statements, bank positions and tax situations. The standard those documents deserve does not depend on the size of the business receiving them.
2.3 Removal of the small business exemption has been recommended in the Privacy Act review and is expected in a future tranche of reform. This policy is written to the standard Somerset intends to keep either way.
3 · What Somerset collects, and why
The Healthcheck application
The form on the home page asks for your name, your email, your business name and what it does, how many people you have on a payroll, roughly what the business turns over, and what is driving you to look now. Somerset uses it to decide whether a Healthcheck is worth both parties’ time, and to prepare for the conversation.
The Five Foundations Check
The Check collects your first name and email, your industry, turnover band, team size and years trading, the trigger you select, your answers to the twenty-five questions, and the result calculated from them. A first name and an email address are required to reach the results screen. They are used to send you a copy, and to send you the benchmark data the Check is building once there is enough of it to be worth reading.
The Diagnostic intake
The intake form is sent only to clients who have engaged Somerset for a Diagnostic. It asks for revenue, net profit, owner drawings, cash at bank, wages, debtor days, ATO position, margin by line, pricing history, succession within the business, and what triggered the engagement.
That form does not post to a web server. It assembles your answers into an email addressed to Somerset. Your financial position travels as email and is held in Somerset’s mail system and your engagement file — it is never written into a third-party form dashboard. That is a deliberate decision, not an oversight.
While you are filling it in, your answers are saved in your own browser so you can leave to find the figures and come back. That copy stays on your device, is never sent anywhere, and is deleted the moment you send the form. There is also a Clear saved answers button, for a shared or borrowed computer.
Engagement records
Session notes, correspondence, and the documents you provide — profit and loss, balance sheet, bank statements, aged receivables, payroll summaries — together with the analysis and documents produced from them.
Workshop and training participants
Where Somerset runs a workshop or training programme for your business, it collects the names, roles and work contact details of participants, together with attendance and any work they submit as part of the programme.
Correspondence
Email, telephone, LinkedIn messages and calendar invitations.
Technical information
This site is hosted by Netlify, which records the IP address, browser and request details of every visitor in its server logs. The typefaces are served by Google Fonts, which means your IP address reaches Google when a page loads.
4 · What Somerset does not do
- No analytics, advertising or tracking cookies. This site sets no cookies of its own and runs no analytics provider. If that changes, this page changes first and says what was added.
- No selling. Somerset does not sell, rent, licence or trade personal information. There is no arrangement under which anyone pays for access to it.
- No sensitive information. Somerset does not ask for health information, race, religion, political opinion, sexual orientation, union membership or criminal record, and does not want it. Volunteered sensitive information is not recorded.
Somerset uses software, some of it AI-assisted, in preparing analysis and documents. Client information is not published, not licensed to anyone, and not used for any purpose other than the engagement it belongs to.
5 · When business information is also personal information
If your business is a sole trader or a partnership, or a small company where the business is effectively you, then information about the business’s finances is also information about you. Somerset treats it that way regardless of which box it arrived in.
6 · Profiling and alignment work with your team
Some engagements include questionnaires or profiling instruments completed by your staff. Those answers are personal information about them, not about the business. The protocol is fixed:
- Participation is voluntary. It is the business’s responsibility to obtain each person’s informed consent before they take part, and Somerset will ask you to confirm that you have.
- Individual results go to the individual.
- The business receives team-level and aggregated results only, unless that individual has agreed in writing that their own result may be shared.
- Responses are kept for no more than 24 months after the engagement ends, then destroyed.
This is the part of an engagement most likely to go wrong for someone, so it is the part Somerset will not vary informally. If you want the protocol changed, it is changed in writing before anyone answers a question.
7 · Who has access
7.1 Somerset personnel. Your information is available to Somerset personnel who need it to do the work — the coach or trainer on your engagement, and whoever supports it operationally. Access is limited to what the role requires.
7.2 Every person engaged by Somerset, whether as an employee, a contractor or an associate, is bound in writing to confidentiality and to this policy before they are given access to client information. That obligation continues after they stop working with Somerset.
7.3 Service providers.
- Netlify, Inc. (United States) — hosts this website and receives submissions from the Healthcheck application and the Check.
- Google LLC (United States) — serves the site’s typefaces, and hosts Somerset’s email, calendar and file storage.
7.4 Others, only where it applies. Professional advisers you ask Somerset to speak to — your accountant, bookkeeper, broker or solicitor — and then only what is needed for that conversation. Somerset’s own accountant and solicitor, where required for tax, audit or legal purposes. And where the law requires it: a court order, a subpoena, or a statutory obligation.
7.5 Nobody else. There is no marketing agency, no CRM vendor holding a copy of your file, and no data broker anywhere in the chain.
8 · Information sent overseas
Netlify and Google store data on servers in the United States and in other countries. If you use a form on this site, or send email to Somerset, your information will be handled outside Australia, and overseas recipients are not necessarily bound by Australian privacy law or subject to Australian enforcement.
If you would rather that did not happen, do not use the forms. Telephone or post does the same job.
9 · How it is kept
Accounts are protected with strong, unique passwords and multi-factor authentication. Devices are encrypted. Client financial documents are held in access-controlled storage rather than left in open email threads. Paper is shredded. Access is granted by role and removed when someone stops working with Somerset.
No system is perfectly secure. If information Somerset holds is lost or accessed without authorisation, and there is a real risk of serious harm to you, Somerset will tell you — what happened, what was exposed, and what to do about it — whether or not the Notifiable Data Breaches scheme obliges it to.
10 · How long it is kept
| What | How long |
|---|---|
| Enquiries and applications that do not become engagements | 24 months from last contact, then deleted |
| Five Foundations Check submissions | 24 months, then deleted |
| Team profiling and alignment responses | 24 months after the engagement ends, then destroyed |
| Workshop and training participant records | 24 months after the programme ends, then destroyed |
| Engagement records, including financial documents | 7 years after the engagement ends, then destroyed or de-identified |
| Financial records Somerset is required to keep | As required by law |
Seven years covers both the tax record-keeping period and the six-year limitation period for a contract claim in New South Wales, with a margin.
11 · Email from Somerset
Giving Somerset your email through the Check or an application puts you on the Somerset list. About one email a month — the Five Foundations benchmark once there is enough of it to be worth reading, a webinar, occasionally something Somerset is running with someone else. Your email is also used to send your Check result and to reply to what you asked. That is the whole of it.
Every message carries an unsubscribe link, honoured on the first request. Somerset complies with the Spam Act 2003 (Cth). Somerset does not sell your address, does not share it, and does not add you to anyone else’s list.
If you have given Somerset a phone number, or you are already corresponding, Somerset may call you about it. No number of yours goes to anyone else.
12 · Access, correction and deletion
Email jay@somersetbusinessadvisory.com.au. You can ask for a copy of what Somerset holds about you, ask for it to be corrected, or ask for it to be deleted.
Somerset will respond within 30 days, and there is no fee. The only things not deleted on request are records Somerset is legally required to keep, and anything needed for a legal claim actually on foot. Where Somerset refuses, it will say why in writing.
13 · Complaints
Email Somerset. You will get an acknowledgement within 5 business days and a substantive answer within 30 days.
If you are not satisfied with that answer, you can raise it with the Office of the Australian Information Commissioner — oaic.gov.au, 1300 363 992. Because Somerset is a small business operator (clause 2), the Commissioner’s jurisdiction over a complaint about Somerset is limited. That does not change how Somerset will deal with it: your complaint is handled as though the Act applied in full.
14 · Children
This site and this business are directed at people who own, run or manage businesses. Nothing here is aimed at anyone under 18, and Somerset does not knowingly collect their information.
15 · Changes, and change of entity
15.1 The date at the top is the date this version took effect. Where something material changes — adding analytics, changing a retention period, adding a service provider — this page is updated and says what changed. Continuing to use the site after that means you accept the current version.
15.2 If Somerset incorporates, restructures or transfers its business, personal information held by Somerset may transfer to the successor entity as part of that business. The successor will be bound by this policy, or by one no less protective of your information, and clause 1.2 will be updated to name it. Somerset will not use a change of entity to lower the standard set out here.
16 · Contact
Somerset Business Advisory
T2A Nirimba Education Precinct, Warawara Cct, Quakers Hill NSW 2763
jay@somersetbusinessadvisory.com.au
Related: Website Terms of Use · Terms of Engagement · Website Disclaimer.