Privacy Policy

This is the Privacy Policy of Michelle Whitehead ABN: 91968443292 trading as Carefree Counsel.

If you have any questions or need further information, please email me:

I am committed to protecting your privacy when you interact with my business, whether you are a contact, customer, supplier, contractor or employee of mine. I choose to voluntarily comply with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth) (Privacy Act).

This document describes how I collect and manage your personal and sensitive information when you interact with my business. I take this responsibility very seriously. If you have any questions or concerns about how your personal or sensitive information is being handled, please do not hesitate to contact me.

Personal Information

If you engage with me via this website or social media, interact with my business in some way, or choose to become my client, I may need to collect the following kinds of personal information from you, including:

  • contact details such as your name, business name, ABN, role, position or occupation, address, email address, and phone number;
  • information about your personal circumstances that is relevant to my work and the ways I might support you;
  • information about your business, your requirements and the services (including risk management, legal services or conflict resolution) that you may wish to engage me to provide;
  • your opinion about future topics, products or services that may interest you, including information that allows me to tailor my content to your needs when you sign up for one of my webinars or promotional events, or respond to one of my newsletters;
  • information regarding your attendance at webinars, seminars, courses, programs and promotional events held by me or which I attend as a speaker;
  • your IP address, and information about your browsing history to help me improve the usability and appeal of my website. More information about this is found in the section on Cookies below;
  • if you are an employee or contractor, or propose working with me in that capacity, information about your qualifications, skills and work experience; and
  • if you are a supplier or prospective supplier, information about your business skills, services, products and prices.

I may collect and use your personal information to:

  • respond to your enquiries;
  • provide you with business services including risk management, legal services, coaching, mentoring and mediation;
  • employ competent and diligent personnel;
  • monitor or improve the use of and satisfaction with my website, products or services; and
  • let you know about my work, relevant news, my expertise and products or services that may be of interest to you.

If you do not provide me with information when requested to do so, I may not be able to carry out your instructions or achieve the purpose for which the information has been sought.

I may, from time to time, send you newsletters, invitations and updates about my services. I will only do so if you have requested to receive such communications through a double opt-in process. You can opt out of receiving any further such communications by replying to the message you received, or by clicking the “unsubscribe” option at the bottom of any marketing e-mail received from me.

Collection of Personal Information

Where practicable I will only collect personal information about you directly from you. However, in some circumstances I may obtain personal information from a third party. If this information is obtained contrary to this Privacy Policy and the Privacy Act, I will destroy or de-identify such information within a reasonable period.

I may collect your information by various means including when:

  • you contact me with a question, comment or inquiry;
  • you subscribe to my newsletter;
  • you attend a seminar or event where I am hosting or presenting;
  • you correspond with me on a social media platform such as Facebook, LinkedIn, Instagram or similar sites;
  • you opt in to receive a free resource from me or sign up for my newsletter;
  • you book a consultation or purchase a product or service from me;
  • you share general information relating to your business or personal life;
  • you provide me with a testimonial;
  • I visit your website or social media profiles in preparation for working with you;
  • my website automatically collects information about you and your activities on my site (including analytics and cookies - more information on this is set out below); or
  • a third party supplies information to me, such as when you are referred or introduced to me by a mutual acquaintance.

I will only collect your information:

  • with your full awareness and consent, such as when you email me, tick a checkbox or fill in a form to provide me with information;
  • if I need it to provide you with information or services that you request;
  • if I am legally required to collect it;
  • if collecting the information is necessary to preserve life or keep someone safe from harm;
  • for necessary administrative processes if you become my client; or
  • if I believe that I can demonstrate a legitimate interest in using your data for marketing purposes, although I will always give you a choice to opt out.

Sensitive Information

I understand that some information is particularly sensitive and that you are trusting me to keep this information confidential.

The sensitive information I collect from you may include:

  • trade secrets, intellectual property and information about your business that is not in the public domain;
  • information about disputes, including correspondence and contact details for the other party, your intentions, and instructions for how you would like to proceed;
  • legal, financial or administrative data relevant to the work you have engaged me to perform; and
  • information about risks and challenges you are facing in your business, including your personal feelings about those issues.

I will only collect sensitive information by methods that are reasonably secure, such as:

  • through my intake form in Acuity when you book an appointment;
  • in a zoom consultation or face to face;
  • when you send me information in an email (please note that email may not be sufficiently secure – if the information is extremely sensitive, ask me about alternative ways to share it with me.)

The reason why I collect your sensitive information is:

  • so that I can provide you with the services you have requested from me; and
  • to ensure that I am providing you with the most appropriate services.

I am committed to securely storing and handling your sensitive information.

  • Sensitive information is stored on password protected devices with a high level of cybersecurity;
  • Only I and trusted team members have access to your sensitive information, and only on a need to know basis;
  • Sensitive information may be stored securely online through Google Workspace. You can find out more about their security provisions in the section on Security below.

All information collected from children under the age of 18 is classified as sensitive information.

  • I do not collect sensitive information from anyone under the age of 18.

Disclosure of Information

I may disclose your information if required under the following circumstances:

  • provide you with the services you have requested;
  • to send you products that you have purchased;
  • where disclosure is necessary to carry out your instructions, such as corresponding with someone else on your behalf;
  • where I use support services to assist me in my business; and
  • to refer you to other service providers at your request.

You consent to me sharing relevant information, on a strictly need-to-know basis, with:

  • people you authorise me to correspond with, as reasonably required to carry out your instructions;
  • my subcontractors;
  • Third party providers who assist with:
    • accounting
    • administration
    • archiving
    • auditing
    • business consulting
    • email marketing
    • legal or financial advice
    • website maintenance
    • technological services 

I will also disclose your information if required by law in response to a subpoena, discovery request or a court order, in compliance with mandatory reporting obligations, or in circumstances permitted by the Privacy Act – for example, where I have reasonable grounds to suspect that someone is engaging in unlawful activity, or misconduct of a serious nature that relates to my work with you. I may also make a disclosure to an appropriate authority if I have serious concerns about your health, safety or wellbeing.

I will use all reasonable means to protect the confidentiality of your information while in my possession or control. I will not knowingly share any of your information with any third party other than the service providers who assist me with necessary business activities or the services I am providing to you. To the extent that I do share your information with third-party service providers, I only do so if I am satisfied that the service provider has a suitably protective privacy policy of their own, or they have signed a confidentiality agreement with me. Some of my service providers may be overseas and may not be subject to Australian Privacy Laws. You can find further information under the Security section below.

If you have any concerns regarding the disclosure of your information, please do not hesitate to get in touch with me to discuss this personally.


I take reasonable physical, technical and administrative safeguards to protect your personal and sensitive information from misuse, interference, loss, and unauthorised access, modification and disclosure.

I manage risks to your information by:

  • storing files and devices securely;
  • ensuring that only I and trusted key subcontractors have access to sensitive information, and that my subcontractors are bound by strict confidentiality provisions;
  • releasing information to service providers on a strictly need-to-know basis; and
  • conducting regular audits of my security systems.

As mentioned above, your information may also be stored with a third-party provider, where it will be managed under their security policy. The following security policies may apply during our work together:

  • Acuity -
  • Facebook ads -
  • Google Workspace -
  • MailerLite -
  • QuickBooks -
  • Streak -
  • WordPress -
  • Zoom -

If you are communicating with me via electronic means such as email, Zoom, contact forms or Facebook, I may not have full control over the transmission or storage or any personal information disclosed (although I try to employ best practice cybersecurity standards at all times). You agree that by participating in such forms of communication you understand and accept that there is an inherent risk of disclosure or loss of your personal information for which I cannot be held responsible. If you are concerned about transferring particularly sensitive information, please ask me about alternative options that may be more secure.

Cookies & Google Analytics

Cookies are small text files that are commonly used by websites to improve a user’s experience, collect statistics or marketing information and provide access to secure areas.

The only cookies used by my website come from either WordPress, and relate to site functionality, or Google Analytics.

You can choose to configure your browser settings not to accept cookies but this may interfere with the functioning of this website, such as access to my content portal, affiliate dashboard, or the ability to login and download purchases.

I use Google Analytics to collect information about your use of my website so that I can get strategic information about how my website is being used and improve its performance. You can find out more about the information Google collects and how it is used here:

Google also provides an add-on for your browser that you can use to opt-out and prevent your data being used by Google Analytics. You can access that add-on here:

Access to Information

You can contact me to access, correct or update your personal information at any time. 

Unless I am subject to confidentiality obligations or some other restriction on giving access to the information which permits me to refuse you access under the Privacy Act, and I believe there is a valid reason for doing so, I will endeavour to make your information available you within 30 days.


If a breach If a breach of this Privacy Policy occurs, or if you wish to a request a change to your personal information, you may contact me by sending an email outlining your concerns to me at

If you are not satisfied with my response to your complaint you may seek a review by contacting: the Office of the Australian Information Commissioner using the information available at

Notification of Change

When I update my Privacy Policy, I will post a copy of the revised policy on my website.

Notification of Breach

If I have reason to suspect that a serious data breach has occurred and that this may result in harm or loss to you, I will immediately assess the situation and take appropriate remedial action. If I still believe that you are at risk, I will notify the Office of the Information Commissioner and either notify you directly, or if that is not possible, publicise a notification of the breach on this website.

Thank you!

This Privacy Policy was created using my own Privacy Policy DIY Pack. Copying it without permission is an infringement of my copyright and I regularly search for key phrases and follow up with people who are using my work without first purchasing it from me. Look after your business and your clients by creating your own Privacy Policy with a Contracts that Care DIY Pack!

Do you ever worry that you don't know what you don't know?

I provide the information you need, and I make it easy to read!