Privacy Policy
Last updated: September 2026
1. Who we are
Cr8trix is a forensic strategic consulting practice. We provide strategic analysis, consulting, research, and related services to clients globally. References to "we", "us", or "our" in this policy refer to Cr8trix.
For privacy enquiries, contact us at [email protected].
2. Information we collect
We collect information you provide directly, including:
- Contact details (name, email address, phone number) submitted via enquiry or contact forms
- Professional information (organisation, role, industry) provided when commissioning research or engaging services
- Payment information processed securely through Stripe — we do not store card details
- Research panel registration data, including professional background and expertise areas
- Survey and research responses submitted through our platform
We also collect limited technical data automatically, including IP address, browser type, pages visited, and referring URLs, to operate and improve the site.
3. How we use your information
We use collected information to:
- Respond to enquiries and deliver contracted services
- Process payments and manage billing
- Administer research panels and communicate with participants
- Send service-related communications (confirmations, updates, invoices)
- Improve our website and services
- Comply with legal obligations
We do not sell your personal information to third parties.
4. Legal basis for processing
Where applicable under privacy law (including the Australian Privacy Act 1988 and GDPR), we process personal data on the following bases:
- Contract performance — to deliver services you have engaged us for
- Legitimate interests — to operate and improve our business, where not overridden by your rights
- Consent — where you have explicitly agreed, such as research panel participation
- Legal obligation — where required by law
5. Data sharing
We share personal data only where necessary:
- Stripe — for payment processing
- Prolific — for research participant sourcing, where applicable
- Email service providers — to send transactional communications
- Legal or regulatory authorities — where required by law
All third-party processors are required to handle data securely and in accordance with applicable law.
6. Data retention
We retain personal data for as long as necessary to fulfil the purposes described in this policy, or as required by law. Client and project records are typically retained for seven years for accounting and legal purposes. Research panel data is retained for the duration of your participation and for a reasonable period thereafter.
7. Your rights
Depending on your location, you may have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your data (subject to legal obligations)
- Object to or restrict certain processing
- Withdraw consent where processing is consent-based
- Lodge a complaint with a supervisory authority
To exercise any of these rights, contact us at [email protected].
8. Cookies
We use cookies and similar technologies to operate the site and, with your consent, to analyse usage. You can manage cookie preferences through the cookie banner displayed on your first visit. Declining analytics cookies does not affect your ability to use the site.
9. Security
We implement appropriate technical and organisational measures to protect personal data against unauthorised access, loss, or disclosure. Payment data is handled exclusively by Stripe and is not stored on our systems.
10. Changes to this policy
We may update this policy from time to time. Material changes will be communicated via the site. Continued use of our services after changes constitutes acceptance of the updated policy.