Privacy Policy

Last updated: 30 September 2026

Founders Lab is operated by Joshua Samson Todes (ABN 27 171 223 481), trading as Founders Lab, based in Sydney, Australia ("we", "us" or "our"). We work with clients in Australia and internationally.

This policy explains how we handle personal information collected through our website and related enquiries and correspondence.

Information you provide

When you contact us, we collect the information you submit, including your name, email address, business or project name, enquiry topic, and message. We also collect any additional information you choose to provide in follow-up correspondence.

Please only provide information relevant to your enquiry. Avoid sending sensitive personal information, identity documents, passwords, or personal information about other people unless it is necessary and you are authorised to share it.

You can browse our website without submitting a contact form. You may contact us using a pseudonym where practical, although we need a working contact address to reply and may need further details to discuss or provide services.

Technical information and cookies

We do not use website analytics, advertising trackers, or tracking pixels.

Our website hosting and form services may automatically record basic technical information, such as your IP address, browser type, requested pages, and the date and time of a request. This information supports website delivery, troubleshooting, security, and spam prevention.

We do not use cookies for analytics or advertising. Any cookies or similar technologies needed by our website infrastructure are used to support functionality or security.

How we use your information

We use personal information to:

  • Read and respond to your enquiry.
  • Discuss your requirements and prepare proposals or quotes.
  • Manage correspondence and any resulting business relationship.
  • Operate and protect our website and communication systems.
  • Meet applicable legal obligations and resolve disputes.

Submitting an enquiry does not subscribe you to a newsletter or marketing list. We do not sell or rent your personal information.

Who can access your information

Information is available to members of our team who need it to handle your enquiry or carry out the purposes described above.

We also use service providers for website hosting, contact-form delivery, email, and information storage. These providers process information as needed to supply their services to us.

Our relevant providers are Cloudflare (website hosting, security, and bot protection), Resend (delivery of form submissions by email), Calendly (call scheduling), and Google (the mailbox where we receive and answer enquiries).

We may disclose information to professional advisers where necessary, or to another person or authority where disclosure is required or permitted by applicable law. We may also share information at your request or with your consent.

International handling

We operate from Australia, so enquiries from overseas are handled in Australia. Our service providers may also store or process information overseas, including in the United States.

Where information is handled overseas, we take reasonable steps to protect it and meet any applicable requirements for international transfers. Contact us for information about the arrangements relevant to your enquiry.

Storage, security, and retention

We hold enquiry information electronically in the systems used to receive, manage, and respond to messages. We take reasonable steps to protect it against misuse, loss, and unauthorised access, disclosure, or alteration, including limiting access to people who need it.

We keep personal information for as long as reasonably necessary for the purpose for which it was collected. When deciding how long to retain it, we consider whether your enquiry is ongoing, whether it results in a client relationship, and whether records are needed for legal obligations or disputes.

When information is no longer needed and retention is not legally required, we take reasonable steps to delete it or remove identifying details.

Access, correction, and other requests

You can contact us to request access to personal information we hold about you, correct inaccurate information, or ask us to delete information we no longer need.

We may need to verify your identity before responding. If we cannot fulfil a request, we will explain why, unless the law prevents us from doing so. We respond within the time required by applicable law.

Depending on the laws that apply to you, you may also have rights to restrict or object to processing, receive a portable copy of your information, or withdraw consent where processing relies on consent. Withdrawing consent does not affect processing that occurred lawfully before withdrawal.

Visitors from the European Economic Area or United Kingdom

Where European or UK data protection law applies, we act as the controller of the personal information covered by this policy. We process enquiries to take steps you request before entering a contract, or for our legitimate interests in responding to business enquiries and managing correspondence. We also rely on legitimate interests to protect our website and systems, subject to your rights and interests.

Where applicable, we process information to meet legal obligations or obtain consent when required. You can contact us to exercise your rights or request further information about international-transfer safeguards.

Other websites

Our website may link to external websites or services. Their handling of information is governed by their own privacy policies.

Questions and complaints

To make a privacy request or complaint, contact Founders Lab at hello@founderslab.com.au. Please describe your concern and provide a way for us to reply.

We will review your complaint, investigate the relevant circumstances, and aim to respond within 30 days. If we need more time, we will explain why and keep you informed.

If you are dissatisfied with our response, you can contact the Office of the Australian Information Commissioner, where the matter falls within its jurisdiction, or the relevant privacy regulator in your country. This does not limit any right you have to complain directly to a regulator.

Changes to this policy

We will update this policy when our practices change and revise the date above. Where applicable law requires additional notice or consent, we will provide it.

Have a question about this policy? Contact us