Privacy Policy
Reviewed: 15 September 2026
This Privacy Policy explains how Whitehorne Scientific Consulting ("we," "our," or "us") collects, uses, and protects personal data.
We provide professional services to universities and research organizations within the European Economic Area (EEA).
As a boutique company operated solely by two core consultants, we are deeply committed to data privacy. We operate under strict data protection protocols and do not engage in tracking, profiling, automated marketing, or AI decision making of any kind.
We undertake no forms of marketing or market research etc. other than the general text that is provided on our website, or what is provided solely through word of mouth.
All interactions, enquiries, contracts, client work and service delivery are performed exclusively by us; we do not utilize external contractors or third-party service providers.
Data Controller and International Status
Whitehorne Scientific Consulting
[ABN 56 624 391 331]
PO Box 128 Euroa Victoria AUSTRALIA
Contact: Contact us
As we offer services to individuals working within Universities and Institutions within the EU/EEA, we comply with the General Data Protection Regulation (GDPR) alongside the Australian Privacy Act 1988.
The Data We Collect and Why
We only collect the absolute minimum personal data necessary to communicate with you, secure our website against abuse, process payments, and deliver our contracted services.
When you contact us using our enquiry forms (or contact us via email directly), we collect the information you voluntarily provide. We use this data solely to respond to your enquiry, ascertain if we are the right consultants to support you, and provide the requested information or service detail. The legal basis for processing this data is our legitimate interest in responding to customer inquiries.
Contact and General Information: Name, institutional email address and query information (and if required a copy of a previous research proposal submission and/or reviewer reports).
Technical Security Data: Confirmation that you are human and not a bot.
Source of Data: We receive this data directly from you via direct email, or our website contact form.
Legal Basis for Processing under GDPR:
Contractual Necessity: To provide/confirm service availability, service scope/details and pricing and assess if we are the right consultants to take on the (potential) contracted work (e.g. suitability or provision to provide an an offer of support).
Legitimate Interests: To respond to your direct enquiries and requests, manage our ongoing professional relationships, and/or protect our digital infrastructure from spam and automated abuse.
At your request, if we are contracted to work with you, then we will invoice you for this work. The information required for this includes:
Contact Information: Name, institutional email address for sending invoices, billing address, required order number(s), VAT number.
Technical Security Data: None
Source of Data: We receive this data directly from you via direct email.
Legal Basis for Processing under GDPR:
Contractual Necessity: To take steps at your request and enter into a contract.
Legitimate Interests: To enter into a contract.
Legal Obligation: To comply with Australian tax and financial reporting laws, and VAT 0% reverse charge rule requirements
What We Do NOT Do
To keep your data safe, we maintain a highly restricted data environment:
No Outside Contractors: No third-party contractors, freelancers, or external agencies have access to your data or project files. All work is handled strictly by the two core consultants.
No Analytics: Our website does not use tracking software, we perform no analysis of website users.
No Marketing Cookies: We do not deploy advertising or tracking cookies.
No Newsletters: We do not run email marketing campaigns, newsletters, or automated mailing lists.
No Data Selling: We never sell, rent, or trade your personal data with third parties.
Third-Party Software Stack (Data Processors)
While we do not share your information with outside contractors, we do utilize a minimal, secure software stack which is strictly necessary to run our day-to-day business infrastructure and administrative operations:
Communications & Storage (EU Based): Our email and file storage are securely hosted within the EU, with robust zero-access architecture compliant with Swiss and EU privacy standards.
Document Creation (Microsoft Word): We utilize Microsoft Word locally on our encrypted hardware for service deliverables. No client data is uploaded to public or unvetted cloud systems.
Invoicing & Accounting: We utilize a well-known, respected and trusted platform strictly for financial management, billing, and tax compliance.
Payment Processing: Clients pay us via international direct bank transfer or credit card payment. Credit card payments are made by clients via an EU based (GDPR compliant) banking institution. We have no access to, nor do we process banking details ourselves..
Bot & Spam Protection: To protect our site from automated spam, our contact forms use Prosopo Procaptcha (EU Based and GDPR compliant). This service is engineered with a privacy-first approach; it operates without deploying tracking cookies and does not profile users across websites.
International Data Transfers (EU to Australia)
Some of your personal data will be transferred to and stored in Australia, where our business operates, other personal data is stored within the EU.
To Australia: We safeguard data transfers by ensuring that our operations align with data protection guarantees required by EU institutions.
To Third-Party Tools: Our providers wherever possible are EU based (and as such GDPR compliant), and where this is not possible, we use trusted providers with strict security and privacy protocols in place.
Data Security Protocols
Despite being a two-person team, we enforce enterprise-grade data security measures to protect your information:
Devices are fully encrypted and protected by strong, unique passwords.
Multi-Factor Authentication (MFA) is enforced across all business accounts where this is available.
We review our stored data annually and securely delete information that is no longer required.
Data Retention
We only keep your personal data for as long as necessary to fulfill the purposes we collected it for. By Australian law, we are required to retain financial and transaction records for 7 years for tax and audit purposes. Non-financial institutional contact details are deleted or archived once our business relationship ends and/or no further communication is anticipated.
Your GDPR Rights
Under the GDPR, you have the following rights regarding your personal data:
Access & Portability: The right to request copies of your data or have it transferred to another organization.
Rectification: The right to request that we correct inaccurate information.
Erasure ("Right to be Forgotten"): The right to request that we delete your personal data (subject to our 7-year Australian tax retention obligations).
Restriction & Objection: The right to limit or object to our processing of your data.
To exercise any of these rights, please contact us directly. We will respond to your request within 30 days free of charge.
Right to Lodge a Complaint
If you are located in the EEA and believe we are processing your data unlawfully, you have the right to lodge a complaint with your local European Data Protection Authority (DPA).
