THE STRAUSS AGENCY PRIVACY STATEMENT 

Last updated: JUNE 2026

The Strauss Agency Pty Ltd, 41-51 Wentworth Ave, Pagewood NSW 2035  (“TSA Events”, “we”, “our”, “us”) provides marketing, communications, association management, congresses, meetings, event services and related consulting services to its clients (“Clients”).

This Privacy Policy explains how we collect, use, disclose, store and protect personal information in connection with:
• our website and digital platforms (where TSA Events acts as data controller); and
• events and projects delivered on behalf of Clients (where TSA Events typically acts as data processor/service provider).

We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and, where applicable, international privacy frameworks.

1. Scope of this Privacy Policy
This Privacy Policy applies to all TSA Events services.
It does not apply to:
• third-party websites, platforms or suppliers; or
• Clients or sponsors/exhibitors, who may have their own privacy policies.

2. Roles and Responsibilities
Depending on the activity:
• Client projects / events:
TSA Events generally acts as a data processor, handling personal data on behalf of the Client (who is the data controller).
• Website / marketing / TSA-led activities:
TSA Events acts as a data controller.

If you have questions about how your data is used in a specific event, we may direct you to the relevant Client.

3. Types of Personal Data Collected
We collect personal information necessary to deliver event and related services, including:

Identification and contact details
• name, email address, phone number, address
• organisation, role, industry
Event and travel information
• travel bookings, itineraries, accommodation preferences
• passport and visa details (where required)
• location data during events
Preferences and requirements
• dietary requirements, allergies (may be sensitive data)
• accessibility requirements
• event interests and engagement
Financial information
• payment details (processed via secure third-party providers)
Technical and usage data
• website interactions, app usage, IP address
Media and communications
• photographs, video and audio recordings
• communications with TSA Events
Emergency information
• emergency contact details (where required)

We only collect data that is reasonably necessary for event delivery and related services.

4. How We Collect Personal Data
We collect personal information from:

• you directly (e.g. registrations, forms, correspondence)
• our Clients (who must ensure lawful collection and disclosure)
• event interactions (e.g. app usage, badge scanning)
• third-party service providers (e.g. travel or registration platforms)

At or before collection, we provide (or our Clients provide) a collection notice outlining:
• purpose of collection
• key disclosures
• how to access this Privacy Policy

5. Legal Basis for Processing
We process personal data based on:
Contractual necessity – to deliver events, bookings and services
Legal obligations – e.g. travel, security or regulatory requirements
Legitimate interests – event operations, safety, service improvement
Consent – where required (e.g. marketing, sensitive data, photography)

You may withdraw consent at any time where processing relies on consent.

6. Purpose of Processing

We use personal data to:

Event delivery and logistics
• manage registrations, attendance, communication
• coordinate travel and accommodation
• ensure safety and emergency response
Client reporting and compliance
• provide reporting to Clients (including aggregated or limited personal data where necessary)
• monitor compliance with Client policies
Communication and experience
• send event-related communications
• customise event experiences
Marketing (where permitted)
• send relevant information about events or services
• this will only occur where:
o you have opted in; or
o we are otherwise permitted by law
Analytics and improvement
• analyse trends and improve services (using aggregated or de-identified data where possible)

7. Sensitive Data
Sensitive information (e.g. health or dietary requirements) is:

• collected only where necessary;
• collected with explicit consent; and
• used strictly for event delivery (e.g. catering, accessibility, safety).

Access to this data is restricted and subject to enhanced security measures.

8. Photography and Recording
Events may be photographed or recorded.

We will:
• notify attendees in advance (e.g. registration, signage)
• provide reasonable opt-out mechanisms (e.g. notifying staff, identifiable markers)

Content may be used for:
• event reporting
• marketing and promotional purposes

You may request removal of identifiable content where reasonably practicable.

9. Disclosure of Personal Data

We may disclose personal data to:

Service providers
• event platforms, registration systems, mobile apps
• travel and accommodation providers
• IT, cloud and security providers
Clients
• as part of event delivery and reporting
Sponsors and exhibitors (only where applicable)
• where you choose to share your details (e.g. badge scanning, opt-in)
Regulators and authorities
• where required by law

We require third parties to comply with applicable privacy laws and implement appropriate safeguards.

10. International Data Transfers
As events are delivered globally, personal data may be transferred overseas.

Where this occurs, we ensure:
• appropriate safeguards are in place; and
• transfers comply with applicable privacy laws

11. Data Retention
We retain personal data only for as long as necessary, including for:
• event delivery and follow-up
• legal and financial obligations
• Client requirements

Retention periods vary depending on the purpose and legal obligations.

Where possible, data is:
• deleted; or
• de-identified when no longer required

12. Security and Data Protection
We implement appropriate measures, including:
• restricted access controls
• secure cloud storage environments
• encryption and secure transmission
• contractual confidentiality obligations

We regularly review our security practices.

13. Data Breach Response
TSA Events has procedures to manage data breaches.

Where a breach is likely to result in serious harm, we will:
• notify affected individuals; and
• comply with the Notifiable Data Breaches (NDB) scheme under Australian law

14. Your Rights
Subject to applicable law, you may:
• request access to your personal data
• request correction of inaccurate data
• request deletion (where applicable)
• object to or restrict processing
• opt-out of marketing communications
• lodge a complaint

For Client-managed events, requests may be referred to the Client (data controller).

15. Direct Marketing
We will only send marketing communications where permitted by law.

You can opt out at any time via:
• unsubscribe links; or
• contacting us directly

We do not sell personal data.

16. Children’s Privacy
We do not knowingly collect personal data from children without appropriate consent.

17. Complaints
If you have a concern:
• Contact us using details below
• We aim to respond within 30 days
You may also lodge a complaint with:
• Office of the Australian Information Commissioner (OAIC)

18. Changes
We may update this Privacy Policy from time to time.
The latest version will be available on our website.

19. Contact
Data Protection Contact
Email: events@tsaevents.com.au
Address: 41-51 Wentworth Ave, Pagewood, NSW 2035