Privacy Policy

Australia and New Zealand

Effective date: 10 August 2026 · Version 2.1

This privacy policy explains how Tellisto (Rohan Hinton trading as Tellisto, ABN 53 050 194 779) (Tellisto, we, us or our) collects, holds, uses and discloses personal information. It applies to our website, our platform, our galleries, the Client Vault, and everything else we do.

Tellisto provides software for professional photographers and videographers in Australia and New Zealand. Photographers use it to run their businesses (leads, bookings, invoicing and messaging) and to deliver finished shoots to their clients through private online galleries. In this policy, references to photographers include videographers, and a reference to a photograph includes a video.

We have written this as a single policy for both Australia and New Zealand. It is designed to meet the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), and the Information Privacy Principles (IPPs) under the Privacy Act 2020 (NZ). Where those laws differ, we apply the standard that gives you the greater protection.

1. Who this policy is for and our role

  1. 1.1

    This policy is for everyone whose personal information we may handle, including:

    1. photographers who hold an account with us;
    2. the photographers’ clients, leads and prospective clients;
    3. people who appear in photographs or videos uploaded to our platform (including children);
    4. people who view or interact with a gallery;
    5. people who buy a Client Vault keepsake; and
    6. people who report content to us.
  2. 1.2

    We handle information in two different capacities:

    Information we are responsible for

    For a photographer’s own account, business and billing information, and for things we do across the platform (such as security, fraud prevention, and meeting our legal obligations), we decide how the information is handled and we are responsible for it.

    Information we handle for a photographer

    For information a photographer enters or uploads about their own clients, leads, gallery viewers and the people in their photographs, the photographer decides how it is used, and we hold and process it on the photographer’s behalf as part of providing our service to them. In that situation the photographer is the business you primarily deal with, and some requests (for example about access or deletion) may need to be directed to, or actioned by, the photographer. We explain how we help with this in clause 12.

  3. 1.3

    This split also affects how we handle a data breach, which we explain in clause 14.

2. The kinds of personal information we collect

  1. 2.1

    The personal information we collect depends on who you are and how you use our service. The table below summarises the main categories. Not all of it applies to every person.

    The kinds of personal information we collect
    CategoryWhat it can includeWhose information
    Photographer account and businessName, business name, email, phone, password (stored in hashed form), business and branding details, ABN, custom domain and DNS records, and API access tokens the photographer creates.Photographers
    Billing and paymentSubscription and Client Vault billing status and Stripe customer, subscription and payment references; a photographer’s bank account or PayID details used to receive payments from their own clients; a business client’s ABN on invoices; and records of manual (cash or bank) payments. We never hold full card numbers – card details are entered directly with Stripe.Photographers; their clients
    Clients and leadsNames, contact details, notes, and booking, quote and invoice records (such as shoot type, date, location and amounts), entered by the photographer into their client records.Photographers’ clients and leads
    Form and enquiry submissionsEnquiries through an embeddable enquiry form (name, email, phone, message); public booking and waitlist requests (name, email, phone, preferred times and an optional note, encrypted at rest); questionnaire answers (free text authored by the client); and an email address a gallery viewer leaves to be told when a download is ready.Photographers’ clients, leads and viewers
    E-signing evidenceFor the contract e-signing feature: the signer’s name and email, their typed signature and consent confirmation, the IP address and browser user-agent at the moment of signing, and the signed PDF – kept as evidence under electronic-transactions law.People who sign a photographer’s document
    Photographs and videosThe photographs and videos uploaded by photographers. These are personal information because they show identifiable people, and they may include children. Location metadata is stripped from every client-reachable copy of a photograph, unless the photographer chooses to keep it for a gallery, in which case a full-resolution download retains the metadata embedded in the file. Video files keep the metadata embedded in them, which can include location data.People in photographs, including children
    Email delivery and engagementWhether emails we send were delivered, bounced, opened or clicked. Account and security emails carry no open or click tracking.Recipients of platform email
    Calendar connectionA photographer’s external calendar subscription URL (stored encrypted) and the resulting busy-time blocks only – never event titles or details.Photographers
    Security, device and log dataLogin-device records (via a hashed cookie), IP addresses, browser user-agent, coarse location derived from IP address, captcha outcomes, and an append-only audit log. IP addresses and user-agents are removed after 90 days unless a legal hold applies.Anyone who uses the service
    AnalyticsProduct analytics on how photographers use the platform (photographers are identified); anonymous usage events for gallery visitors (page views and interactions, with no profile created); and masked session replay (typed input is masked, but what was on screen – which can include the photographs or videos in a gallery – may be reproduced).Photographers; gallery visitors
    Abuse reports and Client VaultA reporter’s email address (encrypted) when content is reported; and, for the Client Vault, a purchasing consumer’s verified email and a fallback contact email.Reporters; Client Vault consumers
  2. 2.2

    We do not collect identification documents, health records, or precise (GPS) location data. Where a photographer enables card payments, Stripe collects their identity-verification information directly, and we receive only the account identifier and its readiness status.

3. Sensitive information

  1. 3.1

    Sensitive information (as defined in the Privacy Act 1988 (Cth)) includes information about a person’s health, race, religious beliefs, sexual orientation and similar matters. We do not deliberately collect sensitive information, and we do not ask for it.

  2. 3.2

    However, professional photography and videography of people is our core content, and photographs, videos and free-text fields can incidentally reveal sensitive information – for example, a wedding photograph may show religious observance, or a client note may mention something personal. Photographs of children (newborn, family and child portraiture) are a normal part of our photographers’ work. We treat this information carefully, and we do not classify people or build profiles of them, or make decisions based on it.

  3. 3.3

    We do not perform facial recognition and we do not extract biometric information from photographs or videos. Photographers warrant to us, under their terms, that they hold the consents and model releases needed for the people in their photographs, including parental consent for any child.

4. Children’s information

  1. 4.1

    Photographs of children are a normal part of our photographers’ work. Newborn, maternity, family and child portraiture all involve images or videos of children, and our platform holds those images or videos because photographers upload them to deliver to their clients.

  2. 4.2

    We do not knowingly collect personal information directly from children, and our platform is not designed for or directed at children. Accounts are for photographers, who must be at least 18.

  3. 4.3

    Where we hold information about a child, we almost always hold it on behalf of a photographer (see clause 1.2). The photographer decides how it is used, and warrants to us that they hold the consents needed for the people in their photographs, including the consent of a parent or guardian for any child.

  4. 4.4

    We do not use images or videos of children to build profiles, we do not perform facial recognition or extract biometric information, and we do not advertise to children or to anyone shown in a photograph. Our scanning of uploads against databases of known abuse imagery uses a mathematical hash only, never the image itself. For a video, we sample frames from it and match a hash of each sampled frame in the same way, and only the hash is used, never the video itself.

  5. 4.5

    If you are a parent or guardian and you have a concern about a photograph of your child, or you want it accessed, corrected or removed, you can contact us at [email protected] or contact the photographer. We will help route your request to the right place, and clause 12 explains how we handle requests of this kind.

5. How we collect personal information

  1. 5.1

    We collect personal information in the following ways:

    1. Directly from photographers – when they sign up, set up their account, and use the platform.
    2. Indirectly, from photographers, about other people – when a photographer enters their clients’ or leads’ details into their client records, or uploads photographs of people. In these cases we usually collect the information from our customer (the photographer) rather than from the individual concerned.
    3. Directly from individuals, through forms we host – enquiry forms, public booking and waitlist pages, questionnaires, contract-signing pages, and download-notification prompts. When someone submits an enquiry form we also automatically record anti-spam evidence (IP address, user-agent and captcha outcome).
    4. Automatically, when the service is used – through cookies, IP and user-agent logging, login-device records and analytics, as described in clause 13.
    5. From third parties – payment and status information from Stripe; email delivery events from Resend; busy-time information from a photographer’s connected external calendar; and ABN validation results from the Australian Business Register. We also receive information through email and customer support.
  2. 5.2

    Sometimes we collect information about a person from someone else rather than from that person – for example, a photographer’s client details, or a photograph of someone the photographer has taken. Two different rules apply to that:

    Australia

    Australian Privacy Principle 5 requires us to take reasonable steps to make a person aware of the collection and of the matters in this policy, whether we collect their information from them or from someone else.

    New Zealand

    Information Privacy Principle 2 requires personal information to be collected from the person concerned, unless an exception applies. Where a photographer gives us their client’s details or uploads a photograph, we rely on the exceptions that allow collection from another source – relevantly, that the person has authorised it, that collecting directly would not be reasonably practicable, or that collecting directly would prejudice the purpose of collection. Information Privacy Principle 3, which is the notice principle, applies where we collect information directly from a person, such as through the enquiry, booking, questionnaire and signing forms described above. Information Privacy Principle 3A applies a similar notice obligation where we collect information indirectly – such as a photographer’s client details or a photograph of a person the photographer has taken – and we take the reasonable steps it requires in the ways described in clause 5.3.

  3. 5.3

    However we collect it, we take reasonable steps to make the person aware of this policy. Because galleries are delivered under the photographer’s branding, we do this through a neutral privacy link shown in the gallery, and through the photographer, rather than by placing our brand in front of the photographer’s clients.

6. Why we collect, hold, use and disclose personal information

  1. 6.1

    We use personal information for the following purposes:

    1. Providing the service – hosting and delivering galleries; running the photographer’s client records, bookings, quotes and invoices; scheduling; the contract e-signing feature and keeping the required signing evidence; hosting questionnaire responses; account management and authentication; and operating the Client Vault.
    2. Billing and payments – charging for our subscriptions and the Client Vault through Stripe, generating tax-correct invoices for photographers to send their own clients, and facilitating card payment of those invoices on the photographer’s own Stripe account. We take no part of, and never hold, the funds a client pays a photographer.
    3. Communicating with you – sending transactional email such as gallery delivery, booking and invoice notifications, payment reminders, download-ready notifications, and account and security messages.
    4. Marketing to photographers – sending marketing email to photographers only, with their consent and a one-click unsubscribe. We never send marketing to a photographer’s clients. See clause 7.
    5. Referrals – attributing a referred sign-up to the ambassador who made it, so that any revenue share can be paid.
    6. Security and fraud prevention – login-device recognition, IP and user-agent logging, the audit log, and captcha and anti-spam checks.
    7. Trust, safety and legal compliance – automatically scanning uploads against databases of known abuse imagery (only a mathematical hash of an image, or of a sampled video frame, is ever sent for matching, never the image or video itself), handling reports about content, enforcing our acceptable-use rules, preserving records under a legal hold, and disclosing information to law enforcement or regulators where we are required or permitted to. This may include our staff, or trusted providers acting for us, reviewing content (including manually) where necessary for safety, to handle a report, or to meet a legal obligation.
    8. Improving the service – using product analytics and masked session replay as described in clause 13.
  2. 6.2

    We only use and disclose personal information for the purpose we collected it for, for a directly related purpose you would reasonably expect, or where you have consented or the law otherwise permits it.

  3. 6.3

    We do not sell personal information, and we do not share it for third-party advertising. We do not use our customers’ content (including photographs and videos) to train artificial-intelligence models. We do not identify, profile or advertise to gallery viewers or to the people in photographs or videos.

7. Direct marketing

  1. 7.1

    We send marketing communications only to photographers, and only where we are permitted to. Every marketing email includes a simple way to unsubscribe, and we act on unsubscribe requests promptly. We send marketing consistently with the Spam Act 2003 (Cth) and the Unsolicited Electronic Messages Act 2007 (NZ).

  2. 7.2

    We do not send marketing to a photographer’s clients, leads or gallery viewers. Where a photographer sends messages to their own clients through our platform, the photographer is responsible for having the necessary consent, and we transmit those messages on their behalf.

8. Who we disclose personal information to

  1. 8.1

    We disclose personal information to the service providers we rely on to run our platform. We require them to protect the information and to use it only for the purposes we engage them for. The main providers are set out below.

    Our main service providers
    ProviderWhat we use it forWhere it is processed
    NeonApplication databaseAustralia (Sydney)
    Fly.ioApplication hostingAustralia (Sydney)
    Cloudflare R2Storage of uploaded photographs, videos and galleriesUnited States and globally (see clause 9)
    CloudflareContent delivery, security and captcha (Turnstile)United States and globally
    StripePayment processing for our subscriptions, the Client Vault, and photographers’ client payments (Stripe Connect)United States
    ResendSending our emails and reporting delivery eventsUnited States
    PostHogProduct analytics and masked session replayEuropean Union
    Arachnid ShieldHash-only matching of uploads against known child sexual abuse material databases (only a hash is sent, never the image or video; for a video, hashes of sampled frames)Canada
    Australian Business RegisterValidating Australian photographers’ ABNsAustralia
  2. 8.2

    We also disclose personal information to law enforcement agencies, regulators, courts and other authorities where we are required or permitted to by law, or to protect people’s safety. And if our business is sold or restructured (for example, when the business is transferred to Tellisto Pty Ltd), we may disclose personal information to the acquiring entity, which will remain bound by a policy at least as protective as this one.

9. Sending personal information overseas

  1. 9.1

    Some of the providers listed in clause 8 are located or incorporated outside Australia and New Zealand, as shown in the table. This means personal information may be disclosed to, stored in, or accessed from countries including the United States and the countries in which those providers operate.

  2. 9.2

    In particular, we store uploaded photographs, videos and galleries on infrastructure operated by Cloudflare, a company incorporated in the United States with a global network. That infrastructure honours only a best-effort location preference for the Oceania region, and we do not claim, and cannot guarantee, that photographs or videos are stored only in Australia or New Zealand. We do not claim Australian or New Zealand data residency for photographs or videos, and the laws of other countries, including United States lawful-access laws, may apply to that infrastructure. We say this plainly rather than imply a level of protection the infrastructure does not provide.

  3. 9.3

    Australia

    Before we disclose personal information to an overseas recipient, we take the steps that are reasonable in the circumstances, as Australian Privacy Principle 8 requires, to ensure the recipient does not breach the Australian Privacy Principles. We remain accountable under the Privacy Act 1988 (Cth) for what those recipients do with the information. We do not ask you to consent to overseas disclosure as a way of removing that accountability.

  4. 9.4

    New Zealand

    Where we send personal information to a provider outside New Zealand to hold or process it on our behalf as our agent, and that provider does not use it for its own purposes, that is not a disclosure under Information Privacy Principle 12. We stay responsible for the information, and we require those providers to protect it. Where Information Privacy Principle 12 does apply to a disclosure, we make the disclosure only on a basis that principle allows – usually because the recipient is subject to privacy laws that provide comparable safeguards, or has agreed to protect the information in a way that provides comparable safeguards.

10. Storing and protecting personal information

  1. 10.1

    We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps include encrypting several sensitive fields at rest, stripping location metadata from every client-reachable copy of a photograph (except where the photographer chooses to keep it for a gallery, and except for video files, which keep their embedded metadata), hashing passwords and login-device cookies, access controls, and keeping an append-only audit log.

  2. 10.2

    No method of electronic storage or transmission is completely secure, so we cannot guarantee absolute security. We keep personal information only for as long as we need it, as described in clause 11.

11. How long we keep personal information

  1. 11.1

    We keep personal information for as long as we need it for the purpose we collected it, and then we take reasonable steps to delete or de-identify it. In practice:

    1. IP addresses and browser user-agent records are removed after 90 days, unless a legal hold applies to them.
    2. We keep a minimal, append-only audit skeleton (a record that an event occurred, without the underlying content) for longer, so that we can meet our security, accountability and legal obligations.
    3. Account, client and gallery information is kept while the relevant account or keepsake is active, and is deleted or de-identified after it ends, subject to any legal hold and to the Client Vault lifecycle in the Client Vault terms.
    4. Signing evidence for the e-signing feature is kept as a record for as long as needed under electronic-transactions law.
  2. 11.2

    A legal hold is where we are required, or reasonably need, to preserve particular records – for example, in connection with a safety matter, a dispute, or a request from a court, regulator or law enforcement agency. Where a legal hold applies, we preserve the relevant records and do not delete them, even where they would otherwise be deleted or where a deletion request has been made (see clause 12).

12. Accessing, correcting and deleting your personal information

  1. 12.1

    You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is wrong, out of date, incomplete or misleading. These rights reflect Australian Privacy Principles 12 and 13 and Information Privacy Principles 6 and 7.

  2. 12.2

    You can also ask us to delete personal information we hold about you. We will action a valid deletion request unless we are required or permitted to keep the information – for example, where a legal hold applies (clause 11.2), or where we need it to meet a legal obligation, resolve a dispute, or enforce our terms. If we cannot delete something, we will tell you why.

  3. 12.3

    If you are a photographer’s client, lead, gallery viewer, or a person in a photograph, we usually hold your information on behalf of the photographer (see clause 1.2). In that case, the quickest path is often through the photographer, and we may need to refer your request to them or ask them to action it. We will help route your request to the right place.

  4. 12.4

    To make a request, contact us at [email protected]. We may need to verify your identity first. We will respond within a reasonable time and within any period required by law, and we do not charge a fee for making a request (though a reasonable charge may apply for giving access in some cases).

13. Cookies and analytics

  1. 13.1

    We use a small number of first-party cookies: a login session cookie, a gallery viewer session cookie, and a device-recognition cookie (stored as a hash) that helps keep logins secure. We use Cloudflare Turnstile for captcha, to tell humans from bots.

  2. 13.2

    We use PostHog (hosted in the European Union) for product analytics and session replay. Photographers are analysed as identified users. Gallery visitors are recorded only as anonymous usage events (page views and interactions) – no profile is created and no attempt is made to identify them. Session replay masks all typed input, but can reproduce what was shown on screen, which may include the photographs or videos displayed in a gallery during a session.

  3. 13.3

    We record delivery, open and click events for the service emails we send, so that photographers can see whether their client received an email and so we can monitor our sending health. Account and security emails are never open- or click-tracked.

  4. 13.4

    You can control cookies through your browser settings. Blocking some cookies may affect how parts of the service work, such as staying logged in.

14. If something goes wrong – data breaches

  1. 14.1

    We have processes to detect, assess and respond to data breaches. If a breach is likely to cause serious harm, we will notify the people affected and the relevant regulator, in line with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth) in Australia, and Part 6 of the Privacy Act 2020 (NZ) in New Zealand.

  2. 14.2

    Because of the two capacities described in clause 1.2, a breach is routed according to who is responsible for the information. Where a breach affects information we hold on a photographer’s behalf, we notify the photographer so that they can meet their own obligations, and we assist them. Where a breach affects information we are responsible for, we assess and notify as required.

15. Complaints

  1. 15.1

    If you have a concern or complaint about how we have handled your personal information, please contact us first at [email protected]. We will take your complaint seriously and aim to resolve it promptly.

  2. 15.2

    If you are not satisfied with our response, you can complain to the relevant regulator. In Australia, that is the Office of the Australian Information Commissioner (www.oaic.gov.au). In New Zealand, that is the Office of the Privacy Commissioner (www.privacy.org.nz).

16. Changes to this policy

  1. 16.1

    We may update this policy from time to time, for example to reflect changes to our service, our providers, or the law. When we make a change, we update the effective date at the top, and where a change materially affects your rights we take reasonable steps to bring it to your attention. The current version is always available on our website.

17. How to contact us

  1. 17.1

    For any privacy question or request, or to reach the person responsible for privacy at Tellisto, contact us at:

    Tellisto

    Email: [email protected]

    Post: PO Box 313, Erskineville NSW 2043