Home / Privacy Policy
Legal

Privacy Policy Privacy Policy

Last updated: 2 October 2026

About this policy

Tell Media Pty Ltd (ABN 69 167 561 168) is a digital marketing and reporting agency. In this policy, "Tell Media", "we", "us" and "our" mean Tell Media Pty Ltd.

This policy explains how we collect, hold, use and disclose personal information. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). The policy applies to visitors to tellmedia.com.au, our clients and prospective clients, their staff and customers whose information we handle while working for them, and suppliers.

You can contact us about privacy at privacy@tellmedia.com.au or through the contact form on this website.

Personal information we collect

We only collect personal information we need for our services and business. Depending on how you deal with us, this may include:

  • Contact details: name, business name, job title, email, phone and address.
  • Account and billing details: ABN, invoicing contacts and payment records. We don't store full card numbers.
  • Communications: emails, messages, call notes and meeting notes.
  • Website and advertising data: IP address, device and browser type, pages visited, and cookie or pixel identifiers.
  • Client business data: when a client engages us, we may handle personal information inside their systems, such as customer names, emails, phone numbers and purchase history in sales, point-of-sale, ecommerce, advertising and accounting platforms.

We don't intend to collect sensitive information (such as health, religious or political details). If it reaches us incidentally inside client data, we don't use it for any purpose.

You can deal with us anonymously or under a pseudonym where that's practical, for example when making a general enquiry. We usually can't provide services that way.

How we collect it

Most personal information comes directly from you: when you contact us, fill in a form, sign up to our emails, or work with us as a client or supplier. We also collect it:

  • Automatically through cookies, analytics and advertising pixels when you use our website.
  • From our clients, through systems they authorise us to access (for example their ad accounts, ecommerce store, POS system or accounting software). The client is responsible for having told its own customers and staff that this can happen.
  • From public sources, such as business directories, LinkedIn and company websites, when researching prospective clients.

If we receive personal information we didn't ask for and don't need, we destroy or de-identify it as soon as practical.

Why we collect, use and disclose it

We use personal information to:

  • Respond to enquiries and provide quotes.
  • Deliver our services: running advertising, measuring results, uploading conversions to ad platforms, and building reports for clients.
  • Manage client accounts, invoicing and payments.
  • Send our newsletters and marketing, if you've agreed or would reasonably expect it.
  • Improve our website and services.
  • Meet our legal, tax and record-keeping obligations.

We only use or disclose personal information for the purpose we collected it for, a related purpose you'd reasonably expect, or as the law permits or requires. We do not sell personal information.

Client data and accounting software integrations

When a client engages us, we handle data in their systems on their behalf and only on their instructions. We use it only to deliver the services they've asked for, never for our own marketing, and we never sell or share it with other clients.

Accounting integrations (such as MYOB). Some clients authorise us to connect to their accounting software so we can produce financial, stock and marketing-return reports. For these integrations:

  • The client's administrator authorises access through the software's own secure sign-in (OAuth 2.0). We never ask for or store their accounting login password.
  • Access is read-only. We do not create, change or delete anything in the client's accounting file.
  • We request only the data areas we need (for example accounts, sales, purchases, inventory, banking and contacts), and never payroll or employee records.
  • Extracted data is used only to produce that client's reports and is stored in accounts the client controls or approves.
  • The client can withdraw access at any time from within the accounting software, or by asking us. We then stop all access and delete the stored access tokens and extracted data within 30 days, unless the client asks us to keep reports or the law requires otherwise.

AI tools and automated processing

We use AI tools, mainly Anthropic's Claude, to run reporting scripts, analyse client data and draft reports and recommendations. We keep the setting that lets AI providers use our conversations to train their models switched off. We only use paid AI accounts that we control, never free public AI tools.

Reports and recommendations produced with AI are reviewed by a person before they go to a client. We do not use personal information to make decisions that significantly affect individuals' rights or interests using a computer program alone. Automated processing is limited to things like matching store sales to advertising conversions and building aggregated reports. If that changes, we'll update this policy to describe the kinds of personal information and decisions involved.

Who we share it with

We share personal information only with service providers that help us deliver our services, and only what each one needs. They're bound by their own privacy and security terms, and we choose providers with strong security practices. Our main providers are:

  • Anthropic (Claude) – AI analysis and reporting scripts (United States)
  • Google (Workspace, Analytics, Ads) – email, documents, website analytics and advertising (United States and other countries)
  • Meta (Facebook, Instagram) – advertising and conversion measurement (United States and other countries)
  • Microsoft Advertising – advertising (United States and other countries)
  • Dropbox – file and credential storage (United States)
  • Make.com – workflow automation and encrypted token storage (European Union / United States)
  • Klaviyo and Shopify – client email marketing and ecommerce work (United States / Canada)
  • Ad and reporting connectors (such as Pipeboard and Adspirer) – reading client ad account data (United States)
  • Client systems (such as MYOB and POS software) – data the client authorises us to read (usually Australia)

We may also disclose information to our professional advisers (accountants, lawyers), or where the law requires, such as to a regulator or court.

Overseas disclosure

Some of our service providers store or process information outside Australia, mainly in the United States, and also in the European Union, Canada and other countries where those providers run their data centres (see the list above).

Before we use an overseas provider, we take reasonable steps to make sure it handles personal information in a way consistent with the APPs, for example through its contractual privacy and security commitments. Where a client requires their data to stay in Australia or New Zealand, we'll agree that with them in writing before we start.

How we protect it

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, change or disclosure. These include:

  • Multi-factor authentication on every account that can reach client or personal data.
  • Encryption in transit (TLS 1.2 or higher) for all connections to client systems and providers.
  • Encryption at rest on the storage we use, and API keys and access tokens kept encrypted (AES-256), separately from their encryption keys. Tokens and credentials are never put in web addresses or shown in reports.
  • Least-privilege access: read-only access to client systems wherever possible, and access limited to the people who need it.
  • Access logs: for client system integrations, we record each access (date and time, process, action, success or failure) and keep those logs for at least 12 months.
  • Monitoring and review: we watch for unusual activity, review access regularly, and remove access we no longer need.

No system is completely secure, but we work to keep risks low and act quickly if something goes wrong.

How long we keep it

We keep personal information only as long as we need it for the purpose we collected it, or as the law requires. Then we securely delete or de-identify it.

  • Business and financial records (invoices, contracts): 7 years, as tax law requires.
  • Client data from integrations: for the length of the engagement. Access tokens and extracted data are deleted within 30 days after access is withdrawn or the engagement ends, unless the client asks us to keep reports.
  • Integration access logs: at least 12 months.
  • Marketing contacts: until you unsubscribe, or after 2 years of no contact.

Marketing, cookies and analytics

We send marketing emails in line with the Spam Act 2003. Every message identifies us and has an unsubscribe link, and we act on unsubscribe requests within 5 business days.

Our website uses cookies and similar technologies, including Google Analytics, Google Ads and the Meta pixel. We use them to understand how the site is used and to show relevant ads on other sites. You can:

  • Block or delete cookies in your browser settings. Some parts of the site may not work properly.
  • Opt out of Google Analytics with the Google Analytics opt-out add-on.
  • Manage ad personalisation in your Google and Meta settings.

Our website and services aren't directed at children under 18, and we don't knowingly collect their personal information.

Access, correction and your choices

You can ask for a copy of the personal information we hold about you, or ask us to correct it, by contacting us (see below). We'll confirm who you are, respond within 30 days, and won't charge for making a request.

If we refuse access or correction, we'll tell you why in writing and how to complain. If your information is held in a client's system (for example as one of their customers), we may refer you to that client, since they control it.

Data breaches

If we suspect a data breach, we act straight away to contain it and assess the risk. If it's likely to cause serious harm, we notify the people affected and the Office of the Australian Information Commissioner (OAIC) under the Notifiable Data Breaches scheme.

If a breach involves a client's data, we tell that client promptly so they can meet their own obligations. Where the data came from a software platform's API (for example MYOB), we also notify that platform as its developer terms require.

Complaints, contact and changes

If you have a question or complaint about how we've handled your personal information, contact us first:

We'll acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you're not satisfied with our response, you can complain to the Office of the Australian Information Commissioner on 1300 363 992.

We review this policy at least once a year and when our practices change. The current version is always on our website, and we'll tell clients directly about significant changes.