Privacy Policy
| Title | Privacy Policy |
| Doc# | POL-DATA-022 |
| Version | 1.0 |
| Date | 08-01-2023 |
This is Tessera’s external Privacy Policy. It explains how Tessera Pty Ltd (“Tessera”, “we”, “us”, “our”) collects, uses, holds and discloses personal information, and how you can access and correct it. Tessera is an Australian company (head office St Georges Terrace, Perth WA 6000) that operates a managed, multi-tenant cloud platform for business customers.
We handle personal information as an APP entity under the Privacy Act 1988 (Commonwealth) and the Australian Privacy Principles (APPs). Where a customer is located in the European Union, the GDPR Data Processing Addendum (POL-DATA-000) applies alongside this policy.
Last updated: 4 March 2025.
A note on our role. Tessera is usually two things at once. We are the APP entity (the business responsible for the data) for the personal information we collect directly to run our commercial relationship with a customer — the account, contact, billing and usage information described below. We are also a service provider (a processor) for the personal information that a customer chooses to put through the Tessera platform — for example records the customer uploads, or contacts the customer captures in the platform. That customer-controlled data is governed by the customer’s own privacy policy and, in the EU, by the DPA referenced above. This policy covers the personal information for which Tessera is itself responsible.
The table below summarises what follows. Each row links to the relevant section.
| Topic | Summary |
|---|---|
| Information we collect | Account and contact information, usage and device information, and billing information we collect to provide and run the Services. |
| How we use your information | To provide, maintain and secure the Services, to communicate with you, to bill you, and to meet our legal obligations — the uses permitted by APP 6. |
| How we share your information | With service providers and sub-processors who help us run the Services, and where required by law. We do not sell personal information. |
| International transfers | Data is processed primarily in Australia. Some sub-processors operate outside Australia under the safeguards required by APP 8. |
| Security | How we protect personal information (APP 11), including TLS in transit and AES-256 at rest. |
| Your rights: access and correction | How to access and correct your personal information under APP 12 and APP 13. |
| Retention | How long we keep personal information, and when we delete it (APP 11.2). |
| Cookies and similar technologies | The cookies and similar technologies we use, and how to control them. |
| Children | The Services are business services and are not directed at children. |
| Changes to this policy | How we update this policy and tell you about material changes. |
| Contact and complaints | How to reach our Privacy team, and how to complain to the OAIC. |
Information we collect
We collect the personal information we reasonably need to provide and run the Services. The main categories are below.
Account and contact information. When a customer sets up an account, and when authorised users are added to it, we collect:
- name,
- work email address,
- a password (stored only as a salted hash),
- job title and department,
- the name of the customer organisation, and
- a phone number.
We also collect correspondence and attachments you send us when you contact support, sales or accounts.
Usage and device information. When the Services are used we automatically collect the operational information needed to run and secure the platform:
- account identifiers and audit-trail entries (logins, configuration changes, administrative actions);
- IP address, browser type and version, operating system, and device type;
- information about how the Services are used, such as the features invoked, pages viewed and timestamps; and
- error, performance and security telemetry used to keep the platform available and to investigate incidents.
We collect this from the platform itself and from our infrastructure providers (for example, AWS CloudTrail logs recorded in the ap-southeast-2 Sydney region).
Billing information. To issue invoices and take payment we collect:
- billing contact name and email address;
- the customer organisation’s billing address and ABN/ACN where applicable;
- purchase-order references; and
- credit-card details, which are handled entirely by our payment-services provider. We do not store full card numbers on Tessera systems.
Information we do not actively collect. The Services are general-purpose business tools. Whether any sensitive information within the meaning of APP 3.3 (health information, racial or ethnic origin, political or religious beliefs, and so on) enters the platform is a matter for each customer. We do not deliberately collect sensitive information about individuals through the Services, and customers should not configure the platform in a way that requires sensitive information to be collected without their own privacy basis for doing so.
How we use your information
We use and disclose personal information for the purposes for which it was collected (the primary purpose), and for directly related secondary purposes, in accordance with APP 6. Those purposes are:
- to set up, operate, maintain and secure customer accounts and the Services;
- to provide technical support and respond to enquiries;
- to bill customers and to manage the commercial relationship;
- to communicate about the Services, including service notifications, security advisories and planned maintenance;
- to detect, prevent and investigate fraud, abuse and security incidents;
- to produce aggregated and de-identified analytics used to improve the Services; and
- to meet our legal, regulatory and accounting obligations.
We will not use personal information for an unrelated purpose unless you consent, or we are required or authorised by law to do so.
Direct marketing. We may send existing customers information about Tessera products that relate to the Services they already use. You can opt out at any time using the unsubscribe link in any marketing email or by contacting privacy@tessera.locoensayo.org. We do not share personal information with third parties so they can market to you independently.
International transfers
The Services are hosted primarily in Australia, in the ap-southeast-2 (Sydney) AWS region, with cross-region standby for resilience. Some of our sub-processors operate from outside Australia — for example, where a specialist provider runs its service from the United States or the European Union.
A cross-border disclosure under APP 8 requires a reasonable step to ensure the overseas recipient does not breach the APPs. We rely on a combination of: contractual safeguards (in particular the EU Standard Contractual Clauses where a sub-processor is in a country without an adequacy finding, and Tessera’s own sub-processor data-protection terms); the Privacy Shield framework for covered transfers; and, where appropriate, your consent.
[Reviewer, 2025-04-08: the sentence above still names the Privacy Shield framework. Privacy Shield was invalidated in 2020 and Tessera is not certified under the EU-US Data Privacy Framework that replaced it. Strike the Privacy Shield reference before the next public refresh — for non-adequate countries we rely on the SCCs and our sub-processor terms, not on Privacy Shield. — I. Ferreira]
If you are an individual whose information may be processed outside Australia and you would like more detail before consenting, contact privacy@tessera.locoensayo.org.
Security
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, as required by APP 11. The controls in place include:
- encryption of personal information in transit using TLS, and at rest using AES-256;
- separation of the management plane from tenant data stores, and least-privilege access enforced through our identity provider and AWS IAM;
- multi-factor authentication for administrative access;
- logging and monitoring of authentication and control-plane activity; and
- an information security management system aligned to ISO/IEC 27001:2022 and the ASD Essential Eight.
No online service can be made completely secure. If a data breach occurs and is assessed as an eligible data breach under the Notifiable Data Breaches scheme, we will notify affected individuals and the OAIC as required by Part IIIC of the Act. You can read more about our security practices on our security page and in our data protection policy.
Your rights: access and correction
You have the right to access personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. These rights sit in APP 12 (access) and APP 13 (correction).
To make a request, contact privacy@tessera.locoensayo.org. We will respond within a reasonable period — generally within 30 days — and will not charge for making an access or correction request, although we may recover a reasonable cost where a request is unusually broad. Before giving access we will take reasonable steps to confirm your identity.
Where we hold personal information only as a processor on behalf of a customer, access and correction requests for that data should be directed to the customer that controls it; we will help the customer respond.
Retention
We keep personal information only for as long as it is needed for the purpose for which it was collected, or as required to meet our legal and accounting obligations (APP 11.2). In practice:
- account and contact information is retained while the account is active, and for the period needed to close out the relationship afterwards;
- usage and security telemetry is retained for the operational and security period defined in our Data Lifecycle and Classification Policy; and
- billing and tax records are retained for the period required by Australian tax law.
When information is no longer required we delete it or de-identify it, subject to any legal hold.
Children
The Services are business services and are not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, contact privacy@tessera.locoensayo.org and we will take steps to delete it.
Changes to this policy
We review this policy regularly and will post updates on this page. Where a change is material we will give affected customers prominent notice — for example by email or an in-product notification — before the change takes effect. We last materially updated this policy on 18 November 2024. Past versions are retained on request.
Contact and complaints
If you have a question, a request, or a complaint about how we have handled personal information, contact our Privacy team:
- email: privacy@tessera.locoensayo.org;
- post: Privacy Team, Tessera, St Georges Terrace, Perth WA 6000; or
- via your customer success manager.
We will acknowledge complaints promptly and aim to resolve them within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
- online at www.oaic.gov.au, or
- by phone on 1300 363 992.
Making a complaint to the OAIC is free.
Document status: v1.0. Last updated 4 March 2025. Next scheduled review: 4 March 2026.