Viya Marketing

Privacy Policy

Version 4 · current · effective 24 Sept 2026 · published 23 September 2026, 11:12 pm

What changed: Added one Facebook permission (Business Manager access) to the list we request, so we can find and publish to Pages that are managed through a Facebook Business Manager. No change to what we do with your data.

Who we are This platform is operated by THE GREAT LEARNING TREE PTY LTD (ABN 28 145 031 563) ("we", "us"). This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it, and how you ask us to delete it. We handle personal information in line with the Australian Privacy Principles set out in the Privacy Act 1988 (Cth). Questions about this policy, or about the information we hold: hello@viyamarketing.com.au. What we collect from you directly When someone signs up, or is invited into a workspace, we collect the details needed to run the account: • Name, email address and role within the workspace • Business details — trading name, address, opening hours, services, brand facts • Content uploaded to or created in the workspace, including images and video • Billing contact details and subscription records • A record of every material action taken in the workspace — who approved what, and when What we collect from connected Meta accounts Connecting a Facebook Page or Instagram account is optional, and is done by the person who administers it, through Facebook Login. We request the permissions pages_show_list, business_management, pages_manage_posts, instagram_basic, instagram_content_publish, pages_read_user_content, pages_read_engagement and pages_manage_engagement. What we take, why, and how long we keep it: • Page access token — So that approved content can be published to the Page without asking the owner to log in each time. Kept: Encrypted at rest (AES-256-GCM) for as long as the connection is active. Deleted when the connection is removed. • Page identifier, Page name and the list of Pages the person administers — So that the right Page can be chosen and shown in the product. Kept: For as long as the workspace is active. • Content published on the Page's behalf, and its Meta post identifier — So the product can show what was published, when, and link back to it. Kept: For as long as the workspace is active. • Engagement and Page insight metrics for that content — So the product can report on how published content performed. Kept: For as long as the workspace is active. • Lead form submissions, where a client connects lead ads — So enquiries reach the business that paid for the advertising. Kept: For as long as the workspace is active, unless deletion is requested sooner. Every channel we can connect, and what each one collects This lists every channel the platform knows about — including the ones it cannot connect to at all, so you can see what is and is not touched: • Facebook — we collect the Page name and id, the list of Pages the person administers, a Page access token, the posts we publish for you and their Meta post ids, and engagement and Page insight metrics for those posts. • Instagram — we collect the Instagram Business account linked to your Facebook Page - its id and username - and, once publishing is permitted, the posts we publish for you and their Instagram media ids. • Google Business Profile — not connected. Nothing is collected from it. • TikTok — we collect your TikTok account's open id, display name and avatar, an access token that lets us post on your behalf, and the posts we publish for you. • Email — we collect the recipient addresses you supply or import, the messages we send for you, and whether each was delivered, opened or clicked. • LinkedIn — not connected. Nothing is collected from it. • YouTube / Shorts — not connected. Nothing is collected from it. • Threads — not connected. Nothing is collected from it. • X — not connected. Nothing is collected from it. • Pinterest — not connected. Nothing is collected from it. • SMS — not connected. Nothing is collected from it. • WhatsApp / RCS — not connected. Nothing is collected from it. • Website / blog / CMS — we collect the site address and the credential or token you connect with, and the pages and posts we publish for you. How we use this information We use it to run the service you asked for: to draft marketing content, to route it to the right person for approval, to publish approved content to the accounts you connected, to report on how it performed, and to bill for the service. Drafts are generated with AI assistance. Nothing is published without a person approving it first. We do not sell personal information. We do not use the content or business data in a workspace to train AI models. AI processing When an AI-assisted feature uses an external provider, we send the provider the text and business context used for that task. Depending on the feature, this may include company and brand facts, content briefs or drafts, comments or reviews being answered, and image-generation prompts. Comments, reviews and free-text briefs can contain customer personal information; if they do, that information may be sent to the provider for the task. When a generated image is checked by an AI provider, that provider also receives the image and the recorded subject, menu and dietary-constraint context. Who we share it with We share personal information with the service providers (sub-processors) that run parts of the platform, and only for the purpose named: • Supabase — Database and file storage for the platform. Receives: Account records, client business data, content, encrypted platform tokens, audit records. • Vercel — Application hosting and delivery. Receives: Request metadata, IP addresses, and anything submitted through the application in transit. • Anthropic Claude — Generating draft marketing copy. Receives: The business details and brand facts supplied for a draft. Drafts are reviewed by a person before anything is published. • Replicate — Generating draft images. Receives: Image prompts derived from the business's brand facts. • Runway — Generating draft video. Receives: Video prompts and reference imagery supplied for a clip. • Resend — Sending transactional email — approval requests, reports, sign-in links. Receives: Recipient name and email address, and the content of the message. • Stripe — Subscription and payment processing. Receives: Billing contact details and payment records. Card numbers are handled by Stripe directly and are never stored on this platform. • Meta Platforms — Publishing to, and reading engagement from, a connected Facebook or Instagram account. Receives: The content published on the account's behalf, and the Page identifiers needed to publish it. • Google Business Profile API — Publishing updates to a connected Google Business Profile. Receives: The content published on the profile's behalf, and the profile identifiers needed to publish it. Where it is stored Data is stored with the providers listed above, which operate infrastructure outside Australia. Using this platform means personal information may be handled overseas by those providers. How long we keep it Account and workspace data is kept for as long as the workspace is active. When a workspace closes, we delete platform access tokens immediately and remove workspace content within 90 days, allowing for copies held in routine backups to age out. Records of who approved what, and when, are kept for 7 years. They are the evidence that published content was approved, and they cannot be edited after the fact. How we protect it Platform access tokens are encrypted before they are stored. Access to a workspace is restricted to the people assigned to it, and every material action is recorded in an append-only audit log. No system can promise that data is never at risk. If a breach affects personal information we hold, we will act on it and notify affected people where we are required to. Accessing, correcting and deleting your information You can ask for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Write to hello@viyamarketing.com.au and we will respond within 30 days. Full instructions, including how to disconnect this app from your Facebook account, are on the data deletion page: /data-deletion Revoking access to a connected account You can remove this app's access to your Facebook or Instagram account at any time from Facebook Settings, under Business Integrations. Doing so stops us publishing to that account and revokes the access token. Complaints If you are not satisfied with how we have handled your personal information, contact us at hello@viyamarketing.com.au. You may also complain to the Office of the Australian Information Commissioner at oaic.gov.au. Changes to this policy When this policy changes, the new version is published here with its effective date, and previous versions stay available in the archive below.

Version archive

Previous published versions with effective and published dates.