Privacy Policy – Passtab

This Privacy Policy describes how we at Invision Marketing Services (IMS) collect, use, and manage Personal Information (PI) that is collected and stored using Passtab.

Customers that are located within the European Union, click here to see our EU Privacy Notice.

Introduction

Passtab is used to collect and collate information about visitors, staff, contractors, students and others (Registrants) who arrive at and/or depart from premises of an organisation.

Passtab has an Administrator and a Visitor Module. The Administrator can access PI via web browser-enabled devices, including computers, tablets, and smartphones. The Visitor Module is used to record arrivals, departures, and movements of Registrants.

Collection of Personal Information (PI)

We collect PI when we create a Passtab Administrator. We collect:

a. Account name
b. Email address
c. Password
d. Organisation name and address
e. Contact Phone Number
f. Contact Name

The school or organisation collects PI when a Registrant uses the Visitor Module to register arrival or departure from premises. The Administrator (not IMS) determines what information is collected; depending on category of Registrant, it may typically include but is not limited to:
a. Arrival and departure time
b. Category of Registrant
c. The access point for arrival and departure
d. A PIN associated with a Registrant
e. Employer (if a contractor)
f. Reason for visit
g. Electronic signature
h. Photo image
i. Phone number
j. Certificate expiry date
k. Items booked out to the Registrant

Sensitive Personal Information

The Passtab service may be used by schools or organisations to record and manage sensitive personal information where required for operational purposes, such as first aid documentation. This may include health or medical information entered by authorised users.

Purpose of Collection

Sensitive personal information is processed exclusively to meet the specific safety, compliance, and operational requirements defined by the Customer (school or organisation). Passtab does not use sensitive personal information for marketing, advertising, or any profiling/analytics outside of the Customer’s configured workflow.

Collection and Control

Data Controller: Sensitive information is controlled by the school or organisation using the Passtab service. The school is responsible for determining the lawful basis for collection and for obtaining any required consents.

Data Processor: Passtab acts as a service provider (Processor) and handles this information only in accordance with the documented instructions of the school or organisation.

Access Restriction: Our authorised support personnel (including overseas staff) are restricted from accessing sensitive health or medical records via Role-Based Access Controls (RBAC), unless specifically authorised by the school to resolve a technical issue.

Storage and Security

Sensitive personal information is:

  • Stored exclusively within our secure, private AWS instances in the Sydney, Australia region.
  • Encrypted both in transit and at rest using industry-standard protocols.
  • Protected by mandatory Multi-Factor Authentication (MFA) for all administrative access.

Access and Correction

As the school or organisation maintains control over this data, individuals seeking to access, correct, or delete sensitive personal information should primarily contact the relevant school administrator. Passtab will assist schools in fulfilling these requests as required by the Privacy Act 1988 (Cth).

How we use PI

We use Administrator-related PI to manage, service, and invoice our accounts.

We may monitor system data, including limited PI to maintain optimum system performance.

In addition, Administrators (not IMS) use PI they have collected to manage their facility. This includes managing emergencies by allowing Administrators and delegated staff to view the database of Registrants who are on or off the premises.

How we manage PI

PI is stored on a secure server provided by Amazon Web Service that is physically located in Australia. Communication between the Administrator account and the server is encrypted in transit. Access to the secure server is restricted to authorised IMS personnel. Limited access to redacted or de-identified system information may be provided to authorised personnel located outside Australia for the purposes of system maintenance, technical support, or security monitoring, subject to strict confidentiality and security controls.

We do not combine PI with other data or modify it. We may disclose PI to third parties when directed by the Account Administrator or required by law or government regulation. When an account is closed, we delete its PI after one month.

We securely store the passwords for Administrators. Administrators have password-protected access to all PI relating to Registrants of their account. Administrators can also delegate password-protected access to their staff. Registrants do not have access to PI when using the Visitor Module.

Administrators can view, download and store PI. Security for viewed and downloaded data is the responsibility of Administrators. It is also the responsibility of Administrators to advise Registrants of their privacy policy in relation to viewed and downloaded data, and if necessary this Privacy Policy.

If we undergo a business restructure, merger, acquisition, sale or divestiture of all or part of our business or assets, the Personal Data processed within the Passtab platform may be made available to or transferred to a successor operator or entity as part of that transaction. We will take steps to ensure that any such disclosure and/or transfer is subject to suitable privacy and data protection safeguards, including to preserve the continuity of your account and the overall functionality of the Passtab platform as a visitor management system. Your Personal Data may become subject to a different privacy policy implemented by the new owner or entity.

Artificial Intelligence (AI)

This section applies specifically to the use of Artificial Intelligence (AI) within the service in the form of facial recognition.

Use of Facial Recognition Technology (AI Privacy Statement)

Passtab offers an optional facial recognition feature to streamline visitor sign-in and sign-out. This section explains how personal information is collected, used, and protected when this feature is enabled.

Information Collected

If enabled by the school and you choose to use the feature, we collect and process:

  • A facial photograph captured at sign-in
  • A system-generated facial identifier (Face ID string)
  • Basic account details required for identity verification

This feature does not collect behavioural, predictive, or profiling information.

Purpose of Processing

Facial images and identifiers are used solely for:

  • Identity verification during sign-in and sign-out
  • Matching repeat visitors to their existing records

This information is not used for:

  • AI model training or development
  • Marketing or advertising
  • Behavioural monitoring or profiling
  • Analytics beyond identity verification

Use of AI

Facial comparison is performed using Amazon Web Services (AWS) Rekognition, a secure managed AI service.

The system performs similarity matching only. It does not generate content, perform behavioural analysis, or make automated decisions that affect individual rights.

Passtab does not modify, train, or fine-tune the underlying AI model using customer data.

Storage and Retention

Facial data is:

  • Encrypted in transit and at rest
  • Stored within secure AWS infrastructure

Data is retained only for as long as necessary to support identity verification, in accordance with:

  • School-configured retention settings
  • Contractual obligations
  • Applicable legal requirements

Sharing of Information

Facial recognition data is processed using:

  • Amazon Web Services (AWS), which provides hosting infrastructure and facial comparison services

Personal information is not sold or shared for marketing or unrelated purposes.

Consent and Control

Use of facial recognition is optional.

  • You will be asked to opt in before your facial data is used
  • If you decline, you can continue to use standard sign-in methods
  • You may withdraw consent at any time by requesting removal of your facial data through the site administrator

Your Rights

You have the right to:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your facial data
  • Withdraw consent to the use of facial recognition

Requests can be made through the relevant site administrator or by contacting us using the details in this Privacy Policy.

Withdrawal of consent will disable facial recognition for your profile but will not affect your ability to use alternative sign-in methods.

 

 

 

Reporting Breaches of Privacy

We are committed to ensuring the privacy of all PI we collect. Certain compulsory obligations have been placed on organisations under the Privacy Act 1988 (Cth) to notify specific types of data breaches (Notifiable Data Breaches “NDB”) to individuals affected by the breach as well as to the Office of the Australian Information Commissioner (OAIC). 

In the event of a PI data breach of either Administrator Information or Registration Information, IMS will notify the party affected within 7 days of IMS becoming aware of the breach, and provide:
a. Our identity and contact details;
b. A description of the data breach;
c. The kinds of information that is suspected of being affected;
d. Recommendations about the steps you should take to limit the impact of the breach;
and
e. Advice as to whether we have contacted the OAIC about the breach.

How to access your PI

PI collected when signing in at a school or organisation is controlled by that school or organisation. Requests to access or correct that information should be made directly to them in the first instance.

Where Passtab processes PI on behalf of a school or organisation and is able to assist, we will provide reasonable assistance to support access requests in accordance with applicable privacy laws.

For a detailed list of the sub-processors used by Invision in delivering our services, please refer to our list of sub-processors.

Contact details:

Laura Hunt
General Manager
Invision Marketing Services Pty Ltd
Suite 12-17, Level/2 Brandon Park Dr, Wheelers Hill VIC 3150
Within Australia: 03 9800 1489
Outside Australia: +61 3 9800 1489
Email: laurahunt AT invision.net.au (Replace AT with @)

We will endeavour to respond to your request within three business days.

Changes to our Privacy Policy

Our Privacy Policy complies with the Australian Privacy Principles contained within the Privacy Act 1988 (Cth). We may amend this Privacy Policy to reflect changes in legislation or our business. If we amend the policy we will post the change on our website.

Response to Requests

If you are not satisfied with our response to your request for information you may wish to contact the Office of the Australian Information Commissioner:
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
www.oaic.gov.au

This privacy statement was updated on: 14/05/2026

Privacy Notice United Kingdom and European Union – Passtab

This Privacy Notice describes how we at Invision Marketing Services (Invision) collect, use, and manage Personal Data that is collected and stored using Passtab for customers in the European Union. This notice is compliant with the EU General Data Protection Regulation (GDPR).

Invision Marketing Services Pty Ltd (Invision) is a wholly owned subsidiary of Nelnet International Pty Ltd.

This Privacy Notice describes how Invision processes Personal Data both for our account holders (customers) and on behalf of our customers.

Our Relationship

For all information collected by our customers and stored using Passtab, Invision acts as a Data Processor, while the customer (the organisation or school) remains the Data Controller. Invision uses Passtab to process personal data solely in accordance with the instructions provided by our customers. This relationship is governed by the UK & EU GDPR Addendum (Data Processing Agreement) to the Passtab Terms and Conditions of use.

How Passtab is Used

Passtab is a platform used by our customers to register individuals who arrive at and/or depart from their premises. Our customers collect personal data using Passtab to identify individuals and comply with their specific entry, security, and emergency management policies.

Personal Data we collect

We collect Personal Data in accordance with instructions provided by our customers. The customer (not Invision) determines the categories of the personal data that is collected.

Depending on the requirements dictated by the security and emergency management policies of the customer, Personal Data that is collected on behalf of the customer may typically include:
• Visitor name and contact information
• Arrival and departure time
• Category of visitor
• The access point used for arrival and departure
• A PIN associated with a visitor
• Employer (if the visitor is a contractor)
• Reason for visit
• Electronic signature
• Photo image
• Information relating to certificates

When we create a customer account, we also collect the name and contact details of the customer’s nominated representative.

Sensitive Information

The Passtab service may be used by schools or organisations to record and manage sensitive personal information where required for operational purposes, such as first aid documentation. This may include health or medical information entered by authorised users.

Purpose of Collection

Sensitive personal information is processed exclusively to meet the specific safety, compliance, and operational requirements defined by the Customer (school or organisation). Passtab does not use sensitive personal information for marketing, advertising, or any profiling/analytics outside of the Customer’s configured workflow.

Collection and Control

Data Controller: Sensitive information is controlled by the school or organisation using the Passtab service. The school is responsible for determining the lawful basis for collection and for obtaining any required consents.

Data Processor: Passtab acts as a service provider (Processor) and handles this information only in accordance with the documented instructions of the school or organisation.

Access Restriction: Our authorised support personnel (including overseas staff) are restricted from accessing sensitive health or medical records via Role-Based Access Controls (RBAC), unless specifically authorised by the school to resolve a technical issue.

Storage and Security

Sensitive personal information is:

  • Stored exclusively within our secure, private AWS instances in the London, UK region.
  • Encrypted both in transit and at rest using industry-standard protocols.
  • Protected by mandatory Multi-Factor Authentication (MFA) for all administrative access.

Access and Correction

As the school or organisation maintains control over this data, individuals seeking to access, correct, or delete sensitive personal information should primarily contact the relevant school administrator. Passtab will assist schools in fulfilling these requests as required by the UK & EU GDPR.

Personal Data we collect

We collect Personal Data in accordance with instructions provided by our customers. The customer (not Invision) determines the categories of the personal data that is collected.

Depending on the requirements dictated by the security and emergency management policies of the customer, Personal Data that is collected on behalf of the customer may typically include:
• Visitor name and contact information
• Arrival and departure time
• Category of visitor
• The access point used for arrival and departure
• A PIN associated with a visitor
• Employer (if the visitor is a contractor)
• Reason for visit
• Electronic signature
• Photo image
• Information relating to certificates

When we create a customer account, we also collect the name and contact details of the customer’s nominated representative.

Consent for collection of Personal Data

As the Data Controller, the customer (the organisation or school that holds the Passtab account) is responsible for obtaining consent for the collection of Personal Data from visitors to their organisation. In accordance with the UK & EU GDPR Addendum of the Passtab Terms and Conditions of use, Invision is solely a Data Processor acting on behalf of the customer.

Passtab includes technical features that the customer may use to facilitate the obtaining of consent from data subjects.

We collect Personal Data to fulfil a contract with the customer to provide visitor registration and related services.

How we use Personal Data

We monitor de-identified statistics generated in the course of processing Personal Data in order to maintain optimum system performance.

We do not combine, modify, or use this Personal Data to contact individuals unless required by law.

We do not disclose Personal Data to third parties outside of our corporate group. Personal Data may be shared within Nelnet International for internal administrative purposes, corporate reporting, and to support system security and integrity. All such sharing is conducted under strict confidentiality and in compliance with the UK & EU GDPR. When an account is closed, we delete its Personal Data after 60 days.

We note, for the avoidance of doubt, that the customer (not Invision) may use Personal Data, that has been collected and subsequently downloaded from Passtab, to comply with their security and emergency management policies. Use of Personal Data outside the Passtab system by customers is governed by the respective privacy notices of those customers.

We use account-related Personal Data to manage, service, and invoice our accounts.

How we manage Personal Data

Personal Data is stored on a secure server provided by Amazon Web Service that is physically located in the London, United Kingdom. Communication between the Administrator account and the server is encrypted in transit. Data is also encrypted at rest.

Access to the secure server is restricted by password to authorised Invision personnel.

We note, again for the avoidance of doubt, that customers can view, download and store Personal Data from the Passtab system. Security for viewed and downloaded data is the responsibility of customers. It is also the responsibility of customers to advise data subjects of their privacy policy in relation to viewed and downloaded data, and if necessary, this Privacy Policy.

Customers have password-protected access to all Personal Data in the Passtab system and are responsible for delegation of password-protected access to other people.

Artificial Intelligence (AI)

This section applies specifically to the use of Artificial Intelligence (AI) within the service in the form of facial recognition.

Use of Facial Recognition Technology (AI Privacy Statement)

Passtab offers an optional facial recognition feature to streamline visitor sign-in and sign-out. This section explains how personal information is collected, used, and protected when this feature is enabled.

Information Collected

If enabled by the school and you choose to use the feature, we collect and process:

  • A facial photograph captured at sign-in
  • A system-generated facial identifier (Face ID string)
  • Basic account details required for identity verification

This feature does not collect behavioural, predictive, or profiling information.

Purpose of Processing

Facial images and identifiers are used solely for:

  • Identity verification during sign-in and sign-out
  • Matching repeat visitors to their existing records

This information is not used for:

  • AI model training or development
  • Marketing or advertising
  • Behavioural monitoring or profiling
  • Analytics beyond identity verification

Use of AI

Facial comparison is performed using Amazon Web Services (AWS) Rekognition, a secure managed AI service.

The system performs similarity matching only. It does not generate content, perform behavioural analysis, or make automated decisions that affect individual rights.

Passtab does not modify, train, or fine-tune the underlying AI model using customer data.

Storage and Retention

Facial data is:

  • Encrypted in transit and at rest
  • Stored within secure AWS infrastructure

Data is retained only for as long as necessary to support identity verification, in accordance with:

  • School-configured retention settings
  • Contractual obligations
  • Applicable legal requirements

Sharing of Information

Facial recognition data is processed using:

  • Amazon Web Services (AWS), which provides hosting infrastructure and facial comparison services

Personal information is not sold or shared for marketing or unrelated purposes.

Consent and Control

Use of facial recognition is optional.

  • You will be asked to opt in before your facial data is used
  • If you decline, you can continue to use standard sign-in methods
  • You may withdraw consent at any time by requesting removal of your facial data through the site administrator

Your Rights

You have the right to:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your facial data
  • Withdraw consent to the use of facial recognition

Requests can be made through the relevant site administrator or by contacting us using the details in this Privacy Policy.

Withdrawal of consent will disable facial recognition for your profile but will not affect your ability to use alternative sign-in methods.

Your Rights

You have the right to access any Personal Data that we hold about you and to request information about:
• The nature of Personal Data we hold about you
• Why and how we process your Personal Data
• The recipients to whom Personal Data has or will be disclosed
• For how long we intend to retain your Personal Data
• If we did not collect the data directly from you, information about the source

Note, however, that Invision is a processor for our customers. Our customers determine which categories of data to collect and are responsible for obtaining your consent. Moreover, customers have complete access to all data relating to their account in the Passtab system – Invision does not have any personal data in addition to that which our customers can view and download.

Therefore, in the first instance, requests for access to, or erasure of Personal Data or should be sent to our customer – which will be the organisation where you registered as a visitor.

If you are not able to contact the customer, or are not satisfied with the response you receive, please contact us with your request using the contact information below.

Data Security

Personal Data for UK and EU customers is stored on secure servers provided by Amazon Web Services (AWS) located in London, United Kingdom.

Personal Data for our customers in the European Union is stored on secure servers located in London, United Kingdom. These transfers from the EU to the UK are conducted in accordance with the EU-UK Adequacy Decision, which recognises the UK as providing an equivalent level of data protection to that of the EU.

Passtab data security features include:
• Contracting Amazon Web Servcies (AWS) to host the Passtab database and the Invision CRM database
• Databases being physically located in the London, United Kingdom
• Data backup being controlled by the AWS ‘back-up and restore’ system
• All data being continually replicated across fault-tolerant and self-healing database servers for maximum reliability
• Encrypting all data that is transmitted between the app/browser and server using the industry standard TLS 1.2 protocol
• Encryption of all data at rest
• Use of secure customer passwords 

Invision organisational data security measures include:
• MFA password protected access for staff
• Scheduled data protection training for staff
• Scheduled data protection assessments for staff
• Scheduled audit of the end-to-end process with a focus on data security
• Processing of all personal data within the Passtab system
• Appointment of a Data Protection Officer

Personal Data is hosted and stored within the London, United Kingdom. Access to this data from locations outside the UK (such as for technical support or administrative purposes) is strictly controlled and protected by Standard Contractual Clauses to ensure an equivalent level of data protection as required by the UK GDPR.

While Invision provides robust security features, the Customer remains responsible for managing access to their Passtab Administrator account and ensuring their own internal data handling policies are followed.

Retention of Personal Data

Our customers manage your Personal Data within the Passtab system. Therefore, our customers determine how long to retain Personal Data in accordance with their respective policies and data retention and erasure policies.

If you have any questions relating to the retention of Personal Data, in the first instance, please contact our customer – which will be the organisation where you registered as a visitor.

If you are not able to contact the customer, or are not satisfied with the response you receive, please contact us with your request using the contact information below.

How to access your Personal Data

For information on how to access your Personal Data at Invision please contact our Data Protection Officer at our registered office with your request:

 

Australian Representative 

Laura Hunt
Operations and Data Protection Manager
Invision Marketing Services Pty Ltd
Suite 12-17, Level/2 Brandon Park Dr, Wheelers Hill VIC 3150, Australia
Within Australia: 03 9800 1489
Outside Australia: +61 3 9800 1489
Email: laurahunt AT invision.net.au (Replace AT with @)

United Kingdom Representative

As Invision Marketing Services Pty Ltd is located outside of the United Kingdom, we have appointed a UK Representative to act as a local point of contact for our UK customers and for the Information Commissioner’s Office.

If you are located in the United Kingdom and have questions regarding your personal data or your rights under the UK GDPR, you may contact our representative:

Name: John Holder
Organisation: Albion Computers
Email: j.holder@albion.co.uk
Role: UK Data Protection Representative

We will endeavour to respond to your request within three business days.

Changes to our Privacy Notice

Our Privacy Notice complies with the UK General Data Protection Regulation (UK GDPR), the Data Protection Act 2018, and the EU General Data Protection Regulation 2016/679. We may amend this Privacy Notice to reflect changes in legislation or our business operations. If we amend the notice, we will post the updated version on our website at https://passtab.com/privacy-policy/

This privacy statement was updated on: 14/05/2026