Privacy Policy
Effective 2026-06-21 · 2026-06-21
hey ema — Privacy Policy
Effective date: 2026-06-21 Last updated: 2026-06-21
1. About this Policy
This Privacy Policy explains how By Loci Pty Ltd ACN 635 780 451 (Hey ema, we, us, our) collects, uses, discloses, and protects Personal Information when you visit our websites, sign up for or use the Hey ema service, contact us, or otherwise interact with us.
We are committed to protecting your privacy and to handling Personal Information in accordance with:
- the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs);
- the General Data Protection Regulation (GDPR) and the UK GDPR, where they apply;
- the California Consumer Privacy Act of 2018 as amended by the California Privacy Rights Act (CCPA/CPRA), where it applies; and
- other privacy laws of the jurisdictions in which we operate.
If you have a question or want to exercise a right, contact us using the details in §15 below.
2. Who this Policy applies to
This Policy applies to:
- Visitors to our websites and marketing properties;
- Account holders and Authorised Users who sign up for or use Hey ema as part of a Customer account;
- End Users of our Customers, in respect of the Personal Information we Process as a Controller (e.g. authentication metadata, abuse-prevention information). For Personal Information we Process on behalf of a Customer (e.g. content the Customer's End Users submit through Hey ema), the Customer is the Controller and you should refer to the Customer's privacy notice. We Process that Personal Information as a Processor under our Data Processing Agreement with the Customer;
- Prospects and other people who interact with us; and
- Job applicants.
3. The Personal Information we collect
We collect Personal Information directly from you, automatically through your use of our websites and Hey ema, and from third parties (such as our Customers, payment providers, identity providers, and lawful public sources).
We collect the following categories:
-
(a) Account information — name, work email, work phone, role/title, employer, login credentials (hashed), profile picture (if you upload one).
-
(b) Customer-supplied information — Personal Information submitted by a Customer or Authorised User into Hey ema (e.g. event registrant lists, attendee preferences, free-text content). For this category, we are typically a Processor — see §4 below.
-
(c) Usage and device information — IP address, device identifiers, browser type, operating system, referring URL, pages visited, features used, error logs, approximate location derived from IP.
-
(d) Cookies and similar technologies — see our Cookie Policy for details.
-
(e) Communications — emails, support tickets, chat transcripts, call recordings (where notified), feedback, survey responses.
-
(f) Payment and billing information — payment card or bank account details (typically tokenised by our payment provider; we do not store full card numbers), billing contact details, transaction history.
-
(g) Marketing preferences — your subscription status for newsletters, events, and other marketing communications.
-
(h) Recruitment information — if you apply for a role, your CV, work history, references, right-to-work information, and any information you choose to provide.
-
(i) Information collected from third parties — such as identity verification services, sanctions/anti-money-laundering screening (where applicable), and integrations you authorise (e.g. Google, Microsoft, Salesforce).
We do not knowingly collect special categories of Personal Information (such as health, biometric, or genetic data). If a Customer chooses to use Hey ema with such categories, the Customer must comply with the AI Addendum and any restrictions set out in our documentation.
4. Our role: Controller vs Processor
Different parts of Hey ema involve different roles:
-
As a Controller, we determine the purposes and means of Processing for: account data; usage and device information; cookies and similar technologies; marketing data; payment data we collect for our own billing; and Personal Information collected through our websites or recruitment processes.
-
As a Processor, we Process Personal Information that a Customer (or its Authorised Users) submits or directs us to Process through Hey ema (such as content about End Users). The Customer is the Controller of that Personal Information. Our Processing is governed by the Data Processing Agreement (DPA) we have with that Customer. When you interact with Hey ema as an End User of one of our Customers, please refer to the Customer's own privacy notice for information about why your information is being collected.
This Policy primarily addresses the Controller role. Where we act as a Processor, we follow the Customer's instructions and the DPA.
5. Why we use Personal Information and our legal bases
We use Personal Information for the purposes set out below. The legal bases below are the GDPR/UK GDPR bases. The APP equivalents are listed where relevant.
| Purpose | Examples | GDPR/UK GDPR legal basis | APP basis |
|---|---|---|---|
| Provide and operate Hey ema | Authenticating users, delivering features, troubleshooting | Contract; legitimate interests | APP 6.1(a) (primary purpose) |
| Account and Customer administration | Onboarding, account configuration, support | Contract; legitimate interests | APP 6.1(a) |
| Billing and payment | Invoicing, processing payments, collecting overdue amounts | Contract; legitimate interests; legal obligation (tax) | APP 6.1(a); 6.2 (legal authorisation) |
| Security, fraud prevention, abuse | Detecting and preventing unauthorised access, abuse and fraud; investigating incidents | Legitimate interests; legal obligation | APP 6.1(a); 6.2(b) (enforcement); 6.2(e) (lessening serious threat) |
| Product improvement and analytics | Understanding usage, improving features, fixing bugs, AI training (subject to AI Addendum and opt-outs) | Legitimate interests | APP 6.1(a); APP 6.2(a) (related secondary purpose with reasonable expectation) |
| Marketing and events | Sending newsletters, product updates, event invitations (with opt-out) | Consent (where required); legitimate interests | APP 7 (direct marketing rules); Spam Act consent |
| Legal and compliance | Complying with laws, responding to regulators, enforcing our rights | Legal obligation; legitimate interests | APP 6.2(b)–(c) |
| Recruitment | Assessing applications, conducting interviews, making offers | Legitimate interests; consent | Employee Records exemption may apply |
| Corporate transactions | Due diligence in connection with M&A, financing or insolvency | Legitimate interests | APP 6.2(d) (related to primary) |
6. AI processing and use of Customer Data for training
Hey ema uses artificial intelligence (including third-party models) to process Customer Data. Subject to the AI / Data Use Addendum in our customer agreement (and the opt-outs and exclusions described there):
- We may use Customer Data to operate Hey ema, including to generate AI outputs requested by the Customer or its Authorised Users.
- We may use Customer Data to train, evaluate and improve Hey ema's models and product. For data protected by the GDPR or UK GDPR, we use it for training only in aggregated, anonymised form (so it is no longer personal data), or otherwise only on a lawful basis the Customer has established; for other data we use it on a de-identified or aggregated basis. Training use is off by default for EU/UK personal data and for customers in regulated sectors, and the Customer (and, where applicable, End Users) can opt out at any time.
- We do not use Customer Data for marketing or to train models offered to other customers as a separate product without consent.
- We exclude special categories of personal data, biometric data, health information, financial account numbers, government identifiers, children's data, and identifiable End User free-text content from training use by default.
If you are an End User and wish to understand how the Customer permits us to use your data, please refer to that Customer's privacy notice or contact the Customer.
7. Who we share Personal Information with
We share Personal Information with:
-
(a) Sub-processors — vendors who Process Personal Information on our behalf (cloud hosting, AI model providers, payment processors, support and analytics tools). The current list is at our Sub-processor page at https://heyema.app/docs/sub-processors.
-
(b) Customers — for End User Personal Information that we Process as a Processor, the Customer is the Controller and decides how to use it.
-
(c) Affiliates — entities under common control with By Loci Pty Ltd, on the same terms as this Policy.
-
(d) Professional advisers — lawyers, accountants, auditors, insurers, on a need-to-know basis under confidentiality obligations.
-
(e) Acquirers — in connection with a merger, acquisition, financing, restructure or insolvency, with appropriate confidentiality protections.
-
(f) Authorities — government, regulatory or law enforcement bodies, where required by Applicable Law or to protect our or another person's rights, property or safety, or where you have given consent.
-
(g) With your consent — to any other person you direct.
We do not sell Personal Information for money. We do not knowingly "share" Personal Information for cross-context behavioural advertising as defined under the CCPA/CPRA.
8. International transfers
Hey ema is operated from Australia and uses Sub-processors in Australia, the European Union, the United Kingdom, the United States, and other jurisdictions. When we transfer Personal Information across borders, we apply appropriate safeguards:
- From the EU/EEA and UK to other countries: where the destination is not subject to an adequacy decision, we rely on the European Commission's Standard Contractual Clauses (Module 2 — Controller to Processor — and Module 3 — Processor to Sub-processor — as applicable, including for onward transfers to our Sub-processors), the UK International Data Transfer Addendum, and we conduct Transfer Impact Assessments where required.
- From Switzerland: we apply the SCCs with the Swiss-specific modifications, with the Swiss Federal Data Protection and Information Commissioner as the relevant authority.
- From Australia overseas: we comply with APP 8 and remain accountable for the acts and omissions of overseas recipients, except in the limited circumstances permitted by the Privacy Act.
- From the US to other countries: we apply the protections required by applicable US state laws.
You can request a copy of the relevant transfer safeguard by contacting us using the details in §15.
9. How we keep Personal Information secure
We implement technical and organisational security measures designed to protect Personal Information from unauthorised access, alteration, disclosure or destruction. These include:
- Encryption in transit (TLS 1.2+) and at rest (AES-256 or equivalent);
- Access controls based on least privilege, with multi-factor authentication for staff;
- Network segmentation, firewalls, and intrusion detection;
- Vendor security reviews of Sub-processors;
- Logging, monitoring and incident response procedures, with our Data Breach Response Plan aligned to the Notifiable Data Breaches scheme and GDPR Articles 33–34;
- Background checks on staff (where lawful) and confidentiality obligations;
- Staff training on privacy and security.
No system is completely secure. If you suspect a security issue, please contact us at security@heyema.com.
10. How long we keep Personal Information
We keep Personal Information only as long as we need it for the purposes for which we collected it, or as required by law. In general:
- Account data: for as long as the Customer's account is active, plus a reasonable wind-down period (typically up to 12 months) and any period required by law.
- Customer Data we Process for a Customer: for the period set in the Customer's agreement and the DPA (typically returned or deleted within 30 days after termination of the Customer's subscription).
- Billing and tax records: for at least 7 years from the date of the relevant transaction (Australian tax law requirement).
- Marketing data: until you unsubscribe, plus a short suppression-list retention period to honour your unsubscribe.
- Recruitment records: for unsuccessful applicants, typically up to 12 months unless you ask us to keep them longer.
- Logs and security telemetry: typically up to 12 months, longer where required to investigate an incident or comply with law.
11. Australian residents — your rights
If you are in Australia, you have rights under the Privacy Act:
- Access — to ask for a copy of the Personal Information we hold about you (APP 12);
- Correction — to ask us to correct Personal Information that is inaccurate, out-of-date, incomplete, irrelevant or misleading (APP 13);
- Anonymity and pseudonymity — to deal with us without identifying yourself, where lawful and practicable (APP 2);
- Direct marketing opt-out — to ask us to stop sending direct marketing (APP 7);
- Complaint — to complain to us, and if you are not satisfied, to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
12. EU/EEA and UK residents — your rights
If the GDPR or UK GDPR applies to our Processing of your Personal Information, you have these rights:
- Access to the Personal Information we hold about you and information about how we Process it (Art. 15);
- Rectification of inaccurate or incomplete Personal Information (Art. 16);
- Erasure in certain circumstances ("right to be forgotten") (Art. 17);
- Restriction of Processing in certain circumstances (Art. 18);
- Data portability (Art. 20);
- Objection to Processing carried out on the basis of legitimate interests, including profiling (Art. 21);
- Withdraw consent at any time, where Processing is based on consent (Art. 7(3));
- Lodge a complaint with your supervisory authority. In the UK, the supervisory authority is the Information Commissioner's Office (ICO) at ico.org.uk. In the EU, the supervisory authority of your habitual residence, place of work, or place of the alleged infringement.
We will respond within one month of receiving a verifiable request, extendable by two months for complex requests.
If you are in the EU or UK, you may also contact our appointed representative:
- EU GDPR representative: Jacob Thomas, By Loci Pty Ltd, 101 Camberwell Road, Hawthorn East VIC 3123, Australia — privacy@heyema.com
- UK GDPR representative: Jacob Thomas, By Loci Pty Ltd, 101 Camberwell Road, Hawthorn East VIC 3123, Australia — privacy@heyema.com
13. California, Colorado, Connecticut, Texas, Virginia and other US residents — your rights
If we collect Personal Information from California residents, the CCPA/CPRA applies. Other US states (including Colorado, Connecticut, Texas, Utah, Virginia) provide similar rights. To the extent these laws apply to your Personal Information, you have the right to:
- Know / access the categories and specific pieces of Personal Information we have collected about you, the sources, the purposes, and the categories of recipients;
- Delete Personal Information we have collected about you (subject to permitted exceptions);
- Correct inaccurate Personal Information;
- Opt-out of "sale" or "sharing" of Personal Information. We do not sell or share Personal Information for cross-context behavioural advertising. We honour the Global Privacy Control (GPC) signal as an opt-out where it is required;
- Limit use of sensitive personal information to the purposes specified in the CCPA/CPRA;
- Non-discrimination for exercising your rights;
- Authorised agent — you may designate an authorised agent to make a request on your behalf in accordance with the CCPA/CPRA's verification rules.
We do not knowingly collect Personal Information from minors under 16 without authorisation as required by the CCPA/CPRA.
To exercise rights under the CCPA/CPRA or other US state laws, contact us using the details in §15. We will verify your identity (typically by matching information you provide to information in your account) and respond within the time required by the relevant law (45 days under the CCPA, with one extension of up to 45 days where reasonably necessary).
Notice at collection (CCPA/CPRA) — the categories of Personal Information we collect, the purposes, the categories of sources, and the categories of recipients are set out in §3, §5 and §7 of this Policy.
14. Children
Hey ema is a business tool and is not directed to children. We do not knowingly collect Personal Information directly from children. The age below which a child cannot consent, and the consent rules that apply, vary by jurisdiction — for example, under 13 under the US COPPA, and between 13 and 16 under Article 8 of the GDPR depending on the Member State. Where Applicable Law sets such an age, that age applies. If you are a Customer using Hey ema in connection with services that may reach children, you must ensure you have all consents and authorisations required by Applicable Law (including, in the US, COPPA where applicable) and you must comply with the AI Addendum.
15. How to contact us / make a request
You can contact us about this Policy or to make a privacy request:
- Email: privacy@heyema.com
- Phone: +61 3 9034 5221
- Post: Privacy Officer, By Loci Pty Ltd, 101 Camberwell Road, Hawthorn East VIC 3123, Australia
- Web form: https://heyema.com/privacy
If you are an EU or UK resident, you may also contact our representative using the details in §12.
16. Changes to this Policy
We may update this Policy from time to time. We will post the updated Policy on our website with an updated "Last updated" date. Where the changes are material we will notify Customers by email or through the Hey ema service before the changes take effect.
17. Definitions used in this Policy
Capitalised terms not defined here have the meanings given in the Hey ema Master Subscription Agreement and the MSA and its Schedules.
- Authorised User — see the MSA.
- Cookie Policy — our policy on cookies and similar technologies, available at https://docs.heyema.app/cookies.
- Customer — the entity that has a subscription agreement with Hey ema.
- End User — an individual to whom the Customer makes Hey ema (or its outputs) available.
- Personal Information — see the MSA and its Schedules.
- Sub-processor — a third party engaged by Hey ema to Process Personal Information on Hey ema's behalf.