Privacy Policy – Resitab

This Privacy Policy describes how we at Invision Marketing Services (IMS) collect, use, and manage Personal Information (PI) that is collected and stored using Resitab.

Introduction

Resitab is used to collect and collate information about visitors, staff, contractors, students and others (Registrants) who arrive at and/or depart from premises of an organisation.

Resitab has an Administrator and a Visitor Module. The Administrator can access PI via web browser-enabled devices, including computers, tablets, and smartphones. The Visitor Module is used to record arrivals, departures, and movements of Registrants.

Collection of Personal Information (PI)

We collect PI when we create a Resitab Administrator. We collect:

a. Account name
b. Email address
c. Password
d. Organisation name and address
e. Contact Phone Number
f. Contact Name

The school or organisation collects PI when a Registrant uses the Visitor Module to register arrival or departure from premises. The Administrator (not IMS) determines what information is collected; depending on category of Registrant, it may typically include but is not limited to:

a. Arrival and departure time
b. Category of Registrant
c. The access point for arrival and departure
d. A PIN associated with a Registrant
e. Employer (if a contractor)
f. Reason for visit
g. Electronic signature
h. Photo image
i. Phone number
j. Certificate expiry date
k. Items booked out to the Registrant

Sensitive Personal Information

The Passtab service may be used by schools or organisations to record and manage sensitive personal information where required for operational purposes, such as first aid documentation. This may include health or medical information entered by authorised users.

Purpose of Collection

Sensitive personal information is processed exclusively to meet the specific safety, compliance, and operational requirements defined by the Customer (school or organisation). Passtab does not use sensitive personal information for marketing, advertising, or any profiling/analytics outside of the Customer’s configured workflow.

Collection and Control

Data Controller: Sensitive information is controlled by the school or organisation using the Passtab service. The school is responsible for determining the lawful basis for collection and for obtaining any required consents.

Data Processor: Passtab acts as a service provider (Processor) and handles this information only in accordance with the documented instructions of the school or organisation.

Access Restriction: Our authorised support personnel (including overseas staff) are restricted from accessing sensitive health or medical records via Role-Based Access Controls (RBAC), unless specifically authorised by the school to resolve a technical issue.

Storage and Security

Sensitive personal information is:

  • Stored exclusively within our secure, private AWS instances in the Sydney, Australia region.
  • Encrypted both in transit and at rest using industry-standard protocols.
  • Protected by mandatory Multi-Factor Authentication (MFA) for all administrative access.

Access and Correction

As the school or organisation maintains control over this data, individuals seeking to access, correct, or delete sensitive personal information should primarily contact the relevant school administrator. Passtab will assist schools in fulfilling these requests as required by the Privacy Act 1988 (Cth).

How we use PI

We use Administrator-related PI to manage, service, and invoice our accounts.

We may monitor system data, including limited PI, to maintain optimum system performance.

In addition, Administrators (not IMS) use PI they have collected to manage their facility. This includes managing emergencies by allowing Administrators and delegated staff to view the database of Registrants who are on or off the premises.

How we manage PI

PI is stored on a secure server provided by Amazon Web Service that is physically located in Australia. Communication between the Administrator account and the server is encrypted in transit.

Access to the secure server is restricted to authorised IMS personnel. Limited access to redacted or de-identified system information may be provided to authorised personnel located outside Australia for the purposes of system maintenance, technical support, or security monitoring, subject to strict confidentiality and security controls.

We do not combine PI with other data or modify it.

We may disclose PI to third parties when directed by the Account Administrator or required by law or government regulation.

When an account is closed, we delete its PI after one month.

We securely store the passwords for Administrators. Administrators have password-protected access to all PI relating to Registrants of their account. Administrators can also delegate password-protected access to their staff. Registrants do not have access to PI when using the Visitor Module.

Administrators can view, download and store PI. Security for viewed and downloaded data is the responsibility of Administrators. It is also the responsibility of Administrators to advise Registrants of their privacy policy in relation to viewed and downloaded data, and if necessary, this Privacy Policy.

If we undergo a business restructure, merger, acquisition, sale or divestiture of all or part of our business or assets, the Personal Data processed within the Entrytab platform may be made available to or transferred to a successor operator or entity as part of that transaction. We will take steps to ensure that any such disclosure and/or transfer is subject to suitable privacy and data protection safeguards, including to preserve the continuity of your account and the overall functionality of the Entrytab platform as a visitor management system.  Your Personal Data may become subject to a different privacy policy implemented by the new owner or entity.

Artificial Intelligence (AI)

This section applies specifically to the use of Artificial Intelligence (AI) within the service in the form of facial recognition.

Use of Facial Recognition Technology (AI Privacy Statement)

Passtab offers an optional facial recognition feature to streamline visitor sign-in and sign-out. This section explains how personal information is collected, used, and protected when this feature is enabled.

Information Collected

If enabled by the school and you choose to use the feature, we collect and process:

  • A facial photograph captured at sign-in
  • A system-generated facial identifier (Face ID string) 
  • Basic account details required for identity verification

This feature does not collect behavioural, predictive, or profiling information.

Purpose of Processing

Facial images and identifiers are used solely for:

  • Identity verification during sign-in and sign-out
  • Matching repeat visitors to their existing records

This information is not used for:

  • AI model training or development
  • Marketing or advertising
  • Behavioural monitoring or profiling
  • Analytics beyond identity verification

Use of AI

Facial comparison is performed using Amazon Web Services (AWS) Rekognition, a secure managed AI service.

The system performs similarity matching only. It does not generate content, perform behavioural analysis, or make automated decisions that affect individual rights.

Passtab does not modify, train, or fine-tune the underlying AI model using customer data.

Storage and Retention

Facial data is:

  • Encrypted in transit and at rest
  • Stored within secure AWS infrastructure

Data is retained only for as long as necessary to support identity verification, in accordance with:

  • School-configured retention settings
  • Contractual obligations
  • Applicable legal requirements

Sharing of Information

Facial recognition data is processed using:

  • Amazon Web Services (AWS), which provides hosting infrastructure and facial comparison services

Personal information is not sold or shared for marketing or unrelated purposes.

Consent and Control

Use of facial recognition is optional.

  • You will be asked to opt in before your facial data is used
  • If you decline, you can continue to use standard sign-in methods
  • You may withdraw consent at any time by requesting removal of your facial data through the site administrator

Your Rights

You have the right to:

  • Access your personal information
  • Request correction of inaccurate information
  • Request deletion of your facial data
  • Withdraw consent to the use of facial recognition

Requests can be made through the relevant site administrator or by contacting us using the details in this Privacy Policy.

Withdrawal of consent will disable facial recognition for your profile but will not affect your ability to use alternative sign-in methods.

Reporting Breaches of Privacy

We are committed to ensuring the privacy of all PI we process and store within the Entrytab platform for our customers. Certain compulsory obligations have been placed on organisations under the Privacy Act 1988 (Cth) to notify specific types of data breaches (Notifiable Data Breaches “NDB”) to individuals affected by the breach as well as to the Office of the Australian Information Commissioner (OAIC).

In the event of a PI data breach of either Administrator Information or Registration Information, IMS will notify the party affected within 7 days of IMS becoming aware of the breach, and provide:

a. Our identity and contact details;
b. A description of the data breach;
c. The kind of information that is suspected of being affected;
d. Recommendations about the steps you should take to limit the impact of the breach;

and

e. Advice as to whether we have contacted the OAIC about the breach.

How to access your PI

PI collected when signing in at a school or organisation is controlled by that school or organisation. Requests to access or correct that information should be made directly to them in the first instance.

Where Entrytab processes PI on behalf of a school or organisation and is able to assist, we will provide reasonable assistance to support access requests in accordance with applicable privacy laws.

For a detailed list of the sub-processors used by Invision in delivering our services, please refer to our list of sub-processors.

Contact details:

Laura Hunt
General Manager
Invision Marketing Services Pty Ltd
Suite 12-17, Level/2 Brandon Park Dr, Wheelers Hill VIC 3150
Within Australia: 03 9800 1489
Outside Australia: +61 3 9800 1489
Email: laurahunt AT invision.net.au (Replace AT with @)

We will endeavour to respond to your request within three business days.

Changes to our Privacy Policy

Our Privacy Policy complies with the Australian Privacy Principles contained within the Privacy Act 1988 (Cth). We may amend this Privacy Policy to reflect changes in legislation or our business. If we amend the policy we will post the change on our website.

Response to Requests

If you are not satisfied with our response to your request for information you may wish to contact the Office of the Australian Information Commissioner:

Phone: 1300 363 992
Email: enquiries@oaic.gov.au
www.oaic.gov.au

This privacy statement was updated on: 14/05/2026

Book a demonstration

Book a demonstration

Contact our customer service team to discuss your unique needs. Our front desk registration system is highly customisable – we’d love to help you find a solution that works for you.

Let’s get started