Our operating position
We use information to deliver the work a person or business has asked us to perform. We do not sell personal information, and connected-account access is not permission to use that information for unrelated purposes.
Who this policy covers.
Visual State Studio ("Visual State", "we", "us" or "our") is a Melbourne-based AI implementation and creative studio. This policy applies when you visit visualstate.studio, contact us, become a client, interact with a workflow we operate, or authorise VisualState Automation to connect to a business account.
A signed client agreement, project scope or collection notice may give more specific information about a particular service. If another organisation controls the information and Visual State only processes it for that organisation, that organisation remains responsible for its own privacy notices and lawful instructions.
Information we collect.
The information we collect depends on how you deal with us. It may include:
- name, business name, role, email address, phone number and location;
- enquiry, booking, proposal, project, billing and support information;
- messages, call notes, files, approvals, workflow rules and feedback you provide;
- customer or prospect records a client authorises us to process for an agreed workflow;
- website and device information such as IP address, browser type, page activity, referral source and security logs; and
- publicly available business information used for carefully targeted research, subject to our outreach controls and opt-out records.
We usually collect information directly from you, from an authorised business account, from a client acting with authority, from our service providers, or from public business sources. Please do not provide sensitive information unless it is genuinely required and we have agreed on how it will be handled.
Meta and connected-account data.
When an authorised person connects Facebook, Instagram, Messenger or Meta Ads to VisualState Automation, the integration may receive and process only the data needed for the enabled tools and approved workflow. Depending on the permissions granted, this can include:
- business, Page, Instagram profile and ad-account identifiers and names;
- Page and Instagram content, comments, conversations and message metadata;
- lead-form submissions, audience or campaign configuration, advertising creative, delivery and performance information;
- Page, content, account and campaign insights;
- webhook events and conversion or event information connected to an authorised dataset or pixel; and
- access tokens and technical identifiers required to maintain the authorised connection.
Authorised business use only.
We use Meta platform data to perform the connected business workflow, provide support, maintain security and meet the account owner’s instructions. We do not sell Meta platform data or use private messages, leads or account data for unrelated advertising.
You can remove a connection through the relevant Meta or Instagram settings and may also request deletion through our data deletion process.
Why we use information.
We collect, hold, use and disclose information where reasonably necessary to:
- respond to enquiries, scope projects and provide requested services;
- connect, configure, test, operate and support authorised automations;
- prepare drafts, route work, update records and carry out actions a responsible person has approved;
- manage client relationships, accounts, billing, support and service quality;
- secure our systems, investigate errors, prevent misuse and maintain audit records;
- meet legal, regulatory, insurance and contractual requirements; and
- send relevant business updates or marketing where consent exists or the communication is otherwise permitted, with working opt-out controls.
Where practical, we use aggregated or de-identified information for service improvement and reporting.
Storage, security and overseas processing.
We use technical and organisational safeguards proportionate to the information and workflow. These include scoped access, separate credentials, encrypted connections, managed secret storage, authentication controls, activity records, approval gates and removal of access when it is no longer required.
Some providers process or store information outside Australia, including in the United States and other countries where their infrastructure or support teams operate. Overseas privacy protections may differ from Australian law. We assess providers and configure available privacy, security and retention controls according to the service and risk.
No online system is completely risk free. If we identify an eligible data breach, we will investigate, contain and notify affected parties and regulators where required.
Retention and deletion.
We keep personal information only for as long as it is reasonably needed for the purpose collected, an agreed client workflow, security and audit requirements, dispute handling, or legal and financial recordkeeping. Retention periods vary according to the record and the service.
- connection credentials and tokens are revoked or removed when the connection ends or they are no longer needed;
- temporary processing data is deleted or de-identified when the operational purpose is complete;
- client and transaction records may be retained for contractual, tax, insurance or legal requirements; and
- limited backup copies may remain until the relevant backup cycle expires, protected from ordinary use.
For Meta-connected information, follow the steps on our data deletion page. We may need to verify that the requester is authorised to act for the connected account before deleting business data.
Access, correction and complaints.
You may ask what personal information we hold about you, request access or correction, withdraw a consent where applicable, or raise a privacy complaint. Email team@visualstate.studio with enough detail for us to identify the relevant relationship or record.
We will acknowledge the request, verify identity or authority where necessary, and respond within a reasonable period. Access may be limited where an exception under applicable law applies, in which case we will explain the basis where we can.
If a privacy complaint is not resolved with us, you may be able to contact the Office of the Australian Information Commissioner. Visit oaic.gov.au for current guidance and complaint options.
Automated systems and human review.
Our systems may classify, summarise, draft, route, schedule or update information as part of an approved workflow. We design consequential pricing, scope, contractual, complaint, safety, financial and sensitive customer decisions to follow the human approval path agreed with the responsible business.
We do not present an automated recommendation as a legal, medical, financial or professional decision. If the use of automated processing materially changes, we will update this policy and any relevant collection notice or project documentation.
Cookies, children, updates and contact.
Our website uses cookies and similar technologies to operate, to understand how the site performs and to measure our advertising. Alongside our own essential storage, we use Google (Google Ads and Google Analytics) and Meta (the Meta Pixel and the Meta Conversions API). Together these record the pages you visit, information about your device and browser, and the advertising click identifiers that tell us which ad or search result brought you here. We keep those click identifiers in a first party cookie for up to 90 days. If you send us a booking request, the contact details you submit are also used, in a scrambled (hashed) form, to confirm that the request came from one of our advertisements.
Using these technologies means disclosing that information to Google and to Meta, who store and process it overseas, including in the United States. We send them only what is described above. We never send them the content of your enquiry or anything you tell us about your business.
You can opt out of our advertising measurement and marketing at any time by emailing team@visualstate.studio. You can also control advertising directly with each provider, through Google Ad Settings and Meta ad preferences. Your own browser controls can restrict some of these technologies, although doing so may affect how parts of this site work.
Our business services are not directed to children. We do not knowingly collect a child’s personal information through VisualState Automation without an appropriate lawful basis and responsible adult or organisational authority.
We may update this policy when our services, providers or legal obligations change. The current version will remain available at this URL with its effective date.
Privacy contact
Visual State Studio · South East Melbourne, Victoria
This policy describes our current operating practices and does not limit any rights available under applicable law.