This Privacy Policy explains how SEO BY DESIGN (ABN 27 604 617 923), trading as ReviewProsper ("ReviewProsper", "we", "us" or "our"), handles personal information through the ReviewProsper website and managed customer reactivation service (the "Service").
ReviewProsper follows the Australian Privacy Principles (APPs) as its standard for handling personal information. We also design our electronic messaging processes with the Spam Act 2003 (Cth) in mind. This statement describes the standard we follow. It does not make a representation about whether every provision of the Privacy Act 1988 (Cth) applies to SEO BY DESIGN in every circumstance.
This Policy is publicly available so Clients, prospective Clients and people contacted through a campaign can understand what information we handle and why. A link to this Policy does not, by itself, mean that every person receiving a message has read it or agreed to it.
1. Who this Policy covers
This Policy applies to:
- visitors to reviewprosper.ai and related ReviewProsper web pages;
- businesses and authorised users who enquire about, purchase or use the Service ("Clients");
- individuals whose information a Client provides for an approved campaign ("Recipients"); and
- people who communicate with us by telephone, email, a website form, SMS or another supported channel.
2. What the managed Service does
ReviewProsper is a managed customer reactivation service. It is not simply a self-service SMS sender. A Client provides customer records, explains the relationship and proposed contact basis, approves the campaign purpose and approves the message content. ReviewProsper then prepares and configures the approved campaign, releases messages in controlled batches, monitors conversations, handles routine replies within approved rules, applies suppression and refers matters requiring judgement or authority to a human.
Each Client receives a separate ReviewProsper campaign workspace and may be given login access to it. The workspace sits within ReviewProsper's managed agency environment. ReviewProsper therefore holds and processes the customer data used to deliver the Service. Client data is logically segregated in the Client's own sub-account, and access is restricted to authorised ReviewProsper personnel, authorised Client users and service providers needed to deliver the Service.
The Client remains responsible for the legitimacy and accuracy of the information it supplies, the proposed contact basis, the accuracy of its business identity and contact details, and its approval of the campaign purpose and content. ReviewProsper is responsible for operating the agreed managed process with reasonable care, including controlled sending, monitored reply handling, suppression and escalation as described in the applicable agreement.
3. Personal information we collect and hold
The information we collect and hold depends on the relationship and the campaign. It may include:
- Client and enquiry information - name, business name, role, email address, telephone number, postal address, enquiry details, proposal information, billing details and support history.
- Authorised-user information - name, business contact details, login details, access permissions and activity within the Client's campaign workspace.
- Recipient identity and contact information - name, mobile number and related contact information supplied by the Client.
- Relationship history - relevant purchase, quote, enquiry, service, membership, renewal, booking or other history, including dates and general descriptions supplied to support personalisation and the proposed contact basis.
- Conversation information - approved outgoing messages, typed replies, message status, conversation context, stated needs, questions, timing, preferences and requests for human assistance.
- Campaign and outcome information - audience segment, campaign and message version, send and delivery records, campaign stage, qualification status, assigned owner, next action, booking or review links offered, bookings, review requests, referrals and outcomes later confirmed by the Client.
- Preference and suppression information - opt-outs, do-not-contact instructions, wrong-person or wrong-number corrections, complaints, delivery failures and suppression status.
- Website and technical information - IP address, browser and device information, cookie identifiers, page activity and information submitted through forms.
- Payment information - payment status and transaction records received from payment providers. We do not intentionally store complete payment-card details.
We do not design campaigns to solicit sensitive information such as health information, financial details, legal advice or other highly personal material. A Recipient may nevertheless disclose sensitive or private information in an open conversation. Where that occurs, the answering process is configured not to provide specialist advice. The conversation may be restricted, referred to an authorised human or handled in another appropriate way, and the information is retained only where needed for the conversation, the campaign record, security or legal obligations.
4. How we collect personal information
We collect personal information:
- directly from Clients, prospective Clients and authorised users when they enquire, complete a form, provide campaign instructions, use a campaign workspace or communicate with us;
- from Clients when they provide agreed customer records, relationship history, suppression records and campaign data;
- from Recipients when they reply to a campaign message, call, use a booking or review link, submit information through a connected page or otherwise continue the conversation;
- automatically through the messaging, campaign and website systems used to deliver and measure the Service; and
- from service providers that support messaging, hosting, artificial intelligence processing, website analytics, payments, security and customer support.
Much of the Recipient information is collected indirectly from the Client before the first message is sent. ReviewProsper requires the Client to explain the source of the mobile number, the relevant customer relationship and the proposed contact basis. Where reasonably practicable, information is checked, corrected or excluded before sending.
5. Why we collect, use and disclose personal information
We collect, use and disclose personal information where reasonably necessary to:
- assess whether a prospective Client and database may be suitable for the Service;
- prepare, configure, test, operate and monitor an approved campaign;
- personalise an opening using relevant information from the Recipient's genuine relationship with the Client;
- send messages, receive replies and maintain the conversation record;
- distinguish practical needs, future timing, questions, referrals, reviews, wrong records, opt-outs and matters requiring a human;
- generate routine replies within approved campaign rules and provide the conversation and context to an authorised human when judgement is required;
- apply opt-outs, corrections, do-not-contact instructions and other suppression controls;
- record campaign stages, handovers, bookings, review requests and Client-confirmed outcomes;
- provide reports, customer support and service communications;
- manage authorised access, payments, records and the Client relationship;
- operate, secure, troubleshoot and improve the Service;
- prevent misuse, investigate complaints and respond to security incidents; and
- meet contractual, insurance, accounting, regulatory and legal obligations.
We do not sell personal information. We do not use a Client's customer database to market unrelated products or services to those customers, or make it available to another Client.
6. Artificial intelligence and automated processing
ReviewProsper uses an artificial intelligence answering agent as part of its managed conversation process. This is referred to operationally as the ReviewProsper SMS Android. It assists with understanding incoming messages, preparing routine replies, classifying conversation outcomes and identifying when a human should take over.
To perform those tasks, information relevant to the conversation may be processed through the OpenAI application programming interface (API). Depending on the conversation, this may include the Recipient's name, relevant purchase or enquiry history, the approved business and campaign context, the Recipient's typed reply and enough earlier conversation content to produce a contextually appropriate response.
This information is sent for the purpose of operating the answering agent and supporting the approved campaign. It is not sent to a public consumer ChatGPT conversation. Processing remains subject to the technical, contractual and data-handling arrangements that apply to the API service used by ReviewProsper.
The SMS Android operates within rules and boundaries configured for the campaign. It is not authorised to give finance, legal, health or other specialist advice, make binding decisions for the Client, approve pricing exceptions, determine a trade-in or valuation, or resolve a complaint without appropriate authority. Routine processing is monitored. Ambiguous, sensitive, high-risk or out-of-scope matters are referred to the Client's nominated person or another authorised human.
Automated classification and drafting can make mistakes. Human monitoring and escalation are part of the Service because automated processing is not guaranteed to understand every message, instruction or opt-out expressed in unusual language.
7. SMS, contact basis and responsibility
Commercial electronic messages are regulated by the Spam Act 2003 (Cth). The Act addresses consent, sender identification, contact information and a functional unsubscribe facility.
The Client is responsible for establishing and documenting the contact basis relied on for the proposed audience. The Client must provide accurate source and relationship information, disclose earlier opt-outs and approve its business identity, campaign purpose and message content. A past purchase or enquiry does not automatically resolve whether a later commercial message is permitted.
ReviewProsper prepares and sends Client-approved messages as a managed service. We use reasonable endeavours to operate a monitored, reply-capable channel, identify recognised opt-outs, record equivalent requests expressed in other language, apply suppression and refer ambiguous or sensitive replies for human review. These operational controls do not replace the Client's responsibility for the contact basis or make either party's compliance automatic.
A Recipient may opt out by replying DELETE, STOP, UNSUBSCRIBE, saying that they do not want to be contacted again, or using any other words that clearly communicate the same request. We aim to suppress the record immediately when the request is recognised. Automated filtering may not interpret every unusual expression, which is why monitored human review is also used.
8. Privacy notices for indirectly collected information
This public Policy explains ReviewProsper's overall handling practices, but it is not treated as the only notice that may be relevant when Recipient information is collected indirectly from a Client. Where a collection notice is required or appropriate, ReviewProsper and the Client will consider the most suitable point and method for the particular relationship and campaign.
Depending on the circumstances, notice may be provided through the Client's privacy policy or wording used when the information is originally collected, a short linked notice on a campaign or support page, information provided during reply handling, or a later message in the conversation. The tested two-text recognition opening does not need to be altered merely because another notice method is used. The appropriate approach depends on what the Client previously told the customer, the information involved and what is reasonable in the circumstances.
9. Direct marketing by ReviewProsper
We may market ReviewProsper's own services to Clients, prospective Clients and business contacts where permitted. A person can opt out at any time by using the unsubscribe method provided or contacting us. We do not use a Client's Recipient list for ReviewProsper's own unrelated direct marketing.
10. Service providers and overseas processing
ReviewProsper uses service providers to operate the managed Service. The current core data chain includes:
- GoHighLevel and LeadConnector for the managed campaign workspace, customer records, automation and conversation storage;
- Twilio, through LeadConnector for SMS transmission and related carrier functions; and
- OpenAI for API-based artificial intelligence processing used by the SMS Android.
We may also use providers for website hosting, forms, analytics, payments, security, professional advice and support. We disclose only the information reasonably needed for the relevant function.
The current core providers listed above are based in the United States, and personal information may be stored or processed there. Cross-border processing can involve privacy and enforcement arrangements different from those in Australia. We take reasonable steps appropriate to the Service to assess providers, restrict access and use contractual and technical controls. We do not state that every overseas recipient is bound by the APPs in exactly the same way as an Australian entity.
Service providers and processing locations can change. Material changes affecting how personal information is handled will be reflected in this Policy where appropriate.
11. Security and separation of Client data
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include:
- separate Client sub-accounts within the managed agency environment;
- role-based access and restriction to authorised ReviewProsper personnel, authorised Client users and required providers;
- authentication controls and review of user access;
- encryption in transit where supported by the systems involved;
- controlled campaign releases, monitoring, logging and suppression records;
- reasonable provider assessment and contractual controls; and
- incident investigation and access removal when an engagement or authorised role ends.
No transmission, storage or artificial intelligence system is completely secure or error-free. We cannot guarantee absolute security, uninterrupted availability or that every automated output will be correct.
12. Data incidents and notification
We investigate suspected loss, unauthorised access or disclosure of personal information and take reasonable steps to contain and assess the incident. Where the Notifiable Data Breaches scheme or another legal notification obligation applies, we will follow the applicable assessment and notification requirements. We may also notify an affected Client or individual where appropriate to manage risk, even if a particular statutory notification threshold is not established.
13. Retention, deletion and suppression records
We retain personal information for the period reasonably needed to deliver the Service, maintain campaign and consent records, provide reporting and handover, resolve disputes, investigate complaints, protect security and meet accounting, insurance, contractual or legal obligations.
During an engagement, customer records, relationship history, campaign versions, conversation history, delivery records, campaign stages, bookings, review requests, handovers and reported outcomes may remain in the Client's ReviewProsper sub-account. The applicable proposal, order or service arrangement may set a more specific retention or deletion period.
When an engagement ends, we may provide or permit an agreed export or handover, remove Client-user access and close or archive the Client sub-account. Subject to agreed arrangements and records we reasonably need to retain, we take reasonable steps to delete or de-identify customer and campaign data after the applicable retention period. Provider backups and system logs may be removed according to the provider's normal backup and deletion cycle rather than immediately.
After other Recipient information is deleted, we may retain a minimal suppression record, such as the mobile number, suppression status and date, so that a person who opted out is not accidentally included in another campaign. This record is used to prevent further contact, not to continue marketing.
14. Cookies, analytics and website forms
Our website may use cookies and similar technologies needed to operate forms, remember preferences, understand site use, measure enquiries and protect the site. Depending on the tools active on the site, analytics or advertising technologies may collect IP address, browser, device and page-interaction information. Browser settings can be used to control some cookies, although disabling them may affect website functions.
Information submitted through a website form is used for the stated purpose, such as responding to an enquiry, assessing database fit or arranging a call. It may be added to ReviewProsper's managed workspace so the enquiry can be followed up and recorded.
15. Access, correction and questions about Recipient data
We use the access and correction principles in APP 12 and APP 13 as our operating standard. A person may ask what personal information we hold about them or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify identity before acting on the request.
Where information was provided by a Client, we may consult with or refer the request to that Client because it manages the underlying customer relationship and may hold the original source record. ReviewProsper may still need to correct the information in its own campaign workspace, apply a suppression or preserve a limited audit record.
We will respond within a reasonable period. Access may be limited where disclosure would affect another person's privacy, reveal confidential or legally privileged material, prejudice an investigation or where another lawful reason applies. If a request is declined, we will explain the reason where appropriate and describe how to raise a complaint.
16. Contact and privacy complaints
Questions, access or correction requests and privacy complaints can be sent to:
Privacy Officer - SEO BY DESIGN, trading as ReviewProsper
Email: [email protected]
Level 27, 101 Collins Street, Melbourne VIC 3000, Australia
Phone: 1300 667 241 or +61 489 083 592
Please provide enough information for us to understand the issue without sending unnecessary personal or sensitive information. We will acknowledge the complaint and aim to investigate and respond within a reasonable period.
If the Privacy Act applies to the matter and the person is not satisfied with our response, they may be able to contact the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992. Concerns about unsolicited commercial electronic messages may be directed to the Australian Communications and Media Authority at acma.gov.au.
17. Changes to this Policy
We may update this Policy when the Service, providers, legal requirements or our handling practices change. The current version will be available on our website and the "Last updated" date will identify the latest published version. Where a change materially affects an active Client or the agreed handling of Client data, we will communicate it where appropriate.