Overview
Allusio ("we", "us", "our") operates the Allusio platform, a production management and crew coordination tool for the screen industry, at allusio.tech (the "Service"). This policy applies to everyone who uses the Service: individual account holders, production teams, and the cast, crew, and contacts whose information gets entered into it.
Allusio is owned and operated by Ben Young, trading as Allusio. It is not a registered company or incorporated entity; it operates as an unincorporated business. This doesn't change your rights: the Privacy Act 2020 defines "agency" broadly enough to cover an individual carrying on a business, so the obligations in this policy apply in full regardless of corporate structure. References to "we", "us", or "Allusio" mean Ben Young trading as Allusio.
We are a New Zealand business and this policy is written to meet our obligations under the Privacy Act 2020, including the 13 Information Privacy Principles (IPPs) set out in section 22 of the Act, which govern how New Zealand agencies must collect, use, store, and disclose personal information. Allusio is an "agency" for the purposes of section 4 of the Act.
The short version: we collect what we need to run a production management tool, we don't sell data or use it for advertising, we disclose our infrastructure providers below, and you can request access, correction, or deletion of your personal information at any time. Because we're in beta, some of our internal practices are still evolving faster than a policy document can, so Section 10 spells out exactly what that means and doesn't mean.
Key terms and roles
A few terms are used consistently through this policy:
- "Account Holder" means anyone who creates an Allusio login (email and password, invite, or passkey).
- "Production Owner" means the Account Holder who creates a production and controls who's invited to it and what permissions they have.
- "Production Personnel Data" means information about cast, crew, agents, or other individuals that a Production Owner or their team enters into a production, including names, contact details, dates of birth, headshots, availability, contracts, and similar records.
- "Service Data" means everything else generated by using the app, including scenes, schedules, sets, wardrobe items, and shot lists.
Information we collect
Account information
When you create an account we collect your full name and email address, and a password, hashed and never stored in plain text, via Supabase Auth. If you set up a passkey, we store the associated WebAuthn credential instead of a password. If you're added via an invite code or early-access gate code, we also record the code used and its status.
Production and personnel data
Production Owners and their teams enter information into a production to run it, including:
- Cast: first and last name, date of birth, agent name, email, mobile number, headshot image, availability and conflict periods, and free text notes.
- Crew: first and last name, department, role, email, mobile number, headshot image, availability and conflict periods, and free text notes.
- Production members: the email address and permission level of anyone invited to collaborate on a production, and the status of that invite.
- Characters, scenes and scripts: scene numbers, synopses, page counts, interior/exterior and time-of-day tags, and the characters and extras associated with each scene.
- Locations and sets: names, physical addresses, and reference files or photos associated with a location, which may include private addresses.
- Schedules: shoot dates, call times, and events, which may be shared outside the app via a link (see Section 6).
We store this information on behalf of the Production Owner. It's entered by production staff, not by the individuals it describes. See Section 4.
Contracts and signatures
Where a production uses Allusio to send engagement contracts, we store the contract content, the signer's typed or drawn signature, their name, and the date and time of signing. Signing links sent to cast or crew use a unique, single-use token and don't require the signer to have an Allusio account.
Uploaded files and media
This includes headshots, wardrobe reference photos, production design reference images, and location photos or documents uploaded by production teams. We don't ask for or knowingly store body measurements, medical, or biometric data. Wardrobe records in Allusio track garments and items, not personal measurements.
Usage, device and diagnostic data
- IP address, used among other things to rate limit public contract signing links against abuse.
- Browser type, device type, and general connection metadata, largely captured by our network provider (Cloudflare) as traffic passes through.
- Authentication metadata such as sign-in timestamps and session status.
Communications and support
If you email us, or we email you about password resets, invites, or contract notifications, we retain that correspondence to assist you and keep a record of what was sent.
Your role for production data
This section matters, so we're stating it plainly: when you or your production add personal information about a third party, such as a cast member, crew member, agent, or contact, into Allusio, you're the one responsible for that information under privacy law, not us. We act as your service provider, storing and processing that information on your instructions to run the platform. We're not a party to the relationship between your production and the people whose data you enter.
In practice, this means:
- You're responsible for having a lawful basis to collect and enter someone's personal information, including letting them know, in the ordinary course of engaging them, that their details will be held in a production management tool.
- You're responsible for the accuracy of the information you enter, and for using Allusio's role-based permissions to limit who on your team can see it.
- If a cast or crew member wants their information accessed, corrected, or deleted, that request should generally go to the Production Owner first. We'll assist Production Owners in fulfilling it, and we'll step in directly if we can't reach the Production Owner or if the request concerns how Allusio itself has handled the data, for example a security issue.
- We'll access production data ourselves only where necessary: to provide support you've asked for, to investigate suspected misuse, security incidents, or technical faults, to enforce our terms, or where the law requires it.
This allocation of responsibility doesn't reduce our own obligations under the Privacy Act 2020 for information we hold. We still have to keep it secure, use it only for proper purposes, and respond to individuals who come to us directly. It simply reflects that, for most personnel data, your production is closer to the people involved and better placed to be the first point of contact.
How we use information
We use the information described above to:
- Provide, run, and maintain the Service, including features still in active development during beta.
- Authenticate you and keep accounts and productions secure.
- Send transactional email, including invites, password resets, and contract notifications.
- Respond to support requests and communicate with you about your account.
- Diagnose bugs, monitor reliability, and improve the product, including by reviewing how features are used in aggregate.
- Detect, investigate, and prevent fraud, abuse, or unauthorised access.
- Meet our legal obligations, including responding to lawful requests from authorities.
We don't sell personal information, use it to serve advertising, or use it to train third party or general purpose machine learning models. We may use de-identified or aggregated data (which is no longer personal information once it can't reasonably be linked back to you) to understand product usage and guide development.
Overseas storage and transfers
Under Information Privacy Principle 12 (section 22, Privacy Act 2020), we can only send your personal information overseas where the recipient is subject to comparable privacy safeguards, is contractually bound to protect it, the transfer is authorised or required by another New Zealand enactment, or another exception in IPP 12(1) applies. Separately, Part 8 of the Act (sections 192 to 193) lets the Privacy Commissioner prohibit an overseas transfer that would circumvent the Act; we're not aware of any transfer prohibition notice applying to us. We rely on our infrastructure providers' certifications and contractual commitments (referenced in Section 6) to meet the IPP 12 requirement.
Our database and file storage run on Supabase's AWS infrastructure, and our network traffic passes through Cloudflare's global edge network, both of which mean your information may be stored or processed outside New Zealand, including in Australia and/or the United States depending on our configured project region.
By using the Service, you acknowledge your information may be processed outside New Zealand as described above.
Security
Information Privacy Principle 5 (section 22, Privacy Act 2020) requires us to have reasonable security safeguards in place. We take steps appropriate to a platform of our size and stage, including:
- TLS encryption for all data in transit.
- Encryption at rest, provided by Supabase/AWS.
- Role and permission based access controls at the production level.
- Authentication handled by Supabase Auth, including support for passkeys, with passwords hashed rather than stored in plain text.
- Rate limiting on public, unauthenticated endpoints such as contract signing links.
No method of transmission or storage is completely secure, and this is especially true of a product still in active beta development. See Section 10. We can't guarantee absolute security, but we investigate and remediate vulnerabilities as we become aware of them, and we'll notify affected individuals and the Privacy Commissioner as required by law if a breach occurs (Section 15).
Retention
Information Privacy Principle 9 (section 22, Privacy Act 2020) requires us not to keep personal information for longer than is required for the purpose it was collected. In practice:
- We keep your account information for as long as your account is active, or as needed to provide the Service.
- If you delete your account, we'll delete or anonymise your personal information within 30 days, except where we need to keep it for legal, security, or dispute resolution reasons.
- Routine backups may retain a copy of deleted data for a further period of up to 90 days as part of our standard backup cycle, after which it's purged.
- Production Personnel Data entered by a Production Owner, for example a crew list you appear on, may be retained by that production after you personally leave it or delete your own account, since the Production Owner controls that record. You can ask the Production Owner to remove it, or contact us and we'll assist.
- During beta, we may need to retain diagnostic and support data (logs, error reports) for longer than in a mature product, to investigate recurring issues. See Section 10.
Beta program, additional terms
Allusio is currently in a beta / early access phase. Some features, security controls, monitoring, and internal data handling processes are still being built, tested, or refined as we grow. This section explains what that means for your data, on top of everything above.
- No uptime or integrity guarantee. We don't guarantee continuous availability, error free operation, or that data will never be lost, duplicated, or temporarily inaccessible during beta. We take reasonable steps to prevent this, but beta software carries more risk than a mature product, and we recommend keeping your own copies of anything critical (such as signed contracts) until this changes.
- Broader internal access, for now. To diagnose bugs, verify data integrity, and respond to support requests quickly during this phase, authorised Allusio personnel may need to access account and production data more directly than we expect to once the platform matures. We aim to limit this access to what's reasonably necessary and log it where practical.
- Practices may change quickly. We may adjust features, data fields, storage structures, or subprocessors during beta without individual notice in advance. Where a change affects how we handle personal information, we'll update this policy and, for material changes, notify Account Holders by email or in-app notice.
- Platform maintenance actions. We may temporarily restrict, suspend, or reset accounts, productions, or clearly marked test/demo environments at our discretion, to protect platform stability or security.
- Your statutory rights are unaffected. Nothing in this section limits or removes the rights the Privacy Act 2020 gives you. Access, correction, and the ability to complain to the Privacy Commissioner apply in full throughout the beta period, regardless of what else is changing under the hood.
Children and minors
Creating an account
The Service is not directed at, and account registration is not intended for, individuals under the age of 16. We do not knowingly let a child create an Allusio account.
Minors as cast or crew
Screen productions frequently involve minors, most commonly child actors. Because Allusio is used by production staff to manage cast and crew, a Production Owner's team may enter a minor's personal information (name, date of birth, contact details for a parent, guardian, or agent, and a headshot) as Production Personnel Data, even though the minor never interacts with Allusio directly.
Consistent with Section 4, the Production Owner is responsible for collecting and entering that information lawfully, for example with the informed involvement of a parent or guardian and in line with applicable child performer regulations, and for limiting who on the production can see it using Allusio's access controls. Allusio processes it only as instructed.
If you're a parent or guardian and believe a child's information has been added to a production without appropriate care, contact the relevant Production Owner directly, or contact us at the address in Section 18 and we'll assist in following it up.
Automated decision-making
We don't use your personal information to make automated decisions that have a legal or similarly significant effect on you.
Your rights under the Privacy Act 2020
You have the right to:
- Access (Information Privacy Principle 6): ask for a copy of the personal information we hold about you.
- Correction (Information Privacy Principle 7): ask us to correct information that's wrong or incomplete. If we disagree, you can ask us to attach a statement of correction to the record instead.
- Deletion: ask us to delete your personal information, subject to the exceptions in Section 9. Deletion isn't a standalone IPP right, but we offer it as standard practice.
- Portability: ask for your data in a structured, commonly used format.
To exercise any of these, email us at the address in Section 18, addressed to our Privacy Officer. In line with section 41 of the Privacy Act 2020, we'll respond as soon as reasonably practicable and no later than 20 working days after we receive your request. If we need longer, or if we intend to refuse or charge for a request, we'll tell you why within that period and let you know you can complain to the Privacy Commissioner about our decision. If your request relates to Production Personnel Data entered by someone else's production, see Section 4 for how that works in practice.
These rights are currently handled by email rather than a self-service tool in the app. That's on our roadmap, not yet shipped.
Data breaches
If a privacy breach occurs involving your personal information that has caused, or is reasonably likely to cause, serious harm, it's a "notifiable privacy breach" under Part 6 of the Privacy Act 2020 (sections 112 to 118), and we'll notify both the Office of the Privacy Commissioner and affected individuals as soon as practicable. In assessing serious harm we'll consider the factors listed in section 113, including the sensitivity of the information, whether it's protected by security measures, and who may have accessed it. Failing to notify a notifiable breach without reasonable excuse is itself an offence under the Act, carrying a fine of up to NZD 10,000 (section 118). Given our beta stage, we may also choose to notify you of breaches that don't strictly meet the serious harm threshold, as an extra precaution while our processes mature.
Changes to this policy
We may update this policy as the Service, and our beta program in particular, evolves. When we do, we'll update the effective date at the top of this page, and for material changes we'll notify you by email or in-app notice. Continuing to use the Service after a change takes effect means you accept the revised policy.
Complaints
If you believe we've mishandled your personal information, we'd rather hear from you directly first at the address below. If you're not satisfied with our response, you have the right under sections 69 to 70 of the Privacy Act 2020 to complain to the Office of the Privacy Commissioner:
Phone: 0800 803 909
Post: PO Box 10 094, Wellington 6140, New Zealand
Web: privacy.org.nz
Contact us
Questions about this policy, data requests, or privacy concerns: we're happy to help. Under section 201 of the Privacy Act 2020, every agency must appoint a Privacy Officer responsible for the agency's compliance with the Act. Ours is:
Email: allusioproductionsuite@gmail.com