TEP Client logo

Privacy Policy

The Everyone Project Australia

How we collect and use your personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles

Version 2.0 — 4 September 2026

At a glance

Who we are The Everyone Project ("TEP") — the trading name of Every1data Limited. We build and operate the TEP tool and we are the entity responsible for the personal information collected through it. Because we offer the tool in Australia we are bound by the Australian Privacy Principles (APPs). Contact details: section 1.
What the tool is An industry-wide initiative to understand more about the people working in your industry — for example their demographics and their experience of work. We typically collect this information directly from you through a short survey.
Why we’re giving you this So you understand what we collect, why, how we protect it, and the choices and rights you have. This is our privacy policy under APP 1.
Your privacy, in short Taking part is voluntary and every question is optional. We only collect what we need. We won’t disclose the survey answers you give us to anyone — including the organisation that engaged you — or use them for any purpose you haven’t agreed to. Your answers are encrypted and stored in Australia, and you can view, change or delete them at any time. If you have concerns, contact us; you can also complain to the Office of the Australian Information Commissioner.

Sections

1. Who we are and how to contact us

The Everyone Project ("TEP", "we", "us") is the trading name of Every1data Limited. We operate the TEP tool and we are the entity responsible for the personal information handled through it.

Operator Every1data Limited, trading as The Everyone Project (UK company number 16820575; registered office 71–75 Shelton Street, Covent Garden, London WC2H 9JQ). Because we offer the tool to people in Australia we carry on business here, giving us an "Australian link" under s 5B of the Privacy Act 1988 (Cth), so we are bound by the APPs.
Privacy Officer

[email protected]

For help using the tool, contact [email protected].

‘We’ in the policy refers to The Everyone Project and the people who work for it, including its employees and contractors. This is our general privacy policy. Additional protections may apply to particular functionality — for example the collection notice shown in the survey (section 6). Defined terms are in section 16.

2. Who this policy is for

This policy applies to three groups. Find the group that applies to you.

Group Who this means
A. Contributors People invited — or who volunteer — to share information about themselves through the tool, usually because they have contributed (paid or unpaid) to a screen project registered on it. Contributors may include children and other young or vulnerable people (section 12).
B. Organisation users Employees, contractors and representatives of organisations that use the tool — typically production companies, funders and broadcasters — and the people they invite.
C. Website visitors Anyone who visits our marketing and sign-in pages.

It also applies to personal information we hold about our own staff, contractors and suppliers, as well as the contact details of individuals who work for current, past and prospective customers, suppliers, and other types of professional associates and personal contacts. We may check supplier details against public registers such as ASIC.

3. What personal information we collect

3A. Contributors

From the organisation that engaged you:

  • Contact information — your name and email address.

  • Role information — the project you contributed to and your role (e.g. job title).

From you:

  • Your survey answers (self-reported information) — only if you choose to provide them. These may include demographic information about you, your work and your experience of equity and inclusion. Most of this is "sensitive information" under the Privacy Act, so we give it extra protection (sections 6 and 10).

  • Usage information — how you use the tool, so we can operate, secure and improve it.

  • Support information — anything you give us when you contact us for help.

3B. Organisation users

  • Account and contact information (name, work email, role, organisation, login details); the projects you register; usage information; and support information. We do not knowingly collect sensitive information about organisation users.

3C. Website visitors

  • Device and connection data and cookies. Strictly necessary cookies make the site work; we also use limited analytics cookies to improve it.

4. Where we get your information

  • Directly from you — wherever practical to do so: when you complete a survey, create an account, contact us or use the tool.

  • From the organisation that engaged you — when they register their projects.

  • From other authorised users — when they invite you or add you to an account.

  • Automatically — through cookies, server logs and usage analytics.

  • Limited public sources — for example public project credits, where we can do so by lawful and fair means (APP 3.5).

When we receive your details from someone else. Your name, email address and role information usually reach us from the organisation that engaged you, not from you, and we do not rely on that organisation having obtained your consent. APP 3.6 permits collection from someone other than you where collecting it directly is unreasonable or impracticable, which is the position here: until an organisation tells us you worked on a project, we cannot identify or contact you.

Two limits apply. We take only contact and role information this way — sensitive information comes only from you, with your consent (section 6). And we take reasonable steps under APP 5 to tell you promptly that we hold your details: the invitation we send indicates who we are, what we hold, where we got it, what we will use it for, disclosure, and how to access, correct or delete it. You can unsubscribe or ask us to delete your details at any time.

We maintain some records of the interactions we have with individuals, including the services we have provided to you and responses to any enquiries you have made. We categorise information for reporting purposes only (section 13).

5. How and why we use your information

We use personal information only for the purpose we collected it for, or a directly related purpose you would reasonably expect, unless you consent otherwise or the Privacy Act permits or requires it (APP 6). We use it to:

  • invite contributors and run the voluntary survey;

  • with your consent, analyse your survey answers to produce anonymised reporting and benchmarks;

  • provide the tool to organisation users, manage their access and provide technical or other support to you;

  • operate, secure and improve the tool, and answer your enquiry about our services and complaints;

  • manage our employment or business relationship with you;

  • promote our other programs, products or services which may be of interest to you (unless you have opted out from such communications) — for contributors only where you have agreed, and every message carries an unsubscribe link (APP 7); and

  • meet our legal and accountability obligations, and establish, exercise or defend legal claims.

Reporting produced by the tool is de-identified so that it does not contain personal information (section 10).

If you have taken part before. We use your existing record to link you to further projects rather than asking you to complete the survey again. We tell you each time, and you can choose project by project not to be associated.

We do not intentionally collect unsolicited personal information. Where we receive it anyway, we review it as soon as practicable and, if we could not have collected it under APP 3, destroy or de-identify it unless the law requires us to keep it (APP 4).

Most of what you tell us in the survey is "sensitive information" under the Privacy Act — for example information about your ethnic origin, religious or philosophical beliefs, sexual orientation or practices, and experience of disability. APP 3.3 allows us to collect it only with your consent, and only where it is reasonably necessary for our functions. So:

  • We only collect your survey answers with your consent, and we tell you what we are asking for and why before you decide, in the collection notice shown in the survey.

  • Your consent is captured on your own device before your answers are sent to us. You can try the survey first and decide at the end whether to contribute.

  • You can skip any question, choose "prefer not to say", or decline altogether — it does not affect anything else.

  • When you submit your answers, you consent to us using them only to: (a) create reports and analysis on the industry workforce, without identifying you; (b) seek further consent or information from you; (c) maintain and improve our service; and (d) remind you that we hold this information.

  • You can change your mind at any time and delete your answers by signing in or contacting us.

  • Your answers are protected by client-side field-level encryption and reporting is anonymised, so you cannot be identified (section 10).

7. Who we disclose information to

We do not sell personal information, and we do not disclose your survey answers to anyone other than you. We disclose other personal information only where necessary and lawful:

Recipient Purpose and safeguards
Our service providers Our third-party service providers are bound by contract to only use your personal information on our behalf, under our instructions, to the standards we set, and to bind their subcontractors equivalently. Because we retain effective control, giving personal information to them is generally a "use" rather than a "disclosure" under the Privacy Act. The categories are cloud hosting; data storage; productivity and collaboration; email and bulk communications; finance and billing; and customer support and analytics. A current list of the providers in each is available from our Privacy Officer on request.
Organisations using the tool Access only to (i) information they provided themselves and (ii) anonymised reporting that is not personal information. They are contractually prohibited from attempting to re-identify anyone, and they never see your survey answers.
Professional advisers; regulators, courts and law enforcement Where we need advice, or where required or authorised by law, court order or to establish or defend legal rights. We do not disclose survey answers to advisers.
A successor organisation If our business or assets are reorganised or transferred, personal information may pass to the successor under the same protections.

Links to other sites. If we ever provide links to third party websites. These linked sites are not under our control, and we are not responsible for the conduct of companies linked to or from our website. Check their own terms and privacy policy before giving them your personal information.

8. Where your information is held

We store your personal information in Australia. Your survey answers and the other personal information you give us are held at rest in Microsoft’s Australian Azure regions.

Some other information is handled overseas. Contact, account, support, email-delivery and sign-in details are handled by our providers’ systems, and by our own authorised personnel, outside Australia — including in the United Kingdom and the European Union. Our network and security provider operates a global edge network; information passing through it is in transit only.

Sensitive information. Sensitive information within your survey answers is held at rest in Australia and stays encrypted at field level throughout, including when our systems are accessed for support.

How we protect it. Where personal information goes overseas, we remain accountable for it under s 16C of the Privacy Act and take the reasonable steps APP 8.1 requires: written contracts imposing APP-equivalent obligations, restricted and logged access, and encryption in transit and at rest. No country is currently prescribed under Australian law as having a substantially similar privacy law, so we do not rely on that exception.

9. How long we keep your information

We do not set fixed retention periods. We keep personal information only for as long as we are using it for a purpose described in this policy, review what we hold periodically, and then destroy or de-identify it as APP 11.2 requires. Contributors can delete their survey answers at any time. We maintain an internal retention policy recording how we apply these rules.

10. How we keep your information safe

We take the security of your information seriously. All data is managed in accordance with our Data Security Measures and Access Policy. Our measures are kept under review and currently include:

  • An information security management system certified to ISO/IEC 27001.

  • Encryption of personal information in transit and at rest, with client-side field-level encryption of your survey answers.

  • Differential privacy and related privacy-preserving techniques applied to all reporting outputs.

  • Role-based access controls, multi-factor authentication and audit logging appropriate to the sensitivity of the information.

  • Storage of your personal information in highly secure Microsoft data centres in Australia.

  • Regular security testing, monitoring, staff training and confidentiality undertakings.

  • A documented breach-response process. Where a data breach is likely to result in serious harm we will notify affected individuals and the Office of the Australian Information Commissioner, as Part IIIC of the Privacy Act requires.

11. Your rights and choices

The tool is designed to give you direct control:

  • View and download — sign in to see and download your information.

  • Correct or update — edit your survey answers directly.

  • Link or unlink — choose, project by project, whether your survey answers are associated with a project.

  • Delete — delete your survey answers at any time; you can keep your contact details on file so we respect your contact preferences.

  • Stop being invited — unsubscribe from invitations at any time.

In addition, under APP 12 you can ask for access to the personal information we hold about you, and under APP 13 you can ask us to correct it. We will take reasonable steps to make appropriate corrections to personal information so that it is accurate, complete and up to date. We aim to respond within 30 days. We may need to verify your identity first, and where role information came from the organisation that engaged you we may need to consult them before changing it. If we refuse access or correction, we will tell you why and how to complain.

To exercise these rights, contact our Privacy Officer (section 1). We will periodically remind you that we hold your information and how to update or delete it.

12. Children and young people

Contributors can include children, such as child actors. Some survey questions are not asked of people under 15. Where a contributor is under 15 or otherwise cannot consent for themselves, a parent, guardian or authorised representative can consent and complete the survey on their behalf, and the tool provides flows designed for this. Wording is clear and age appropriate. If you are a parent or guardian and believe we have collected your child’s information without appropriate consent, please contact us (section 1).

13. Automated decision-making

We do not make decisions about you solely by automated means that could reasonably be expected to significantly affect your rights or interests. We use automated processing to:

  • categorise personal information for reporting purposes;

  • apply differential privacy and other privacy-preserving techniques before reporting;

  • classify and prioritise support requests; and

  • detect and limit abusive or suspicious activity, for example rate-limiting or temporary suspensions.

The kinds of personal information used in that automated processing are your survey answers, your role and project information, usage information and support information. Where any of it could meaningfully affect you, a person is involved before a decision is taken.

14. Changes to this policy

We will review this policy regularly, and we may update it from time to time. The current version and date are shown at the top. Where changes are material, we will take reasonable steps to notify active users by email or through the tool.

15. How to make a complaint

If you have a question or a complaint about how we handle your personal information, contact our Privacy Officer first, at [email protected], so we can try to put things right.

While we endeavour to resolve complaints quickly and informally, if you wish to proceed to a formal privacy complaint, please put it in writing by email. We will acknowledge it promptly and respond within 30 days.

If we do not respond within 30 days, or you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) by calling them on 1300 363 992, making a complaint online at www.oaic.gov.au, or writing to them at OAIC, GPO Box 5288, Sydney NSW 2001.

16. Definitions

TEP / we / us The Everyone Project, the trading name of Every1data Limited — the entity responsible for personal information collected through the tool.
The tool TEP’s platform for measuring and reporting workforce diversity, equity and inclusion in the screen sector, as deployed in Australia.
Contributor An individual who has contributed (paid or unpaid) to a project registered on the tool, or expects to.
Survey answers (self-reported information) Information you choose to provide about yourself in the survey and any follow-up, or when you edit it later. It does not include information about you that we receive from anyone else — such as your name, email and role provided by the organisation that engaged you.
Personal information Information or an opinion about an identified individual, or one who is reasonably identifiable. Sensitive information is the subset given extra protection: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union or professional association membership, sexual orientation or practices, criminal record, and health, genetic and biometric information (both s 6(1) Privacy Act).
Differential privacy Adding carefully calibrated random noise to results so that individual contributions cannot be reverse-engineered or re-identified.
APP An Australian Privacy Principle, in Schedule 1 to the Privacy Act 1988 (Cth).