Legal
Privacy Policy
Last updated: 13 May 2026
This Privacy Policy explains how HEFTE collects, uses, discloses, stores, and protects your personal information. HEFTE is operated by Rockley Consulting Pty Ltd (ABN 78 673 819 773) ("we", "us", "our"), and is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Questions? Contact us at contact@hefte.au.
1. What this Privacy Policy covers
This Privacy Policy covers personal information collected through:
- The HEFTE website at hefte.au, including the quiz, calculator, comparison tools, and contact forms.
- Emails you send to our addresses ending in @hefte.au.
- Any other interactions you have with HEFTE.
It does not cover the privacy practices of the EFTPOS providers we refer you to. Once your information is shared with a referral partner under section 4 below, the partner's own privacy policy applies to their handling of it.
2. What personal information we collect
We collect the following kinds of personal information when you use HEFTE:
Through the contact and matching forms:
- Your name and the business you operate.
- Your email address.
- Optional: your phone number.
- Information about your venue (venue type, point-of-sale system, number of venues and terminals, monthly card volume, current EFTPOS provider, urgency, and specific requirements such as Pay@Table or QR ordering).
Automatically when you visit hefte.au:
- IP address (used to enforce per-IP rate limiting on form submissions).
- Browser type, device, and operating system.
- Pages visited and time spent on each page (for site analytics).
- Cookies and similar technologies (see section 7).
If you correspond with us by email:
- The contents of your email and any information you choose to include.
We do not collect sensitive information (as defined in the Privacy Act), financial account details, or merchant statement data through this website.
3. Why we collect personal information
We collect personal information to:
- Match you to an EFTPOS provider suited to your venue.
- Forward your enquiry to that provider so they can contact you with a quote.
- Send you a confirmation of your submission and a record of the details you provided.
- Operate, secure, and improve the HEFTE website.
- Comply with our legal obligations.
- With your consent, send you occasional updates about EFTPOS regulation, pricing, and HEFTE-related news.
If we cannot collect the personal information described above, we may not be able to provide you with a referral or respond to your enquiry.
4. How we share your personal information
Referral partners.
When you submit a matching enquiry through hefte.au, we forward the details you provided to the EFTPOS provider we have matched you to. HEFTE has referral arrangements with Zeller, Zero Payments, H&L Pay and urpay. By submitting the form, you consent to your details being shared with the matched provider for the purpose of providing you with a quote and contacting you about that quote.
Once your information is shared with a referral partner, the partner is responsible for handling it under its own privacy policy.
Service providers.
We use the following third-party service providers to operate the HEFTE website:
| Provider | Purpose | Location of data processing |
|---|---|---|
| Vercel Inc. | Website hosting and serverless functions | United States |
| Notion Labs Inc. | Lead storage in our Notion workspace | United States |
| Maileroo | Transactional email delivery | European Union (Germany, Netherlands, Finland) |
| Cloudflare Inc. | Bot protection (Turnstile) and content delivery | United States and globally |
Each of these providers has its own privacy and security framework. We have selected providers with industry-standard security and privacy practices and, where applicable, contractual commitments to data protection.
Compliance and protection.
We may disclose personal information where required or authorised by law, or to protect our or another party's rights, property, or safety.
We do not sell personal information to any party, and we do not share it for marketing purposes by any third party other than as described above.
5. Disclosure to recipients overseas
As shown in the table above, several of our service providers process data outside Australia. Under Australian Privacy Principle 8, we remain accountable for the handling of personal information disclosed to overseas recipients unless an exception applies.
We have taken reasonable steps to satisfy ourselves that each overseas recipient handles personal information consistently with the Australian Privacy Principles, including by reviewing each provider's published privacy and security practices and (where applicable) their contractual commitments to data protection.
6. How we store and protect personal information
Lead enquiries are stored in our Notion workspace, which is protected by account-level access controls, multi-factor authentication for administrative access, and the security measures Notion itself provides.
Emails are transmitted via Maileroo and stored within the relevant inbox (contact@hefte.au or related @hefte.au addresses).
Site analytics and protection cookies are stored as described in section 7.
We retain lead enquiries in Notion for twenty-four (24) months from the date of submission, after which they are reviewed and either deleted or anonymised. If you ask us to delete your information sooner, we will do so unless we are required by law to retain it.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure.
7. Cookies and similar technologies
The HEFTE website uses cookies and similar technologies for the following purposes:
| Cookie / technology | Purpose | Retention |
|---|---|---|
_ga | Site usage analytics (Google Analytics 4) — aggregate data, not personally identifiable | 2 years |
_ga_ZJ18E32F5R | GA4 session tracking for this property — aggregate data, not personally identifiable | 2 years |
| Vercel platform cookies | Site delivery and routing | Session |
| Cloudflare Turnstile | Bot protection on contact form (token-based — no cookie set on this domain) | Session |
| Vercel Web Analytics | Aggregate site analytics — first-party only, no personal data transferred | Session |
| Vercel Speed Insights | Core Web Vitals performance monitoring — first-party only | Session |
You can disable cookies in your browser settings. Some parts of the website, including the contact form, may not function correctly without certain cookies.
We do not use cookies for advertising or cross-site tracking.
8. Your rights and choices
You have the right to:
- Access the personal information we hold about you.
- Correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
- Request deletion of your information from our records, subject to any legal obligation we have to retain it.
- Withdraw consent to future communications by replying "unsubscribe" to any HEFTE email or contacting us at contact@hefte.au.
- Complain about how we have handled your personal information (see section 11).
To exercise any of these rights, email contact@hefte.au. We will respond within a reasonable period (and in any event within thirty (30) days).
9. Direct marketing
We will only send you direct marketing communications if you have given us your express consent, or where we are otherwise permitted to do so under the Spam Act 2003 (Cth) and the Privacy Act 1988 (Cth).
Every marketing email we send will include an unsubscribe link or instructions for opting out. You can also opt out at any time by emailing contact@hefte.au.
10. Children
HEFTE is a business-to-business service and is not directed to individuals under sixteen (16) years of age. We do not knowingly collect personal information from children. If you believe we hold information about a child, contact us and we will delete it.
11. How to complain
If you believe we have handled your personal information in a way that breaches the Privacy Act 1988 (Cth) or this Privacy Policy, please contact us first at contact@hefte.au with a description of your concern. We will investigate and respond to your complaint within a reasonable period (and in any event within thirty (30) days).
If you are not satisfied with our response, you can lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
- Website: www.oaic.gov.au
- Phone: 1300 363 992
12. Changes to this Privacy Policy
We may update this Privacy Policy from time to time. The version in force at any time will be the version published at hefte.au/privacy with the most recent "Last updated" date. Material changes will be highlighted on the home page for a period of at least thirty (30) days.
13. Contact
For any privacy enquiry, contact:
Privacy Officer
Rockley Consulting Pty Ltd
PO Box 113
Claremont TAS 7011
Australia
Email: contact@hefte.au
Operated by Rockley Consulting Pty Ltd, ABN 78 673 819 773.