Skip to content
Go to homepageDrova logo

Privacy Policy

Effective starting: 12 August 2026

This privacy policy ("Privacy Policy") applies to Drova Pty Limited and our related entities (“Drova”, “us”, “we” and “our”). It explains how we collect, use, store, disclose, and protect your Personal Information when you use Drova Services, visit our websites, or otherwise interact with us. It also explains how you may contact us to raise any privacy concerns or to otherwise exercise your rights.

We recommend you read this Privacy Policy in full.

1. Terms Used in Our Privacy Policy

“Drova Services” refers to any of the products and services we may provide to you.

“Personal Information” refers to any information that may identify you or could be reasonably used to identify you, directly or indirectly. This includes names, identifiers, contact details, location data, online identifiers, and any information you provide, upload, or generate through Drova Services.

“User Content” refers to any content you create, upload, store, communicate, or display through Drova Services. Content may include Personal Information, including Sensitive Information.

2. Updates to Our Privacy Policy

We may update this Privacy Policy periodically. When we do, we will update the “Effective Starting” date. If changes are material, we will notify you via email, website notices, or login alerts.

If you do not agree with the updated terms, you should stop using Drova Services or exercise your rights as described in this Privacy Policy, or otherwise as provided by law.

3. Why Do We Collect Your Personal Information?

We collect Personal Information to provide, operate, improve, and secure Drova Services. If we cannot collect certain information, you may not be able to use Drova Services or to create an account.

We use Personal Information to:

  • Perform and administer Drova Services and manage our relationship with you as a customer;
  • To assess whether to take you on as a new client;
  • To perform background checks when required by law;
  • Understand how you use Drova Services;
  • Personalise your experience;
  • Develop new features and products;
  • Conduct analytics and market research to understand how Drova Services are used;
  • Provide predictive functionality, recommendations, comments and prompts;
  • Respond to support requests, inquiries and communications;
  • Process transactions;
  • Maintain accurate records for billing and administration;
  • Identify, prevent and resolve technical or security issues;
  • Send operational communications;
  • Send marketing communications (where permitted) and manage your marketing preferences;
  • Enforce agreements;
  • Compare information for accuracy;
  • Assess employment applications and evaluate candidate qualifications;
  • Maintain employment records;
  • Comply with our legal obligations, respond to court orders or legal process, and fulfil regulatory requirements or reporting obligations;
  • Protect our legal rights and interests;
  • Perform any other functions described in our terms and conditions or this Privacy Policy.

We may also use Personal Information for additional purposes disclosed at the time of collection.

4. What Personal Information Do We Collect?

The Personal Information we may collect includes information that you provide voluntarily to us, information that we collect automatically and information that we obtain from third party sources.

We may also process Personal Information incorporated in the content that users create, provide, post, host, upload, store, communicate or display when you use the Drova Services (“User Content”). This may include Sensitive Information, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. Where we process Personal Information in content, we do so on behalf of our customers and users and it is their responsibility to have lawful grounds to use that Personal Information.

4.1 Information You Provide

  • Name, email, phone number, mailing address;
  • Usernames, social media profiles, job titles, company name;
  • Profile information and photos;
  • Billing information (payment details, billing address);
  • Communication preferences;
  • Content you post, upload, store, or generate;
  • Interactions with other users;
  • Information submitted through forms, emails, or support channels;
  • Your preferences for marketing and the Drova Services;
  • Employment history, professional experience, required authorisation and licences, professional registrations, and information about your right to work in the relevant jurisdiction (when you apply for a job with us).

4.2 Information We Collect Automatically

  • IP address, browser type, configuration, plug-ins;
  • Date/time of access, referring webpage;
  • Language preferences;
  • Cookie data;
  • Device type, operating system, device identifiers, application IDs;
  • Crash information;
  • General location (via Wi-Fi or IP address).

4.3 Analytics Information

We collect analytics data about:

  • Username and IP address;
  • Features accessed;
  • Domain names and identifiers;
  • Attachments (filenames, sizes);
  • Aggregated usage data (non-identifying).

4.4 Third-Party Integrations

If you integrate third-party services:

  • We may receive account information from those providers;
  • We do not collect or store third-party passwords.

4.5 Marketing and User Base Information

We may collect:

  • Information from marketing partners;
  • Publicly accessible databases;
  • Social media;
  • Related bodies corporate;
  • Service partners.

5. How We Collect Personal Information

We collect Personal Information:

  • When you create or update an account;
  • When another user creates an account for you;
  • When you use Drova Services;
  • Through your device or browser;
  • When you submit information via forms, emails, or communications;
  • From third-party marketing partners;
  • From publicly accessible sources;
  • From related bodies corporate;
  • From third-party service providers you integrate;
  • By generating analytics data through queries and usage analysis.

6. How We Disclose Personal Information

We may disclose Personal Information to:

6.1 Team Administrators

If you use Drova as part of an organisation, administrators may:

  • Access and control your account;
  • Retrieve, share, or delete your Personal Information.

6.2 Service Providers

Technology, hosting, analytics, and customer support providers may access Personal Information to facilitate and improve Drova Services.

6.5 Business Transfers

If Drova is sold or restructured, Personal Information may be transferred to the new owner.

6.6 Marketing

We may disclose Personal Information to third parties for marketing only with your consent or where lawful grounds exist.

6.7 Professional Advisers

We may disclose Personal Information to bankers, auditors, insurers and insurance brokers, legal advisers and other professional advisers to obtain professional advice, or to comply with contractual requirements or law.

6.8 Storage and Offshore Transfers

We store your personal information in Australia. However, your information may be accessed from or transferred to locations outside Australia (including the USA and UK) in these circumstances:

  • When our service providers are located overseas
  • When we work with overseas business partners
  • When using cloud-based services or data storage solutions

Our Approach to Overseas Disclosure

Before disclosing your personal information overseas, we take reasonable steps to ensure that the recipient treats your information in accordance with applicable law by only sending what is necessary, requiring recipients to protect your information through contractual agreements which require the recipient to comply with the privacy standards in applicable law or through other mechanisms that provide comparable safeguards and by monitoring how recipients handle your information.

7. Data Retention, Access, Correction and Deletion

We retain Personal Information where:

  • We have a legitimate business need; or
  • Retention is required under legal, tax, or accounting obligations;
  • Retention is permitted under privacy law applicable to User Content;
  • Retention is allowed under contracts with customers.

When no longer needed, we will delete or anonymise Personal Information or securely store it until deletion is possible (eg. backups).

8. Artificial Intelligence and Similar Technologies

We may use automated processing, including machine learning and artificial intelligence technologies, to help provide, improve and secure Drova Services. For example, automated processing may be used to:

  • generate recommendations, comments, prompts or suggested actions;
  • improve search, categorisation and workflow efficiency;
  • detect fraud, misuse, spam or security threats;
  • personalise aspects of your experience with Drova Services.

Automated processing assists our services but is not intended to produce decisions that have legal or similarly significant effects on individuals without appropriate human involvement. Where applicable privacy laws provide rights relating to automated decision-making or profiling, you may contact us to request further information or to exercise those rights.

Data Protection and Security

When we work with third-party AI providers, we ensure they handle your personal information in accordance with privacy laws through contractual requirements and appropriate safeguards.

Your Rights and Our Commitments

Any information generated or inferred about you by AI technologies is treated as Personal Information, and you maintain all the rights outlined in this Privacy Policy. When using AI with your Personal Information, we commit to:

Transparency and Control

  • We'll inform you when AI is used to make decisions that may significantly affect you
  • We maintain human oversight and review of significant AI-generated decisions
  • Our staff are trained to understand AI limitations and verify outputs before relying on them
  • We implement processes to verify the accuracy of AI-generated outputs

Security

  • We use appropriate technical and organisational measures to maintain the security and integrity of your personal information
  • We regularly test and monitor AI outputs for accuracy and reliability

Risk Mitigation

  • We regularly assess and document risks associated with using AI to process personal information
  • We implement appropriate measures to address these risks
  • We continuously monitor AI performance and regularly review their impact

9. Cookies, Pixels and Tracking Technologies

We use cookies, tracking pixels and similar technologies on our website and in our emails to:

  • Improve user experience;
  • Remember your login status;
  • Make interfaces more user-friendly;
  • Maintain session security;
  • Provide personalised features;
  • Store your preferences;
  • Enable core website features;
  • Target advertising; and
  • Support analytics.

You can manage these technologies by:

  • Adjusting your browser settings to block or delete cookies
  • Using privacy-focused browser extensions
  • Configuring your email client to block images
  • Using our cookie preference settings

Some features may not function if cookies are disabled.

Google Analytics

We use Google Analytics to understand how people use our website. This involves cookies that collect information about your browsing activity. You can opt out of Google's advertising features through your Google account settings, browser add-ons, or your device's privacy settings. Google provides various tools and options to control how your data is used for advertising purposes. You can learn more about how Google uses your data and your available options on Google's privacy pages.

10. Security

In storing your Personal Information, we use a number of security and organisational measures and technologies to safeguard your Personal Information from unauthorised access, modification or disclosure and misuse, interference or loss. We have personnel tasked with protecting your information, developing new security features, and identifying and mitigating vulnerabilities. Our existing security measures include encryption, two-factor authentication, and notifications when new devices and apps are connected with your user account. We also have in place security measures and policies focused on restricting access to sensitive information to authorised personnel, and we consistently review our security procedures and architecture with a consideration of new technologies and updated methods. Despite our reasonable efforts however, no system is ever perfect.

Whilst we hold your information on a secured server behind a firewall and we encrypt data transfer using 256bit SSL encryption, please be aware that there are inherent risks in transmitting information using the internet.

The Drova Services are certified to meet ISO 27001 information security standards. Please contact us for further information on the scope of our ISO 27001 certification.

12. International Data Transfers (EEA and UK Visitors)

Your Personal Information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have privacy laws that are different to the laws of your country (and, in some cases, may not be as protective).

Specifically, our group companies and third-party service providers and partners operate around the world and, in particular, in Australia, the United States of America, the Netherlands, Germany, South Africa, Hong Kong, the United Kingdom and Vietnam. This means that when we collect your Personal Information we may process it in any of these countries, pursuant to any privacy laws that apply to Your Content. We currently host our servers for the Drova Services using a third-party hosting provider, Amazon Web Services (“AWS”).

13. California User Requests

Californian users of the Drova Services will have additional rights afforded to them under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA, effective 1 January 2023).

The CCPA and the CPRA provide California users various rights with respect to the personal information we collect, including the right to, with certain limitations:

  • request to access the personal information we hold about you;
  • request that we delete any or all of your personal information;
  • opt out of the “sale” of your personal information;
  • opt out of the “sharing” of your personal information for cross-context behavioural advertising.

California users of the Drova Services may make a request with respect to any of these rights by contacting us by using the contact details provided under the ‘Contacting Drova about Privacy’ heading below.

14. Your Privacy Rights

You have the following privacy rights, regardless of the legal jurisdiction of Your Content:

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable privacy laws.

Please note that we do not offer any of the rights described above with respect to any Personal Information that is incorporated in any User Content. We process such content on behalf of our customers and if your Personal Information is contained in any such content, you should contact the customer on whose behalf we have stored the information.

  • If you wish to access, correct, update or request deletion of your Personal Information, you can do so at any time by using the setting made available via the Drova Services or by, if settings are not available via the Drova Services, by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below. In the event we cannot grant you access to your Personal Information, we will tell you why.
  • You can object to processing of your Personal Information or ask us to restrict processing of your Personal Information. Again, you can exercise these rights by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below.
  • You have the right to opt-out of marketing communications we send you at any time, and for which you have previously elected to opt-in. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided under the “Contacting Drova about Privacy” heading below. If you do opt out, please provide us sufficient time to process your preferences. Additionally, if you do opt out, we may still contact you for transactional or informational purposes, and with these purposes potentially including customer service issues, payment inquiries, or product inquiries.
  • If we have collected and processed your Personal Information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful processing grounds other than consent.
  • You have the right to complain to a privacy authority about our collection and use of your Personal Information. For more information, please contact your local privacy authority. (Contact details for data protection authorities in the European Economic Area, Switzerland, United Kingdom and certain non-European countries (including the US and Canada) are available here.)

15. Additional Privacy Rights (EEA and UK Visitors)

In addition to the rights you have outlined under “Your privacy rights”, you also have the below rights.

Right to Erasure

You can request deletion of your personal data in certain limited circumstances as set out in European Data Protection Law, such as where the data is no longer necessary or has been unlawfully processed. This right is not absolute and we may be required or entitled to retain your data for legal, regulatory or legitimate business reasons.

Right to Restrict Processing

You can ask us to suspend processing where:

  • You contest the accuracy of the data
  • Processing is unlawful but you don't want erasure
  • We no longer need the data but you need it for legal claims
  • You've objected to processing pending verification of our legitimate grounds

Right to Data Portability

Where technically feasible, you can receive your personal data in a structured, commonly used format or have it transmitted to another controller where:

  • Processing is based on consent or contract
  • Processing is automated

Right to Object

You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.

16. Contacting Drova about Privacy

Please contact us using the below details if you have queries about our Privacy Policy and privacy practices, or the way we deal with your Personal Information. You may also contact us using these details if you wish to exercise any of your privacy rights described in the section entitled “Your privacy rights” above.

Postal Address: Drova Level 1, 47 York Street, Sydney NSW 2000 Australia Telephone: +61 1300 333 472

Email: hr@drova.com

Position title and name:

Co-founder & Head of ESGRC: Rachel Riley

Where you are located in the European Economic Area (EEA) or the United Kingdom, you may also contact Drova Limited:

Postal Address: 22 Wycombe End,

Beaconsfield, Buckinghamshire HP9 1NB United Kingdom Telephone: +442045257290 Email: hr@drova.com

Position title and name:

Co-founder & Chief Commercial Officer: Rachel Riley

When you request that we access or correct your Personal Information, we will need to locate the relevant information, so it would greatly assist us if you could supply as much supporting detail as possible. Where we refuse any access or correction request, we will comply with any requirements under applicable laws to notify you of our reasons for doing so and the mechanisms through which you may complain. Where we deny a request to correct information after you have made a request to us, we will comply with any applicable legal requirements to advise you of any inaccuracies or lack of necessary detail within your request.