Privacy Policy
Effective starting: 12 August 2026
This privacy policy ("Privacy Policy") applies to Drova Pty Limited and our related entities (“Drova”, “us”, “we” and “our”). It explains how we collect, use, store, disclose, and protect your Personal Information when you use Drova Services, visit our websites, or otherwise interact with us. It also explains how you may contact us to raise any privacy concerns or to otherwise exercise your rights.
We recommend you read this Privacy Policy in full.
1. Terms Used in Our Privacy Policy
“Drova Services” refers to any of the products and services we may provide to you.
“Personal Information” refers to any information that may identify you or could be reasonably used to identify you, directly or indirectly. This includes names, identifiers, contact details, location data, online identifiers, and any information you provide, upload, or generate through Drova Services.
“User Content” refers to any content you create, upload, store, communicate, or display through Drova Services. Content may include Personal Information, including Sensitive Information.
2. Updates to Our Privacy Policy
We may update this Privacy Policy periodically. When we do, we will update the “Effective Starting” date. If changes are material, we will notify you via email, website notices, or login alerts.
If you do not agree with the updated terms, you should stop using Drova Services or exercise your rights as described in this Privacy Policy, or otherwise as provided by law.
3. Why Do We Collect Your Personal Information?
We collect Personal Information to provide, operate, improve, and secure Drova Services. If we cannot collect certain information, you may not be able to use Drova Services or to create an account.
We use Personal Information to:
- Perform and administer Drova Services and manage our relationship with you as a customer;
- To assess whether to take you on as a new client;
- To perform background checks when required by law;
- Understand how you use Drova Services;
- Personalise your experience;
- Develop new features and products;
- Conduct analytics and market research to understand how Drova Services are used;
- Provide predictive functionality, recommendations, comments and prompts;
- Respond to support requests, inquiries and communications;
- Process transactions;
- Maintain accurate records for billing and administration;
- Identify, prevent and resolve technical or security issues;
- Send operational communications;
- Send marketing communications (where permitted) and manage your marketing preferences;
- Enforce agreements;
- Compare information for accuracy;
- Assess employment applications and evaluate candidate qualifications;
- Maintain employment records;
- Comply with our legal obligations, respond to court orders or legal process, and fulfil regulatory requirements or reporting obligations;
- Protect our legal rights and interests;
- Perform any other functions described in our terms and conditions or this Privacy Policy.
We may also use Personal Information for additional purposes disclosed at the time of collection.
4. What Personal Information Do We Collect?
The Personal Information we may collect includes information that you provide voluntarily to us, information that we collect automatically and information that we obtain from third party sources.
We may also process Personal Information incorporated in the content that users create, provide, post, host, upload, store, communicate or display when you use the Drova Services (“User Content”). This may include Sensitive Information, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. Where we process Personal Information in content, we do so on behalf of our customers and users and it is their responsibility to have lawful grounds to use that Personal Information.
4.1 Information You Provide
- Name, email, phone number, mailing address;
- Usernames, social media profiles, job titles, company name;
- Profile information and photos;
- Billing information (payment details, billing address);
- Communication preferences;
- Content you post, upload, store, or generate;
- Interactions with other users;
- Information submitted through forms, emails, or support channels;
- Your preferences for marketing and the Drova Services;
- Employment history, professional experience, required authorisation and licences, professional registrations, and information about your right to work in the relevant jurisdiction (when you apply for a job with us).
4.2 Information We Collect Automatically
- IP address, browser type, configuration, plug-ins;
- Date/time of access, referring webpage;
- Language preferences;
- Cookie data;
- Device type, operating system, device identifiers, application IDs;
- Crash information;
- General location (via Wi-Fi or IP address).
4.3 Analytics Information
We collect analytics data about:
- Username and IP address;
- Features accessed;
- Domain names and identifiers;
- Attachments (filenames, sizes);
- Aggregated usage data (non-identifying).
4.4 Third-Party Integrations
If you integrate third-party services:
- We may receive account information from those providers;
- We do not collect or store third-party passwords.
4.5 Marketing and User Base Information
We may collect:
- Information from marketing partners;
- Publicly accessible databases;
- Social media;
- Related bodies corporate;
- Service partners.
5. How We Collect Personal Information
We collect Personal Information:
- When you create or update an account;
- When another user creates an account for you;
- When you use Drova Services;
- Through your device or browser;
- When you submit information via forms, emails, or communications;
- From third-party marketing partners;
- From publicly accessible sources;
- From related bodies corporate;
- From third-party service providers you integrate;
- By generating analytics data through queries and usage analysis.
6. How We Disclose Personal Information
We may disclose Personal Information to:
6.1 Team Administrators
If you use Drova as part of an organisation, administrators may:
- Access and control your account;
- Retrieve, share, or delete your Personal Information.
6.2 Service Providers
Technology, hosting, analytics, and customer support providers may access Personal Information to facilitate and improve Drova Services.
6.5 Business Transfers
If Drova is sold or restructured, Personal Information may be transferred to the new owner.
6.6 Marketing
We may disclose Personal Information to third parties for marketing only with your consent or where lawful grounds exist.
6.7 Professional Advisers
We may disclose Personal Information to bankers, auditors, insurers and insurance brokers, legal advisers and other professional advisers to obtain professional advice, or to comply with contractual requirements or law.
6.8 Storage and Offshore Transfers
We store your personal information in Australia. However, your information may be accessed from or transferred to locations outside Australia (including the USA and UK) in these circumstances:
- When our service providers are located overseas
- When we work with overseas business partners
- When using cloud-based services or data storage solutions
Our Approach to Overseas Disclosure
Before disclosing your personal information overseas, we take reasonable steps to ensure that the recipient treats your information in accordance with applicable law by only sending what is necessary, requiring recipients to protect your information through contractual agreements which require the recipient to comply with the privacy standards in applicable law or through other mechanisms that provide comparable safeguards and by monitoring how recipients handle your information.
7. Data Retention, Access, Correction and Deletion
We retain Personal Information where:
- We have a legitimate business need; or
- Retention is required under legal, tax, or accounting obligations;
- Retention is permitted under privacy law applicable to User Content;
- Retention is allowed under contracts with customers.
When no longer needed, we will delete or anonymise Personal Information or securely store it until deletion is possible (eg. backups).
8. Artificial Intelligence and Similar Technologies
We may use automated processing, including machine learning and artificial intelligence technologies, to help provide, improve and secure Drova Services. For example, automated processing may be used to:
- generate recommendations, comments, prompts or suggested actions;
- improve search, categorisation and workflow efficiency;
- detect fraud, misuse, spam or security threats;
- personalise aspects of your experience with Drova Services.
Automated processing assists our services but is not intended to produce decisions that have legal or similarly significant effects on individuals without appropriate human involvement. Where applicable privacy laws provide rights relating to automated decision-making or profiling, you may contact us to request further information or to exercise those rights.
Data Protection and Security
When we work with third-party AI providers, we ensure they handle your personal information in accordance with privacy laws through contractual requirements and appropriate safeguards.
Your Rights and Our Commitments
Any information generated or inferred about you by AI technologies is treated as Personal Information, and you maintain all the rights outlined in this Privacy Policy. When using AI with your Personal Information, we commit to:
Transparency and Control
- We'll inform you when AI is used to make decisions that may significantly affect you
- We maintain human oversight and review of significant AI-generated decisions
- Our staff are trained to understand AI limitations and verify outputs before relying on them
- We implement processes to verify the accuracy of AI-generated outputs
Security
- We use appropriate technical and organisational measures to maintain the security and integrity of your personal information
- We regularly test and monitor AI outputs for accuracy and reliability
Risk Mitigation
- We regularly assess and document risks associated with using AI to process personal information
- We implement appropriate measures to address these risks
- We continuously monitor AI performance and regularly review their impact
Google Analytics
We use Google Analytics to understand how people use our website. This involves cookies that collect information about your browsing activity. You can opt out of Google's advertising features through your Google account settings, browser add-ons, or your device's privacy settings. Google provides various tools and options to control how your data is used for advertising purposes. You can learn more about how Google uses your data and your available options on Google's privacy pages.
10. Security
In storing your Personal Information, we use a number of security and organisational measures and technologies to safeguard your Personal Information from unauthorised access, modification or disclosure and misuse, interference or loss. We have personnel tasked with protecting your information, developing new security features, and identifying and mitigating vulnerabilities. Our existing security measures include encryption, two-factor authentication, and notifications when new devices and apps are connected with your user account. We also have in place security measures and policies focused on restricting access to sensitive information to authorised personnel, and we consistently review our security procedures and architecture with a consideration of new technologies and updated methods. Despite our reasonable efforts however, no system is ever perfect.
Whilst we hold your information on a secured server behind a firewall and we encrypt data transfer using 256bit SSL encryption, please be aware that there are inherent risks in transmitting information using the internet.
The Drova Services are certified to meet ISO 27001 information security standards. Please contact us for further information on the scope of our ISO 27001 certification.
11. Legal Basis for Processing Personal Information (EEA and UK Visitors)
If you are a visitor from the European Economic Area or the United Kingdom, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.
However, we will normally collect Personal Information from you only where we have your consent to do so, where we need the Personal Information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Information from you or may otherwise need the Personal Information to protect your vital interests or those of another person (e.g. other users).
If we ask you to provide Personal Information to comply with a legal requirement or to perform a contract with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as of the possible consequences if you do not provide your Personal Information).
Similarly, if we collect and use your Personal Information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.
Most of the ways in which we use your personal data are based on our legitimate interests in:
- providing and administering the Drova Services;
- keeping our website and the Drova Services secure;
- keeping the Drova Services up to date and enhancing them, both generally and for your use of them; and
- marketing our products and services.
When we rely on our legitimate interests as a lawful ground to process your Personal Information, we do so taking into account the potential impact on your privacy and we offer the right to object to or opt out from processing as described below in the “Your privacy rights” section below.
If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided under the “Contacting Drova about Privacy” heading below.
12. International Data Transfers (EEA and UK Visitors)
Your Personal Information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have privacy laws that are different to the laws of your country (and, in some cases, may not be as protective).
Specifically, our group companies and third-party service providers and partners operate around the world and, in particular, in Australia, the United States of America, the Netherlands, Germany, South Africa, Hong Kong, the United Kingdom and Vietnam. This means that when we collect your Personal Information we may process it in any of these countries, pursuant to any privacy laws that apply to Your Content. We currently host our servers for the Drova Services using a third-party hosting provider, Amazon Web Services (“AWS”).
13. California User Requests
Californian users of the Drova Services will have additional rights afforded to them under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA, effective 1 January 2023).
The CCPA and the CPRA provide California users various rights with respect to the personal information we collect, including the right to, with certain limitations:
- request to access the personal information we hold about you;
- request that we delete any or all of your personal information;
- opt out of the “sale” of your personal information;
- opt out of the “sharing” of your personal information for cross-context behavioural advertising.
California users of the Drova Services may make a request with respect to any of these rights by contacting us by using the contact details provided under the ‘Contacting Drova about Privacy’ heading below.
14. Your Privacy Rights
You have the following privacy rights, regardless of the legal jurisdiction of Your Content:
We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable privacy laws.
Please note that we do not offer any of the rights described above with respect to any Personal Information that is incorporated in any User Content. We process such content on behalf of our customers and if your Personal Information is contained in any such content, you should contact the customer on whose behalf we have stored the information.
- If you wish to access, correct, update or request deletion of your Personal Information, you can do so at any time by using the setting made available via the Drova Services or by, if settings are not available via the Drova Services, by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below. In the event we cannot grant you access to your Personal Information, we will tell you why.
- You can object to processing of your Personal Information or ask us to restrict processing of your Personal Information. Again, you can exercise these rights by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below.
- You have the right to opt-out of marketing communications we send you at any time, and for which you have previously elected to opt-in. You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided under the “Contacting Drova about Privacy” heading below. If you do opt out, please provide us sufficient time to process your preferences. Additionally, if you do opt out, we may still contact you for transactional or informational purposes, and with these purposes potentially including customer service issues, payment inquiries, or product inquiries.
- If we have collected and processed your Personal Information with your consent, then you can withdraw your consent at any time. Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful processing grounds other than consent.
- You have the right to complain to a privacy authority about our collection and use of your Personal Information. For more information, please contact your local privacy authority. (Contact details for data protection authorities in the European Economic Area, Switzerland, United Kingdom and certain non-European countries (including the US and Canada) are available here.)
15. Additional Privacy Rights (EEA and UK Visitors)
In addition to the rights you have outlined under “Your privacy rights”, you also have the below rights.
Right to Erasure
You can request deletion of your personal data in certain limited circumstances as set out in European Data Protection Law, such as where the data is no longer necessary or has been unlawfully processed. This right is not absolute and we may be required or entitled to retain your data for legal, regulatory or legitimate business reasons.
Right to Restrict Processing
You can ask us to suspend processing where:
- You contest the accuracy of the data
- Processing is unlawful but you don't want erasure
- We no longer need the data but you need it for legal claims
- You've objected to processing pending verification of our legitimate grounds
Right to Data Portability
Where technically feasible, you can receive your personal data in a structured, commonly used format or have it transmitted to another controller where:
- Processing is based on consent or contract
- Processing is automated
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes. We will stop processing unless we can demonstrate compelling legitimate grounds.
Right to Withdraw Consent
Where processing is based on consent, you can withdraw it at any time without affecting the lawfulness of prior processing.
16. Contacting Drova about Privacy
Please contact us using the below details if you have queries about our Privacy Policy and privacy practices, or the way we deal with your Personal Information. You may also contact us using these details if you wish to exercise any of your privacy rights described in the section entitled “Your privacy rights” above.
Postal Address: Drova Level 1, 47 York Street, Sydney NSW 2000 Australia Telephone: +61 1300 333 472
Email: hr@drova.com
Position title and name:
Co-founder & Head of ESGRC: Rachel Riley
Where you are located in the European Economic Area (EEA) or the United Kingdom, you may also contact Drova Limited:
Postal Address: 22 Wycombe End,
Beaconsfield, Buckinghamshire HP9 1NB United Kingdom Telephone: +442045257290 Email: hr@drova.com
Position title and name:
Co-founder & Chief Commercial Officer: Rachel Riley
When you request that we access or correct your Personal Information, we will need to locate the relevant information, so it would greatly assist us if you could supply as much supporting detail as possible. Where we refuse any access or correction request, we will comply with any requirements under applicable laws to notify you of our reasons for doing so and the mechanisms through which you may complain. Where we deny a request to correct information after you have made a request to us, we will comply with any applicable legal requirements to advise you of any inaccuracies or lack of necessary detail within your request.