Summary: We collect only what we need to run the platform. We do not sell your data. You can access, correct, or delete your information at any time. Full details below.
Yapa Technologies Pty Ltd ("we", "us", "our") operates the Navo platform at navosuite.com and via mobile applications ("Platform"). We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and our practices are designed to be consistent with the General Data Protection Regulation (EU) 2016/679 ("GDPR") to facilitate global operations.
By creating an account or using the Platform you confirm you have read and understood this Privacy Policy.
If you participate in our referral programme, we collect referral link data to track successful referrals and issue credits, including referrer account ID, referee email, referral date, and credit status.
If you subscribe during the founding member period, we record your founding tier and applicable discount rate for the lifetime of your account, used solely to apply your founding discount to invoices.
If you are a Founding Partner, we record your invitation, 60-day access period, and conversion status for the lifetime of your account.
We use personal information to create and manage accounts, deliver Platform features, process payments, send transactional communications, and provide customer support.
AI Training requires your separate explicit consent at signup. We use anonymised and aggregated derivatives of your project data to train and improve AI features. We will never use your name, contact details, specific property addresses, or individually identifiable financial figures in AI training without additional explicit consent. You may withdraw AI training consent at any time by emailing hello@navosuite.com. Withdrawal takes effect immediately for future processing.
We use Google Analytics and may use additional analytics tools. We send product updates and feature announcements with your consent only. All commercial electronic messages comply with the Spam Act 2003 (Cth). Unsubscribe at any time via any email or by emailing hello@navosuite.com.
| Data Category | Retention Period |
|---|---|
| Account and identity data | Duration of subscription + 12 months post-cancellation |
| Project and property data | Duration + 12 months post-cancellation, then anonymised |
| Financial transaction records | 7 years (Income Tax Assessment Act 1997) |
| Photos and media uploads | Duration + 30 days post-cancellation, then deleted |
| Anonymised/aggregated data | Retained indefinitely for AI training and product improvement |
| Support correspondence | 3 years from last interaction |
We do not sell, rent, or trade personal information. We may disclose to authorised processors including Supabase (database infrastructure), Stripe and Airwallex (payment processing), Google Analytics, and Apple and Google (app distribution). We disclose to law enforcement only where required by law or court order.
You have the right to access the personal information we hold about you, request correction of inaccurate information, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.
You have the right to access, rectification, erasure, restriction, data portability, and to object to processing. Withdraw consent at any time. Lodge complaints with your local data protection authority.
Submit requests to hello@navosuite.com with subject "Privacy Rights Request". We respond within 30 days. Data deletion requests are actioned without undue delay and in any event within 30 days.
We implement TLS 1.2+ encryption in transit, AES-256 encryption at rest, Supabase Row Level Security for data isolation, multi-factor authentication, and role-based access controls. At launch, production data access is limited to founding directors. We maintain an incident response plan and breach notification procedures.
In the event of a suspected eligible data breach we will complete our assessment within 30 days of first forming reasonable grounds for suspicion. The 30-day notification clock begins from that point. If confirmed, we notify the OAIC and affected individuals immediately. For GDPR users we notify the relevant supervisory authority within 72 hours. Report suspected breaches to hello@navosuite.com with subject "Security Incident".
We embed privacy considerations into the design and development of the Platform from the outset, consistent with GDPR Article 25. We collect only the minimum personal data necessary, default to the most privacy-protective settings, and conduct privacy impact assessments for new features involving significant personal data processing.
The Platform is for persons 18 years or older only. Contact hello@navosuite.com immediately if you believe a minor has registered.
Material changes will be notified by email and Platform notice at least 14 days before taking effect. For EEA/UK users, where a material change requires new consent under GDPR, we will seek that consent explicitly rather than relying on continued use.
Privacy Officer: Yapa Technologies Pty Ltd, 3/24 Wolseley Road, Mosman NSW 2088, hello@navosuite.com