Legal document 01 / 06

Privacy Policy

Effective: 17 May 2026 Yapa Technologies Pty Ltd ABN 21 697 117 936

Summary: We collect only what we need to run the platform. We do not sell your data. You can access, correct, or delete your information at any time. Full details below.

1. Introduction

Yapa Technologies Pty Ltd ("we", "us", "our") operates the Navo platform at navosuite.com and via mobile applications ("Platform"). We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and our practices are designed to be consistent with the General Data Protection Regulation (EU) 2016/679 ("GDPR") to facilitate global operations.

By creating an account or using the Platform you confirm you have read and understood this Privacy Policy.

2. What We Collect

Identity and Account Information

Property and Project Data

Financial and Payment Data

Technical and Usage Data

2a. Referral and Founding Member Data

If you participate in our referral programme, we collect referral link data to track successful referrals and issue credits, including referrer account ID, referee email, referral date, and credit status.

If you subscribe during the founding member period, we record your founding tier and applicable discount rate for the lifetime of your account, used solely to apply your founding discount to invoices.

If you are a Founding Partner, we record your invitation, 60-day access period, and conversion status for the lifetime of your account.

3. How We Use Your Information

Service Delivery (Primary Purpose)

We use personal information to create and manage accounts, deliver Platform features, process payments, send transactional communications, and provide customer support.

AI Training and Product Improvement

AI Training requires your separate explicit consent at signup. We use anonymised and aggregated derivatives of your project data to train and improve AI features. We will never use your name, contact details, specific property addresses, or individually identifiable financial figures in AI training without additional explicit consent. You may withdraw AI training consent at any time by emailing hello@navosuite.com. Withdrawal takes effect immediately for future processing.

Analytics and Marketing

We use Google Analytics and may use additional analytics tools. We send product updates and feature announcements with your consent only. All commercial electronic messages comply with the Spam Act 2003 (Cth). Unsubscribe at any time via any email or by emailing hello@navosuite.com.

4. Data Retention

Data CategoryRetention Period
Account and identity dataDuration of subscription + 12 months post-cancellation
Project and property dataDuration + 12 months post-cancellation, then anonymised
Financial transaction records7 years (Income Tax Assessment Act 1997)
Photos and media uploadsDuration + 30 days post-cancellation, then deleted
Anonymised/aggregated dataRetained indefinitely for AI training and product improvement
Support correspondence3 years from last interaction

5. Disclosure of Personal Information

We do not sell, rent, or trade personal information. We may disclose to authorised processors including Supabase (database infrastructure), Stripe and Airwallex (payment processing), Google Analytics, and Apple and Google (app distribution). We disclose to law enforcement only where required by law or court order.

6. Your Privacy Rights

Australian users (Privacy Act 1988)

You have the right to access the personal information we hold about you, request correction of inaccurate information, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or 1300 363 992.

EEA and UK users (GDPR)

You have the right to access, rectification, erasure, restriction, data portability, and to object to processing. Withdraw consent at any time. Lodge complaints with your local data protection authority.

Exercising your rights

Submit requests to hello@navosuite.com with subject "Privacy Rights Request". We respond within 30 days. Data deletion requests are actioned without undue delay and in any event within 30 days.

7. Data Security

We implement TLS 1.2+ encryption in transit, AES-256 encryption at rest, Supabase Row Level Security for data isolation, multi-factor authentication, and role-based access controls. At launch, production data access is limited to founding directors. We maintain an incident response plan and breach notification procedures.

8. Notifiable Data Breaches

In the event of a suspected eligible data breach we will complete our assessment within 30 days of first forming reasonable grounds for suspicion. The 30-day notification clock begins from that point. If confirmed, we notify the OAIC and affected individuals immediately. For GDPR users we notify the relevant supervisory authority within 72 hours. Report suspected breaches to hello@navosuite.com with subject "Security Incident".

9. Privacy by Design

We embed privacy considerations into the design and development of the Platform from the outset, consistent with GDPR Article 25. We collect only the minimum personal data necessary, default to the most privacy-protective settings, and conduct privacy impact assessments for new features involving significant personal data processing.

10. Children

The Platform is for persons 18 years or older only. Contact hello@navosuite.com immediately if you believe a minor has registered.

11. Changes to This Policy

Material changes will be notified by email and Platform notice at least 14 days before taking effect. For EEA/UK users, where a material change requires new consent under GDPR, we will seek that consent explicitly rather than relying on continued use.

12. Contact

Privacy Officer: Yapa Technologies Pty Ltd, 3/24 Wolseley Road, Mosman NSW 2088, hello@navosuite.com