top of page

Privacy Policy

Effective starting: 28 August 2024

This privacy policy ("Privacy Policy") applies to Drova Pty Limited and our related entities (“Drova”, “us”, “we” and “our”) and details our commitment to protecting the privacy of our customers and users.

This Privacy Policy describes how and why we collect Personal Information about you, how we use, manage, store, and disclose that information, and how you can exercise your privacy rights. This Privacy Policy also outlines how you can contact us to access and update your Personal Information and/or how you can raise any privacy concerns.

We recommend that you read this Privacy Policy in full to ensure you are fully informed. However, if you wish to only access a particular section of this Privacy Policy, then you can click on the relevant link below to jump to that section.
 

Terms used in our Privacy Policy

“Drova Services” refers to any of the products and services we may provide to you. 

When referenced in this Privacy Policy, “Personal Information” means any information or data that identifies you, or that could reasonably be used (for instance, in combination with other data) to identify you directly or indirectly, including by reference to identifiers such as names, identification numbers, location data, and/or online identifiers. Personal Information can include information you provide to us (for example, through our websites and your use of the other Drova Services), publicly available information, and/or information we collect from other sources as described in this Privacy Policy.
 

Updates to our Privacy Policy

We may update this Privacy Policy from time to time by posting a new version on any of our websites. When an updated Privacy Policy is posted, we will change the “Effective Starting” date at the top of the policy accordingly.

Where our changes are material, we will try to notify you – this may be by way of an email or a notice on our websites, or an alert on the login screens for the Drova Services that will appear for at least 30 days. We may not notify you if the way in which we use your Personal Information has not changed, or otherwise where any changes are not material.

If you do not agree with its terms or any of the changes we make, you should either cease using the Drova Services or exercise whatever rights you may have, as described in this Privacy Policy, to opt out of how we use your Personal Information.


Why do we collect your Personal Information?

We collect your Personal Information to supply you with the Drova Services and to further develop, enhance and safeguard those services. We may also use your Personal Information to:

  • perform and administer the Drova Services;

  • understand the way you use the Drova Services;

  • improve your experience when using the Drova Services, including by personalising the services, modifying the layout or operation of any interface, developing new products, or otherwise learning about your level of satisfaction;

  • facilitate the predictive functionality and the provision of recommendations, comments and prompts forming part of the Drova Services;

  • address and reply to requests for customer support;

  • process transactions;

  • identify, remedy and prevent any technical or security issues affecting the Drova Services;

  • send you information by email, mail or other channels;

  • send you marketing communications, offers and opportunities relating to us or to carefully chosen third-party organizations where we think they might be relevant to you; 

  • enforce our Agreement with you;

  • compare information for accuracy;

  • perform any other functions described in our terms and conditions or this Privacy Policy.

If we do not collect Personal Information from you, you might not be able to use the Drova Services or otherwise create an account or profile with us. Additionally, some of the functions comprising the Drova Services may not be available to you, and/or we might not be able to communicate with you (including through marketing communications).


Other ways we use your information

We may also collect, use, store and disclose your Personal Information for purposes and for recipients additional to those that are set out in this Privacy Policy. Where we do so, we will disclose those purposes and recipients to you when you provide your information to us.


What Personal Information do we collect?

The Personal Information we may collect includes information that you provide voluntarily to us, information that we collect automatically and information that we obtain from third party sources. This may include, but is not limited to:

  • your contact details, including your name, mailing and email addresses, and phone numbers;

  • any usernames you may hold, any social media profiles you may hold, job title(s), company name, photographs, and any additional information connected with a profile or account that you create or that is created for you;

  • your billing information, including your payment details and billing address;

  • preferences about the way you would like us to communicate with you, including in respect of marketing communications;

  • information about the way you access and use the Drova Services, the content you post, your interactions with other users, and your use of features, links and third-party integrations;

  • log information such as your IP address, the date and time when you used the Drova Services, the details of the webpage you visited before accessing the Drova Services, your browser type, configuration and plug-ins, your language preferences, and cookie data. For more information on our use of cookies, please see our Cookie Policy;

  • information about the device on which you are using the Drova Services, including the device type and settings, operating system, device identifiers, application IDs, and crash information. We may use your Wi-Fi and IP address from your device or browser to ascertain your general location, but we will only collect GPS location data from your mobile device with your consent;

  • analytics information collected when you use the Drova Services, or information that we generate or derive, including through queries we run in respect of use of the services and content contained in the services. This data, which could incorporate Personal Information, may include the username and IP address of the person using the Drova Services, the parts of the Drova Services being accessed and used, any relevant domain names and identifiers, and data about attachments (including their original filenames and sizes). We may also collect aggregated analytics data about the use of the Drova Services, which will not contain Personal Information;

  • information about third-party services you integrate when using the Drova Services. We will connect any such services to the Drova Services, and we may receive information about your account (including Personal Information) from the third-party service provider. We will not collect or hold your passwords for any third-party services; and

  • information about our user base and the performance of marketing campaigns. This might include Personal Information and/or aggregated information that does not identify individuals.

We may also process Personal Information incorporated in the content that users create, provide, post, host, upload, store, communicate or display when you use the Drova Services (“User Content”). This may include sensitive information, such as personal data revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, or trade union membership, and the processing of genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health or data concerning a natural person’s sex life or sexual orientation. Where we process Personal Information in content, we do so on behalf of our customers and users and it is their responsibility to have lawful grounds to use that Personal Information. We will not be responsible for obtaining consent for the use of any sensitive information that is incorporated in any User Content.


How do we collect Personal Information?

We collect Personal Information in a number of ways, including:

  • when you establish an account with us, or when another user (for instance, a user from your company) creates an account for you;

  • when you create or amend your profile;

  • when you use the Drova Services;

  • through your device or browser, as outlined above;

  • when you submit Personal Information directly to us, including through the use of our websites and the other Drova Services, where you submit online forms, and where you send emails or other communications to us;

  • from third parties. To ensure we are providing you with information, marketing, offers and opportunities that are relevant to you, we may collect information about you from sources including our marketing partners, publicly-accessible databases and social media. We may also collect information about our user base, the Drova Services and our marketing campaigns from our related bodies corporate, our service partners, or others;

  • from your third-party service providers. We may collect information from the providers of third-party services you integrate when using the Drova Services, as described above; and

  • by running analytics or generating analytics data in connection with the Drova Services, including through queries we run in respect of use of the services and content contained in the services.

 

How do we disclose Personal Information?

We may disclose the Personal Information we collect:

  • with your team administrator, where you use the Drova Services as part of a team (for instance, a purchaser team in an acquisition transaction). In line with your company’s policies, your team administrator may be able to access and control your Drova account and retrieve, share or delete your Personal Information;

  • with other users of the Drova Services. For example, your name, photograph and contact details may be displayed to other users, including in your profile and in posts or notifications. Similar types of Personal Information might also be made available to others in your organisation to allow them to locate and collaborate with you. You can also choose to share information with others as part of the Drova Services, such as when you use our online virtual data rooms to communicate with others;

  • with our service providers, such as our technology and customer assistance service providers. Those providers may access your Personal Information as we may direct or permit in order to facilitate and improve your use of the Drova Services;

  • in accordance with legal requirements and our legal rights – for example, where necessary to comply with statutory or legal requirements, to prevent fraud, to prevent death or serious injury, or to protect our proprietary rights. Where you use our Q&A functionality, we may provide certain organisations whose registered users view or post Q&A information with a separate copy of that information, in order for them to comply with the rules of the U.S. Securities and Exchange Commission (SEC). Those organisations (and their related companies) may use and disclose such information to the extent required to comply with those SEC rules, and any other law to which they are subject (and may transfer and store that information offshore); and

  • to related entities of Drova Pty Ltd for the purposes of performing the Services and operating our group’s business. A list of our group companies is set out below:

TriLine GRC Pty Ltd

TriLine GRC Limited

Drova Pty Ltd

Drova Limited

  • to a new owner or potential buyer of Drova, where the ownership of all or substantially all of the Drova business, or individual business units owned by Drova, were to change. This information would be provided in order to allow the Drova Services to continue to operate.

Some of the recipients described above, including our service providers, your team administrator, other users of the Drova Services, any new owner of Drova, and the SEC, are or may be located offshore.

We may disclose your Personal Information to third parties to allow them to market to you (including through direct marketing) if we have first obtained your consent or if we have other lawful grounds to do so.

 

Data retention, access, correction, and deletion

We retain Personal Information we collect from you where we have an ongoing legitimate business need to do so, and where you have not requested us to delete your Personal information, pursuant to any privacy laws that apply to Your Content.  Examples of legitimate business needs include, but are not limited to continuing to provide you access to the Drova Services or to comply with applicable legal, tax or accounting requirements.

You have a right to request a copy of your Personal Information, to object to our usage of your Personal Information, to request the correction of Your Personal Information, or to request the deletion or restriction of your Personal Information.   Your requests and choices may be limited in certain cases such as, but not limited to situations where your request would reveal information pertaining to another person, or where you ask us to delete Your Personal Data, and we are permitted by law to retain Your Personal Data, or have a compelling legitimate reason for doing so.

Subject to any privacy laws that apply to your content, when we have no ongoing legitimate business need to process your Personal Information, we will either delete or anonymise it or, if this is not possible (for example, because your Personal Information has been stored in backup archives), then we will securely store your Personal Information and isolate it from any further processing until deletion is possible.

We only retain Personal Information for such time as permitted by our contracts with our customers, or for such time as those customers otherwise instruct or permit us to do so, or pursuant to any privacy laws that apply to Your Content.  


Cookies and similar tracking technology

We use cookies and similar tracking technology (collectively, “Cookies”) to collect and use Personal Information about you, and to otherwise make interfaces more user-friendly, to provide you a better experience, and to target advertising to you that may be of interest. You can control or reset your cookies through your web browser, which allows you to customise your cookies preferences, to refuse all cookies, or to indicate when a cookie is being sent.  Note that some elements of the Drova Services may not function properly if the ability to accept cookies is disabled.

For further information about the types of Cookies we use and why, as well as further information on how you can control Cookies, please see our Cookie Policy.
 

Security

In storing your Personal Information, we use a number of security and organisational measures and technologies to safeguard your Personal Information from unauthorised access, modification or disclosure and misuse, interference or loss. We have personnel tasked with protecting your information, developing new security features, and identifying and mitigating vulnerabilities. Our existing security measures include encryption, two-factor authentication, and notifications when new devices and apps are connected with your user account. We also have in place security measures and policies focused on restricting access to sensitive information to authorised personnel, and we consistently review our security procedures and architecture with a consideration of new technologies and updated methods. Despite our reasonable efforts however, no system is ever perfect.

Whilst we hold your information on a secured server behind a firewall and we encrypt data transfer using 256bit SSL encryption, please be aware that there are inherent risks in transmitting information using the internet.

The Drova Services are certified to meet ISO 27001 information security standards. Please contact us for further information on the scope of our ISO 27001 certification.
 

Legal basis for processing Personal Information (EEA and UK visitors)

If you are a visitor from the European Economic Area or the United Kingdom, our legal basis for collecting and using the Personal Information described above will depend on the Personal Information concerned and the specific context in which we collect it.

However, we will normally collect Personal Information from you only where we have your consent to do so, where we need the Personal Information to perform a contract with you, or where the processing is in our legitimate interests and not overridden by your data protection interests or fundamental rights and freedoms. In some cases, we may also have a legal obligation to collect Personal Information from you or may otherwise need the Personal Information to protect your vital interests or those of another person (e.g. other users).

If we ask you to provide Personal Information to comply with a legal requirement or to perform a contact with you, we will make this clear at the relevant time and advise you whether the provision of your Personal Information is mandatory or not (as well as of the possible consequences if you do not provide your Personal Information).

Similarly, if we collect and use your Personal Information in reliance on our legitimate interests (or those of any third party), we will make clear to you at the relevant time what those legitimate interests are.

Most of the ways in which we use your personal data are based on our legitimate interests in:

  • providing and administering the Drova Services;

  • keeping our website and the Drova Services secure;

  • keeping the Drova Services up to date and enhancing them, both generally and for your use of them; and

  • marketing our products and services.

When we rely on our legitimate interests as a lawful ground to process your Personal Information, we do so taking into account the potential impact on your privacy and we offer the right to object to or opt out from processing as described below in the “Your privacy rights” section below.

If you have questions about or need further information concerning the legal basis on which we collect and use your Personal Information, please contact us using the contact details provided under the “Contacting Drova about Privacy” heading below.
 

International data transfers (EEA and UK visitors)

Your Personal Information may be transferred to, and processed in, countries other than the country in which you are resident. These countries may have privacy laws that are different to the laws of your country (and, in some cases, may not be as protective).

Specifically, our group companies and third-party service providers and partners operate around the world and, in particular, in Australia, the United States of America, the Netherlands, Germany, South Africa, Hong Kong, the United Kingdom and Vietnam. This means that when we collect your Personal Information we may process it in any of these countries, pursuant to any privacy laws that apply to Your Content.  
We currently host our servers for the Drova Services using a third-party hosting provider, Amazon Web Services (“AWS”).
 

California user requests

Californian users of the Drova Services will have additional rights afforded to them under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA, effective 1 January 2023).  

The CCPA and the CPRA provide California users various rights with respect to the personal information we collect, including the right to, with certain limitations:

  • request to access the personal information we hold about you;

  • request that we delete any or all of your personal information;

  • opt out of the “sale” of your personal information;

  • opt out of the “sharing” of your personal information for cross-context behavioural advertising. 

California users of the Drova Services may make a request with respect to any of these rights by contacting us by using the contact details provided under the ‘Contacting Drova about Privacy’ heading below.  


Your privacy rights

You have the following privacy rights, regardless of the legal jurisdiction of Your Content:

  • If you wish to access, correct, update or request deletion of your Personal Information, you can do so at any time by using the setting made available via the Drova Services or by, if settings are not available via the Drova Services, by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below. In the event we cannot grant you access to your Personal Information, we will tell you why.

  • You can object to processing of your Personal Information or ask us to restrict processing of your Personal Information.  Again, you can exercise these rights by contacting us using the contact details provided under the “Contacting Drova about Privacy” heading below.

  • You have the right to opt-out of marketing communications we send you at any time, and for which you have previously elected to opt-in.  You can exercise this right by clicking on the “unsubscribe” or “opt-out” link in the marketing e-mails we send you. To opt-out of other forms of marketing (such as postal marketing or telemarketing), please contact us using the contact details provided under the “Contacting Drova about Privacy” heading below. If you do opt out, please provide us sufficient time to process your preferences.  Additionally, if you do opt out, we may still contact you for transactional or informational purposes, and with these purposes potentially including customer service issues, payment inquiries, or product inquiries. 

  • If we have collected and processed your Personal Information with your consent, then you can withdraw your consent at any time.  Withdrawing your consent will not affect the lawfulness of any processing we conducted prior to your withdrawal, nor will it affect processing of your Personal Information conducted in reliance on lawful processing grounds other than consent.

  • You have the right to complain to a privacy authority about our collection and use of your Personal Information. For more information, please contact your local privacy authority. (Contact details for data protection authorities in the European Economic Area, Switzerland, United Kingdom and certain non-European countries (including the US and Canada) are available here.)

We respond to all requests we receive from individuals wishing to exercise their data protection rights in accordance with applicable privacy laws.

Please note that we do not offer any of the rights described above with respect to any Personal Information that is incorporated in any User Content. We process such content on behalf of our customers and if your Personal Information is contained in any such content, you should contact the customer on whose behalf we have stored the information.
 

Contacting Drova about Privacy

Please contact us using the below details if you have queries about our Privacy Policy and privacy practices, or the way we deal with your Personal Information. You may also contact us using these details if you wish to exercise any of your privacy rights described in the section entitled “Your privacy rights” above.

Postal Address:
Drova
Level 1, 47 York Street,
Sydney NSW 2000
Australia
Telephone: +61 1300 333 472
Email: hr@drova.com


Position title and name:

Co-founder & Head of ESGRC: Rachel Riley

Where you are located in the European Economic Area (EEA) or the United Kingdom, you may also contact Drova Limited:

Postal Address:
22 Wycombe End,

Beaconsfield, Buckinghamshire
HP9 1NB
United Kingdom
Telephone: +442045257290
Email: hr@drova.com


Position title and name:

Co-founder & Chief Commercial Officer: Rachel Riley

When you request that we access or correct your Personal Information, we will need to locate the relevant information, so it would greatly assist us if you could supply as much supporting detail as possible. Where we refuse any access or correction request, we will comply with any requirements under applicable laws to notify you of our reasons for doing so and the mechanisms through which you may complain. Where we deny a request to correct information after you have made a request to us, we will comply with any applicable legal requirements to advise you of any inaccuracies or lack of necessary detail within your request.   

We take your privacy complaints seriously at all times. Where you inform us that you have a complaint about our handling of your Personal Information, we will contact you to let you know which of our team members will investigate your matter and the timeframe within which they will aim to respond to you.

bottom of page