Privacy Policy
Last updated: 26 April 2026
1. About This Policy
This Privacy Policy explains how Arvoe Pty Ltd (ABN 52 691 800 398) ("Arvoe", "we", "us", "our") collects, uses, discloses, and protects personal information in connection with our website at www.arvoe.ai (the "Website"), our AI governance platform (the "Platform"), and related services.
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to Arvoe's handling of Personal Information. As a company that provides AI governance tools to educational institutions, we hold ourselves to the highest standards of data protection — particularly when it comes to information relating to children.
2. Information We Collect
2.1 Information you provide directly
- Contact information: name, email address, phone number, school name, and role when you request a demo, complete our self-assessment, subscribe to our newsletter, or contact us.
- Account information: name, email, role, and school affiliation when you create a Platform account.
- Assessment data: responses to our AI Governance Self-Assessment, including maturity scores and governance posture information.
- Communications: content of emails, support requests, and other correspondence with us.
2.2 Information collected automatically
- Usage data: pages visited, time spent, referring URLs, and interaction patterns on our Website.
- Device information: browser type, operating system, device type, screen resolution, and IP address.
- Cookies and similar technologies: we use essential cookies for Website functionality and optional analytics cookies to understand usage patterns. See Section 8 for details.
2.3 Information from third parties
We may receive information from schools that use our Platform in connection with their AI governance programs. This may include aggregated or de-identified data about AI tool usage patterns, governance maturity assessments, and risk posture information. We do not receive identifiable student data through the Platform.
3. How We Use Your Information
We collect and use personal information for the following purposes:
- To provide, maintain, and improve our Website and Platform
- To process and respond to your enquiries, demo requests, and support requests
- To deliver self-assessment results and governance maturity scorecards
- To send you information about our products, services, and AI governance insights (with your consent, where required)
- To generate anonymised, aggregated benchmarking data to help schools understand their governance posture relative to peers
- To comply with legal obligations, including the Privacy Act 1988 and applicable education sector regulations
- To protect the security and integrity of our services
We will not use your personal information for purposes materially different from those described here without notifying you and, where required, obtaining your consent.
4. Children's Privacy
Arvoe does not knowingly collect personal information from children under 18.
Our Website and self-assessment tools are designed for use by school leaders, administrators, and educators — not students. The Platform is used by authorised school staff to manage institutional AI governance.
Where a school uses the Arvoe Platform as part of its AI governance program, any data relating to students is managed under the school's own privacy policies and obligations. Arvoe acts as a service provider to the school and processes data only as directed by the school under a data processing agreement.
We are committed to compliance with the Children's Online Privacy Code when it takes effect in December 2026, and we will update this policy to reflect any additional obligations that arise.
5. Disclosure of Information
We do not sell, rent, or trade your personal information. We may disclose personal information in the following circumstances:
- Service providers: to trusted third-party providers who assist us in operating our Website and Platform (e.g., hosting, analytics, email delivery). These providers are contractually required to protect your information and use it only for the services they provide to us.
- Aggregated data: we may share anonymised, aggregated benchmarking data that cannot identify any individual or school. This data helps the education sector understand AI governance maturity patterns.
- Legal requirements: where required by law, regulation, legal process, or enforceable government request.
- Business transfers: in connection with a merger, acquisition, or sale of assets, subject to confidentiality obligations.
- With your consent: where you have given us explicit consent to share your information for a specific purpose.
5.1 Sub-processors
We rely on a small number of trusted sub-processors to operate the Website and Platform. The current providers and the regions in which they process data are summarised below. The full list — including each provider's role, retention terms, and links to their privacy policies and Data Processing Agreements — is published at arvoe.ai/sub-processors.
See arvoe.ai/sub-processors for full details, including retention windows and provider trust pages.
6. Data Storage and Security
We take the security of your personal information seriously and implement appropriate technical and organisational measures, including:
- Encryption of data in transit (TLS) and at rest
- Access controls limiting who can view personal information to authorised personnel only
- Regular security reviews of our infrastructure and third-party providers
- Incident response procedures for data breaches, including notification to affected customers within 72 hours of becoming aware of an eligible breach (consistent with our Services Agreement), and compliance with the Notifiable Data Breaches scheme to the extent it applies to Arvoe
7. Automated Decision-Making and AI Features
7.1 AI features in the Platform
The Arvoe Platform includes AI-assisted features that support your team's governance, risk, and compliance work. These features include risk identification suggestions, policy and control drafting assistance, control framework mapping, compliance gap analysis, and Ask Arvoe — a conversational assistant that draws on your governance records to answer questions.
7.2 Personal information used by AI features
AI features may process personal information about your staff, administrators, and any third parties referenced in your governance records (for example, named risk owners, control approvers, or individuals mentioned in incident notes). The Platform is designed for staff and administrative data only. We do not knowingly process student personal information through AI features, and our customer terms prohibit the upload of student data unless we have specifically agreed in writing to support that data type.
7.3 Decision-support, not automated decisions
The Platform is decision-support software. It does not make automated decisions that produce legal effects or that significantly affect individuals. Human review by an authorised member of your school is a condition of use of every AI feature — enforced contractually under our customer terms and reflected in the design of the Platform, where AI-generated outputs are presented as suggestions for review rather than as final decisions.
7.4 Right to seek human review
If you believe a decision made about you by your school or employer was substantially assisted by an AI feature in our Platform, you can seek human review of that decision through the school or employer that made it. Arvoe does not make decisions about individuals — we are a service provider to the school or organisation that does. We will assist schools acting in good faith to investigate such requests.
7.5 AI sub-processors
Generative AI features (including Ask Arvoe) are powered by Anthropic's Claude API. Anthropic processes inputs and outputs under a data processing agreement that prohibits training on customer data and retains data transiently for up to 7 days for safety and abuse-monitoring purposes only. Zero Data Retention is available on request under the Anthropic DPA at higher token rates.
Embedding inference for in-platform semantic search is performed by Microsoft's Azure OpenAI Service in Australia. Embeddings are short text fragments derived from tenant content; data does not leave Australia and is not shared with OpenAI. See arvoe.ai/sub-processors for the full list of AI and infrastructure sub-processors.
7.6 APP 1.7 transparency commitment
We are committed to compliance with the automated decision-making transparency obligations under Australian Privacy Principle 1.7, commencing 10 December 2026. As we approach that date we will publish additional disclosures setting out the kinds of personal information our AI features process and the kinds of decisions our outputs may substantially assist with, so that schools can incorporate that information into their own privacy policies.
8. Cookies and Analytics
We use the following types of cookies:
- Essential cookies: required for basic Website functionality (e.g., session management, security). These cannot be disabled.
- Analytics cookies: used to understand how visitors interact with our Website. We use privacy-respecting analytics tools and do not use analytics data for advertising or profiling.
We do not use advertising cookies, tracking pixels from ad networks, or any form of cross-site tracking. We do not sell data to advertisers or data brokers.
9. Your Rights
We commit, as a matter of policy and contract, to providing you with the following rights in respect of your personal information, irrespective of whether a particular obligation under the Australian Privacy Principles technically applies to Arvoe:
- Access the personal information we hold about you
- Correct inaccurate or out-of-date information
- Request deletion of your personal information (subject to legal obligations requiring retention)
- Withdraw consent for marketing communications at any time
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe your privacy has been breached
To exercise any of these rights, contact us at privacy@arvoe.ai. We will respond within 30 days.
10. Data Retention
We retain personal information only for as long as necessary to fulfil the purposes described in this policy, or as required by law. Specifically:
- Website enquiries and self-assessment data: retained for 2 years from the date of collection, unless you become a Platform customer (in which case it becomes part of your account data).
- Platform account data: retained for the duration of the customer relationship plus 12 months, unless a longer retention period is required by law.
- Marketing preferences: retained until you unsubscribe or request deletion.
- Aggregated benchmarking data: retained indefinitely as it is anonymised and cannot identify individuals or schools.
- AI provider inputs and outputs: retained transiently (up to 7 days) by our AI provider for safety and abuse-monitoring purposes, after which they are deleted. Not used to train AI models.
11. Third-Party Links
Our Website may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. We encourage you to review their privacy policies before providing any personal information.
12. International Data Transfers
The majority of Arvoe customer data is processed within Australia. Some processing occurs outside Australia in connection with the Platform's generative AI features and transactional email delivery. The current sub-processors and the countries in which they process data are listed at arvoe.ai/sub-processors.
Where data is processed outside Australia, we operate to the standards set by Australian Privacy Principle 8 and take reasonable steps to ensure the overseas recipient handles your information consistently with the Australian Privacy Principles, including through contractual obligations (Data Processing Agreements with standard contractual clauses where applicable) and reliance on the provider's published security certifications (such as SOC 2 Type II or ISO 27001) where available. Data processed outside Australia for AI features is transient and not used to train AI models; see Section 10 for retention details.
We will notify Platform customers of any material changes to the countries in which data is processed, in accordance with the notification commitments published at arvoe.ai/sub-processors.
13. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, services, or legal obligations. We will post the updated policy on this page with a revised "last updated" date. For material changes, we will provide additional notice (such as an email to Platform customers).
14. Contact Us
If you have questions about this Privacy Policy or wish to exercise your privacy rights, please contact us:
Arvoe Pty Ltd
Email: privacy@arvoe.ai
General: hello@arvoe.ai
Gold Coast, Queensland, Australia
If you are not satisfied with our response to a privacy concern, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.