Version 2.0

GovernApp Security and Privacy Statement

How GovernApp handles customer data, personal information, security practices, retention, access and privacy requests.

1. Scope of this Statement

Carlton Rossiter Pty Ltd (ABN 32 617 116 677) ("Carlton Rossiter", "GovernApp", "we", "us" or "our") is committed to protecting the security, confidentiality and privacy of information handled through the GovernApp Service (the Service). This Statement describes how GovernApp handles Customer Data, Personal Information and security-related information in connection with the Service.

This Statement should be read together with the GovernApp Terms and Conditions.

This Statement applies to information collected or processed through the Service, related support interactions, and associated operational and security processes.

GovernApp may collect and process the following categories of information:

  • account and contact details, such as names, email addresses, job titles and billing details;
  • Customer Data uploaded to, stored in, submitted to, or generated through the Service;
  • technical and usage information, such as login records, browser type, device information, service interaction data and IP address information;
  • website and service analytics data, including information about page views, navigation paths, session duration, feature usage, clicks, engagement patterns, referral sources and campaign interactions; and
  • support, feedback and communications records.

2. Data Security Measures

Encryption: Data transmitted between user devices and GovernApp systems is protected using industry-standard encryption protocols, including SSL/TLS in transit where applicable.

Access Controls: Access to information within the Service is restricted to authorised personnel and service providers who require access for legitimate operational, support, development or security purposes.

GovernApp uses access controls, authentication mechanisms and role-based permissions designed to limit and monitor access to information.

Data Storage: GovernApp seeks to store Service data using secure infrastructure and hosting arrangements designed to protect against unauthorised access, loss, misuse and interference.

Where data is described as being stored in Australian-based infrastructure, this refers to primary hosting arrangements unless otherwise disclosed for specific integrations, subprocessors, backup systems or support tools.

Backup and Recovery: Regular backups and recovery procedures are maintained to support business continuity, resilience and restoration in the event of system failure or other operational disruption.

Security Incidents: GovernApp maintains procedures for identifying, investigating, containing and responding to suspected or actual security incidents affecting the Service.

Where required by law, or where GovernApp considers notification appropriate in the circumstances, GovernApp will notify affected Customers of confirmed incidents involving unauthorised access to Personal Information or Customer Data within a reasonable time after awareness and initial verification.

3. Privacy and Data Handling

GovernApp collects and uses information to:

  • provide, operate, maintain and support the Service;
  • authenticate users and administer accounts;
  • secure, monitor and improve the Service;
  • measure website and service usage, user engagement and feature adoption;
  • analyse traffic sources, campaign effectiveness and audience behaviour;
  • support marketing communications, audience development and, where permitted by law, remarketing activities;
  • communicate with Customers about service, billing, operational or support matters;
  • comply with legal obligations; and
  • undertake permitted analytics, research and benchmarking using de-identified information.

GovernApp only collects and uses information to the extent reasonably necessary for those purposes or as otherwise permitted or required by law.

Analytics, Cookies and Similar Technologies: GovernApp may use analytics tools, cookies, pixels, tags and similar technologies on its website and within the Service to understand how visitors and users interact with the website and Service, improve performance and usability, measure engagement, and support marketing and remarketing activities.

These technologies may collect information such as browser type, device identifiers, IP address, pages visited, time spent, navigation behaviour, actions taken within the website or Service, referral sources and campaign response data.

Where required by applicable law, GovernApp will seek consent for certain analytics, advertising or remarketing technologies and provide users with options to manage their preferences.

Customer Data and Ownership: Customers retain ownership of their Customer Data.

GovernApp does not sell, rent or lease Customer Data or Personal Information to third parties. GovernApp uses Customer Data solely to provide, secure, maintain, support and improve the Service, and as otherwise described in this Statement or permitted by contract or law.

Authority and Responsibility: Customers are responsible for ensuring they have the authority, rights and consents necessary to upload or submit Customer Data to the Service, including where that data contains Personal Information about other individuals.

Third-Party Service Providers and Integrations: GovernApp uses third-party service providers and technical integrations to host, secure, authenticate, support and improve the Service. These may include hosting providers, authentication providers, analytics providers, communication tools, software development frameworks, advertising platforms and AI-enabled services.

GovernApp only discloses information to these providers where reasonably necessary for the operation, support, security, marketing or improvement of the Service, or where required by law.

Some providers may store or process information outside Australia. Where this occurs, GovernApp takes reasonable steps to implement contractual, technical and organisational safeguards appropriate to the circumstances.

AI-Enabled Functionality: Where AI-enabled functionality is used as part of the Service, GovernApp will seek to disclose the nature of that processing in product documentation, feature-specific notices or other customer communications.

GovernApp aims to apply reasonable controls to limit unnecessary disclosure of Personal Information or confidential information through AI-enabled functionality.

Use of De-identified Data: Information collected in and through the Service may be used for analytics, research, benchmarking, product improvement and publication of materials that support understanding of governance practices or promotion of the Service, provided that any such information is de-identified so that it does not reasonably identify a Customer or individual.

4. Retention, Access and Deletion

GovernApp retains information only for as long as reasonably necessary to provide the Service, comply with legal obligations, resolve disputes, enforce agreements, maintain security records, and support backup, audit and business continuity processes.

During an active subscription, Customers may request access to, correction of, export of, or deletion of Customer Data, subject to technical feasibility, legal obligations, commensurate fees, and verification of identity and authority.

Following termination or expiry of an account, GovernApp may retain Customer Data for a limited period to support account closure, recovery, audit, legal compliance and backup cycling, after which the data will be securely deleted or de-identified in accordance with GovernApp’s retention practices, unless longer retention is required by law.

GovernApp may charge a reasonable fee for non-standard data extraction, exceptional deletion assistance, restoration requests, or similar work outside standard Service functionality or support. Any such fee will be disclosed in advance.

5. Compliance Approach

GovernApp seeks to handle Personal Information in a manner consistent with applicable privacy and data protection obligations that apply to its operations, including relevant Australian privacy laws.

GovernApp may undertake periodic security reviews, risk assessments or other assurance activities to support the ongoing security and resilience of the Service.

6. Access and Correction Requests

Subject to applicable law, individuals may request access to Personal Information held about them and request correction of inaccurate, out-of-date, incomplete, irrelevant or misleading Personal Information.

Requests should be submitted using the contact details below. GovernApp may need to verify the identity and authority of the person making the request before taking action.

7. Updates to this Statement

GovernApp may update this Statement from time to time to reflect changes to the Service, security practices, legal obligations or operational requirements.

Updated versions may be published through the Service, on the website, or otherwise notified to Customers.

8. Contact Information

For questions or concerns regarding security or privacy, or to make a privacy-related request, please contact:

Data Protection Officer: dpo@governapp.com

By using the Service, users acknowledge that they have read and understood this Statement.