OHVORA

Privacy Policy

How Ohvora collects, uses, protects and respects personal information

Effective date
28 July 2026

Business
Ohvora | ABN 78 230 902 857

Ohvora believes technology should serve people—not replace them. That includes treating personal information with care, being clear about how it is used, and collecting only what is reasonably needed to provide useful business systems.

Ohvora is a registered Australian business name operated by Leigh James Henry (ABN 78 230 902 857). This Privacy Policy explains how Ohvora (“we”, “us”, “our”) handles personal information through https://ohvora.com.au, enquiries, consultations and services.

We aim to handle personal information consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and with the privacy commitments described in this Policy.

1. Scope of this Policy

This Policy applies to personal information we handle about:

·  Website visitors, prospects and people who contact Ohvora;

·  clients, their staff, suppliers and authorised representatives;

·  people who interact with a client-facing system configured or supported by Ohvora; and

·  other individuals whose information is provided to us in connection with our business.

When Ohvora processes information through a system on behalf of a client, that client may decide why and how the information is collected. The client’s privacy policy may also apply, and privacy requests may need to be handled with that client.

2. Personal information we may collect

Contact and business information

This may include your name, business name, role, email address, telephone number, communication preferences, enquiry details, meeting notes and other information you choose to provide.

Service and account information

This may include account details, user permissions, project requirements, support requests, system configuration information, billing records, transaction references and records of our business relationship. Payment card details are generally processed by payment providers rather than stored directly by Ohvora.

Website and technical information

This may include IP address, browser and device information, pages viewed, dates and times, referring pages, approximate location, cookies and similar technical data.

Interaction and workflow data

Where relevant to an agreed service, this may include chat or message content, call recordings or transcripts, enquiry and lead details, appointment information, form responses, workflow events, delivery status and system performance data.

Sensitive information

We do not seek to collect sensitive information unless it is reasonably necessary for an agreed purpose and collection is lawful. Please do not provide health, identity, financial or other sensitive information unless requested through an approved and secure process.

3. How we collect personal information

We may collect personal information:

·  directly from you when you contact us, book a consultation, complete a form, enter an agreement or request support;

·  from a client or authorised representative who asks us to configure or support a business system;

·  automatically when you use the Website or an enabled service;

·  from third-party platforms connected to an agreed workflow; and

·  from public sources where collection is lawful and reasonably related to our business.

Where practical, you may interact with us anonymously or using a pseudonym. We may be unable to provide certain services if we cannot verify or use the information reasonably required.

4. Why we use personal information

We may use personal information to:

·  respond to enquiries, book consultations and communicate with you;

·  prepare proposals, enter and administer agreements, invoice and keep business records;

·  design, configure, operate, maintain, troubleshoot and improve agreed business systems;

·  route enquiries, support appointments, send authorised messages and generate client reports;

·  protect users and systems, prevent fraud, investigate misuse and manage security incidents;

·  meet legal, regulatory, insurance and accounting obligations;

·  understand Website performance and improve our services; and

·  send marketing communications where we have consent or are otherwise permitted by law.

You can opt out of marketing at any time using the unsubscribe method in the message or by contacting us. Transactional and service messages may still be sent where necessary to provide a service or respond to you.

5. Automated systems and AI-assisted processing

Some Ohvora services use automated or AI-assisted tools to interpret inputs, generate draft responses, route enquiries, summarise interactions or trigger agreed workflows. These tools support business processes and may not always produce accurate or complete results.

We aim to configure appropriate human review, escalation and access controls for the purpose and risk of each system. Where reasonably practicable, people should be informed when they are interacting with an automated system or when an interaction is being recorded.

Ohvora does not intentionally use identifiable client or end-user content to train a general-purpose AI model for unrelated purposes. If a proposed use materially differs from the purpose for which information was collected, we will seek appropriate authority or consent and update relevant notices where required.

De-identified or aggregated operational information may be used to understand performance and improve services where individuals are not reasonably identifiable.

6. When we disclose information

We do not sell or rent personal information. We may disclose information where reasonably necessary to:

·  cloud hosting, communications, CRM, calendar, payment, analytics, security, support and AI-processing providers that help deliver our services;

·  professional advisers, insurers, contractors and suppliers who need the information for an authorised purpose;

·  a client on whose behalf an interaction or workflow is being managed;

·  a purchaser or successor in connection with a proposed or completed business transfer, subject to appropriate protections;

·  regulators, law-enforcement bodies, courts or other parties where required or authorised by law; or

·  another party with your consent or at your direction.

We seek to limit disclosure to what is reasonably necessary and use contractual, access or confidentiality controls where appropriate.

7. Overseas processing

Some technology providers may process or store information outside Australia. The countries involved can vary depending on the provider, service configuration and data-routing arrangements.

Where Australian privacy law applies, we will take reasonable steps required by law before disclosing personal information overseas. Before deploying a client system, relevant provider locations and cross-border arrangements should be assessed as part of the implementation.

8. Cookies and analytics

The Website may use cookies and similar technologies that are necessary for operation, remember preferences, support security or help us understand Website use. Where required, we will provide choices or seek consent for non-essential cookies.

You can restrict cookies through your browser settings, although some Website features may not work as intended. The Website should identify material analytics or advertising tools in its cookie notice or consent settings when they are enabled.

9. Direct marketing

We may send information about Ohvora’s services where you have consented or where permitted by law. Commercial electronic messages will identify the sender and include a functional way to unsubscribe. We will action valid unsubscribe requests within the period required by law.

We do not treat a general enquiry or one-off transaction as unlimited consent to receive marketing.

10. Security

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, secure transmission, provider due diligence, backups, logging and staff or contractor confidentiality obligations, depending on the service.

No internet transmission or storage method is completely secure. If you believe information connected with Ohvora has been compromised, contact us promptly.

11. Data breaches

We will assess suspected data breaches and take reasonable steps to contain and reduce harm. Where the Notifiable Data Breaches scheme applies, we will notify affected individuals and the Office of the Australian Information Commissioner when required. Where we process information for a client, we will cooperate with that client in responding to the incident in accordance with applicable agreements and law.

12. Retention and deletion

We keep personal information only for as long as reasonably needed for the purpose for which it was collected, to provide services, resolve disputes, maintain security and business records, or meet legal, tax, insurance and contractual obligations.

Retention periods vary according to the type of information, the relevant service and provider settings. When information is no longer required, we take reasonable steps to delete it or de-identify it, subject to backups, legal holds and technical limitations.

Client-specific retention, export and deletion settings may be set out in a service agreement or implementation record.

13. Access and correction

You may ask for access to personal information we hold about you or request that inaccurate, out-of-date, incomplete, irrelevant or misleading information be corrected. Contact us using the details below.

We may need to verify your identity and may refuse or limit a request where permitted by law. If so, we will explain the reason where required. If the information is controlled by an Ohvora client, we may refer the request to that client or assist them to respond.

14. Privacy complaints

If you have a privacy concern, contact us and describe the issue and the outcome you are seeking. We will acknowledge and investigate the complaint and aim to respond within a reasonable period.

If you are not satisfied with our response and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au.

15. Children’s privacy

The Ohvora Website and business services are intended for adults and businesses, not children. We do not knowingly collect personal information directly from children through the Website. A client service that may involve children requires appropriate notice, authority, safeguards and configuration for that context.

16. Third-party websites and services

Links and connected platforms may have their own privacy policies and practices. Ohvora is not responsible for how an independent third party handles information outside the service or configuration we control. You should review the relevant third-party privacy information.

17. Changes to this Policy

We may update this Policy when our practices, services or legal obligations change. The current version and effective date will be posted on the Website. If a change is material, we may provide additional notice where appropriate.

Contact Ohvora

Business: Ohvora, operated by Leigh James Henry (ABN 78 230 902 857)
Website: https://ohvora.com.au
Email
: [email protected]

Please use the subject line “Privacy request” so we can direct your enquiry appropriately.