Legal
Privacy Policy
Last updated: 15 July 2026 · v2.0
Oiva Developments Pty Ltd (ABN 93 693 621 457) (“Oiva”, “we”, “us” or “our”) is committed to protecting your privacy and handling personal information openly, transparently and with care. This Privacy Policy explains how we collect, hold, use and disclose personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and other applicable Australian laws.
Oiva is an Australian, sovereign, AI-native software platform for the early childhood education and care (ECEC) sector. All customer data is hosted in Australia, and we do not transfer customer data overseas as part of our platform operations.
1. Who this policy applies to
This policy applies to personal information we handle about:
- visitors to our website (oiva.com.au) and people who contact us or join our waitlist;
- our customers (approved providers and services) and their personnel who use, or register interest in using, the Oiva platform; and
- individuals whose personal information our customers enter into the Oiva platform, including children, parents, guardians and educators.
Where our customers use the Oiva platform to manage records about children, families and staff, that information is collected and held by us on behalf of the customer. The customer decides what information is entered, who may access it, and how it is used within the platform. If you are a parent, guardian or educator with questions about information held about you or your child in a service’s Oiva records, please contact that service in the first instance.
2. Personal information we collect
The kinds of personal information we collect and hold depend on your relationship with us:
- Contact details: name, email address, phone number and business address.
- Account information: username, authentication credentials (passwords are stored only as one-way salted hashes), and your role within your organisation.
- Business information: childcare service name, provider and service approval numbers, and centre details.
- Operational data entered by customers: enrolment records, attendance and session data, Child Care Subsidy (CCS) related information, staff qualification records, medical and health information relevant to a child’s care and safety, and incident reports. Some of this is sensitive information under the Privacy Act and is handled with a higher level of protection.
- Payment-related information: where a service uses integrated billing, information reasonably necessary to establish and process payments is collected and processed by our authorised payment partners. We do not store full card numbers on the Oiva platform, and we minimise the payment details we hold. Direct debit details are collected and secured by our authorised payment partners.
- Usage data: log files, IP addresses, device and browser type, and pages visited, collected automatically when you use our website or platform. See our Cookie Policy for details.
- Communications: records of emails, messages, support requests and feedback you send us.
- AI-generated or inferred information: where an AI feature generates or infers information about an identified individual (for example, a drafted observation about a child prepared for educator review), we treat that output as personal information and protect it accordingly.
Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym, for example when making a general enquiry about our products. Anonymity is not practicable where we must verify identity, such as for a platform account or CCS-related transactions.
3. How we use personal information
We collect, hold and use personal information only for purposes that are reasonably necessary for our functions and activities, including to:
- provide, operate, secure, support and improve the Oiva platform and our website;
- process CCS claims and communicate with the Department of Education and Services Australia on a customer's behalf, where authorised;
- send service-related communications, account notices and security alerts;
- respond to enquiries, support requests and feedback;
- send product updates and waitlist communications where you have opted in (you may unsubscribe at any time);
- comply with our legal obligations, and establish or defend legal claims; and
- conduct de-identified and aggregated analytics to understand how the platform is used and to improve our service.
What we do not do
- We do not sell, rent or trade personal information.
- We do not use personal information held on behalf of our customers to train artificial intelligence models.
- We do not undertake biometric identification or processing.
- We do not use third-party advertising cookies or disclose behavioural data to advertisers.
4. Artificial intelligence
Oiva is an AI-native platform: certain features use artificial intelligence, including generative AI, to assist educators and service administrators. Our commitments:
- Humans stay in control. AI features assist and draft; they do not decide. Any AI output that could affect a child’s record, a family’s entitlements, a compliance outcome or a payment is subject to review and approval by a qualified human before it takes effect. There is no fully automated decision path.
- AI stays in Australia. All AI processing for the platform occurs on infrastructure located in Australia. Personal information is not sent overseas for AI processing.
- Data minimisation and redaction. We minimise the personal information included in AI prompts. Financial identifiers such as tax file numbers, bank account details and Customer Reference Numbers are structurally excluded from AI processing, and these exclusions are technically enforced and tested.
- No training on your data. Personal information entered into the platform is not used to train or fine-tune AI models.
- Transparency. Where you interact directly with an AI feature (such as an assistant or chatbot), it is clearly identified as AI. AI-generated content presented for human review is labelled as such.
- Auditability. AI interactions are logged with appropriate redaction and retention controls so that they can be reviewed and audited.
For a detailed explanation of how AI is used in Oiva, the rules it operates under, and your rights, see our AI Transparency Statement.
5. Automated decision-making
Oiva does not make any decision that significantly affects an individual’s rights or interests using a computer program without human involvement. Computer programs, including AI, are used within the platform to assist with operational tasks, for example preparing draft documentation, surfacing compliance information, estimating fees and subsidy amounts, or flagging records for human attention. In each case, a person makes, reviews or approves the decision. Automated outputs are inputs to human decisions, not substitutes for them.
If we ever introduce a decision made solely by automated means that could significantly affect you, we will update this policy first and put in place appropriate safeguards, including rights of review.
6. Data storage and security
All personal information we hold is stored on cloud infrastructure physically located in Australia. We do not transfer personal information outside Australia, and we are not likely to disclose personal information to overseas recipients.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These measures include:
- encryption in transit (TLS) and at rest for all customer data;
- strict logical tenant isolation, enforced at the database layer, so that each service's data is segregated from every other service's data;
- least-privilege, role-based access controls, with multi-factor authentication for administrative access;
- comprehensive, tamper-evident audit logging of access to and changes in the platform;
- continuous monitoring, alerting and regular security reviews, with our security program aligned to the Australian Cyber Security Centre's Essential Eight; and
- organisational measures including staff confidentiality obligations, security training, access reviews, and an incident response plan.
Data breach notification: If a data breach occurs that is likely to result in serious harm to any individual, we will assess and notify affected individuals and the OAIC in accordance with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act.
No method of electronic storage or transmission is completely secure. If you believe your information has been compromised, contact us immediately at privacy@oiva.com.au.
7. Disclosure of personal information
We may disclose personal information to:
- Australian Government agencies (for example, the Department of Education and Services Australia via the CCSS) where required to deliver the service and as authorised by the customer or by law;
- third-party service providers located in Australia who assist us in operating our platform and website (such as cloud hosting, email delivery, payment processing and error monitoring), under contractual confidentiality and privacy obligations;
- professional advisers such as lawyers, accountants and insurers, under confidentiality; and
- law enforcement or regulatory bodies where required or authorised by law.
We do not disclose personal information to overseas recipients in the ordinary course of our business. Where the platform handles government related identifiers, such as Customer Reference Numbers used in CCS administration, we use and disclose them only as reasonably necessary to perform CCS-related functions or as otherwise required or authorised by law (APP 9).
8. Children's information
Our customers enter records about children in their care into the Oiva platform. This information is collected and held on behalf of the customer. We handle children’s information with extra care:
- access is restricted strictly to authorised users of the relevant service, enforced technically through tenant isolation and role-based access;
- children's information is never used for marketing, profiling or AI model training;
- AI features operating on children's records always require human (educator or administrator) review before any output is saved to a child's record; and
- we retain children's information only as long as necessary to provide the service or as required by law, including record-keeping obligations under education and care services law.
Oiva is a business-to-business platform. Our website and platform are designed for use by adults, and we do not knowingly collect personal information directly from children. If you believe a child’s information has been provided to us without appropriate authority, please contact us.
9. Direct marketing
We only send marketing and waitlist communications where you have opted in, and every message includes a functional unsubscribe facility, consistent with the Spam Act 2003 (Cth) and APP 7. We action unsubscribe requests promptly. Service-related communications, such as security alerts and account notices, are not marketing and may still be sent to account holders.
10. Cookies and website analytics
Our website uses cookies and similar technologies to remember your preferences and to understand, in aggregate, how visitors use our site. We use first-party, privacy-respecting analytics only. We do not use third-party advertising cookies and we do not sell behavioural data. Full details, including the cookies we set and how to control them, are in our Cookie Policy. You can control cookies through your browser settings; disabling cookies may affect some website functionality.
11. Access, correction and complaints
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us at privacy@oiva.com.au. We will respond within 30 days. We do not charge for making a request.
Where the information is held on behalf of a customer (for example, your child’s records at a service using Oiva), we may refer your request to that service and support it to respond.
If you believe we have breached the APPs or mishandled your personal information, please complain to us first at privacy@oiva.com.au. We take complaints seriously and will investigate and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
12. Retention and destruction
We retain personal information only as long as necessary for the purposes described in this policy, to comply with legal obligations (including record retention requirements under family assistance law and education and care services law), to resolve disputes and to enforce our agreements. When personal information is no longer required, we take reasonable steps to destroy it securely or to de-identify it.
When a customer leaves the platform, we provide their data to them in a usable format and then delete it in accordance with our retention schedule and applicable law.
13. Changes to this policy
We may update this Privacy Policy from time to time. Where changes are material, we will notify customers by email or through the platform before they take effect. The date at the top of this page reflects when the policy was last revised.
14. Contact us
If you have any questions, concerns or requests relating to your privacy or this policy, please contact us.
Related legal documents