This Privacy Policy explains how Appcovi collects, uses, stores and shares personal information when you use Compliance HQ. It is written to align with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and, where applicable, the EU GDPR.
What we collect
From workspace owners: name, email, hashed password, workspace name, logo, primary colour, Stripe customer ID and billing status, and any content you upload.
From staff members: only what an owner enters (name, role, department, phone) plus what the staff member optionally adds in their PWA (avatar photo, preferred language, signature drawn on their device, answers to training questions).
Automatically: minimal server logs (IP, user-agent, request path, timestamp) used for debugging and security. We do not use third-party analytics or advertising cookies.
Why we collect it
To provide the Service — build your training matrix, generate certificates, send reminders, process subscription payments, and enable owner countersign. We do not sell personal information to third parties.
AI processing
Training PDFs, translated content and short-answer responses are sent to Google Gemini via the Emergent LLM proxy to perform question extraction, translation and grading. These providers process the content transiently to return a result and do not use it to train their models.
Data location and retention
Data is stored on Appcovi-managed infrastructure in Australia. Uploaded PDFs, avatars and signature images are stored on encrypted disk. We retain Your Content while your workspace is active and delete it within 30 days of workspace closure, except where retention is required by law.
Sharing with third parties
We share the minimum necessary information with the following processors:
- StripePayment processing — subscription plan, billing email, card token. Card details are handled by Stripe, never by Appcovi.
- GeminiGoogle Gemini via Emergent LLM — AI text extraction, translation and short-answer grading.
- ResendTransactional email — password reset, expiry reminders.
Your rights
You may request access to, correction of, or deletion of the personal information we hold about you at any time by emailing appcovi2026@gmail.com. Workspace owners can also export their data as CSV directly from the app.
If you are a staff member and prefer not to use a personal avatar or answer training questions, speak to the workspace owner — they administer the workspace.
Security
Passwords are hashed with bcrypt. Sessions use HTTP-only, SameSite=None, Secure cookies with a Bearer-token fallback. All traffic is served over HTTPS. Access to production systems is limited to Appcovi engineers and audited.
Cookies
We use one first-party cookie (chq_token) to keep you signed in. No advertising or tracking cookies are set.
Children
Compliance HQ is a workplace tool and is not directed at children under 16. Do not add anyone under 16 to a workspace without a parent's or guardian's consent.
Complaints
If you believe we have mishandled your personal information, please contact us first. If you remain unsatisfied, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
Changes to this Policy
Material changes will be notified in-app at least 14 days before taking effect. The date at the top of this page is always the current effective date.