Privacy Policy
Effective date: October 1 2026
1. About this policy
Harvy is operated by Tereo Pty Ltd trading as Harvy Intelligence (ABN 93 702 333 784) (we, us, or our). Harvy includes the websites at harvy.au, the application at app.harvy.au, and related onboarding, support, reporting, and professional services.
This policy explains how we collect, hold, use, and disclose personal information. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) to the extent they apply to us. Where they do not apply to a particular act or practice, we aim to use equivalent standards.
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. It can include information about customer administrators, authorised users, drivers, prospective customers, and other people whose information appears in material supplied to Harvy.
2. Our role and the customer's role
Our business customers decide which users, drivers, work diary sheets, compliance records, and related information are submitted to Harvy. For that information, we generally act as the customer's service provider and process it to provide Harvy and follow the customer's lawful instructions.
In this policy, Customer Data means information a customer or its users submit to Harvy, including driver and work diary information.
We handle account, billing, security, website, sales, and support information for our own business purposes as described in this policy.
Customers remain responsible for their own privacy notices, workplace processes, authority to provide information to Harvy, and responses to individuals where the customer controls the relevant record. If you are a driver or employee and your employer supplied your information, contact your employer first. We will assist the customer where reasonably required.
3. Personal information we collect
Depending on how Harvy is used, we may collect:
Contact and account information: name, employer, role, email address, telephone number, account identifiers, user permissions, login events, and authentication records.
Driver and work diary information: driver name and contact details, driver licence number and jurisdiction, base or depot, accreditation or fatigue scheme information, vehicle registration, work and rest times, dates, locations, two-up driver details, comments, handwriting, signatures, and other information visible on uploaded work diary sheets.
Compliance and operational information: source-document images, extracted data, possible errors or breaches, review outcomes, non-conformance actions, notes, reports, audit records, and information about who reviewed or changed a record.
Customer configuration information: organisation, depots, drivers, vehicles, rulesets, custom AFM or ACH rules, user roles, reporting preferences, and service settings.
Billing information: subscription, invoice, transaction, and payment-status information. Payment providers may collect card or bank details directly. We do not need to store complete card details when a payment provider handles them.
Support and communications: enquiries, calls, emails, meeting notes, feedback, attachments, and support history.
Technical and usage information: IP address, browser and device type, operating system, session and event data, approximate location derived from an IP address, error logs, security events, and pages or features used.
Website and sales information: demo requests, form submissions, marketing preferences, referral information, cookie and analytics identifiers, and business-network or company-level visitor information.
A work diary or related correspondence may incidentally reveal sensitive information, such as health or fatigue information, union membership, or biometric-like signatures. Customers should not provide sensitive information that Harvy does not need. We handle sensitive information only with consent or as otherwise permitted by law.
4. How we collect information
We collect personal information:
directly from you when you create or use an account, contact us, request a demo, or communicate with us;
from the customer organisation that creates your account or supplies driver and work diary information;
from uploaded documents, emails, scanners, integrations, and configuration chosen by a customer;
automatically through the website or application, including through cookies, logs, analytics, security, and business-visitor technologies; and
from service providers, referral partners, public business sources, and third parties where collection is lawful.
If practical, you may deal with us without identifying yourself or by using a pseudonym. This is usually not practical for account access, support, billing, security, or compliance records because we need to associate those activities with the correct organisation and user.
5. Why we use personal information
We use personal information to:
provide, configure, secure, maintain, and support Harvy;
receive and process work diary sheets, extract information, identify possible errors or breaches, and produce customer reports;
authenticate users, administer permissions, and keep an activity record;
provide onboarding, training, support, billing, and service communications;
investigate faults, misuse, security events, and suspected fraud;
improve the reliability, usability, and performance of Harvy;
meet legal, accounting, insurance, regulatory, and dispute-resolution obligations;
manage our customer and supplier relationships; and
send marketing to business contacts where permitted by law, subject to opt-out rights.
We may create aggregated or de-identified information for analytics, benchmarking, service improvement, and business planning. We will take reasonable steps to prevent that information from identifying an individual or customer before treating it as de-identified.
We do not sell personal information.
6. AI and automated processing
Harvy uses automated tools, which may include optical character recognition and artificial intelligence, to read work diary sheets, extract information, apply configured rules, and flag possible errors or breaches.
These outputs are recommendations and information aids. Harvy does not make the customer's final employment, disciplinary, safety, regulatory, or compliance decision. An authorised person must review source records and outputs before relying on them or taking action.
Automated processing can be affected by scan quality, handwriting, missing pages, configuration, rule changes, and model limitations. We use customer corrections and operational feedback to improve service performance. We do not permit a third-party model provider to train a general-purpose model on Customer Data unless this is expressly disclosed and authorised.
If our use of automated processing changes so that a computer program uses personal information to make or substantially assist a decision that could reasonably be expected to significantly affect an individual's rights or interests, we will update this policy and provide the information required by applicable law.
7. Who we disclose information to
We may disclose personal information to:
the customer organisation, its administrators, and authorised users;
providers that support hosting, databases, storage, authentication, email, communications, customer support, payments, analytics, error monitoring, document processing, AI or OCR, security, backups, and professional services;
contractors who help deliver onboarding, data review, support, or development and who are subject to appropriate confidentiality and security obligations;
professional advisers, auditors, insurers, and financiers;
regulators, law-enforcement bodies, courts, and other parties where required or authorised by law;
a party involved in a proposed or completed financing, merger, sale, restructure, or transfer of Harvy, subject to appropriate controls; and
another party with the consent or lawful direction of the relevant individual or customer.
We do not permit service providers to use personal information for their own unrelated marketing.
8. Overseas processing and disclosure
The Harvy database, including Customer Data, is hosted in Australia. Some service providers or their support personnel may process or access personal information outside Australia, including the United States. Provider locations can change as services and subprocessors change.
Where the Privacy Act applies, we take reasonable steps appropriate to the circumstances to require overseas recipients to protect personal information consistently with the APPs. This may include contractual privacy and security obligations, access restrictions, due diligence, and review of provider practices.
Contact us if you want the current list of relevant provider locations.
9. Cookies, analytics, and website visitor information
Our websites and application may use cookies and similar technologies to keep users signed in, remember settings, protect the service, understand use, measure campaigns, diagnose errors, and identify business-level website interest.
You can control non-essential cookies through available consent controls and browser settings. Blocking some cookies may affect service functions. Business-visitor tools may use network and device information to associate a visit with an organisation. We use this information for business sales and service improvement, not to identify a private household visitor.
10. Direct marketing
We may send product updates, event information, or offers to business contacts where permitted by law. You can opt out using the unsubscribe link or by contacting us. We will continue to send service, security, billing, and legal notices where necessary.
We do not use Customer Data about drivers for unrelated direct marketing.
11. Data security and incidents
We take reasonable technical and organisational steps to protect personal information against misuse, interference, loss, and unauthorised access, modification, or disclosure. Measures may include access controls, authentication, encryption in transit, restricted support access, logging, backups, staff and contractor obligations, and incident-response procedures.
No online service is completely secure. Customers must protect account credentials, configure permissions appropriately, remove users who no longer need access, and notify us promptly of suspected compromise.
If we become aware of unauthorised access to or disclosure of Customer Data in our control that is reasonably likely to materially affect a customer, we will notify that customer without undue delay and take reasonable steps to contain and fix the problem. If an eligible data breach occurs, we will also assess and respond to it in accordance with applicable law, including notification obligations where required.
12. Retention and deletion
During a customer's subscription, we keep work diary sheets and related records submitted to Harvy available to the customer for at least 3 years from the date of upload, unless the customer deletes them or its agreement with us says otherwise. A customer may require a longer period under law, accreditation, contract, dispute hold, or its own record-keeping policy. The customer is responsible for selecting and meeting its required retention period and exporting records when needed.
We retain other personal information only for as long as reasonably necessary for the purposes described in this policy, including to provide the service, maintain security and audit logs, recover from outages, meet tax and corporate record obligations, resolve disputes, and enforce agreements.
When an account ends, the customer can export its Customer Data for 30 days, unless the law, security, or its agreement with us requires otherwise. After that, Customer Data is handled under the applicable Terms, Order, and any written data-processing agreement. Data may remain temporarily in backups until the backup cycle expires. We may retain information that law requires us to keep, and may retain properly de-identified information.
13. Access and correction
You may ask for access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant, or misleading. Contact the Privacy Officer using the details below.
If the information is Customer Data controlled by your employer or another customer, we may refer the request to that customer and assist it to respond. We may need to verify your identity and authority. We will respond within a reasonable period and, where the APPs apply, give any required written reasons and complaint options if access or correction is refused.
We do not charge for making a request. We may charge reasonable costs for providing access where permitted by law and will tell you first.
14. Privacy complaints
Send a written complaint to the Privacy Officer. Include enough information for us to understand the concern and the outcome you seek. We will acknowledge the complaint, investigate it, and aim to respond within 30 days. If we need more time, we will explain why.
If you are not satisfied and the Privacy Act applies, you may complain to the Office of the Australian Information Commissioner. The OAIC will generally expect you to have first given us a reasonable opportunity to respond.
15. Third-party services and links
Harvy may integrate with or link to third-party services. Their handling of information outside Harvy is governed by their own terms and privacy policies. Customers are responsible for choosing and authorising integrations. We are responsible for our own handling of personal information as described in this policy and applicable law.
16. Changes to this policy
We may update this policy when our services, providers, practices, or legal obligations change. We will publish the updated version with a new effective date. We will give reasonable advance notice of a material change where practical and seek consent if required by law.
17. Contact us
Privacy Officer
Tereo Pty Ltd
ABN: 93 702 333 784
Email: support@harvy.au
Website: harvy.au
