Skip to content
Gavi
  • How we work
  • Services
  • Proof
  • Pricing
Book a call →
  • How we work
  • Services
  • Proof
  • Pricing
  • FAQ
Book a call →

Privacy

Privacy Policy

Last updated 30 September 2026

The short version: we collect what we need to talk to you and do good work, we don’t sell it, and you can ask us to see, fix or delete it at any time.

On this page

About this policyWhat we collectHow we collect itHow we use itCookies, analytics and advertisingWho we share it withOverseas disclosureClient systems and dataStorage and securityHow long we keep itAccess, correction and your choicesComplaintsChanges to this policyContact us

About this policy

This policy explains how Gavi (“Gavi”, “we”, “us”, “our”) collects, uses, stores and discloses personal information when you visit this website, book a call with us, or work with us. We’re led from Melbourne, Victoria, Australia, and we handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).

If you’re a client, your engagement agreement may include additional terms about data we handle on your behalf. Where it does, that agreement applies alongside this policy.

What we collect

We only collect what we need to talk to you and do the work:

  • Contact details such as your name, email address, phone number, company and role.
  • Project information you choose to share, like what you’re building, your current systems, timelines and budget.
  • Booking details when you schedule a call, including the time you choose and any notes you add.
  • Billing information for clients, such as business name, ABN or tax details, billing address and payment records. We don’t store card numbers.
  • Technical information collected automatically when you browse, such as IP address, browser and device type, pages viewed, referring site, and approximate location.

We don’t ask for sensitive information (such as health or financial hardship details) and ask that you don’t send it to us. You can browse this site without telling us who you are.

How we collect it

Mostly directly from you: when you book a call, email us, talk with us, or sign an agreement. Some information comes from the tools we use to run the site (see cookies and analytics), and occasionally from public sources such as your company website or LinkedIn profile when we prepare for a call you’ve booked.

How we use it

We use personal information to:

  • respond to your enquiries and run the calls you book;
  • scope, quote, deliver and support the work you engage us for;
  • send invoices, manage payments and keep business records;
  • understand how the site is used so we can improve it, and measure whether our advertising works;
  • protect the security of our systems and prevent misuse;
  • meet our legal, tax and regulatory obligations.

We don’t sell personal information, and we don’t add you to a mailing list unless you ask to be on one. If we ever send you marketing, every message will include a way to opt out.

Cookies, analytics and advertising

This site uses a small number of cookies and similar technologies:

  • Google tag (Google Ads) helps us measure visits and the effectiveness of our ads. Google may set cookies and process your IP address and browsing data under its own privacy policy. You can control ad personalisation in your Google ad settings.
  • Cal.com powers our booking popup and may set cookies needed for scheduling to work.

You can block or delete cookies in your browser settings. The site will still work, although booking may need you to continue on cal.com.

Who we share it with

We share personal information only where needed to run our business, and only with people bound to protect it:

  • our own team members working on your enquiry or project, including engineers based in India;
  • service providers who help us operate, such as scheduling (Cal.com), email and document tools, cloud hosting, analytics and advertising (Google), and accounting and payment providers;
  • professional advisers such as accountants, lawyers and insurers;
  • authorities, where the law requires it or to protect our rights.

If Gavi is ever involved in a merger or sale, information may transfer to the new owner, who must continue to protect it under this policy.

Overseas disclosure

Part of our team works from India, and some of our service providers store data in other countries, including the United States. When we disclose personal information overseas, we take reasonable steps to make sure the recipient handles it consistently with the Australian Privacy Principles, through confidentiality obligations, contractual terms and access controls.

Client systems and data

When we build or run software for you, we may have access to personal information held in your systems, such as your customers’ data. We handle it only on your instructions and for the purpose of the engagement, with the least access needed. Your repositories, cloud accounts and keys stay yours. The confidentiality and data handling terms in your engagement agreement apply to that information, and we’ll return or delete it at the end of the engagement as agreed.

Storage and security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access or disclosure. That includes encrypted storage and transport, multi-factor authentication, role-based access, and keeping access limited to the people who need it. No system is perfectly secure, so if we become aware of a data breach likely to cause serious harm, we’ll notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

How long we keep it

We keep personal information only as long as we need it for the purposes above. Enquiries that don’t turn into work are deleted or de-identified within two years. Client and financial records are kept for as long as the law requires, which in Australia is generally at least five years for tax records.

Access, correction and your choices

You can ask to see the personal information we hold about you, ask us to correct it, or ask us to delete it where we’re not required to keep it. To make a request, get in touch and we’ll respond within 30 days. We may need to verify your identity first, and if we can’t meet a request, we’ll explain why.

If you’re in the European Union or the United Kingdom, you also have rights under the GDPR, including to object to or restrict processing and to data portability. We rely on our legitimate interests in responding to enquiries and running our business, on contract when we work together, and on your consent for non-essential cookies where that’s required.

Complaints

If you think we’ve mishandled your personal information, please get in touchfirst so we can put it right. We’ll acknowledge your complaint within 7 days and aim to resolve it within 30. If you’re not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

Changes to this policy

We may update this policy as our services or the law change. The latest version will always be on this page, with the date it was last updated at the top. If a change materially affects how we use information we already hold, we’ll let affected clients know.

Contact us

Questions about privacy? Get in touch. You can also read our terms.

Gavi

Software built for real users. Not just the demo. Led from Melbourne.

Site

How we workServicesProofPricingFAQ

Contact

Book a call

Elsewhere

Verlynk (opens in a new tab)
© 2026 Gavi
PrivacyTerms