Privacy Policy
Aevi Tech Pty Limited · ACN 650 586 637
Version 1.1 · Effective: 1 May 2025
Last updated: July 2026
This Privacy Policy explains how Aevi Tech Pty Limited (ACN 650 586 637) collects, uses, stores, and discloses personal information in connection with the CertMate platform and Mobile Application.
1. Who We Are
Aevi Tech Pty Limited (ACN 650 586 637) ("Aevi Tech", "we", "us", "our") operates the CertMate biosecurity certification management platform, available at app.certmate.com.au and as a Mobile Application for iOS and Android devices.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the General Data Protection Regulation (GDPR) applies to users in the European Economic Area, we comply with those obligations.
This Privacy Policy applies to all users of CertMate including company administrators, inspectors, drivers, third party certifiers, landowners, and partners.
2. What Personal Information We Collect
2.1 Account and Identity Information
When you or your company registers for CertMate, we collect:
- Full name, email address, and job title
- Company name, ABN, business address, and company type
- User role within your organisation (e.g. administrator, inspector, driver, landowner)
- Profile photograph (optional, if uploaded)
- Inspector credentials and licence information (for users performing inspection sign-off)
- Digital signature (for certificate authorisation purposes)
2.2 Certificate and Operational Data
When using CertMate to create and manage biosecurity certificates, we collect:
- Vehicle registration numbers, make, model, and fleet details
- Certificate details including biosecurity declaration content, dates, and status
- Property names, locations, and GPS coordinates
- Driver names and contact information associated with certificates
- Inspector approval records and sign-off details
2.3 Payment Information
When you subscribe to CertMate, billing is handled by our payment processor, Stripe, Inc. We do not collect or store full credit card or bank account details. Stripe collects and processes payment information in accordance with its own Privacy Policy and PCI DSS standards. We retain records of subscription status, billing dates, and invoice amounts.
2.4 Technical and Device Data
When you use the CertMate web application or Mobile Application, we may automatically collect:
- IP address and browser or device type
- Operating system version and device identifiers
- Application usage logs, session duration, and feature interactions
- Anonymised crash and diagnostic data (used solely to improve platform stability)
2.5 Location Data
The Mobile Application may request access to your device's location services when you use property or field-based features, such as recording property GPS coordinates or checking in to a property. This one-off location access is optional; you may decline or revoke permission at any time through your device settings.
Continuous vehicle location (geofencing and telematics). Where your organisation enables CertMate's optional continuous compliance feature, CertMate collects the location of nominated fleet vehicles over time so it can automatically log entry to and exit from registered properties, verify the vehicle's hygiene certificate at the property boundary, and raise compliance alerts (including entry into designated no-go zones). For each position we may collect the vehicle registration, latitude and longitude, timestamp, speed, and accuracy. Position data is sourced either from your organisation's In-Vehicle Monitoring System (IVMS / telematics provider) or, where used, from a driver's device GPS while the application is open.
This feature is off by default. It is only activated when an administrator of your organisation enables it and confirms that affected drivers have been informed and that the organisation has a lawful basis to collect the data. An administrator can disable it at any time, which immediately stops the collection of new position data. Continuous location data is used solely for the compliance purposes described above and is not used for marketing or sold to third parties.
2.6 Biometric Data
CertMate offers an optional Biometric Authentication feature using your device's fingerprint or facial recognition capability. All biometric processing is performed entirely on your device by your device's operating system. We do not collect, transmit, store, or have access to any biometric data at any time.
2.7 Communications
If you contact us via email or our support portal, we collect your name, email address, and the content of your communications in order to respond to your enquiry and maintain support records.
2.8 In-App Messages
CertMate includes an optional Direct Messaging feature available to administrators of eligible (Enterprise) companies. Where your company uses this feature, we collect and store the full content of the messages you send, the identity of the sender and the participants and their companies, and the associated timestamps. Messages may contain personal information that you or other participants choose to include; please do not include sensitive personal information in messages beyond what is necessary. How long messages are kept is described in Section 6, and who can see them is described in Section 4.8.
3. How We Use Your Personal Information
We use your personal information only for the purposes for which it was collected or for directly related purposes, including:
| Purpose | Legal Basis (GDPR) / APP Basis |
|---|---|
| Providing and operating the CertMate platform | Contractual necessity / Primary purpose |
| Creating, managing, and distributing biosecurity certificates | Contractual necessity / Primary purpose |
| User authentication and account security (including MFA) | Contractual necessity / Primary purpose |
| Processing subscription payments via Stripe | Contractual necessity / Primary purpose |
| Sending transactional emails (certificate notifications, account alerts) | Contractual necessity / Primary purpose |
| Providing customer support and responding to enquiries | Legitimate interest / Secondary purpose (reasonably expected) |
| Improving CertMate using anonymised usage and diagnostic data | Legitimate interest / Secondary purpose (reasonably expected) |
| Complying with legal obligations | Legal obligation |
| Sending product updates and service announcements | Legitimate interest / Consent (where required) |
We will not use your personal information for unrelated secondary purposes without your consent, unless we are required to do so by law.
4. Who We Share Your Information With
We do not sell your personal information. We share information only as described below.
4.1 Sub-processors and Service Providers
| Provider | Purpose | Data Location |
|---|---|---|
| Supabase, Inc. | Database hosting, user authentication, file storage | Australia |
| Stripe, Inc. | Payment processing and subscription management | United States (PCI DSS compliant) |
| Google LLC (Firebase / Play Store) | Android app distribution; crash reporting (anonymised) | United States |
| Apple Inc. (App Store) | iOS app distribution | United States |
Each sub-processor is bound by contractual obligations to protect your data and use it only for the specified purpose.
4.2 Within Your Organisation
Your personal information may be visible to other authorised users within your company on the CertMate platform (e.g. administrators can see team member profiles and roles). This is necessary for the operation of the platform.
4.3 Third Party Certifiers (TPC)
If your company has authorised a Third Party Certifier to issue certificates on your behalf, that TPC will have access to your company's vehicle data, driver names, and operational information to the extent necessary to perform the certification function. This sharing is authorised by your company administrator.
4.4 Partner Companies
If your company account is managed by an authorised Partner, that Partner may access your company's account information and user data in accordance with their agreement with Aevi Tech.
4.5 Landowner Companies
Where a subscribing company has established a link with a Landowner Company, limited certificate and property data may be shared with the Landowner Company to support property-level biosecurity record keeping. This occurs only when both parties have established the link through CertMate.
4.6 Legal and Regulatory Disclosure
We may disclose personal information where required by law, court order, or government authority, or where we reasonably believe disclosure is necessary to protect our rights, property, or the safety of any person.
4.7 Business Transfers
In the event of a merger, acquisition, or sale of all or part of Aevi Tech's business, personal information may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.
4.8 In-App Messaging (Cross-Company)
The Direct Messaging feature allows an administrator of an eligible company to exchange messages with administrators of another company with which their company holds an approved link. In such cross-company conversations, the content of the messages and the identity of the participating companies are visible to the administrators of both companies. This sharing occurs only where both companies have established and maintained an approved link through CertMate; if the link is withdrawn, ongoing cross-company access to the conversation is removed (although the messages themselves are retained — see Section 6). Notification emails and mobile push notifications about new messages do not contain the message content itself.
5. Data Storage and Security
5.1 Where Your Data Is Stored
Customer Data is stored on Supabase infrastructure hosted in Australian data centres. Some data processed by our sub-processors (e.g. Stripe for payments, Apple/Google for app distribution) may be stored or processed outside Australia. Where international transfers occur, we take steps to ensure your data receives an equivalent level of protection.
5.2 Security Measures
We implement appropriate technical and organisational security measures to protect personal information, including:
- Encryption of data in transit (TLS) and at rest
- Row-level security (RLS) ensuring each company can only access its own data
- Role-based access controls limiting data access to authorised users
- Mandatory multi-factor authentication (MFA) for administrator roles
- Audit logging of sensitive administrative actions
- Regular security reviews and penetration testing
No system or transmission over the internet can be guaranteed as completely secure. You use CertMate at your own risk and are responsible for maintaining the security of your account credentials.
5.3 Offline Data
When you use CertMate in Offline Mode, a subset of your data is stored locally on your device. You are responsible for the physical security of your device. Data stored locally is subject to your device's built-in security protections.
5.4 Data Breach Notification
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches (NDB) scheme under the Privacy Act 1988 (Cth), within 30 days of becoming aware of the breach.
6. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, including for the duration of the contractual relationship and any subsequent legally required retention period.
| Data Type | Retention Period |
|---|---|
| Active account and user data | For the duration of the subscription, plus 30 days post-termination |
| Biosecurity certificates and related records | 10 years from certificate creation (to support regulatory audit requirements) |
| Payment and billing records | 7 years (as required by the Corporations Act 2001 (Cth)) |
| Support communications | 3 years from last contact |
| Anonymised diagnostic / usage data | Indefinitely (not linked to individuals) |
| In-app messages and conversation records | Retained indefinitely as immutable records (see below) |
| Training Account data (all types) | Training records are deleted 10 days from creation. Remaining account data is retained while the account is in use and is deleted when the account is closed. |
Following the post-termination retention period, Customer Data will be permanently deleted from our systems, except for records we are required or permitted to retain by law or for the integrity of the platform. We may retain de-identified or aggregated data derived from Customer Data for platform improvement purposes.
Training Accounts. A Training Account is a free account provided to training organisations for demonstration and instruction only. Personal information entered into a Training Account — including the names and email addresses of participants added by the account administrator — is stored on the same infrastructure and protected by the same measures described in Section 5. Training records created in the account are permanently deleted 10 days after they are created. The account itself does not expire on a fixed date; remaining data is retained while the account is in use and is permanently deleted when the account is closed, which Aevi Tech may do at any time on reasonable notice. Records created in a Training Account are training records only; they are not biosecurity certificates and are not retained for the 10-year period that applies to real certificates. A Training Account is isolated from every other company using CertMate: its data is not visible to any other organisation, and no email is sent from it to anyone outside the account. Where a person is added to a Training Account for demonstration purposes, the account administrator is responsible for having a lawful basis to enter that person's details.
In-app messages are retained as immutable records: once sent, a message cannot be edited or deleted, and messages are retained indefinitely, including after the relevant conversation, the Direct Messaging feature, or your subscription ends. This supports the integrity and evidentiary reliability of communications within CertMate's biosecurity-compliance context. If you wish to request the deletion or restriction of message content that contains your personal information, contact us at support@aevi.tech; we will assess each request in accordance with applicable law and the limited exceptions that apply to records we are required or permitted to retain.
7. Your Privacy Rights
Subject to applicable law, you have the following rights regarding your personal information:
7.1 Australian Privacy Act Rights
- Access: You may request a copy of personal information we hold about you.
- Correction: You may request correction of inaccurate or incomplete information.
- In-app messages: Messages sent through the Direct Messaging feature are immutable records and cannot be edited or deleted through the platform. The access and correction rights above are subject to this and to the retention exceptions described in Section 6.
- Complaints: You may lodge a complaint with us or with the OAIC (oaic.gov.au) if you believe we have breached the APPs.
7.2 Additional GDPR Rights (EEA Users)
If you are located in the European Economic Area, you additionally have the right to:
- Erasure ("right to be forgotten") — request deletion of your personal data
- Restriction of processing — request we limit how we use your data
- Data portability — receive your data in a structured, machine-readable format
- Object to processing based on legitimate interests
- Lodge a complaint with your local supervisory authority
7.3 How to Exercise Your Rights
To exercise any of these rights, contact us at support@aevi.tech. We will respond within 30 days. We may ask you to verify your identity before processing your request. We will not charge a fee for reasonable access or correction requests.
7.4 Opt-Out of Marketing
You may opt out of marketing communications at any time by clicking "Unsubscribe" in any email we send, or by contacting us at support@aevi.tech. Transactional and operational emails (e.g. certificate notifications, account alerts) cannot be opted out of while your account is active.
8. Cookies and Local Storage
The CertMate web application uses browser local storage and session storage to maintain your authenticated session and cache operational data for offline functionality. We do not use third-party advertising or tracking cookies.
The following types of storage are used:
| Type | Purpose | Expires |
|---|---|---|
| Authentication token (local storage) | Maintains your login session across browser sessions | On logout or token expiry |
| Offline cache (local storage) | Stores operational data for Offline Mode | Cleared on account logout or data sync |
| Session state (session storage) | Tracks in-page navigation and form state | On browser tab close |
You may clear local storage through your browser settings. Doing so will log you out of CertMate and clear any locally cached offline data.
9. Children's Privacy
CertMate is a business-to-business platform intended for use by companies and their employees. We do not knowingly collect personal information from individuals under the age of 18. If you believe a person under 18 has provided us with personal information, please contact us at support@aevi.tech and we will delete it promptly.
10. Third-Party Links and Services
CertMate may contain links to third-party websites or integrate with third-party services (such as app stores or biosecurity authority portals). This Privacy Policy does not apply to those third parties. We recommend reviewing the privacy policies of any third-party services you use in connection with CertMate.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, CertMate's features, or applicable law. We will notify you of material changes by:
- Posting the updated policy on our website at www.aevi.tech/privacy-policy and app.certmate.com.au/privacy
- Sending an email notification to the primary contact email for your account
Your continued use of CertMate after the effective date of any updated Privacy Policy constitutes your acceptance of the changes.
12. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our handling of your personal information, please contact our Privacy Officer:
Aevi Tech Pty Limited — Privacy Officer
Email: contact@aevi.tech
Post: Unit 59, 1 Lyra Avenue, Hope Island QLD 4212
We will acknowledge your request within 5 business days and respond fully within 30 days.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
CertMate Privacy Policy v1.1 · Aevi Tech Pty Limited ACN 650 586 637 · Effective May 2025 · Last updated July 2026