← Back to home
Legal

Privacy Policy

Last updated 27 June 2026

1. Who we are

This Privacy Policy explains how Roova (“Roova”, “we”, “us”, “our”) handles your personal information. Roova is an information and workflow platform for active Australian property investors. The service is operated by Cosmic Storage Solutions (sole trader Brendan Faulds) trading as Roova. [ABN to be inserted — placeholder pending registration.]

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle banking and financial data shared through the Consumer Data Right, we are also bound by the CDR privacy safeguards and the Competition and Consumer (Consumer Data Right) Rules. This policy describes what we collect, why, how we protect it, and the rights you have.

2. What personal information we collect

We collect only what we need to provide the service. That falls into four categories:

  • Account & contact details — your name, email address, mobile number (used for multi-factor authentication), organisation/entity details, and the password hash and MFA secrets that secure your login.
  • The portfolio and financial data you enter — properties, owner entities, loans, tenancies, maintenance jobs, expenses, documents, notes and any other records you add to run your portfolio. This is your data; you control what you put in.
  • Banking data accessed via the Consumer Data Right — where you choose to connect an account, we receive read-only access to account details, balances, transactions and loan data through an accredited CDR intermediary. We never receive your banking login credentials, and we have no ability to move money.
  • Usage & technical data — basic logs needed to run and secure the service: IP address, device/browser type, timestamps, the actions you take in the app, and audit records of security-relevant events.

3. How and why we use your information

We use your personal information to:

  • provide the core service — maintaining your portfolio register, allocating transactions, generating reports and surfacing the information you ask for;
  • authenticate you and protect your account, including enforcing multi-factor authentication;
  • operate, secure, debug and improve the platform;
  • communicate with you about your account, security matters and material changes to the service; and
  • meet our legal and record-keeping obligations.

Roova provides information and estimates to support your decisions — not financial, tax, legal or investment advice. We do not use your portfolio or banking data to train AI models, and your data is never pooled with another customer’s.

4. Consumer Data Right (CDR) data handling

Where you connect bank or loan accounts, that data is shared under Australia’s Consumer Data Right and handled to the CDR privacy safeguards:

  • Read-only. We can read account, transaction and loan information. We cannot initiate payments, transfers or any financial action.
  • Consent-based. We collect CDR data only with your express, time-limited consent, and only for the purposes you agree to.
  • Minimised. We request the narrowest set of data needed to deliver the feature you asked for, and retain it no longer than necessary.
  • Revocable. You can withdraw your consent at any time, from within Roova or via your bank. When consent ends we stop collecting new CDR data and de-identify or delete the data we hold in line with the CDR Rules.

CDR data is accessed through an accredited data recipient / intermediary. Their handling of your data is also governed by the CDR regime.

5. Who can see your data

Access to your data is tightly controlled. Only three categories of people can ever see it: you and the people you invite into your organisation, and authorised Roova staff acting for support and operations (described below). Nobody else.

Isolation from other customers

Each customer’s data is isolated from every other customer’s. That isolation is enforced at the database layer using PostgreSQL row-level security — not just in application code — so the database itself refuses to return rows that don’t belong to your organisation. If a query ever forgets to scope itself, it returns zero rows, never another customer’s data. We verify this with a hostile cross-tenant test suite that runs on every release, and a failing test blocks the release. The result is simple to state: no other customer can ever see your data.

Roova staff access (including “view as” / impersonation)

So that we can operate, support, troubleshoot and maintain the service, authorised Roova staff and administrators may access your account and the data within it. This includes a “view as” / impersonation capability that lets a support administrator see the product as you see it, in order to diagnose a problem you’ve reported or to assist you. By using Roova you consent to this access. We hold it to strict limits:

  • Authorised staff only. Access is restricted to specific authorised personnel under least-privilege controls — not available to everyone, and not to other customers.
  • Legitimate purposes only. It is used solely to operate, support, troubleshoot and maintain the service — never to browse your information out of curiosity, and never for marketing or sale.
  • Logged to an immutable audit trail. Staff access and impersonation are recorded to an append-only audit log — who accessed what, and when — that cannot be quietly altered or deleted.

6. Disclosure of your information

We never sell your personal information. We do not sell, rent or trade it to anyone, ever, and we do not use it for third-party advertising. We disclose your information only in the following limited circumstances:

  • Sub-processors needed to run the service. We share data with the providers required to operate Roova — for example, our Australian-region hosting, email and SMS delivery, error monitoring, and, if you connect banking, an accredited CDR intermediary. Each is bound by confidentiality and data-protection obligations and may use your data only on our instructions to provide the service.
  • Where we are legally compelled. We disclose data where required by a subpoena, court order, search warrant, or other binding legal or regulatory requirement. Where we are lawfully able to, we will tell you first.
  • To protect rights or safety. Where reasonably necessary to protect the rights, property or safety of you, us or others, or to investigate fraud or a security incident.
  • In a business transfer. If Roova is involved in a merger, acquisition or sale of assets, your data may transfer to the successor entity, subject to this Policy; we will give you notice and the protections described here will continue to apply.
  • At your direction. Where you ask us to — for example, generating an accountant pack that you choose to share.

Outside these circumstances, we do not disclose your personal information to anyone.

7. Data security

We take the protection of your data seriously and apply layered safeguards:

  • Encryption in transit and at rest across our services and databases.
  • Mandatory multi-factor authentication (MFA) on every account.
  • Database-level tenant isolation — each customer’s data is fenced off using PostgreSQL row-level security, enforced at the database, not just in application code. A query that forgets to scope returns zero rows, never another customer’s data.
  • Australian hosting and data residency — your data is stored in Australia.
  • Append-only audit logging of security-relevant and financial events — including any authorised-staff access or impersonation (see section 5).
  • Least-privilege access controls and regular backups.

No system can be guaranteed perfectly secure, but we design Roova so that the protection of your data does not depend on a single control.

8. Data retention

We keep personal information only for as long as we need it to provide the service, and to meet our legal obligations. Some records relevant to tax — for example, expense and income records that may be needed for the ATO — are retained for the periods required by Australian law. CDR data is retained and de-identified or deleted in line with the CDR Rules. When data is no longer required, we delete or de-identify it.

9. Your rights under the Privacy Act and the APPs

Under the Australian Privacy Principles you can:

  • Access the personal information we hold about you;
  • Correct information that is inaccurate, out of date or incomplete; and
  • Complain if you believe we have mishandled your personal information.

To make a request or complaint, contact us using the details below. We will acknowledge your complaint and aim to resolve it promptly. If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. CDR-related complaints can also be raised with the OAIC.

10. Cookies and analytics

We use a small number of cookies and similar technologies that are necessary to keep you logged in and to keep the service secure. Where we use analytics, we keep it privacy-respecting and use it only to understand and improve how the product is used — not to build advertising profiles.

11. Overseas disclosure

We host and store your data in Australia. Some of our service providers may operate or store limited operational data overseas. Where that occurs, we take reasonable steps to ensure those providers handle your information consistently with the Australian Privacy Principles. CDR data is handled within the bounds of the CDR regime.

12. Changes to this policy

We may update this policy as the product and the law evolve. When we make a material change we will update the “Last updated” date and, where appropriate, notify you. Your continued use of Roova after a change means you accept the updated policy.

13. How to contact us

For any privacy question, request or complaint, contact us:

[email protected]

We aim to acknowledge privacy enquiries within a few business days.

Last updated 27 June 2026.