Privacy Policy
1. Introduction
This Privacy Policy ("Policy") describes how Octavvio Pty Ltd (ABN 65 698 936 659, "Octavvio", "we", "us", or "our") collects, uses, discloses, and protects personal information in connection with the Octavvio platform (the "Service").
This Policy is incorporated into, and forms part of, Octavvio's Terms of Service. Where the Terms of Service refer to retention periods, sub-processors, data subject rights, or breach notification, this Policy is the authoritative source. Two related instruments are referenced throughout: the Executive Consent Addendum (defined and required under Terms of Service Section 8.3, executed personally by each Executive) and the Data Processing Agreement ("DPA", referenced in Terms of Service Section 17, available on request).
Because the Service involves cloning a person's voice and generating a photorealistic video likeness, some of the information we process is biometric or "special category" personal information under applicable law. Section 9 sets out how we handle this category specifically, including the consent model that governs it.
2. Scope and Applicable Law
We primarily operate in Australia, New Zealand, and Singapore, and this Policy is drafted to meet the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the New Zealand Privacy Act 2020 (including the Biometric Processing Privacy Code 2025), and Singapore's Personal Data Protection Act 2012 (PDPA).
Where the Service is offered to Customers in other jurisdictions, this Policy is also intended to meet the EU/UK General Data Protection Regulation (GDPR), India's Digital Personal Data Protection Act 2023, and applicable US state privacy and biometric laws (see Section 17).
3. Controller and Processor Roles
For account, billing, and website data, Octavvio acts as controller (or APP entity, under Australian terminology) — we determine the purposes and means of processing this information.
For Biometric Data and Customer Content submitted to generate a Video, Octavvio acts as a processor on the Customer's instructions, save for the direct consent relationship Octavvio holds with each Executive described in Section 9. Where an Executive exercises a right directly against Octavvio (for example, withdrawing consent under Section 9), Octavvio handles that request even though the Customer is otherwise the controller of the underlying Brief.
4. Information We Collect
We collect the following categories of information:
- chevron_rightAccount information: name, business email address, company name, and role, provided at sign-up.
- chevron_rightBilling information: billing address and payment details, processed by our payment processing provider (we do not store full card numbers).
- chevron_rightCustomer Content: Briefs, scripts, reference voice recordings, images, and other materials submitted to generate a Video.
- chevron_rightBiometric Data: voiceprints, Voice Clones, facial geometry, and Avatar/Digital Twin models created from reference recordings (see Section 9).
- chevron_rightUsage data: log data, device and browser information, and platform interaction data collected automatically when you use the Service.
- chevron_rightCommunications: correspondence with our support team and responses to surveys or feedback requests.
5. How We Use Your Information
We use personal information to:
- chevron_rightProvide, operate, and maintain the Service, including generating Videos from Briefs;
- chevron_rightProcess payments and manage your Subscription Plan;
- chevron_rightCommunicate with you about your account, billing, and service updates;
- chevron_rightMaintain the security and integrity of the Service, including detecting fraud and abuse;
- chevron_rightComply with our legal obligations, including tax, corporate, and data protection law;
- chevron_rightWith separate, freestanding consent only, improve or train AI models (see Section 9.1 of the Terms of Service for the opt-in/opt-out distinction between non-biometric and biometric content).
6. Anonymity and Pseudonymity
Consistent with Australian Privacy Principle 2, where it is lawful and practicable to do so, you may interact with us anonymously or under a pseudonym — for example, when making a general enquiry that does not require us to verify your identity or provide the Service to you.
It is not practicable to offer this option for core account and billing functions, or for the biometric consent process described in Section 9, because the Service cannot be provided, and the Executive's identity cannot be verified for consent purposes, without identifying information.
7. Unsolicited Personal Information
If we receive personal information that we did not solicit — for example, information included in an email or attachment we did not request — we will assess within a reasonable period whether we could have lawfully collected it under Section 4. If we could not have, and the information is not contained in a Commonwealth record, we will destroy or de-identify it as soon as practicable, consistent with Australian Privacy Principle 4.
8. Automated Decision-Making
The Service uses automated systems, including large language models and rendering pipelines, to generate Video scripts, captions, and visual output from your Brief. These systems do not make decisions with legal or similarly significant effects on individuals — they produce draft creative content that the Customer reviews before distribution (see Terms of Service Section 18, AI-Generated Content Disclaimer).
Ahead of the Australian Privacy Principle 1.7 commencement on 10 December 2026, which will require entities to disclose in their privacy policy whether personal information is used in substantially automated decisions with a legal or similarly significant effect, we confirm that Octavvio does not currently use personal information in this way. We will update this section if that changes.
9. Biometric Information and Consent
Creating a Voice Clone or Avatar involves processing an Executive's voice recording and/or image. This data is used to generate synthetic voice/video likeness of the Executive, and may constitute biometric or "special category" personal information under the GDPR, the Australian Privacy Act 1988, the New Zealand Privacy Act 2020 and Biometric Processing Privacy Code 2025, Illinois BIPA, and comparable laws in other markets where the Service is offered.
9.1 Consent model
Before any reference recording is submitted, the Customer must obtain the Executive's informed consent, and each Executive must personally execute an Octavvio Executive Consent Addendum, as described in Terms of Service Section 8. Octavvio does not create a Voice Clone or Avatar without both the Customer's warranty and the Executive's own signed Addendum.
9.2 Withdrawal
An Executive may withdraw consent at any time by contacting privacy@octavvio.com directly. On receipt of a valid withdrawal, we will disable the affected Voice Clone and Avatar and delete the underlying reference recording within the timeframes set out in Section 14.
9.3 No model training without separate consent
We do not use Biometric Data to train general-purpose or product AI models unless the Executive has given separate, freestanding consent for that specific purpose, distinct from and in addition to the consent given for Video generation.
11. Cross-Border Disclosure
Because our providers are located in the countries listed in Section 10, personal information, including Biometric Data, is disclosed overseas. Before making such a disclosure, we take reasonable steps to ensure the overseas recipient does not breach the APPs in relation to that information, consistent with Australian Privacy Principle 8, including through contractual data-processing terms with each provider.
12. Data Security
We apply technical and organisational security measures appropriate to the sensitivity of the data we process, including encryption in transit and at rest, role-based access controls and row-level security on our database, staff vetting and confidentiality obligations, and contractual security obligations imposed on every provider, consistent with Australian Privacy Principle 11.
13. Data Breach Notification
If we experience a data breach that is likely to result in serious harm to an individual, we will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988. Where the GDPR or UK GDPR applies, we will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, consistent with GDPR Article 33, and affected individuals where required by Article 34.
A breach notice will describe, to the extent known: what happened, the categories of information involved, the likely consequences, and the steps we are taking and recommend you take in response.
14. Data Retention and Deletion
We retain personal information only for as long as necessary for the purposes described in this Policy, or as required by law:
- chevron_rightRaw reference voice/image recordings: deleted within 14 days of successful Voice Clone/Avatar creation.
- chevron_rightVoice Clones and Avatars: retained while the Executive's consent remains active, and deleted within 30 days of a valid withdrawal under Section 9.2.
- chevron_rightCustomer Content and generated Videos: retained for the life of the account, plus a 30-day export window after account closure (see Terms of Service Section 14).
- chevron_rightAccount and billing records: retained for at least 7 years after account closure, to meet Australian tax and corporate record-keeping obligations.
- chevron_rightUsage and log data: retained for up to 12 months for security and troubleshooting purposes.
15. Data Quality
Consistent with Australian Privacy Principle 10, we take reasonable steps to ensure the personal information we collect, use, and disclose is accurate, up to date, and complete, having regard to the purpose of the use or disclosure. You can help us do this by keeping your account information current and by promptly notifying us of any inaccuracy via privacy@octavvio.com.
16. Your Rights — Access, Correction and Deletion
A Customer or Executive may request access to, correction of, or deletion of their personal information, including a Voice Clone or Avatar, by contacting our Privacy Officer at privacy@octavvio.com. We will respond within 30 days, consistent with Australian Privacy Principles 12 and 13.
Depending on your location, you may also have rights under other applicable law — for example, the right to data portability and the right to object to processing under the GDPR, or the right to correction under the New Zealand Privacy Act 2020 and Singapore's PDPA. We will handle a request under the framework most favourable to you where more than one applies.
17. US State Biometric Law
Where an Executive is located in, or the Service is used to process biometric data of an individual located in, Illinois, Texas, or Washington, Octavvio: does not sell, lease, trade, or otherwise profit from biometric identifiers or biometric information; applies the retention and destruction schedule in Section 14; and collects a written release before capturing a biometric identifier, satisfied by the Executive Consent Addendum described in Section 9.1. This is intended to meet the Illinois Biometric Information Privacy Act (BIPA), the Texas Capture or Use of Biometric Identifier Act (CUBI), and Washington's biometric privacy law (RCW 19.375).
Octavvio™ · Privacy Policy · 0.6