Privacy Policy
Last updated: 18 August 2026
This policy explains how Handover HQ Pty Ltd handles personal information collected through this website. It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and it sets out the additional rights available to visitors in the European Economic Area and the United Kingdom.
1. Who we are
Handover HQ Pty Ltd (ABN 34 689 167 477) ("Handover HQ", "we", "us") is an Australian company registered in New South Wales. We build a workforce transition platform that helps organisations capture knowledge when an employee leaves, transfers or takes extended leave.
We are the data controller for the personal information described in this policy. You can reach our privacy contact at hello@handoverhq.ai.
2. What this policy covers
This policy covers the public Handover HQ website at handoverhq.ai, including the enquiry form.
It does not cover the Handover HQ application itself (app.handoverhq.ai) or our partner portal (partners.handoverhq.ai). When a customer organisation uses the application, that organisation is the controller of the employee information it puts into the platform and we act as its processor under a separate agreement. Those services have their own terms and privacy documentation.
3. What personal information we collect
Information you give us. When you submit the enquiry form we collect your full name, work email address, company name, job role, company size where you choose to provide it, and your indicated interest level (for example a product demo, design partner or enterprise pilot). If you email us, we collect whatever you include in that correspondence.
Information collected automatically. Our hosting provider records standard server logs when you visit, including your IP address, the pages requested, the date and time, your browser user agent and the referring page. These logs exist for security, abuse prevention and diagnosing faults.
Information we do not collect. We do not ask for and do not want payment card details, government identifiers, or sensitive information as that term is defined in the Privacy Act — including health, biometric, racial or ethnic origin, political, religious or sexual orientation information. Please do not send us any of this through the form.
4. Why we collect and use it
We use the personal information described above to:
- respond to your enquiry and follow up about Handover HQ;
- contact you about getting started with Handover HQ, onboarding and support;
- assess whether Handover HQ is a fit for your organisation and tailor what we send you;
- operate, secure and troubleshoot this website; and
- meet our legal and record-keeping obligations.
We do not sell your personal information, and we do not disclose it to third parties for their own marketing purposes.
5. The basis on which we handle your information
Australia. We collect personal information only where it is reasonably necessary for our business functions, consistent with APP 3, and we use and disclose it only for the purpose for which it was collected or a directly related purpose you would reasonably expect, consistent with APP 6.
European Economic Area and United Kingdom. Where the GDPR or UK GDPR applies, we rely on your consent for sending you marketing communications (Article 6(1)(a)), and on our legitimate interests in operating, securing and improving our website and responding to business enquiries (Article 6(1)(f)). Where we rely on consent you may withdraw it at any time, and doing so does not affect the lawfulness of anything we did beforehand.
6. Who we share it with
We do not sell your personal information. We do share it with the service providers we rely on to run this website and communicate with you. Each is bound to handle the information only on our instructions and to keep it secure.
| Provider | What it does | Where it processes data |
|---|---|---|
| Supabase | Database and serverless function that receive and store enquiries submitted through the website. This is where the information you type into the form is held. | Sydney, Australia (AWS ap-southeast-2) |
| Vercel | Hosting and content delivery for this website. Holds server access logs, including IP addresses. Does not hold form submissions. | United States, with content delivered from edge servers worldwide |
| Google Workspace | Our business email. Only holds correspondence if you choose to email us directly. | United States and other countries in Google's global network |
We may also disclose personal information where we are required or authorised to do so by law, to enforce our legal rights, or to a purchaser in connection with a sale or restructure of our business — in which case the information would remain subject to protections equivalent to this policy.
7. Overseas disclosure
The information you submit through the enquiry form is stored in Australia. Our database is hosted in Sydney (AWS ap-southeast-2), and the enquiry details you give us — your name, work email, company, role, company size and interest level — stay there.
Two categories of information are handled outside Australia. Our website host keeps server access logs, including your IP address, on infrastructure in the United States and delivers pages from edge servers around the world. And if you choose to email us rather than use the form, that correspondence sits in our business email, which operates across Google's global network.
Where personal information is handled overseas, we take steps that are reasonable in the circumstances, as required by APP 8, to ensure the recipient does not breach the Australian Privacy Principles. We select providers that publish enforceable data processing terms and appropriate security certifications, and we limit what each provider receives to what it needs. You should be aware that overseas recipients are subject to the laws of their own jurisdiction, which may differ from Australian privacy law, and that Australian courts and the Office of the Australian Information Commissioner may have limited practical ability to enforce against them. Where personal information is transferred out of the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses or the UK Addendum as applicable.
8. Cookies and similar technologies
This website does not use advertising or cross-site tracking cookies, and it does not load analytics or marketing scripts unless you accept them through the cookie banner.
We use browser localStorage to remember the choice you make in that banner, so we do not have to ask again on every visit. This is strictly necessary for the site to respect your preference and is stored only in your own browser. You can clear it at any time through your browser settings, which will cause the banner to reappear.
9. How we keep it secure
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, as required by APP 11. These steps include encryption in transit using HTTPS, encryption at rest with our database provider, access controls limiting the information to those in our team who need it, and providers selected for their security posture.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we suspect a data breach that is likely to result in serious harm, we will assess it and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where the GDPR applies we will notify the relevant supervisory authority within 72 hours where required.
10. How long we keep it
We keep enquiry information for as long as needed for the purpose it was collected, and in any case no longer than 24 months after your last interaction with us, unless you ask us to delete it sooner or we are required to keep it longer to meet a legal obligation or to establish or defend a legal claim.
Server logs are retained for a short period by our hosting provider for security and diagnostic purposes and are then discarded. If you become a customer, information relating to that relationship is retained under the terms of your customer agreement rather than this policy.
11. Your rights and choices
Wherever you are located, you may ask us to:
- Access the personal information we hold about you (APP 12);
- Correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13);
- Delete it, where we have no continuing lawful reason to keep it;
- Withdraw consent to marketing or launch communications; and
- Stop receiving email from us, either by using the unsubscribe link or by contacting us directly.
If the GDPR or UK GDPR applies to you, you additionally have the right to restrict or object to our processing, the right to data portability, and the right not to be subject to a decision based solely on automated processing. We do not carry out automated decision-making or profiling that produces legal or similarly significant effects.
To exercise any of these rights, email hello@handoverhq.ai. We will respond within 30 days, and within one month where the GDPR applies. We may need to verify your identity before acting on a request. There is no charge to make a request, and we will tell you in advance if a request is one of the rare cases where a reasonable cost applies.
12. Marketing communications
We send commercial electronic messages only where we have your consent or another basis permitted by the Spam Act 2003 (Cth). Every marketing email we send identifies us and contains a functional unsubscribe facility, and we action unsubscribe requests promptly. Unsubscribing from marketing does not stop operational messages that relate to a request you have made.
13. Anonymity and pseudonymity
You can browse this website without telling us who you are. Under APP 2 you may deal with us anonymously or under a pseudonym where it is lawful and practicable. It is not practicable for the enquiry form, because we need to be able to contact you and understand which organisation you represent.
14. Children
Handover HQ is a business product intended for use by organisations and their staff. This website is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has provided us with personal information, contact us and we will delete it.
15. Third-party links
This website may link to third-party sites we do not control. This policy does not apply to them, and we are not responsible for their privacy practices. We encourage you to read the privacy policy of any site you visit.
16. Changes to this policy
We may update this policy from time to time to reflect changes to our practices, our service providers or the law. The current version is always available at this address and is dated at the top. Where a change is significant, we will take reasonable steps to notify you — for example by email or a prominent notice on this website.
17. Contact us and how to complain
If you have a question about this policy, want to exercise a right, or wish to complain about how we have handled your personal information, contact us first at hello@handoverhq.ai. Please describe the issue and what outcome you are seeking.
We will acknowledge your complaint promptly and respond substantively within 30 days. If we need longer, we will tell you why and agree a timeframe with you.
If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner: online at oaic.gov.au, by phone on 1300 363 992, or by post to GPO Box 5218, Sydney NSW 2001.
If you are in the European Economic Area or the United Kingdom, you also have the right to lodge a complaint with your local supervisory authority, or with the UK Information Commissioner's Office at ico.org.uk.
