Privacy Policy
Last updated: 3 August 2026
This policy explains how Film Drop Pty Ltd (ABN 68 627 722 105) (“Klievo”, “we”, “us”), an Australian business operating the Klievo event-CRM platform and mobile apps (the “Service”), collects, uses, stores and discloses personal information. It is written to satisfy the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU and UK General Data Protection Regulation (“GDPR”), the New Zealand Privacy Act 2020, and applicable US state privacy laws, for users in those regions. Postal address: 255 Briens Road, Wentworthville NSW 2145, Australia. Contact us any time at support@klievo.com.
1. The two kinds of data we handle
a. Account data — we are the controller
When a business signs up we collect what is needed to run its workspace: name, email address, authentication details (or your Google, Apple or Microsoft sign-in identity), business profile details, subscription billing information (handled by Stripe — we never see or store full card numbers), notification preferences and push tokens, and support correspondence.
b. Customer Data — we are the processor
Businesses use Klievo to manage their own records, which include personal information about their clients, leads, and crew: names, contact details, event details, message threads, questionnaire and form responses, contracts and signatures, invoices, payment records, timesheets, shift and availability records. For this data the business is the controller (or “APP entity”) and Klievo processes it only on the business's instructions to provide the Service. A data processing agreement reflecting this policy is available on request at support@klievo.com.
c. If you are a client or crew member of a business that uses Klievo
You may interact with Klievo through a booking form, questionnaire, client portal, e-signing page or the crew app. The business you work with — not Klievo — decides what is collected there and why. To access, correct or delete that information, contact that business first; we assist it in fulfilling your request, and if you cannot reach it we will help directly at support@klievo.com. Two things worth knowing:
- E-signing — when you sign a contract we record the signature, your name, and an audit trail (timestamp, IP address, device information) that makes the signature verifiable.
- Email open tracking — emails a business sends through Klievo may include an open-tracking pixel that records when the email is opened (time, IP-derived approximate location, device type). If you prefer not to be tracked, disable remote-image loading in your email client, or ask the sender to turn tracking off.
2. What we collect automatically
- Operational logs — IP address, browser type, requests and errors, used for security, rate limiting, abuse prevention and debugging.
- Error telemetry (Sentry) — stack traces and request context when something breaks, so we can fix it. No session recording.
- Product analytics (PostHog, EU-hosted) — feature usage events and, if enabled, session replay with keystrokes and form inputs masked — collected only after you accept the analytics consent banner. Decline (or ignore) the banner and nothing is collected. You can change your choice at any time in settings.
3. How we use personal information (purposes and legal bases)
- to provide, secure and support the Service — performance of our contract with you;
- to bill subscriptions and meet tax obligations — contract / legal obligation;
- to send service, security and billing notices — legitimate interests (running the Service safely); these are not marketing;
- to prevent fraud and abuse and enforce our terms — legitimate interests / legal obligation;
- to improve the product through consent-gated analytics — consent, withdrawable at any time;
- to comply with law and establish or defend legal claims — legal obligation / legitimate interests.
We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use Customer Data or data obtained through connected accounts to train AI or machine-learning models.
4. Who we share data with (sub-processors)
We share personal information only with the service providers below, each bound by its own data-protection commitments, and only to the extent needed to run the feature involved. We will update this table before adding a provider that processes personal information.
| Provider | Purpose | Location |
|---|---|---|
| Supabase | Database, authentication and file storage | Cloud infrastructure (region pinned per project) |
| Vercel | Application hosting and content delivery | Global edge network |
| Stripe | Payment processing — your Klievo subscription; and, separately, payments your clients make to you when you connect your own Stripe account | Global |
| Email sending and calendar sync — only for workspaces that connect a Google account (see section 5) | Global | |
| Microsoft | Email sending and calendar sync — only for workspaces that connect a Microsoft account (see section 5) | Global |
| Meta Platforms | WhatsApp, Instagram and Facebook messaging — only for workspaces that connect those channels | Global |
| Twilio | SMS messaging — only for workspaces that connect SMS | Global |
| Resend | Transactional platform emails from Klievo itself (e.g. account notices). Never used to send your business email | Global |
| Expo (EAS) | Mobile push-notification delivery for the Klievo app | Global |
| Sentry | Error telemetry so we can find and fix crashes (errors only — no session recording) | Cloud |
| PostHog (EU) | Product analytics and (if enabled) masked session replay — only after you accept the analytics consent banner | European Union |
| Cloudflare (Workers AI) | AI-assisted drafting features (e.g. suggested replies) — processes only the text needed for the suggestion; see section 12 | Global edge network |
Separately, when a workspace connects its own accounts (Google, Microsoft, Meta, Twilio, Stripe, Xero, QuickBooks, MYOB, Sage), data flows to and from those providers at that workspace's direction — they act for the workspace, not for Klievo. We may also disclose information where required by law, or to protect the rights, safety or property of Klievo, our users or the public.
5. Data received from Google and Microsoft APIs
This section applies only when a workspace explicitly connects a Google or Microsoft account, and describes everything Klievo does with data received through those APIs.
What we access, and why
- Sign in with Google / Microsoft / Apple — your name, email address and profile identifier, used solely to create and secure your account.
- Email sending (Gmail / Outlook) — permission to send email on your behalf, so messages to your clients come from your own address. We store the OAuth token (encrypted) and a copy of each message you send through Klievo in your workspace's message history.
- Email reading (Gmail / Outlook) — if and when the two-way inbox feature is enabled for your workspace, permission to read and label messages in the connected mailbox, used solely to display client conversation threads inside your workspace and mark them read. We sync only the threads involving your workspace's clients.
- Calendar (Google Calendar / Outlook) — permission to create, update and delete the events Klievo pushes to your calendar. We store event identifiers so we can update or remove events we created.
Our commitments for this data
- We use it only to provide the user-facing features described above — never for advertising, never to train AI or machine-learning models, and never for market research or profiling.
- We do not transfer it to anyone except the sub-processors in section 4 (as needed to run the Service), as required by law, or as part of a merger or acquisition with prior notice to you.
- No human at Klievo reads it, except with your explicit permission for a support request, where necessary for security or abuse investigation, or where required by law.
- Disconnecting the integration in Settings revokes our access and deletes the stored tokens immediately. You can also revoke access from your Google Account or Microsoft Account settings, and request deletion of synced copies at support@klievo.com.
Klievo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
6. Cookies
Klievo uses strictly-necessary cookies to keep you signed in, remember your active workspace and protect against cross-site request forgery; these are required for the Service to work and cannot be switched off. Optional analytics run only after you accept the in-product consent banner. We use no third-party advertising cookies and no cross-site tracking.
7. International transfers
Our providers operate global infrastructure, so personal information may be processed outside your country, including outside Australia, New Zealand, the EU and the UK. Where the GDPR or UK GDPR applies, transfers rely on adequacy decisions or standard contractual clauses (with the UK addendum) put in place with our providers; under APP 8 we take reasonable steps to ensure overseas recipients handle information consistently with the APPs. Product analytics is deliberately EU-hosted.
8. Retention and deletion
| Data | Kept for |
|---|---|
| Account and workspace data | Life of the workspace, then deleted on request (see section 8) |
| Customer Data (your business records) | Life of the workspace; you can delete records in-product at any time |
| Signed contracts and e-signature audit records | Life of the workspace — signature validity depends on the audit trail; export before deleting |
| Google / Microsoft OAuth tokens | Until you disconnect the integration or delete the workspace — then revoked and deleted immediately |
| Operational and security logs | Up to 90 days |
| Error telemetry (Sentry) | Up to 90 days |
| Product analytics (PostHog) | Up to 24 months, EU-hosted, consent-gated |
| Encrypted backups | Deleted records age out on a rolling schedule, typically within 30 days |
| Billing and tax records | As long as tax and accounting law requires (typically 7 years in Australia) |
To delete a workspace or your account entirely, use the in-product option or email support@klievo.com. Deletion removes records from the production database immediately and connected sign-in identities are revoked (including Apple token revocation); residual copies expire from encrypted backups on the schedule above.
9. Security
All traffic is encrypted in transit (TLS) and data is encrypted at rest by our infrastructure providers. Every workspace's data is isolated at the database layer with row-level security. Passwords are checked against known-breach lists at signup, OAuth tokens and credentials are stored encrypted and never exposed to the browser, and we apply security headers, rate limiting, webhook signature verification and audit logging across the platform. Klievo staff can access a workspace only through an authenticated, logged support-access mechanism, and only to resolve a support request or investigate abuse. No system is perfectly secure — if we become aware of a data breach likely to result in serious harm, we will notify affected users and the relevant regulator without undue delay (including under the Australian Notifiable Data Breaches scheme and GDPR Articles 33–34).
10. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, and to withdraw consent (for example, analytics consent) at any time. Businesses can export their core records (clients, jobs, invoices) directly from the Service. To exercise any right, email support@klievo.com — we verify the request and respond within 30 days. We never discriminate against you for exercising a privacy right.
- Australia — you may complain to us first, and then to the OAIC at oaic.gov.au.
- EU / UK — you may lodge a complaint with your data-protection authority (in the UK, the ICO).
- United States — residents of states with privacy laws (including California) have rights to know, access, correct, delete and port. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months.
11. AI features
Some features use AI to draft suggestions (for example, a suggested reply to a client message). Only the text needed for the suggestion is sent to the AI provider (Cloudflare Workers AI), the output is shown to you for review before anything is sent, and neither we nor the provider use your data to train models. AI features never take actions on your behalf automatically.
12. Automated decision-making
Klievo makes no automated decisions about you that produce legal or similarly significant effects.
13. Children
The Service is for businesses and is not directed at children under 16. We do not knowingly collect personal information from children as account holders.
14. Changes to this policy
We may update this policy from time to time. For material changes we will give notice by email or in-product notice before the change takes effect. The “Last updated” date at the top reflects the current version.
15. Contact
Privacy questions, requests and complaints: support@klievo.com, or by post to 255 Briens Road, Wentworthville NSW 2145, Australia. Our data processing agreement for business customers is available on request.