Privacy Policy

Last updated: 4 September 2026

This policy explains how Film Drop Pty Ltd (ABN 68 627 722 105) (“Klievo”, “we”, “us”), an Australian business operating the Klievo event-CRM platform and mobile apps (the “Service”), collects, uses, stores and discloses personal information. It is written to satisfy the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles, the EU and UK General Data Protection Regulation (“GDPR”), the New Zealand Privacy Act 2020, and applicable US state privacy laws, for users in those regions. Postal address: 255 Briens Road, Wentworthville NSW 2145, Australia. Contact us any time at support@klievo.com.

1. The two kinds of data we handle

a. Account data — we are the controller

When a business signs up we collect what is needed to run its workspace: name, email address, authentication details (or your Google, Apple or Microsoft sign-in identity), business profile details, subscription billing information (handled by Stripe — we never see or store full card numbers), notification preferences and push tokens, and support correspondence.

b. Customer Data — we are the processor

Businesses use Klievo to manage their own records, which include personal information about their clients, leads, and crew: names, contact details, event details, message threads, questionnaire and form responses, contracts and signatures, invoices, payment records, timesheets, shift and availability records. For this data the business is the controller (or “APP entity”) and Klievo processes it only on the business's instructions to provide the Service. A data processing agreement reflecting this policy is available on request at support@klievo.com.

c. If you are a client or crew member of a business that uses Klievo

You may interact with Klievo through a booking form, questionnaire, client portal, e-signing page or the crew app. The business you work with — not Klievo — decides what is collected there and why. To access, correct or delete that information, contact that business first; we assist it in fulfilling your request, and if you cannot reach it we will help directly at support@klievo.com. Two things worth knowing:

  • E-signing — when you sign a contract we record the signature, your name, and an audit trail (timestamp, IP address, device information) that makes the signature verifiable.
  • Email open tracking — emails a business sends through Klievo may include an open-tracking pixel that records when the email is opened (time, IP-derived approximate location, device type). If you prefer not to be tracked, disable remote-image loading in your email client, or ask the sender to turn tracking off.

2. What we collect automatically

  • Operational logs — IP address, browser type, requests and errors, used for security, rate limiting, abuse prevention and debugging.
  • Error telemetry (Sentry) — stack traces and request context when something breaks, so we can fix it. No session recording.
  • Product analytics (PostHog, EU-hosted) — feature usage events and, if enabled, session replay with keystrokes and form inputs masked — collected only after you accept the analytics consent banner. Decline (or ignore) the banner and nothing is collected. You can change your choice at any time in settings.

3. How we use personal information (purposes and legal bases)

  • to provide, secure and support the Service — performance of our contract with you;
  • to bill subscriptions and meet tax obligations — contract / legal obligation;
  • to send service, security and billing notices — legitimate interests (running the Service safely); these are not marketing;
  • to prevent fraud and abuse and enforce our terms — legitimate interests / legal obligation;
  • to improve the product through consent-gated analytics — consent, withdrawable at any time;
  • to comply with law and establish or defend legal claims — legal obligation / legitimate interests.

We do not sell personal information, we do not share it for cross-context behavioural advertising, and we do not use Customer Data or data obtained through connected accounts to train AI or machine-learning models.

4. Who we share data with (sub-processors)

We share personal information only with the service providers below, each bound by its own data-protection commitments, and only to the extent needed to run the feature involved. We will update this table before adding a provider that processes personal information.

ProviderPurposeLocation
SupabaseDatabase, authentication and file storageCloud infrastructure (region pinned per project)
VercelApplication hosting and content deliveryGlobal edge network
StripePayment processing — your Klievo subscription; and, separately, payments your clients make to you when you connect your own Stripe accountGlobal
GoogleEmail sending and calendar sync — only for workspaces that connect a Google account (see section 5)Global
MicrosoftEmail sending and calendar sync — only for workspaces that connect a Microsoft account (see section 5)Global
Meta PlatformsWhatsApp, Instagram and Facebook messaging — only for workspaces that connect those channelsGlobal
TwilioSMS messaging — only for workspaces that connect SMSGlobal
ResendTransactional platform emails from Klievo itself (e.g. account notices). Never used to send your business emailGlobal
Expo (EAS)Mobile push-notification delivery for the Klievo appGlobal
SentryError telemetry so we can find and fix crashes (errors only — no session recording)Cloud
PostHog (EU)Product analytics and (if enabled) masked session replay — only after you accept the analytics consent bannerEuropean Union
Cloudflare (Workers AI)User-invoked AI assistance using Cloudflare-hosted Gemma 4 26B A4B (model publisher: Google); see section 11Global edge network

Separately, when a workspace connects its own accounts (Google, Microsoft, Meta, Twilio, Stripe, Xero, QuickBooks, MYOB, Sage), data flows to and from those providers at that workspace's direction — they act for the workspace, not for Klievo. We may also disclose information where required by law, or to protect the rights, safety or property of Klievo, our users or the public.

5. Data received from Google and Microsoft APIs

This section applies only when a workspace explicitly connects a Google or Microsoft account, and describes everything Klievo does with data received through those APIs.

What we access, and why

  • Sign in with Google / Microsoft / Apple — your name, email address and profile identifier, used solely to create and secure your account.
  • Email sending (Gmail / Outlook) — permission to send email on your behalf, so messages to your clients come from your own address. We store the OAuth token (encrypted) and a copy of each message you send through Klievo in your workspace's message history.
  • Email inbox access — Klievo's current Google and Microsoft connection flows do not request permission to read, modify or label your inbox. A workspace that previously authorised the legacy Gmail inbox-sync scope may continue to sync client-matched message headers, text and HTML bodies, snippets and attachment-presence metadata into its message history until that connection is disconnected; attachment files are not downloaded. We do not request that legacy scope from new connections.
  • Google Calendar — Klievo requests permission to create, update and delete events only in the dedicated Google calendar it creates. If you enable Calendar Inbox, Google's read-only permission allows access to events across calendars available to your account. Klievo lists those calendars but requests event data only from the calendars you explicitly select and only within your configured sync window, to surface potential imports in your workspace. We store event identifiers so we can update or remove events we created.
  • Microsoft Outlook Calendar — Microsoft's Calendars.ReadWrite permission technically permits full read and write access across calendars available to your Microsoft account. Klievo limits its use to creating, updating and deleting events in the dedicated Outlook calendar it creates, and to requesting event data only from calendars you explicitly select for Calendar Inbox and only within your configured sync window.

Our commitments for this data

  • We use it only to provide the user-facing features described above — never for advertising, never to train AI or machine-learning models, and never for market research or profiling.
  • We do not transfer it to anyone except the sub-processors in section 4 (as needed to run the Service), as required by law, or as part of a merger or acquisition with prior notice to you.
  • No human at Klievo reads it, except with your explicit permission for a support request, where necessary for security or abuse investigation, or where required by law.
  • Disconnecting the integration in Settings revokes our access and deletes the stored tokens immediately. You can also revoke access from your Google Account or Microsoft Account settings, and request deletion of synced copies at support@klievo.com.

Klievo's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

6. Cookies

Klievo uses strictly-necessary cookies to keep you signed in, remember your active workspace and protect against cross-site request forgery; these are required for the Service to work and cannot be switched off. Optional analytics run only after you accept the in-product consent banner. We use no third-party advertising cookies and no cross-site tracking.

7. International transfers

Our providers operate global infrastructure, so personal information may be processed outside your country, including outside Australia, New Zealand, the EU and the UK. Where the GDPR or UK GDPR applies, transfers rely on adequacy decisions or standard contractual clauses (with the UK addendum) put in place with our providers; under APP 8 we take reasonable steps to ensure overseas recipients handle information consistently with the APPs. Product analytics is deliberately EU-hosted.

8. Retention and deletion

DataKept for
Account and workspace dataLife of the workspace, then deleted on request (see section 8)
Customer Data (your business records)Life of the workspace; you can delete records in-product at any time
Signed contracts and e-signature audit recordsLife of the workspace — signature validity depends on the audit trail; export before deleting
Google / Microsoft OAuth tokensUntil you disconnect the integration or delete the workspace — then revoked and deleted immediately
AI inputs and saved drafts or suggestionsCloudflare processes each request to return the result; Klievo stores saved suggestions and drafts in your workspace until you delete the related record or workspace
Apple sign-in revocation recordsEncrypted retry records are deleted after successful revocation, or within 40 days if provider or configuration failures require manual review
Operational and security logsUp to 90 days
Error telemetry (Sentry)Up to 90 days
Product analytics (PostHog)Up to 24 months, EU-hosted, consent-gated
Encrypted backupsDeleted records age out on a rolling schedule, typically within 30 days
Billing and tax recordsAs long as tax and accounting law requires (typically 7 years in Australia)

To delete a workspace or your account entirely, use the in-product option or email support@klievo.com. After any ownership or outstanding-pay blockers are resolved, deletion removes the active account and profile from production and starts revocation of connected sign-in identities. A short-lived, encrypted Apple token record may be retained only to retry or manually complete that revocation on the schedule above; residual copies expire from encrypted backups on the schedule above.

9. Security

All traffic is encrypted in transit (TLS) and data is encrypted at rest by our infrastructure providers. Every workspace's data is isolated at the database layer with row-level security. Passwords are checked against known-breach lists at signup, OAuth tokens and credentials are stored encrypted and never exposed to the browser, and we apply security headers, rate limiting, webhook signature verification and audit logging across the platform. Klievo staff can access a workspace only through an authenticated, logged support-access mechanism, and only to resolve a support request or investigate abuse. No system is perfectly secure — if we become aware of a data breach likely to result in serious harm, we will notify affected users and the relevant regulator without undue delay (including under the Australian Notifiable Data Breaches scheme and GDPR Articles 33–34).

10. Your rights

Depending on where you live, you may have the right to access, correct, export, restrict, object to the processing of, or delete your personal information, and to withdraw consent (for example, analytics consent) at any time. Businesses can export their core records (clients, jobs, invoices) directly from the Service. To exercise any right, email support@klievo.com — we verify the request and respond within 30 days. We never discriminate against you for exercising a privacy right.

  • Australia — you may complain to us first, and then to the OAIC at oaic.gov.au.
  • EU / UK — you may lodge a complaint with your data-protection authority (in the UK, the ICO).
  • United States — residents of states with privacy laws (including California) have rights to know, access, correct, delete and port. We do not sell personal information and do not share it for cross-context behavioural advertising, and have not done so in the preceding 12 months.

11. AI features

Klievo uses Cloudflare Workers AI to run the Cloudflare-hosted Gemma 4 26B A4B model (@cf/google/gemma-4-26b-a4b-it, published by Google). The model runs on Cloudflare's infrastructure; we do not send data to Google's hosted AI services and do not use an AI aggregator or model gateway for these features.

What is sent

  • Lead analysis and quote drafting may send the relevant lead message or notes, extracted event details, job and client context, and the workspace's quote-item catalogue. Lead notes can include text that arrived through an email-forwarding address.
  • Quote-email drafting may send the client and business names, quote totals and terms, and relevant line-item names, descriptions and prices.
  • Reply drafting sends the message subject, client and job context, and the instruction you type. It does not send the incoming email body.

Your control

No lead, message, quote or connected-account data is sent to Workers AI merely because you open a page. Processing begins only after you choose a clearly labelled AI action beside an in-product disclosure. Lead suggestions require a separate Apply action. A quote-drafting action creates an editable draft quote in your workspace, but it is not issued or sent without your review. Klievo does not send a message, confirm a booking or allocate crew from an AI result without your review. Google Calendar event data is not sent to Workers AI. If the limited subject or context used by a user-invoked reply feature originated from a connected Google account, it is processed only to provide that visible feature and only after you choose the AI action.

Training, storage and retention

Neither Klievo nor Cloudflare uses your Customer Data or connected-account data to train or improve generalised AI models. Every model request sets store: false, and these features do not use Cloudflare R2, KV, Durable Objects, Vectorize or AI Gateway payload logging to store prompts or responses. Cloudflare processes the request to return the output. If you save or use the result, Klievo stores the relevant suggestion or draft in your own workspace under the retention rules in section 8. The original lead, job, quote or message data remains subject to its normal workspace retention period.

12. Automated decision-making

Klievo makes no automated decisions about you that produce legal or similarly significant effects.

13. Children

The Service is for businesses and is not directed at children under 16. We do not knowingly collect personal information from children as account holders.

14. Changes to this policy

We may update this policy from time to time. For material changes we will give notice by email or in-product notice before the change takes effect. The “Last updated” date at the top reflects the current version.

15. Contact

Privacy questions, requests and complaints: support@klievo.com, or by post to 255 Briens Road, Wentworthville NSW 2145, Australia. Our data processing agreement for business customers is available on request.