Legal
Cookie PreferencesPrivacy Policy
Effective date: 21 July 2026 ยท Last updated: 21 July 2026
1. About this Privacy Policy
This Privacy Policy explains how Robina Research Pty Ltd (ABN 93 698 569 407) ("Robina Research", "Loviva", "we", "us" or "our"), the operator of the Loviva wellbeing-navigation service (the "Service"), collects, holds, uses, discloses and protects personal information.
This Policy applies to the Loviva websites, applications, interfaces, features and related services.
We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), the Notifiable Data Breaches scheme, and other applicable Australian privacy laws.
This Policy should be read together with our Terms and Conditions.
2. Key privacy principles that apply to Loviva
We aim to:
- collect only the information reasonably necessary for the Service;
- be transparent about what we collect and why;
- protect information with appropriate technical, organisational and access controls;
- treat health, mental-health, safety-related and other sensitive information with heightened care;
- seek consent before collecting sensitive information;
- avoid using personal information for unrelated purposes without a lawful basis;
- provide meaningful control over your information;
- support your rights under the Privacy Act 1988 (Cth);
- manage overseas processing responsibly; and
- notify you and the Office of the Australian Information Commissioner (OAIC) if a notifiable data breach occurs.
3. What information we collect
We collect only information that is reasonably necessary for the Service.
3.1 Information you provide directly
- account details (such as name, email address, and authentication identifiers);
- profile preferences;
- guided navigation choices (selections you make during the Service experience);
- text and voice input;
- location preferences (such as postcode, suburb or chosen radius);
- feedback, ratings, saved items and support requests;
- pilot or research inputs, where you participate in an approved pilot; and
- communications with Loviva.
3.2 Information collected automatically
- device and browser information;
- session identifiers and analytics events;
- diagnostic and performance data;
- approximate location derived from network signals;
- IP address (used for security, fraud prevention and approximate location);
- referral and page-view information; and
- cookies and similar technologies (see section 12).
3.3 Information from third parties
If you sign in through an identity provider (such as Google), we may receive verification details permitted by that provider (such as your name, email and a stable identifier).
We do not receive your third-party password.
For approved pilots or partnerships, we may receive information provided by an authorised partner where you have consented or the partnership permits it.
3.4 Sensitive information
Some information you enter could be considered sensitive information under the Privacy Act, including information about health, mental-health preferences, or safety concerns.
We take the following measures:
- we only collect sensitive information where reasonably necessary for the Service;
- we ask for consent through your use of features that involve sensitive input;
- we treat sensitive information with heightened care;
- we minimise storage;
- we restrict internal access;
- we apply additional controls to voice and free-text input; and
- we do not use sensitive information for advertising.
You should avoid submitting more sensitive information than needed to receive help.
4. Voice input
If you enable voice input, your device records audio and sends it to Loviva or a contracted speech-processing provider for transcription.
We may:
- temporarily store audio for the time reasonably needed to complete transcription and provide the Service;
- retain the transcript;
- use the transcript to generate results;
- use aggregated, de-identified information to improve accuracy and safety; and
- delete audio once it is no longer required.
Where a contracted provider processes audio, we require appropriate contractual and security protections.
Voice input may capture voices of other people. You are responsible for ensuring you have any required permissions.
5. How we use information
We use information to:
- operate and provide the Service;
- authenticate users and secure accounts;
- generate navigation results, clarifications and matches;
- personalise the experience within the intended scope of the Service;
- operate approved pilots and evaluations;
- measure Service performance;
- improve quality, safety and reliability;
- maintain and improve the verified resource catalogue;
- prevent, detect and investigate misuse, fraud or security issues;
- communicate with you about your use of the Service;
- comply with legal obligations; and
- protect the rights, property or safety of Loviva, users or the public.
6. How AI is used with your information
Loviva uses AI to help interpret intent, produce clarification choices, generate short supportive text, and rank approved catalogue resources.
AI processing occurs within the Service's controlled workflow. AI is not permitted to:
- diagnose users;
- prescribe treatment;
- invent third-party services or contact details;
- make final catalogue decisions; or
- make clinical decisions.
Where an AI processing provider is used, appropriate contractual and security protections are applied.
Where the Service uses AI to make a decision that materially affects you, you may request human review under section 11.
7. Automated processing
The Service uses automated processing to:
- generate navigation options;
- surface potentially relevant resources;
- rank the order of results; and
- detect security or safety risks.
Automated processing is not used to:
- determine eligibility for health services;
- form clinical conclusions; or
- make legally significant decisions about a user.
You may request human review, correction of information used, or an explanation of how a result was generated, in line with section 11.
8. When we disclose information
We may disclose personal information to:
8.1 Service providers acting for us
We use trusted providers to help operate the Service, such as cloud hosting, authentication, database, AI processing, speech-to-text, analytics, customer communication, security and infrastructure providers.
These providers may only process information for the purposes we authorise and under appropriate contractual protections.
8.2 Pilot and research partners (where you participate)
Where you participate in an approved pilot or research activity, we may share specified information with the pilot partner, in accordance with the pilot terms and any required consent.
Wherever practical, information will be de-identified or aggregated before sharing.
8.3 Legal, safety and regulatory disclosures
We may disclose information where reasonably necessary to:
- comply with law, court order or lawful government request;
- protect the rights, property or safety of Loviva, users or the public;
- respond to a suspected serious threat to life, health or safety;
- cooperate with authorised investigations; or
- enforce our Terms.
8.4 Corporate transactions
In a genuine corporate restructure, financing, merger, acquisition or transfer of the Service, information may be transferred subject to appropriate confidentiality and privacy protections.
8.5 What we do NOT do
- we do not sell personal information;
- we do not use sensitive information for advertising;
- we do not share individually identifiable Loviva session content with third-party providers for their own marketing; and
- we do not create profiles about you for third-party marketing use.
9. Overseas processing
Some providers we rely on may process personal information outside Australia, including in the United States, the European Union or the United Kingdom.
Where personal information is processed overseas, we:
- select providers that we consider suitable;
- use contractual protections consistent with the Privacy Act;
- restrict use to authorised purposes; and
- apply reasonable security controls.
If you would like a current list of countries where key providers process information, contact us using the details in section 15.
10. Security
We use reasonable technical, organisational and administrative safeguards, including:
- encryption in transit;
- encryption at rest for stored information;
- role-based access controls;
- principle of least privilege;
- activity logging;
- audit trails for sensitive administrative actions;
- protections against unauthorised access, misuse or interference;
- secure development processes;
- credential and secret protection;
- vendor due-diligence and contractual protections; and
- incident-response processes.
No system is completely secure, but we take reasonable steps consistent with the sensitivity of the information.
If we become aware of a notifiable data breach involving your personal information, we will comply with the Notifiable Data Breaches scheme.
11. Your privacy rights
Consistent with the Privacy Act 1988 (Cth), you may:
- request access to the personal information we hold about you;
- request correction of information that is inaccurate, incomplete or outdated;
- withdraw a previously given consent for future processing (where consent is the basis for processing);
- request deletion of personal information, subject to legal retention and dispute-resolution needs;
- request human review of a decision that materially affects you where automated processing was involved;
- make a privacy complaint;
- opt out of marketing communications; and
- adjust device permissions such as microphone and location.
To exercise these rights, contact us using the details in section 15.
We may need to verify your identity before responding.
Some information may be retained where required for legal, security, backup, audit, safety, dispute-resolution or fraud-prevention purposes.
12. Cookies and similar technologies
We use cookies and similar technologies to:
- maintain sign-in sessions;
- remember preferences;
- measure Service performance and usage patterns;
- protect against abuse; and
- support essential functions.
You can manage cookies through your browser or device settings. Blocking certain cookies may reduce Service functionality.
13. Retention
We keep personal information for as long as reasonably needed to:
- operate the Service;
- maintain account continuity;
- meet legal, tax and record-keeping obligations;
- protect against fraud and misuse;
- resolve disputes;
- support security investigations; and
- carry out authorised research or evaluation activities.
Voice audio is deleted once transcription is complete, unless a specific, disclosed reason justifies limited additional retention.
When information is no longer required, we delete or de-identify it.
14. Children
The Service is not directed to children under 18 unless we have expressly made a specific service or pilot available to younger users with the required parent, guardian, organisational and legal permissions.
If we become aware that we have collected personal information from a child in breach of applicable law or these terms, we will take reasonable steps to delete it.
15. Contact and complaints
Robina Research Pty Ltd
Operator of Loviva
ABN 93 698 569 407
Suite 6001
19 Robina Town Centre Drive
Robina QLD 4226
Australia
Email: anton@robinaresearch.com
Website: https://loviva.ai
If you have a privacy concern, please contact us first. We will acknowledge the request within a reasonable period and aim to resolve it promptly.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC):
Office of the Australian Information Commissioner
Website: https://www.oaic.gov.au
16. Changes to this Privacy Policy
We may update this Privacy Policy to reflect:
- changes to the Service;
- changes to the law or regulatory guidance;
- changes to our providers;
- security or safety improvements; or
- operational changes.
We will publish updates with a revised effective date.
Where a change materially affects your rights or the way we handle your information, we will provide reasonable notice through the Service, email or another appropriate method.
Continued use of the Service after an update indicates that you understand the current Privacy Policy.
