Mobile app coming soon

DVA HELPER​
Privacy Policy
DVA Helper Pty Ltd
Last updated: 14 February 2026

Your privacy is important to us. This policy explains how we handle your information.

Introduction

Digital Virtual Assistant Pty Ltd T/A DVA Helper (ABN 45 694 916 464) (“we”, “us”, or “our”) is committed to protecting the privacy of Australian veterans who use our services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services. 

We comply with the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles (“APPs”), as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth). As a provider of services involving the collection and handling of health information, we are an APP entity for the purposes of the Privacy Act, regardless of our annual turnover, and we are subject to the full suite of APP obligations including the Notifiable Data Breaches scheme. 

We also comply with the Australian Consumer Law as set out in Schedule 2 of the Competition and Consumer Act 2010 (Cth), and the Cyber Security Act 2024 (Cth), to the extent applicable to our operations. 

Information We Collect

We collect information that you provide directly to us. This includes personal identification information (such as your name, email address, and phone number), service history and military records, medical information and health records relevant to your DVA claim, documents you upload to support your claim, communications with our service, and payment information (when applicable). 

We also collect technical information automatically when you use our platform, including your IP address, browser type, device information, and usage data (pages visited, time spent, features used). This information is collected through essential cookies and server logs. 

We will only collect personal information that is reasonably necessary for, or directly related to, our functions and activities of assisting you with your DVA claim (APP 3). We do not collect personal information unless it is necessary for the purpose of providing our services to you. 

Sensitive Information and Health Information

We understand that your medical records and health information are particularly sensitive. Under the Privacy Act, health information is classified as “sensitive information” and attracts additional privacy protections. 

We collect health information with your express consent, which you provide when you upload medical records or enter health-related information into our platform. We only collect health information that is reasonably necessary for preparing your DVA claim. 

Your medical records are processed using secure, AI-powered document analysis to identify relevant information for your claim. This processing occurs within Australian infrastructure. We handle all health information in accordance with the Privacy Act 1988 (Cth) and its provisions for sensitive information, the My Health Records Act 2012 (Cth) requirements (where applicable), and applicable state and territory health records legislation. 

You may withdraw your consent for us to collect or process your health information at any time by contacting us. However, withdrawing consent may affect our ability to provide our services to you.

How We Use Your Information

We use the information we collect for the following primary purposes: to provide, maintain, and improve our DVA claims assistance services; to process your intake information and prepare claim documentation; to analyse your medical records to identify relevant conditions and evidence; to match your conditions with applicable Statements of Principles (SOPs) under the Military Rehabilitation and Compensation Act 2004 (MRCA), Safety, Rehabilitation and Compensation (Defence-related Claims) Act 1988 (DRCA), and Veterans’ Entitlements Act 1986 (VEA); to communicate with you about your claim progress and our services; to process payments and manage your account; and to comply with legal obligations. 

We will not use or disclose your personal information for a purpose other than the primary purpose of collection, unless you would reasonably expect us to use or disclose the information for a secondary purpose, or you have consented, or use or disclosure is required or authorised by or under an Australian law or a court/tribunal order (APP 6).

Automated Decision-Making and AI Processing

Our platform uses artificial intelligence and automated processes to analyse your uploaded medical documents, identify potential conditions and relevant SOPs, generate structured prompts for additional information, and assist in drafting responses to DVA correspondence. 

In accordance with the transparency obligations introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth), which require disclosure of automated decision-making processes by 10 December 2026, we proactively disclose the following: our AI analysis is used as an assistive tool only and does not make final decisions on your behalf; all AI-generated outputs are presented to you for review, confirmation, and amendment before any action is taken; and we do not guarantee the accuracy or completeness of any AI-generated analysis. You retain full responsibility for reviewing and approving all claim materials before lodgement.

Information Sharing and Disclosure

We do not sell, rent, or trade your personal information. We may share your information with service providers who assist us in operating our platform (including cloud hosting, payment processing, and AI processing services), subject to binding confidentiality agreements that require them to handle your information in accordance with the APPs. We may also share your information with DVA or other government agencies at your explicit request and direction to support your claim, and with legal authorities when required by or under an Australian law or a court or tribunal order. 

Where we engage third-party service providers, we take reasonable steps to ensure they are bound by obligations to protect your personal information that are comparable to those imposed on us under the APPs (APP 8).

Data Storage and Sovereignty

Your data stays in Australia. We are committed to data sovereignty for Australian veterans. All data is stored on servers located in Australia (AWS Sydney region, ap-southeast-2). Your documents and personal information do not leave Australian data centres. AI processing of your documents occurs within Australian infrastructure. 

In the event that any data processing requires transfer outside of Australia (for example, if a third-party service provider has overseas infrastructure), we will notify you and obtain your explicit consent before any transfer occurs. We will also take reasonable steps to ensure the overseas recipient handles the information in accordance with the APPs, as required under APP 8. As at the date of this policy, no personal information or health information is transferred outside Australia. 

Data Security

We implement robust technical and organisational measures to protect your information, as required by APP 11 (as amended by the Privacy and Other Legislation Amendment Act 2024). These measures include encryption of data in transit (TLS 1.2 or higher) and at rest (AES-256), secure authentication with strong password requirements and multi-factor authentication, regular security assessments, penetration testing, and vulnerability management, role-based access controls limiting who can view your information, secure document storage with versioning and backup, and logging and monitoring of access to personal information. 

We do not store full payment card data. Payment processing is handled by PCI-DSS compliant third-party payment providers. 

Notifiable Data Breaches

In accordance with Part IIIC of the Privacy Act (the Notifiable Data Breaches scheme), if we become aware of an eligible data breach involving your personal information that is likely to result in serious harm, we will promptly notify the affected individuals and the Office of the Australian Information Commissioner (OAIC). Our notification will include a description of the data breach, the kinds of information involved, and recommendations about the steps you should take in response. 

We maintain a documented data breach response plan and will assess any suspected data breach within 30 days (or sooner where practicable) to determine whether it constitutes an eligible data breach requiring notification. We also comply with ransomware and cyber extortion reporting obligations under the Cyber Security Act 2024 (Cth), where applicable.

Limitation of Liability

To the maximum extent permitted by Australian law, and subject to the consumer guarantees set out in section 7: 

Our Services are provided “as is” without warranties of any kind beyond those implied by law that cannot be excluded. We do not guarantee the accuracy of AI-generated analysis or recommendations. We are not liable for any claim outcome or DVA decision. Our total aggregate liability to you for any loss or damage arising out of or in connection with these Terms or the Services is limited to the total fees you have actually paid to us in the 12 months preceding the event giving rise to the claim. 

We exclude liability for any indirect, incidental, special, consequential, or punitive damages, including loss of profits, data, or goodwill, to the maximum extent permitted by law. 

Important: Nothing in these Terms excludes, restricts, or modifies any consumer guarantee, right, or remedy conferred on you by the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010) or any other applicable law that cannot be excluded, restricted, or modified by agreement. 

Your Rights

Under Australian privacy law, you have the right to access the personal information we hold about you (APP 12), request correction of inaccurate, out-of-date, incomplete, irrelevant, or misleading information (APP 13), request deletion of your information (subject to legal retention requirements), withdraw consent for data processing at any time, be notified of eligible data breaches likely to result in serious harm, and lodge a complaint with the Office of the Australian Information Commissioner (OAIC). 

We will respond to access and correction requests within 30 days. If we refuse a request, we will provide written reasons. To exercise your rights, please contact us at privacy@dvahelper.com.au.

If you are not satisfied with our response to a privacy complaint, you may lodge a complaint with the OAIC at www.oaic.gov.au or by calling 1300 363 992. 

Statutory Tort for Serious Invasions of Privacy

We acknowledge that since 10 June 2025, individuals have a statutory right of action under Part VIA of the Privacy Act for serious invasions of privacy. This includes invasions by intrusion upon seclusion or misuse of personal information. We take this obligation seriously and have designed our systems, processes, and access controls to minimise the risk of any conduct that could constitute a serious invasion of privacy. 

Data Retention

We retain your personal information only for as long as necessary to fulfil the purposes for which it was collected, or as required by law. Specific retention periods are as follows: claim documentation is retained while your account is active and for 7 years after account closure (to align with general Australian limitation periods and tax record-keeping obligations); account information is retained until you request deletion or for 7 years after account closure, whichever is later if required by law; financial and transaction records are retained as required by Australian tax law (7 years from the relevant transaction); and server logs and technical data are retained for 12 months. 

When personal information is no longer required to be retained, we will take reasonable steps to destroy or de-identify it in accordance with APP 11.2.

Cookies and Tracking

We use essential cookies to keep you signed in to your account, remember your preferences, and ensure the security of our platform. We may also use analytics cookies to understand how our platform is used so we can improve our services. We do not use advertising or tracking cookies, and we do not share cookie data with third-party advertisers. You can manage your cookie preferences through your browser settings. Disabling essential cookies may affect the functionality of our platform. 

Children’s Privacy

Our services are not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18 without appropriate consent, we will take steps to delete that information promptly. 

Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or applicable law. We will notify you of any material changes by posting the updated policy on our website, updating the “Last updated” date, and notifying you by email where the changes are significant. Your continued use of our services after notification constitutes your acceptance of the updated policy. We encourage you to review this policy periodically. 

Contact Us

If you have questions about this Privacy Policy, wish to exercise any of your rights, or have a privacy complaint, please contact us: 

Privacy Officer 

Digital Virtual Assistant Pty Ltd T/A DVA Helper 

Email: privacy@dvahelper.com.au 

We will acknowledge receipt of your complaint within 5 business days and endeavour to resolve it within 30 days.

Governing Law

This Privacy Policy is governed by the laws of the Commonwealth of Australia, including the Privacy Act 1988 (Cth), the Privacy and Other Legislation Amendment Act 2024 (Cth), and applicable state and territory legislation.