PROVEN — Strength Through Skill

Privacy policy

Last updated: 17 September 2026

Summary. This document explains what Personal Information PROVEN collects, why it is collected, who it is disclosed to, where it is stored, how long it is retained and how it is destroyed. The operative commitments are set out in the numbered clauses below; this summary does not limit them.

In short: PROVEN collects only the information required for the App to function. The App contains no advertising, no tracking and no analytics of any kind. We do not sell Personal Information. We do not collect device location. Metadata embedded in photographs, including GPS coordinates, is removed on your device before upload.

1. Introduction and scope

1.1 This Privacy Policy is issued by PROVEN Training & Development Pty Ltd (ACN 678 084 789, ABN 61 678 084 789), an Australian proprietary company with its principal place of business in Western Australia (“PROVEN”, “we”, “us” or “our”).

1.2 This Policy applies to the PROVEN mobile application (the App) and to the website at proventraining.au (the Site), together the Services.

1.3 We handle Personal Information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs) contained in Schedule 1 to that Act. Commercial electronic messages are sent in accordance with the Spam Act 2003 (Cth).

1.4 By creating an account or otherwise using the Services, you acknowledge that your Personal Information will be handled as described in this Policy.

2. Definitions

2.1 In this Policy, unless the context requires otherwise:

  • Personal Information has the meaning given in section 6(1) of the Privacy Act, being information or an opinion about an identified individual, or an individual who is reasonably identifiable.
  • Account Information means the information described in clause 3.1(a).
  • User Content means Lift Records, Form Submissions, photographs, comments and any other material you create, upload or submit through the Services.
  • Lift Record means a record of a lift created in the App, including its particulars, associated steps, comments and photographs.
  • Form Submission means the answers you enter into a fillable form in the App and elect to save.
  • Organisation means a company or other entity established within the App, and Organisation Library means the collection of Lift Records shared to that Organisation.
  • Organisation Administrator means a user granted administrative rights in respect of an Organisation.
  • Service Provider means a third party engaged by us to perform a function on our behalf, as listed in clause 8.
  • Eligible Data Breach has the meaning given in Part IIIC of the Privacy Act.
  • Company Agreement means the PROVEN Company Agreement under which an Organisation takes out a company account, and Agreement Record means the record described in clause 3.1(h).

3. Personal Information we collect

3.1 We collect only such Personal Information as is reasonably necessary for the functions and activities described in this Policy. Specifically, we collect:

  • (a) Account Information — your name, your email address and a password. Authentication is performed by our database Service Provider. Your password is stored solely as a cryptographic hash and is not retrievable by any person at PROVEN. We additionally record the membership tier applicable to your account, and the dates on which you accepted the Safety Disclaimer and the Terms of Use, together with the versions accepted, for the purpose of evidencing that acceptance.
  • (b) Training and progress data — the modules and lessons you have completed, your quiz and practice-examination results, slides you have flagged, guides you have starred, and calculations you have saved. This data enables continuity of use between sessions and forms the basis of any completion record.
  • (c) Lift Records — the particulars you enter in respect of a lift (including reference, site, job, load, crane, radius and dates), together with any steps, comments and photographs you add. We also maintain a record of edits and deletions made to a Lift Record, so that a shared record cannot be altered without trace.
  • (d) Form Submissions — the answers you enter, retained so that they may be restored to a replacement or additional device.
  • (e) Organisation membership data — where you join an Organisation, we record the fact of membership, your role, the commencement and expiry of your access, and a history of changes to that membership (including joining, approval, change of role and cessation of access). That history is retained deliberately, as the record of who held access at a given time.
  • (f) Correspondence — support messages submitted through the App, and the name, email address and message submitted through the contact form on the Site. This information is used to respond to you and for no other purpose.
  • (g) Subscription address — where you provide your email address through the notification form on the Site, that address, used solely for the purposes described in clause 5.
  • (h) Agreement Records — where you accept or sign the Company Agreement on behalf of an Organisation, on the Site or in the App, we record your name, position, email address and PROVEN account, the Organisation, the date and time, the version of the Company Agreement accepted, the method of acceptance and, where you sign by drawing or typing your signature, an image of that signature or the name typed. This record is kept as evidence that the Company Agreement was accepted and by whom.
  • (i) Account deletion requests — where you ask in the App for your account to be deleted, the date of that request and the date on which deletion falls due under clause 11.1(c).

4. Practices we do not engage in

4.1 For the avoidance of doubt, we do not:

  • (a) display advertising in the App, or incorporate any advertising software within it;
  • (b) incorporate any third-party analytics, attribution or tracking technology in the App; construct behavioural profiles of users; or track users across other applications or websites;
  • (c) sell, rent or trade Personal Information, or disclose it to any third party for that party’s own marketing purposes;
  • (d) request, collect or record device location data; or
  • (e) purchase or rent contact lists. The only email addresses we hold are those provided to us directly by the individual concerned.

5. Electronic messages

5.1 We send two categories of email, which are treated differently:

  • (a) Transactional messages relating to your account, including address confirmation, responses to support enquiries and notices material to your access. These form part of the Services and, as they are not commercial electronic messages for the purposes of the Spam Act, they cannot be unsubscribed from while an account subsists.
  • (b) Product update messages, sent only where you have provided your address through the notification form on the Site or have otherwise consented to receive them. These advise that the App has been released and, from time to time, that a further release of significance has been made. They do not constitute a newsletter and are not sent frequently.

5.2 Every message described in clause 5.1(b) contains a functional unsubscribe facility, which takes effect upon a single action. You may alternatively withdraw your consent by contacting us at the address in clause 16. We do not sell, rent or otherwise disclose your address, and we do not acquire contact lists from third parties.

6. Photographs and image metadata

6.1 Photographs attached to a Lift Record are re-encoded on your device prior to upload. That process removes the metadata embedded by the capturing device, including GPS coordinates, device identifiers and timestamps. We receive the image only, and not the location at which it was captured.

6.2 The App provides an obscuring (blur) tool enabling you to redact faces, names, registration plates or other identifying features before a photograph is saved.

6.3 You are responsible for ensuring that you are permitted to capture and to share any photograph you upload. Many sites impose their own restrictions on photography.

7. Disclosure and visibility of your information

7.1 Access to information within the Services is determined as follows:

  • (a) User Content is private to you by default. Lift Records and Form Submissions you save are visible to you alone unless and until you share them.
  • (b) Where you share a Lift Record with an Organisation Library, the members of that Organisation may view it, together with your name recorded as contributor. Sharing is voluntary and is exercised on a per-record basis.
  • (c) An Organisation Administrator may view the membership of that Organisation, each member’s role and access dates, the history of membership changes, and the Lift Records shared to that Organisation Library. An Organisation Administrator may not view your private Lift Records, your Form Submissions or your training and progress data.
  • (d) Personnel of PROVEN are able to access Organisation Libraries. Such access is exercised solely for the purposes of operating, supporting and administering the Services. We disclose this expressly rather than leave it to be discovered.
  • (e) Material downloaded for offline use bears your name and email address as a visible watermark. Such material is licensed to you personally, and the watermark is applied to discourage further distribution.
  • (f) A copy of an Agreement Record, including any signature image, is provided to the person who accepted the Company Agreement and to the Organisation’s billing contact, and may be viewed by that Organisation’s Organisation Administrators. It is not visible to other members of the Organisation.

7.2 We do not otherwise disclose Personal Information, except where disclosure is required or authorised by or under an Australian law or a court or tribunal order.

8. Service Providers

8.1 We engage a deliberately limited number of Service Providers, each performing only the function identified:

  • (a) Supabase — database, authentication and file storage services. Account Information, User Content and Form Submissions are held on this infrastructure.
  • (b) Netlify — hosting of the Site and delivery of the forms contained on it.
  • (c) Apple — distribution of the App and, during testing, distribution of pre-release versions via TestFlight. Where you have enabled Apple’s own analytics or crash-reporting settings on your device, Apple may provide us with crash diagnostics. That setting is controlled by you at the device level and is not set or required by us.
  • (d) Expo — delivery of application updates.

9. Cookies and website measurement

9.1 The Site sets no cookies. No consent mechanism is presented because no consent is required.

9.2 The Site loads no resources from any third party. Fonts, images and stylesheets are served from our own domain, with the consequence that visiting a page does not disclose your visit to any third party. We do not identify visitors to the Site and we do not measure traffic to it.

9.3 Clause 9.2 does not extend to any external hyperlink you elect to follow, including the link to the Office of the Australian Information Commissioner in clause 16, which will take you to a third-party website governed by that party’s own terms.

10. Location of data and cross-border disclosure

10.1 Personal Information is held by Supabase on cloud infrastructure located in Sydney, Australia (the ap-southeast-2 region) and is not stored outside Australia.

10.2 Certain ancillary services described in clause 8, including the delivery of application updates and distribution through the App Store, are operated from outside Australia. Where Personal Information is accessed from outside Australia, it continues to be handled in accordance with this Policy.

11. Retention and destruction

11.1 We retain Personal Information only for so long as it is required, and destroy it in accordance with the following:

  • (a) Form Submissions. A deleted Form Submission is moved to a recently-deleted state and remains recoverable for 30 days. Upon expiry of that period it is permanently deleted and cannot be restored. This is deliberate: an inadvertent deletion should not destroy a record, and a deletion should ultimately be effective.
  • (b) Organisation membership history is retained for so long as the Organisation subsists, constituting the record of who held access and when.
  • (c) Account Information, Lift Records and training data are retained while your account subsists. Where you close your account, including by using Delete my account in the App, or request its deletion, such information is retained for a period of three months and is then permanently deleted. That period operates as a safeguard against inadvertent or reconsidered deletion. Following its expiry the information is irrecoverable.
  • (d) Subscription addresses are retained until you unsubscribe or request removal, whereupon the address is deleted.
  • (e) Agreement Records, including any signature image, are retained for so long as the Organisation subsists and for seven years afterwards, as evidence of the agreement, and are then permanently deleted. They are not deleted earlier if the person who accepted leaves the Organisation or deletes their own account.

12. Access, correction and erasure

12.1 In accordance with APP 12 and APP 13, you may request access to the Personal Information we hold about you, request its correction, or request deletion of your account and the information associated with it. Requests may be made to the address in clause 16 and are actioned without charge.

12.2 Two limitations apply, and are stated plainly:

  • (a) a Lift Record you have shared to an Organisation Library forms part of that Organisation’s records and may be retained by it after your membership ends, although we will remove your name from it upon request; and
  • (b) Organisation membership history is retained for the reason given in clause 11.1(b).

13. Security and data breach notification

13.1 Personal Information is transmitted in encrypted form, and the database enforces per-user access controls such that one account cannot read the records of another.

13.2 No system of security is infallible. In the event of an Eligible Data Breach affecting you, we will notify you, and will do so promptly and in accordance with Part IIIC of the Privacy Act.

14. Eligibility and intended users

14.1 You must be at least 16 years of age to hold a PROVEN account. The Services are intended for persons working in, or preparing to work in, the lifting industry. We do not knowingly collect Personal Information from any person under 16. If you believe that a person under that age has created an account, please contact us and the account will be removed.

14.2 Certain parts of the Services presuppose that the user holds a relevant licence. The reference material, calculators and Lift Records are prepared for certified riggers and crane operators and assume that training and competence. Preparatory and learning material is provided for persons working towards a licence. For the avoidance of doubt, use of the Services does not constitute a qualification, and nothing within the Services authorises any person to carry out high risk work for which they are not licensed and competent.

15. Amendments to this Policy

15.1 Where we change the manner in which Personal Information is handled, this page will be updated and the date recorded at the head of this Policy amended accordingly. Where a change is material, we will notify you within the App rather than rely upon your re-reading of this page.

16. Complaints and contact

16.1 Enquiries, requests under clause 12 and privacy complaints may be directed to info@proventraining.au. We would prefer to hear from you first and to put the matter right.

16.2 If you are not satisfied with our handling of a privacy complaint, you may refer the matter to the Office of the Australian Information Commissioner at oaic.gov.au.