Last updated: 14 July 2026
DataVance (ABN 16 787 418 307) operates the DVAP (DataVance Accounts Payable) API at
api.dvap.datavance.com.au. This policy explains how we handle personal
information under the Australian Privacy Act 1988 (Cth) and the Australian Privacy
Principles (APPs), and, where it applies to you, the EU/UK GDPR. Contact:
support@datavance.com.au.
To provide the service (extraction, validation, fraud screening, matching, approvals, export), enforce quotas and rate limits, secure and audit the service, respond to support requests, and improve the service. Our published accuracy metrics are computed from public benchmark datasets and synthetic documents — never from customer documents.
Cross-border disclosure (APP 8): document content transits to Anthropic in the United States for extraction; our stored records remain in Australia.
We retain your data while your account is active. Audit events are append-only by design (they cannot be edited through the API). On written request — or 30 days after termination — we delete your organisation's stored data, except where we are legally required to retain it.
TLS for all traffic, encrypted storage volumes, API keys stored only as hashes, HMAC-signed webhook deliveries, and role-based access controls on API keys.
You may request access to or correction of personal information we hold (APP 12–13). If the GDPR applies to you, you also have rights of erasure, portability, restriction, and objection. Write to support@datavance.com.au; we respond within 30 days. If you are unsatisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC).
We may update this policy; the "last updated" date above reflects the current version. Material changes will be notified via the marketplace listing or your contact email.