Delegate HQ — Data Processing & Security
Version: 1.0 Effective date: 16 September 2026 Last updated: 16 September 2026
1. Purpose
This document describes how Delegation HQ approaches the processing and protection of Customer Data in Delegate HQ.
It supplements the Delegate HQ Terms of Service and Privacy Policy.
Where Delegation HQ and a Customer enter into a separately signed data-processing, security or government contract, that agreement prevails to the extent of any expressly stated inconsistency.
2. Roles
The Customer determines what Customer Data it places in Delegate HQ, why that information is used and which Authorised Users may access it.
Delegation HQ processes Customer Data to provide, operate, maintain, secure and support Delegate HQ and to meet applicable legal obligations.
Nothing in this document transfers ownership of Customer Data to Delegation HQ.
3. Customer instructions
The Customer's use and configuration of Delegate HQ, together with the applicable agreement, constitute instructions to Delegation HQ concerning ordinary processing necessary to provide the service.
Delegation HQ will not intentionally process identifiable Customer Data for materially unrelated purposes except where:
- instructed or authorised by the Customer;
- necessary to protect the service, Customers or users;
- permitted under the applicable agreement; or
- required or authorised by law.
4. Data minimisation
Delegation HQ follows a data-minimisation approach.
We aim to collect, process and retain only information reasonably necessary for identified operational, security, support, contractual or legal purposes.
New integrations and service providers should be assessed with the question: does this information actually need to be collected, transferred or retained?
5. Customer Data ownership
Customer Data remains the Customer's data.
Delegation HQ obtains only the limited rights necessary to provide, secure, maintain and support Delegate HQ and comply with applicable law.
6. Confidentiality
Customer Data is treated as confidential information.
Personnel and service providers may access Customer Data only where reasonably necessary for legitimate operational purposes and subject to appropriate confidentiality and access controls.
7. Access control
Delegate HQ is designed around authenticated access and Customer-controlled permissions.
Customers are responsible for:
- managing their Authorised Users;
- assigning appropriate roles and permissions;
- removing access when no longer required;
- protecting credentials; and
- reporting suspected credential compromise.
Delegation HQ will apply reasonable controls to administrative access to production systems.
8. Tenant separation
Delegate HQ is a multi-tenant service.
Delegation HQ uses technical controls designed to prevent one Customer from accessing another Customer's data.
Attempts to bypass tenant separation, authentication or authorisation controls are prohibited and may result in immediate suspension and security investigation.
9. Encryption and transmission
Delegation HQ will use reasonable industry-standard protections for Customer Data transmitted over public networks.
Where supported and appropriate within the production architecture, data at rest will be protected using security controls provided by the relevant infrastructure platform.
Specific cryptographic implementation details may be withheld from public documentation where disclosure would create unnecessary security risk.
10. Secure development
Privacy and security considerations form part of Delegate HQ's development process.
Reasonable practices may include:
- source control;
- controlled deployment processes;
- database migration management;
- access-control review;
- dependency maintenance;
- testing;
- vulnerability remediation;
- least-privilege design;
- tenant-isolation controls; and
- review of material changes affecting data handling.
11. Logging and monitoring
Delegation HQ may maintain operational, authentication, security and audit information reasonably necessary to operate and protect Delegate HQ.
Logging should be proportionate to its purpose.
Delegation HQ does not intentionally collect excessive user information merely because logging technology permits it.
Security and operational logs may be retained for reasonable periods appropriate to troubleshooting, investigation, compliance and security.
12. Administrative and support access
Delegation HQ personnel will not routinely access Customer Data without a legitimate operational reason.
Access may occur where reasonably necessary to:
- respond to a Customer support request;
- troubleshoot a service problem;
- maintain or restore the service;
- investigate suspected misuse or security incidents;
- protect Delegate HQ or other Customers; or
- comply with law.
Administrative access should be appropriately restricted and, where technically practicable and proportionate, logged.
13. Service providers and subprocessors
Delegation HQ may use subprocessors and infrastructure providers to deliver Delegate HQ.
They may perform functions including:
- database hosting;
- authentication;
- storage;
- application hosting;
- payment processing;
- email delivery;
- monitoring;
- security; and
- support infrastructure.
Delegation HQ will assess material providers having access to Customer Data with regard to their function, security, privacy and data-location implications.
Delegation HQ intends to maintain a public Subprocessor List.
14. Data location
Customer Data for the standard Delegate HQ service is stored in Australia.
Delegation HQ will not intentionally store Customer Data for the standard Delegate HQ service outside Australia.
This Australian data-residency commitment applies to the primary application database, Customer file and object storage, and other persistent storage of Customer Data forming part of the standard Delegate HQ service.
A Customer may request a dedicated instance of Delegate HQ hosted in another available geographic region. Where Delegation HQ agrees to provide a dedicated instance outside Australia, the Customer's selected hosting region will be expressly documented in the applicable Order Form or separate agreement.
Customer Data for that dedicated instance may then be stored in the agreed region instead of Australia.
Supporting service providers may process limited information outside Australia where reasonably necessary to provide supporting functions and where appropriately assessed and disclosed.
Delegation HQ maintains information about material subprocessors and relevant data-processing locations as part of its service-provider and privacy governance.
15. Backups and recovery
Delegation HQ maintains reasonable backup and recovery arrangements appropriate to the service.
Backups exist primarily for:
- disaster recovery;
- service continuity; and
- system restoration.
They are not intended to operate as a Customer archive, statutory records-management system or customer-level undo facility.
Recovery of an individual item deleted by a Customer cannot be guaranteed.
16. Customer continuity responsibilities
Customers remain responsible for determining whether their legal, governance, archival or business-continuity requirements require independent copies or exports of Customer Data.
Use of Delegate HQ does not transfer those obligations to Delegation HQ unless expressly agreed.
17. Security incidents
Delegation HQ will maintain reasonable processes for responding to suspected security incidents.
Depending on the circumstances, response activities may include:
- identifying and containing the incident;
- protecting affected systems or accounts;
- assessing the information and Customers affected;
- investigating cause and scope;
- undertaking remediation;
- assessing notification obligations; and
- implementing reasonable measures to reduce recurrence.
18. Customer notification
Where a security incident materially affects Customer Data, Delegation HQ will notify the affected Customer without undue delay where appropriate or required by law.
Notifications may be updated as an investigation develops.
Delegation HQ and the affected Customer should reasonably cooperate concerning investigation, remediation and applicable statutory notification obligations.
Separate government contracts may establish specific reporting timeframes.
19. Notifiable data breaches
Where the Australian Notifiable Data Breaches scheme applies, Delegation HQ will assess suspected eligible data breaches and make notifications required by applicable law.
The existence of a security incident does not necessarily mean an eligible data breach has occurred.
20. Customer security obligations
Customers and Authorised Users must:
- protect credentials;
- use individual user accounts;
- configure access appropriately;
- promptly remove unnecessary access;
- promptly report suspected compromise;
- not attempt to circumvent security controls; and
- comply with the Acceptable Use Policy.
Customers should also maintain appropriate security on devices and networks used to access Delegate HQ.
21. Vulnerability reporting
A person who believes they have identified a security vulnerability should report it privately to Delegation HQ rather than exploiting it, accessing Customer Data or publicly disclosing technical details before Delegation HQ has had a reasonable opportunity to investigate and remediate the issue.
Security reports may be sent to:
If that address is not available, reports may be sent to support@delegatehq.com.au.
Testing Delegate HQ for vulnerabilities without authorisation is not permitted merely because a person intends to report the results.
22. Data retention and deletion
Following termination of a subscription, Customer Data will ordinarily remain within Delegation HQ's systems for up to 90 days for potential reactivation or export.
After that period it may be deleted from active systems.
Residual backup copies may remain until normal backup rotation expires.
Information may be retained where required by law or reasonably necessary for security, fraud prevention or legal claims.
23. Return and export
Where Delegate HQ provides export functionality, Customers may use it to obtain available Customer Data during their subscription.
During the post-termination retention period, Delegation HQ may reasonably assist with reactivation or available export mechanisms.
Bespoke migration, transformation or professional data-extraction services are not included unless agreed separately.
24. Customer deletion
Customers may delete information using functionality provided by Delegate HQ.
The Customer is responsible for authorised deletion actions performed through its account.
Delegation HQ does not guarantee recovery of Customer-deleted data.
25. Privacy requests
Where a privacy request relates to personal information controlled directly by Delegation HQ, Delegation HQ will handle the request under its Privacy Policy and applicable law.
Where a request concerns Customer Data controlled by a Customer, Delegation HQ will ordinarily refer the person to that Customer and reasonably assist the Customer where appropriate.
26. Legal demands
Delegation HQ will not voluntarily disclose Customer Data to a government agency, regulator or law-enforcement body merely on informal request.
Where disclosure is legally required or authorised, Delegation HQ will seek to:
- verify the legal basis of the demand;
- disclose only information reasonably required; and
- notify the affected Customer beforehand where legally permitted and appropriate.
27. Artificial intelligence
Identifiable Customer Data will not be used to train public or general-purpose AI models without the Customer's express consent.
Any future AI functionality involving Customer Data should be assessed for privacy, security, data-location, contractual and regulatory implications before deployment.
28. Changes to security architecture
Delegate HQ's technical architecture will evolve.
Delegation HQ may replace infrastructure and service providers where reasonably necessary.
Material changes affecting Customer Data location, privacy or security will be assessed and relevant public documentation updated.
29. No absolute security guarantee
No online service can guarantee absolute security, uninterrupted availability or zero data loss.
The commitments in this document are commitments to reasonable controls, responsible operation and appropriate response, not a representation that security incidents can never occur.
30. Government and higher-assurance requirements
Government Customers may require additional controls, assessments, certifications, contractual clauses, incident timeframes, data-residency requirements or assurance material.
Those requirements may be documented in a separately negotiated agreement.
They do not automatically apply to the standard Delegate HQ subscription unless expressly agreed.
31. Contact
Privacy matters: privacy@delegatehq.com.au
Legal matters: legal@delegatehq.com.au
Security matters: security@delegatehq.com.au, or support@delegatehq.com.au if the security address is unavailable.
General support: support@delegatehq.com.au
Delegation HQ ABN 56 321 616 581 PO Box 4 Officer VIC 3809 Australia
