Delegate HQ — Privacy Policy
Version: 1.0 Effective date: 16 September 2026 Last updated: 16 September 2026
1. Our approach to privacy
Delegate HQ is supplied by Delegation HQ, ABN 56 321 616 581.
We believe privacy is best protected by collecting less information in the first place.
Our approach is simple:
- collect only information we reasonably need;
- use it for clear and legitimate purposes;
- protect information entrusted to us;
- do not sell personal information or Customer Data;
- do not use unnecessary advertising trackers or cross-site profiling;
- do not retain information indefinitely merely because storage is available; and
- be transparent about the service providers that help us operate Delegate HQ.
Privacy and security are considerations in the design of Delegate HQ, not merely matters addressed after a feature is built.
2. Scope
This Privacy Policy explains how Delegation HQ handles personal information in connection with Delegate HQ, our website, customer relationships, support and related business activities.
It should be read together with the Delegate HQ Terms of Service and, where applicable, an agreement with a Customer.
3. Customer-controlled information
There is an important distinction between information Delegation HQ collects for its own business and information a Customer chooses to place in Delegate HQ.
For account, subscription, support and business-administration information, Delegation HQ determines why that information is collected and used.
For Customer Data entered into Delegate HQ, the Customer generally determines what information is entered and why it is processed. The Customer remains responsible for having appropriate authority to collect, use and provide that information.
4. Personal information we may collect
Depending on how a person interacts with us, we may collect:
- name;
- email address;
- organisation or business name;
- position, role or job title;
- account and authentication information;
- subscription and billing information;
- communications with our support, legal or privacy teams;
- IP address and relevant browser, device and technical information;
- security and authentication events;
- service usage and activity information reasonably necessary to operate, troubleshoot and secure Delegate HQ; and
- other information a person voluntarily provides to us.
Where payment cards are processed through an external payment provider, payment-card information is handled by that provider in accordance with its own terms and privacy practices. Delegation HQ does not intentionally store full payment-card credentials in Delegate HQ.
5. Personal information contained in Customer Data
Customers may enter information concerning their personnel or other people into Delegate HQ.
Depending on a Customer's use of the service, this may include:
- names;
- employment or organisational information;
- positions;
- roles and responsibilities;
- delegations and authorities;
- assignments and appointments;
- contact information; and
- other information the Customer chooses to enter.
Delegation HQ does not determine which individuals a Customer chooses to record in Delegate HQ.
6. Sensitive information
Delegate HQ is not intended to be a general repository for unrelated highly sensitive personal records.
Customers should not use Delegate HQ as a general storage location for information such as health records, banking credentials, passwords, tax file numbers, passport information or criminal-history records unless particular functionality has expressly been designed and agreed for that purpose.
7. How we collect information
We may collect personal information:
- directly from a person when they create an account, contact us or use our services;
- from a Customer that creates or administers an account for an Authorised User;
- through the operation and security of Delegate HQ;
- through payment and other service providers;
- from correspondence and support interactions; and
- from other lawful sources where reasonably necessary for our business.
Customer Data is principally provided by Customers and their Authorised Users.
8. Why we use personal information
We may use personal information reasonably necessary to:
- create and administer accounts;
- authenticate users;
- provide Delegate HQ;
- administer subscriptions and payments;
- provide support;
- communicate about the service;
- maintain and secure Delegate HQ;
- detect misuse, unauthorised access and fraud;
- troubleshoot problems;
- understand and improve service performance;
- comply with legal obligations; and
- manage our commercial relationship with Customers.
Our processing of Customer Data is narrower: we process it to provide, maintain, secure and support Delegate HQ according to the Customer's use and configuration and as otherwise permitted by the Customer agreement or law.
We do not repurpose identifiable Customer Data for unrelated advertising or marketing.
9. Selling information
Delegation HQ does not sell Customer Data or personal information to data brokers, advertisers or other third parties.
10. Artificial intelligence
Delegation HQ does not use identifiable Customer Data to train public or general-purpose artificial intelligence models without the Customer's express consent.
If Delegate HQ introduces automated systems that use personal information to make or materially contribute to decisions that could reasonably be expected to significantly affect an individual's rights or interests, we will assess and update our privacy disclosures and practices as required by applicable law.
11. Aggregated and de-identified information
We may create and use aggregated or appropriately de-identified information for legitimate purposes including:
- service performance analysis;
- capacity planning;
- understanding feature usage;
- troubleshooting;
- security;
- product development; and
- improving Delegate HQ.
We do not treat information as de-identified merely because a person's name has been removed if the information remains reasonably capable of identifying them.
12. Service and marketing communications
We may send communications reasonably necessary to operate the Customer relationship, including account, security, billing, support and important service communications.
We may send direct marketing where legally permitted.
Marketing communications will provide a straightforward way to unsubscribe where required.
Unsubscribing from marketing does not prevent necessary account, security, billing or service communications.
13. Cookies and similar technologies
We aim to minimise tracking.
Delegate HQ and our website may use cookies or similar technologies where reasonably necessary for:
- authentication;
- session management;
- security;
- user preferences; and
- essential service functionality.
We may use privacy-conscious analytics where reasonably necessary to understand and improve the service.
We do not intentionally deploy unnecessary behavioural advertising trackers or use cross-site profiling merely because the technology is available.
If our use of tracking or analytics technologies materially changes, we will reassess the privacy implications and update our disclosures and consent mechanisms where required.
14. Service providers and subprocessors
We use service providers to operate Delegate HQ and our business.
These may provide:
- cloud and database hosting;
- authentication;
- data storage;
- application and website hosting;
- payment processing;
- email delivery;
- security;
- support infrastructure; and
- other operational services.
We seek to provide those service providers only with information reasonably necessary for their role and expect appropriate privacy and security protections.
We do not authorise our service providers to use Customer Data for their own unrelated advertising or marketing.
We intend to maintain a public Subprocessor List identifying material providers that process Customer Data.
15. Australian data storage and overseas processing
Customer Data for the standard Delegate HQ service is stored in Australia.
Delegation HQ will not intentionally store Customer Data for the standard Delegate HQ service outside Australia.
A Customer may request its own dedicated instance of Delegate HQ and may request that Customer Data for that instance be stored in another available geographic region. Where Delegation HQ agrees to such an arrangement, the selected data-hosting region will be expressly documented in the Customer's Order Form or separate agreement.
Some supporting service providers may process limited personal information outside Australia in connection with functions such as payments, email delivery or other operational services.
Where reasonably practicable and required, we will identify relevant overseas processing locations in our Subprocessor List or other privacy disclosures.
We assess material overseas processing arrangements having regard to the nature of the information, the purpose of the processing and appropriate privacy and security protections.
Overseas processing of limited supporting information does not change the Australian storage location of Customer Data in the standard Delegate HQ service.
16. Security
We use reasonable technical and organisational safeguards appropriate to the nature of the information and the service.
Depending on the system and information involved, these may include measures concerning authentication, access controls, tenant separation, encryption in transit, controlled administrative access, security logging, backups, software maintenance and incident response.
We do not claim that any internet-based system is completely secure or incapable of being breached.
We intentionally do not publish security information where doing so could weaken the effectiveness of our safeguards.
17. Data breaches
If we become aware of a suspected security incident involving personal information, we will take reasonable steps to investigate, contain, assess and remediate it.
Where the Notifiable Data Breaches scheme or another applicable law applies, we will assess and make notifications as required by law.
Where an incident materially affects Customer Data, we will notify the affected Customer without undue delay where appropriate or required and reasonably cooperate with the Customer concerning notification and remediation responsibilities.
18. Retention
We retain information according to its purpose rather than keeping everything indefinitely.
Customer Data will ordinarily be retained for up to 90 days after a subscription ends and may then be deleted from active systems.
Residual information may remain temporarily in backups until those backups expire through normal rotation. Backups are not ordinarily restored solely to remove individual records.
Billing, taxation and transaction records may be retained for periods required by law.
Contract records, Terms-acceptance information and similar records may be retained for a reasonable period necessary to establish the relationship and protect legal rights.
Support correspondence, operational logs and security records are retained for reasonable operational, security, compliance or legal periods.
Delegation HQ does not retain personal information indefinitely merely because storage is available.
19. Access and correction
A person may contact us to request access to or correction of personal information Delegation HQ controls about them.
We may take reasonable steps to verify identity before providing or changing personal information.
We do not charge a fee merely for making a privacy request. Where applicable law permits a reasonable charge in particular circumstances, we will explain that before proceeding.
Requests may be sent to privacy@delegatehq.com.au.
20. Customer-controlled information and individual requests
If personal information about an individual is contained in Customer Data, the Customer generally controls that information.
For example, if a government Customer has entered information about one of its staff members, the staff member should ordinarily direct an access or correction request to that Customer.
Delegation HQ will not independently alter or delete Customer Data merely because a third party asks us to do so where the Customer is the appropriate entity to determine the request.
We will reasonably assist Customers in responding to legitimate privacy requests where appropriate or required.
21. Deletion and other privacy rights
Where applicable law provides a right to deletion or another privacy right, Delegation HQ will respond in accordance with that law.
A request concerning Customer-controlled Customer Data may need to be handled through the relevant Customer.
Legal, security, contractual or record-retention requirements may sometimes require information to be retained notwithstanding a deletion request.
22. Accuracy
Delegation HQ takes reasonable steps to ensure personal information it controls is accurate, complete and up to date where appropriate.
Customers are responsible for the accuracy and currency of Customer Data they enter into Delegate HQ.
Where practical, Delegate HQ may provide users with tools to update information directly.
23. Children and minors
Delegate HQ is not directed at children.
A person must be at least 18 years old to enter into a Delegate HQ subscription in their own name.
Delegation HQ does not knowingly seek children's personal information for advertising, behavioural profiling or data-brokerage purposes.
A Customer may legitimately hold information concerning a person under 18 or authorise an under-18 user where lawful and appropriate. The Customer is responsible for ensuring it has the necessary lawful authority and supervision.
24. Legal requests and government access
Delegation HQ does not voluntarily disclose Customer Data to law-enforcement agencies, regulators or other government bodies merely because they request it.
We may disclose information where:
- the Customer authorises the disclosure;
- we are required or authorised by applicable law; or
- a valid and enforceable legal process requires disclosure.
Where legally permitted and appropriate, we will seek to notify the affected Customer before disclosing Customer Data.
We aim to disclose only the information reasonably required by the applicable legal demand.
25. Business transfers and restructuring
If Delegation HQ is incorporated, restructured, merged, acquired or its relevant business or assets are transferred, personal information and Customer Data may form part of that transfer where reasonably necessary.
We will seek to ensure that applicable privacy, confidentiality and contractual protections continue to apply.
During due diligence for a potential transaction, we will seek to minimise disclosure of identifiable Customer Data and use appropriate confidentiality and security controls.
A business transfer does not itself authorise the recipient to use Customer Data for unrelated advertising or other incompatible purposes.
26. Privacy complaints
If you believe we have mishandled your personal information, contact:
or write to:
Delegation HQ ABN 56 321 616 581 PO Box 4 Officer VIC 3809 Australia
We will deal with privacy complaints promptly and fairly, investigate as appropriate and keep the complainant reasonably informed if further investigation is required.
Where a complaint concerns Customer Data controlled by one of our Customers, the Customer may be the appropriate organisation to handle some or all of the complaint. We will reasonably assist where appropriate.
If a person is not satisfied with our response and applicable law provides that avenue, they may contact the Office of the Australian Information Commissioner (OAIC).
27. Changes to this Privacy Policy
We may update this Privacy Policy as our service, practices or legal obligations change.
Each version will identify its version, effective date and last-updated date.
Minor administrative changes, corrections and clarifications may take effect when published.
Where we materially change how we collect, use, disclose or protect personal information, we will provide reasonable notice to affected Customers or users where appropriate.
Updating this Privacy Policy does not itself provide consent or legal authority where applicable law requires separate consent or another legal basis.
We intend to retain historical versions so that our privacy practices can be understood over time.
28. Contact us
Privacy enquiries and requests:
Legal enquiries:
General support:
Postal address:
Delegation HQ ABN 56 321 616 581 PO Box 4 Officer VIC 3809 Australia
