Privacy Policy

This Privacy Policy explains how Grasp IT Pty Ltd collects, uses, discloses and protects personal information when you use our websites, applications, APIs, customer portals and online services.

Effective Date: 15 July 2026 Last Updated: 15 July 2026

1. Introduction

Welcome to Grasp IT Pty Ltd ("we", "our", or "us"). We are committed to protecting your privacy and ensuring your personal information is handled securely and transparently.

This Privacy Policy explains how we collect, use, disclose and protect your information when you use:

  • Our websites
  • Web applications
  • Mobile and desktop applications
  • Application programming interfaces (APIs)
  • Customer portals
  • Online services

We process personal information in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and other applicable privacy laws.

2. Data Controller

Company
Grasp IT Pty Ltd
Address
[Company Address]
Email
privacy@graspit.com.au
Telephone
[Phone Number]

Data Protection Officer

Where applicable, enquiries for our Data Protection Officer may be sent to:

privacy@graspit.com.au

3. Information We Collect

Depending on how you use our services, we may collect the following categories of information.

Personal Information

  • Name
  • Company name
  • Job title
  • Email address
  • Telephone number
  • Postal address
  • Username
  • Encrypted or securely hashed password information
  • Profile photographs, where voluntarily provided

Account Information

  • User ID
  • Roles
  • Permissions
  • Group memberships
  • Authentication settings

Technical Information

  • IP address
  • Browser type
  • Device information
  • Operating system
  • Screen resolution
  • Language preferences
  • Time zone

Usage Information

  • Login history
  • Pages viewed
  • Features used
  • Error logs
  • Session duration
  • Clickstream information

Uploaded Content

Where you choose to upload files, we may store:

  • Documents
  • Images
  • Audio files
  • Video files
  • Other files necessary to provide the service

4. How We Collect Information

We collect information when you:

  • Register an account
  • Purchase products or services
  • Contact customer support
  • Submit forms
  • Upload files
  • Use our applications
  • Subscribe to newsletters
  • Use our APIs
  • Enable optional features

Some information is collected automatically using cookies and similar technologies.

5. Lawful Basis for Processing

Under the GDPR, we process personal information under one or more of the following lawful bases.

Consent

We may rely on your consent for optional processing, including:

  • Marketing emails
  • Optional cookies
  • Newsletter subscriptions

Contract

We process information where necessary to provide products or services that you have requested or to take steps before entering into a contract.

Legal Obligation

We process information where necessary to comply with tax, accounting, regulatory and other legal requirements.

Legitimate Interests

We may process information where necessary for our legitimate business interests, provided those interests do not override your rights and freedoms. These interests may include:

  • Improving our services
  • Security monitoring
  • Fraud prevention
  • System administration
  • Customer support

6. How We Use Your Information

We may use personal information to:

  • Provide and operate our services
  • Authenticate users
  • Manage user accounts
  • Process payments
  • Deliver purchased products or services
  • Improve application performance
  • Provide technical and customer support
  • Send service-related notifications
  • Prevent fraud
  • Detect and respond to security threats
  • Meet legal and regulatory obligations
  • Generate analytics
  • Maintain security and audit logs

7. Automated Decision Making

We do not make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing is:

  • Required or authorised by law
  • Necessary to enter into or perform a contract
  • Based on your explicit consent

8. Sharing Information

We may share personal information with trusted service providers and other parties where necessary, including:

  • Hosting providers
  • Payment processors
  • Email delivery providers
  • Cloud storage providers
  • Analytics providers
  • Professional advisers
  • Legal or regulatory authorities where required
We do not sell personal information.

9. International Transfers

Where personal information is transferred outside the United Kingdom or European Economic Area, we implement appropriate safeguards where required. These may include:

  • Standard Contractual Clauses
  • International Data Transfer Agreements
  • Adequacy decisions
  • Approved certification or transfer mechanisms
  • Other legally recognised safeguards

10. Data Retention

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and reporting requirements.

Typical retention periods may include:

Data Category Typical Retention Period
Customer accounts For the duration of the account and a reasonable period after closure
Support requests Up to 7 years
Financial records 7 years or as legally required
Audit logs 12 to 24 months
Marketing consent records Until consent is withdrawn and for a reasonable period afterwards
Security logs Up to 24 months

Actual retention periods may vary depending on contractual, legal, regulatory, operational or security requirements.

11. Security

We implement appropriate technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, alteration or disclosure.

These measures may include:

  • Encryption
  • HTTPS and TLS
  • Secure password hashing
  • Multi-factor authentication
  • Role-based permissions
  • Access logging
  • Firewalls
  • Regular security updates
  • Backup and recovery procedures
  • Vulnerability monitoring

No method of transmission or storage is completely secure. However, we take reasonable steps to reduce the risk of unauthorised access, disclosure or loss.

12. Your GDPR Rights

Subject to applicable law, you may have the right to:

  • Access your personal information
  • Correct inaccurate or incomplete information
  • Request deletion of your personal information
  • Restrict certain processing activities
  • Object to certain processing activities
  • Withdraw consent at any time
  • Request data portability
  • Lodge a complaint with an applicable supervisory authority

To make a privacy request, contact: privacy@graspit.com.au .

We may need to verify your identity before responding to a request.

13. Children's Privacy

Our services are not intended for children under 16 unless the relevant service expressly states otherwise and the processing is permitted by applicable law.

We do not knowingly collect personal information from children in circumstances where parental or guardian consent is legally required and has not been obtained.

14. Third-Party Services

Our websites and applications may contain links to third-party websites, applications or services.

We are not responsible for the privacy, security or content practices of third parties. You should review the privacy policies of any third-party service before providing personal information.

15. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes to our services, legal obligations, technology or business practices.

Where appropriate, material changes will be communicated through our website, application, customer portal or another suitable communication method.

The date shown at the top of this policy indicates when it was last updated.

16. Contact

For privacy enquiries, requests or complaints, contact:

Contact
Privacy Officer
Company
Grasp IT Pty Ltd
Email
privacy@graspit.com.au