1. Introduction
This Privacy Policy explains how we collect, use, disclose and protect your information when you use:
- Our websites
- Web applications
- Mobile and desktop applications
- Application programming interfaces (APIs)
- Customer portals
- Online services
We process personal information in accordance with the General Data Protection Regulation (EU) 2016/679 (GDPR), the UK GDPR and other applicable privacy laws.
2. Data Controller
- Company
- Grasp IT Pty Ltd
- Address
- [Company Address]
- privacy@graspit.com.au
- Telephone
- [Phone Number]
Data Protection Officer
Where applicable, enquiries for our Data Protection Officer may be sent to:
3. Information We Collect
Depending on how you use our services, we may collect the following categories of information.
Personal Information
- Name
- Company name
- Job title
- Email address
- Telephone number
- Postal address
- Username
- Encrypted or securely hashed password information
- Profile photographs, where voluntarily provided
Account Information
- User ID
- Roles
- Permissions
- Group memberships
- Authentication settings
Technical Information
- IP address
- Browser type
- Device information
- Operating system
- Screen resolution
- Language preferences
- Time zone
Usage Information
- Login history
- Pages viewed
- Features used
- Error logs
- Session duration
- Clickstream information
Uploaded Content
Where you choose to upload files, we may store:
- Documents
- Images
- Audio files
- Video files
- Other files necessary to provide the service
4. How We Collect Information
We collect information when you:
- Register an account
- Purchase products or services
- Contact customer support
- Submit forms
- Upload files
- Use our applications
- Subscribe to newsletters
- Use our APIs
- Enable optional features
Some information is collected automatically using cookies and similar technologies.
5. Lawful Basis for Processing
Under the GDPR, we process personal information under one or more of the following lawful bases.
Consent
We may rely on your consent for optional processing, including:
- Marketing emails
- Optional cookies
- Newsletter subscriptions
Contract
We process information where necessary to provide products or services that you have requested or to take steps before entering into a contract.
Legal Obligation
We process information where necessary to comply with tax, accounting, regulatory and other legal requirements.
Legitimate Interests
We may process information where necessary for our legitimate business interests, provided those interests do not override your rights and freedoms. These interests may include:
- Improving our services
- Security monitoring
- Fraud prevention
- System administration
- Customer support
6. How We Use Your Information
We may use personal information to:
- Provide and operate our services
- Authenticate users
- Manage user accounts
- Process payments
- Deliver purchased products or services
- Improve application performance
- Provide technical and customer support
- Send service-related notifications
- Prevent fraud
- Detect and respond to security threats
- Meet legal and regulatory obligations
- Generate analytics
- Maintain security and audit logs
7. Automated Decision Making
We do not make decisions based solely on automated processing that produce legal or similarly significant effects unless the processing is:
- Required or authorised by law
- Necessary to enter into or perform a contract
- Based on your explicit consent
8. Sharing Information
We may share personal information with trusted service providers and other parties where necessary, including:
- Hosting providers
- Payment processors
- Email delivery providers
- Cloud storage providers
- Analytics providers
- Professional advisers
- Legal or regulatory authorities where required
9. International Transfers
Where personal information is transferred outside the United Kingdom or European Economic Area, we implement appropriate safeguards where required. These may include:
- Standard Contractual Clauses
- International Data Transfer Agreements
- Adequacy decisions
- Approved certification or transfer mechanisms
- Other legally recognised safeguards
10. Data Retention
We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, including legal, accounting, security and reporting requirements.
Typical retention periods may include:
| Data Category | Typical Retention Period |
|---|---|
| Customer accounts | For the duration of the account and a reasonable period after closure |
| Support requests | Up to 7 years |
| Financial records | 7 years or as legally required |
| Audit logs | 12 to 24 months |
| Marketing consent records | Until consent is withdrawn and for a reasonable period afterwards |
| Security logs | Up to 24 months |
Actual retention periods may vary depending on contractual, legal, regulatory, operational or security requirements.
11. Security
We implement appropriate technical and organisational measures designed to protect personal information against loss, misuse, unauthorised access, alteration or disclosure.
These measures may include:
- Encryption
- HTTPS and TLS
- Secure password hashing
- Multi-factor authentication
- Role-based permissions
- Access logging
- Firewalls
- Regular security updates
- Backup and recovery procedures
- Vulnerability monitoring
No method of transmission or storage is completely secure. However, we take reasonable steps to reduce the risk of unauthorised access, disclosure or loss.
12. Your GDPR Rights
Subject to applicable law, you may have the right to:
- Access your personal information
- Correct inaccurate or incomplete information
- Request deletion of your personal information
- Restrict certain processing activities
- Object to certain processing activities
- Withdraw consent at any time
- Request data portability
- Lodge a complaint with an applicable supervisory authority
To make a privacy request, contact: privacy@graspit.com.au .
We may need to verify your identity before responding to a request.
13. Children's Privacy
Our services are not intended for children under 16 unless the relevant service expressly states otherwise and the processing is permitted by applicable law.
We do not knowingly collect personal information from children in circumstances where parental or guardian consent is legally required and has not been obtained.
14. Third-Party Services
Our websites and applications may contain links to third-party websites, applications or services.
We are not responsible for the privacy, security or content practices of third parties. You should review the privacy policies of any third-party service before providing personal information.
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes to our services, legal obligations, technology or business practices.
Where appropriate, material changes will be communicated through our website, application, customer portal or another suitable communication method.
The date shown at the top of this policy indicates when it was last updated.
16. Contact
For privacy enquiries, requests or complaints, contact:
- Contact
- Privacy Officer
- Company
- Grasp IT Pty Ltd
- privacy@graspit.com.au