← Back to GroupDesk

Privacy Policy

Last updated: August 2026

GroupDesk ("we", "us", "our") provides club and community group management software to organisations across Australia. This policy explains how we collect, use, store and protect personal information through the GroupDesk platform. It should be read together with our Terms of Service.

1. What information we collect

When your organisation uses GroupDesk we may collect:

2. Who owns this data

Your organisation owns all data entered into GroupDesk. We act as a data processor on your behalf. We do not claim ownership of your members' information, financial records, documents or any other content you enter into the platform.

3. How we use your information

We use the information collected to:

We do not use your organisation's data, or your members' personal information, for advertising or for any purpose unrelated to providing the service.

4. Where your data is stored

GroupDesk is hosted on secure servers located in the United States, operated by our hosting provider. This means that data entered into the platform is transferred to and stored in the United States. We remain accountable for the protection of this information in accordance with the Australian Privacy Principles, and we take reasonable steps to ensure our hosting provider handles it securely.

Transactional emails (such as password resets, renewal reminders and event notifications) are sent via Brevo, whose infrastructure processes data in the European Union.

5. How we protect your data

We take reasonable technical and organisational measures to protect your data, including:

No method of electronic storage or transmission is 100% secure. While we strive to protect your information, we cannot guarantee absolute security.

6. Data breach notification

If a data breach occurs that is likely to result in serious harm to individuals whose information we hold, we will notify affected organisations without undue delay, and will notify affected individuals and the Office of the Australian Information Commissioner where required, consistent with the Notifiable Data Breaches scheme under the Privacy Act 1988.

7. Data sharing

We do not sell, rent or trade your organisation's data to third parties. We may share information with:

8. Member data entered by your organisation

Each organisation using GroupDesk is responsible for ensuring it has appropriate consent to store and process the personal information of its own members within the platform. GroupDesk provides the tools; your organisation controls what data is entered and how it is used in accordance with your own privacy obligations.

9. Information about children

Many community organisations have members under the age of 18, and organisations may enter information about junior members into GroupDesk. This information is collected and controlled by your organisation, with consent obtained from parents or guardians as required. We apply the same security protections to all member information regardless of age, and we do not use information about any member — junior or otherwise — for any purpose other than providing the platform.

10. Your rights

Under the Australian Privacy Act 1988, you have the right to access and correct personal information we hold about you. To exercise these rights, contact us at support@groupdesk.com.au. If you are a member of an organisation that uses GroupDesk, your first point of contact for access or correction of your membership information is your organisation, as it controls the data entered into the platform. We will assist organisations to respond to such requests.

11. Complaints

If you believe we have mishandled your personal information, please contact us at support@groupdesk.com.au and we will investigate and respond within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

12. Data retention

We retain your organisation's data for as long as your account remains active. If you cancel your subscription, we retain your data for 30 days to allow for export, after which it is permanently deleted from our live systems unless retention is otherwise required by law. Deleted data may persist in encrypted backups for a further limited period until those backups are cycled out, after which it is unrecoverable.

Data entered during a free trial that does not convert to a paid subscription is retained for 30 days after the trial ends, then deleted on the same basis.

13. Cookies

GroupDesk uses essential session cookies required for login functionality. We do not use third-party advertising or tracking cookies.

14. Changes to this policy

We may update this privacy policy from time to time. Material changes will be communicated to active subscribers via email before they take effect.

15. Contact us

For any privacy related questions or to exercise your rights under this policy, contact us at support@groupdesk.com.au.