1. Our role
We currently provide services to Australian agencies. We handle information about website visitors, account users and people whose records an agency manages through Delegate. Depending on the work involved, these people include owners, tenants, applicants, buyers, sellers, suppliers and trades.
An agency generally decides what information it needs for its property services and which of its users may access it. We handle that information to provide the agreed services. We also handle information for our own customer relationships, enquiries, support, service administration and security. The agency's privacy notice explains its separate activities. Our involvement does not remove our own obligations under applicable law.
2. Information we collect and hold
The information involved depends on how you use the services and the work the agency carries out. It can include:
- names, contact details, business details, roles, enquiries, support correspondence and communication preferences;
- account details, agency membership, access permissions, authentication and account activity;
- property, ownership, tenancy, application and workflow records, including relevant identity, financial and suitability information, reference responses and uploaded documents;
- messages, selected recipients, subjects, attachments, delivery information, and email open and link-click events;
- documents and signing evidence, including the signer's name, recipient details, IP address, browser information and signing activity; and
- session, device-recognition, security and technical information needed to operate and protect the service.
Personal information may be contained in a file or a record about a property or business. Please do not send unrelated identity documents, bank statements, health information, government identifiers, passwords or card details through general enquiries or support messages. Where sensitive information is necessary for a particular service, its collection and handling must have the consent or other authority required by law.
3. How we receive information
We receive information when you use the website or platform, make an enquiry, complete a form, submit a portal request, communicate with us or upload a document. We also receive information from agencies, authorised users, references and other people involved in the relevant work, and through customer-authorised data syncing.
For the agreed trust-system sync, the customer creates a dedicated user in its external trust-account system. That arrangement uses multifactor authentication. The information available to the sync depends on the agreed service and the permissions granted.
If you choose to book a demo, our booking page links to Google’s appointment scheduling service. Google collects your name, email address, agency name and discussion points, and handles email verification, appointment invitations, meeting details and configured reminders. Delegate receives the appointment in its Google Calendar and uses the booking information to arrange and provide the demo. The booking form is hosted by Google; its privacy policy explains its handling of information.
You may make a general enquiry anonymously or under a pseudonym where practicable. Identifying information may be needed to provide an account or service, verify your authority, or respond to a request about your records. If required information is not supplied, we may be unable to carry out that request.
4. Why information is used
Information is used to provide and administer agreed services, organise agency records and workflows, deliver authorised communications, respond to enquiries and support requests, manage access, investigate errors or security issues, and meet applicable legal requirements. The purpose of an agency's use of its records is determined by that agency's services and lawful instructions.
We also use de-identified information to improve Delegate and provide industry support. For those purposes, we use information with identifying details removed, rather than identifiable agency, owner or tenant records. De-identification is a privacy measure, not a guarantee that information can never be re-identified.
This policy does not provide blanket permission for unrelated advertising, the sale of personal information or training general-purpose AI models. Any new purpose must have its own lawful basis and any notice or permission required by law.
5. Who receives information
Information is available to authorised users and relevant participants according to access permissions and the workflow involved. A message, document, request or approval may be shared with the recipients selected by the sender or the relevant workflow. Check recipients and attachments before sending.
Delegate personnel access information to carry out their work on the agreed services. Our Philippines-based team accesses customer information through Delegate. That team does not directly access customers' external trust-account systems.
We use service providers for hosting, storage and email delivery. MailerSend handles email sender and recipient details, subject lines, message content and selected attachments for delivery. Inbox and signing workflows can include uploaded files or completed signed documents. MailerSend also processes delivery and interaction information. Its own privacy policy explains its handling of service and account information.
Relevant information may also be disclosed where authorised by you or the customer, to advisers where needed for the relevant matter, or where disclosure is required or permitted by applicable law. A recipient such as an agency, landlord, contractor or reference may have separate responsibilities for information it receives.
6. Overseas handling
Personal information can be accessed and processed outside Australia. This includes our team's access in the Philippines and processing by MailerSend and its providers. MailerSend's published data-processing terms and provider list identify a data centre in Belgium and group providers in Ireland, the United States and Poland, and provide for international processing.
These locations do not mean every item is sent to every listed country. Overseas handling depends on the service involved. We do not represent that all storage, provider copies, backups or support access remain in Australia. Applicable cross-border privacy requirements continue to apply; this policy does not ask you to waive them.
7. Cookies and email tracking
The platform uses a session cookie for sign-in and access control. An optional remembered-device cookie can last up to seven days. Browser storage is also used for interface preferences. Blocking essential cookies can prevent sign-in or other requested functions.
Inbox emails and newsletters sent through the supported MailerSend functions use open and link-click tracking. This can record interaction events associated with a recipient, message, event time and clicked link. Email software can affect whether an open is detected. Sign-in emails use a separate delivery path with open and click tracking disabled.
You can manage cookies and remote images through your browser or email software. Those settings may affect functionality and do not necessarily prevent link-click tracking. Use a newsletter's unsubscribe link to stop those newsletter messages, or contact the sender about its communications.
Fonts on the homepage and Insights pages are served by Delegate.
8. Security and retention
Delegate uses account and agency permissions, protected session cookies and access checks to control use of the platform. The dedicated external trust-system sync account uses multifactor authentication; this statement does not describe every other account's settings. No online service can guarantee complete security. Contact us promptly if you suspect unauthorised access or a privacy incident.
Our policy is to delete agency customer data 30 days after its subscription is cancelled. The applicable service agreement determines when cancellation takes effect and the customer's export arrangements. This policy does not extend a shorter agreed deletion deadline or reduce an agreed export right.
Particular information may need to be retained where the law requires it, including records needed to meet legal obligations. Such retention is limited to the relevant purpose. Information held by an agency or another independent recipient is subject to that party's obligations. Contact us about cancellation, data export, deletion or any particular category of information.
9. Access, correction and complaints
Contact our privacy contact at support@delegatemywork.com.au to request access to or correction of your personal information, raise a privacy concern, or ask about deletion. Include enough detail to identify the information or concern and how you would like us to respond. We may need to verify your identity and authority without collecting more information than necessary.
If information is held for an agency, we may direct the relevant part of your request to that agency and assist as required. We remain the contact for Delegate's own handling. Access, correction and any refusal or permitted charge are subject to applicable law; a commercial data-export fee does not determine your statutory privacy rights.
For a complaint, tell us what happened and the outcome you seek. We will review the issue, seek relevant information and respond with the outcome or next steps within a reasonable period, subject to any applicable legal deadline. If the matter is not resolved, you can contact the Office of the Australian Information Commissioner, subject to its complaint process and jurisdiction.
10. Policy updates
The effective date and version appear on this page. We update this policy to reflect changes to the service or our handling of information. An update does not itself provide consent for a new purpose or amend a customer's signed service agreement. Any additional notice or permission required by law remains necessary.
