Privacy Policy
Last updated: 19 September 2026
1. Overview
Matter Desk Pty Ltd (ACN 697 017 502) ("we", "us", "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information, including the limits of the arrangements currently verified. It is not a certification of compliance with the Privacy Act 1988 (Cth) or the Australian Privacy Principles (APPs).
Read these data-handling limits before providing confidential matter information. Contact us with questions about the arrangements relevant to your firm.
2. Information we collect
We may collect the following types of personal information:
- Account information: name, email address, password hash, firm name, role, and billing details.
- Matter data: matter descriptions, documents you upload, AI-generated outputs, deadlines, time entries, and correspondence metadata.
- Usage data: pages visited, features used, timestamps, device type, browser, and IP address.
- Support communications: messages you send to our support team.
3. How we use your information
We use your personal information to:
- Provide, operate, and improve Matter Desk.
- Process AI-assisted legal research, document analysis, and memo generation linked to your matters.
- Send transactional emails (account confirmation, password resets, billing receipts).
- Monitor system security and prevent abuse.
- Comply with legal obligations.
4. Australian-region customer storage
Primary customer databases and matter-document storage use Australian regions. This does not establish Australian storage or processing for every operational record or service provider. AI processing is described separately below.
5. AI processing, provider controls, and APP 8
AI-assisted research, analysis and drafting send relevant matter context to a third-party AI provider; processing and storage may occur outside Australia. Matter Desk does not use customer content to train models it owns. Matter Desk does not claim provider zero-retention or no-training until the applicable account controls and written terms are independently verified.
Payment and email services may also involve personal information being processed or stored outside Australia. Their operational logs are not covered by the Australian primary-storage statement above. Product analytics and error-tracking services are not currently configured; this policy does not imply that they are operating with verified Australian data handling.
Assessment of overseas providers' locations, terms and controls, including the steps required under Australian Privacy Principle 8 (APP 8) where applicable, is not yet complete. This policy is not an assurance that all overseas-provider safeguards have been implemented or independently verified. Contact us to confirm the arrangements relevant to your firm before providing confidential matter information.
6. Disclosure of personal information
We do not sell your personal information. We may disclose it to:
- Third-party service providers who assist in operating Matter Desk (as described above).
- Law enforcement or regulatory bodies where required by law or court order.
- Professional advisers (lawyers, accountants) for legitimate business purposes.
7. Data security
Primary service controls include encryption in transit (TLS), encryption at rest, row-level security on database access, signed URLs for document access, and product records for currently instrumented substantive actions. These controls do not establish the safeguards of every external service or an independent security certification.
8. Data retention and deletion
You can delete your account from inside the app. Open Settings, then Profile, then Delete account. The screen shows what is removed and what your firm keeps before anything happens.
When you delete your account, your sign-in, email address, password, name and profile details are removed straight away and you are signed out on every device. Your notifications, search history and private AI chats go with them.
Records a law practice has to keep stay with the firm whose workspace they belong to. Matters, documents, time entries, notes and audit history remain in that firm’s client files, without your contact details and without the device and network details recorded against your actions. Text you typed into documents, notes and messages is kept as you wrote it, so your name can still appear inside that text.
If a task you started was already running when you delete your account, it can finish and leave one record behind, which is retained without your contact details and without the device and network details recorded against your actions.
A Principal can close a firm workspace in the same place. Closing a workspace cancels the subscription immediately and removes everyone’s access. A closed workspace is kept securely, is not visible to anyone, and can be restored on request for 60 days. A workspace with no matters or documents is deleted straight away. We will publish the deletion schedule for closed workspaces in this policy once it is in force.
Billing records are kept as tax law requires. Backup copies expire on our normal backup cycle rather than being removed on the day of a request.
Contact us to confirm retention, export and deletion arrangements for your workspace, including backups and external services. A complete retention and deletion schedule has not yet been verified. Applicable legal obligations may require some records to be retained. This policy does not set a fixed deletion date.
9. Your rights
You can:
- Request access to the personal information we hold about you.
- Request correction of inaccurate or outdated information.
- Delete your account yourself in the app, at Settings, then Profile, then Delete account, or ask us to delete your personal information.
- Complain to the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs.
10. Cookies and analytics
We use essential cookies for authentication and session management. We may use analytics tools to understand usage patterns. You can control cookie preferences through your browser settings.
11. Notifiable data breaches and incident response
The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth) sets assessment and notification requirements where it applies. The summary below does not establish that incident-response controls have been independently verified.
11.1 Scope: what triggers NDB obligations
The NDB scheme applies when an "eligible data breach" occurs: that is, unauthorised access to, unauthorised disclosure of, or loss of personal information that we hold, where it is likely to result in serious harm to any individual whose information is involved. Serious harm includes financial loss, physical harm, serious psychological distress, damage to reputation, or identity theft. Breaches involving legal professional privilege material, sensitive financial data, or confidential matter documents are assessed as high-risk.
11.2 Assessment, 30-day statutory window
Upon becoming aware of circumstances that suggest an eligible data breach may have occurred, we will take reasonable steps to assess whether a notifiable data breach has in fact occurred. Where s 26WH applies, all reasonable steps must be taken to complete the assessment within 30 calendar daysof becoming aware of the grounds for suspicion. We begin assessment promptly and manage the response according to the circumstances, statutory requirements, and current incident-response process.
11.3 OAIC notification
Where there are reasonable grounds to believe an eligible data breach occurred and no exception applies, notification to the Office of the Australian Information Commissioner (OAIC) and affected individuals is required as soon as practicable. The statement must include:
- The identity and contact details of Matter Desk and our Privacy Officer.
- A description of the breach: what happened, how it was discovered, and when.
- The kinds of personal information involved (e.g. account details, matter documents, billing data).
- Recommended steps individuals can take in response to the breach.
11.4 Individual notification
Individual notification follows the applicable NDB requirements, including any applicable exceptions. Each notification will include:
- A plain-language description of the breach and the circumstances in which it occurred.
- The types of personal information involved and its likely sensitivity.
- Specific, practical steps you should take to protect yourself (e.g. change credentials, monitor financial accounts, place a credit alert).
- Contact details for our Privacy Officer and the OAIC (1300 363 992 / www.oaic.gov.au) for further assistance.
Where it is not reasonably practicable to notify every affected individual directly, we will publish a prominent notice on our website and notify via in-app alert where the individual's account remains accessible.
11.5 Incident response steps
- Contain: Immediately revoke affected credentials, rotate secrets, isolate affected systems, and block unauthorised access vectors.
- Assess: Determine the nature and scope of the breach, the personal information affected, and the likelihood of serious harm.
- Notify: Report to the OAIC and notify affected individuals as soon as practicable after the assessment concludes that an eligible data breach has occurred, in accordance with Part IIIC of the Privacy Act 1988 (Cth).
- Remediate: Patch the root-cause vulnerability, deploy additional controls, and restore affected systems from clean backups.
- Review: Conduct a post-incident review, update controls and procedures, and retain incident records.
11.6 Record-keeping
Incident record-keeping and retention arrangements require verification alongside the response process. This policy does not promise a fixed incident-record retention period. Contact us for the arrangements relevant to your firm.
If you believe your data may have been compromised, or you wish to report a suspected security incident, contact us immediately at security@matterdesk.ai. You may also contact the OAIC directly at www.oaic.gov.au or on 1300 363 992.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notification. Review the updated policy before relying on a data-handling assurance.
13. Contact us
If you have questions about this Privacy Policy or wish to exercise your rights, contact us at privacy@matterdesk.ai.
See also: Terms of Service | Compliance and Security