Privacy Policy
Last updated: 10 July 2026
Matter Desk Pty Ltd (ACN 697 017 502) (“Matter Desk”, “we”, “us”) provides an AI-powered legal workbench for Australian law firms. This Privacy Policy explains how we collect, use, store, and disclose personal information, and how it interacts with our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Who this policy applies to
This policy applies to personal information we handle about visitors to our website, prospective customers, individual users of the Service (lawyers, paralegals, support staff), administrators of a firm workspace, and people whose details appear in customer content uploaded by a firm.
2. What we collect
We collect the following categories of personal information:
- Account data: name, work email, role within the firm, profile preferences, and authentication credentials.
- Firm data: firm name, billing email, business address, ABN where supplied, and the configuration choices the partner administrator makes.
- Customer content: matter records, documents, notes, deadlines, draft correspondence, generated memos, search history, and other material a firm chooses to upload or generate inside the Service. This may include personal information about the firm’s clients, opposing parties, witnesses, or counterparties.
- Usage telemetry: which features the user interacts with, error reports, performance metrics, and similar operational signals. We use this to keep the Service reliable and to improve it. We do not include the contents of customer documents in usage telemetry.
- Payment data: Matter Desk does not store full card numbers. Our payment processor handles card capture and tokenisation. We retain a customer identifier, the last four digits of the card used, the card brand, and invoice history.
- Support communications: emails, in-app chat, and screen-share sessions when a firm asks us for help.
3. How we use it
We use personal information to:
- provide, maintain, and secure the Service;
- respond to research, drafting, and matter management requests submitted by users on behalf of the firm;
- manage subscriptions, billing, trials, invoices, and refunds;
- send service notifications (deadline reminders, billing notices, security alerts) and product updates the firm has opted in to;
- investigate misuse, enforce our terms, and meet legal and regulatory obligations including responses to lawful demands;
- improve the Service: aggregate, de-identified usage analysis to find rough edges and prioritise upgrades.
Matter Desk does not use customer content to train models that it owns, and we do not sell or rent personal information to advertisers or data brokers. Third-party AI handling is described below and in the current subprocessor schedule.
4. AI processing of customer content
AI-assisted research, analysis, and drafting send only the minimum relevant customer-content excerpts required for the requested feature to a third-party AI provider. That processing may occur outside Australia and is subject to the APP 8 safeguards described below.
Matter Desk does not use customer content to train models it owns. We do not promise provider zero retention or no training unless the applicable account controls and written provider terms have been independently verified.
Where a cited authority is not matched to a retrieved source record, the Service may return the phrase “Authority not verified”. A source-record match is provenance only; independent legal verification is required before relying on the output.
5. Where we store data
Customer databases, matter-document storage, exports, and primary operational records use Australian regions. AI processing is described separately above because it may occur outside Australia. Data in transit is protected by TLS 1.2 or higher; data at rest is encrypted with industry-standard ciphers. Access to production systems is gated by single sign-on, multi-factor authentication, and least-privilege role assignment.
Ancillary operational tools (such as error tracking, product analytics, payments, and email delivery) may process limited personal information outside Australia. Where a vendor does so, we take reasonable steps under APP 8 before disclosure, including due diligence, data minimisation, access controls, and review of available contractual and privacy terms.
6. Disclosure
We disclose personal information only:
- to the firm whose workspace the information lives in, scoped by the access controls the partner administrator configures;
- to our service providers (hosting, AI processing, payments, email delivery, error tracking, product analytics, customer support tooling) under their applicable service, privacy, and data-processing terms;
- to law enforcement or regulatory bodies where compelled by valid legal process, and only to the extent compelled. We will tell the affected firm wherever the law allows; and
- to a successor entity in the event of a corporate transaction (merger, acquisition, asset sale), under confidentiality obligations no less protective than this Policy.
7. Retention
We retain customer content while the firm maintains an active workspace and for the post-termination period stated in the applicable order form and current retention schedule. Deletion from backups follows the normal backup rotation. We retain account, billing, and audit records for the period required by Australian tax, anti-money-laundering, and consumer-protection law, typically seven years.
A firm may export customer content while its workspace is active and during any post-termination export window stated in its order form.
8. Your rights under the Privacy Act
Subject to limited exceptions in the Privacy Act, you can ask us to:
- tell you what personal information we hold about you;
- give you a copy of that information;
- correct information that is inaccurate or out of date;
- delete information where we no longer have a lawful basis to keep it; and
- stop sending marketing communications (you can also opt out via the unsubscribe link in any marketing email).
Send requests to privacy@matterdesk.ai. We respond within the period required by applicable law and aim to acknowledge requests promptly. If we cannot grant a request in full, we will tell you why.
If you are unhappy with how we have handled your personal information, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
9. Cookies and similar technologies
The Service uses essential cookies for authentication, session management, and CSRF protection. We use a small number of non-essential cookies and similar local-storage entries for product analytics and to remember preferences (theme, recently viewed matters). Non-essential cookies activate only after a user gives consent in the cookie banner.
10. Children
The Service is not intended for individuals under 18 and we do not knowingly collect personal information from minors. If you believe a minor has signed up, contact us so we can remove the account.
11. International users
The Service targets Australian law firms. Where personal information about residents of other jurisdictions is processed through the Service, we do so under the contractual instructions of the firm and rely on the safeguards described above. Individuals in the European Union or the United Kingdom can exercise the rights described in section 8, which align with the access, rectification, and erasure rights provided under the GDPR.
12. Changes to this policy
We may update this Privacy Policy from time to time. Material changes will be notified to the firm’s billing email at least 30 days before they take effect. The “last updated” date at the top of this page records the most recent change.
13. Contact
Matter Desk Pty Ltd (ACN 697 017 502) handles this policy. Privacy questions or complaints can be sent to privacy@matterdesk.ai. General questions can be sent to hello@matterdesk.ai.