Privacy Policy

Last updated 25 June 2026

This Privacy Policy explains how Geidi Pty Ltd handles personal information through the Geidi IT Portal at portal.geidi.com. We are committed to protecting your privacy and complying with the Australian Privacy Act 1988 (Cth) and, where applicable, the EU and UK General Data Protection Regulation (GDPR).

1. Who we are

In this policy, “Geidi”, “we”, “us” and “our” mean Geidi Pty Ltd, a company incorporated in Australia. Geidi is an IT managed services provider. The Geidi IT Portal (the “Portal”) is the software at portal.geidi.com through which we and our clients administer Microsoft 365 and related services.

This policy applies to the Portal. Our public website, geidi.com, and any separate engagement or services agreement may have their own terms.

2. The two capacities in which we handle data

We handle personal information in two distinct roles, and your rights differ depending on which applies:

  • As controller — for personal information about the people who sign in to and use the Portal (our own staff and operators, and the client administrators we authorise). Under the GDPR we are the data controller of this information; under the Privacy Act we are the APP entity responsible for it. This policy governs that information.
  • As processor / service provider — when we administer a client organisation’s Microsoft 365 tenant and on-premises directory on that organisation’s behalf, the personal information of that client’s end-users (employees, contacts, mailboxes, accounts) is controlled by the client organisation, not by us. We process it only on the client’s documented instructions and under our services agreement and any data processing terms with them. Under the GDPR we act as a data processor for that data. If you are an end-user of one of our client organisations, please direct privacy requests to your own organisation in the first instance; we will assist them as required.

3. Personal information we collect about Portal users

When you sign in to and use the Portal, we collect:

  • Identity and account data — your name, work email address, Microsoft Entra (Azure AD) object identifier and tenant identifier, your organisation, and your assigned roles and permissions. We obtain these through Microsoft Entra single sign-on (SSO) when you authenticate; we do not see or store your Microsoft password.
  • Authentication and session data — sign-in events, session tokens (stored in secure cookies), and multi-factor / authentication-method status used to operate and secure the Portal.
  • Usage, audit and security logs — records of actions you take in the Portal (for example, workflows you run and changes you make), together with timestamps, the affected user or resource, your IP address, request correlation identifiers, and security events (such as access attempts). We keep these for security, troubleshooting, audit and compliance.
  • Support information — information you submit through the support tools (for example a request you raise or a project you generate), and related correspondence.
  • Technical data — limited device and browser information necessary to deliver the service securely.

We do not seek to collect sensitive information (as defined in the Privacy Act, such as health, biometric or other special-category data) through the Portal, and we ask that you do not submit it.

4. Data we process on behalf of client organisations

On the instructions of our client organisations, the Portal accesses and processes data within their Microsoft 365 tenants and on-premises directories via the Microsoft Graph API and related interfaces. This can include directory data (names, usernames, email addresses, job titles, group memberships), mailbox and delegation settings, licensing and subscription data, conditional-access and Intune policy data, and similar administrative information. We process this data solely to provide the managed services requested by the client, we do not use it for our own purposes, and access is restricted to authorised operators and segregated per tenant using row-level security. The relevant client organisation is the controller of that data and determines how long it is retained within their tenant.

5. How we collect personal information

  • directly from you when you sign in or use the Portal;
  • from Microsoft Entra ID and the Microsoft Graph API when you authenticate or when we administer a tenant;
  • automatically through our logging, security and audit systems as you use the Portal; and
  • from our client organisations when they authorise you or instruct us.

6. Why we collect and use personal information (and our lawful bases)

We collect and use the personal information described above to:

  • authenticate you and provide, operate and maintain the Portal;
  • perform the managed IT services requested by us or our clients;
  • secure the Portal, detect and prevent misuse, and investigate incidents;
  • keep audit trails for accountability and compliance;
  • provide support and respond to your requests; and
  • comply with our legal obligations.

Where the GDPR applies, our lawful bases are: performance of a contract (providing the Portal and services to you or your organisation); our legitimate interests in operating, securing and improving the Portal (balanced against your rights); compliance with a legal obligation; and, where relevant, your consent. Under the Privacy Act we collect personal information that is reasonably necessary for these functions and use it for those purposes and directly related purposes you would reasonably expect.

We do not make decisions about you based solely on automated processing that produce legal effects or similarly significantly affect you.

7. Disclosure and our service providers

We do not sell your personal information. We disclose it only as needed to operate the Portal and provide our services, including to the following categories of service providers (sub-processors), who are bound to protect it:

  • Microsoft — identity (Entra ID / Azure AD), Microsoft 365, Microsoft Graph and Azure Automation, used for authentication and to administer tenants;
  • Google Cloud (Google LLC) — application hosting and infrastructure;
  • Supabase — managed PostgreSQL database hosting;
  • Cloudflare — DNS and edge network/security services;
  • Crayon / rhipe (PRISM) — Microsoft licensing and subscription management;
  • Plane — issue and work tracking, where used for support; and
  • professional advisers, and law-enforcement or regulators where we are legally required to disclose.

We may also disclose information to a client organisation about its own authorised users, and as part of any sale or restructure of our business (subject to confidentiality).

8. Overseas and cross-border transfers

Some of our service providers store or process data outside Australia. In particular, the Portal is hosted on Google Cloud in the asia-south1 (Mumbai, India) and us-central1 (United States) regions, and Microsoft operates a global infrastructure. Where we disclose personal information overseas, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. Where the GDPR applies, transfers outside the EEA/UK are made under an appropriate safeguard such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or an adequacy decision.

9. Cookies and similar technologies

The Portal uses strictly necessary cookies to keep you signed in and to secure your session. We do not use the Portal to serve advertising and we do not use third-party advertising or cross-site tracking cookies. Because these cookies are essential to the service, the Portal will not function correctly without them.

10. How we protect your information

We take the security of personal information seriously and apply measures including:

  • Microsoft Entra SSO and multi-factor authentication for access;
  • role-based access control and per-tenant row-level security so data is segregated and access is least-privilege;
  • encryption of data in transit (TLS) and secrets held in a managed secret store;
  • strict content-security and transport-security policies; and
  • audit logging, monitoring and access controls.

No system is completely secure, and we cannot guarantee absolute security, but we work to protect your information and to respond promptly to any incident.

11. How long we keep personal information

We keep personal information only for as long as necessary for the purposes described in this policy, including to provide the service, to meet our security, audit and legal obligations, and to resolve disputes. Audit and security logs are retained for the period required for accountability and compliance. When information is no longer required, we take reasonable steps to delete or de-identify it. Data we process within a client’s tenant is retained according to that client’s instructions and their own retention settings.

12. Your privacy rights

Under the Australian Privacy Act, you may request access to the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

Where the GDPR or UK GDPR applies, you also have the rights to: access; rectification; erasure (“right to be forgotten”); restriction of processing; data portability; objection to processing based on legitimate interests; and to withdraw consent at any time where processing is based on consent. You also have the right to lodge a complaint with a supervisory authority.

To exercise any of these rights, contact us using the details below. We will respond within the time required by law. If you are an end-user of one of our client organisations, we will refer your request to that organisation, which controls your data.

13. Data breaches

We maintain processes to detect, assess and respond to data breaches. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme, and any other regulator as required by law. Where we act as a processor for a client, we will notify the client without undue delay so they can meet their own obligations.

14. Direct marketing

The Portal is an administrative tool and we do not use it to send you marketing. Any service-related communications we send (such as security or operational notices) are necessary for providing the service.

15. Children

The Portal is intended for use by businesses and their authorised personnel. It is not directed at children and we do not knowingly collect personal information from children.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version here and revise the “Last updated” date above. Material changes will be communicated by reasonable means. Your continued use of the Portal after an update constitutes acceptance of the revised policy.

17. How to contact us

If you have a question, a request about your personal information, or a privacy complaint, contact our Privacy Officer:

We will acknowledge and investigate your complaint and respond within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC). If the UK or EU GDPR applies to you, you may also complain to the UK Information Commissioner’s Office (ICO) or your local European data protection authority.

Privacy Policy — Geidi