GrantMe Privacy Policy
Grant Me Australia Pty Ltd (ABN 57 699 140 657) trading as GrantMe (“GrantMe”, “we”, “us”, “our”).
Effective date: 14/09/2026 · Version 1.5
1. About this policy
GrantMe is a grant-management platform built for South Australian schools. This policy explains what personal information we collect, how we use and protect it, who we share it with, and the rights you have. It is written to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
By using GrantMe, the school and its authorised staff agree to the handling of personal information as described here.
This policy sits alongside our Terms of Service and, for schools with a subscription or pilot agreement, our Data Processing Agreement. Where this policy and the Data Processing Agreement differ on a data protection matter, the Data Processing Agreement applies.
2. What we collect
We deliberately collect as little personal information as possible. GrantMe is used by school staff to manage grants. It is not a student system.
Information you provide
- The email address and display name of each authorised staff user, and the access level their school gives them (used to identify the account and control what each person can see).
- School details: name, ABN, sector and state (used to match relevant grants).
- Grant application content that staff choose to enter or upload.
- School planning documents (such as a School Improvement Plan or Annual Report) that staff choose to upload. These documents, and the text extracted from them, are stored and may be read by our AI system to suggest content for the school’s profile (such as mission and vision statements). Suggestions are never saved automatically. A staff member must review and approve them first.
Information we generate
- Records of AI interactions, kept for auditing and quality review.
- Security and audit logs (IP addresses in these logs are hashed; we do not store names or emails in them).
- A session cookie that keeps you securely signed in. GrantMe does not use advertising or tracking cookies.
- Aggregated, de-identified statistics about how the service is used, which help us operate, secure and improve it. These never identify a school, an individual, or the content of any application.
3. What we do NOT collect
To keep our privacy footprint low, GrantMe does not collect:
- Any student information, including names, student identifiers or records.
- Teacher or staff personal details beyond the account holder’s login email, display name and access level.
- Financial or banking details.
- Health information or biometric data.
If personal information we do not need is uploaded to GrantMe, we destroy or de-identify it as soon as practicable, where lawful to do so.
4. How we use your information
We use personal information only to:
- Provide and operate the GrantMe service (matching grants, managing applications and acquittals).
- Secure the platform, prevent misuse and maintain audit records.
- Respond to support requests and communicate about the service.
- Meet our legal and compliance obligations.
We do not sell personal information. We do not use school data to train AI models, and our AI provider is contractually prohibited from training on customer data.
5. Marketing communications
We will only send you sales, marketing or promotional messages if you opt in. You can withdraw consent at any time. This does not affect essential service messages (for example, security notices, outage alerts or renewal reminders), which we may still need to send.
6. Who we share it with
We share personal information only with the service providers that help us run GrantMe, each under a contract requiring them to protect it and to comply with applicable privacy law. Your account data is hosted in Australia.
| Provider | What they process | Location |
|---|---|---|
| Google Cloud (Firebase, Cloud Run, Firestore, Firebase Authentication, Cloud Storage) | Hosting, database, sign-in, file storage and logging (all account data) | Sydney, Australia (australia-southeast1), with all resources pinned to Australia |
| Amazon Web Services (Bedrock) | AI drafting and review: your school profile information, project information, the text of documents you upload, and the application drafts the AI helps write | Sydney, Australia (ap-southeast-2), using an inference configuration restricted to Australian regions |
| Microsoft (Entra ID) | Sign-in, where your school chooses to use its own Microsoft account. Your email address and the authentication response only. No school content. | Global (Microsoft Entra). Where you use your school’s own Microsoft tenant, Microsoft handles this under your school’s own arrangements with Microsoft. |
| Cloudflare | Security, traffic protection and content delivery. Request metadata only, no account content | Global edge network |
| Upstash | Rate limiting, to protect the service from abuse. Hashed request and user identifiers only | Sydney, Australia (ap-southeast-2) |
| Vision6 (Constant Contact) | Transactional email (invitations, notifications) and the school-facing newsletter. Recipient email addresses and message content | Australia |
Beyond these providers, we disclose personal information only where you have consented, where it is required or authorised by law or a court/tribunal order, or where it is reasonably necessary for an enforcement body’s activities.
Sharing a successful application with other schools (optional, and off unless you choose it)
GrantMe maintains a library of anonymised examples drawn from successful grant applications, used to help other schools write better applications. Nothing your school writes goes into that library unless a school administrator expressly chooses to contribute a specific application. There is no blanket or account-level consent, and declining has no effect on your use of GrantMe.
If your school does choose to contribute an application:
- it is automatically anonymised first, to remove school names, individual names, monetary amounts and other identifying details;
- a person reviews it before it becomes available to anyone;
- no information identifying your school, your staff or your projects is ever made available to another school; and
- you can withdraw your consent at any time and we will remove it.
7. Sending information overseas
Your account data is stored in Australia (Sydney). Two limited exceptions apply:
- Our security and content-delivery provider, Cloudflare, operates a global network, so limited request metadata (which contains no account content) may be handled outside Australia in the course of protecting the service.
- Where your school signs in using its own Microsoft or Google account, that sign-in exchange is handled by that provider on its own infrastructure.
We take reasonable steps to ensure any overseas handling is consistent with the Australian Privacy Principles. Aside from these two exceptions, we do not transfer school data outside Australia without your school’s prior written agreement.
8. How we protect it
We apply layered technical and organisational safeguards, including:
- Encryption of data in transit and at rest.
- Multi-factor authentication on every account. There is no password-only access.
- Role-based access, so each school can only see its own data, enforced at the database layer as well as in the application.
- Application-layer protections including request validation and rate limiting on every request, and per-school data isolation enforced at the database layer.
- Network-level protection against malicious and denial-of-service traffic through Cloudflare, in front of the service.
- Continuous audit logging, automated security scanning of our code and dependencies, and annual review of our privacy and security controls.
Further detail, including our current independent assurance position, is on our Security page.
9. How long we keep it
We keep personal information only as long as needed to provide the service and to meet legal obligations.
When your school stops using GrantMe, we make your data available for export for 30 days, and then delete or de-identify account data within 30 days of the end of that export period.
For resilience, encrypted backups are retained for up to 30 days, so information you delete may persist in secure backups for that period before being overwritten. On request, we provide written confirmation once data has been deleted.
Security and audit logs are retained for at least 12 months, so that we can investigate security incidents. These logs contain hashed IP addresses, not names or email addresses.
10. Your rights
You can ask us to give you access to, correct, or delete the personal information we hold about you. We handle these requests free of charge and respond within 30 days, usually much sooner. Account administrators can also export and delete data directly from the GrantMe dashboard at any time.
To make a request, contact us using the details below.
11. Complaints
If you believe we have mishandled your personal information, please contact us first so we can try to resolve it. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
12. Contact us
Privacy Officer
Grant Me Australia Pty Ltd
Email: privacy [at] grantme.au
Postal address: Angaston SA 5353
13. Changes to this policy
We review this policy at least annually and whenever our practices change. We will publish any updated version on our website and update the effective date above. Where changes are significant, we will take reasonable steps to notify affected schools.