Privacy Policy
How Workshop Software Pty Ltd collects, uses, discloses and protects personal information
Effective date: 8 November 2026
Who we are and who this policy covers
Workshop Software Pty Ltd, ABN 72 165 417 916 (Workshop Software, we, us, our) provides workshop management software to automotive, fleet and related trade businesses around the world. Our registered office is Suite 2305, 4 Daydream Street, Warriewood NSW 2102, Australia.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where we handle personal information of people in New Zealand, the United Kingdom, the European Economic Area or the United States, the additional sections at the end of this policy also apply.
Capitalised terms such as Service, Customer, User, AI Feature and Third Party Service have the meaning given in our Subscription Agreement. This policy explains how we handle personal information about three groups of people. The rules that apply depend on which group you are in.
| Who you are | Examples | Our role |
|---|---|---|
| Customers and Users | Owners, managers and staff of a workshop or fleet business that subscribes to Workshop Software, and people who sign up for a free trial | We decide how and why your information is handled. We are the “APP entity” or “controller”. |
| End Customers of our customers | Vehicle owners, fleet operators and other people whose details a workshop enters into Workshop Software to run its business | The workshop decides how and why your information is handled. We process it on the workshop’s instructions as its service provider or “processor”. The workshop’s own privacy policy governs its use of your information. |
| Website visitors and prospects | People who browse workshopsoftware.com, download a guide, request a demo, contact us or attend an event | We decide how and why your information is handled. We are the “APP entity” or “controller”. |
If you are an End Customer of a workshop that uses Workshop Software and you want to access, correct or delete your information, or ask how it is used, please contact the workshop directly. We will help the workshop respond and will forward relevant requests to it.
1. The kinds of personal information we collect
Customers and Users
- Identity and contact details: name, business name, ABN or business number, role, email address, phone number, business address.
- Account details: username, login credentials (we never store your password in readable form), User permissions, preferences and settings, communications with our support team.
- Billing details: billing contact, billing address, plan and add-ons, invoices, payment history and the last four digits of your payment card. We do not store full card numbers or keep them in our records. Card payments are processed by our payment processors.
- Usage and device information: how you use the Service, features used, pages viewed, IP address, browser and device type, operating system, log data, error reports and approximate location derived from IP address.
- Marketing information: your marketing preferences, responses to campaigns, webinar and event registrations, and information you give us in surveys or reviews.
End Customers of our customers (processed on the workshop's behalf)
- Contact and identity details entered by the workshop: name, phone, email, address, company name.
- Vehicle details: registration, VIN, make, model, odometer, service history, inspection results, images and notes recorded against a job.
- Transaction details: quotes, jobs, invoices, payments and payment status, and messages exchanged with the workshop through the Service.
- Any other information the workshop chooses to record. We ask workshops not to record sensitive information (such as health information) unless they need it and are permitted to.
Website visitors and prospects
- Details you give us through forms, chat, email or phone: name, business name, email, phone, country, the topic of your enquiry, and the content of your message.
- Technical and analytics information collected by cookies and similar technologies, described in section 8.
1.1 We do not collect government identifiers such as tax file numbers or driver licence numbers about Customers or Users, and we ask workshops not to enter them into the Service unless the law requires it for their business.
2. How we collect personal information
2.1 Directly from you, when you create an account, use the Service, contact support, fill in a form on our website, register for a webinar or event, or speak with our sales or customer success teams.
2.2 From your business, where your employer or the business you work for adds you as a User.
2.3 Automatically, through the Service and our website, using log files, cookies and similar technologies described in section 8.
2.4 From third parties, such as our resellers and partners who refer you to us, publicly available business registers, and Third Party Services you connect to the Service (for example your accounting platform), where the integration sends us information about you or your business.
2.5 End Customer information is collected by the workshop, not by us. The workshop enters it into the Service or imports it, and in some cases End Customers provide it directly through a feature that the workshop has enabled, for example online bookings.
2.6 If you give us personal information about someone else (for example a colleague or a customer), you must have the right to do so and must tell them about this policy where required.
2.7 If your business applies to take card payments from its customers through the Service, the payment processor collects information about your business and about the people who apply for it or act on its behalf, such as identity and verification details and device and log-in information, directly from you. The processor uses that information to verify identity, meet its legal obligations and prevent fraud, and handles it under its own privacy policy.
3. Why we collect, hold and use personal information
3.1 We collect, hold and use personal information about Customers, Users, website visitors and prospects for the following purposes:
- to provide, operate and support the Service, set up and manage accounts, authenticate Users and respond to requests;
- to process payments, issue invoices and manage subscriptions;
- to communicate with you about the Service, including service notices, security alerts, changes to our terms and renewal reminders;
- to provide customer success, onboarding and training;
- to respond to enquiries, demo requests and support tickets;
- to send marketing communications about our products, features, events and offers where you have agreed to receive them or where the law otherwise permits, and to measure how those communications perform;
- to understand how the Service and our website are used, to fix problems and to improve, develop and test our products, including AI Features;
- to detect, investigate and prevent fraud, security incidents, misuse and breaches of our terms;
- to comply with law, including tax, accounting and record-keeping obligations, and to respond to lawful requests from regulators and law enforcement; and
- to establish, exercise or defend legal claims.
3.2 We use End Customer information only on the instructions of the workshop, to provide the Service to it, and as set out in the Data Processing Addendum. This includes storing it, displaying it to the workshop’s Users, sending messages the workshop chooses to send, processing payments the workshop takes, sharing it with Third Party Services the workshop has connected, and creating de-identified and aggregated data as described in section 5.
3.3 We will not use or disclose personal information for a purpose other than the one it was collected for unless the other purpose is related to the primary purpose (or directly related, for sensitive information) and you would reasonably expect it, you have consented, or the law permits or requires it.
4. Artificial intelligence and automated decision-making
4.1 AI Features in the Service. The Service may include features that use artificial intelligence (AI Features) to draft and summarise text, organise and classify information, analyse business data and present insights, and respond to questions from Users. We take reasonable steps to make it clear in the Service when a feature relies on an AI system, and we describe individual AI Features in our help documentation. The AI Features Addendum to our Subscription Agreement describes these categories and sets out how data is handled. Its commitments apply to every AI Feature.
4.2 How AI Features use personal information. When a User activates an AI Feature, the information needed for that task, drawn from a defined list of fields permitted for that feature (which may include End Customer information such as a customer name or vehicle details recorded in a job), is sent to an AI model to generate a result. AI models are provided by third-party AI providers under contracts that require them to keep the information confidential, to delete it within 30 days (subject to limited legal and safety exceptions described in our AI Features Addendum) and prohibit them from using it to train their models. Our AI providers currently process information in the United States. They are identified in the sub-processor list in our Data Processing Addendum. We do not use personal information to train our own AI models.
4.3 Human review. AI Features produce suggestions and drafts. We design AI Features so that a person, not the AI system, makes the decision, except for a feature that a workshop has chosen to enable to act automatically, which the workshop configures and reviews.
4.4 Automated decision-making statement. This section describes how computer programs are used in decisions that could reasonably be expected to significantly affect an individual’s rights or interests. (a) Payments: our payment processor screens card transactions for fraud using card, transaction and device information. A failed payment leads to a payment failure notice under our Subscription Agreement and, if it remains unpaid after the notice period, to suspension of access until it is paid. You can ask us at any time to have a payment failure or suspension reviewed by a person. (b) Misuse: automated monitoring of account and usage information may flag an account for potential misuse of the Service, such as abuse of a free trial. A decision to pause an account for misuse is made by a member of our team, and you can ask for it to be reviewed. (c) AI Features that classify, tag, score or summarise records are tools the workshop uses to run its business. Any decision about an End Customer made using an AI Feature is made by the workshop, not by us, and the workshop’s own privacy policy applies. We do not use computer programs to decide whether to offer you the Service or what price to charge you. We will update this section if these processes change.
4.5 Reporting, analytics and benchmarks. Reports about a workshop’s own business use that workshop’s own records. Any benchmark or insight that compares a workshop with other workshops is built from aggregated and de-identified data as described in section 5. They inform decisions made by the workshop’s own people; they do not make decisions about individuals.
4.6 Staff use of AI tools. Our internal policy prohibits staff from entering customer or End Customer personal information into publicly available generative AI tools. Our staff use AI-assisted support and diagnostic tools provided under commercial terms that prohibit the provider from using our data to train its models and require it to delete that data within 30 days, subject to limited legal and safety exceptions. Those tools may process customer and End Customer information when our staff provide support or diagnose a problem. Their provider is identified in the sub-processor list in our Data Processing Addendum.
5. De-identified and aggregated data, and industry insights
5.1 Our Subscription Agreement permits us to create de-identified and aggregated data from information in the Service, including End Customer information and usage information, and is the workshop’s instruction to us to do so. Once information has been de-identified to the standard in that Agreement it is no longer personal information, and we hold and use it in our own right. We may use that data to operate, secure and improve the Service, to develop new features, to train, fine-tune, test and evaluate AI models and AI Features (never using personal information for that purpose), and to produce benchmarks, industry statistics and insights for the automotive and related trades. These insights may be shown to customers inside the Service, published, or provided to partners, industry bodies and researchers. Information that has only been pseudonymised or minimised (for example, by replacing names with codes) is still personal information and is handled under the rest of this policy, not under this section.
5.2 Before we use information this way we remove or transform identifiers so that the data is no longer about an identifiable individual or business, or one who is reasonably identifiable, applying techniques appropriate to the sensitivity of the data and the context in which it will be used or released. We do not publish or provide any statistic or benchmark in a form that identifies, or could reasonably be used to identify, a workshop, a User or an End Customer, and we do not attempt to re-identify anyone. If we ever find that data we treated as de-identified could reasonably be re-identified, we treat it as personal information again and protect it under this policy.
5.3 Once de-identified in accordance with section 5.2, this data is no longer personal information and the access and correction rights in section 10 do not apply to it. Our Subscription Agreement sets out the licence our customers give us to create it.
6. Who we disclose personal information to
6.1 We disclose personal information to the following kinds of recipients, only to the extent needed for the purposes in section 3:
- Our service providers, who host and support the Service and our business, acting on our instructions and under contracts that restrict how they may use the information (payment processors also use some information for their own purposes, as section 6.2 explains). They include: cloud hosting and infrastructure providers; application monitoring and diagnostics providers; AI model providers for AI Features and for AI-assisted support and diagnostic tools used by our staff (see section 4); payment processors (see 6.2); SMS, messaging and email delivery providers; customer relationship management, marketing, support ticketing and live chat tools (which hold Customer, User and prospect contact details and our correspondence with you; they are not used to store End Customer records, although correspondence you send us may incidentally include End Customer information); subscription billing providers (which hold billing contact and invoice details); product analytics and in-app guidance tools; and professional advisers, auditors and insurers. The providers that process End Customer data are named, with their locations, in the sub-processor list in our Data Processing Addendum.
- Third Party Services you choose to connect, such as accounting platforms, parts and vehicle data suppliers, and marketing or messaging platforms. When a workshop connects one of these, we share the information needed for the integration on the workshop’s instructions, and the provider’s own privacy policy governs what it does with it.
- Our partners and resellers, where you were introduced to us by a partner or you ask us to work with one, limited to the information needed for that relationship.
- Regulators, courts and law enforcement, where required or authorised by law, or to protect our rights, safety or property or those of others.
- A buyer or successor, if we sell or transfer all or part of our business, in which case the recipient takes on the obligations in this policy.
6.2 Payments. Card payments, including payments that workshops take from End Customers through the Service, are processed by PCI DSS compliant third-party payment processors. Card details are passed to the processor to complete the payment. We do not store your full card number or keep it in our records; we keep only limited details such as the last four digits of your card. Our payment processors process information in the countries shown for them in the sub-processor list in our Data Processing Addendum. They process payment information to complete transactions. They also use some payment, transaction and device information for their own purposes, such as preventing fraud across their networks, assessing risk, improving their services and meeting their legal and regulatory obligations. For those purposes they act as independent controllers under their own privacy policies, not on our instructions or the workshop’s. Processors that handle End Customer payments are named in the sub-processor list in our Data Processing Addendum. Our own subscription fees are collected through our subscription billing provider, which uses a third-party payment gateway to process card payments. That gateway handles our Customers’ billing and card details, not End Customer information.
6.3 We do not sell personal information, and we do not disclose personal information to third parties for their own marketing. We do not share mobile numbers or SMS opt-in information with third parties for marketing.
6.4 We keep a current list of the sub-processors that handle End Customer information, with their locations, in the Data Processing Addendum, and we tell customers before adding a new one.
7. Overseas disclosure
7.1 The Service is hosted in data centres operated by our cloud infrastructure provider. Customer and End Customer data is stored in the region for the customer’s market: Australia for customers in Australia and New Zealand; the European Union for customers in the United Kingdom and Europe; and the United States for customers in the United States and the rest of the world. We configure our infrastructure so that backups are stored in the same region as the data they back up. Some processing happens in a fixed location, whichever region your data is stored in: emails sent from the Service to End Customers are delivered from Australia for Australian and New Zealand customers and from the United States for all other customers; SMS messages sent from the Service are delivered from Australia for all customers; application logs, which may contain End Customer information, are processed in Australia; and our cloud operations support provider accesses the Service from Australia.
7.2 Some of our service providers are located, or process information, outside the country you are in. Our AI providers and some monitoring, support, billing and marketing tools are located in the United States. Our subscription analytics provider is located in the European Union (Ireland). Our payment processors process information in the countries shown for them in the sub-processor list in our Data Processing Addendum. Our application monitoring provider hosts our logs in Australia and is a United States company. Members of our team located in the United Kingdom access personal information to provide support and operate the Service. Before we disclose personal information overseas we take reasonable steps to ensure the recipient handles it in a way that is consistent with the APPs, including through contractual protections, and where the GDPR or UK GDPR applies we use the transfer mechanisms described in section 12.
7.3 We rely on the reasonable steps described in section 7.2 for overseas disclosures, rather than on your consent. If we ever need to rely on your consent for a particular overseas disclosure, we will tell you expressly at the time, including that the recipient may not be bound by the APPs.
8. Cookies, analytics and similar technologies
8.1 Our website and the Service use cookies and similar technologies. Cookies are small text files stored on your device.
8.2 Strictly necessary cookies keep you logged in, remember your session, protect against fraud on payment screens and support essential functions. They cannot be switched off without affecting the Service.
8.3 Analytics and performance cookies help us understand how our website and the Service are used so we can improve them. We use third-party analytics tools for this purpose.
8.4 Marketing cookies are used on our public website to measure our advertising, show relevant advertising on other sites, and understand which content leads to enquiries. They are set by third-party advertising, analytics and marketing platforms we use. You can accept or reject these cookies through the cookie banner on our website and through your browser settings, as described in section 8.5.
8.5 You can control cookies through your browser settings and, where we display one, through the cookie banner on our website. Visitors from the European Union and the United Kingdom are asked for consent before non-essential cookies are set.
8.6 Our servers also record standard log information such as IP address, browser type, pages requested, referring page and timestamps. We use this for security, troubleshooting and aggregate reporting.
9. Marketing communications
9.1 We may send you information about our products, features, events and offers by email, and in some cases by SMS or phone, where you have opted in, where you are an existing customer and the communication relates to similar products or services, or where the law otherwise permits.
9.2 Every marketing email contains an unsubscribe link, and every marketing SMS tells you how to opt out. You can also change your preferences by contacting us. We action opt-out requests within 5 business days. Opting out of marketing does not stop service messages we need to send you, such as invoices, renewal notices and security alerts.
9.3 We comply with the Spam Act 2003 (Cth) and the Do Not Call Register Act 2006 (Cth) in Australia and equivalent laws elsewhere.
10. Access, correction and your other rights
10.1 You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Customers and Users can view and update most of their details directly in the Service.
10.2 To make a request, email support@workshopsoftware.com. We will verify your identity, respond within 30 days or any shorter period the law that applies to you requires (for example one month under the GDPR and UK GDPR, or 20 working days for access requests under the Privacy Act 2020 (NZ)), and generally will not charge a fee. If we refuse a request in whole or part we will tell you why in writing and how to complain.
10.3 If you are an End Customer of a workshop, please direct your request to the workshop, which controls your information. We act on its instructions and will help it respond.
10.4 Additional rights for people in New Zealand, the United Kingdom, the European Economic Area and certain US states are described in sections 12 and 13.
11. Data security and retention
11.1 We take reasonable steps, including technical and organisational measures, to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These include encryption of data in transit, access controls with multi-factor authentication for our staff and role-based permissions for Users, logging and monitoring, code review of changes before release, quarterly third-party vulnerability scanning, a documented incident response plan, and daily backups.
11.2 Data breaches. If a data breach occurs that is likely to result in serious harm to individuals, we will notify the Office of the Australian Information Commissioner and affected individuals as required by the Notifiable Data Breaches scheme, and will notify affected customers so that they can meet their own notification obligations. Our Data Processing Addendum sets out notification timeframes for End Customer data.
11.3 Retention. We keep personal information for as long as we need it for the purposes in section 3, and then take reasonable steps to delete or de-identify it. How long we need it depends on the kind of information. Customer and End Customer data in the Service is kept for the period after a paid subscription ends that is set out in our Subscription Agreement (up to 12 months, so that the workshop can reactivate). Data entered during a free trial that does not become a paid subscription is deleted within 30 days after the trial ends. In either case copies may then persist in long-term archival backups that are kept for disaster recovery only and deleted at the end of the archive cycle. Account, billing and tax records are kept for as long as the Corporations Act 2001 (Cth) and tax law require, which is generally up to 7 years. Support correspondence and CRM records are kept for as long as they are useful in dealing with you or resolving a dispute. Marketing preference records are kept for as long as needed to honour your choices. Website analytics data is kept in aggregated form. You can ask us to delete personal information we hold about you as a controller and we will do so within 30 days unless the law requires us to keep it, we need it to complete a transaction or resolve a dispute, or the request concerns information that the workshop you work for controls (such as your activity within its Account), in which case we will refer that part of the request to the Customer that added you and handle ourselves the information we hold about you as a controller, such as your login and contact details. End Customers should ask their workshop, which controls their information.
12. Additional information for the United Kingdom and European Economic Area
12.1 Controller and processor. For Customer, User, website visitor and prospect information, Workshop Software Pty Ltd is the controller. For End Customer information, the workshop is the controller and we are its processor under a Data Processing Addendum that includes the mandatory terms required by Article 28 of the GDPR and UK GDPR.
12.2 Legal bases. We process personal information on the following bases: performance of our contract with you (providing the Service and support, billing); our legitimate interests (securing and improving the Service, understanding usage, business-to-business marketing to existing customers, preventing fraud, establishing and defending claims, and creating de-identified and aggregated data, as described in section 5, from information we hold as controller), balanced against your rights; your consent (non-essential cookies, marketing to prospects where consent is required); and compliance with legal obligations (tax and accounting records, responding to lawful requests).
12.3 International transfers. Where we transfer personal information out of the UK or EEA to a country that does not have an adequacy decision, including Australia and the United States, we rely on the UK International Data Transfer Agreement or the UK Addendum to the EU Standard Contractual Clauses (for UK data) and the EU Standard Contractual Clauses (for EEA data), together with supplementary measures where needed. You can request a copy by contacting us. For customers in the United Kingdom and the European Economic Area this includes the storage of End Customer information in the region described in section 7.1, the delivery of emails from the United States, the delivery of SMS messages from Australia, the processing of application logs in Australia, access by our cloud operations support provider from Australia, the processing described in section 4 by our AI providers in the United States, and payment processing as described in section 6.2.
12.4 Your rights. You have the right to access your personal information, to have it corrected or erased, to restrict or object to processing (including to object at any time to direct marketing), to data portability, and to withdraw consent where processing is based on consent. You also have the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects; as stated in section 4.4, any such decision is subject to review by a person on request. To exercise these rights contact support@workshopsoftware.com. You may also complain to your local supervisory authority, including the UK Information Commissioner’s Office.
12.5 Retention is as stated in section 11.3.
13. Additional information for New Zealand and the United States
New Zealand
13.1 We comply with the Information Privacy Principles in the Privacy Act 2020 (NZ). Where we disclose personal information about people in New Zealand to a recipient outside New Zealand, we do so only where the recipient is subject to comparable privacy safeguards, is bound by contract to provide them, or another exception in Information Privacy Principle 12 applies. Where we collect personal information about you from a source other than you, we will take reasonable steps to make you aware of it where required by Information Privacy Principle 3A. You may complain to the Office of the Privacy Commissioner (privacy.org.nz) if you are not satisfied with our response.
United States
13.2 For End Customer information, we act as a “service provider” or “processor” for the workshop under applicable US state privacy laws, including the California Consumer Privacy Act, and we do not sell or share that information or use it for our own purposes except as those laws permit for service providers.
13.3 For Customer, User and prospect information, residents of California and other states with comprehensive privacy laws may have rights to know, access, correct and delete personal information, to opt out of the sale or sharing of personal information and of targeted advertising, and not to be discriminated against for exercising those rights. We do not sell personal information. Advertising cookies on our public website may be treated as “sharing” for cross-context behavioural advertising under California law; you can opt out of them through the cookie banner on our website and, where applicable law requires us to, we honour valid opt-out preference signals such as Global Privacy Control sent by your browser. To exercise any other right, email support@workshopsoftware.com. We will verify your request and respond within the time the applicable law allows. You may appoint an authorised agent to make a request on your behalf. In the last 12 months we have collected the categories of personal information described in section 1, for the purposes in section 3, and disclosed them to the categories of recipients in section 6.
13.4 Text messaging. If you opt in to receive SMS from Workshop Software, message frequency varies, message and data rates may apply, you can reply STOP to opt out or contact support@workshopsoftware.com for help, and we do not share your mobile number or opt-in status with third parties for marketing.
14. Children
14.1 The Service and our website are intended for businesses and are not directed at children. We do not knowingly collect personal information from anyone under 18, other than as End Customer information a workshop may record (for example a young driver’s vehicle details) or as User information where a workshop adds an employee or apprentice under 18 as a User, in which case we handle it as User information under this policy. If you believe a child has provided personal information to us directly, contact us and we will delete it.
15. Complaints
15.1 If you have a concern about how we have handled your personal information, please contact our Privacy Officer at support@workshopsoftware.com or by post to Privacy Officer, Workshop Software Pty Ltd, Suite 2305, 4 Daydream Street, Warriewood NSW 2102, Australia. Please describe the concern and how you would like it resolved.
15.2 We will acknowledge your complaint within 5 business days, investigate it, and respond within 30 days. If we need more time we will tell you why and when to expect a response.
15.3 If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992), or to the privacy regulator in your country, including the Office of the Privacy Commissioner (New Zealand), the Information Commissioner’s Office (United Kingdom) or the supervisory authority in your EEA member state.
16. Changes to this policy
16.1 We may update this policy from time to time. We will publish the updated policy on our website with its effective date and a summary of what changed. If a change materially affects how we handle your personal information we will give Customers at least 30 days’ notice by email before it takes effect, and where the change involves a new use of End Customer information we will give workshops enough notice to update their own privacy notices.
16.2 This policy was last updated on 8 November 2026. Previous versions are available on request.