Policies
Privacy policy
What personal data we collect, how we use it, and your rights regarding your information.
Last reviewed: 17 July 2026
Global Consortium Group ("we", "our" or "us") is committed to protecting and respecting your privacy. This notice explains what personal data we collect, how we use it, and your rights regarding your information. It applies to visitors and users of our website, globalconsortiumgroup.com, and any related services we provide.
We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth). The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your personal information. A copy of the principles is available from the Office of the Australian Information Commissioner at oaic.gov.au. Where UK or EU data protection law applies to you, we honour the rights in UK GDPR Articles 15 to 22 and the equivalent Articles of the EU GDPR, alongside the Australian Privacy Principles set out below.
1. Who we are
Global Consortium Group is a joint Australian and UK based company that provides the services described on this website.
2. What information we collect
Information you provide to us
- Name
- Email address
- Phone number
- Company name and job title
- Any additional information provided when contacting us
Information collected automatically
Our website sets no analytics or marketing cookies. When you submit our contact form, the service providers listed in section 6 process the technical data (such as IP address) needed to deliver your message. See our cookie policy for full detail.
We do not transact through this website. Where we need contract information to provide our services, we collect and hold only what the contract and the law require.
Sensitive information
We use sensitive information — racial or ethnic origin, political opinions, religious beliefs, criminal record or health information, as defined in the Privacy Act 1988 (Cth) section 6 and in UK GDPR Articles 9 and 10 — only for the purpose you gave it to us for, with your consent, or where the law requires it. We do not invite this information through the contact form.
3. How your information is used
- To provide and maintain our website and services
- To respond to enquiries and provide support
- To comply with legal obligations
4. Legal basis for processing
- Consent (UK GDPR Article 6(1)(a)) — when you give us your information voluntarily
- Legitimate interests (UK GDPR Article 6(1)(f)) — responding to an enquiry you send us
- Legal obligation (UK GDPR Article 6(1)(c)) — when the law requires us to keep or disclose information
Under the Australian Privacy Principles, APP 3 of Schedule 1 to the Privacy Act 1988 (Cth) governs how we collect your information and APP 6 governs how we use and disclose it.
5. Sharing your personal data
We do not sell your personal data. We share it with the processors listed in section 6, with a regulator or court where the law requires it, and — where your enquiry concerns a specific engagement — with the consortium member working on it. We share it with nobody else. Each processor in section 6 acts under a written contract meeting UK GDPR Article 28(3), and each consortium member is bound by a written confidentiality agreement.
We collect your personal information from you. Where someone else gives us information about you, the Privacy Lead tells you, unless the law prevents us from doing so. Our website may contain links to third-party websites; we are not responsible for their privacy practices and encourage you to review their policies.
6. Third-party service providers
The following processors handle personal data on our behalf, each limited to what is necessary to deliver its service:
- Netlify — website hosting, content delivery and the serverless endpoint that receives contact form submissions. Legal basis: legitimate interests (UK GDPR Article 6(1)(f)). Netlify acts under a written processor contract meeting UK GDPR Article 28(3).
- Microsoft 365 — email and business systems where your enquiry is received and handled; contact form submissions are delivered into our Microsoft 365 environment through Microsoft's Graph API. Legal basis: legitimate interests (UK GDPR Article 6(1)(f)). Microsoft acts under a written processor contract meeting UK GDPR Article 28(3).
7. Security and retention
We hold your information in our Microsoft 365 tenant, with multi-factor authentication on every account and access limited to the people handling your enquiry. No transmission over the internet is completely secure, and we do not claim otherwise.
We retain personal data only for as long as necessary for the purposes set out in this notice, or as required by law (for example, tax and accounting obligations). When your personal information is no longer needed, we will take reasonable steps to destroy or permanently de-identify it.
8. Your rights
- Access (UK GDPR Article 15; APP 12) — request a copy of the personal data we hold about you
- Correction (UK GDPR Article 16; APP 13) — ask us to correct inaccurate or incomplete data
- Deletion (UK GDPR Article 17) — request deletion of your personal data, subject to legal requirements
- Objection (UK GDPR Article 21) — object to certain uses, such as direct marketing
- Restriction (UK GDPR Article 18) — request that we limit how we process your data
- Portability (UK GDPR Article 20) — request your data in a structured, commonly used format
To exercise these rights, contact admin@globalconsortiumgroup.com. We respond within one month, as UK GDPR Article 12(3) requires, and within 30 days for a request made under APP 12 of Schedule 1 to the Privacy Act 1988 (Cth). The first copy of your personal data is free, as UK GDPR Article 15(3) requires. We charge only where a request is manifestly unfounded or excessive (UK GDPR Article 12(5)), or where you ask for further copies, and we tell you the fee before we do any work. To protect your personal information, we may require identification before releasing it.
If you find that information we hold is inaccurate or out of date, please let us know as soon as practicable so we can update our records.
Children's privacy
Our website is not intended for children, and we do not knowingly collect data from children.
Policy updates
We update this notice when our practices change. The Privacy Lead posts each change on this page with an updated review date.
9. Contact us
Global Consortium Group
Email: info@globalconsortiumgroup.com
Address: 43 Brook St, Windsor, Queensland 4030, Australia