0
Skip to Content
Monarch360
Monarch360
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact
Monarch360
Monarch360
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact

Privacy Policy

Version 2.0 Last updated: 6 October 2026 Monarch360 Pty Ltd · ABN 28 659 647 373
Master Agreement Product Schedules Support Schedule AI Feature Entries Data Protection and Security Privacy Policy

Contents

  1. 1. About this policy
  2. 2. Customer Content stays in your environment
  3. 3. Personal information we collect
  4. 4. How we collect personal information
  5. 5. How we use personal information
  6. 6. AI features
  7. 7. Disclosure of personal information
  8. 8. Where we operate
  9. 9. Security
  10. 10. Data breaches
  11. 11. Retention
  12. 12. Access, correction and complaints
  13. 13. Customer responsibilities
  14. 14. Marketing, cookies and analytics
  15. 15. Children
  16. 16. Third-party services and links
  17. 17. General
  18. 18. Changes to this policy
  19. 19. Contact us

This policy in brief

  • Customer Content stays in your organisation's own cloud environment. We do not host, store or back it up (section 2).
  • We hold limited business contact, licensing and support information, and we do not sell personal information (sections 3 and 5).
  • Limited information may occasionally be accessed from outside Australia, under contractual safeguards (section 8).
  • To ask a question, request access or correction, or make a complaint, contact us (section 19).

This summary is for convenience only. The full policy below applies.

This policy explains how Monarch360 collects, uses, discloses, stores and protects personal information across its website, software products and services.

Monarch360 Pty Ltd (ABN 28 659 647 373; ACN 659 647 373) of Level 28, 140 St Georges Terrace, Perth WA 6000.

1About this policy

Monarch360 Pty Ltd (Monarch360, we, us or our) provides enterprise software products and related services, including deployment, support and professional services (the Services), to public sector and enterprise organisations.

This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct it, ask us a question or make a complaint. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This policy applies to:

  • personal information about people at our customers, prospective customers, partners and suppliers, and visitors to our website (Business Contacts); and
  • personal information about the users of the Services that we receive to license, deploy and support the Services (Licensing and Support Data).

This policy does not apply to the records, documents and metadata our customers create or manage using the Services (Customer Content), which remain in the customer's own environment as described in section 2. It also does not apply to information handled by your organisation's cloud platform providers or other third parties under their own terms, or by our Authorised Partners acting under their own privacy policies.

2Customer Content stays in your environment

Our products are designed to operate within your organisation's own cloud environment, using cloud services and subscriptions that your organisation owns and controls. Customer Content stays in that environment. We do not host, store or back up Customer Content on systems owned or operated by Monarch360.

If a product or feature ever requires us to host or process Customer Content on our own systems, this will be set out in your organisation's agreement or the relevant product documentation, and we will handle that content only as your organisation's service provider and in line with its instructions.

This means:

  • your organisation controls where Customer Content is stored, who can access it, and how long it is kept, under its own agreements with its cloud platform providers and its own security configuration;
  • your organisation is responsible for complying with the Privacy Act, any applicable state or territory privacy legislation (including the Privacy and Responsible Information Sharing Act 2024 (WA) where it applies to you) and records legislation in relation to Customer Content; and
  • individuals who want to access or correct personal information contained in Customer Content should contact the organisation that holds it (see section 12.5).

We may access Customer Content only where your organisation grants us access to deliver, deploy or support the Services, and only to the extent needed for that purpose. When we do, we act on your organisation's instructions and do not use Customer Content for any other purpose.

3Personal information we collect

Depending on how you deal with us, we may collect:

  • Business Contact information: name, job title, organisation, business email address, phone number, and the content of your enquiries and communications with us, for example when you request a demonstration or a quote, respond to a tender, attend an event, or subscribe to updates.
  • Licensing and Support Data: user names, email addresses, user and tenant identifiers, licence allocation and activation details, and technical information needed to deploy, license and support the Services.
  • Support information: details provided when a support request is raised, including screenshots, error messages and, where needed to diagnose an issue, limited samples of Customer Content that your organisation chooses to share with us.
  • Website information: information you submit through forms on our website, and technical information such as IP address, browser type and pages visited, collected through cookies and similar technologies.

We do not intentionally collect sensitive information (such as health information, racial or ethnic origin, or criminal records). If sensitive information is incidentally included in Customer Content or support material your organisation shares with us, we handle it only to provide the relevant support and in line with your organisation's instructions.

4How we collect personal information

We collect personal information directly from you or your organisation, including through our website, sales and tender processes, deployment and support activities, and your organisation's use of the Services. We may also collect Business Contact information from publicly available sources (for example, a published staff directory or tender portal) or from our Authorised Partners, for legitimate business purposes such as identifying the right contact at a current or prospective customer.

5How we use personal information

We use personal information to:

  • provide, deploy, license, operate, maintain and support the Services;
  • respond to enquiries, prepare quotes and tender responses, and manage our relationships with customers, partners and suppliers;
  • diagnose and resolve technical issues;
  • send service communications, such as release, maintenance and security notices;
  • send marketing communications, with your consent or as otherwise permitted by law (you can opt out at any time);
  • maintain, improve and secure our products and services;
  • manage licence compliance and protect our intellectual property; and
  • comply with our legal obligations, and establish, exercise or defend legal claims.

We do not sell personal information.

6AI features

Some of our products include optional artificial intelligence (AI) features. These features run within your organisation's own cloud environment, under your organisation's configuration and control.

We do not use Customer Content, or personal information contained in it, to train AI models. We do not use personal information to make decisions about individuals by automated means. Any decision your organisation makes using the output of an AI feature is your organisation's decision, and your organisation should review AI output before relying on it.

7Disclosure of personal information

We may disclose personal information to:

  • our employees and contractors who need it to perform their roles, including deployment, development and support;
  • our Authorised Partners, where they are involved in supplying, deploying or supporting the Services for your organisation;
  • service providers that support our business operations, such as cloud hosting, email, support ticketing and accounting providers;
  • professional advisers, such as lawyers, accountants, auditors and insurers;
  • a prospective purchaser, investor or their advisers, in connection with a proposed sale, merger, financing or restructure of our business, subject to confidentiality obligations; and
  • courts, regulators, law enforcement and other government bodies, where required or authorised by law.

We require our contractors and service providers to keep personal information confidential and to use it only for the purpose for which we provide it.

8Where we operate

We are an Australian company. The personal information we hold is stored using established cloud service providers, and we select Australian data hosting where the provider offers it.

Personal information we hold may, from time to time, be accessed from outside Australia by our personnel or service providers. Where this occurs, we take reasonable steps to ensure the information is handled consistently with the APPs, including through contractual confidentiality, privacy and security obligations, and access that is limited to what is required for the task.

9Security

We take reasonable technical and organisational steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include access controls, multi-factor authentication, least-privilege access for our personnel, and confidentiality obligations for our staff and contractors.

Because Customer Content remains in your organisation's own environment, its security depends primarily on the configuration of your organisation's cloud environment, including access controls, multi-factor authentication, backup, retention and information governance settings. Your organisation is responsible for those settings.

No system is completely secure, and we cannot guarantee that information will never be accessed, disclosed or lost without authorisation.

10Data breaches

If we become aware of a data breach involving personal information we hold, we will assess it promptly and, where the breach is likely to result in serious harm, notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as required by the Notifiable Data Breaches scheme.

If we become aware of a breach affecting Customer Content in your environment, or personal information we handle on your organisation's behalf, we will notify your organisation without undue delay so that it can meet its own obligations, including any obligations under the Privacy and Responsible Information Sharing Act 2024 (WA). Your organisation remains responsible for assessing and notifying breaches of Customer Content under the law that applies to it.

11Retention

We keep personal information only for as long as we need it for the purposes in this policy, including to meet legal, tax, contractual and audit requirements, and then securely delete or de-identify it. Customer Content is retained, and disposed of, according to your organisation's own settings and records obligations, not by us.

12Access, correction and complaints

12.1 You can ask for access to, or correction of, personal information we hold about you by contacting us using the details in section 19. We may need to verify your identity first.

12.2 We will generally respond within 30 days. We do not charge for making a request, but may charge a reasonable fee for providing access in some circumstances. If we refuse a request, we will tell you why, unless it would be unreasonable to do so, and how you can complain.

12.3 If you think personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you can ask us to correct it.

12.4 If you have a complaint about how we have handled your personal information, please contact us. We will investigate and respond, generally within 30 days. If you are not satisfied with our response, you can contact the OAIC:

  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

12.5 If your personal information is held in records managed by one of our customers (for example, a local government), please contact that organisation directly. It controls those records and is responsible for responding to access, correction and complaint requests about them. If we receive such a request, we may refer it to the relevant organisation.

13Customer responsibilities

Where your organisation uses the Services, your organisation is responsible for:

  • having a lawful basis to collect, use and disclose personal information in Customer Content, and giving any notices to individuals that the law requires;
  • configuring and securing its cloud environment, including user access, backup and retention settings;
  • sharing with us only the minimum personal information needed when raising a support request, and de-identifying it where practicable; and
  • the actions of its users, and of any third-party applications, workflows or customisations it adds to its environment.

14Marketing, cookies and analytics

We will only send you marketing communications as permitted by law. Each marketing email includes a way to unsubscribe, and you can also opt out by contacting us.

Our website uses cookies and similar technologies to operate the site, remember preferences and understand how visitors use it. You can control or block cookies through your browser settings, although some parts of the website may not work as intended if you do.

15Children

The Services and our website are designed for organisations and are not directed at children. We do not knowingly collect personal information from children.

16Third-party services and links

The Services operate with third-party cloud platforms chosen by your organisation, and our website may link to third-party sites. We are not responsible for the privacy practices of those platform providers or any other third party, which are governed by their own terms and policies.

17General

This policy describes our practices. It does not form part of any contract, and does not create contractual rights or obligations, unless a written agreement with us expressly says so. If this policy is inconsistent with your organisation's agreement with us, that agreement prevails.

Nothing in this policy excludes, restricts or modifies any right or remedy, or any guarantee, that cannot be excluded under law, including the Australian Consumer Law.

18Changes to this policy

We may update this policy from time to time. The current version will always be published on our website with its "last updated" date. Where we make a material change, we will take reasonable steps to let active customers know.

19Contact us

For privacy questions, access or correction requests, or complaints, please contact our Privacy Officer:

Privacy Officer, Monarch360 Pty Ltd
Level 28, 140 St Georges Terrace, Perth WA 6000
Phone: (08) 9288 1726
Email: info@monarch360.com.au

Related documents: Master Agreement · Product Schedules · Support Schedule · AI Feature Entries · Data Protection and Security Terms

Version history: Version 1.0, effective 3 June 2022 (last updated 1 July 2026). Version 2.0, published 6 October 2026. Previous versions are available on request.

COMPANY

About Us‍ ‍

Partners‍ ‍

Blogs

PRODUCTS

Monarch EDRMS‍

Ulysses ‍

Apollo

SERVICES

Microsoft SharePoint‍

Microsoft Power Platforms ‍ ‍

Microsoft Dynamics 365

© 2026 Monarch Pty Ltd. All Rights Reserved

CONTACT US

Level 28, 140 St. George's Terrace, Perth, WA 6000

Phone: 08 9288 1726

Email: info@monarch360.com.au