0
Skip to Content
Monarch360
Monarch360
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact
Monarch360
Monarch360
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact
Monarch
Apollo
Ulysses
About Us
Services
Our Partners
Contact

Data Protection and Security Terms

Version 1.0 Published: August 2026 Monarch360 Pty Ltd · ABN 28 659 647 373
Master AgreementProduct SchedulesSupport ScheduleAI Feature EntriesData Protection and Security

Contents

  1. 1. Customer Content
  2. 2. Processing locations
  3. 3. Subprocessors
  4. 4. Transient Processing Services
  5. 5. Permissions and support access
  6. 6. Security controls
  7. 7. Security Incidents
  8. 8. Export and deletion
  9. 9. Assurance

About this page

These terms describe how Monarch360 protects Customer Content. Monarch360 maintains these controls substantially as described and may update them, provided the overall level of protection is not materially reduced (clause 7.4 of the Agreement). It forms part of the Published Terms under clause 1.4 of the Master Software Licence and Subscription Agreement. Capitalised terms have the meaning given in that agreement.

1Customer Content

1.1 Records, documents, emails, meeting papers, signed documents, metadata and personal information that the Customer places in or processes through the Products. This may include sensitive information and information about the Customer’s personnel, contractors, customers and members of the public. The Customer identifies any higher-risk categories in its Order Form.

2Processing locations

2.1 Tenant Products run within the Customer Environment. Customer Content remains in that environment’s data residency location.

2.2 AI Features run in the Customer’s own Microsoft Azure subscription within the Customer Environment, unless the applicable AI Feature Entry states otherwise. Customer Content processed by them does not leave the Customer Environment.

2.3 Hosted Services are hosted and processed in Australian data centre regions of Monarch360’s cloud providers, without global or multi-region deployments that would process Customer Content outside Australia.

2.4 Licensing data. Monarch360 receives User and usage data needed for licensing and licence compliance, such as tenant and User identifiers, User counts and feature usage (clause 3.4 of the Agreement). This data does not include document content.

2.5 Personnel access to Customer Content is governed by clause 7.3 of the Agreement.

3Subprocessors

3.1 Monarch360 uses established cloud hosting, AI and productivity service providers, and any Authorised Partner named in an Order Form. A current list of subprocessors, their purpose and processing locations is provided on request.

3.2 Changes affecting a Hosted Service are managed under clause 6.3 of the Agreement. Where a cloud AI provider retains prompts or outputs for abuse monitoring or safety purposes, that retention is described in the applicable AI Feature Entry.

4Transient Processing Services

4.1 Unless its Product Schedule states otherwise, a Transient Processing Service may retain only operational metadata: job and request identifiers, timestamps, tenant, site and user identifiers, file identifiers and locations, file type and size, processing status, error codes, classification labels and retention or disposal recommendations.

4.2 No document content, extracted text, prompts or AI outputs are retained beyond the transient period in clause 6.2 of the Agreement (maximum 24 hours). Operational metadata is retained for the subscription term plus 12 months, unless the Customer directs earlier deletion on exit.

5Permissions and support access

5.1 The platform permissions each Product requests (such as Microsoft Graph or SharePoint permissions), their purpose and whether they are delegated or application permissions are documented and provided before installation and whenever they materially change (clause 4.5 of the Agreement).

5.2 Support access to a Customer Environment uses Customer-approved named accounts or time-bound delegated administration, is requested per task and is removed when no longer required.

6Security controls

AreaControl
IdentitySingle sign-on through an enterprise identity provider (such as Microsoft Entra ID)
AuthenticationMulti-factor authentication for all Monarch360 Personnel
AccessLeast-privilege, role-based access; privileged access reviewed at least quarterly; access removed within one business day after a person’s role changes or engagement ends
EncryptionTLS 1.2 or higher in transit; AES-256 at rest with cloud-platform-managed or per-tenant keys
Vulnerability managementSecurity patches applied on a risk basis, with critical vulnerabilities remediated as a priority; dependency and code vulnerability scanning in the release pipeline
LoggingApplication and security logs exclude document content and are retained for the period configured for the relevant service
BackupsMonarch360 backs up its own configuration and operational metadata only. Customer Content in the Customer Environment is backed up by the Customer (clause 7.7).

7Security Incidents

7.1 Monarch360 security contact: security@monarch360.com.au, or another contact Monarch360 notifies in writing.

7.2 Customer contact: the notice contact in the Order Form, unless the Customer nominates another.

7.3 Monarch360 aims to give initial notice within 72 hours after confirming a Security Incident, then updates at least every two business days until it is contained, followed by a closing summary (clause 7.5 of the Agreement).

8Export and deletion

8.1 Customer Content in Tenant Products remains in the Customer Environment and can be exported with that platform’s native tools. On request, Monarch360 provides an export of Product configuration, such as metadata schema and workflow settings.

8.2 For Hosted Services, Customer Content and operational metadata are exported on request during the transition period and deleted within 90 days after the subscription ends (clause 9.5 of the Agreement). Monarch360 confirms deletion in writing on request.

9Assurance

9.1 A summary of security controls and one completed security questionnaire per Subscription Year (the Customer’s standard questionnaire or an industry-standard equivalent). Any further verification is subject to clause 7.6 of the Agreement.

Governing agreement: Monarch360 Master Software Licence and Subscription Agreement (Version 2.0). This page forms part of the Published Terms under clause 1.4 of that agreement and describes scope, service levels and technical matters only. If there is any inconsistency, the agreement prevails (clause 1.3). The version current when an Order Form is formed applies to it, subject to clause 4.3. Previous versions are available on request.

COMPANY

About Us‍ ‍

Partners‍ ‍

Blogs

PRODUCTS

Monarch EDRMS‍

Ulysses ‍

Apollo

SERVICES

Microsoft SharePoint‍

Microsoft Power Platforms ‍ ‍

Microsoft Dynamics 365

© 2026 Monarch Pty Ltd. All Rights Reserved

CONTACT US

Level 28, 140 St. George's Terrace, Perth, WA 6000

Phone: 08 9288 1726

Email: info@monarch360.com.au