Privacy Policy

Effective Date: 3 June 2022   •   Last Updated: 01/07/2026

This policy explains how Monarch360 collects, uses, discloses, stores and protects personal information across its website, software products and services.

1. About this policy

Monarch360 Pty Ltd (ACN 659 647 373, ABN 28 659 647 373) of Level 28, 140 St Georges Terrace, Perth WA 6000 (Monarch 360, we, us or our) provides SharePoint-native software-as-a-service products (the Services), primarily to Australian local government and other organisational customers. The specific products and modules covered by the Services for a given customer are identified in that customer's order form or subscription agreement.

This policy explains how we collect, hold, use and disclose personal information, and how you can access or correct it, contact us, or make a complaint. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Even where a small business exemption might otherwise apply to us, we have chosen to handle personal information in line with the APPs as a matter of good practice, given the nature of the Services we provide to government and public-sector customers.

This policy applies to:

●      personal information we collect about individuals at organisations that are our customers or prospective customers, and their staff (Business Contacts); and

●      personal information that may be contained within the records, documents and other content our customers store, process or manage using the Services (Customer Data).

It does not apply to information you provide to a third party, such as Microsoft, when using Microsoft 365 or SharePoint Online directly — that is governed by Microsoft's own privacy terms.

2. Our role: most Customer Data stays in your own environment

Our products are built to operate natively within your organisation's own Microsoft 365 / SharePoint tenant. This means that, for most of our Services, Customer Data (including any personal information it may contain) is created, stored and processed within your own Microsoft 365 environment, under your organisation's existing Microsoft agreements and security configuration — not on servers owned or operated by Monarch 360.

Where a specific Service or feature does involve us collecting, storing or processing Customer Data outside your tenant (for example, certain application logs, configuration data, hosted components, or optional cloud-based features), this is described in the relevant product documentation, and we act on your organisation's behalf and instructions as your service provider in doing so. Your organisation (as the entity that determines what personal information is collected and why) remains responsible, as between us, for complying with its own obligations under the Privacy Act or any applicable state or territory information privacy legislation in respect of Customer Data, including obligations to individuals whose personal information is contained in your records.

3. Personal information we collect

Depending on how you interact with us, we may collect:

●      Business Contact information: names, job titles, employer, business email addresses and phone numbers, and details of your enquiries or communications with us — for example, when you request a demonstration, contact our support team, or sign up to receive updates from us.

●      Account and usage information: user identifiers, login and access logs, and technical usage data about how the Services are used, to the extent this is generated or accessible in the course of providing and supporting the Services.

●      Support information: details you or your organisation provide when raising a support request, including, where necessary to diagnose an issue, limited samples of Customer Data that you choose to share with us.

●      Website information: information collected through our website, such as through contact or enquiry forms, and standard technical information (such as IP address, browser type and pages visited) collected via cookies or similar technologies, where used.

●      Customer Data: to the limited extent described in section 2, where a Service or feature involves us processing Customer Data outside your Microsoft 365 tenant.

We do not knowingly collect sensitive information (such as health, racial or ethnic origin, or criminal record information) about individuals, except to the extent such information may be incidentally contained within Customer Data that our customers choose to manage using the Services, in which case we process it solely as your service provider and in accordance with your instructions.

4. How we collect personal information

We generally collect personal information directly from you or your organisation, including through our website, sales and support interactions, and your use of the Services. We may also collect personal information from publicly available sources (for example, a council's published staff directory) for legitimate business development purposes, such as identifying an appropriate contact at a prospective government customer.

5. How we use personal information

We use personal information to:

●      provide, operate, maintain and support the Services;

●      respond to enquiries, provide quotes, and manage our relationship with customers and prospective customers;

●      provide customer support and diagnose technical issues;

●      send you service-related communications (such as maintenance notices or security updates);

●      with your consent or as otherwise permitted by law, send you marketing communications about our products and services, from which you may opt out at any time;

●      improve, develop and secure our products and services; and

●      comply with our legal obligations, and establish, exercise or defend legal claims.

We do not sell personal information to third parties.

6. Disclosure of personal information

We may disclose personal information to:

●      our employees and contractors (including contractors engaged to provide development or support services) who need it to perform their roles;

●      IT and hosting service providers that support our business operations (for example, Microsoft, where a hosted component of the Services is used);

●      professional advisers (such as lawyers, accountants and auditors);

●      a prospective purchaser or its advisers, in the context of a proposed sale, merger or restructuring of our business, subject to appropriate confidentiality protections; and

●      government or regulatory bodies, or other third parties, where required or authorised by law, including in response to a lawful request from a law enforcement or regulatory agency.

Where we engage a third-party service provider or contractor to process personal information on our behalf, we take reasonable steps to ensure that provider protects the information consistently with this policy and the APPs, including, where they are located outside Australia, in the manner described in section 7.

7. Overseas disclosure

Where a hosted component of the Services or a supporting IT system involves storage on Microsoft Azure infrastructure, we work with our customers to configure that storage in an Australian data centre region wherever the Service supports this, reflecting the data residency expectations of our government customers.

Some limited technical or diagnostic information (for example, associated with global support or licensing systems) may be handled by service providers with infrastructure located outside Australia, including in jurisdictions such as the United States. In addition, from time to time some of our own development, support or maintenance functions may be performed by Monarch 360 personnel or contractors located outside Australia. Where either of these occurs, we take reasonable steps — including contractual protections consistent with APP 8 — to ensure the recipient handles personal information consistently with the APPs before any overseas disclosure or access occurs, and we do not disclose Customer Data to an overseas recipient other than as described in this policy or as instructed by your organisation.

We keep this section under review and will update it if the countries or circumstances involved in any overseas handling of personal information change materially.

8. Data security

We take reasonable technical and organisational steps to protect personal information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure, having regard to the nature of the information and the risks involved. Because most Customer Data remains within your own Microsoft 365 tenant, the security of that data is primarily governed by your organisation's own Microsoft 365 security configuration, and we encourage customers to apply appropriate access controls, multi-factor authentication and information governance settings within their own environment.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

9. Data breach notification

If we become aware of a data breach involving personal information we hold that is likely to result in serious harm to any individual, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, where required. Where a breach affects Customer Data held within your own Microsoft 365 tenant, we will notify you promptly so that your organisation can meet its own notification obligations.

10. Data retention

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, or as required by law (including, for government customers, applicable state records and retention requirements that govern how long certain records must be kept). Customer Data held within your own Microsoft 365 tenant remains under your organisation's control and retention settings at all times.

11. Access, correction and complaints

11.1 You may request access to, or correction of, personal information we hold about you by contacting us using the details in section 13. We will respond within a reasonable period, and will not charge you for making a request, although reasonable costs may apply to fulfilling it in some circumstances. We may need to verify your identity before providing access.

11.2 If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it.

11.3 If you wish to make a complaint about how we have handled your personal information, please contact us using the details below. We will investigate and respond to your complaint within a reasonable time.

11.4 If you are not satisfied with our response, you may lodge a complaint with the OAIC:

●      Website: www.oaic.gov.au

●      Phone: 1300 363 992

11.5 If your personal information forms part of records held by a Western Australian local government or other public-sector customer using the Services (rather than information we hold as described in section 3), your access, correction or complaint rights in relation to that information are generally exercised against that organisation directly, as the entity that determines how and why that information is collected and used, rather than against Monarch 360.

12. Changes to this policy

We may update this policy from time to time to reflect changes in our practices or in applicable law. We will post the updated policy on our website with a revised "last updated" date, and, where changes are material, we will take reasonable steps to notify active customers.

13. Contact us

For privacy questions, access or correction requests, or complaints, please contact:

Monarch360 Pty Ltd

ACN 659 647 373 | ABN 28 659 647 373

Level 28, 140 St Georges Terrace, Perth WA 6000

Phone: (08) 9288 1726

Email: info@monarch360.com.au