Privacy Policy
Privacy Policy
Version 2026-09-25 · effective 25 September 2026 · https://embed.mbot-dev.com.au/legal/privacy/2026-09-25
Privacy Policy
Last updated: 25 September 2026
1. About this policy
-
(a) This Privacy Policy explains how Monkey Tech Pty Ltd (ABN 44 627 133 500) (“we”, “us”, “our”) collects, holds, uses, discloses, and otherwise handles personal information. It should be read together with our Cookie Policy and Terms of Service.
-
(b) We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) as amended by the Privacy and Other Legislation Amendment Act 2024 (Cth), and by the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act.
-
(c) To the extent we handle personal information of individuals located in the European Union or United Kingdom, we also comply with the applicable requirements of the EU General Data Protection Regulation (GDPR) and UK GDPR. See section 10 for details.
-
(d) “Personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether recorded in a material form or not. This includes information such as your name, email address, phone number, IP address, or any other data that can reasonably identify you, directly or indirectly.
-
(e) If you have questions about this policy, please contact us using the details in section 15.
2. What personal information we collect
-
(a) The types of personal information we may collect include:
- (i) Identity information — your name, job title, and employer or organisation name;
- (ii) Contact information — email address, phone number, and business address;
- (iii) Account information — username, password (stored in hashed form), role, and preferences;
- (iv) Technical information — IP address, browser type and version, operating system, device identifiers, and timezone;
- (v) Usage information — pages visited, features used, session duration, and actions taken within MonkeyBot;
- (vi) Communication information — records of correspondence with us, including support requests, feedback, and survey responses;
- (vii) Financial information — billing details and payment information necessary to process transactions (we do not store full credit card numbers; payment processing is handled by PCI-DSS compliant third-party providers); and
- (viii) Any other information you choose to provide to us in the course of using our services.
-
(b) We do not intentionally collect sensitive information (as defined in the Privacy Act) unless it is reasonably necessary and we have obtained your consent. If we become aware that sensitive information has been collected without proper authority, we will take reasonable steps to delete it.
3. How we collect personal information
-
(a) We collect personal information by lawful and fair means, and only where it is reasonably necessary for our business functions and activities (APP 3). We collect information:
- (i) directly from you, when you create an account, use MonkeyBot, contact us, submit a form, or respond to a survey;
- (ii) from your organisation’s administrator, where your employer has provisioned your MonkeyBot account;
- (iii) automatically, through cookies and similar technologies when you use our websites and application (see our Cookie Policy); and
- (iv) from third parties, including your employer, referral partners, or publicly available sources, where it is reasonable and practicable to do so.
-
(b) Where we receive personal information about you from a third party and it is not information we need for our functions or activities, we will, if lawful and reasonable, destroy or de-identify that information (APP 4).
-
(c) Where it is lawful and practicable, you may deal with us on an anonymous or pseudonymous basis (APP 2). However, if you do not provide us with the personal information we request, we may not be able to provide you with our products and services, or the quality of those services may be affected.
4. Notification of collection
At or before the time we collect your personal information (or as soon as practicable after), we will take reasonable steps to notify you of, or ensure you are aware of (APP 5):
- (a) our identity and contact details;
- (b) the fact that we are collecting the information and the circumstances of collection;
- (c) whether collection is required or authorised by law;
- (d) the purposes for which we collect the information;
- (e) the consequences if we do not collect the information;
- (f) the entities or types of entities to which we usually disclose information of that kind;
- (g) that this Privacy Policy contains information about how you may access and correct your personal information, and how to complain about a breach of the APPs; and
- (h) whether we are likely to disclose the information to overseas recipients, and if practicable, the countries in which they are located.
5. How we use your personal information
-
(a) We use personal information only for the primary purpose for which it was collected, or for a secondary purpose that you would reasonably expect and that is related to the primary purpose, unless we have your consent or are otherwise permitted under the APPs (APP 6). Our primary purposes include:
- (i) providing, maintaining, and improving MonkeyBot and related services;
- (ii) managing your account, authenticating your identity, and providing customer support;
- (iii) administering our business, including billing, invoicing, and contract management;
- (iv) communicating with you about your account, service updates, and changes to our terms or policies;
- (v) analysing usage patterns to improve functionality, performance, and user experience;
- (vi) investigating and responding to complaints, disputes, or security incidents; and
- (vii) complying with our legal and regulatory obligations.
-
(b) Direct marketing (APP 7): We may use your personal information to send you information about our products, services, and opportunities that we believe may be of interest to you. You may opt out of receiving marketing communications at any time by using the unsubscribe link in any email, or by contacting us. We will process your opt-out request promptly and at no cost.
-
(c) We will not use or disclose your personal information for a purpose you would not reasonably expect. Where the proposed Privacy Amendment (Personal Data Protection) Bill 2026 introduces a statutory “fair and reasonable” test, we are committed to meeting that standard.
6. Disclosure of personal information
-
(a) We may disclose your personal information to:
- (i) our employees, officers, contractors, and professional advisers, to the extent reasonably necessary to provide our services;
- (ii) our hosting, infrastructure, and technology service providers (see section 8);
- (iii) payment processors, for billing and transaction purposes;
- (iv) your employer or organisation administrator, where your account is managed by them;
- (v) regulatory authorities, law enforcement, or courts, where required or authorised by law, a court order, or a warrant; and
- (vi) a successor entity, in the event of a merger, acquisition, or sale of all or part of our business, subject to the acquiring entity agreeing to handle your personal information in accordance with this policy.
-
(b) We will not sell, rent, or trade your personal information to third parties for their own marketing purposes.
-
(c) Before disclosing your personal information to any new category of recipient not described above, we will update this policy and, where required, seek your consent.
7. Automated decision-making
MonkeyBot does not currently make decisions that have a legal or similarly significant effect on you based solely on automated processing of your personal information. If this changes, we will update this policy to explain the logic involved, the significance and expected consequences for you, and how you can request human review, in accordance with the automated decision-making transparency obligations commencing 10 December 2026 under the Privacy and Other Legislation Amendment Act 2024.
8. Cross-border disclosure of personal information
-
(a) We may disclose personal information to overseas recipients in the following countries (APP 8):
- Australia (primary hosting and operations);
- United States (cloud infrastructure and third-party service providers); and
- Singapore (cloud infrastructure).
-
(b) Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs, including by:
- (i) entering into contractual arrangements that require the recipient to handle personal information in accordance with the APPs;
- (ii) conducting due diligence on the recipient’s privacy and data protection practices; and
- (iii) where applicable, relying on the recipient’s compliance with a substantially similar privacy framework (e.g. EU Standard Contractual Clauses, UK International Data Transfer Agreement, or binding corporate rules).
-
(c) If additional countries become relevant, we will update this section to reflect the change.
9. Security of personal information
-
(a) We take reasonable steps to protect personal information from misuse, interference, loss, and from unauthorised access, modification, or disclosure (APP 11). Our security measures include:
- (i) encryption of data in transit (TLS) and at rest;
- (ii) access controls and authentication requirements;
- (iii) regular security assessments and monitoring;
- (iv) staff training on data handling and privacy obligations; and
- (v) contractual requirements on third-party service providers to maintain adequate security controls.
-
(b) When personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify the information (APP 11.2).
-
(c) No method of electronic transmission or storage is completely secure. While we strive to protect your personal information, we cannot guarantee its absolute security.
10. Rights of individuals in the EU and UK (GDPR)
This section applies to you if you are located in the European Economic Area or the United Kingdom.
-
(a) Lawful basis: We process your personal data on the following legal bases under Article 6 GDPR:
- (i) Contract — where processing is necessary to perform our contract with you or your organisation;
- (ii) Legitimate interests — where processing is necessary for our legitimate business interests (e.g. improving our services, security), provided those interests are not overridden by your rights;
- (iii) Consent — where you have given specific, informed, and unambiguous consent; and
- (iv) Legal obligation — where processing is required to comply with applicable law.
-
(b) Your GDPR rights: Subject to applicable exceptions, you have the right to:
- (i) access your personal data and receive a copy of it;
- (ii) rectify inaccurate or incomplete personal data;
- (iii) request erasure of your personal data (“right to be forgotten”);
- (iv) restrict processing in certain circumstances;
- (v) data portability (receive your data in a structured, machine-readable format);
- (vi) object to processing based on legitimate interests or for direct marketing; and
- (vii) not be subject to decisions based solely on automated processing, including profiling, that produce legal or similarly significant effects.
-
(c) To exercise any of these rights, please contact us at the details in section 15. We will respond within 30 days. We may ask you to verify your identity before acting on your request.
-
(d) If you believe we have not adequately addressed your concern, you have the right to lodge a complaint with your local data protection supervisory authority.
-
(e) Children: MonkeyBot is a business-to-business application. We do not knowingly collect personal data from individuals under 16 years of age. If you are under 16, please do not provide us with your personal data without the consent of a parent or guardian.
-
(f) International transfers from the EU/UK: Where we transfer personal data outside the EEA or UK, we rely on appropriate safeguards such as Standard Contractual Clauses approved by the European Commission, or the UK International Data Transfer Agreement, as applicable.
11. Notifiable Data Breaches
If we become aware of an eligible data breach (as defined under Part IIIC of the Privacy Act) that is likely to result in serious harm to any individual whose personal information is involved, we will:
- (a) take reasonable steps to contain the breach and mitigate any resulting harm;
- (b) assess the breach to determine whether it is likely to result in serious harm;
- (c) notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable, in accordance with the Privacy Act; and
- (d) keep a record of the breach, our assessment, and the steps taken.
12. Access and correction
-
(a) You may request access to the personal information we hold about you at any time (APP 12). We will respond to your request within a reasonable period (and no later than 30 days).
-
(b) If you believe any personal information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, you may request that we correct it (APP 13). We will take reasonable steps to correct the information as requested.
-
(c) We will not charge you for making a request, but we may charge a reasonable fee for providing access if the request requires a significant effort to locate or compile the information.
-
(d) We may refuse access or correction in certain circumstances permitted by the Privacy Act (for example, where providing access would pose a serious threat to the life or health of any individual). If we refuse, we will provide you with written reasons and inform you of the mechanisms available to complain.
13. Complaints
-
(a) If you believe we have breached the APPs or handled your personal information inappropriately, please contact us at the details in section 15. We take all complaints seriously.
-
(b) We will acknowledge your complaint within 5 business days and will investigate and respond within 30 days.
-
(c) If you are not satisfied with our response, you may lodge a complaint with the OAIC:
- Website: www.oaic.gov.au
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
14. Changes to this policy
-
(a) We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.
-
(b) Where changes are material, we will provide reasonable notice through the MonkeyBot application, by email, or by a prominent notice on our website before the changes take effect. Where acceptance is required, the updated policy will be presented for your review.
-
(c) The “Last updated” date at the top of this policy indicates the most recent revision. We encourage you to review this policy periodically.
15. Contact us
If you have questions about this Privacy Policy, wish to exercise your rights, or want to make a complaint, please contact us:
Monkey Tech Pty Ltd Email: privacy@monkeytech.com.au Website: https://www.monkeytech.com.au
16. Websites
- (a) This policy applies to the following websites and applications operated by Monkey Tech Pty Ltd:
- monkeytech.com.au
- monkeytech.au
- monkeybot.io
- monkeybot.com.au
- monkeybot.au
-
(b) Our websites may contain links to third-party websites. We are not responsible for the privacy practices or content of those websites. We encourage you to read the privacy policy of every website you visit.
- (c) For information about how we use cookies and similar technologies on our websites, please refer to our Cookie Policy.
Version history
- Version 2026-09-25 · effective 25 September 2026 · How Monkey Tech collects, uses and protects personal information, now accepted in the app on behalf of your organisation.
- Version 2023-07-01 · effective 1 July 2023 · How Monkey Tech collects, uses and protects personal information, now accepted in the app on behalf of your organisation.