What you may and may not do with Monkey Assets — the rules that keep the service safe, lawful and reliable for everyone.
Effective date: 22 July 2026. Version: 2026-07-22c. When we change this Policy, we will update the date shown here; see section 17 for how changes take effect.
This Acceptable Use Policy (the "Policy" or "AUP") sets out the rules for using Monkey Assets, a multi-tenant, QR-based IT asset register operated by Ausplace Solutions Pty Ltd ATF Cowley Family Trust (ABN 80 826 600 762) of Unit 2, 14 Cox Road, Windsor 4030, Queensland, Australia ("we", "us", "our" or the "Operator"). Monkey Assets is a MonkeyCode / Ausplace product.
The "Service" means the Monkey Assets platform in all of its forms, including the web application at https://monkeyassets.net (and the legacy alias assets.monkeycode.au, which redirects to it), the Monkey Assets iPhone app (once released), the Windows and macOS desktop uploader, the REST API, and the AI photo-intake feature, AI Performance Scoring and Microsoft 365 / Entra integration described below.
This Policy forms part of, and is incorporated into, the Monkey Assets Terms of Service (the "Terms"). Capitalised terms that are not defined here have the meaning given to them in the Terms. If there is any conflict between this Policy and the Terms, the Terms prevail, except that this Policy prevails to the extent it deals specifically with acceptable use.
This Policy applies to everyone who accesses or uses the Service. This includes account holders, the organisation an account belongs to (the "Customer"), individual users and administrators the Customer invites or provisions, and anyone using an API token or credential issued in connection with a Customer's account. The Customer is responsible for ensuring that everyone who uses the Service through its account complies with this Policy.
Because Monkey Assets is designed primarily for business use, the Customer that contracts with us is treated as the controller of the personal information it uploads (for example, records about its own staff and assets), and we handle that information on the Customer's behalf and on its instructions, as described in the Terms and our Privacy Policy. This Policy governs how the Service itself may be used; it does not change who owns the data — the Customer's data remains the Customer's data.
Monkey Assets is provided for one purpose: to let a Customer label its IT and physical assets with QR tags, scan them, and maintain an inventory and related records for its own organisation. You must use the Service only for that purpose and only in a lawful, honest and reasonable way.
At a high level, and without limiting the more specific rules below, you must not use the Service to do anything that is illegal, that harms or interferes with other users or tenants, that harms us or our infrastructure or providers, that misuses the Service as general-purpose storage or bandwidth unrelated to asset management, or that undermines the security or integrity of the Service.
You are responsible for all activity that occurs under your account and under any API token or credential issued to you, whether or not you authorised that activity, unless the activity resulted solely from our own breach of the Terms. You must keep your credentials, API tokens and any two-factor authentication factors secure, and notify us promptly at support@monkeyassets.net if you believe an account, token or credential has been compromised.
You must not use the Service to store, upload, transmit, link to, generate or otherwise make available any Content, or to engage in any conduct, that:
You are solely responsible for your Content and for ensuring you have the right and authority to upload it. In particular, before you import or add records about individuals (including staff, device owners or assignees, whether typed in, imported from a file, or imported from your Microsoft Entra directory), you must have a lawful basis and the authority to do so and to have us process that information on your behalf.
Monkey Assets is an IT asset register. It is not designed, and must not be used, as a system of record for sensitive or highly regulated categories of information. You must not upload, store or process the following categories of data in the Service ("Prohibited Data"):
We do not claim any specific security certification (for example, we make no SOC 2 or ISO/IEC 27001 claim) and offer no uptime service level at the current plan tiers. You must not rely on the Service as a compliant repository for regulated data, and you must not use it in a way that would place us under compliance obligations we have not agreed to assume.
The Service, its storage, its file and photo attachments, and its API are provided to support asset management for your organisation. They are not general-purpose infrastructure. You must not use any part of the Service to:
AI Feature usage is metered according to your plan. You must not use automation, scripting or bulk-submission techniques to evade AI metering, to run the AI Feature on images that are not genuine photos of your own assets, or to use the AI Feature as a general-purpose image-analysis or optical-character-recognition service unrelated to asset intake.
AI Performance Scoring is provided free the first time a machine registers itself through a check-in, and consumes a metered AI unit when a User re-scores an asset. You must not use repeated deletion and re-registration of the same machine, check-in submissions that do not describe a machine genuinely in your own register, or other automation, to obtain scoring beyond what the Service provides, or use AI Performance Scoring as a general-purpose hardware-benchmarking or valuation service unrelated to your own asset register.
AI output — the details read from a photo, and the performance ratings, estimated build years and notes produced by AI Performance Scoring — is produced on a best-effort basis and is not guaranteed to be accurate. AI Performance Scoring writes its output to the asset record without prompting anyone to confirm it. You must review and verify AI output before relying on it, and you must not present unverified AI output as a verified or authoritative asset record.
You must not take any action that compromises, or is intended to compromise, the security, integrity, availability or isolation of the Service or of any other tenant. In particular, you must not:
If you discover a security vulnerability, we ask that you disclose it responsibly and privately to us at support@monkeyassets.net and give us a reasonable opportunity to address it before disclosing it to anyone else. Good-faith security research reported this way, without accessing other tenants' data and without degrading the Service, will not be treated as a breach of this Policy.
The Microsoft Integration lets a Customer connect its own Microsoft Entra / Microsoft 365 tenant to the Service. Directory import is read-only by default. Certain features can write back to the Customer's own Microsoft tenant — for example, setting a device's Intune primary user, or adding a person to an Entra sign-in group used for Conditional-Access gating — and these features act only when the Customer explicitly switches them on.
In connection with the Microsoft Integration, you must not:
You are responsible for the configuration and consequences of any write-back feature you enable in your own Microsoft tenant. We act only within the scope you authorise and only when you have switched the relevant feature on.
You must not use the Service, or any communication, invitation, notification or export feature associated with it, to:
Except to the minimum extent that applicable law expressly permits and cannot be excluded by agreement, you must not:
Nothing in this section limits any right you have under the Australian Consumer Law or other law that cannot lawfully be excluded.
Monkey Assets is multi-tenant. You must respect the isolation and shared nature of the Service. You must not:
If you become aware of any use of the Service that breaches this Policy, of any Content that is unlawful or harmful, or of a security vulnerability, please report it to us promptly.
When reporting, please give us enough detail to investigate — for example, the account, organisation, record, URL or API activity involved, and a description of the issue. We will handle reports in accordance with our Privacy Policy and applicable law. Deliberately false or malicious reports may themselves breach this Policy.
We do not routinely monitor the content of Customer Data, and we access it only as needed to operate, secure, support and maintain the Service, to comply with law, or as otherwise permitted by the Terms and our Privacy Policy. We are the processor of Customer Data on the Customer's behalf; the Customer remains the controller of the personal information it uploads.
However, to protect the Service, our other customers, our providers and the public, we reserve the right (but do not assume any obligation) to investigate suspected breaches of this Policy. This may include reviewing audit logs, IP address and usage information, API activity, and — where reasonably necessary and permitted by law — relevant Content. We may also disclose information where we are required to do so by law or by a valid request from a regulator or law-enforcement body.
If you breach, or we reasonably believe you have breached, this Policy, or if your use of the Service creates a risk to the Service, to other tenants, to us, or to any person, we may take any action we consider appropriate, including one or more of the following:
Where it is reasonable to do so, we will give notice and an opportunity to remedy the breach before suspending or terminating. Where the breach is serious, unlawful, or poses an immediate risk to the Service, other tenants, or any person — for example, active security probing, distribution of malware, use as a data relay, or storage of prohibited or unlawful content — we may act immediately and without prior notice, and give notice afterwards.
Our rights under this Policy are in addition to our rights to suspend or terminate for breach, non-payment, or abuse under the Terms. Suspension or termination for non-payment is governed by the Terms; downgrading a paid plan does not by itself delete your data, and this Policy does not change that.
To the extent permitted by law, we are not liable for any loss you suffer as a result of action we reasonably take to enforce this Policy. Nothing in this Policy excludes, restricts or modifies any consumer guarantee or other right you have under the Australian Consumer Law or other law that cannot lawfully be excluded, and any limitation of our liability applies only to the extent the law permits. Where a liability for failure to comply with a non-excludable consumer guarantee can be limited, our liability is limited, at our option, to supplying the relevant services again or paying the cost of having them supplied again.
If your account is terminated, your right to access and use the Service ends. Following termination, and except where the law or the seriousness of the breach requires otherwise, we will provide a copy of your Customer Data on written request for the window described in the Terms, after which it will be deleted from active systems and then, in the ordinary course, from our nightly encrypted backups as those backups age out.
Where content or an account has been suspended or terminated because it is unlawful, or because retaining or returning it would itself be unlawful or would create a serious risk, we may withhold, restrict, or delete that content rather than making it available for export, to the extent the law permits and requires.
You remain responsible for any fees accrued up to termination, and for any liability arising from your breach of this Policy, including under the indemnity in the Terms.
You are responsible for your use of the Service and for your Content. As set out more fully in the Terms, and to the extent permitted by law, you agree to indemnify us against loss, liability, cost and expense that we reasonably incur arising out of or in connection with your misuse of the Service, your unlawful or infringing Content, or your breach of this Policy. This section is subject to, and does not exclude, any right you have under the Australian Consumer Law or other law that cannot lawfully be excluded.
We may update this Policy from time to time — for example, to address new abuse patterns, new features, or changes in the law. We will give reasonable notice of changes and update the effective date shown in section 1, and continued use of the Service after a change takes effect means you accept the updated Policy. Where a change is material, we may require you to re-accept this Policy before continuing to use the Service, consistent with the change process in the Terms.
This Policy is governed by the laws of Queensland, Australia, and forms part of the Terms. The Service is hosted on Amazon Web Services in the Sydney, Australia region (ap-southeast-2), with customer data stored in Australia at rest and nightly encrypted backups. Details of how we collect, use, disclose and secure personal information — including overseas disclosure to sub-processors such as our third-party AI processing provider and Stripe, and how to access, correct or complain (including to the Office of the Australian Information Commissioner) — are set out in our Privacy Policy.
Questions about this Policy, or reports of misuse, can be sent to Ausplace Solutions Pty Ltd ATF Cowley Family Trust at support@monkeyassets.net (privacy matters: privacy@monkeyassets.net), Unit 2, 14 Cox Road, Windsor 4030, Queensland, Australia, ABN 80 826 600 762.