What personal information Monkey Assets collects, how we use and protect it, who we share it with, and your rights under Australian privacy law.
Effective date: 22 July 2026. Last updated: 22 July 2026.
This Privacy Policy explains how Ausplace Solutions Pty Ltd ATF Cowley Family Trust (ABN 80 826 600 762) of Unit 2, 14 Cox Road, Windsor 4030, Queensland, Australia ("we", "us", "our") collects, uses, discloses, stores and protects personal information in connection with the Monkey Assets service. Monkey Assets is a MonkeyCode / Ausplace product.
Monkey Assets is a multi-tenant, QR-based IT asset register for businesses and managed-service providers. It lets you label IT equipment with QR tags, scan those tags to view and update records, and maintain an inventory. The service is delivered through a web application at https://monkeyassets.net (the former address assets.monkeycode.au redirects there), a forthcoming iPhone app, a Windows and Mac desktop uploader, and a REST API (together, the "Service").
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Policy tells you what we collect, why, who we share it with, whether it may go overseas, how long we keep it, how you can access or correct it, and how to make a privacy complaint. It applies to the Service and to our related websites, apps, integrations and support channels, but not to any third-party product or website we link to or integrate with, which have their own privacy terms.
If any term of a written agreement between you and us (for example our Terms of Service or a data processing agreement) conflicts with this Policy in relation to Customer Data, that agreement prevails to the extent of the conflict.
In this Policy:
Monkey Assets is mostly a business-to-business service, and it is important to understand who is responsible for which information.
For some information we act on our own behalf. This includes the account and billing details of the Customer and its Authorised Users, the technical and usage information generated when the Service is used, and our own operational records. For that information we are the entity responsible under the Privacy Act, and this Policy governs how we handle it.
For People Data that a Customer uploads or imports about its own staff, device owners and other individuals, the Customer is effectively the controller of that information โ the Customer decides what to collect and why, and is responsible for having a lawful basis to provide it to us, and for giving those individuals any notice (including APP 5 notice of collection) and obtaining any consents required under the APPs before providing their information to us or using features such as the AI photo-intake feature and AI performance scoring. We act as a processor: we host, store, back up and process that People Data on the Customer's behalf, on the Customer's instructions, and only to provide, secure and support the Service (or as required by law). The Privacy Act does not use the words "controller" and "processor" in the way some overseas laws do, but this describes the practical split, and it is set out in more detail in our Terms of Service and any data processing terms.
If you are an individual whose People Data appears in a Customer's Organisation (for example you are an employee whose device is tracked), the Customer is usually your first point of contact for questions about why your information is held, and for access or correction requests. We will generally refer such requests to the relevant Customer and assist them to respond. However, because we also hold that information, this referral is not absolute: we will comply with our own obligations under APPs 5, 12 and 13 where the law requires us to act directly.
The categories of personal information we collect depend on how you use the Service. They include:
Account and profile details โ the name, email address and organisation name of the person who registers or is invited, a hashed (not plain-text) password, and, if you enable it, information needed for app-based two-factor authentication. If you sign in using Microsoft single sign-on, we receive the basic identity details that sign-in returns.
Asset records โ details of the IT equipment you track, such as make, model, serial number, specifications, location, notes, assignment and status, together with any photos, documents or other files you attach. These records can contain personal information where, for example, a device is assigned to a named person or a note or file names an individual.
People Data โ information about individuals you add manually or import from your own Microsoft 365 / Microsoft Entra directory, including names, email addresses and user principal names (UPNs), and information about device owners and assignees. You control what People Data you bring into the Service.
Photos submitted to the AI photo-intake feature โ where you photograph a device to have its details read from the image, the image itself and the details extracted from it, which can include make, model, model number, serial number, IMEI, operating system and storage (see the dedicated section below).
Machine check-in data โ where a machine is registered or updated through the desktop uploader, an intake key or the check-in API, the hardware and firmware characteristics it reports about itself, which may include component identifiers. We store this in full on the asset record, in Australia. Where AI performance scoring is switched on it also contributes to the asset's rating, but only a fixed, named subset of it is sent to our AI processing provider for that purpose โ what we keep here is broader than what we send, and section 8 sets out exactly what leaves.
Found-device reports โ where a Customer has switched on the optional found-device feature (it is off by default, and applies only to organisations that enable it), a member of the public who finds one of that Customer's labelled assets can scan its QR code and leave a way to be contacted โ a phone number or email address, an optional name, and an optional short note โ so the owner can arrange the item's return. This is the one part of the Service that collects personal information directly from individuals who hold no account: we collect it as the responsible APP entity, for the single purpose of passing it to the organisation the asset is registered to.
Billing information โ for paid plans (Starter and Pro), limited billing details processed through our payment provider, such as your billing name, plan, billing status and a card reference (for example the card type and last four digits). Card details are entered directly with our payment provider; we do not collect or store full card numbers. The Free plan requires no card.
Technical, security and usage information โ including IP addresses, audit logs of significant actions within your Organisation, API tokens you generate, usage and rate-limit counters, session and device information, app and browser type, and diagnostic and error information. If we add push notifications to the iPhone app, we will also handle a push-notification device token to deliver them; the app does not use push notifications and we do not handle any device token today.
Support and communications โ the content of messages, requests and attachments you send us when you contact support or otherwise correspond with us.
We collect personal information:
Where practical we collect personal information directly from the individual concerned. Because this is a B2B service, People Data is often provided to us by the Customer rather than by the individual. If we receive personal information we did not ask for and do not need, we will deal with it in accordance with the APPs.
Under APP 2 you can, in some situations, deal with an organisation without identifying yourself or by using a pseudonym. The Service is an account-based business tool: accounts, per-organisation isolation, security controls such as two-factor authentication, audit logging, and support all depend on knowing who is acting within an Organisation. For those reasons it is generally not practicable for us to deal with Customers or Authorised Users anonymously or under a pseudonym, and we rely on APP 2.2 on that basis.
You can still make a general enquiry to our support or privacy contacts without holding an account, although we may need to verify your identity before acting on a request that concerns personal information.
The optional found-device feature is a limited exception: a person who finds a labelled asset can report it without holding an account, giving their name is optional, and they may use a pseudonym โ though they must leave a working phone number or email address, since the only purpose of the report is to let the owner contact them.
We collect and use personal information for the following purposes:
We use personal information only for the purposes for which it was collected, for a directly related purpose you would reasonably expect, or as otherwise permitted or required by law or with your consent. We do not sell personal information.
The Service has two features that send information to our third-party AI processing provider. They work differently, send different information, and we make different commitments about each, so they are described separately below.
AI photo intake โ the Service offers an optional feature that lets you photograph a device so that its details can be read automatically. When you use this feature, the image you submit is sent to our third-party AI processing provider, which analyses the image and returns what it can read: typically the make, model, model number, serial number, IMEI for a cellular device, operating system and storage, together with any other detail useful to an asset register that is visible in the image. This feature is metered according to your plan.
We send the image to the provider to read the device's details from it and, in the same call, to rate the device and estimate the year its model was sold. Where AI performance scoring is switched off for your Organisation, those ratings are discarded and never stored. We use the result for no other purpose. Under the terms on which we use the provider, the provider is not permitted to train its AI models on what we submit. Beyond producing the result we ask for, submissions also pass through the provider's automated safety systems, which check for misuse of its service. The provider's published policy is to delete images and results from its systems within 30 days; where its safety systems flag something it may keep them for up to two years, and it may also keep material for longer where the law requires it. Those retention practices are the provider's published policy rather than terms we have negotiated, and the provider can change them. If we change providers, we will update this section and the Sub-processors list.
Our third-party AI processing provider may process the image outside Australia (see "Overseas disclosure" below). Because a photograph may incidentally capture a person or other personal information, if you use this feature in relation to your staff or other individuals, you (the Customer) are responsible for giving those individuals any notice required under APP 5 and obtaining any consent required before you submit their information. Please only submit images of equipment for asset-register purposes, and avoid capturing people's faces or unrelated personal information in the frame.
The details extracted from a photo are produced on a best-effort basis and are not guaranteed to be accurate or complete. You are prompted to check and confirm the results before saving, and you remain responsible for the accuracy of your records. Do not rely on the extracted output without verifying it.
AI performance scoring โ this is a separate feature. It sends different information at different times, and the paragraphs above about submitted images do not describe it; where something said above also applies here, we say so. Where it is switched on for your Organisation, which it is by default, the Service rates a computer, phone or tablet out of 100 for office, gaming and creative work, estimates the year the model was sold where the record has no year, and writes a short explanatory note. It runs automatically, without prompting anyone, when a machine first registers itself through a check-in โ from the desktop uploader, an intake key, or your own tooling calling the check-in API โ and again whenever an Authorised User re-scores an asset. Only computers, phones and tablets are scored, and scoring does not run where the free-scoring limits set out in our Terms have been reached or the provider is unavailable; in those cases the machine simply arrives unrated.
To produce that rating we send our third-party AI processing provider the hardware details recorded for the asset โ its type, manufacturer, model, serial number, operating system, CPU, memory and storage โ together with a fixed, named set of hardware characteristics from the machine's own check-in: for each processor, graphics adapter and disk, its make, model, size, speed, core count and whether the disk is solid-state; the motherboard and BIOS maker, model, version and release date; and the system maker and model. That list is exhaustive, and it is enforced where the request is built rather than by asking anyone to send us less. Anything else a check-in reports is discarded before the request leaves, whatever tool sent it and whatever the field is called. In particular we do not send the serial number of any component, the device or host name, any hardware identifier such as a UUID, any IP or MAC address, or the name, username or user principal name of the person an asset is assigned to. We send those details only to obtain the rating, and we use them for no other purpose. The asset fields in the first list are ones you can edit, so whatever you record in them is what is sent.
The provider may process those details outside Australia (see "Overseas disclosure" below), and as that section explains it does not commit to a single processing location. A device serial number is not on its own information about a person, but we hold it alongside the record of who a device is assigned to, so we treat these details as personal information and disclose them on the basis set out in that section. We do not rely on consent for that disclosure. These details go to the same provider, through the same interface and on the same terms as submitted images, so what is said above applies to them too: the provider is not permitted to train its AI models on them, and the retention practices described above are the ones it publishes for what we send it โ its own published policy rather than terms we have negotiated, and it can change them.
An administrator can switch AI performance scoring off for your whole Organisation at any time in your account settings. While it is off, no specifications are sent to the provider by either trigger: a machine still registers and still receives its tag and QR code, but it arrives unrated, and the AI photo-intake feature stops adding ratings to the records it creates (it still reads the device's details from the photo). Switching it off does not delete ratings already produced, and switching it back on does not rate machines that checked in while it was off.
The ratings, the estimated build year and the note are AI-generated estimates. Because scoring runs unattended, it writes them to the asset record without asking anyone to confirm them first; the record identifies them as AI-generated and the scoring is recorded in the asset's history. An estimated year is only written where the record has no year, so it never replaces a year you entered, and you can edit or clear that year like any other field. The ratings and the note that comes with them are replaced by re-scoring the asset โ which uses one AI unit and requires the feature to be switched on โ or by writing them through the API, and they are cleared automatically if the asset is retyped to something that is not scored. You should check them before relying on them.
Automated processing, stated plainly โ because a rating produced by a computer program can feed decisions about equipment, and you may need to assess that against your own obligations. What the program uses: the asset's own hardware detail (type, manufacturer, model, serial number, operating system, CPU, memory and storage) and the named check-in characteristics listed above. What it does not use: any information about the person a device is assigned to. No name, username, user principal name, email address or device name is sent, and the rating a device receives would be identical if it were sitting unassigned in a cupboard. What it produces: three ratings out of 100, an estimated year the model was sold, and a short explanatory note, each recorded as AI-generated. It rates equipment. It does not assess, rank, score or infer anything about a person, and it does not itself decide anything โ what an organisation does with a rating, including any decision to reissue, keep or retire a device, is that organisation's decision and is made outside the Service. From 10 December 2026 the Privacy Act will require certain automated decision-making to be described in a privacy policy; we describe ours here, whether or not that requirement turns out to apply to this feature.
You can connect your own Microsoft Entra tenant to the Service. The integration operates on your own tenant, at your initiative and under your tenant administrator's authorisation.
By default the integration is read-only: it imports directory information you select (such as names, email addresses and UPNs) into your Organisation as People Data. We do not write anything back to your tenant by default.
The integration also offers optional, opt-in features that write to your tenant only when you switch them on โ specifically, setting a device's Intune primary user, and adding a person to an Entra sign-in group so you can apply Conditional Access controls. These write actions occur only at your direction, using the permissions you grant, and only against your own tenant. You can turn them off at any time.
You are responsible for the configuration of your tenant, the permissions you grant, and the lawfulness of the directory data you import and the changes you make through these features.
We do not sell personal information and we do not disclose it except as described in this Policy. We disclose personal information to:
Our current sub-processors and key third parties are:
We may update our sub-processors as the Service evolves. We will keep this list current and, where required, give reasonable notice of material changes. The countries in which these recipients are likely to process personal information are set out in the next section.
Customer Data is hosted and backed up in Australia (AWS Sydney, ap-southeast-2). However, some personal information may be disclosed to, or processed by, recipients located outside Australia. The recipients, and the countries in which they are likely to process personal information, are:
Where we disclose personal information overseas, we take reasonable steps in the circumstances to ensure the overseas recipient does not breach the APPs in relation to that information, including by putting binding contractual protections in place. This is the basis on which we make these disclosures under APP 8.1. Under APP 8 and section 16C of the Privacy Act, we generally remain accountable for the acts and practices of these overseas recipients in relation to that personal information as if we had done them ourselves, except where an exception in the Privacy Act applies.
We do not rely on your individual consent as the basis for these overseas disclosures. Where People Data about a Customer's staff or other individuals is involved, the relevant Customer is responsible for giving those individuals any notice required under APP 5 (including that their information may be disclosed to overseas recipients) and for obtaining any consent required, before providing that information to us or using features that involve overseas processing. Because AI performance scoring is on by default, a Customer that has not switched it off should treat it as a feature in use for this purpose.
Overseas privacy laws may differ from Australian law, and in some cases the protections available in the recipient country may not be the same as under the Privacy Act. We manage this risk through the reasonable steps and contractual protections described above, rather than by asking you to waive your rights.
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our current measures include:
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. We do not make any specific security certification claims (for example SOC 2 or ISO 27001) in this Policy, and nothing here is an uptime or availability guarantee. You are responsible for keeping your account credentials and API tokens secure, using the available security features, and managing access within your Organisation.
The web app uses cookies and similar technologies that are necessary to make the Service work and keep it secure โ for example to keep you signed in, maintain your session, support two-factor authentication, and protect against cross-site request forgery and other abuse. Some technical mechanisms, such as usage and rate-limit counters, are also used to protect the Service.
These are essential, first-party cookies and mechanisms. We do not use the Service to serve third-party advertising. If we introduce optional analytics or other non-essential cookies in future, we will update this Policy and, where required, seek your consent. You can control cookies through your browser settings, but disabling essential cookies will prevent parts of the Service from working.
We keep personal information for as long as we need it to provide the Service and for the purposes described in this Policy, and then delete or de-identify it, unless we are required or permitted by law to keep it longer (for example to meet tax, accounting or other legal obligations, or to resolve disputes).
While your account is active, we retain your account details and Customer Data so the Service can function. Encrypted backups are taken nightly and are retained for a rolling period before being overwritten, which means recently deleted data may persist in backups for a limited time.
Downgrading a paid plan (for example from Pro to Starter, or to Free) does not delete your Customer Data. While your account is active you can export your Customer Data at any time using the export tools in the Service. If your account is terminated, or you ask us to close it, you may also request a copy from us for 30 days afterwards, after which we will delete it from the live Service in the ordinary course, with residual copies removed from backups as they cycle out. That window and the specific retention periods are set out in our Terms of Service.
For People Data we process on a Customer's behalf, we act on the Customer's instructions regarding retention and deletion, subject to our own legal retention obligations and our backup cycle.
Found-device reports are retained for a maximum of 60 days from submission and are then deleted automatically, whether or not they have been read. They are also deleted when the related asset is deleted, and the organisation that received a report can delete it earlier at any time. Because finders do not hold accounts, this automatic deletion is the primary erasure mechanism for their details; a finder can also email privacy@monkeyassets.net at any time to have their details removed sooner, quoting the reference code shown when they submitted.
Under APPs 12 and 13 you may request access to the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact us using the details below. We will verify your identity, respond within a reasonable time (and in any event within the timeframes required by the Privacy Act), and generally provide access without charge, though we may recover reasonable costs for certain requests. If we refuse access or a correction, we will tell you why in writing and how you can complain, except where the law says we do not have to.
Much of the personal information in the Service can be viewed and updated directly by you within your Organisation.
If your personal information is held as People Data within a Customer's Organisation (for example your employer's account), the Customer decides what is collected and why. In that situation we will generally refer your access or correction request to the relevant Customer and assist them to respond. However, because we also hold that information, we will comply with our own obligations under APPs 12 and 13 (and APP 5) where the law requires us to act directly โ we will not treat the referral to the Customer as a reason to decline a request the law requires us to handle ourselves.
We may send you service, transactional and administrative messages about your account and the Service โ for example security notices, billing messages, and important changes. These are part of providing the Service and you cannot opt out of them while you hold an account.
We will only send you marketing communications where this is permitted by law, and you can opt out at any time using the unsubscribe mechanism in the message or by contacting us. We do not sell your information to third parties for their marketing.
The Service is a business IT-asset-management tool intended for organisations and their staff. It is not directed at, or intended for use by, children, and we do not knowingly collect personal information from individuals under 18. If you believe a child's personal information has been provided to us, please contact us and we will take appropriate steps to delete it.
We maintain measures to detect and respond to security incidents. If a data breach occurs that is likely to result in serious harm to affected individuals, we will comply with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth), including notifying the OAIC and affected individuals as required.
Where a breach affects People Data we process on a Customer's behalf, we will notify the affected Customer without undue delay and cooperate with the Customer so it can meet its own notification obligations.
We may update this Privacy Policy from time to time to reflect changes to the Service, our practices, or the law. The current version will always be available within the Service or on our website, with the effective date shown at the top. Where changes are material, we will take reasonable steps to notify you, for example by email or an in-app notice. Your continued use of the Service after an update takes effect indicates your acceptance of the updated Policy.
If you have a question, request or concern about privacy, or want to make a complaint about how we have handled your personal information, please contact us:
Please include enough detail for us to understand and investigate your concern. We will acknowledge your complaint, investigate it, and respond in writing within a reasonable time (and in any event within 30 days). If we need more time or information, we will let you know.
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC): online at oaic.gov.au, by phone on 1300 363 992, or by writing to GPO Box 5288, Sydney NSW 2001. The OAIC generally expects you to raise your complaint with us first and give us a chance to respond.
This Privacy Policy is governed by the laws of Queensland, Australia and the Commonwealth of Australia. It should be read together with our Terms of Service and any applicable data processing terms.