Legal

Privacy Notice

MONOLITHS ONLINE (ABN 42 677 027 584) operates Monoliths and is the data controller for the personal information described below. This notice explains what we collect, why we collect it, who we share it with, and the choices you have.

Last updated 24 August 2026

Who we are

MONOLITHS ONLINE, a company registered in Australia (ABN 42 677 027 584), trading as Monoliths. We decide how personal information in the Monoliths service is handled, which makes us the data controller. Privacy questions can be sent to support@monoliths.online.

Where you store your own clients' details in Monoliths, you are the controller of that information and we process it on your behalf as part of providing the service.

What we collect and why

  • Account details — name, email address, login credentials and authentication identifiers (including Google sign-in identifiers if you use it). Used to create and secure your account. Legal basis: performance of our contract with you.
  • Business profile — business name, ABN or tax number, phone, website, address, logo and document footer. Used to brand your quotes and documents. Legal basis: performance of contract.
  • Workspace content — projects, tasks, events, notes, quotes, client names and uploaded files and images. Used to provide the workspace and sync it across your devices. Legal basis: performance of contract.
  • Communication preferences — reminder email address, daily digest settings and digest hour. Used to send the reminders you ask for. Legal basis: performance of contract and, for marketing messages, consent.
  • Subscription records — plan, subscription status, billing period and the customer and subscription identifiers issued by our payment provider. Used to give you the right level of access. Legal basis: performance of contract and legal obligation. Card and payment details are collected and held by Paddle, not by us.
  • Technical and usage data — IP address, device and browser information, timestamps, error reports and basic usage events. Used to keep the service secure, diagnose faults and improve the product. Legal basis: legitimate interests in operating a secure, working service.
  • Support messages — the content of emails and requests you send us. Used to answer you and improve support. Legal basis: legitimate interests.

Who we share information with

  • Paddle.com — our Merchant of Record and reseller, for the sale of subscriptions, payment processing, subscription management, invoicing, tax compliance and refunds.
  • Infrastructure and hosting providers — for application hosting, database storage, file storage, authentication and transactional email delivery.
  • Services you connect yourself — if you link a third-party account such as a calendar or file storage provider, information is exchanged with that provider under your authorisation, and you can revoke access at any time.
  • Professional advisers — legal, accounting and audit advisers where necessary.
  • Authorities — where we are required to disclose by law, or to establish or defend legal claims.

We do not sell personal information, and we do not share it for third-party advertising.

International transfers

Our providers may store or process information outside Australia, including in the United States and the European Union. Where information leaves Australia or the EEA/UK, we rely on appropriate safeguards such as standard contractual clauses or adequacy decisions, and we require providers to protect it to a comparable standard.

How long we keep it

We keep workspace content for as long as your account is active. After you close your account or your subscription ends, your content stays available for export for 30 days and is then deleted or anonymised from active systems, with backups aging out shortly afterwards. Billing and tax records are retained for as long as Australian law requires (generally five to seven years). Security logs are kept for a short rolling period.

Security

We apply appropriate technical and organisational measures, including encryption in transit and at rest, row-level access controls so each account can only reach its own records, private storage for uploaded files and logos with time-limited access links, hashed credentials, and least-privilege access for administrators. No system is perfectly secure, but we treat unauthorised access as a serious incident and will notify affected users and regulators where the law requires.

Your rights

Subject to applicable law, you can ask us to give you access to the personal information we hold about you, correct it if it is wrong, delete it, restrict or object to certain processing, provide it in a portable form, or withdraw consent where we relied on consent. Most of this you can do yourself from your workspace settings; otherwise email support@monoliths.online and we will respond within one month.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). Users in the UK or EEA may also complain to their local supervisory authority.

Cookies and similar technologies

We use strictly necessary cookies and local storage to keep you signed in, remember your workspace preferences and protect against abuse — the service cannot function without these. We use a small amount of aggregate product analytics to understand which features are used. We do not run advertising or cross-site tracking cookies. You can clear or block cookies in your browser settings, though signing in will not work without the essential ones.

Changes and contact

We will update this notice as the service evolves and will tell you about material changes by email or in-app. See also our Terms & Conditions and Refund Policy.

MONOLITHS ONLINE (ABN 42 677 027 584) — support@monoliths.online