Skip to content
Home » Privacy Policy

Privacy Policy

WHO WE ARE

Merlo AI Technologies Pty Ltd (ACN 685 955 266, ABN 93 685 955 266) builds an AI platform for strata and property management businesses. We’re based at Suite 19, Level 2, 66 Victor Crescent, Narre Warren, Victoria 3805.

This policy explains what we do with personal information. We handle it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Questions, requests or complaints: privacy@merlo.ai

THE TWO SITUATIONS THIS COVERS

Your rights depend on which of these applies to you, so it’s worth thirty seconds.

If you deal with us directly — you enquired about the platform, you use it as one of our customer’s staff, you contacted support, or you visited our website — we handle your information for our own purposes. This policy covers that, and you can contact us about it.

If your information is in a customer’s system — you’re a lot owner, occupier, tenant, committee member, supplier or contractor, and a strata or property manager uses our platform — then we’re just the software. Your strata or property manager decides what information exists, what happens to it, and how long it’s kept. We act on their instructions.

So if you want to see what’s held about you, have it corrected, or raise a concern, contact the strata or property manager you deal with, not us. They hold the relationship and the obligations. If you write to us instead, we’ll pass it to them and tell you we have.

WHAT WE COLLECT ABOUT YOU

If you enquire or use the platform: your name, work email, phone, job title, the business you work for, and — if you’re a user — your access role, login records, and what you did in the platform, including which actions you approved.

If you contact support: your contact details and whatever you tell us or attach.

If you visit our website: IP address, browser and device type, pages viewed, and when. Through cookies. More on that below.

If you apply for a job or supply us: what you send us, and what referees tell us.

We don’t seek out sensitive information — health, biometric, racial or ethnic origin, political or religious views, sexual orientation, criminal record. We ask our customers not to put sensitive information into the platform, and our customer agreement says so.

We don’t use government identifiers like tax file numbers or licence numbers as our own way of identifying you.

You can browse our website without telling us who you are. We can’t give you support or platform access without knowing who you are.

WHY WE USE IT

To answer your enquiry. To run, support, secure and improve the platform. To create accounts and manage access. To keep a record of who approved what, so our customers can supervise their own business. To investigate incidents and prevent misuse. To invoice. To send you notices about maintenance, security and changes to our terms. To send marketing, if you want it. To understand how the platform is used so we can make it better. To hire people. To meet our legal obligations.

We won’t use it for something unrelated unless you’d reasonably expect it, you’ve agreed, or the law requires it.

HOW WE HANDLE OUR CUSTOMERS’ DATA

This is the part our customers care about, and the part we’ve designed deliberately.

We keep as little as possible

The platform works inside your Microsoft 365 environment and the other systems you connect. It reads what it needs, when it needs it, and that information stays where it lives — in your mailboxes, your documents, your strata management platform.

What we store in our own database is operational data: the references, status, timestamps, configuration and audit records we need to run a workflow and show you what happened. Our database is not a second copy of your mailbox, your document library or your strata records — those stay in your systems.

Your data is yours

Our customers own their data. We don’t. We use it only to run the platform for them, to follow their instructions and configuration, and where the law requires us to.

We don’t sell it. We don’t hand it to anyone for their own commercial purposes. We don’t use it for advertising.

We don’t train AI models on it

We don’t use our customers’ data to train, fine-tune or improve any AI model, and the AI provider we use is contractually barred from doing it too.

We do look at de-identified, aggregated numbers about how the platform performs — volumes, response times, error rates, which features get used. That doesn’t identify a customer, a person or a property.

Where it lives

Our database and file storage sit in Microsoft Azure’s Australia East region, in Sydney.

Email, calendar, documents and directory data stay in your own Microsoft 365 tenant, in whatever region you’ve configured. We work with it there rather than moving it to us.

AI processing happens overseas. That’s the next section, and it’s the one to read properly.

How long we keep it

We delete our customers’ data within 30 days of their contract ending. Backups are overwritten on a rolling cycle shortly after that.

We keep de-identified aggregated information, and anything the law requires us to retain.

Requests from individuals

If someone asks us for access to, correction of, or deletion of information sitting in a customer’s account, we refer it to that customer and tell the person we’ve done so. We don’t answer for our customers — they hold the relationship. We help them respond.

AI PROCESSING OVERSEAS

To do the AI part, we send content to OpenAI for processing. That happens in data centres outside Australia, including the United States. The content can include personal information about lot owners, occupiers, tenants, committee members and suppliers.

We’ve configured it so that:

  • the content isn’t retained by OpenAI after the response comes back, and
  • it isn’t used to train or improve their models.

Those are contractual commitments, and we take reasonable steps to make sure the provider handles personal information consistently with the Australian Privacy Principles.

What we can’t change: an overseas provider is subject to the laws of its own country. Those laws differ from Australian law and may let or require it to disclose information to a government or regulator there. Australian law may not be enforceable against it, and you may not be able to get redress under the Privacy Act for what it does.

If you’re a lot owner, occupier or tenant: this disclosure is made by your strata or property manager, using our platform — not by us on our own account. Our customer agreement requires them to tell you about it in their own privacy notice. Ask them, and see “the two situations” above.

WHAT THE AI ACTUALLY DOES

Since we’re an AI company, you’re entitled to a plain answer.

It reads and drafts. It interprets information in our customer’s systems and produces drafts, classifications, summaries, extracted values, reminders and suggested actions. It can also do things — draft or send correspondence, create a task or work order, update a record.

A person approves the things that matter. The platform is set up so that significant actions are prepared and then held for a person to approve before they take effect. That covers changes to contact details, bank or payment details, levy and financial records, insurance policy details, renewal dates and premiums, and strata roll entries — plus supplier instructions, compliance filings, anything that binds or changes an insurance policy, and anything that creates or waives a legal right.

Our customer agreement requires our customers to keep that setting in place and to have a qualified person review each one.

It doesn’t decide things about you on its own. We don’t use the platform to make a decision with a legal or significant effect on someone without real human review, and our customer agreement prohibits our customers from doing it. Where the AI produces something that feeds a decision about you, it’s a recommendation to a person. The person decides.

It can be wrong. AI is probabilistic. It can produce output that’s inaccurate or out of date, and it can sound confident while being wrong. That’s exactly why a person reviews it. If you think a decision about you was based on something inaccurate, talk to the strata or property manager you deal with.

There’s a record. The platform logs what it did, what it referenced, who approved it and when, so our customers can show how something was handled.

WHO ELSE SEES IT

The providers who help us run the platform:

ProviderWhat forWhere
Microsoft AzureHosting, database, file storage, backupsAustralia East (Sydney)
Microsoft Azure Monitor and Application InsightsPerformance monitoring, error loggingAustralia East (Sydney)
Microsoft 365 and Microsoft GraphWorking with the mailboxes, calendars, files and directory in your own tenant, and sending mail through itYour tenant, in your region
OpenAIAI processing — classification, extraction, summarising, draftingUnited States and other locations they use
Atlassian (Jira)Support requestsAustralia or the United States, depending on how our Atlassian instance is configured

We also use providers for things that don’t touch customer data — website hosting and analytics, CRM and marketing, e-signature, accounting and payments.

We check providers before we use them, and our contracts with them cover confidentiality, security and limits on what they can do with the information. AI providers are also barred from training on it.

If you’re one of our customer’s users, we show that customer what you did in the platform, including what you approved or rejected. They’re entitled to supervise how it’s used in their business.

We may also disclose information to our professional advisers under confidentiality; to a referral partner who introduced you, only as far as needed; to a court, regulator or law enforcement agency where the law requires it; and to a prospective purchaser or investor in our business under confidentiality.

If we get a legal demand for a customer’s data, then unless we’re barred from doing so we’ll tell that customer first, give only what’s required, and try to have the demand pointed at them instead of us.

SECURITY

We take reasonable steps to protect information from loss, misuse and unauthorised access.

Data is encrypted in transit and at rest. Access by our people is limited to those who need it for a specific reason, uses named accounts with multi-factor authentication, and is logged. Credentials for connected systems are held in a managed secrets service. We run backups. We review code before it ships, scan our dependencies for known vulnerabilities, and have controls aimed at prompt injection. Our people are under confidentiality obligations and get privacy and security training. We have an incident response plan.

Two things worth being straight about.

We run shared infrastructure. Our customers’ data sits in a shared, multi-tenant database rather than a separate database per customer. Access is scoped so that a customer’s users see only that customer’s data. Where the platform works inside your Microsoft 365 environment, who can reach what is governed by the identity, permission and conditional access controls you already run there — we don’t build a parallel one.

We’re not certified. We don’t hold ISO 27001 certification or a SOC 2 attestation. What’s above is what we do, not what an auditor has signed off. We’ll say so if that changes.

No system is perfectly secure. If you think something’s gone wrong, email privacy@merlo.ai.

IF THERE’S A DATA BREACH

If we find out that personal information we hold has been accessed, disclosed or lost without authorisation, we’ll assess it quickly and work to contain it.

Where it affects a customer’s data, we notify that customer without undue delay and within 48 hours of becoming aware, tell them what we know, and help them work out whether it’s a notifiable breach and make any notification they have to make.

Where we’re the one who has to notify, we notify affected individuals and the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme.

MARKETING

We’ll email you about our products if you’ve asked us to, if you gave us your details in a business context and would expect it, or if you’ve otherwise agreed. Every marketing email has an unsubscribe link, and you can tell us to stop any time at privacy@merlo.ai. We comply with the Spam Act 2003 (Cth).

Service messages are different. If you’re a user or a billing contact, we’ll still send you notices about security, maintenance and changes to our terms, because you need them.

We don’t hand your details to anyone else for their marketing.

COOKIES

Our website uses cookies to make it work, remember your preferences, and understand how the site is used. Some are ours, some belong to the analytics and marketing tools we use. Your browser settings can block or delete them, though parts of the site may stop working properly if you do.

We link to other websites. Their privacy practices are their own.

SEEING AND FIXING YOUR INFORMATION

Email privacy@merlo.ai and ask. We may need to check who you are first, so we don’t give your information to someone else.

We’ll usually respond within 30 days. There’s no charge to ask. If giving you access takes substantial work we may charge a reasonable cost-based fee, and we’ll tell you the amount before we spend it.

The Privacy Act lets us refuse in some situations — where it would unreasonably affect someone else’s privacy, where it relates to anticipated legal proceedings, or where a request is frivolous or vexatious. If we refuse, we’ll tell you why in writing and how to complain about it.

If your request is about information in a customer’s account, send it to the strata or property manager you deal with. See “the two situations” above. If it comes to us, we’ll refer it and let you know.

COMPLAINTS

Tell us. We’d rather hear it and fix it.

Email privacy@merlo.ai with enough detail for us to understand what happened. We’ll acknowledge it within 5 business days, investigate, and respond in writing — usually within 30 days. If we need longer we’ll tell you why and when.

If you’re not satisfied, the Office of the Australian Information Commissioner can take it from there:

  • oaic.gov.au
  • 1300 363 992
  • GPO Box 5288, Sydney NSW 2001

CHANGES

We’ll update this policy as the platform, our providers or the law change. The current version is always on our website with its version number and date at the top. We’ll take reasonable steps to tell customers and users about material changes, and where a contract requires notice, we’ll give it.

Changes to providers who handle customer data are notified to our customers under their agreement with us.

CONTACT

Privacy — privacy@merlo.ai

Support — support@merlo.ai

Post — Privacy Officer, Merlo AI Technologies Pty Ltd, Suite 19, Level 2, 66 Victor Crescent, Narre Warren, Victoria 3805, Australia

End of policy.