Mandate
What is MandateWhy MandateHow it works
Sign inSee Mandate in action
Sign in

LEGAL · PRIVACY POLICY

Privacy Policy

Australian SaaS / business control platform

Last updated: 18 August 2026

Mandate Privacy Policy

Australian SaaS / business control platform

1. Who we are

Mandate is a business control and accountability platform available through mandatehq.com.au and related application services. The service is operated by ESNP PTY LTD (ABN 19 607 597 526, ACN 607 597 526), trading as Mandate HQ (we, us or our). This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with Mandate.

Mandate is primarily intended for organisations and their authorised users in Australia. An organisation using Mandate generally decides what workforce, business, asset, finance and document information it enters into its Mandate environment and who may access that information.

2. Scope of this policy

This policy applies to the Mandate public website, the Mandate application, account administration, support, security operations, integrations and other services we provide. It does not replace an organisation's own privacy notices, employment policies or legal obligations to its employees, contractors, customers or other individuals.

For customer-controlled records, we generally handle the information to provide the service to the organisation. We may separately handle account, billing, support, security and product-use information for our own legitimate business and legal purposes.

3. Personal information we may collect

Depending on the modules and features used, personal information handled through Mandate may include:

  • Account and contact information, such as name, email address, phone number, organisation, role, sign-in identifiers and account preferences.
  • Organisation and access information, such as branches, locations, departments, positions, permissions, administrator settings and audit history.
  • Workforce and engagement information, such as employment or contractor status, role, start or end dates, onboarding information, emergency contacts and work-related declarations.
  • Identity, qualification and compliance information, such as licences, tickets, certifications, right-to-work evidence, identity documents and expiry or renewal dates where an organisation chooses to record them.
  • Payroll, payment or financial information where enabled, such as bank details, pay-related records, expense or reimbursement information, approvals and supporting evidence.
  • Business and accounting information, including integration metadata and, where an organisation authorises a connected accounting feature, accounting records made available through that integration.
  • Asset and custody information, such as an individual's assignment to or responsibility for vehicles, equipment, technology or other assets.
  • Documents and evidence uploaded to or generated through the service.
  • Support and communication records, such as enquiries, implementation notes, service requests and incident reports.
  • Technical, usage and security information, such as IP address, browser or device information, timestamps, authentication events, diagnostic logs and security events.

4. Sensitive information

Some organisations may use Mandate to handle information that is sensitive under Australian privacy law, for example health information contained in an incident or leave record, or other sensitive information contained in documents or onboarding responses. Sensitive information should only be entered where the organisation has a lawful basis to collect and use it and where the information is reasonably necessary for the relevant function or activity.

Mandate does not require organisations to collect sensitive information merely because a field or document feature exists. Organisations are responsible for deciding what information is appropriate to collect from their people and for providing any notices or obtaining any consents required by law.

5. How we collect information

We may collect personal information:

  • directly from you, including when you request access, create or use an account, complete onboarding, upload a document, submit a form or contact support;
  • from the organisation that invites you to or administers Mandate;
  • from other authorised users acting within their organisation's permissions;
  • from connected services or integrations that the organisation authorises;
  • automatically through normal operation of the service, including authentication, audit, security and diagnostic logs; and
  • from public or lawful business sources where reasonably necessary for implementation, support, verification or administration.

6. How we use personal information

We may use personal information to:

  • provide, operate, maintain and improve Mandate;
  • create and administer organisations, accounts, permissions and subscriptions;
  • deliver workflows, reminders, alerts, approvals, audit history and other features configured by an organisation;
  • store, retrieve and present records and evidence to authorised users;
  • support onboarding, implementation, troubleshooting and customer service;
  • secure the service, investigate misuse, detect incidents and maintain audit records;
  • operate authorised third-party integrations;
  • communicate important service, security, billing or product information;
  • analyse reliability and product performance using information appropriate for that purpose; and
  • comply with applicable legal obligations and respond to lawful requests.

7. AI and automated processing

Mandate may use automation and, where enabled, AI-assisted features to reduce administrative effort, for example to summarise information, classify records, suggest categories or highlight items that may need attention. Mandate's product design is that AI may assist and recommend, but does not autonomously approve, make binding business decisions or override a person's accountability.

Where personal information is used in an automated process, we aim to use only the information reasonably necessary for that function and to maintain appropriate human oversight. We will update this policy if our use of automated decision-making changes in a way that materially affects individuals' rights or interests.

Internal development tools

Our development team may use software engineering and AI-assisted coding tools to write, review and maintain source code. Our policy is not to intentionally submit live customer production data, employee records, payroll data, identity documents or other sensitive customer information into general-purpose development assistants. Development tools are not intended to form part of Mandate's production customer-data processing pipeline.

8. Disclosure of personal information

We may disclose or make personal information available:

  • within the relevant organisation, according to the permissions and access settings configured for that organisation;
  • to an authorised service provider or implementation partner where the organisation has approved or enabled that access;
  • to infrastructure, hosting, database, authentication, email, security, support and other suppliers that help us operate Mandate;
  • to connected third-party services, such as an accounting platform, when an organisation authorises the integration;
  • to professional advisers, insurers, auditors or potential business transaction counterparties where reasonably necessary and subject to appropriate confidentiality obligations; and
  • where required or authorised by law, court order or a lawful regulatory or enforcement process.

We do not sell personal information.

9. Overseas handling and service providers

Some technology and integration providers may store or process information outside Australia. Based on Mandate's current service configuration and providers, personal information may be processed in Australia and the United States, and may also be processed in other countries where an authorised provider or its subprocessors operate. We take reasonable steps required by applicable Australian privacy law when personal information is handled overseas and will update this policy if our material processing locations change.

10. Security

We take reasonable technical and organisational steps designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Controls may include organisation separation, permission-based access, authentication controls, encryption or protected storage where appropriate, audit history, secure document access and monitoring of security-relevant events.

No internet or cloud service can guarantee absolute security. Organisations are also responsible for managing their users, permissions, devices and internal access practices.

11. Retention, deletion and de-identification

We retain personal information for as long as reasonably necessary to provide the service, meet contractual commitments, maintain security and audit history, resolve disputes and comply with legal obligations. Where personal information is no longer required for a permitted purpose and we are not legally required to retain it, we will take reasonable steps to delete or de-identify it.

Deletion from active systems may not immediately remove information from encrypted backups or immutable security records. Such copies may remain for a limited period until they are overwritten or expire under our retention processes.

12. Access and correction

You may request access to, or correction of, personal information that we hold about you, subject to applicable law. Where the information is controlled by the organisation you work for or are engaged by, we may refer the request to that organisation or ask you to contact its administrator.

13. Direct marketing and service communications

We may send operational communications that are necessary to provide Mandate, such as account invitations, security alerts, workflow notifications and service notices. If we send promotional or marketing communications, we will provide a way to opt out where required by law. Opting out of marketing does not prevent us from sending essential service or security communications.

14. Cookies and similar technologies

The Mandate website and application may use cookies, local storage and similar technologies that are reasonably necessary for sign-in, security, preferences, performance and analytics. Where optional analytics or marketing technologies are introduced, we will update our notices and consent practices where required.

15. Data breaches

We maintain processes for assessing and responding to suspected data breaches. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify affected individuals and the relevant regulator as required.

16. Complaints

If you have a privacy concern or complaint, contact us using the privacy contact below. We will investigate and respond within a reasonable period. If you are not satisfied, you may be able to complain to the Office of the Australian Information Commissioner (OAIC).

17. Changes to this policy

We may update this Privacy Policy to reflect changes to the service, law or our information-handling practices. We will update the 'Last updated' date and, where a change is material, take reasonable steps to bring it to the attention of affected users or organisations.

18. Contact

Privacy enquiries: privacy@mandatehq.com.au

Operator: ESNP PTY LTD trading as Mandate HQ

ABN: 19 607 597 526

ACN: 607 597 526

Location: Queensland, Australia

← Back to Mandate

Mandate

Where decisions become action.

Product

  • Plans & pricing
  • Capabilities
  • Workforce migration
  • How Mandate Works

Company

  • Contact

Trust & legal

  • Security
  • Privacy
  • Terms
  • Cookie Policy
  • EULA

© 2026 Mandate

People · Assets · Finance · Me