SECURITY + DATA PROTECTION

Controlled access. Traceable history. Customer-owned data.

Mandate is designed to keep business information available to the right people, inside the right organisation, with permission-based access and a traceable operational history.

Last updated: 26 August 2026

Access pillars

  • INDIVIDUAL ACCESS

    Authorised users use individual accounts.

  • ORGANISATION CONTROL

    Customers decide who may access their Mandate environment.

  • DELEGATED ACCESS

    Service Provider Access is customer-authorised and permission-scoped.

  • TRACEABLE EVENTS

    Authentication, audit and security events can leave history.

ACCESS MODEL

Access follows authority, not visibility.

A record existing in Mandate does not automatically create a login. Access is granted to authorised users and shaped by the organisation's configured permissions.

  1. PERSON

    exists in the organisation

  2. ACCOUNT

    individual authorised sign-in

  3. PERMISSION

    what this user may do

  4. ORGANISATION

    where that authority applies

  5. ACTION

    work performed in Mandate

  6. HISTORY

    audit / security context retained

CURRENT POLICY POSITION

What Mandate currently establishes.

These statements are intentionally limited to controls and responsibilities described by Mandate's Privacy Policy, Terms of Use and EULA.

  • CUSTOMER DATA

    The customer organisation retains ownership of Customer Data and decides what information it is legally entitled to collect and store.

  • ORGANISATION SEPARATION

    Controls may include organisation separation, permission-based access, authentication controls and secure document access.

  • DATA PROTECTION

    Mandate takes reasonable technical and organisational steps designed to protect information from misuse, interference, loss and unauthorised access.

  • SERVICE PROVIDER ACCESS

    External provider access must be authorised by the customer and remains subject to the scope and permissions configured for that relationship.

  • AUDIT + SECURITY EVENTS

    Technical, usage and security information may include timestamps, authentication events, diagnostic logs and security events.

  • RETENTION + BACKUPS

    Deletion from active systems may not immediately remove information from encrypted backups or immutable security records; those copies may remain for a limited period.

AI + DEVELOPMENT TOOLS

Assistive by design. Human accountability stays in place.

Where enabled, Mandate may use automation or AI-assisted features to summarise, classify, suggest or surface information. The product position in the Privacy Policy and EULA is that these features assist people rather than autonomously make binding business decisions.

SHARED RESPONSIBILITY

Security is shared between Mandate and the customer organisation.

Mandate protects the service within its control. Customers remain responsible for their users, permissions, devices and decisions about what information they collect and store.

Customer responsibilities

  • ✓ Protect account credentials and devices.
  • ✓ Use individual accounts rather than shared sign-ins.
  • ✓ Assign, vary and remove permissions appropriately.
  • ✓ Decide what information may lawfully be collected and stored.
  • ✓ Notify Mandate if unauthorised access or a security incident is reasonably suspected.

THIRD-PARTY SERVICES

Infrastructure and integrations can involve other providers.

Mandate may use infrastructure, hosting, database, authentication, email, security, support and other suppliers. Organisations may also authorise integrations with external business systems.

  • AUSTRALIA

    Mandate is primarily intended for organisations and authorised users in Australia.

  • UNITED STATES

    Based on the current policy, some personal information may be processed in the United States.

  • OTHER PROVIDER LOCATIONS

    Information may also be processed in other countries where an authorised provider or its subprocessors operate.

Security questions should have a clear destination.

Privacy enquiries: privacy@mandatehq.com.au

Security and legal enquiries: legal@mandatehq.com.au

Operator: ESNP PTY LTD trading as Mandate HQ · Queensland, Australia