Back to Policies

Privacy Policy

We take the privacy of the people whose information passes through our hands seriously. This policy explains what personal information we collect, how we use it, who we share it with, and what rights you have. It covers personal information we collect for our own purposes, and personal information we handle on behalf of our…

Privacy Policy

Mojo Soup Pty Ltd
Effective: September 2026 · Version 1.2

We take the privacy of the people whose information passes through our hands seriously. This policy explains what personal information we collect, how we use it, who we share it with, and what rights you have.

It covers personal information we collect for our own purposes, and personal information we handle on behalf of our clients in the systems we host and support.

1. Who we are

Mojo Soup Pty Ltd is an Australian digital and business transformation partner. We design, build, host and support technology solutions for private and public sector clients.

We handle personal information in accordance with the Australian Privacy Principles.

Where we deliver services to a government agency, we are held to the same privacy standards as the agency itself. For Queensland Government clients, this means we apply the Queensland Privacy Principles to the information we handle on their behalf. Equivalent standards apply where we work with agencies in other jurisdictions.

2. Two different roles

There are two ways personal information reaches us, and different rules apply to each.
Information we collect for our own purposes. This is information you give us directly, such as when you contact us, apply for a role, or subscribe to something we publish. We decide what we collect and why. Sections 3 and 5 to 13 apply.
Information we handle for our clients. When we host or support a system for a client, that system holds information about the client’s own staff, customers or citizens. We do not decide what goes into it and we do not own it. Our client does. We handle it only to deliver the service we have been contracted to deliver. Section 4 applies, along with sections 5 to 13.

3. Information we collect for our own purposes

Depending on how you interact with us, this may include:

  • Your name, job title and the organisation you work for.
  • Your contact details, including email address and phone number.
  • The content of your enquiry or correspondence with us.
  • Recruitment information, if you apply to work with us.
  • Technical information about your visit to our website, including analytics and cookie data.

We use this information to respond to you, to manage our client and supplier relationships, to consider you for roles, and to improve our website.

Our website uses cookies and similar technologies to understand how visitors use the site so that we can improve it. We use Google Analytics, which sets cookies and collects information such as the pages you visit, how long you spend on them, the type of device and browser you use, and a general location derived from your IP address. You can block or delete cookies through your browser settings, and doing so will not stop you using the site.

4. Information we handle for our clients

Our role

When we host or support a client system, the client remains responsible for the personal information it holds. The client decides what is collected, why, and who may access it. The client issues its own collection notice and privacy policy to the people whose information is in the system.

Our role is to run the platform securely and to act on our client’s instructions.

What we handle

The information varies by engagement, and is set by the client. It commonly includes names, work contact details, organisational details, user profiles and access records, records associated with a person’s role, and system-generated audit logs and usage information.

What we use it for

We use personal information held in a client system only to perform our obligations under our contract with that client. In practice this means:

  • Authenticating users and granting, changing and removing access.
  • Hosting, operating, maintaining, patching and supporting the platform.
  • Monitoring performance, availability, security, compliance and audit requirements.
  • Investigating and resolving incidents and service requests.
  • Producing operational and service level reporting for the client.
  • Carrying out testing, evaluation and continuous improvement at the client’s direction.
  • Producing de-identified statistical insights and reporting at the client’s direction.

What we do not do

  • We do not use client-held personal information for any purpose other than performing the contract.
  • We do not sell, rent or trade personal information.
  • We do not use it for marketing, sales or business development.
  • We do not use it to train artificial intelligence or machine learning models.
  • We do not combine one client’s data with another’s.

5. Who we share information with

We share personal information only where we need to and only where we are permitted to:

  • Our own personnel, restricted to those who need access to do their job. All personnel are bound by confidentiality obligations and privacy training, and sign additional deeds where a client requires it.
  • Our subcontractors and technology partners, where they are needed to deliver the service. They are bound by contract to the same privacy, confidentiality and security obligations that apply to us.
  • Cloud platform providers, principally Microsoft, which provides the hosting platform for most of the solutions we deliver.
  • Our client, where the information is theirs.
  • Google, which provides the analytics service described in section 3, and the providers of our newsletter and enquiry tools. These providers receive website and newsletter information only. They never receive information we hold on behalf of a client.

We will not disclose personal information held on behalf of a client to anyone else without that client’s prior written consent, unless the disclosure is required or authorised by law. Where we are compelled by law to disclose, we tell the client where we are legally able to do so.

6. Where information is stored

Personal information we hold on behalf of our clients is stored in Australia, in Australian cloud regions operated by our platform providers, or on systems located in Australia. We do not transfer it outside Australia. Where a client engagement requires otherwise, we do so only with that client’s prior written consent.

Our own business systems are also hosted in Australia. The exception is website analytics and newsletter information. Google Analytics processes data on servers outside Australia, as may the providers of our newsletter and enquiry tools. This information is limited to what is described in section 3 and never includes information we hold for a client.

7. How we protect it

We protect personal information against loss and against unauthorised access, use, modification, disclosure and other misuse. Our controls include:

  • Encryption of data at rest and in transit, using current industry standards.
  • Multi-factor authentication and privileged access management for administrative access.
  • Role-based access control, applied on a least-privilege basis.
  • Named individuals nominated for access to client production data and environments, approved by the client, with any change to those individuals or their scope of access approved in the same way.
  • Network segmentation and isolation of client environments from one another.
  • Audit logging of access, changes and administrative actions.
  • Continuous monitoring with security alerting.
  • Patching to the manufacturer’s recommendations.
  • Regular testing against common application vulnerabilities.

We are working towards ISO/IEC 27001 certification. Where a client engagement requires certification of our infrastructure partners, we contract only with partners who hold it.

Where a client requires it, we complete annual security assessments and support independent security, vulnerability and penetration testing of the environments we run.

8. How long we keep it

We keep personal information for as long as we need it for the purpose we collected it, and for as long as the law requires.

For information we hold on behalf of a client, retention is set by the client and by the records legislation that applies to them. When an engagement ends, we give the client the agreed period to extract its data, then securely destroy or erase the remaining copies in our possession and confirm this to the client in writing.

9. Accessing and correcting your information

You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, incomplete or out of date.

If your information is in a system we host for a client, that information belongs to the client, not to us. Please make your request to the organisation that gave you access to the system. They will contact us if they need our help. We do not action access or correction requests received directly from individuals for client-held information, and we will refer you to the right place if you contact us.
For information we hold for our own purposes, contact us using the details in section 13.

10. Data breaches

If personal information we hold is lost, or accessed, used, changed or disclosed without authorisation, we act immediately to contain the incident and limit the harm.

Where the information belongs to a client, we notify that client immediately, investigate with them, provide a risk assessment and root cause analysis within the timeframe our contract requires, and carry out an agreed remediation plan. We give the client whatever information it needs to meet its own data breach notification obligations. The client decides whether a breach is notifiable, and makes any notification to the regulator and to affected individuals.

Where the information is our own, we assess the breach and notify in line with our obligations under Australian privacy law.

11. Complaints

If you believe we have mishandled your personal information, please tell us using the details in section 13. We will acknowledge your complaint within five business days and respond as quickly as we can.

If your complaint relates to information held in a system we run for a client, we will refer it to that client, because they are the organisation responsible for the information, and we will tell you who is handling it.

If you are not satisfied with the outcome, you can refer your complaint to:
The Office of the Information Commissioner Queensland at oic.qld.gov.au, for information held by a Queensland Government agency.
The Office of the Australian Information Commissioner at oaic.gov.au, for information covered by Commonwealth privacy law.

12. Changes to this policy

We review this policy at least annually, and whenever there is a material change to our services or to privacy law. The current version is always the one published on this page.

13. Contact us

Privacy Officer, Mojo Soup Pty Ltd
Email: info@mojosoup.com.au
Phone: 1300 984 767
Post: Level 1, 200 Creek Street, Spring Hill QLD 4000
ABN: 35 135 971 836
mojosoup.com.au