AusMDM
← ausmdm.com.au

AusMDM Privacy Policy

Effective date: 1 July 2026 · Last updated: 11 August 2026

1. Who we are

AusMDM ("we", "us") is operated by AUSMDM PTY LTD (ACN 699 803 542, ABN 37 699 803 542), based in Queensland, Australia. We provide a mobile device management (MDM) platform that Australian businesses use to manage their own company-owned Android devices, and businesses manage their devices through our web console.

Software on a managed device. Depending on how a device is enrolled, one or more of the following are installed on it: the AusMDM Agent (com.ausmdm.agent); Android Device Policy, Google's own device management application, where a device is enrolled through Google's Android Management API; and AusMDM companion applications such as AusMDM Location (com.ausmdm.location), which records device location, and, in future, an AusMDM launcher and an AusMDM support application. Where this policy refers to the Agent, it refers to whichever of these AusMDM applications is installed on the device.

Contact: matthew@ausmdm.com.au · https://ausmdm.com.au

2. Important - the role of your employer

AusMDM is deployed by businesses on devices those businesses own, to manage and secure those devices. If you are an employee or user of a device managed with AusMDM, your employer (the organisation that owns and enrolled the device) decides what data is collected and how it is used. In data-protection terms, your employer is the controller of that data and AusMDM acts as the processor operating the platform on their behalf. If you have questions about how your device is managed or want to access or correct your information, please contact your employer in the first instance.

3. Customers, end users and administrators

AusMDM is a device-management service that businesses subscribe to in order to manage their own devices. To explain how privacy responsibilities are split, this policy uses the following terms:

For account information about Customers and Administrators - such as login details, billing details, and use of the console - AusMDM decides how that information is used and is responsible for it (the data controller). This is the information described elsewhere in this policy.

For information on or about managed devices and their End users, AusMDM acts only on the Customer's instructions and handles that information on the Customer's behalf (as a data processor). In these cases the Customer is responsible for the End user's information (the data controller). If you are an End user and you want to access, correct, or delete your information, or you have questions about why a device is managed, please contact your employer or the organisation that manages your device - they control that information, not AusMDM.

Some AusMDM support features - including remote view, screenshots, and remote control - can display whatever is shown on a managed device at the time an Administrator uses them, and a saved screenshot may retain it. An Administrator can also send a message that appears on the device. A Customer is responsible for telling its End users that their devices are managed and may be viewed or controlled remotely for support, and for obtaining any consent required by law before enrolling a device.

4. What the AusMDM Agent collects on managed devices

The Agent only operates on managed, company-owned devices, and collects only what is needed to manage those devices:

DataWhy it is collected
Device location (approximate and precise, including in the background), and, where the managing business enables it, a location history / trail of past positions over timeTo let the managing business locate its own company-owned devices in the admin console, to allow a business's clock-in/clock-out web app to record location at the time of clock-in, and - where the business enables location history - to show where a device has been over a chosen period, including grouping past positions into trips and converting recorded coordinates into an approximate street and suburb name for display and export. Location history is an optional feature the managing business turns on; when it is off, no trail of past positions is kept.
Geofence events (where the managing business enables geofencing) - a record that a device entered or left a named place the business has defined, with the time and the location reading at the crossingTo let the managing business see when its own company-owned devices arrive at or leave places it has defined (such as a depot or work site), and, where the business turns on email alerts for a place, to send an alert to the recipients the business chooses. Geofence crossings are worked out on our Australian servers from the location readings the device already sends for the purposes above - the geofencing feature adds no new collection on the device. It is an optional feature the managing business turns on; when it is off, no geofence events are recorded.
Device names and labels (the name, department, group and other fields an administrator gives a device)To help the managing business organise and identify its own devices. These fields are entered by the managing business and may, at the business's choice, include a person's name (for example, the worker a device is assigned to). AusMDM stores whatever the business enters and does not require any personal information in these fields.
Device identifiers & information (device ID, model, manufacturer, serial where available, Android version)To identify and manage each enrolled device and apply the correct policies.
Device status / telemetry (battery level, charging state, network/connectivity status, online status, last-seen time)To show device health in the admin console and deliver management reliably.
App / management information (which managed apps are installed or assigned, kiosk/policy state, management actions and logs)To apply and enforce the policies the business configures (e.g. kiosk, allowed apps, updates).
Messages an administrator sends to a device (the text of a message, who sent it, and when), together with a record of itTo let an administrator send a notice to a managed device - for example an instruction or a reminder - and to show the business a record of the messages it has sent. The administrator writes the message; AusMDM stores it so that it can be delivered and reviewed. This is not SMS or text messaging: it is an in-app notice shown by the AusMDM application, and it does not use the device's phone number or messaging service.
Screen content (live screen view and on-demand screenshots, captured by the accessibility service)To let an administrator remotely view the device screen for support and troubleshooting. Whatever is displayed at the time - which could include personal information you have entered - is visible to the administrator.
Remote control input (taps, swipes, key presses and text entered remotely by an administrator)To let an administrator remotely operate the device for support. Because this runs through the Android accessibility service, the service can also observe on-screen content, including text in input fields.

What the Agent does NOT collect: the Agent does not read, access or collect the device's SMS or text messages, call logs, contacts, the microphone or audio, calendar entries, health/fitness data, photographs or camera images, or web-browsing history. Where a managed device is subject to a website access policy, the policy simply allows or blocks a page from loading on the device; the addresses of pages a person visits or attempts to visit are not recorded on the device and are never sent to us.

An important qualification. A business may choose to allow a messaging, telephone, contacts, camera or photo application to run on a managed device. Anything created with those applications - messages, call history, saved contacts, photographs - is created and stored on the device by those applications. The Agent does not read that content and does not send it to us. However, if an administrator uses remote view or remote control while such content is displayed on the screen, they will see it, and a screenshot an administrator takes and saves to the console may contain it. Screen content is the one route by which information of this kind can reach the console, and only while an administrator is actively viewing or capturing the screen.

What an administrator can see and do

Because AusMDM is a remote-management tool, an administrator from the managing business can - using the features above - view your device's screen live, take screenshots of it, remotely control the device, and send a message to it. While doing so, they may see whatever is on the screen at the time, which can include personal information - for example an open message, a contact, or a photograph, if the business permits those applications on the device.

What remote control means. There is no command in AusMDM that switches on a device's camera or takes a photograph. However, remote control works by sending taps, swipes and typed text to the device, so an administrator using it can operate the device much as a person holding it could - which, if the business permits a camera application on the device and has not disabled the camera, could include opening that application and taking a photograph. A business can disable the camera on its managed devices entirely. We describe this plainly because you should know what the tool can do, not only what it is meant for.

These capabilities exist so the business can support and manage its own devices. Your employer decides when and how they are used and is responsible for informing you about it; if you have questions, contact your employer.

Information the business enters. Some information in the console - such as device names, department and group labels, and (where enabled) a device's location history - is entered or turned on by the managing business, not by AusMDM. Where the business chooses to include a person's name or other personal information in these fields, or to enable location history and screen-capture features on a device assigned to a particular worker, the business is the controller of that information. The business is responsible for having a lawful basis for it and for informing its workers that their devices are managed and may be located, viewed and recorded for management purposes. AusMDM stores and processes this information only on the business's instructions.

5. Information from businesses, administrators and website enquiries

Separately from the device data above, we collect account information from the businesses that buy AusMDM and the administrators who use our web console. This includes the business or organisation name, the administrator's name and email address, a securely hashed password, and the management settings and device data the business configures in its console. Where a business is billed for the service, we also collect billing and business details for invoicing - the business name and ABN, a billing contact name, a billing email address, and a billing address. We use this to create and secure accounts, provide and support the service, issue invoices, and contact administrators about their account. To produce and manage invoices, these billing and business details are sent to our accounting provider, Xero, which creates the corresponding invoice in our accounts. Administrators can view and update their profile details by signing in to the console.

Website enquiries and demo requests. When you submit an enquiry or request a demo through ausmdm.com.au, we collect the details you provide - your name, business name, email address, phone number (if you provide one), region or time zone, approximate number of devices, your preferred demo date and time (for demo requests), and any message - and, if you tick the optional box, your consent to receive AusMDM product updates. We use these details only to respond to your enquiry or arrange your demo and, where you have opted in, to send occasional updates you can unsubscribe from at any time. Enquiry and demo details are delivered to us by email through our email provider, Resend, and are not published or sold.

Cookies and session storage. The AusMDM console uses only the cookies and browser storage needed to sign you in and keep the service working (for example, keeping you signed in), and does not use advertising or cross-site tracking cookies. Our public marketing website (ausmdm.com.au) additionally runs the Google Ads tag (gtag.js), which measures how our advertising performs - for example, whether a visit that followed a Google ad led to an enquiry or demo request. This tag may set advertising cookies in your browser and send information such as your IP address, device and browser type, and the pages you view to Google, which processes it in the United States (see sections 9 and 10). It runs on our public marketing pages only - not in the admin console, not on managed devices, and not on this privacy page - and concerns public website visitors only. You can block or clear these cookies through your browser settings.

6. How we use information

We use the information above only to: enrol and identify managed devices; apply the management policies the business configures (kiosk/single-app mode, allowed apps, updates, location); deliver remote commands, messages and policy updates; provide remote support (live screen view, screenshots, and remote control); create, secure and support console accounts; show device status in the admin console; and keep the Agent and platform running and updated. We do not use it for advertising, and we do not sell it.

7. How information is shared

We do not sell personal information, and we do not share the information we hold about Customers, Administrators, End users or managed devices for third-party advertising. The one exception, on our public marketing website only, is the Google Ads measurement tag described in sections 5, 9 and 10, which relates to public website visitors - not to managed devices, End users, or console data.

8. Apps and content deployed through AusMDM

AusMDM lets a Customer install third-party apps and open web content on managed devices. Those apps and websites are provided by other companies and are governed by their own privacy policies and terms, not by this policy.

AusMDM does not collect, receive, store, or control the personal information that a deployed app or website gathers. For example, if a Customer deploys a staff clock-in app, any details an End user enters into that app - such as their name, email address, or date of birth - are collected and held by that app's provider, not by AusMDM. We never see that information. Where a Customer deploys a web app that requests the device's location (for example, to geo-stamp a clock-in), the managed device may grant that request automatically without an on-screen prompt; the location goes to that web app's provider under its own privacy policy, not to AusMDM.

Cameras and photographs. A Customer may allow a camera application, a photo gallery application, or a website that uses the camera to run on a managed device - for example, a clock-in web app that captures a photograph of the person clocking in. Where that happens, the photograph is taken by that application or website and is stored on the device or sent to that provider. AusMDM does not collect, receive, store or have access to those photographs. The Customer decides whether such applications are permitted on its devices, and is responsible for informing its End users.

Each Customer is responsible for choosing which apps and websites to deploy to its devices, for reviewing the privacy practices of those providers, and for informing its End users and obtaining any consent those providers or the law require.

9. Where your information is stored

We host our platform on servers located in Sydney, Australia. Your console records - devices, users, groups, settings and history - are stored there, and device location and location history travel from the device directly to our Australian servers.

We are precise about this rather than sweeping. Some supporting providers process limited information overseas:

Where information is handled overseas, we take reasonable steps to ensure it is protected consistently with this policy and the Australian Privacy Principles.

10. Sub-processors

To run the service, AusMDM uses a small number of trusted third-party providers ("sub-processors") that may process limited information on our behalf. They are:

As described in the section on where your information is stored, your console records and your device location history are stored in Australia. Device management operations, email delivery, push notifications, invoicing through our accounting provider, advertising measurement on our public marketing website, and (where location history is enabled) the reverse geocoding of coordinates involve information being processed overseas by the providers listed above. We take reasonable steps to ensure our sub-processors protect information consistently with this policy and applicable law, and we will update this list if our providers change.

11. Emails and communications

Service messages. We send emails that are part of providing the service and that you cannot opt out of while you have an account - for example account invitations, password resets, security notices, and notices about changes, updates or upgrades to the service.

Marketing. We may also send administrators and customers emails about AusMDM products, features and offers. If you tick the optional updates box when submitting a website enquiry or demo request, you are opting in to these emails. You can opt out of marketing emails at any time using the unsubscribe link in the email or by contacting us, and we handle marketing messages in line with the Spam Act 2003 (Cth). Opting out of marketing does not stop the service messages above. We do not send marketing to device end users.

12. Data retention

We retain management data for as long as a device is enrolled and the business remains a customer, and for a reasonable period afterwards as needed for support, security, audit, and legal obligations. When a device is unenrolled or an account is closed, associated data is deleted or de-identified in line with the managing business's instructions and our retention practices.

Some features have their own limits. Where a business enables location history, we keep only a limited recent trail per device - the most recent points, up to about 30 days - and older points are automatically removed. Where a business enables geofencing, geofence events (records of a device entering or leaving a defined place) are kept for about 90 days, and older events are automatically removed; the places themselves are kept while the business keeps them. Screenshots a business chooses to keep are retained until deleted; deleting one moves it to an archive from which it is permanently removed after a short period. Turning a feature off stops further collection for that feature.

13. Security

We use reasonable technical and organisational measures to protect information, including encrypted transport (HTTPS) between devices and our servers and access controls on the admin console. No method of transmission or storage is completely secure, but we work to protect information against unauthorised access, loss, or misuse. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth).

14. Your rights and choices

Because your employer controls the data on a managed device, please direct requests to access, correct, or delete your information to your employer. Where we hold information directly (for example, an administrator's account details), you can access and update it in the console, or contact us at matthew@ausmdm.com.au to request access to or deletion of your account information (subject to information we are required or permitted by law to keep). We handle personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles.

15. Complaints

If you have a privacy question or complaint, please contact us at matthew@ausmdm.com.au and we will work with you to resolve it. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.

16. Children

AusMDM is an enterprise product for managing business-owned devices. It is not directed to children and we do not knowingly collect personal information from children.

17. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the "Last updated" date above.

18. Contact

AUSMDM PTY LTD - matthew@ausmdm.com.au - https://ausmdm.com.au