Privacy Policy

Direct answer

We do not use Customer Data to train public or foundation AI models unless you expressly agree in writing. Customer instances are provisioned in supported regions, and Australia and the United States are currently available.

About this policy

This Privacy Policy explains how Morpheus OS Pty Ltd collects, uses, discloses, stores and protects personal information in connection with MorpheusOS, our website, applications, workflows, support and related services.

What we collect

We may collect:

  • account and contact information, such as name, email address, role, organisation and billing details;
  • workspace and workflow content that may include personal information;
  • prompts, instructions, files, messages, documents and outputs;
  • connected-application data you authorise MorpheusOS to access;
  • authentication, access, audit and security logs;
  • support, sales and communications records;
  • website, analytics, cookie and device information; and
  • information from public, licensed or customer-provided sources where used in configured workflows.

How we use it

We use personal information to:

  • provide, configure, secure and support MorpheusOS;
  • operate workflows and connected applications requested by customers;
  • authenticate users and manage permissions;
  • maintain audit trails and security controls;
  • monitor service reliability and prevent misuse;
  • respond to support, legal and compliance requests;
  • improve product performance and user experience;
  • process billing and account administration; and
  • comply with legal obligations.

AI processing

MorpheusOS may process personal information through AI-assisted workflows to prepare drafts, summaries, research, recommendations, data enrichments, actions or other outputs.

AI outputs should be reviewed by an authorised human before they are used externally or for any decision that materially affects a person.

We do not use Customer Data to train public or foundation AI models unless expressly agreed in writing.

Privacy controls in the product

MorpheusOS includes configurable privacy controls designed to help customers identify, redact, audit and manage personal information. Depending on the customer instance and policy settings, these controls may include jurisdiction-specific PII detection, sensitive-data redaction, PII audit events, subject request workflows, legal hold controls, provider posture checks and human approval requirements for sensitive disclosure.

These controls are configured per customer instance. Their availability and enforcement depend on the customer’s policy settings, and they are not represented as being enabled by default on every instance.

Operational logging is designed to strip credentials and sensitive-tier personal information before log records reach logging sinks. Contact details may still appear in operational logs where there is a legitimate operational reason.

Sensitive information

You must not submit sensitive information to MorpheusOS unless it is necessary for the agreed workflow, you have a lawful basis to do so, and appropriate safeguards are in place.

Sensitive information may include health information, biometric information, government identifiers, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, union membership, criminal record information or similar protected information.

Disclosure

We may disclose personal information to:

  • authorised users within your organisation;
  • service providers and subprocessors that help us operate MorpheusOS;
  • connected applications you authorise;
  • professional advisers;
  • regulators, courts, law enforcement or government agencies where required by law; and
  • parties involved in a business sale, merger, financing or restructuring, subject to confidentiality and legal requirements.

Data regions and cross-border processing

MorpheusOS is designed around regional deployment cells. Customer instances are provisioned in supported regions. Australia and the United States are currently available. Additional regions may be available by agreement or as MorpheusOS provisions further regional cells.

Some subprocessors, support operations or model providers may process data outside your region. Region availability, subprocessors and cross-border processing details should be confirmed in the applicable order form, security documentation or data processing terms.

Retention

We retain personal information for as long as needed to provide MorpheusOS, comply with legal obligations, resolve disputes, enforce agreements, maintain security and support offboarding.

Customer Data retention and deletion may be controlled by your plan, settings or signed agreement. See Regions, retention and offboarding.

Security

We use safeguards designed to protect personal information, including encryption, access controls, audit trails, credential protection, secure development practices and monitoring.

If we become aware of a data breach that is likely to result in serious harm or otherwise requires notification, we will assess and notify affected parties and regulators as required by applicable law.

Your rights

Depending on where you are located, you may have rights to access, correct, delete, object to, restrict or receive a copy of personal information, and to complain to a privacy regulator.

Australian users may contact us about access and correction under the Australian Privacy Principles.

California and other US state residents may have additional rights, including rights to know, access, correct, delete, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against for exercising privacy rights.

MorpheusOS provides tools to help administrators search, export and erase personal information across supported stores, subject to legal holds, technical feasibility and records we are required to retain for security, audit, backup and legal obligations.

To make a privacy request, contact contact@morpheusos.ai.

Cookies

Our website sets no cookies and loads no analytics, advertising or third-party scripts. See our Cookie Notice for what it does store on your device, and what will change if that ever does.

Complaints

If you have a privacy concern, contact contact@morpheusos.ai. We will review and respond within a reasonable period.

If you are in Australia and are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.