Brolly Privacy Policy — Australia and New Zealand
Published: 27 August 2026
Effective date: 1 September 2026
Brolly Australasia Pty Ltd (ABN 66 633 439 577) (“Brolly”, “we”, “us” or “our”) respects the privacy of the people whose personal information we handle.
This policy explains how we collect, hold, use and disclose personal information in connection with our websites, sales and marketing activities, support services and the Brolly platform. It also explains how to access or correct information, make a privacy request, or raise a complaint.
The short version
- We collect the information needed to provide, secure, support and improve Brolly and to operate our business.
- Customer-controlled social media records are processed on the customer’s behalf. We do not use Customer Data for third-party advertising.
- We use cookies and similar technologies for necessary functions and, subject to applicable choices, analytics and attribution.
- We use reasonable safeguards to protect personal information and retain it only for documented business, contractual and legal purposes.
- You may contact us to access or correct personal information or to make a privacy complaint.
1. Scope and our role
This policy applies to personal information handled through:
brolly.ioand Brolly’s regional websites;- the Brolly applications and services, including Archive, Monitoring, Insights, Protect and supported integrations;
- Brolly’s knowledge base, support and customer-success channels;
- trials, demonstrations, orders, billing and account administration;
- events, downloads, newsletters, surveys and other sales or marketing activities; and
- dealings with suppliers, partners, advisers, job applicants and contractors.
Brolly handles information in two different capacities:
- For Brolly’s own business activities, such as website analytics, sales, user accounts, security, support and billing, Brolly determines why and how personal information is handled.
- For Customer Data, Brolly generally processes information on the customer’s instructions to provide the service. The customer decides which accounts to connect, who may access the archive, how long records are kept and how records are used or disclosed. The customer’s privacy notices and legal obligations also apply.
Customer Data is controlled by the customer and processed by Brolly on the customer’s behalf. This does not change any rights held by social media users, content creators or other third parties.
This policy does not govern a customer’s independent handling of information, third-party social media platforms, or websites and services that Brolly does not control.
2. Personal information we collect and hold
The information we handle depends on how a person interacts with Brolly.
2.1 Website visitors, prospects and business contacts
We may collect:
- name, work email address, telephone number, organisation, role and location;
- information submitted through forms, correspondence, calls, demonstrations, events, surveys or resource downloads;
- marketing preferences and records of communications;
- referral source, campaign and interaction information; and
- professional information available from a person’s organisation, authorised representative, business partner or a public source.
2.2 Account users
We may collect:
- name, work email address, organisation, role and account permissions;
- account, authentication and security information;
- connected-service authorisations and configuration choices;
- support requests, product feedback and communications;
- service activity, audit and diagnostic logs; and
- information required to administer a trial, subscription or Order.
2.3 Billing and commercial information
We may collect contact, invoicing, transaction, tax and subscription information. Payment-card details are handled by Brolly’s payment providers; Brolly does not need to retain a complete payment-card number to administer an account.
2.4 Customer Data from connected services
When an authorised customer connects a supported social media account or other service, Brolly may retrieve and preserve information made available through the relevant official API or integration. Depending on the service, authorisation and product configuration, this may include:
- account and profile information;
- posts, comments, replies, reactions and conversation context;
- edits, deletions and version history;
- images, video, audio, attachments and linked content;
- usernames, display names and other public or authorised identifiers;
- timestamps, post and account IDs, URLs, visibility status and other metadata; and
- private or direct messages where the connected service and customer’s authorisation permit capture.
Customer Data may contain personal information about people who do not have a Brolly account. It may also contain sensitive information if a social media user or customer includes that information in content. Brolly does not require customers to provide sensitive information unless it is necessary for their authorised use of the service and lawful for them to process.
2.5 Usage, device and analytics information
We may collect:
- IP address, browser, device, operating system and approximate location derived from IP;
- pages and features viewed, website and knowledge-base searches, clicks, navigation paths, referrer and campaign information;
- login, authentication, performance, error, security and audit events;
- cookie and similar-technology identifiers; and
- interaction information such as scrolling, clicks and session-replay data where that technology is enabled and permitted.
Searches made inside the Brolly platform are not logged; export actions are.
2.6 Other business relationships
For suppliers, partners, advisers, contractors and job applicants, we may collect business contact details, qualifications, correspondence, payment information, checks and other information reasonably required for the relationship.
3. How we collect personal information
We collect personal information:
- directly from you when you contact us, complete a form, create an account, start a trial, enter an Order, request support or otherwise interact with Brolly;
- from your organisation, account administrator or authorised representative;
- through your use of Brolly websites, applications and support properties;
- from connected services that a customer has authorised Brolly to access;
- from service providers, resellers, partners and referral sources;
- from public professional and organisational sources; and
- where authorised or required by law.
Where practicable, you may contact Brolly without identifying yourself or by using a pseudonym. We will need sufficient accurate information where identity is necessary to provide an account, secure the service, verify authority, process a payment or respond to a privacy request.
If you provide personal information about another person, you must be authorised to do so and, where required, make them aware of this policy.
4. Why we use personal information
We may use personal information to:
- provide, configure, operate and maintain the websites and services;
- create and administer accounts, trials, subscriptions and Orders;
- capture, preserve, index, search, analyse and export Customer Data on a customer’s instructions;
- authenticate users and manage permissions;
- provide support, training and customer-success services;
- communicate about services, incidents, changes, renewals and billing;
- process payments, invoices and taxation records;
- monitor performance, diagnose faults and improve usability and functionality;
- maintain security, prevent misuse, investigate suspected fraud and enforce agreements;
- conduct analytics, attribution, research and business planning;
- provide requested resources and, where permitted, relevant marketing communications;
- manage suppliers, partners, advisers, contractors and recruitment;
- establish, exercise or defend legal claims;
- comply with legal, regulatory, records-management and law-enforcement obligations; and
- support a merger, financing, reorganisation or sale of all or part of the business, subject to appropriate protections.
We may use information for another purpose where you have consented or where the use is authorised or required by law.
5. Cookies, analytics and cross-property identifiers
Brolly uses cookies and similar technologies for:
- necessary functions, such as authentication, security, load balancing and remembering privacy choices;
- preferences, such as language, region and display settings;
- analytics, such as understanding visits, feature use, errors and journeys; and
- attribution and marketing, such as measuring campaigns and, where enabled, limiting or assessing advertising.
Depending on the Brolly property and a person’s choices, providers may include Google Tag Manager/Analytics, Google Ads conversion linking, Clicky, HubSpot, Microsoft Clarity, Meta, LinkedIn and Brolly’s self-hosted Umami analytics.
Non-essential technologies are controlled through Brolly’s Cookie Preferences tool where consent or a choice is required. Browser controls may also block or delete cookies, although doing so can affect some functions.
Brolly also uses Umami, a self-hosted, first-party analytics tool operated on Brolly’s own infrastructure, to measure visits and journeys across Brolly-controlled properties. Umami does not use cookies or similar identifiers stored on a device and is not used for advertising; it receives technical information such as IP address, pages viewed and referrers. Because it stores nothing on a device, it operates independently of the Cookie Preferences tool.
Brolly also stores first-party campaign-attribution information (such as referral source, campaign identifiers and the landing page) in the browser when a person arrives from a link carrying that information. It stays in the browser and is used by Brolly only if the person later submits a form.
Where a signed-in user interacts with more than one Brolly-controlled website, support property or service, Brolly may use an account-level identifier, such as a user_id, to associate usage information across those properties. This helps us understand a journey across the website, knowledge base and application and to operate, secure, support, analyse and improve Brolly.
Brolly does not use an email address as the analytics user_id. The identifier is pseudonymous to the analytics provider, but it remains personal information in Brolly’s hands because Brolly can associate it with an account. We do not use that identifier to sell personal information or enable third parties to market their own products to an individual.
The Cookie Preferences tool should be consulted for the current categories and providers used on the relevant Brolly property.
6. Connected platforms and API data
Brolly accesses a connected service only after an authorised customer completes the service’s authentication and permission process. Brolly uses the resulting access to retrieve supported content and metadata for the services selected by the customer.
This may include content made available by Meta services, Google/YouTube, X, LinkedIn and other supported providers. Each provider operates under its own terms and privacy policy.
Meta Platform Data
Brolly may use Meta APIs to retrieve supported content and metadata from an authorised Facebook Page, Instagram business account or other connected Meta property. Where authorised and supported, this may include Page content, comments, replies, reactions, media, metadata and Page inbox messages.
To authenticate and operate the integration, Brolly may also process Meta app-scoped user or account identifiers, access tokens, granted permissions, connection metadata and authorisation records. Brolly uses this information only to provide, secure and support the customer-authorised connection. Stored credentials are protected, access is restricted, and Brolly ceases using and deletes them when they are no longer required, subject to documented security and legal-retention requirements.
Meta Platform Data is used to provide the customer’s selected Brolly services. Brolly does not sell, license or transfer Meta Platform Data to data brokers, advertising networks, advertising exchanges or other advertising or monetisation services. It is not used for third-party advertising or advertising-profile creation.
Brolly does not use Meta Platform Data to track or profile individuals across customers, unrelated accounts, services or locations, or to provide individual-surveillance capabilities. Any organisation, classification, sentiment analysis or customer-configured alerting is limited to authorised customer content and is provided for organisational recordkeeping, community governance and service administration.
7. Customer Data and individual requests
Where Brolly processes Customer Data for a customer, the customer is normally responsible for responding to people whose information appears in that archive. If you are seeking access, correction or deletion of a social media record held for a Brolly customer, contact that customer first.
If Brolly receives such a request directly, we may refer it to the relevant customer and assist that customer as required by the applicable agreement and law. We will not delete or alter an official record contrary to the customer’s lawful instructions, a records-retention requirement, legal hold or other binding obligation.
Requests concerning your own Brolly account, website interactions or direct dealings with Brolly can be sent to Brolly under clause 14.
8. Automated analysis
Depending on the products and configuration selected by a customer, Brolly may use automated tools to organise Customer Data, support search, identify versions, classify content, generate themes or sentiment, and surface customer-configured signals or alerts.
These outputs assist authorised customer users. They may be incomplete or incorrect and should be reviewed in context. Brolly does not use these features by themselves to make decisions that produce legal or similarly significant effects for an individual. Customers remain responsible for decisions they make using the outputs.
9. When we disclose personal information
We may disclose personal information to:
- the customer and its authorised users where information relates to that customer’s service;
- hosting, infrastructure, security, support and software providers;
- payment, invoicing and financial-service providers;
- customer relationship, communications, analytics and marketing-service providers;
- connected platforms where transmission is necessary to operate an authorised integration;
- resellers, implementation partners and professional advisers subject to appropriate obligations;
- regulators, courts, law-enforcement bodies and other authorities where disclosure is authorised or required; and
- a prospective or completed purchaser, investor or successor involved in a corporate transaction, subject to confidentiality and appropriate safeguards.
Providers may access personal information only for the services they perform for Brolly or as otherwise permitted by law. Brolly does not sell Customer Data or allow third parties to use Customer Data for their own advertising.
We may disclose aggregated or de-identified information that does not reasonably identify an individual.
10. Overseas processing and disclosure
Brolly is based in Australia and provides services across multiple countries. Personal information may be stored, accessed or processed in Australia, New Zealand and countries in which Brolly’s service providers operate.
Customer Data for Australian and New Zealand customers is hosted on AWS cloud infrastructure located in Australia unless an Order states otherwise. Other Customer Data hosting and residency commitments may be stated in an Order or DPA. Business systems used for customer relationship management, communications, analytics, support, security and billing may operate from other countries.
Brolly takes reasonable steps required by applicable law before disclosing personal information to an overseas recipient. For New Zealand information, Brolly will use a permitted basis for overseas disclosure, such as comparable safeguards or an appropriate contractual arrangement.
Brolly maintains a current list of its service providers and the countries of likely overseas recipients, prepared through its production service-provider review. The list is available on request — email privacy@brolly.com.au — and through Brolly’s DPA process.
11. Retention and deletion
Brolly retains information only for as long as reasonably required for the purposes described in this policy, an applicable agreement or law.
- Customer Data: retained according to the customer’s subscription, applicable records schedules, legal holds and documented instructions.
- After paid-service termination: unless an Order or DPA states otherwise, standard export functions remain available for 90 days. After that period, Brolly may delete Customer Data from active systems through its documented deletion cycle.
- Trial data: may be deleted after a trial ends in accordance with Brolly’s documented retention practices (see the Terms of Service).
- Account and support information: retained while the account is active and afterwards where needed for support history, security, disputes or legal compliance.
- Billing, taxation and contract records: retained for applicable statutory and business-record periods.
- Analytics and marketing information: retained according to Brolly’s documented settings and the relevant consent or preference.
- Backups: residual copies may remain until overwritten through the ordinary backup cycle and remain protected while retained.
Brolly may retain information where required by law, a legal hold, a customer’s lawful records obligation, fraud prevention, security or the establishment, exercise or defence of legal claims.
See How to request data deletion for request instructions.
12. Security and privacy incidents
Brolly uses reasonable administrative, physical and technical safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include access controls, encryption, authentication, monitoring, audit logging, supplier controls and incident-response processes appropriate to the information and service.
No internet-connected service is completely secure. Customers and users must protect their credentials, use available security controls and notify Brolly promptly of suspected unauthorised access.
Brolly will assess and notify eligible data breaches as required by the Australian Privacy Act 1988 and notify privacy breaches that have caused or are likely to cause serious harm as required by the New Zealand Privacy Act 2020. Contractual notifications concerning Customer Data are addressed in the applicable agreement or DPA.
More information is available in Brolly’s Security and Compliance information.
13. Direct marketing
Brolly may send marketing communications where permitted by law. You can opt out using the unsubscribe facility in the message or by contacting us. Opting out of marketing does not prevent service, security, billing or legal communications required for an account or existing relationship.
Brolly does not use Customer Data to market to the people whose content appears in a customer archive.
14. Access, correction and other privacy requests
Subject to applicable law, you may ask Brolly to:
- confirm whether we hold personal information about you;
- provide access to that information;
- correct information that is inaccurate, incomplete or out of date; or
- delete information where Brolly is permitted and required to do so.
Send a request to privacy@brolly.com.au or use the Brolly contact page. Include enough information for us to identify the relevant records and understand the request. We may take reasonable steps to verify identity or authority before acting.
We will respond within the period required by applicable law. New Zealand access and correction requests ordinarily require a decision within 20 working days. We will generally not charge for a request, but a lawful charge may apply in limited circumstances and will be explained before it is incurred.
Access, correction or deletion may be limited where permitted or required by law, including where disclosure would affect another person, reveal protected information, prejudice security, conflict with a legal retention requirement or where Brolly cannot verify the request.
15. Privacy complaints
If you believe Brolly has mishandled personal information, contact our Privacy Officer using the details below and describe:
- what happened;
- the information or interaction concerned;
- the outcome you are seeking; and
- how we can contact you.
We will acknowledge the complaint, investigate it and respond within a reasonable period. We aim to provide a substantive response within 30 days, although a complex matter may require longer. If more time is needed, we will explain why and provide an update.
If an Australian complaint is not resolved, you may contact the Office of the Australian Information Commissioner. If a New Zealand complaint is not resolved, you may contact the Office of the Privacy Commissioner.
16. Children
Brolly’s websites and services are designed for organisations and their personnel, not for children acting in their personal capacity. We do not knowingly create platform accounts for children. Customer Data may contain social media content relating to children where a customer lawfully captures that content for its organisational purposes; in that situation Brolly processes the information on the customer’s behalf and applies the contractual safeguards for Customer Data.
17. Changes to this policy
We may update this policy to reflect changes in law, technology or Brolly’s practices. We will publish the updated policy with a revised date. Where a change is material, we will provide additional notice where required or reasonably appropriate.
18. Contact Brolly
Privacy Officer
Brolly Australasia Pty Ltd
PO Box 356, Caloundra QLD 4551, Australia
- Email: privacy@brolly.com.au
- Phone: 1300 011 589
- Support: support@brolly.com.au
- Contact page: brolly.io/au/contact/