Privacy policy
How we collect, use and protect personal information, in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Last updated 6 October 2026.
BlueArc Technologies Pty Ltd, ABN 61 690 034 121, makes BlueArc MMS. This policy covers this website, bluearcmms.com.au, and the accounts people use to sign in to BlueArc MMS. Where a client uses BlueArc MMS to hold information about its own customers, workers or assets, that client decides how the information is handled and we handle it on the client's behalf under our Terms of Business. We handle personal information in line with the Australian Privacy Principles in everything we do, whether or not a particular obligation is compulsory for a business of our size.
1. What we collect
When you book a demo or contact us. Your name, business name and work email, and optionally your phone number, the equipment you look after and your message. We also record the IP address the request came from, to help us block automated abuse.
When you become a client. Your business name, ABN, address and industry, and for each person we deal with, their name, role, email address and phone number. When you accept a proposal we record the name typed in, the date and time, the IP address and the version of our terms that applied. When we invoice you we keep a copy of the billing details used.
When you use BlueArc MMS. Your name, email address, organisation and role, and when you last signed in. Passwords are stored only as one way hashes, never in a form that can be read back. Administrators use two factor sign in with recovery codes.
How we collect and hold it. We collect information directly from you, through our website form, email and phone calls, and from your organisation when it creates your BlueArc MMS account. Clients enter information about their own customers, workers and contacts into BlueArc MMS. We hold information electronically with the providers listed in section 6.
What we do not collect. We do not collect card or bank account details. We do not run a mailing list or newsletter, and every email we send responds to something you did.
2. Why we collect it
To answer enquiries and arrange demos, to prepare proposals, to deliver and support BlueArc MMS, to invoice and be paid, to keep an accurate record of what was agreed, and to meet our record keeping obligations under Australian law. We do not sell personal information or disclose it for anyone else's marketing.
3. No training of AI models
Information held in our systems, including client data in BlueArc MMS and anyone's contact details, is not used to train any artificial intelligence model, whether ours or a third party's.
4. AI features in BlueArc MMS
BlueArc MMS uses AI in three places, always as a draft for a person to check: drafting a form template from an existing document, suggesting estimate line items, and summarising reports. These requests are processed by Anthropic's Claude API, outside Australia. Anthropic's commercial terms prohibit training on this data.
5. Automated decisions
BlueArc MMS checks readings about equipment against the limits configured for it, and flags a reading that fails. Those checks are about equipment, not people, and a competent person makes every inspection and certification decision. We do not use computer programs to make decisions that could reasonably be expected to significantly affect the rights or interests of an individual. If that changes, we will update this policy first.
6. Who else receives information
| Provider | What they handle | Where |
|---|---|---|
| Supabase | The BlueArc MMS database, files and sign in | Sydney |
| Our application hosting | The BlueArc MMS application programming interface, run with the Sydney region set | Sydney |
| Anthropic | Text sent to the optional AI features | Outside Australia |
| SendGrid | Delivery of email sent by BlueArc MMS | United States |
| Expo | Delivery of push notifications to the field app | United States |
| Cloudflare | Security and delivery for this website, including your IP address | Global network |
| Microsoft 365 | Our email, including messages to support@bluearcmms.com | May be outside Australia |
| Xero | Invoice data, only if a client connects its Xero account | Under Xero's terms |
We may also disclose personal information where the law requires it, or to professional advisers bound to keep it confidential.
7. Where information is held
BlueArc MMS data at rest, including the database, files and sign in, is held in the Sydney region. We are likely to disclose some personal information to overseas recipients: to the United States, where email and push notifications are delivered, to Anthropic outside Australia for the AI features, and to Microsoft, which may store our email outside Australia. Where personal information is handled outside Australia we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.
8. Cookies
This website uses no advertising or tracking cookies. Our Cookie Policy lists what is used and why.
9. How long we keep things
Demo requests and enquiries: up to 2 years after our last contact with you, then deleted, unless you become a client.
Signed proposals and invoices: 7 years.
Client data in BlueArc MMS: for as long as the client subscribes, then 90 days after termination so a late export can be met, then deleted, other than records we must keep by law.
Backups: each organisation is backed up nightly and backups are kept on a set schedule.
Audit log: regulated changes in BlueArc MMS are written to an append only audit log that cannot be altered afterwards.
10. Security
Every record in BlueArc MMS belongs to one organisation, and customers in the portal reach only their own account. Roles are held per organisation. Documents and photos are private, not public links. Administrators use two factor sign in. Nothing reaches a customer or supplier by email, SMS or push without a human release, and a blocked send is audited.
11. If something goes wrong
If we become aware of unauthorised access to, or disclosure or loss of, personal information we hold, we will assess it promptly and take steps to contain it. Where it is likely to result in serious harm, we will notify the individuals concerned and the Office of the Australian Information Commissioner as soon as practicable under the Notifiable Data Breaches scheme. Where we hold information on behalf of a client, we will also notify that client.
12. Access, correction and complaints
You can ask what personal information we hold about you, ask us to correct it, or ask us to delete it unless we are required to keep it. We respond within 30 days and do not charge. If you think we have mishandled your information, email support@bluearcmms.com, marked for the attention of our Privacy Officer, and we will respond within 30 days. If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
13. Changes to this policy
We will update this policy when what we do changes. Where a change materially affects information we already hold about you, we will take reasonable steps to tell you.
BlueArc Technologies Pty Ltd, ABN 61 690 034 121
Level 35, 100 Barangaroo Avenue, Sydney NSW 2000
1300 171 099 · support@bluearcmms.com