Privacy Policy
Effective Date: 15 June 2026
Last updated: 15 June 2026
Table of Contents
- Who We Are
- Personal Information We Collect
- Technical and Usage Data We Collect Automatically
- Cookies and Embedded Content
- How We Use Your Information
- Email and Marketing
- Disclosure to Third Parties and Overseas Recipients
- Data Retention
- Your Rights and Choices
- Children's Privacy
- Data Security
- Data Breaches
- Changes to This Policy
- How to Contact Us
1. Who We Are
MonSec ("we," "our," or "us") is a student cybersecurity society at Monash University and an Australian not-for-profit organisation. This Privacy Policy explains how we collect, use, share, and protect your personal information when you visit our website, create an account, join our community, attend our events, or take part in our Capture the Flag (CTF) competitions.
If you have any questions about this policy or your personal information, you can contact us at team@monsec.io.
2. Personal Information We Collect
The personal information we collect depends on how you interact with us. It may include:
- Account data: your username, email address, optional first and last name, a securely hashed password, and an optional backup email address.
- Profile data: a profile avatar image, if you choose to upload one.
- Contact-form submissions: the name, email address, and message you provide when contacting us.
- Event attendance: registration and check-in details synced from Eventbrite, which may include your name, email address, Monash student ID, and check-in status.
- CTF participation: your team membership, challenge submissions, and hint unlocks.
- Discord identifiers: for first-year representatives, Discord account identifiers obtained via Discord OAuth when you connect your Discord account.
- MSA membership records (where applicable): name, email address, student ID, campus, and membership status.
- Suggestions and feedback that you choose to submit to us.
3. Technical and Usage Data We Collect Automatically
When you use our website, we automatically collect certain technical information to operate and secure the service. This includes your IP address, browser and user-agent details, device fingerprint signals, session identifiers, the pages and requests you make, and records of login and two-factor authentication (2FA) attempts. We collect this data for security, abuse prevention, and to operate and improve the service.
4. Cookies and Embedded Content
We use strictly-necessary cookies only, namely a session cookie and a 2FA trust-device cookie. We do not use advertising or third-party tracking cookies. Some pages may offer optional embedded third-party content, such as YouTube videos and interactive maps, which only loads if you choose to load it or otherwise consent. You can review and manage your choices on our Cookies settings page.
5. How We Use Your Information
We use the information we collect to:
- provide and manage accounts and run our events;
- operate our CTF competitions;
- communicate with you about our activities and your requests;
- maintain the security of the service and prevent fraud and abuse; and
- where you have opted in, send you community updates and newsletter emails.
6. Email and Marketing
We only send bulk or community emails to people who have not opted out. Every bulk email includes an unsubscribe link, and you can opt out at any time using the unsubscribe page or by emailing team@monsec.io. Transactional emails (such as password resets and security notices) are not marketing and may still be sent to you while you have an account.
7. Disclosure to Third Parties and Overseas Recipients
We do not sell your personal information. We share limited personal information with service providers who help us operate the service, and some of these providers may store or process your information overseas:
- Eventbrite — event registration and ticketing (United States).
- Discord — first-year-representative OAuth sign-in (United States).
- Google / Gmail API — transactional email delivery (United States).
- YouTube — optional embedded videos (United States).
- OpenStreetMap / Leaflet — optional interactive maps.
By using these features, your information may be disclosed to recipients located outside Australia. We may also disclose information where required or authorised by law.
8. Data Retention
We keep application request logs for approximately 30 days. We retain security and audit records, and your account records, for as long as your account is active and as required for our legitimate interests or to meet our legal obligations. You can request deletion of your data at any time.
9. Your Rights and Choices
You can access and update much of your information from your profile, or you can contact us at team@monsec.io. Depending on where you live, you may have the right to access, correct, delete (erase), and obtain a machine-readable export of your personal information. Please note that deleting your account anonymises your personal information.
- EU / EEA / UK users: under the GDPR you have rights to access, rectification, erasure, data portability, and to object to certain processing, as well as the right to lodge a complaint with your local supervisory authority.
- Australian users: you may complain to us first, and you also have the right to complain to the Office of the Australian Information Commissioner (OAIC).
- California and other US users: we do not sell your personal information.
10. Children's Privacy
Our service is not directed to children under 13, and we do not knowingly collect personal information from them. You must be at least 13 years old to use the service or create an account. If you believe a child under 13 has provided us with personal information, please contact us so we can remove it.
11. Data Security
We take reasonable steps to protect your personal information. These include encrypting data in transit, storing passwords only as salted hashes, applying access controls, and supporting two-factor authentication (2FA). No method of transmission or storage is completely secure, so we cannot guarantee absolute security.
12. Data Breaches
If a data breach occurs, we will assess it and, where required by law, notify affected individuals and the relevant regulator — for example, the OAIC under Australia's Notifiable Data Breaches scheme.
13. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the "Last updated" date above. We encourage you to review this page periodically for the latest information.
14. How to Contact Us
If you have any questions about this Privacy Policy or wish to exercise your rights, please email us at team@monsec.io.