Pinga · 2M Systems Pty Ltd

Privacy Policy

1. Who we are and how to contact us

Pinga is operated by 2M Systems Pty Ltd, ABN 20 613 465 900. This policy covers our handling of personal information through Pinga, including information about website visitors, account holders and alert contacts who may not have a Pinga account.

For privacy enquiries, access or correction requests, account closure or complaints, email [email protected].

2. Information we collect

3. Where it comes from

We collect information from you, your identity provider, your organisation’s administrators, connected equipment and systems, and notification providers. An organisation can add you as an alert contact without creating an account for you. Contact that organisation or us if you believe your details have been added incorrectly.

If required contact or authentication details are not supplied, we may be unable to provide account access or deliver the relevant notifications. Do not send unnecessary sensitive information, credentials or secrets in alarm messages.

4. How we use information

We use information to authenticate users, administer organisations, match and interpret alarms, run escalation steps, deliver alerts and recovery messages, record responses, troubleshoot issues, protect the service, respond to requests and meet applicable legal obligations. Information is not collected by Pinga for advertising profiles.

Organisation administrators and authorised users can see the records available to their organisation. Alert recipients receive the information included in their notification and the associated response page. Only share alarm information with contacts authorised to receive it.

5. Service providers and AI

We disclose information as needed to providers supporting the service:

We may also disclose information to professional advisers or authorities where reasonably necessary for legal obligations, dispute handling or protection against misuse. Providers may maintain their own operational, security and account records under their terms and privacy notices.

6. Storage and overseas processing

Pinga’s application and database are hosted on our own servers in Australia, reached through Cloudflare. The inbound email storage and Lambda forwarding setup uses AWS’s Sydney region. Some processing occurs overseas: the Twilio SMS integration uses its US1 region, and other providers operate international infrastructure. Australia and the United States are relevant processing locations; other locations depend on the provider, network routing and account configuration.

Using an Australian domain or Australian phone number does not mean all information stays in Australia. Contact us for current information about provider locations if your organisation has data residency requirements.

7. Security and cookies

Pinga uses HTTPS, access controls, organisation-scoped data access, expiring response links and authenticated provider endpoints to protect information. No service can guarantee absolute security. Protect your account and notification links, and report suspected unauthorised access to us.

Pinga uses essential session and sign-in cookies to maintain login and protect authentication. Infrastructure and identity providers may use cookies for their own security or sign-in functions. The Pinga interface does not currently include advertising trackers or optional marketing analytics. Blocking essential cookies can prevent sign-in.

8. Retention and deletion

We keep information for operating the service, maintaining alarm history, handling support and disputes, and meeting applicable legal requirements. Alarm history and original inbound email archives do not currently have a universal automatic deletion period. Retention depends on the record, your organisation’s needs, configured storage policies and applicable obligations.

Authorised administrators can request closure or deletion by contacting us. We will confirm the scope, verify authority and explain any information that must be retained and the expected handling timeframe. Removing a contact or monitor does not necessarily erase historical alarm records. Copies may remain in backups until they are replaced or expire, and notifications already delivered may remain with recipients or providers.

9. Access and correction

You can ask what personal information we hold about you and request access or correction using the email above. Provide enough information to identify the relevant account, organisation or alert. We may verify identity and authority before responding and will explain any lawful reason for refusing a request. Where information was supplied by an organisation, we may need to work with its authorised administrator while respecting your rights.

10. Complaints and changes

For a privacy complaint, email us with the issue and your preferred outcome. We aim to respond within 30 days; if more time is needed, we will explain why. If you are not satisfied, you can contact the Office of the Australian Information Commissioner for information about available complaint pathways and whether it can consider your complaint.

We may update this policy as the service or our practices change. The date above identifies this version. We will provide notice of material changes where appropriate.