Scope and responsibility
This policy explains how Mozzy, currently operated by William Thomas, handles personal information in connection with its website, accounts, workspaces, bug reports, attachments, and Assistance connections.
Workspace owners and members decide what they submit. An organisation using Mozzy may have its own privacy obligations for content concerning its customers, staff, or users.
Information we collect
- Account information: name, email address, password hash, verification status, sign-in activity, role, and Terms acceptance.
- Workspace information: workspace and project names, membership, invitations, settings, and project URLs.
- Report evidence: issue descriptions, reproduction steps, device and browser details, URLs, screenshots, files, logs, console output, and status history.
- Assistance information: connection configuration, health status, response time, software versions, and technical events submitted by authorised connected systems. WordPress events may include fatal PHP errors, database error messages, email failures, and supported scheduled-task failures.
- Contact information: the name, email address, topic, message, account association, delivery status, and resolution status of enquiries sent through the Contact form.
- Technical and usage information: essential session and security data, page views, successful sign-ins, active time by Mozzy section, recognised automated-agent name and category, and approximate country or Australian state codes.
- Abuse-prevention information: the result and timing of session-based maths challenges, hidden bot fields, and network information temporarily processed to apply submission rate limits.
Some report evidence may incidentally contain personal or sensitive information. Submit only what is reasonably necessary to diagnose the issue.
For Mozzy Work extension usage totals, we record the member account ID, browser type and calendar date of successful authenticated extension requests, including automatic refresh while connected. These daily records are retained for 90 days and shown as aggregate counts to Super Admins. This counter does not collect browsing history, website content, passwords or access tokens.
Why we use information
We use information to create and secure accounts, provide isolated workspaces, store and organise reports, process attachments, deliver transactional email, operate Assistance connections, export selected reports, understand aggregated platform usage, prevent misuse, diagnose faults, and communicate about the service.
Contact and registration submissions are checked automatically for a correct session-based maths answer, an unfilled hidden field, a plausible completion time, and applicable rate limits. A submission that fails these checks is rejected rather than stored. A person can retry with a new challenge or contact support if a legitimate submission continues to fail.
We do not currently sell personal information or use workspace evidence for third-party advertising.
Who can see workspace content
Workspace content is available to authorised members of that workspace. Workspace owners control invitations and membership. Super Admin access is used for platform administration and account management, including protected access to generated maintenance invoices and maintenance logs when billing or support administration requires it.
Contact enquiries are available to authorised Super Admins and may be emailed to active Super Admins so they can respond. Assistance events and the readable reports created from them are available to members of the connected workspace.
Exported files leave Mozzy’s access controls. The person exporting or sharing them is responsible for protecting the resulting copy.
Overseas processing
Some service providers may process or store information outside Australia. The countries involved depend on the providers and regions configured for the deployment. Reasonable steps should be taken to assess provider privacy and security practices before enabling them.
Security and retention
We use access controls, workspace separation, password hashing, verified accounts, and other reasonable technical and organisational safeguards appropriate to the service. No internet-connected system can be guaranteed completely secure.
Assistance access tokens are generated for individual connections. Mozzy stores a one-way hash for authentication and a separately encrypted copy so authorised workspace members can retrieve the token from the connection actions. The shared WordPress plugin stores its token in the connected website’s options after a short-lived, one-time pairing exchange; Mozzy does not place the permanent token in the browser return URL.
The WordPress connector is designed not to send passwords, cookies, form contents, database records, WordPress users, or visitor IP addresses. Error messages, affected URLs, and file paths can still contain incidental personal or confidential information, so connector events should be reviewed and the connected website configured appropriately.
Account and workspace information is generally retained while needed to provide Mozzy, meet legal obligations, resolve disputes, or protect the service. Done-report retention can be configured before reports move to Archive. Deleted information may remain for a limited period in backups before normal rotation removes it.
Contact enquiries and Assistance events are retained while reasonably needed to respond, maintain incident history, protect the service, or meet applicable obligations. They may be removed or de-identified when no longer required.
Closing an account disables access immediately and starts a 14-day recovery period. Signing in during that period restores the account. After the recovery period, the account and any solely owned workspaces scheduled with it are permanently deleted from the active service; limited backup copies may remain until normal rotation.
If you discover a security concern, contact us promptly and do not include secrets in the initial message.
Access, correction, deletion, and exports
You may request access to personal information about you and ask for inaccurate, out-of-date, incomplete, irrelevant, or misleading information to be corrected. You may also ask about deletion or obtain available workspace exports, subject to the rights of other people and applicable legal requirements.
Regular members can close their account from Settings. Shared workspaces must be transferred before closure so another member’s access and content are not unexpectedly removed. Super Admin accounts cannot be closed through Settings and require direct administrative handling so platform administration is not unintentionally disabled.
Use the contact form with enough detail to identify your account and request. We may need to verify your identity before disclosing or changing information.
Privacy questions and complaints
Send privacy questions or complaints through the contact form. We will acknowledge the concern and aim to investigate and respond within a reasonable period.
If Australian privacy law applies and a complaint remains unresolved, you may be able to contact the Office of the Australian Information Commissioner. Visit oaic.gov.au for current guidance.
Material policy changes will be shown through an updated version and effective date.
Mozzy
Back to sign in