Legal

Privacy Policy

  • Version 1.0
  • Effective 3 August 2026
  • Finetica Pty Ltd · ABN 58 689 613 447

Finetica Pty Ltd (ABN 58 689 613 447) respects your privacy. This policy explains how we collect, hold, use and disclose personal information, and how you can access it, correct it or complain about how we have handled it.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy applies to the Finetica platform, our website at finetica.com.au, and our dealings with customers, prospects, suppliers and job applicants.

1. The two ways we handle information

Finetica handles personal information in two distinct roles, and different parts of this policy apply to each.

Information we handle for our own purposes

This is information about the people we deal with directly — the staff of the accounting practices that subscribe to Finetica, people who contact us through our website, suppliers and job applicants. We decide how this information is handled, and this policy governs it in full.

Information we handle on behalf of our customers

Finetica is used by accounting and advisory practices to prepare compliance workpapers for their own clients. In doing that, practices put client information into the platform — financial records, ledgers, statements and documents that can contain personal information about their clients, and about those clients' employees, directors, beneficiaries and counterparties.

We hold and process that information on the practice's instructions and for the purpose of providing the platform to them. The practice, not Finetica, has the relationship with those individuals and is responsible for telling them how their information is handled, for obtaining any necessary consents, and for responding to their access, correction and complaint requests.

If you are the client of an accounting practice that uses Finetica and you want to know how your information is handled, please contact that practice in the first instance. We will refer any request we receive directly to the relevant practice.

2. What personal information we collect

Account and user information

  • Name, work email address and phone number.
  • The practice you work for, your role and the level of access assigned to you.
  • Authentication data — a securely hashed password, multi-factor authentication settings and secrets, and device tokens where you enable push notifications.
  • Your platform preferences and settings.

Customer and billing information

  • Business name, ABN, contact details and the individuals who administer the account.
  • Subscription, invoicing and payment records. We do not store full card numbers; card payments, where offered, are processed by a payment provider.

Client and financial information within workpapers

Entered by our customers or drawn from the systems they authorise, this can include entity names and ABNs, chart of accounts and ledger transactions, bank and loan statements, invoices and bills, payroll and superannuation records, fixed asset registers, ATO account transactions and lodgement information, and uploaded supporting documents. Section 6 covers this category in more detail.

Technical and usage information

  • IP address, device identifier, browser and operating system.
  • Sign-in history, including the date, time and outcome of sign-in attempts.
  • Activity logs recording actions taken in the platform and the user who took them.
  • Error and diagnostic logs, and records of calls made to connected services.

Communications

  • Enquiries you send through our website contact form or by email, and our replies.
  • Support requests, and notes of meetings, demonstrations and calls.

Job applicants

If you apply for a role with us we collect your application, résumé, work history, qualifications, referee details and any information you give us during the recruitment process.

We do not seek sensitive information (as defined in the Privacy Act) about our users, and ask that you do not provide it unless it is genuinely necessary.

3. How we collect it

Wherever it is reasonable and practicable, we collect personal information directly from the individual concerned. We collect it:

  • Directly from you — when you create an account, accept an invitation, contact us, request a demonstration, subscribe, or use the platform.
  • From your practice — when a practice administrator invites you as a user or sets up your access.
  • From connected services you authorise — Xero and the Australian Taxation Office, where a customer has connected an entity and holds the necessary authority.
  • From documents uploaded to the platform — statements, invoices and other records our customers attach to a workpaper.
  • Automatically — technical and usage information generated when you use the platform or visit our website.
  • From third parties — publicly available business registers, referrals, and recruitment channels where you have applied for a role.

Where we collect information about you from someone other than you — for example from your practice — we take reasonable steps to ensure you are made aware of the matters in this policy.

4. Why we collect, hold, use and disclose it

We use personal information for the purposes it was collected for, for related purposes you would reasonably expect, and where the law otherwise permits or requires. Specifically:

  • to create and administer accounts, authenticate users and control access;
  • to provide, operate, maintain and support the platform, including building, populating and testing workpapers;
  • to exchange data with connected services on our customers' instructions;
  • to send service communications — verification codes, security alerts, invitations, reminders, notifications, and notices about changes to the platform or to our terms;
  • to secure the platform, detect and investigate misuse, unauthorised access and fraud, and maintain audit trails;
  • to troubleshoot faults and improve reliability, accuracy and performance;
  • to bill and collect payment, and to manage our customer relationships;
  • to respond to enquiries, complaints and requests;
  • to send you information about Finetica where you have consented or would reasonably expect it, subject to Section 15;
  • to assess job applications; and
  • to comply with our legal obligations and to establish, exercise or defend legal claims.

We do not sell personal information, and we do not disclose it for another organisation's direct marketing.

5. Our website contact form

When you submit our contact form, the details you enter — your name, email address, and optionally your practice name and phone number — together with your message are emailed to our team. Nothing you enter is stored on the website itself or in a database.

We use those details to respond to your enquiry and to keep a record of our correspondence. If your enquiry does not lead to a business relationship, we delete the correspondence when we no longer need it.

The form sets a short-lived session cookie so we can protect it against automated abuse and cross-site request forgery. It is essential to the form working and is not used for tracking.

6. Client and financial information in workpapers

Compliance workpapers necessarily contain detailed financial information, and that information can include personal information about individuals who have no direct relationship with Finetica.

We handle this information only:

  • on the instructions of the customer whose workspace it sits in;
  • for the purpose of providing, securing and supporting the platform for that customer; and
  • as required or permitted by law.

We do not use it for our own purposes, we do not use it to market to the individuals it concerns, and we do not use it to train third-party generative artificial intelligence models.

Access within Finetica is restricted. A customer's data is segregated from every other customer's. Within a customer's workspace, access is controlled by the role the practice assigns to each of its users. Our own staff may access customer data only where it is necessary to provide support, investigate a fault or maintain security, and that access is logged.

Our customers are responsible for ensuring they hold the client authority and engagement required to put this information into the platform, and for meeting their own privacy obligations to their clients.

7. Tax file numbers

Tax file numbers are protected information under the Privacy (Tax File Number) Rule 2015 and Part IIIA of the Privacy Act 1988 (Cth).

Finetica does not require tax file numbers, and we ask that customers do not enter them into the platform or include them in uploaded documents unless it is genuinely necessary for the workpaper concerned.

Where a tax file number is nonetheless held in the platform, we will use and disclose it only as permitted by taxation law, and only for the purpose for which the customer provided it. We will not use it to establish or confirm an individual's identity for any other purpose, and we take reasonable steps to protect it and to securely destroy it when it is no longer required by law to be retained.

8. Who we disclose personal information to

We disclose personal information only where it is necessary for the purposes described in this policy. The categories of recipient are:

RecipientPurposeLocation
Amazon Web ServicesHosting of the platform and its data; delivery of transactional email and SMS.Australia (Asia Pacific — Sydney)
XeroExchanging ledger and accounting data for entities a customer has connected.Australia, New Zealand and other locations used by Xero
Australian Taxation OfficeRetrieving account and lodgement information under the customer's authorisation.Australia
OpenAIReading uploaded documents to extract figures into the correct workpaper.United States
Google (Firebase)Delivering push notifications, including multi-factor authentication codes, to users who enable them.United States and other locations used by Google
Have I Been PwnedChecking whether a new password has appeared in a known public data breach, using an anonymised fragment of the password's hash.Global (distributed hosting)
Professional advisersLegal, accounting, audit and insurance advice.Australia
Regulators, courts and law enforcementWhere disclosure is required or authorised by law.Australia

We may also disclose personal information to a purchaser or prospective purchaser in connection with a sale, merger or restructure of our business, subject to appropriate confidentiality protections.

We require our service providers to protect personal information, to use it only for the purposes we engage them for, and to comply with obligations no less protective than those in this policy.

9. Disclosure outside Australia

We host the platform and store customer data in Australia. Some limited processing occurs overseas:

  • Document reading. Where a customer uses our document extraction feature, the uploaded document is sent to OpenAI in the United States to be read, and the extracted figures are returned to the workpaper. The document is sent for that purpose only and is not used to train models.
  • Push notifications. Where a user enables push notifications, the notification — including any multi-factor authentication code sent this way — is delivered through Google's Firebase service, which may process it in the United States or other locations.
  • Password breach checking. When a password is set or changed, the first five characters of a cryptographic hash of it are sent to the Have I Been Pwned service, hosted on globally distributed infrastructure, to check whether the password has appeared in a public breach. The password itself never leaves the platform and cannot be reconstructed from the fragment sent.
  • SMS delivery. Verification codes and alerts sent by SMS are dispatched from AWS in Sydney, but may be routed through carrier networks outside Australia on the way to the recipient's handset.
  • Connected services. Data exchanged with Xero may be stored or processed in locations Xero uses outside Australia, under Xero's own privacy terms.

Before disclosing personal information overseas we take steps reasonable in the circumstances to ensure the recipient handles it in a way consistent with the Australian Privacy Principles, including through contractual commitments. You should be aware that overseas recipients are subject to the laws of their own country, and that the protections available to you in those countries may differ from those in Australia.

A customer that does not wish uploaded documents to be processed overseas can choose not to use the document extraction feature and enter the figures manually.

10. Automated processing and AI-assisted features

The platform applies automated rules and calculations to prepare workpapers, and uses artificial intelligence to read uploaded documents and extract figures from them.

These processes produce a draft for a qualified person to review. They do not make decisions about individuals, and no automated process in Finetica makes a decision that legally or significantly affects an individual without a human reviewing and approving it. Every workpaper is prepared for review, adjustment and sign-off by the accounting practice using it.

We also apply automated checks to protect the platform — for example detecting unusual sign-in patterns, blocking passwords known to have appeared in public breaches, and rate-limiting suspicious activity. Where such a check restricts access, a person can review that outcome on request.

11. Cookies and our website

Our website uses only what it needs to work. We set a session cookie when you use the contact form, to protect it against automated abuse and cross-site request forgery. It expires when you close your browser.

We do not use advertising cookies, and we do not run third-party advertising or social media trackers on this website.

Our website loads a web font from Google Fonts. When it does, your browser makes a request to Google's servers, which necessarily discloses your IP address to Google.

Our web server keeps standard access logs — IP address, page requested, timestamp, referrer and browser — which we use to operate and secure the site.

The Finetica platform does not rely on cookies to keep you signed in. It uses your browser's session and local storage instead, which holds only your signed-in session and preferences and is essential to the platform working. Your session entry is cleared when you sign out.

12. How we protect information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Those steps include:

  • encryption of data in transit using current TLS standards;
  • multi-factor authentication on platform accounts, using an authenticator app, a push notification to a registered device, SMS or email;
  • storing passwords only as salted hashes, and checking new passwords against known public breach data;
  • role-based access control, so each user sees only the customers, entities and functions their role permits;
  • segregation of each customer's data from every other customer's;
  • activity, sign-in and exception logging, and monitoring for unauthorised access;
  • limiting staff access to what is required to perform a role, under confidentiality obligations; and
  • regular backups, patching and security review of our infrastructure and code.

No method of transmission or storage is completely secure. While we work hard to protect information, we cannot guarantee absolute security. You can help by keeping your credentials confidential, using multi-factor authentication, and telling us immediately if you suspect your account has been compromised.

13. Data breaches

We maintain a data breach response plan. If we suspect a data breach we will contain and assess it promptly.

If an eligible data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth).

Where a breach affects information we hold on behalf of a customer, we will notify that customer without undue delay and co-operate with them in meeting their own notification obligations.

14. How long we keep information

We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as the law requires.

  • Customer data in workpapers is retained for the term of the customer's subscription. After it ends, we retain it in a retrievable form for 30 days so the customer can obtain an export, then delete or de-identify it from our production systems within a further 60 days. Backup copies age out in the ordinary course of backup expiry.
  • Account and user records are retained while the account is active and for a reasonable period afterwards to handle queries and disputes.
  • Billing and financial records are retained for at least seven years to meet our taxation and corporate record-keeping obligations.
  • Security, sign-in and activity logs are retained for a period appropriate to their purpose, generally no longer than 24 months.
  • Enquiries and correspondence are retained while we need them, then deleted.
  • Unsuccessful job applications are retained for up to 12 months unless you ask us to delete them sooner.

When information is no longer needed and we are not required to keep it, we destroy it securely or de-identify it.

15. Direct marketing

We may send you information about Finetica — product updates, invitations and occasional news — where you have asked for it, where you are a customer, or where you would reasonably expect it having given us your details.

Every marketing message includes a way to unsubscribe, and we will act on an unsubscribe request promptly. You can also opt out at any time by emailing info@finetica.com.au.

Opting out of marketing does not stop service messages we need to send you — verification codes, security alerts, billing notices and notices about changes to our terms.

We comply with the Spam Act 2003 (Cth). We never use information held in a customer's workpapers to market to the individuals it concerns.

16. Accessing and correcting your information

You may ask us for access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

Send your request to info@finetica.com.au. We will need to verify your identity before we act on it. We will respond within 30 days.

Access is normally free. If a request requires substantial work we may charge a reasonable cost-based fee, and we will tell you what it is before we proceed.

There are limited circumstances in which we may refuse access or correction — for example where giving access would unreasonably affect another person's privacy, or where we are required or authorised by law to refuse. If we refuse, we will tell you why in writing and how you can complain.

Many details can be updated directly in your Finetica profile. If the information you are asking about sits inside a workpaper belonging to an accounting practice, please contact that practice — we will refer your request to them.

17. Making a complaint

If you believe we have handled your personal information in breach of the Australian Privacy Principles, please tell us. Email info@finetica.com.au with the words "Privacy complaint" in the subject line, and set out what happened and what you would like us to do.

We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If we need longer we will tell you why and keep you updated.

If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner:

Office of the Australian Information Commissioner
GPO Box 5218, Sydney NSW 2001
Telephone 1300 363 992
www.oaic.gov.au

18. Children

Finetica is a business platform and is not directed at children. We do not knowingly collect personal information from anyone under 18 as a user of the platform. If you believe a child has provided us with personal information, contact us and we will delete it.

19. Changes to this policy

We may update this policy from time to time to reflect changes to the platform, our practices or the law. The current version is always published on this page, with the version number and effective date shown at the top.

Where a change is material, we will give notice by email to account administrators or by notice in the platform before it takes effect.

20. Contact us

For any privacy question, request or complaint:

Privacy Officer
Finetica Pty Ltd
ABN 58 689 613 447
Victoria, Australia
info@finetica.com.au