PrepDesk

Trust

How we look after your clients’ data

Our promise

  1. Your clients’ documents and data are stored and processed only in Australia.
  2. We automatically remove tax file numbers and never store them.
  3. No other firm can ever see your data, and our own staff can see it only when you approve, for a set time, with a record kept.
  4. Your data is never used to train AI models.
  5. You choose how long source documents are kept, and deleted means permanently deleted.
  6. If something goes wrong, we tell you quickly and help you meet your own obligations.

Where is my data?

In Australia. Documents, workpapers and every record are stored in Sydney.

The AI that reads documents runs in Australia too, in Sydney or Melbourne. Nothing about your clients is processed overseas.

What about tax file numbers?

We remove them automatically the moment a document arrives, and we never store them. Your tax software already has them; we don’t need them.

Can anyone else see my clients?

No. Every firm’s data is walled off twice: in our code and in the database itself.

Our team can only look at your data if you grant access for a specific reason and time. Every access is recorded and visible to you.

Is my data used to train AI?

No. Your documents and figures are never used to train AI models.

Who is responsible for the return?

You are. We prepare workpapers for your review. Your registered tax agent reviews, decides and lodges.

Anything exported without review is clearly marked as a draft.

How long do you keep documents?

You decide: from 90 days to 7 years after sign-off (12 months by default). Then they’re permanently deleted.

If you leave, you get 30 days to export everything, then we delete it all and confirm in writing.

How do you protect logins?

Two-step verification for everyone, automatic sign-out after 30 minutes of inactivity, and download links that expire within minutes.

What if something goes wrong?

We have a written incident plan. If your data is affected, we tell you quickly, explain what happened, and help you meet your own obligations, including under the Notifiable Data Breaches scheme.

Who else is involved?

A short list of providers, published below with what each does and where.

Providers that touch data

Every provider that touches data: what it does, what it sees, and where
ProviderWhat it doesData it seesWhere
Amazon Web ServicesFiles, workers, email, OCR, AI (Bedrock), keys, secretsClient documents and figuresSydney; AI also Melbourne
NeonDatabaseAll recordsSydney (on AWS)
VercelWeb appScreens and requests in transitSydney region
Anthropic (through Bedrock)Claude modelsDocument text only (tax file numbers removed first; no page images), processed within AWS AustraliaSydney and Melbourne
XeroClient list import (when connected)Client names and contacts the firm already holds in XeroXero’s own hosting
StripeSubscriptions and paymentsFirm name, billing contact, payment details; no client dataOutside Australia
Error trackingCrash reportsTechnical details only; client data removed before sendingOutside Australia unless an Australian option is chosen

Contact

Questions about your clients’ data, a privacy request or a complaint? Write to us:

malakye@prepdesk.com.auEmail PrepDesk

Privacy policy · Data processing agreement · Terms of service · Start with PrepDesk