Trust
How we look after your clients’ data
Our promise
- Your clients’ documents and data are stored and processed only in Australia.
- We automatically remove tax file numbers and never store them.
- No other firm can ever see your data, and our own staff can see it only when you approve, for a set time, with a record kept.
- Your data is never used to train AI models.
- You choose how long source documents are kept, and deleted means permanently deleted.
- If something goes wrong, we tell you quickly and help you meet your own obligations.
Where is my data?
In Australia. Documents, workpapers and every record are stored in Sydney.
The AI that reads documents runs in Australia too, in Sydney or Melbourne. Nothing about your clients is processed overseas.
What about tax file numbers?
We remove them automatically the moment a document arrives, and we never store them. Your tax software already has them; we don’t need them.
Can anyone else see my clients?
No. Every firm’s data is walled off twice: in our code and in the database itself.
Our team can only look at your data if you grant access for a specific reason and time. Every access is recorded and visible to you.
Is my data used to train AI?
No. Your documents and figures are never used to train AI models.
Who is responsible for the return?
You are. We prepare workpapers for your review. Your registered tax agent reviews, decides and lodges.
Anything exported without review is clearly marked as a draft.
How long do you keep documents?
You decide: from 90 days to 7 years after sign-off (12 months by default). Then they’re permanently deleted.
If you leave, you get 30 days to export everything, then we delete it all and confirm in writing.
How do you protect logins?
Two-step verification for everyone, automatic sign-out after 30 minutes of inactivity, and download links that expire within minutes.
What if something goes wrong?
We have a written incident plan. If your data is affected, we tell you quickly, explain what happened, and help you meet your own obligations, including under the Notifiable Data Breaches scheme.
Who else is involved?
A short list of providers, published below with what each does and where.
Providers that touch data
| Provider | What it does | Data it sees | Where |
|---|---|---|---|
| Amazon Web Services | Files, workers, email, OCR, AI (Bedrock), keys, secrets | Client documents and figures | Sydney; AI also Melbourne |
| Neon | Database | All records | Sydney (on AWS) |
| Vercel | Web app | Screens and requests in transit | Sydney region |
| Anthropic (through Bedrock) | Claude models | Document text only (tax file numbers removed first; no page images), processed within AWS Australia | Sydney and Melbourne |
| Xero | Client list import (when connected) | Client names and contacts the firm already holds in Xero | Xero’s own hosting |
| Stripe | Subscriptions and payments | Firm name, billing contact, payment details; no client data | Outside Australia |
| Error tracking | Crash reports | Technical details only; client data removed before sending | Outside Australia unless an Australian option is chosen |
Contact
Questions about your clients’ data, a privacy request or a complaint? Write to us:
malakye@prepdesk.com.auEmail PrepDeskPrivacy policy · Data processing agreement · Terms of service · Start with PrepDesk