Privacy Policy

Effective date: 15 June 2026

This Privacy Policy explains how Ezyiah collects, uses, stores, discloses and protects personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are committed to managing personal information openly and transparently.

7.1 Information we collect

We may collect personal details (name, email, business name); account credentials; financial and transactional data uploaded by users, including Client Data; Bank Feed Data accessed through Fiskil; AI Memory data; depreciation and fixed asset data; and usage data and technical logs, including IP addresses and timestamps. We do not sell personal information.

7.2 How we collect information

We collect information directly from you, as you use the Services, and, for Bank Feed Data, through Fiskil with the relevant consent under applicable banking data-sharing arrangements, including the Consumer Data Right.

7.3 How we use information

We use information to provide, maintain, secure and improve the Services; to process reconciliations, bank feeds and reports, including BAS, profit and loss and depreciation schedules; to improve categorisation through AI Memory; to communicate service and account updates; and to meet legal obligations. We use personal information for the primary purpose for which it was collected and for related purposes you would reasonably expect.

7.4 AI processing and automated handling

Uploaded data may be processed by AI systems to produce Output, including bank feed categorisation, AI Memory adjustments and automated reporting. Output is generated programmatically and is not routinely reviewed by Ezyiah staff except where needed for support, security or legal reasons. The Services assist professional users and do not make decisions that produce legal or similarly significant effects on individuals without your review. We do not use your data to train generalised AI models. As transparency requirements relating to automated decision-making take effect, we will update this policy accordingly.

7.5 Disclosure

We may disclose personal information to service providers and infrastructure partners, including cloud hosting, Fiskil for bank feeds, AI infrastructure and analytics providers, engaged under confidentiality and security obligations; to professional advisers; and to regulators, courts or authorities where required or authorised by law. We do not sell personal information.

7.6 Overseas disclosure

Some service providers may store or process information outside Australia, including in countries where our cloud and infrastructure providers operate. Where this occurs, we take reasonable steps to ensure recipients handle information consistently with the APPs.

7.7 Data security

We encrypt personal information in transit and at rest, apply role-based access controls and other technical and organisational measures, and follow industry-standard practices, as described in the Data Security and Information Handling Policy. Despite these safeguards, no system is completely secure.

7.8 Data retention

We retain personal information only as long as needed to provide the Services or meet legal obligations, and then take reasonable steps to destroy or de-identify it, as described in the Record Retention and Deletion Policy. This includes Bank Feed Data, AI Memory data and depreciation records.

7.9 Access and correction

You may request access to, or correction of, your personal information by contacting us. We will respond within a reasonable time, generally within 30 days, and may need to verify your identity. Some requests may be subject to exceptions permitted by law.

7.10 Direct marketing

Where we send marketing communications, you can opt out at any time using the unsubscribe function or by contacting us.

7.11 Cookies and analytics

We use cookies and similar technologies as described in the Cookie Policy.

7.12 Complaints

If you have a privacy concern, contact us at [email protected], marked for the attention of the Privacy Officer. We will acknowledge and investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au or on 1300 363 992.

7.13 Changes

We may update this Privacy Policy from time to time. Section 1.16 applies, and continued use of the Services constitutes acceptance of updates.

7.14 Contact

For privacy enquiries, contact [email protected].