Privacy Policy
Effective Date: 12 June 2026
This Privacy Policy explains how blgaccounting.com.au ("we", "us", "our") collects, uses, discloses, and protects personal information in connection with our accounting and related professional services, including our use of third-party email services such as Google, Yahoo, and Microsoft APIs.
1. Introduction
We are committed to maintaining the confidentiality, integrity, and security of the personal information entrusted to us. Given the sensitivity of financial and tax information, we apply strict governance, role-based access, encryption standards, and continuous monitoring to reduce risk and meet applicable professional and statutory obligations.
2. Scope
This Policy applies to personal information we process about (i) clients, (ii) prospective clients, (iii) users of our platform and tools, (iv) vendors, and (v) other individuals whose data we handle in the course of providing accounting, advisory, bookkeeping, compliance, reporting, and related professional services. It covers online and offline collection channels unless stated otherwise.
3. Data We Collect
- Identification & contact: name, address, email, phone, government identifiers where legally required (e.g., tax file / ABN equivalents, business registration numbers).
- Account & authentication: usernames, role assignments, audit trails, session metadata, access logs.
- Financial & transactional: invoices, receipts, bank feed data (where expressly authorized), general ledger details, payroll inputs, expense records, payment confirmations.
- Compliance & regulatory: documents required for KYC/AML (to the extent legally permissible), risk assessments, declarations, attestations.
- Communication records: emails, messages, support tickets, meeting notes.
- Technical (limited): device/browser information, IP address, time zone, usage analytics (aggregated / pseudonymized where possible), security events.
- Optional submissions: feedback, survey responses, uploaded supporting documents.
- Email account data (where authorized via OAuth): email message metadata (subject, sender, date), email body content, and attachments (PDFs, images) from connected Gmail, Yahoo Mail, or Microsoft Outlook accounts, limited to invoices, receipts, and financial documents relevant to our accounting services.
We minimise collection to what is necessary for stated purposes. Where we act on behalf of a client regarding third-party personal information (e.g., employees in payroll), the client warrants lawful collection and transfer.
4. How We Use Personal Information
- Deliver and administer accounting and advisory services.
- Prepare, review, and file financial, tax, and compliance reports.
- Maintain accurate internal records and audit logs.
- Provide secure platform access, authentication, and authorization.
- Detect, prevent, and investigate fraud, errors, or abuse.
- Meet legal, regulatory, professional, and contractual obligations.
- Improve quality, security, automation, and user experience.
- Respond to inquiries and provide client support.
- Conduct anonymised or aggregated analytics (non-identifying).
- Send service-related notices (system changes, incidents, compliance reminders).
- Process email account data (messages and attachments from connected Gmail, Yahoo Mail, or Microsoft Outlook accounts) solely to identify, extract, and categorize invoices, receipts, and financial documents for automated accounting workflows.
We do not sell personal information (including email account data), nor do we permit third parties to use client data for their independent marketing without explicit, informed consent. Email account data is never used for advertising purposes.
5. Legal Bases (Where Applicable)
Depending on jurisdiction, processing is grounded in: (a) performance of a contract; (b) compliance with legal and professional obligations; (c) legitimate interests (e.g., security, service improvement) balanced against individual rights; (d) consent (for optional features); or (e) vital interests or public interest where required.
7. Data Retention
We retain personal information only as long as necessary for service delivery, contractual obligations, statutory limitation periods, professional recordkeeping standards, or regulatory retention requirements (e.g., tax documentation requirements). Email account data (email content and attachments) is retained only for the duration of the relevant financial year processing and any applicable statutory retention period. Upon expiry of retention criteria, data is securely deleted, anonymised, or archived with restricted access.
8. Security Measures
We implement layered safeguards aligned with industry and professional expectations, including: encryption in transit (TLS) and at rest, strict role-based access control (RBAC), principle of least privilege, multi-factor authentication options, network segmentation, secure development lifecycle practices, vulnerability management, intrusion and anomaly detection, logging & immutable audit trails, regular access reviews, incident response procedures, and background checks for staff with elevated privileges.
Email account data is protected with the same layered safeguards, including OAuth token encryption, PIN-protected client review flows, and secure cloud storage with signed URL access controls. No system is fully immune from risk. In the event of a data incident meeting legal notification thresholds, we will follow applicable breach notification laws.
10. International Data Transfers
Where cross-border transfers occur, we rely on applicable adequacy decisions, contractual safeguards (such as standard contractual clauses), or other lawful transfer mechanisms, and we assess jurisdictional risk and implement supplementary controls as needed.
11. Your Rights
Subject to applicable law, you may have rights to access, rectify, update, restrict, object to processing, port, or erase personal information. Requests should: (i) provide sufficient detail to identify data; (ii) include proof of identity; and (iii) specify the right invoked. We will respond within statutory timelines. Certain records (e.g., tax filings, mandatory ledgers) may be exempt from erasure while legal obligations persist.
Where consent is relied upon, you may withdraw it at any time without affecting prior lawful processing.
12. Children’s Privacy
Our services are not directed to children. We do not knowingly collect personal information from individuals below the minimum legal working or consent age in relevant jurisdictions. If you believe we have inadvertently collected such information, contact us for prompt remediation.
13. Changes to This Policy
We may update this Privacy Policy to reflect regulatory, technical, or operational changes. If we change how we access, use, store, or share email account data, we will notify affected users in advance and seek renewed consent where required. Material updates will be posted with a revised Effective Date and, where required, additional notice or consent will be sought.
14. Contact Us
For questions, requests, complaints, or to exercise rights, contact our privacy team at: privacy@blgaccounting.com.au. If unresolved, you may have the right to lodge a complaint with a relevant data protection or privacy regulator in your jurisdiction.
15. Email API Services & User Data
Our platform integrates with third-party email APIs (Gmail, Yahoo Mail, and Microsoft Outlook) to provide automated invoice and receipt extraction from your connected email accounts. This section explains how we handle email account data in compliance with each provider's user data policies, including the Google API Services User Data Policy, Yahoo Developer Terms, and Microsoft APIs Terms of Use.
15.1 Email Data We Access
With your explicit OAuth consent for each provider, we access the following email account data:
- Email message metadata: subject lines, sender/recipient email addresses, and dates of emails matching invoice or receipt keywords.
- Email message content: the body text of emails identified as containing invoices or receipts.
- Email attachments: PDF and image files attached to qualifying emails (excluding inline images and files smaller than 10KB).
We request only the minimum read-only permissions necessary and limit our search to financial documents within your specified financial year, regardless of provider.
15.2 How We Use Email Data
Email account data is used exclusively for the following purposes:
- Identifying and extracting invoices, receipts, and financial documents from your connected email accounts.
- Staging extracted documents for client review and approval before making them available to your accountant.
- Automating data entry into accounting workflows to reduce manual processing.
We do not use email account data for advertising, profiling, credit scoring, or any purpose unrelated to providing our accounting automation services.
15.3 How We Store & Protect Email Data
- OAuth access and refresh tokens are encrypted at rest in our database.
- Extracted email attachments are stored in secure cloud storage with signed URL access controls.
- A PIN-protected client review portal ensures that only the authorized client can approve documents before they become visible to the accountant.
- All data transfers occur over encrypted TLS connections.
15.4 Sharing & Transfer of Email Data
Email account data is shared only with:
- Your authorized accountant or professional service provider, solely after your explicit document-by-document approval via the PIN-protected review portal.
- Cloud infrastructure services used to process and store the data, bound by each provider's data processing terms.
We do not sell email account data. We do not transfer email account data to third parties for advertising, data brokering, or any purpose unrelated to providing our accounting services.
15.5 Data Retention for Email Data
Extracted email attachments and metadata are retained only for the duration of the financial year processing and any applicable statutory retention period required for tax and accounting records. OAuth tokens can be revoked by you at any time via your account permissions page with each provider, which will prevent further access.
15.6 Your Control Over Email Data
You maintain full control over your email data across all connected accounts:
- You can revoke our access at any time via your account permissions page: Google, Yahoo, or Microsoft.
- Before any scanned document is visible to your accountant, you must review and approve it through our PIN-protected client portal.
- You may request deletion of your email-derived data by contacting us (see Section 14).