Privacy Policy
How we collect, use, store, secure and disclose personal information when you use ReconLink. Written to align with the Australian Privacy Principles in Schedule 1 of the Privacy Act 1988 (Cth).
Effective 24 August 2026 · Innovious Group Pty Ltd · ABN 59 637 038 754
Innovious Group Pty Ltd (ABN 59 637 038 754) (“ReconLink”, “we”, “us”, “our”) operates a bank reconciliation and statement-coding platform for Australian accounting practices (the “Service”). This policy explains how we handle personal information when you, your colleagues or your clients interact with the Service or our website at reconlink.com.au.
We treat compliance with the Privacy Act 1988 (Cth) (the Privacy Act) and the thirteen Australian Privacy Principles (APPs) as the floor, not the ceiling. Where we serve users in jurisdictions with stricter requirements (e.g. the European Union under the GDPR, or the United Kingdom under the UK GDPR), we apply those higher standards in addition.
1What this policy covers
This policy applies to all personal information we collect through:
- Our public marketing site at reconlink.com.au;
- The ReconLink application (the practice dashboard, client portal, admin console);
- Email and other support channels (info@reconlink.com.au);
- Inbound channels including the per-client email inbox feature and CSV/Excel/PDF uploads, where personal information may be embedded in the source documents.
This policy does not cover handling of personal information by your accounting practice or by your clients, who remain independent controllers of the data they enter into the Service. It also does not cover third-party sites we link to.
2The kinds of personal information we collect
2.1Account information
Names, work email addresses, business phone numbers, role within the practice, password hashes (we never store cleartext passwords), and authentication metadata such as session timestamps and IP addresses.
2.2Practice and client information
Business names, ABNs, GST registration status, accounting software identifiers, and details of the bookkeeping and BAS engagements between the practice and its clients.
2.3Bank transaction and financial information
Bank transactions uploaded as CSV, Excel or PDF statements, or forwarded to a per-client email inbox. This may include account identifiers (which we store in masked form where possible), transaction descriptions, counterparties, amounts, balances and source documents.
We classify bank transaction and statement data as sensitive financial information and apply heightened controls (see our Security page).
2.4Email and forwarded content
Where you forward statements to the per-client email inbox, we ingest the message envelope (sender, recipient, message ID, timestamp) and the attachment payload. We do not parse forwarded message bodies for content beyond what is necessary to validate the sender and ingest the attachments.
2.5Usage, device and analytics information
Page views, feature interactions, browser type, screen size, approximate location derived from IP address, and application logs. We use this data to operate, secure and improve the Service. We do not run third-party advertising trackers on logged-in product surfaces.
2.6Sensitive information
We do not solicit sensitive information (as defined in section 6 of the Privacy Act, including health information and information about racial or ethnic origin). If sensitive information appears incidentally in a transaction description or attachment, we treat it as confidential and do not use it for any secondary purpose.
2.7Consumer Data Right (CDR) bank-feed data
Where a business bank account is connected through our automated bank feed, we collect account details, balances, transactions and the account holder’s organisation profile under the Consumer Data Right, with the account holder’s express consent. Fiskil is the Accredited Data Recipient; an eligible business customer directs Fiskil to share that data with us. ReconLink is not accredited under the Consumer Data Right. That CDR data is handled in accordance with Fiskil’s CDR Policy — see section 13. The feed is available to business customers only, and Fiskil determines eligibility as part of its consent process.
3How we collect personal information
We collect personal information directly from you when you register, sign in, configure your practice, upload statements, contact support or fill in our contact form. We also collect personal information indirectly when:
- Your practice colleagues invite you to a workspace and populate fields about you;
- Your clients are added by your practice and bank transactions are imported on their behalf;
- An allowlisted sender forwards a statement to a client’s unique email inbox address.
4Why we collect and use personal information
We use personal information to:
- Provide, authenticate and personalise the Service;
- Reconcile, code and report on bank transactions on behalf of the practice;
- Generate BAS, P&L and cash-flow exports in the format requested by the practice;
- Bill subscriptions, manage trials and process refunds;
- Respond to support requests and security or compliance enquiries;
- Detect, investigate and prevent fraud, misuse and security incidents;
- Comply with our legal and regulatory obligations, including under the Privacy Act, the Australian Consumer Law (Schedule 2 of the Competition and Consumer Act 2010 (Cth)) and tax and corporations law;
- Conduct quality and performance research on aggregated, de-identified data sets to improve the Service.
5To whom we disclose personal information
We disclose personal information only to the categories of recipients listed below, and only to the extent required for the purposes set out in section 4:
- Service providers and sub-processors — our infrastructure, communications and analytics vendors, each engaged under written contracts requiring them to protect personal information consistently with the APPs. Our current sub-processor list is set out in section 6.
- Your practice administrators — where you are a practice user, administrators of the same practice workspace can see your account profile and audit-log entries.
- Your clients — where you make information visible through the client portal.
- Professional advisers — lawyers, accountants, auditors and insurers, bound by confidentiality.
- Acquirers — in the event of a sale, merger or asset transfer involving ReconLink, subject to equivalent privacy commitments.
- Law enforcement and regulators — where disclosure is required or authorised by Australian law, including under a warrant, court order or notice from a regulator such as the OAIC, the ATO or ASIC.
We do not sell, rent or trade personal information.
6Sub-processors and overseas transfers
The following sub-processors host or process personal information on our behalf. Our primary database is hosted in AWS Sydney (ap-southeast-2) for Australian data residency. Contact security@reconlink.com.au with any data-handling questions.
- Supabase Inc. (PostgreSQL database + storage) — primary data store, hosted in AWS Sydney (ap-southeast-2). Data at rest is encrypted with AES-256.
- Fiskil Pty Ltd (Consumer Data Right bank feeds) — the Accredited Data Recipient (ADRBNK000246) that operates the CDR consent flow and retrieves your account, balance and transaction data from your bank when you connect an automated bank feed. See section 13 and Fiskil’s CDR Policy.
- Railway Corporation (application hosting) — runs the FastAPI application and background workers.
- Vercel Inc. (frontend hosting) — serves the ReconLink web application. No data is persisted here.
- Postmark / ActiveCampaign Inc. — inbound email parsing for the per-client email inbox feature, and transactional email delivery.
- Resend, Inc. and Zoho Corporation Pty Ltd — transactional and notification email delivery. These providers receive the recipient’s email address, your practice’s name and the content of the message. Reminder and receipt-request emails carry a count of items awaiting your input and a secure link; they do not carry account, balance or transaction detail.
- Mobile Message Pty Ltd (Australia) — SMS delivery for client reminders. Receives the recipient’s mobile number, your practice’s name, a count of items awaiting your input and a secure link. No account, balance or transaction detail is sent by SMS.
- OpenAI, L.L.C. (United States) — large-language-model inference. Used for Layer 3 of our auto-coding stack, which submits the transaction date, amount and description together with the relevant chart of accounts; and for reading source documents you provide to us, which submits the content of uploaded bank statements and receipt images. Requests are made through the OpenAI API, under terms that exclude API data from model training.
- Xero Limited (New Zealand) — where your accounting practice connects a Xero ledger, ReconLink writes coded transaction records (date, amount, description, account code and GST code) into that ledger at the practice’s direction, and reads ledger data back to keep the two in step. This applies to transactions sourced from the bank feed as well as those imported from statements.
- Stripe Payments Australia Pty Ltd — payment processing for subscription billing. Stripe receives no bank-feed, transaction or CDR data.
When we engage a new sub-processor that materially changes where or how personal information is processed, we will update this list and notify practice administrators by email at least 14 days before the change takes effect.
7Data retention and source-document handling
We retain personal information only for so long as is necessary for the purposes set out in this policy or as required by law. Specifically:
- Bank transactions, BAS worksheets and source documents are retained for the period required by Australian tax law (currently five years from the end of the relevant financial year under section 262A of the Income Tax Assessment Act 1936 and equivalent obligations) or for the length of your subscription, whichever is longer.
- Original PDF, CSV and Excel source files retained in Supabase Storage are purged on a schedule set by the practice (default 12 months after the linked statement is committed), subject to the minimum retention period above.
- Account information is retained for the life of the account and for 12 months after closure, after which it is destroyed or irreversibly de-identified.
- CDR bank-feed data (accounts, balances, transactions collected via Fiskil) is retained only while your consent is active and for as long as needed for the bookkeeping purpose it was collected for; on consent withdrawal or expiry it is deleted or irreversibly de-identified, subject to the minimum tax-record retention above (see section 13).
- Marketing contact submissions and newsletter records are retained for 24 months from last interaction unless you ask us to delete them sooner.
8How we protect personal information
We take reasonable steps under APP 11 to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our controls are described in detail in our Security policy and include transport encryption (TLS 1.2 minimum), at-rest encryption, multi-tenant row-level isolation, least-privilege access, audit logging, secret management, dependency scanning and an incident response plan.
9Cookies and tracking technologies
We use a small number of strictly necessary cookies to keep you signed in and to remember workspace selections. Analytics and feature-flag cookies are first-party only and can be disabled in your browser without breaking the core Service. We do not deploy third-party advertising trackers on authenticated product pages.
10Your rights — access, correction and complaints
Under the Privacy Act you may:
- Request access to the personal information we hold about you (APP 12);
- Request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13);
- Request deletion of personal information where we are not required to retain it for a legal, tax or security purpose;
- Lodge a complaint about how we have handled your personal information.
Most of these requests can be self-served from your ReconLink account settings. For anything that cannot, write to info@reconlink.com.au and we will respond within 30 days. If you are not satisfied with our response you may refer the complaint to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.
11Notifiable data breach response
We maintain an incident response plan aligned with the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act. Where a data breach is likely to result in serious harm to individuals and we cannot remediate that risk, we will notify affected individuals and the OAIC as soon as practicable, and in any event within the timeframes required by law.
12Children
The Service is intended for use by accounting practices and their staff in a professional context. We do not knowingly collect personal information from individuals under the age of 16. If you believe we have done so, contact us and we will delete it.
13Consumer Data Right (CDR) bank feeds
Where a business bank account is connected through our automated bank feed, that data is shared under Australia’s Consumer Data Right (CDR) regime. Fiskil Pty Ltd is the Accredited Data Recipient (ADRBNK000246) and operates the consent flow and the connection to the bank. Where an eligible business customer consents, they direct Fiskil to share their CDR data with ReconLink, and we receive and handle it under Fiskil’s Business Consumer Disclosure Agreement. You will see Fiskil and the Consumer Data Right branding on the consent screen when you connect.
ReconLink is not accredited under the Consumer Data Right, is not a CDR Representative, and is not endorsed or approved by the Australian Competition and Consumer Commission or any other regulator.
CDR data accessed through ReconLink is handled in accordance with Fiskil’s CDR Policy, which governs consent, use, disclosure, retention, deletion, de-identification, notifications and complaints for that data. ReconLink does not maintain a separate CDR policy, and this Privacy Policy does not vary or add to Fiskil’s in respect of CDR data. Our Consumer Data Right page summarises the arrangement.
The bank feed is available to business customers only. Eligibility is determined by Fiskil as part of its consent process, which requires business-consumer information including confirmation of an active ABN. A sole trader can qualify even where the bank account is held in their own personal name, provided an active ABN is confirmed. We do not connect, receive, store or process consumer (individual) account data through the Consumer Data Right. Statements you upload or forward to us yourself are not CDR data and are governed by the rest of this Privacy Policy.
The feed collects account details, balances and transactions, plus the account holder’s organisation profile, which identifies the business that holds the connected account. We request nothing beyond these, and we do not use the organisation profile for marketing.
Where your accounting practice has connected an accounting ledger such as Xero, transactions imported through the bank feed and coded in ReconLink are written to that ledger at the practice’s direction. See section 6.
14Changes to this policy
We may amend this policy from time to time. Material changes will be communicated by email to practice administrators at least 14 days before they take effect. The current version is always available at reconlink.com.au/privacy and the effective date is stated at the top of this page.
15Contacting us
Our Privacy Officer can be reached at:
Innovious Group Pty Ltd · Attention: Privacy Officer
Email: info@reconlink.com.au
Postal: a current postal address will be added once our office is established. In the interim, please use the email address above.

