Data Processing & Retention
Last updated: September 2025
SyncBricks provides AI, automation and process discovery services. To identify processes worth optimising, and to build and run automations, we sometimes need access to a customer's systems and to activity or event data that can include information about individual users. These systems can include accounting platforms (such as Xero, MYOB and QuickBooks Online), CRM, ecommerce, payroll, email and document management. This page explains how we handle that data.
Our approach follows privacy by design and by default, consistent with how the process intelligence industry operates and with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). It is aligned with recognised standards such as ISO/IEC 27001 and ISO/IEC 27701, and applies the same core controls that leading process-mining platforms use: collect only what is needed, protect identities, and delete data once the work is complete.
Our Data-handling Principles
- --Data minimisation: we access and process only the data that is necessary for the agreed purpose - no more.
- --Purpose limitation: data obtained for a process discovery or automation engagement is used only for that engagement, not for any unrelated purpose.
- --Customer ownership: the customer owns their data. We act on the customer's instructions and under a written agreement.
- --Transparency: the systems in scope, the data accessed and the retention period are agreed with the customer before work begins.
- --No training of public AI models: customer data is never used to train public or third-party AI models, and is never submitted to consumer AI accounts.
Access to Customer Systems
Where an engagement requires access to a customer's systems, that access is:
- --Scoped and least-privilege: limited to the specific systems and data needed for the work.
- --Read-only where possible: we prefer read-only or export-based access for discovery and analysis; write access is only used where the customer has approved an automation that requires it.
- --Time-boxed: access is granted for the duration of the engagement and revoked on completion.
- --Provisioned by the customer: access is granted through the customer's own controls and consent, with multi-factor authentication for administrative access.
- --Audit logged: access and material actions are recorded so there is a clear trail of what was accessed and done.
Handling User-level & Personal Data
Process and activity data can reveal who did what and when. Before this data is used for analysis, we apply one or more of the three standard techniques used across the process intelligence industry:
- --Filter: exclude personal or sensitive fields that are not needed for the analysis.
- --Anonymise: permanently remove the ability to identify an individual where identity is not needed for the outcome.
- --Pseudonymise: replace direct identifiers (such as user IDs and names) with tokens, ideally at or near the point of extraction, so analysis can proceed without exposing individual identities.
We favour anonymisation or pseudonymisation of user-level data wherever the optimisation outcome does not depend on individual identity. Where personal information is processed, we handle it in accordance with the APPs and the agreed lawful basis, and we support customers in meeting any employee-notification or consultation obligations that apply to them.
Retention & Deletion After the Work Is Done
- --Kept only as long as needed: engagement data is retained only for the period required to deliver the service and any period agreed with the customer.
- --Returned or deleted on completion: when the work is complete, or on contract termination, we return or securely delete customer engagement data - by default within 30 days - unless a longer period is agreed in writing or required by law.
- --Deletion on request: customers may request export or deletion of their data at any time, in accordance with the service agreement and applicable law.
- --Configurable audit logs: retention of audit and log data is configurable and kept for the minimum period needed for security and accountability.
- --Backups: where data persists in encrypted backups after deletion, it is overwritten on the normal backup rotation and is not restored into production use.
Data Processing Agreement
For engagements involving personal information, we can enter into a Data Processing Agreement that sets out the roles of the parties, the scope and purpose of processing, security measures, use of sub-processors, and return or deletion of data on completion. Contact us to request one.
Where Data Is Held
Customer data is hosted in Australia unless the customer is informed and any required approval is obtained. Where we use third-party infrastructure providers, access is limited to what is technically required to deliver the service. Our current providers are listed on the Sub-processors page. For our full set of technical and organisational controls, see the Security & Data Protection statement, and for how we handle personal information generally, see our Privacy Policy.
Contact
For questions about how we process and retain data, or to request a Data Processing Agreement, contact us:
Company: SyncBricks
ABN: 99 257 759 706
Email: hello@syncbricks.com.au
Location: Melbourne, Victoria, Australia
Planning a Process Discovery Engagement?
We'll scope exactly what data is needed, protect user identities, and delete it when the work is done.
Talk to Us