Privacy Policy
Last updated: September 2025
SyncBricks (“we”, “our” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose and safeguard your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Company: SyncBricks
ABN: 99 257 759 706
Email: hello@syncbricks.com.au
Location: Melbourne, Victoria, Australia
Information We Collect
We collect personal information that is reasonably necessary for our business functions and activities. This includes:
- --Contact information: name, email address, phone number, job title, company name
- --Business information: company size, industry, IT infrastructure details provided during consultations
- --Technical information: IP address, browser type, device information, website usage data collected automatically
- --Service data: information collected during service delivery including system configurations, access credentials (encrypted) and support records
How We Use Information
We use your personal information for the following purposes:
- --Service delivery: providing managed IT services, support and consulting
- --Communication: responding to inquiries, sending service updates and newsletters (with consent)
- --Business operations: billing, accounting, compliance and internal administration
- --Improvement: analysing website usage and service performance to improve our offerings
- --Legal obligations: complying with applicable laws, regulations and legal processes
Accounting & Integration Data
When you use our finance automation and integration services, we access data from the accounting and business systems you choose to connect. In Australia these commonly include accounting platforms such as Xero, MYOB (Business and AccountRight), QuickBooks Online and Reckon, together with connected business systems such as email, document management, CRM, ecommerce and payroll (for example Microsoft 365, Google Workspace, HubSpot, Shopify and Employment Hero). This access is subject to the following:
- --Consent-based access: accounting data is only accessed after an authorised administrator connects the account and approves the required permissions through the platform's OAuth 2.0 authorisation process.
- --No credentials stored: we never collect or store your accounting-platform usernames or passwords. OAuth access and refresh tokens are encrypted and stored separately from application code.
- --Least privilege: we request only the minimum data scopes required for the features you activate.
- --Purpose-limited use: accounting data is used solely to provide the integration and automation services you select. We do not sell it, use it for unrelated advertising, or use customer accounting information to train public artificial intelligence models.
- --You stay in control: the connected accounting platform remains your system of record, and you can disconnect the integration at any time.
For the technical and organisational controls we apply to this data, see our Security & Data Protection statement.
AI, Automation & Process Discovery Engagements
Our AI, automation and process discovery services can require access to your systems and to activity or event data that includes information about individual users. We handle this using data minimisation, purpose limitation and privacy-by-design, consistent with recognised process intelligence practice. In particular:
- --We access only the systems and data needed for the agreed work, using scoped, least-privilege and time-boxed access that is revoked on completion.
- --We filter, anonymise or pseudonymise user-level and personal data wherever the optimisation outcome does not depend on individual identity.
- --Engagement data is retained only for as long as needed and is returned or securely deleted when the work is complete - by default within 30 days - unless a longer period is agreed or required by law.
Full detail is on our Data Processing & Retention page.
Information Sharing
We do not sell your personal information. We may share your information with:
- --Service providers: trusted third-party vendors who assist us in delivering services (e.g., cloud hosting, email platforms) under confidentiality agreements
- --Professional advisers: lawyers, accountants and auditors who need access to provide their services
- --Law enforcement: where required by law, court order or to protect our rights, property or safety
Data Security
We take data security seriously and implement measures consistent with the Essential Eight framework to protect your personal information:
- --Encryption of data in transit and at rest
- --Multi-factor authentication for all systems accessing personal data
- --Regular security audits and vulnerability assessments
- --Restricted access to personal information on a need-to-know basis
- --Regular backups and disaster recovery testing
While we strive to protect your personal information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but continuously work to strengthen our defences. Full detail of our controls is on our Security & Data Protection page.
Data Residency & Cross-border Disclosure
Customer data is hosted in Australia (Amazon Web Services, Australia region) unless you and the relevant platform, such as Xero or MYOB, are informed and any required approval is obtained. Where we engage third-party infrastructure providers, access is limited to what is technically required to deliver the service. Our current providers are listed on our Sub-processors page.
Where any disclosure to an overseas recipient may occur, we take reasonable steps to ensure the recipient handles your personal information consistently with the Australian Privacy Principles.
Data Retention
We retain personal and accounting data only for the period required to provide the service, meet contractual requirements and satisfy applicable legal obligations. You may request disconnection, data export or deletion in accordance with your service agreement and applicable law, after which data is deleted or de-identified unless we are legally required to retain it.
Cookies
Our website uses cookies and similar technologies to operate the site and understand how it is used. See our Cookie Policy for details and how to control them.
Your Rights
Under the Privacy Act 1988 (Cth), you have the following rights:
- --Access: request access to the personal information we hold about you
- --Correction: request correction of inaccurate or outdated information
- --Deletion: request deletion of your personal information where no longer needed
- --Complaint: lodge a complaint about our handling of your personal information
To exercise any of these rights, contact us at hello@syncbricks.com.au. We will respond within 30 days.
Contact Us
If you have questions about this Privacy Policy or our handling of your personal information, please contact us:
Have Questions About Our Services?
We're happy to discuss how SyncBricks can help your business with AI-first managed IT services.
Get in Touch