Privacy Policy
Last updated: 23 June 2026
DocFlow (“we”, “us”, “our”) is committed to protecting your privacy. This policy explains how we collect, use, disclose and safeguard personal information, in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). It applies to docflow.au and the DocFlow application.
1. Who we are
DocFlow provides document-collection and payroll-timesheet software for accounting firms. We act as the operator of the platform. Where an accounting firm uses DocFlow to collect documents or timesheets from their own clients (and those clients’ staff), the firm is responsible for that data as the data controller, and DocFlow acts as the data processor on their behalf.
2. Information we collect
- Account information — your name, email address, firm name, password (stored hashed, never in plain text), and any logo or branding you upload.
- Client and engagement data — information your firm enters about its clients (such as name, email, phone, ABN, address), the documents your clients upload, and, for payroll, your clients’ staff details and the timesheets they submit.
- Billing information — handled by our payment processor; we do not store full card numbers.
- Usage and technical data — log data, IP address, device/browser information, and activity within the app, used to operate and improve the service.
3. How we use your information
- To provide, maintain and improve the DocFlow service;
- To send transactional emails and SMS (such as confirmations, document requests, timesheet links and reminders);
- To process subscriptions and payments;
- To provide AI-assisted validation and extraction of data from uploaded documents and timesheets;
- To respond to support requests and communicate with you;
- To detect, prevent and address security or technical issues, and to comply with our legal obligations.
We do not sell your personal information, and we do not use your or your clients’ data for advertising.
4. AI processing of documents
When documents or timesheets are uploaded, we may send them to our AI provider (Anthropic) to validate that the right document was provided and to extract data from it. This processing is transient: it happens to return a result to you. Under Anthropic’s commercial API terms, content sent through the API is not used to train its models and is not retained beyond what is needed to process the request — and we do not permit such use. AI extraction assists your review; you remain responsible for checking the results.
5. Disclosure to service providers (sub-processors)
We use trusted third-party providers to operate DocFlow. They only process data as needed to deliver their service to us, under their own security and privacy obligations:
- Supabase — database, authentication and encrypted file storage;
- Vercel — application hosting;
- Resend — transactional email delivery;
- Twilio — SMS delivery (where enabled);
- Stripe — subscription billing and payments;
- Anthropic — AI validation/extraction of uploaded documents (see section 4);
- Xero — where you connect your Xero organisation, to sync contacts and push documents or payroll data at your direction.
We keep this list current. Where we add or change a sub-processor in a way that materially affects how Customer Data is handled, we will update this policy.
6. Where your data is stored
Your account and document data is stored with our infrastructure providers (primarily Supabase and Vercel). Some providers store or process data outside Australia, including in the United States; AI processing (section 4) is performed transiently overseas. By using DocFlow you acknowledge your information may be stored or processed overseas. We take reasonable steps to ensure such providers handle information consistently with the APPs, including APP 8 (cross-border disclosure).
7. Security
We use commercially reasonable, industry-standard measures to protect your information, including encryption in transit and at rest, access controls, hashed passwords, and one-time-code verification for the client portal. No method of transmission or storage is completely secure, but we work to protect your data and will notify you without undue delay of any eligible data breach as required under the Notifiable Data Breaches scheme.
8. Data retention and deletion
We retain personal information for as long as your account is active or as needed to provide the service, comply with legal obligations, resolve disputes and enforce our agreements. You can export your data at any time while your subscription is active. If your subscription ends, we retain your data for at least 30 days so you can export it before it is removed, after which we may delete it — subject to any legal record-keeping requirements that apply to accounting records. You or your firm may also request deletion of client data at any time.
9. Your rights
You may request access to, or correction of, the personal information we hold about you. You may also request deletion of your account and associated data. To make a request, contact us at privacy@docflow.au. Where DocFlow processes data on behalf of an accounting firm (for example, that firm’s clients or their staff), please direct requests about that data to the firm, and we will support the firm in responding.
10. Cookies
We use essential cookies to keep you signed in and to operate the service, and privacy-friendly, aggregate analytics to understand usage. We do not use cookies for third-party advertising.
11. Changes to this policy
We may update this policy from time to time. The “last updated” date above reflects the latest version. Material changes will be communicated through the app or by email.
12. Contact us
For privacy questions or requests, contact privacy@docflow.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.