Privacy Policy

Last updated: August, 2026  |  Version 2.0

AssetAccountant is online software that manages fixed and leased assets for accounting and taxation purposes. This policy explains what personal information we collect, why we collect it, who we share it with, and what rights you have over it.

It applies to everyone we deal with, and includes dedicated sections for individuals in the United Kingdom and the European Economic Area whose information is protected by the UK GDPR and EU GDPR.

1. Who we are

AssetAccountant Pty Ltd (ABN 73 631 508 051) is the entity responsible for the personal information covered by this policy, including for all customers invoiced in the United Kingdom and the European Economic Area. For the purposes of the UK GDPR and EU GDPR, AssetAccountant Pty Ltd is the data controller.

AssetAccountant Inc is our United States entity and contracts with customers in the United States.

You can reach us about anything in this policy at privacy@asset.accountant.

Our representatives in the UK and EU

AssetAccountant Pty Ltd has appointed DataRep as its Data Protection Representative under Article 27 of the UK GDPR and Article 27 of the EU GDPR. DataRep is a company incorporated in Ireland, registered address 12 Northbrook Road, Dublin, D06 E8W5, Ireland, company number 616588.

If you are in the United Kingdom or the European Economic Area, you can contact DataRep about the personal information we hold about you:

When writing by post, address your letter to "DataRep" and not to AssetAccountant, or it may not reach them. Please refer clearly to AssetAccountant Pty Ltd in your correspondence.

These contact details are for data protection requests from individuals and authorities in the UK and EEA only. For all other enquiries, please contact us at privacy@asset.accountant.

2. When we are a controller and when we are a processor

This distinction matters, because different rules apply.

We are a controller for information we decide how to use ourselves. That covers website visitors, enquiries, marketing, account administration, billing and support.

We are a processor for the asset, lease and finance data our customers load into the AssetAccountant platform. That data belongs to the customer, we handle it only on their documented instructions, and the customer is the controller. If your employer or accountant uses AssetAccountant and you want to know how your information is handled inside the platform, contact them first. We will support them in responding to you.

Our processing of customer data is governed by our customer agreement and, where required, a Data Processing Agreement. A copy is available on request from privacy@asset.accountant.

3. What information we collect

Website visitors and enquirers

  • Name, email address, phone number, company name
  • The content of your enquiry or message
  • Technical data including IP address, browser type, device type, pages viewed and referring source

Customers and platform users

  • Account details, including user names, email addresses and role permissions
  • Billing and subscription information
  • Support requests and correspondence
  • Usage and audit logs relating to the security and operation of the platform

Information our customers upload

Customers upload asset registers, lease schedules and related accounting records. These sometimes contain personal information, such as the name of an employee assigned to an asset. We process this only as described in section 2.

Sensitive information

We do not seek to collect sensitive information, and the platform is not designed to hold it. Where we do receive it, we use it only for the purpose it was provided, with your consent, or where the law requires it.

Information from other sources

We sometimes receive information from implementation partners, accounting software integrations you authorise, referral sources and publicly available business directories. Where we do, we take reasonable steps to make you aware of it.

4. Why we use your information, and our lawful basis

Australian privacy law does not require a stated lawful basis, but UK and EU law does. The table below applies to individuals in the UK and EEA, and describes our purposes generally for everyone else.

What we doWhyLawful basis (UK/EU)
Respond to enquiries, demo requests and pricing requestsTo answer you and discuss whether our software suits youLegitimate interests, and steps taken at your request prior to entering a contract
Provide the platform, manage accounts, deliver supportTo perform our agreement with you or your organisationPerformance of a contract, and legitimate interests where the contract is with your employer
Billing, invoicing and collectionsTo take payment and keep accurate financial recordsPerformance of a contract, and legal obligation
Send product updates and marketing about AssetAccountantTo keep prospective and existing customers informed about our own servicesLegitimate interests, or consent where required by law
Security, fraud prevention, audit loggingTo keep the platform and customer data safeLegitimate interests, and legal obligation
Analytics and improving the website and productTo understand what works and what does notConsent for non-essential cookies, otherwise legitimate interests
Meeting tax, accounting and regulatory obligationsBecause we are required toLegal obligation

Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can ask us for the details of that assessment at any time.

5. Marketing

We send marketing about our own software to people who have enquired, requested a demo or pricing, started a trial, or subscribed. We do not sell your information, and we do not share it with other organisations for their marketing.

You can opt out at any time using the unsubscribe link in any email or by contacting privacy@asset.accountant. We action opt-outs promptly and keep a minimal suppression record so that we do not contact you again by mistake.

6. Who we share your information with

We share personal information with the following categories of recipient, and only the minimum necessary:

  • Cloud hosting and infrastructure providers
  • Payment and subscription billing providers
  • Customer relationship management, support desk and email delivery providers
  • Analytics and website tooling providers
  • Professional advisers, including accountants, auditors and lawyers
  • Regulators, law enforcement or courts, where we are required or authorised by law
  • An acquirer or successor, in connection with a merger, acquisition or sale of assets

A current list of the sub-processors we use to deliver the platform is available on request from privacy@asset.accountant.

7. Where your information is held

AssetAccountant is an Australian company. Our platform and business systems are hosted on Microsoft Azure in the Australia East region. Some of our service providers operate in other countries, including the United States.

If you are in the United Kingdom or the EEA, this means your information is transferred outside your home jurisdiction. Australia is not the subject of an adequacy decision by the UK Government or the European Commission. We therefore rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we carry out transfer risk assessments to confirm the protection is adequate in practice.

You can request a copy of the safeguards we have in place by emailing privacy@asset.accountant.

8. How long we keep your information

InformationRetention period
Enquiries that do not become customersReviewed every 24 months. Records with no engagement in that period are deleted or de-identified unless there is a continuing business reason to keep them
Marketing contact recordsUntil you opt out or the review above removes them, then a minimal suppression record kept indefinitely so we do not contact you again
Customer account and platform dataFor the term of the subscription, then deleted or returned in line with the customer agreement
Billing and financial records7 years, as required by Australian tax law
Support correspondence[CONFIRM: 24 months] after the ticket is closed
Security and audit logs[CONFIRM: 12 months]

When information is no longer needed, we delete it or permanently de-identify it.

9. Security

AssetAccountant is ISO 27001 certified. We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls on a least-privilege basis, logging and monitoring, and regular review of our providers.

No system is completely secure. If a breach occurs that is likely to result in serious harm or a risk to your rights, we will notify the relevant regulator and, where required, notify you. In Australia this is the Office of the Australian Information Commissioner. In the UK and EEA, notification to the supervisory authority is made within 72 hours where the threshold is met.

10. Cookies and analytics

Our website uses cookies and similar technologies. Strictly necessary cookies keep the site working and cannot be switched off. We also use analytics and marketing cookies to understand how the site is used and to measure our campaigns.

You can control cookies through your browser settings, including blocking or deleting them, though some parts of the site may not work as intended if you do. We are implementing a consent tool for visitors in the United Kingdom and the European Economic Area, through which non-essential cookies will be set only with your consent.

11. Your rights

Everyone

You can ask for access to the personal information we hold about you and ask us to correct it if it is wrong. We will not charge for an access request, though we may charge a reasonable administrative fee for providing a copy. We may ask you to verify your identity before we release information.

Additional rights for individuals in the UK and EEA

If the UK GDPR or EU GDPR applies to you, you also have the right to:

  • Have your information erased in certain circumstances
  • Restrict how we use your information
  • Receive your information in a portable, machine-readable format
  • Object to processing based on our legitimate interests, and to object to direct marketing at any time
  • Withdraw consent at any time, where we rely on consent
  • Not be subject to a decision based solely on automated processing that produces legal or similarly significant effects. We do not carry out such decision-making

To exercise any of these, email privacy@asset.accountant or contact our representative DataRep as set out in section 1. We respond within one month, and will tell you if we need longer because the request is complex.

12. Complaints

If you are unhappy with how we have handled your information, contact us first at privacy@asset.accountant so we can try to resolve it.

You can also complain to a regulator:

  • Australia - Office of the Australian Information Commissioner, oaic.gov.au
  • United Kingdom - Information Commissioner's Office, ico.org.uk
  • European Economic Area - the supervisory authority in the country where you live or work

13. Children

AssetAccountant is business software. It is not directed at children and we do not knowingly collect information from anyone under 16.

14. Changes to this policy

We may update this policy from time to time. The current version is always at asset.accountant/privacy-policy, and the date at the top shows when it last changed. Where a change is significant, we will tell you.

15. Contact us

Privacy enquiries, requests and complaints: privacy@asset.accountant
General enquiries: info@asset.accountant
Postal: [CONFIRM: registered address]