Last updated: August, 2026 | Version 2.0
AssetAccountant is online software that manages fixed and leased assets for accounting and taxation purposes. This policy explains what personal information we collect, why we collect it, who we share it with, and what rights you have over it.
It applies to everyone we deal with, and includes dedicated sections for individuals in the United Kingdom and the European Economic Area whose information is protected by the UK GDPR and EU GDPR.
AssetAccountant Pty Ltd (ABN 73 631 508 051) is the entity responsible for the personal information covered by this policy, including for all customers invoiced in the United Kingdom and the European Economic Area. For the purposes of the UK GDPR and EU GDPR, AssetAccountant Pty Ltd is the data controller.
AssetAccountant Inc is our United States entity and contracts with customers in the United States.
You can reach us about anything in this policy at privacy@asset.accountant.
AssetAccountant Pty Ltd has appointed DataRep as its Data Protection Representative under Article 27 of the UK GDPR and Article 27 of the EU GDPR. DataRep is a company incorporated in Ireland, registered address 12 Northbrook Road, Dublin, D06 E8W5, Ireland, company number 616588.
If you are in the United Kingdom or the European Economic Area, you can contact DataRep about the personal information we hold about you:
When writing by post, address your letter to "DataRep" and not to AssetAccountant, or it may not reach them. Please refer clearly to AssetAccountant Pty Ltd in your correspondence.
These contact details are for data protection requests from individuals and authorities in the UK and EEA only. For all other enquiries, please contact us at privacy@asset.accountant.
This distinction matters, because different rules apply.
We are a controller for information we decide how to use ourselves. That covers website visitors, enquiries, marketing, account administration, billing and support.
We are a processor for the asset, lease and finance data our customers load into the AssetAccountant platform. That data belongs to the customer, we handle it only on their documented instructions, and the customer is the controller. If your employer or accountant uses AssetAccountant and you want to know how your information is handled inside the platform, contact them first. We will support them in responding to you.
Our processing of customer data is governed by our customer agreement and, where required, a Data Processing Agreement. A copy is available on request from privacy@asset.accountant.
Customers upload asset registers, lease schedules and related accounting records. These sometimes contain personal information, such as the name of an employee assigned to an asset. We process this only as described in section 2.
We do not seek to collect sensitive information, and the platform is not designed to hold it. Where we do receive it, we use it only for the purpose it was provided, with your consent, or where the law requires it.
We sometimes receive information from implementation partners, accounting software integrations you authorise, referral sources and publicly available business directories. Where we do, we take reasonable steps to make you aware of it.
Australian privacy law does not require a stated lawful basis, but UK and EU law does. The table below applies to individuals in the UK and EEA, and describes our purposes generally for everyone else.
| What we do | Why | Lawful basis (UK/EU) |
|---|---|---|
| Respond to enquiries, demo requests and pricing requests | To answer you and discuss whether our software suits you | Legitimate interests, and steps taken at your request prior to entering a contract |
| Provide the platform, manage accounts, deliver support | To perform our agreement with you or your organisation | Performance of a contract, and legitimate interests where the contract is with your employer |
| Billing, invoicing and collections | To take payment and keep accurate financial records | Performance of a contract, and legal obligation |
| Send product updates and marketing about AssetAccountant | To keep prospective and existing customers informed about our own services | Legitimate interests, or consent where required by law |
| Security, fraud prevention, audit logging | To keep the platform and customer data safe | Legitimate interests, and legal obligation |
| Analytics and improving the website and product | To understand what works and what does not | Consent for non-essential cookies, otherwise legitimate interests |
| Meeting tax, accounting and regulatory obligations | Because we are required to | Legal obligation |
Where we rely on legitimate interests, we have considered whether our interest is outweighed by your rights. You can ask us for the details of that assessment at any time.
We send marketing about our own software to people who have enquired, requested a demo or pricing, started a trial, or subscribed. We do not sell your information, and we do not share it with other organisations for their marketing.
You can opt out at any time using the unsubscribe link in any email or by contacting privacy@asset.accountant. We action opt-outs promptly and keep a minimal suppression record so that we do not contact you again by mistake.
We share personal information with the following categories of recipient, and only the minimum necessary:
A current list of the sub-processors we use to deliver the platform is available on request from privacy@asset.accountant.
AssetAccountant is an Australian company. Our platform and business systems are hosted on Microsoft Azure in the Australia East region. Some of our service providers operate in other countries, including the United States.
If you are in the United Kingdom or the EEA, this means your information is transferred outside your home jurisdiction. Australia is not the subject of an adequacy decision by the UK Government or the European Commission. We therefore rely on the European Commission's Standard Contractual Clauses, together with the UK International Data Transfer Addendum where the UK GDPR applies, and we carry out transfer risk assessments to confirm the protection is adequate in practice.
You can request a copy of the safeguards we have in place by emailing privacy@asset.accountant.
| Information | Retention period |
|---|---|
| Enquiries that do not become customers | Reviewed every 24 months. Records with no engagement in that period are deleted or de-identified unless there is a continuing business reason to keep them |
| Marketing contact records | Until you opt out or the review above removes them, then a minimal suppression record kept indefinitely so we do not contact you again |
| Customer account and platform data | For the term of the subscription, then deleted or returned in line with the customer agreement |
| Billing and financial records | 7 years, as required by Australian tax law |
| Support correspondence | [CONFIRM: 24 months] after the ticket is closed |
| Security and audit logs | [CONFIRM: 12 months] |
When information is no longer needed, we delete it or permanently de-identify it.
AssetAccountant is ISO 27001 certified. We maintain technical and organisational measures appropriate to the risk, including encryption in transit and at rest, access controls on a least-privilege basis, logging and monitoring, and regular review of our providers.
No system is completely secure. If a breach occurs that is likely to result in serious harm or a risk to your rights, we will notify the relevant regulator and, where required, notify you. In Australia this is the Office of the Australian Information Commissioner. In the UK and EEA, notification to the supervisory authority is made within 72 hours where the threshold is met.
Our website uses cookies and similar technologies. Strictly necessary cookies keep the site working and cannot be switched off. We also use analytics and marketing cookies to understand how the site is used and to measure our campaigns.
You can control cookies through your browser settings, including blocking or deleting them, though some parts of the site may not work as intended if you do. We are implementing a consent tool for visitors in the United Kingdom and the European Economic Area, through which non-essential cookies will be set only with your consent.
You can ask for access to the personal information we hold about you and ask us to correct it if it is wrong. We will not charge for an access request, though we may charge a reasonable administrative fee for providing a copy. We may ask you to verify your identity before we release information.
If the UK GDPR or EU GDPR applies to you, you also have the right to:
To exercise any of these, email privacy@asset.accountant or contact our representative DataRep as set out in section 1. We respond within one month, and will tell you if we need longer because the request is complex.
If you are unhappy with how we have handled your information, contact us first at privacy@asset.accountant so we can try to resolve it.
You can also complain to a regulator:
AssetAccountant is business software. It is not directed at children and we do not knowingly collect information from anyone under 16.
We may update this policy from time to time. The current version is always at asset.accountant/privacy-policy, and the date at the top shows when it last changed. Where a change is significant, we will tell you.
Privacy enquiries, requests and complaints: privacy@asset.accountant
General enquiries: info@asset.accountant
Postal: [CONFIRM: registered address]