Privacy Policy
How Fedix collects, uses, and protects your information
Last updated: 11 July 2026
Tax7 R&D Pty Ltd (ABN 28 677 982 544), the owner and operator of the business names Fedix and MyLedger ("Fedix", "we", "us", or "our") is committed to protecting your privacy and handling your personal information in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Information We Collect
- We collect information you provide directly, such as your name, email address, practice details, and payment information when you register for or use our services.
- We automatically collect certain technical information when you visit our website or use our platform, including IP address, browser type, device information, and usage data.
- Third-party personal information. When you use MyLedger or our Practice Manager tools to service your own clients, you provide us with personal information about those clients. This includes their names and contact details, their financial affairs (bank statements, transaction records, income and deductions), identity documents, and their Tax File Numbers (see section 5). We collect and hold this information on your behalf, for the sole purpose of providing the Services to you. You are responsible for ensuring you have the authority and consent to provide it to us.
2. How We Use Your Information
- To provide, maintain, and improve our services, including MyLedger, FediDoc, and our Practice Manager tools.
- To communicate with you about your account, service updates, and support requests.
- To process payments and manage your subscription.
- To provide AI-assisted features, including document OCR, transaction categorisation, working-paper generation, and the AI Copilot. This involves disclosing content to third-party AI providers - see section 4.
- We do not use identifiable client financial data to train our own AI models.
- To comply with legal obligations, including Australian tax and financial reporting requirements.
3. Data Storage and Security
- Your data is stored at rest in Australian data centres. Where we use third-party AI providers to process your data (see section 4, 'AI Processing of Your Data'), that processing may occur outside Australia.
- Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in accordance with the Australian Privacy Principles, including through contractual data-protection obligations.
- We use AES-256 encryption for data at rest and TLS 1.3 for data in transit.
- Access to personal and financial data is strictly controlled through role-based access controls and multi-factor authentication.
4. AI Processing of Your Data
- Fedix uses artificial intelligence to deliver core parts of the Services: optical character recognition (OCR) of bank statements, receipts and other documents; transaction categorisation; working-paper and report generation; the AI Copilot; and, where you use them, meeting transcription and voice features.
- To do this, we disclose content to third-party AI providers. That content can include client names, transaction narratives, amounts, and the contents of documents you upload. The provider processes the content and returns a result to us.
- The AI providers we currently use are OpenAI and Anthropic (located in the United States) and Mistral AI (based in France, which provides our document OCR and processes documents in the European Union). These providers are located outside Australia, and personal information we disclose to them is processed overseas. Before disclosing personal information overseas we take reasonable steps to ensure the recipient handles it in accordance with the Australian Privacy Principles.
- Because OCR works by reading a document in full before any specific detail on it can be located, it is not technically possible to hide or remove a Tax File Number, bank account number or other personal detail from a document before it is sent to our OCR provider. Where a document you upload shows such details, they are disclosed to the OCR provider as part of reading the document, and the extracted text may then be processed by the other AI providers named above. See section 5 for how this applies to Tax File Numbers.
- We do not use identifiable client financial data to train our own models. We are working to put zero-data-retention and no-training terms in place with each AI provider; until those are agreed, you should assume our providers' standard API terms apply.
- AI outputs are suggestions only. You remain responsible for reviewing and verifying them before relying on them for professional purposes.
5. Tax File Numbers
- We collect and hold your clients' Tax File Numbers (TFNs) through our ATO integration, where you use it.
- TFN information is protected under the Privacy (Tax File Number) Rule 2015, issued under section 17 of the Privacy Act 1988 (Cth), in addition to the Australian Privacy Principles.
- We collect TFN information only for the purpose of providing the ATO-related Services you use, and we do not use a TFN to establish or confirm identity for any other purpose.
- TFNs are stored encrypted and are subject to role-based access controls. Access is logged.
- We destroy or de-identify TFN information when it is no longer required by law or for the purpose for which it was collected.
- Where a Tax File Number appears on a document you upload (for example a scanned notice of assessment or payment summary), that document is sent to our OCR provider to be read, and it is not technically possible to remove the TFN before the document is read. In that circumstance your TFN is disclosed to the OCR provider (located overseas) as part of processing your document. We use OCR and AI providers only on paid business terms and, where such terms are available, require them not to train on your data or retain it beyond what is needed to perform the service.
6. Data Sharing and Disclosure
- We do not sell, rent, or trade your personal information to third parties.
- We disclose content to third-party AI providers in order to deliver AI-assisted features - see section 4.
- We may share data with trusted service providers who assist in operating our platform (e.g., cloud hosting, payment processing), subject to contractual confidentiality and data-protection obligations.
- We may disclose information when required by law, regulation, or legal process, including requests from the Australian Taxation Office (ATO).
- If you use integrations (e.g., Xero, Open Banking), data is shared with those services only as authorised by you.
7. Your Rights
- Under Australian Privacy Principle 12 you may request access to the personal information we hold about you. Under Australian Privacy Principle 13 you may ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.
- Australian privacy law does not give a general right to have personal information erased. We will, however, destroy or de-identify personal information when it is no longer needed for any purpose for which it may be used or disclosed, and we are not required by law to retain it (see section 8).
- You can opt out of marketing communications by clicking the unsubscribe link in any email or contacting us directly.
- To exercise any of these rights, contact us at privacy@fedix.com.au. We will respond within a reasonable period, and within 30 days for an access request.
8. Data Retention
- We retain your personal information for as long as your account is active or as needed to provide you with our services.
- Financial data processed through MyLedger is retained in accordance with Australian record-keeping requirements (generally 5-7 years).
- When data is no longer required, and we are not required by law to retain it, it is securely deleted or anonymised.
9. Cookies and Tracking
- We use cookies and similar technologies to improve your browsing experience, analyse site traffic, and understand usage patterns.
- You can control cookie preferences through your browser settings. Disabling cookies may affect the functionality of our website.
- We use Google Analytics with IP anonymisation enabled. Google is located overseas and may process this data outside Australia.
10. Changes to This Policy
- We may update this Privacy Policy from time to time.
- We will notify you by email at least 30 days before any material change takes effect. If you do not accept it, you may terminate without penalty before it takes effect.
11. Complaints
- If you believe we have breached the Australian Privacy Principles, the Privacy (Tax File Number) Rule 2015, or otherwise mishandled your personal information, you can complain to us at privacy@fedix.com.au. Please describe the issue and how you would like it resolved.
- We will acknowledge your complaint within 5 business days and aim to respond substantively within 30 days. If we need longer, we will tell you why and agree a new timeframe with you.
- If you are not satisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC): oaic.gov.au, or by phone on 1300 363 992.
12. Data Breaches
- We are subject to the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).
- If we become aware of a data breach, we will assess it promptly. Where a breach is likely to result in serious harm to any individual whose personal information is involved, and we cannot prevent that harm through remedial action, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
- If the breach affects personal information you have provided to us about your own clients, we will notify you so that you can meet your own obligations.
13. Contact Us
- If you have questions about this Privacy Policy or our data practices, please contact us:
- Email: privacy@fedix.com.au
- Phone: 02 8065 1116
- Address: Sydney, NSW 2000, Australia