How Eziar handles information
Eziar is accounting software for Australian practices. Practices use it to read their clients' documents, check their books and prepare their BAS and workpapers. This policy says what information we collect on this website and in the Eziar service, what we do with it, where it goes, and how to ask us about it.
1. Who we are
Eziar ("we") operates the website at eziar.com and the Eziar service at app.eziar.com. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. This website
You can read eziar.com without giving us any personal information.
- The early-access form. If you ask for early access, we collect what you type: your name, your practice, your work email, your practice's size, the software you use and your message. We use it only to reply to you and to set up early access if you go ahead. We do not add you to a mailing list.
- The notice to us. When you send the form, the details reach us as an email sent through Resend, our email provider, which handles them only to deliver that email.
- Server logs. The site is served by Cloudflare, which records the usual connection details (your IP address, browser and the pages requested) for security and to keep the site running. We use Cloudflare Turnstile on the form to keep bots out.
- Cookies. We do not use advertising or tracking cookies on this site. Cloudflare may set a cookie needed for security. We do not run analytics that identify you.
3. The Eziar service
When an accounting practice uses Eziar, the practice decides what goes in. Most of the information in Eziar is about the practice's clients and belongs to the practice. We process it to provide the service and on the practice's instructions.
What the service holds
- Practice users. Names, work email addresses, the sign-in codes we send, and a record of what each person did in Eziar.
- Client records. Business names, contact names and email addresses for the people a practice asks questions of, and the questions and answers themselves.
- Documents. Invoices, receipts, statements and other files sent to the practice through Eziar, and what Eziar read from them.
- Ledger data. Transactions, accounts and contacts read from the practice's accounting software (today, Xero) with the practice's authorisation, and the entries Eziar prepares from them.
How the service uses it
- To read documents, code entries, run checks and prepare BAS and workpapers for the practice to review.
- To send questions and document requests to a practice's clients, in the practice's name, when the practice approves them.
- To write entries to the practice's accounting software only when a person at the practice approves the write.
- To keep a record of every change, who made it and when, so the practice's file explains itself later.
4. AI providers
Eziar uses AI models to read documents, match them to transactions and draft entries and questions. To do that, the content of documents and the related ledger data are sent to the model provider configured for the practice. Today those providers are Anthropic and OpenAI, under their commercial API terms, which do not use the data to train their models. Providers may process the data outside Australia, including in the United States.
The checks that decide whether an entry passes (GST, duplicates, capital items, wages, super, supplier registration) are rules written by Eziar, not decisions made by a model.
5. Where information is stored
The service runs on Cloudflare's infrastructure. Documents and data are encrypted in transit and at rest. Cloudflare may store or process data in locations outside Australia. Backups are kept to restore the service and are deleted on the same schedule as the data they copy.
6. Who can see it
- People at the practice, according to the access the practice gives them.
- A practice's client sees only what the practice sends to them and what they send back.
- Eziar staff, only when needed to run the service, to help a practice at its request, or to investigate a problem, and under a duty of confidence.
- Our providers named above (Cloudflare, Resend for the website's email notices, the AI providers, and the accounting software the practice connects), each only for the part of the service they provide.
We do not sell information, and we do not use a practice's or a client's information for advertising.
7. How long we keep it
We keep a practice's information for as long as the practice uses Eziar, and for a short period afterwards so the practice can export it. A practice can ask us to delete its information sooner. Server logs are kept for a limited time for security.
8. If you are a client of a practice
If your accountant uses Eziar, your accountant is responsible for how your information is handled, and we act on their instructions. Questions about your information are best put to your accountant first. You can also write to us.
9. Security
- Signing in uses a code sent to your email address; there are no passwords to steal.
- Links sent to clients are unique, expire, and work only from the message they were sent in.
- Every change is recorded. Nothing is posted to accounting software, and nothing is sent to a client, without a person's approval.
- Access to systems is limited to the people who need it, and is reviewed.
10. Your rights
You can ask us what information we hold about you, ask us to correct it, or ask us to delete it. Write to [email protected]. We answer within 30 days. If you are not satisfied with our answer, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au).
11. Changes
When this policy changes, the date at the top changes with it, and practices using Eziar are told. The current version is always at eziar.com/privacy.
Eziar · [email protected] · Australia