Privacy, Security and Cookies

Effective: 1 September 2026 · Version: 2026-09-01

This one document covers three things that are often kept apart: how we handle personal information, how we secure it, and what our website stores on your device. It applies to AutoRemit, operated by Rehab on the Move Pty Ltd (ABN 47 643 094 697), Suite 1, 845 Pacific Highway, Chatswood NSW 2067.

We handle personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth), and we apply them whether or not the Act requires it of a business our size.

Privacy contact: [email protected].

1. The short version

2. Two different roles

The distinction below determines who is answerable for what, so it is worth reading once.

Your own information — your name, work email, role, and your organisation's billing details. We decide how this is handled, and this document governs it.

What you upload — remittance documents and the data drawn from them. That content is yours. We hold and process it on your instructions, to do the job you asked for. You decide what to upload, what to post to your accounting system, and when to delete it. Where that content contains information about other people, you are the one answerable to them for it, and you are responsible for having a lawful basis to give it to us.

3. What we collect

From you, directly: your name, work email, hashed password, multi-factor authentication settings, workspace and role; your organisation's name and billing contact; and anything you send us by email or in support conversations.

From your accounting system, with your authorisation: open invoices and credit notes with their numbers, amounts, dates and contact names; your bank account list; your base currency; and the payment records we write back. The connection is scoped to those permissions. Payroll and employee records are outside that scope and we cannot reach them.

From the documents you send us: remittance advices, uploaded or forwarded by email, kept as you sent them so that every payment we recorded can be audited against the document it came from. Alongside them we keep what we extracted — invoice numbers, amounts, dates, references and payer names — and the match, allocation and posting decisions made against them.

Automatically: IP address, browser and device details, pages visited, and application logs. We use these to run the Service, investigate faults and detect abuse.

Payment details: card payments are handled by Stripe. We never see or store full card numbers.

4. Sensitive information

A remittance holds whatever is printed on it. In NDIS plan management and allied health — which is a significant part of who uses AutoRemit — that can include a participant's name alongside service descriptions, support categories or provider types, from which health or disability information can be inferred. That is sensitive information under the Privacy Act and it carries a higher standard.

We do not ask for it, and AutoRemit does not need it to work. It arrives because it is on the page. So we treat it the way we treat everything else in a remittance: stored as sent, visible only inside your workspace, never used for anything except the matching job, and deleted on the schedule in section 9.

If you upload documents containing sensitive information, you are responsible for having the consent or other lawful basis that the Privacy Act requires for that collection.

5. Why we use it

To run the Service and meet our contract with you: accounts, extraction, matching, posting, support and billing.

To keep it working and keep it safe: fault diagnosis, abuse prevention, security monitoring, and improving accuracy.

To meet legal obligations: tax, accounting, and lawful requests properly made.

To contact you: service and security notices, which you cannot opt out of while you hold an account, and marketing, which you can — see section 11.

We do not use the contents of your remittances for product analytics, marketing, or any purpose other than performing the Service for you.

6. Who we share it with

We do not sell personal information and we do not disclose it for anyone else's marketing.

We use a small number of providers to run AutoRemit. Each is bound by contract to protect the information and use it only to provide their service to us.

Your accounting system is not on this list. Xero is your provider, not ours; we connect to it on your authorisation and your relationship with them is governed by your agreement with them.

We may also disclose information to our professional advisers, where the law requires it, or to a purchaser if we sell the business — in which case this document continues to apply until you are told otherwise.

We keep this table current. Where we add or change a provider that handles customer data, we will update it and give notice of material changes.

7. Where your data is held

In Australia: your database, the remittance documents you upload, and all backups are held on infrastructure in Sydney. Backups replicate to Australian object storage. Inbound and outbound service email is delivered by Amazon SES running in the AWS Sydney region. AI document extraction runs through Amazon Bedrock using an Australian geographic inference profile, with inference confined to AWS regions in Australia. Nothing about your account, your invoices, your matches or your posting history is stored outside Australia.

Other providers: some separate services — subscription billing and the public marketing website — may process limited account, billing or website information outside Australia, as set out in section 6. Those services sit outside AutoRemit’s remittance-processing path and do not receive your remittance documents.

Under Australian Privacy Principle 8 we remain accountable for personal information we disclose to overseas recipients. That obligation applies to those ancillary billing and website providers, not to remittance processing. We take reasonable steps to ensure they handle personal information consistently with the APPs, including contractual commitments, encryption in transit, and limiting what is sent to what the task requires.

If your own compliance obligations require something different, contact us and we will work through the specifics.

8. Security

Isolation. Every workspace is separated from every other. All application queries are scoped to the workspace of the signed-in user, and there is no interface through which one customer's data is reachable from another's session.

Access. Accounts support multi-factor authentication and we recommend enabling it. Access inside a workspace is governed by roles. Our own access is least-privilege, used only for support and operations, and payment-posting actions are logged.

Connections. We connect to your accounting system with OAuth tokens you authorise. We never see or store your accounting system password, and you can revoke the connection from your accounting system at any time.

Encryption. All traffic to and from AutoRemit is encrypted in transit using TLS. Your data, including the database and uploaded remittance documents, is stored on encrypted-at-rest infrastructure. Production data is held on DigitalOcean Block Storage encrypted with LUKS, and inbound email is held briefly in Amazon S3 with server-side encryption.

Backups and recovery. The database replicates continuously to Australian object storage, and restores are tested rather than assumed.

AI processing. Remittance document content is processed through Amazon Bedrock using an Australian geographic inference profile. AI inference is confined to Australian AWS regions and is used only to extract the information AutoRemit needs for the remittance-matching workflow. Amazon Bedrock does not use customer inputs or outputs to train or improve base AI models, and does not share them with third-party model providers.

Availability. We aim to keep AutoRemit available and will give notice of planned maintenance where we can. We do not offer a contractual uptime figure or service credits at current pricing.

Incidents. We monitor for problems and maintain a process to investigate and respond. See section 12 for what happens if a breach affects personal information.

Reporting a vulnerability. If you think you have found a security issue, email [email protected]. We welcome responsible disclosure, will confirm receipt, and will work with you on anything genuine. We will not pursue researchers who act in good faith and give us a reasonable chance to fix the issue first.

9. How long we keep things

Remittance documents and extracted data: for as long as your subscription is active, then deleted within 30 days of it ending. You can delete individual documents from your workspace before that.

Account and billing records: kept while your account is active, then for the period Australian tax and corporations law requires — generally seven years for financial records.

Logs: kept for a limited period for security and troubleshooting, then discarded.

Backups: expire on their own rolling cycle after deletion from the live system. Deleted data may persist in a backup for a short period before that cycle completes.

You can export your data from your workspace at any time while your subscription is active. Export before you cancel.

10. Cookies and website measurement

Two different surfaces, with different rules.

The signed-in application uses only what it needs to work: a session cookie to keep you signed in, and security cookies to protect the sign-in process. These are strictly necessary. Blocking them stops AutoRemit from functioning. No advertising or third-party tracking runs inside the application.

The public marketing website at autoremit.finance is hosted on Wix and uses cookies for the site to function and, where you consent, for traffic measurement. You can accept or decline non-essential cookies through the banner and change your mind at any time by reopening it.

You can also control cookies through your browser. Blocking strictly necessary cookies will break the application.

11. Marketing

We will send you service and security messages about your account for as long as you hold one — those are part of running the Service, not marketing.

Anything promotional is separate. We send it only where the Spam Act 2003 (Cth) permits, every message identifies us and carries a working unsubscribe link, and we act on unsubscribes promptly. Opting out of marketing does not affect your account or your service messages.

12. Data breaches

We are subject to the Notifiable Data Breaches scheme. If a breach involving personal information is likely to result in serious harm and we cannot prevent that harm, we will notify the Office of the Australian Information Commissioner and the individuals at risk, as quickly as the scheme requires.

Where a breach affects information you uploaded, we will tell you without undue delay and give you what you need to meet your own obligations — because for that content, the notification duty is generally yours, and you cannot discharge it without our facts.

13. Access, correction and complaints

You can ask us what personal information we hold about you, ask for a copy, and ask us to correct anything wrong. Email [email protected]. We will respond within 30 days, and if we refuse we will tell you why and how to challenge it.

Most of it you can do yourself: your profile, your workspace members, and your uploaded documents are all visible and editable inside AutoRemit.

If you are unhappy with how we have handled your privacy, tell us first — email the same address with "Privacy complaint" in the subject line and we will investigate and respond within 30 days. If you are still unsatisfied, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au or 1300 363 992.

If your concern is about a document your accounting or bookkeeping provider uploaded to their AutoRemit workspace, they hold that information and we will refer you to them, but tell us anyway and we will help you get to the right place.

14. Anonymity, and what we can't offer anonymously

APP 2 gives individuals the option of dealing with an organisation anonymously or under a pseudonym where that is lawful and practicable. For general enquiries, it is — you can ask us a question without identifying yourself. It is not practicable for an AutoRemit account, because the Service writes financial records into your accounting system and both you and we need an auditable record of who did that.

15. Children

AutoRemit is a business tool. It is not directed at children and we do not knowingly collect their personal information through it. A remittance may name a child as the person a service was provided to; that is content you have uploaded and is handled under sections 2 and 4, not collected by us from the child.

16. Changes

We may update this document. The version and effective date are at the top. For changes that materially affect how we handle personal information, we will give notice by email or in the product before they take effect, and we keep superseded versions.

17. Contact

[email protected]

Rehab on the Move Pty Ltd, Suite 1, 845 Pacific Highway, Chatswood NSW 2067

Rehab on the Move Pty Ltd · ABN 47 643 094 697 · trading as AutoRemit