Privacy Policy
Last Updated: October 2026 • Compliant with the Privacy Act 1988 (Cth) (Australian Privacy Principles) and the Privacy Act 2020 (NZ).
Our Foundational Promise: Zero Permanent Retention of Financial Ledgers
ColdLedger does not maintain a permanent secondary database of your accounting ledgers, invoices, payroll entries, or customer lists. We operate as an ephemeral processing pipeline. We authenticate via official MYOB OAuth 2.0, extract your authorized data over encrypted channels, compile your offline standalone vault (.zip), deliver it directly to your device, and purge temporary processing artifacts within 48 hours.
1About ColdLedger & Scope of this Policy
ColdLedger ("we", "us", or "our") provides automated data extraction, formatting, and offline statutory archiving tools for businesses and accounting practices using MYOB in Australia and New Zealand.
This Privacy Policy explains what information we collect, how we process it, the measures we take to protect your confidentiality, and how we comply with the Australian Privacy Principles (APPs) and New Zealand Information Privacy Principles (IPPs).
2Categories of Information We Collect
A. Account & Waitlist Registration Information
When you register your interest or create an account, we collect your full name, business email address, practice or company name, role (e.g. Accountant, CFO, Business Owner), estimated company file count, and communication preferences. This data is used solely to coordinate invitations, provide customer service, and administer billing.
B. MYOB OAuth 2.0 Credentials & Tokens
To access your company files, we utilize MYOB's official OAuth 2.0 authorization framework. We receive scoped access and refresh tokens. We never see or store your raw MYOB account passwords. Tokens are encrypted at rest using AES-256 and used solely to facilitate the extraction session you explicitly trigger.
C. Financial Ledger & Document Data (Ephemeral Processing Only)
During an active extraction job, our pipeline ingests General Ledger accounts, Trial Balances, transaction journals, tax codes, contact records, and In-Tray binary attachments requested for your archive. This data is processed in memory and encrypted scratch volumes solely to assemble your offline vault.
3How Financial Data is Processed & Purged
We adhere strictly to data minimization and ephemeral processing standards:
- No Training on Your Data: We never train machine learning models, algorithms, or artificial intelligence on your company's financial records or client data.
- Automated Purge Schedule: Once your vault ZIP archive is compiled, it is held in a private encrypted staging bucket for download. Staging files are permanently deleted automatically after 48 hours, or immediately upon user request.
- No Secondary Aggregation: We do not sell, rent, monetize, or broker financial data to data brokers, insurers, lenders, or marketing intermediaries.
4Data Security & Sovereignty
We enforce multi-layered bank-grade security protocols:
Australian & NZ Hosting
Processing servers and staging environments are hosted in high-security, ISO 27001-certified data centres located in Sydney, Australia.
TLS 1.3 & AES-256
All data in transit is encrypted using modern TLS 1.3 ciphers. All temporary staging storage uses AES-256 volume encryption.
5Third-Party Service Providers
We engage select trusted sub-processors strictly necessary to deliver the service:
- MYOB Technology Pty Ltd: For OAuth 2.0 identity federation and AccountRight / Essentials API extraction.
- Stripe, Inc.: For PCI-DSS Level 1 compliant payment processing. Your complete credit card number never touches our servers.
- Cloud Infrastructure Partners: Tier-1 cloud computing infrastructure located in Australia for running containerized extraction workers.
6Your Privacy Rights (Access, Correction & Deletion)
Under the Australian Privacy Act 1988 and the New Zealand Privacy Act 2020, you have the right to:
- Request a copy of the personal information we hold about you.
- Request correction of outdated or inaccurate personal information.
- Request permanent deletion of your waitlist record and account details.
- Lodge a complaint if you believe your privacy has been breached.
To exercise any of these rights, email our Privacy Officer directly at [email protected]. We respond to all requests within 10 business days.
7Contact Our Privacy Officer
ColdLedger Privacy Compliance Desk
Email: [email protected]
General Inquiries: [email protected]
Location: Sydney, New South Wales, Australia.