Ledrix Privacy Policy

Effective date: 7 August 2026 Last updated: 7 August 2026

Ledrix is committed to handling personal information responsibly. This Privacy Policy explains how the operator of the Ledrix platform (Ledrix, we, us or our) collects, uses, holds and discloses personal information when you use our website, platform and related migration services (Services).

This policy is intended to meet the requirements of the Australian Privacy Principles in the Privacy Act 1988 (Cth), where they apply. It should be read with our Terms of Use at https://ledrix.com.au/terms.

1. Personal information we collect

The personal information we collect depends on how you use Ledrix. It may include:

  • identity and contact details, such as name, email address, phone number, job title and organisation;
  • account and access information, such as user ID, role, organisation membership, invitations, authentication data and login activity;
  • client and business information, such as business name, ABN, addresses, contacts, accounting-system identifiers and migration details;
  • information accessed from a connected accounting platform, which may include contact details, transaction and invoice data, payroll-related information, employee information, bank-account details, tax data, attachments and other accounting records within the permissions you authorise;
  • migration and workflow information, such as data-quality findings, mapping decisions, approvals, exception notes, messages, verification results and audit history;
  • support communications and feedback; and
  • technical information, such as IP address, browser and device information, log data, cookies and service usage.

We do not intentionally collect sensitive information unless it is included in data you or an authorised connected platform provides to us. For example, accounting attachments or payroll records may contain sensitive information. Please do not provide more personal information than is necessary for the Services.

2. How we collect personal information

We collect personal information directly from you when you create an account, contact us, request a quote, accept a migration, make a decision or use the Services.

We also collect it from organisations that authorise your access, such as your accounting practice or client business, and from third-party platforms you connect or authorise us to access, including accounting platforms. We may collect technical information automatically through the website and platform.

If you provide another person’s information, you must have authority to do so and, where required, tell them about this policy.

3. Why we use personal information

We use personal information to:

  • provide, administer, secure, support and improve the Services;
  • authenticate users and apply access controls;
  • connect to authorised third-party platforms and perform agreed preflight, migration, verification and support activities;
  • communicate about accounts, service requests, migrations, approvals, changes and support;
  • detect, investigate and prevent fraud, security incidents, misuse and unauthorised access;
  • comply with legal, regulatory, tax, record-keeping and professional obligations;
  • analyse service performance and develop improvements using de-identified or aggregated information where practical; and
  • with your consent where consent is required, send marketing communications. You may opt out at any time.

We do not sell personal information. We do not use accounting-platform data for advertising or to train public artificial-intelligence models.

4. Legal basis and authority

Depending on the circumstances, we handle personal information because it is necessary to provide the Services, comply with law, protect legitimate business and security interests, or because you or the relevant organisation has consented or otherwise authorised the handling.

When a practice, business or other organisation gives you access to Ledrix, it is responsible for ensuring the relevant authority and notices are in place. You are responsible for acting only within the authority and role assigned to you.

5. Cookies and analytics

We may use cookies and similar technologies to keep you signed in, protect the Services, remember preferences, understand usage and improve performance. You can control cookies through your browser settings, although some functions may not work properly if cookies are disabled.

6. Who we disclose personal information to

We may disclose personal information to:

  • your organisation, its authorised users and people you invite or authorise to participate in a migration;
  • accounting platforms and other integrations you authorise, but only as needed to provide the Services;
  • our hosting, database, cloud infrastructure, authentication, security, communication, payment, professional-advice and support providers;
  • our employees, contractors and professional advisers who need the information to provide or support the Services and are subject to appropriate confidentiality obligations;
  • government authorities, regulators, courts, law-enforcement agencies and other parties where required or permitted by law; and
  • a purchaser, successor or adviser in connection with a business restructure, sale or transfer, subject to appropriate safeguards.

We do not disclose personal information to unrelated third parties for their own direct-marketing purposes.

7. Overseas disclosure and processing

Our service providers may store or process information outside Australia, including where a cloud, security, communication or accounting-platform provider operates internationally. The countries involved can change as providers’ infrastructure changes.

Before using a service provider, we take reasonable steps to assess its security and privacy practices and to put appropriate contractual and technical safeguards in place. However, overseas recipients may be subject to foreign laws. By using the Services or authorising an integration, you acknowledge that overseas processing may occur as described in this policy.

8. Security and retention

We use reasonable technical, organisational and administrative safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These measures may include encryption in transit, encrypted credential storage, role-based access controls, audit logs, authentication controls and restricted personnel access.

No system or internet transmission is completely secure. You should protect your account credentials, use strong passwords and promptly notify us of suspected unauthorised access.

We retain personal information only for as long as reasonably necessary to provide the Services, meet legal and record-keeping requirements, resolve disputes and enforce agreements. When information is no longer required, we will take reasonable steps to delete it or de-identify it, subject to backup cycles, legal requirements and active migration records.

9. Access, correction and deletion requests

You may ask for access to, or correction of, personal information we hold about you. You may also ask us to delete personal information where appropriate. Requests can be sent to hello@ledrix.com.au.

We may need to verify your identity and authority before responding. We will respond within a reasonable time and, where we cannot comply with a request, explain why as required by law. Some information may need to be retained for legal, security, audit, contractual or legitimate operational reasons.

If you are a user of a client organisation or accounting practice, some requests may need to be handled with that organisation because it controls the relevant account or migration record.

10. Data breaches

If we become aware of a suspected eligible data breach, we will investigate promptly and take appropriate steps to contain and remediate it. Where required by the Privacy Act 1988 (Cth), we will notify affected individuals and the Office of the Australian Information Commissioner.

11. Complaints

If you have a privacy concern or complaint, contact us at hello@ledrix.com.au with details of the issue. We will investigate and respond within a reasonable time.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at [oaic.gov.au](https://www.oaic.gov.au) or by phone on 1300 363 992.

12. Changes to this policy

We may update this policy from time to time. The current version will be published at https://ledrix.com.au/privacy with its effective date. If we make a material change, we will use reasonable efforts to give notice through the Services or by email where practical.

13. Contact and operator details

Operator: Axiak Pty Ltd ABN: 14 146 366 850 Address: 31 Carrington Road Londonderry NSW 2753 Privacy contact: hello@ledrix.com.au