# Data Protection & Confidentiality Statement

**SyncMate — WYHEN Pty Ltd (ABN 57 688 078 999)**
Version 1.0 · Effective 31 August 2026 · Owner: Founder/Technical Operator · Review: annually

**This statement must be read and signed by every person — founder, employee, contractor or third party — before they are granted any access to SyncMate systems or customer data. No exceptions.**

## 1. What data we handle

SyncMate processes financial documents and data belonging to our customers and, where the customer is an accounting firm, to that firm's own clients. This includes invoices, receipts, bank statements, supplier and customer details, tax information and accounting ledger data, together with the personal data contained in those documents.

For this data WYHEN acts as a **Data Processor**: the customer is the Data Controller and decides what is uploaded and how it is used. WYHEN acts as Controller only in respect of its own account-holder data (customer staff names, email addresses and billing records).

## 2. My obligations

By signing, I acknowledge and agree that:

1. **Confidentiality.** All customer data, and all information about our customers' systems and clients, is confidential. I will not disclose it to any person outside WYHEN except as required to deliver the service or by law.
2. **Purpose limitation.** I will access and use customer data only where necessary to deliver, support or secure the service on the customer's instruction. I will not browse, explore or sample customer data out of curiosity or for any personal purpose.
3. **Support access.** Where I must access a customer's documents or transactions to resolve a specific support issue, I will access only what is necessary for that issue and I understand the access is recorded in the audit log.
4. **No unauthorised copies.** I will not copy, download, export, print, screenshot or transfer customer data to personal storage, personal accounts, removable media, or any tool or service not approved by WYHEN — including AI tools not part of the approved subprocessor list.
5. **No training or secondary use.** I will not use customer data to train, tune or evaluate any machine-learning model, and I will not use it for benchmarking, marketing or product analytics.
6. **Credentials.** I will authenticate only through the approved mechanism (Xero-based sign-in with two-step verification), will not share credentials, will store any secrets only in the approved password manager, and will never place credentials in source code, logs, chat or email.
7. **Device security.** Any device I use to access WYHEN systems will have full-disk encryption, an automatic screen lock, a current supported operating system with security updates applied, and no unapproved remote-access software.
8. **Incident reporting.** I will report any actual or suspected security incident, data exposure, lost device, phishing attempt or policy breach to the Founder immediately and no later than 4 hours after becoming aware of it. I understand WYHEN must notify affected customers within 24 hours.
9. **Privacy law.** I will comply with the Australian Privacy Act 1988 and the Australian Privacy Principles, and with the notification obligations of the Notifiable Data Breaches scheme, and — where a customer's data attracts it — with the GDPR or UK GDPR as applied through our customer agreements.
10. **Data-subject requests.** I will not action any request from an individual concerning customer client data. I will forward it to the Founder so it can be passed to the customer as Controller within two business days.
11. **Training.** I will complete the induction module before receiving access and the annual refresher and quarterly awareness updates thereafter.
12. **Printing.** Printing customer data is not part of any normal workflow. If ever necessary, printed material will be secured in a locked cabinet, never removed from the premises, and cross-cut shredded when no longer required, with disposal recorded.
13. **On departure.** On ending my engagement, or immediately on request, I will return or destroy all customer data and WYHEN information in my possession, surrender all credentials and access, and confirm this in writing.
14. **Survival.** These confidentiality obligations continue indefinitely after my engagement ends.

## 3. Consequences

Breach of this statement may result in immediate withdrawal of access, termination of engagement or employment, and legal action. Where a breach causes a notifiable data breach, WYHEN is required to notify the affected customer and, where applicable, the Office of the Australian Information Commissioner.

## 4. Acknowledgement

I have read and understood this statement and agree to be bound by it.

| Field | Entry |
|---|---|
| Full name | |
| Role | |
| Date access granted | |
| Signature | |
| Date signed | |

**Countersigned for WYHEN Pty Ltd**

| Field | Entry |
|---|---|
| Name | |
| Signature | |
| Date | |

---

*Signed record: the Founder/Technical Operator of WYHEN Pty Ltd has executed this statement as at the effective date. A copy of the executed statement is retained with the security documentation set and is available to customers as evidence on request.*
