Security & Data Protection Statement
Last Updated: August 2026
This statement is written for the IT, risk, and compliance reviewers of accounting firms evaluating SyncMate. It describes exactly who can access client data, how that data is protected, where it is hosted, which third parties are involved, and what we do and do not claim. It is maintained by WYHEN Pty Ltd (ABN 57 688 078 999), the Australian company that operates SyncMate.
To save a copy, use . For a signed copy on letterhead, or a subprocessor's audit report under NDA, email contact@wyhen.com.au.
1. Who can access your data
Every row of data in SyncMate belongs to a specific user and entity. Access is decided at the database layer on every single query, not in the screen code, so a bug in the interface cannot expose another firm's records.
- Your own staff: only the entities they have been invited to. A user who is not a member of an entity cannot read its documents, bills, statements, or advisor history, even with a direct link or an ID.
- Another SyncMate customer: nothing. There is no shared view, no pooled dataset, and no cross-customer benchmarking.
- WYHEN staff: no routine access to your documents or ledger data. Administrative access exists for break-glass support and is used only at your request.
- AI providers: only the content of the document being processed, at the moment it is processed. No training, no retention for model improvement.
- Xero: only what you choose to publish, at the moment you press publish. You can revoke SyncMate's Xero access at any time from Xero itself.
- Nobody else. We do not sell data, do not share it with advertisers or data brokers, and do not pool it across customers for any purpose.
2. How the data is protected
- Database-enforced access rules: Row-Level Security is enabled on every user-data table. Policies scope each row to its owner or to explicit account members, evaluated by the database on every read and write.
- Uploaded files: bills and bank statements are held inside the same access-controlled store as the records they belong to, subject to the same rules — not in a public bucket.
- Xero connection: OAuth 2.0. SyncMate never sees or stores a Xero password. Access and refresh tokens are stored server-side, scoped to the individual user, and never exposed to the browser.
- Encryption in transit: TLS 1.2 or higher on every connection between your browser, SyncMate, and any connected system.
- Encryption at rest: AES-256 managed disk encryption on the underlying database.
- Authentication: Xero OAuth or email and password. Anonymous accounts are disabled. Sessions are short-lived and refreshed against the server.
- Payment data: SyncMate never sees or stores card numbers or bank login credentials. Stripe holds those; we hold only a token.
- Security contact: contact@wyhen.com.au, acknowledged within one business day. If a breach affecting your data occurs, we will notify you promptly and cooperate with your obligations under the Notifiable Data Breaches scheme.
3. AI processing and our no-training commitment
SyncMate uses enterprise API endpoints from OpenAI and Google to read uploaded documents. Under both providers' published API terms, content submitted through these paid endpoints is not used to train or improve their models. SyncMate does not build, train, or fine-tune any model of its own on customer data.
A human reviews and approves every extracted document before anything reaches Xero. The AI proposes; your staff decide. Nothing is posted to your ledger automatically.
4. Certification — stated honestly
WYHEN Pty Ltd is not itself SOC 2 or ISO 27001 certified, and we will not claim otherwise. What we can tell you is that SyncMate holds no customer data outside independently audited platforms — the database and authentication layer, the application hosting, the payment processor, and the AI providers each maintain their own SOC 2 Type II and/or ISO 27001 programs, with reports available under NDA on request.
We make no claim to formal GDPR or HIPAA certification. Our practices align with the Australian Privacy Principles under the Privacy Act 1988 (Cth) and with the data-minimisation, purpose-limitation, and deletion-on-request principles of the GDPR.
5. Subprocessors
Each subprocessor below is bound by its own published terms and security program.
- Supabase — database, authentication, file storage. SOC 2 Type II; hosted on AWS.
- Cloudflare — application hosting, edge compute, DNS. SOC 2 Type II and ISO 27001.
- Lovable — application platform and AI request gateway.
- OpenAI — model inference. SOC 2 Type II; no training on API submissions.
- Google (Gemini API, paid tier) — model inference. ISO 27001 and SOC 2; no training on paid API submissions.
- Stripe — payments and direct debit. PCI DSS Level 1, SOC 2 Type II.
- Xero — your accounting system, connected only with your OAuth authorisation.
6. Where your data is held
We state this precisely because reviewers check it. The SyncMate database runs on AWS in the Asia Pacific (Singapore) region. The application itself is served from a global edge network, and AI processing runs in the providers' own regions. Data is therefore stored and processed outside Australia.
WYHEN is an Australian company bound by the Privacy Act 1988 (Cth). Cross-border disclosure is disclosed here as the Act requires, and each provider is contractually bound to protections equivalent to the Australian Privacy Principles. Firms accept this arrangement routinely; the greater risk would be implying that data never leaves Australia. If Australian data residency is a hard requirement for your firm, tell us — migration to the AWS Sydney region is technically straightforward and we will scope it.
7. What SyncMate holds — and never holds
- Held: uploaded bills, receipts, and bank statements; the fields extracted from them; your Xero organisation names, chart of accounts, and tax rates; your account, entity, and user records.
- Never held: bank login credentials, card numbers, your Xero password, or any data belonging to another SyncMate customer.
- Bank statements: uploaded by you as files. SyncMate has no bank feed and no connection to your bank.
8. Retention, export, backup, and exit
- Ownership: you own everything you upload and everything extracted from it.
- Export: extracted transactions can be exported as CSV from within the app at any time, without asking us.
- Backups: the database is backed up by the platform provider with point-in-time recovery; backups inherit the same encryption and access controls.
- Disconnecting Xero: revoking access stops further sync immediately. Data already in your workspace remains until you ask for it to be deleted.
- Deletion: email contact@wyhen.com.au to have your account and its data permanently deleted, subject only to overriding statutory record-keeping obligations.
9. Data Processing Agreement
A DPA covering scope of processing, the subprocessor list, security measures, audit rights, breach notification, and return of data on termination is available for review or execution.
To have a copy countersigned by WYHEN, email it to contact@wyhen.com.au and we will return an executed version.
10. Questions and reporting
Security questionnaires, requests for a subprocessor's SOC 2 or ISO 27001 report under NDA, and suspected vulnerabilities all go to contact@wyhen.com.au. We acknowledge within one business day.