Trust & Security
Last Updated: July 2026
This page is maintained by WYHEN Pty Ltd (ABN 57 688 078 999) trading as SyncMate to answer the security, privacy, and data-handling questions we most often receive from accounting firms and their clients. It is app-owner-maintained editable content, not an independent third-party certification.
1. Your Client Data — In One Paragraph
The information you upload to SyncMate — bills, bank statements, supplier names, amounts, GST, tracking categories — is used only to (a) return the extracted result to you and (b) power your own private AI memory inside your workspace. It is not used to train any AI model, is not shared with other SyncMate users, and is not sold to third parties. SyncMate does not build, train, fine-tune, or maintain any proprietary AI model.
2. AI Processing — How Your Documents Are Read
SyncMate uses enterprise API endpoints from two AI providers to perform OCR and data extraction on your uploaded documents:
- OpenAI API: per OpenAI's published API data-usage policy, data submitted through the API is not used to train or improve OpenAI's models.
- Google Gemini API (Paid tier): per Google's published Gemini API terms, prompts, files, and responses submitted through the paid API are not used to improve Google's products.
- Routing: requests are sent to these providers through our platform provider's AI gateway. Client financial content (supplier names, invoice amounts, line items) is not used to train models.
- Storage of extracted results: the extracted fields are written back only into your own tenant, protected by Row-Level Security. Only you and members of your workspace can see them.
3. Hosting, Region, and Encryption
- Infrastructure: hosted on Supabase (Postgres, authentication, storage) and Cloudflare (edge compute).
- Region: AWS Asia-Pacific region.
- Encryption in transit: TLS 1.2 or higher on every connection between your browser, SyncMate, and connected third-party systems (Xero, payment providers).
- Encryption at rest: AES-256 via managed disk encryption on the underlying Supabase Postgres database.
- OAuth tokens: your Xero access and refresh tokens are stored server-side, scoped to your user, and never exposed to other users or to the browser.
4. Access Control & Multi-Tenant Isolation
- Sign-in: Xero OAuth 2.0 or email/password managed by Supabase Auth.
- Row-Level Security (RLS): enabled on every user-data table (documents, invoices, bank statements, business accounts, advisor memory). Every row is locked to the signed-in user who owns it, or to the specific team members invited to that workspace — the database itself enforces this, not just the app screens.
- Account membership: team access is gated by server-side membership checks; a user cannot read another workspace's data even if they know an ID.
- Sensitive server-only tables: promotion codes and other privileged rows are readable only by the server, never by the browser.
5. Subprocessors
SyncMate uses the following subprocessors to deliver the service. Each is bound by its own published terms and security program:
- Supabase — Postgres database, authentication, object storage.
- Cloudflare — hosting, edge compute, DNS.
- Lovable — application platform and AI request gateway.
- OpenAI — AI model inference (enterprise API, no training on submissions).
- Google (Gemini API, Paid tier) — AI model inference (no training on submissions).
- Xero — source accounting system, connected via customer-authorised OAuth.
- Stripe — card and Australian direct-debit payments. PCI DSS Level 1.
6. Data Ownership, Retention, and Deletion
- Ownership: you own the data you upload and everything extracted from it.
- Export: extracted transactions can be exported as CSV from within the app.
- Disconnect Xero: revoking Xero access immediately stops further sync. Historical extracted data remains in your workspace until you request deletion.
- Deletion on request: email contact@wyhen.com.au to request permanent deletion of your account and its data. We honour deletion requests subject to any overriding statutory record-keeping obligations (e.g., AML or tax law).
7. Compliance Posture
SyncMate is built on infrastructure and AI platforms that hold SOC 2 Type II and/or ISO 27001 certification — Supabase (database, authentication, storage), Cloudflare (hosting and edge compute), OpenAI and Google (AI inference). Infrastructure-layer controls are therefore covered by independently audited providers, and we layer our own access controls on top: per-tenant Row-Level Security, server-side team membership checks, and OAuth tokens scoped to a single user and never exposed to the browser.
Our own practices align with the Australian Privacy Principles (Privacy Act 1988 Cth) and with the data-minimisation, purpose-limitation, and deletion-on-request principles of GDPR. Copies of our providers' SOC 2 / ISO 27001 reports can be requested under NDA using the contact below.
8. Data Processing Agreement (DPA)
A downloadable DPA template is available for accounting firms and their clients to review or execute. It covers the scope of processing, subprocessor list, security measures, audit rights, breach notification, and data return on termination.
9. Security & Incident Contact
To report a suspected security issue, request a copy of a subprocessor's SOC 2 / ISO 27001 report under NDA, or ask any other security or privacy question, email contact@wyhen.com.au.
We aim to acknowledge security reports within one business day.