Privacy Policy

Effective 1 July 2025 Β· Last updated 29 April 2026 Β· Version 1.0

πŸ”’ Zero AI Training β€” Architectural Guarantee

Your Xero transaction data, financial figures, and emission calculations are never used to train, fine-tune, or improve any AI or machine learning model β€” by EcoLink or any third party. Our carbon accounting engine is 100% deterministic rule-based code, with no connection to any LLM or AI API.

1. Introduction

EcoLink Australia Pty Ltd (β€œEcoLink”) is committed to protecting your privacy. This policy complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

2. Xero Data (Read-Only)

Xero ScopeDataPurpose
accounting.banktransactions.readBank transactionsCarbon classification
accounting.invoices.readInvoices and billsSupplier identification
accounting.contacts.readSupplier namesMerchant routing
accounting.settings.readChart of accountsAccount name resolution

3. What We Do NOT Do

  • βœ—Use your data to train, fine-tune, or evaluate any AI or ML model
  • βœ—Sell, rent, or broker your data to any third party
  • βœ—Use your financial data for advertising or profiling
  • βœ—Share transaction data with other EcoLink customers
  • βœ—Store Xero OAuth tokens in plain text (AES-256-GCM encrypted)

4. Security

Encryption in transit

TLS 1.3

OAuth tokens

AES-256-GCM at rest

Storage bucket

Private β€” signed URLs (5 min TTL)

Database

Row-Level Security on all tables

Reports retention

7 years (ASIC obligations)

Xero tokens on disconnect

Deleted immediately

5. Your Rights (APPs)

Under the Privacy Act 1988, you may access, correct, or request deletion of your personal information. Contact: privacy@ecolink.com.au. For unresolved complaints: Office of the Australian Information Commissioner (OAIC).

Β© 2026 EcoLink Australia Pty LtdTerms of Service β†’