Privacy Policy

Effective date: 26 September 2026 | Version 1.1

Access Analytic Solutions Pty Ltd (ACN 091 625 697), trading as Access Analytic, provides AccessEXL. In this policy, Access Analytic, we, us and our refer to that company.

This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with AccessEXL and related websites, accounts, APIs, MCP services, integrations, support, sales and communications. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles, where they apply.

1. Our role in handling information

1.1 For account, billing, sales, website, security and support information, we generally decide why and how personal information is handled.

1.2 For personal information contained in a customer's workbook inputs, outputs or other Customer Data, the customer generally decides why and how that information is processed. We process it as the customer's service provider to deliver AccessEXL. If you have a request about personal information submitted by an AccessEXL customer, you may need to contact that customer directly.

1.3 AccessEXL is designed so the underlying Excel workbook remains in the customer's Microsoft SharePoint or OneDrive environment. However, values and other data from elements configured by the customer are transmitted to and from AccessEXL when the Service performs a request. Limited data may also be processed for security, diagnostics, support and legal compliance.

2. Personal information we collect

Depending on how you interact with us, we may collect:

  • Identity and contact information, such as name, business name, role, email address, telephone number and postal address.
  • Account and authentication information, such as user ID, organisation, account role, sign-in events, authentication tokens and information received from an identity provider. We do not store your Microsoft password.
  • Commercial and billing information, such as plan, subscription status, transaction records, billing contact and partial payment details supplied by a payment provider. We do not store full payment-card details.
  • Configuration and connection information, such as workbook and tenant identifiers, configured ranges and tables, permissions, endpoint details, integration settings, API keys and connection status.
  • Customer Data transmitted through the Service, which may include workbook input and output values, table rows, instructions, prompts and responses. Its contents are determined by the customer and may include personal information.
  • Technical, usage and diagnostic information, such as IP address, device and browser information, timestamps, request identifiers, API or MCP method, response status, execution duration, usage volume, error details and security events.
  • Support and communications information, including enquiries, call or meeting notes, tickets, attachments and feedback.
  • Marketing and preference information, such as event registrations, communication preferences, campaign interactions and publicly available professional information.
  • Cookies and similar technology information as described in section 8.

We do not ask customers to submit sensitive information unless it is necessary and lawful. Customers should avoid configuring sensitive information for access through AccessEXL unless they have assessed the risks and implemented appropriate controls.

3. How we collect personal information

We collect personal information:

  • directly from you when you register, subscribe, configure or use the Service, contact support, attend a demonstration or communicate with us;
  • from the AccessEXL customer or administrator that invites or manages you;
  • automatically from browsers, devices, APIs, MCP clients, logs, cookies and security tools when the Service is used;
  • from connected services at your or the customer's direction, including Microsoft and selected integration providers;
  • from payment, identity, analytics, communications and customer-management providers; and
  • from public professional sources and referrals where lawful.

Where lawful and practicable, you may interact with us anonymously or using a pseudonym, such as when making a general enquiry. We generally need accurate identity and business information to create and secure an AccessEXL account or provide contracted services.

4. Why we collect, hold, use and disclose information

We may handle personal information to:

  • provide, configure, authenticate, operate and administer AccessEXL;
  • execute authorised workbook requests and return configured outputs;
  • manage subscriptions, usage, billing, customer relationships and partner accounts;
  • provide support, diagnose issues and communicate service notices;
  • protect users, customers and the Service, including detecting misuse, fraud, vulnerabilities and security incidents;
  • monitor performance, analyse use and improve features, reliability and user experience;
  • conduct demonstrations, trials, research and product development using appropriately controlled information;
  • send relevant product and marketing communications where permitted, and honour opt-out preferences;
  • comply with law, respond to lawful requests, resolve disputes and enforce agreements; and
  • support a business transaction such as financing, restructuring, merger or sale, subject to appropriate confidentiality and legal safeguards.

We do not sell personal information. We do not use Customer Data to train a general-purpose AI model.

5. Disclosure to others

We may disclose personal information to:

  • the AccessEXL customer, account administrators and authorised Users associated with the relevant account;
  • service providers that support hosting, infrastructure, identity, monitoring, security, communications, customer management, support, billing, payment processing and professional advice;
  • Microsoft and other connected services where disclosure is necessary to perform the integration requested by the customer;
  • AI, automation or other third-party endpoints selected and configured by the customer. Information sent to those services is also governed by their terms and privacy policies;
  • our personnel, contractors and related entities who need the information and are subject to appropriate duties;
  • regulators, courts, law enforcement or other parties where required or authorised by law, or reasonably necessary to protect rights, safety or security; and
  • a proposed or actual purchaser, investor or adviser in connection with a business transaction, subject to appropriate protections.

A current list of material subprocessors used for Customer Data is available on request from info@accessanalytic.com.au.

6. Overseas handling

Some of our service providers or their support personnel may process or access personal information outside Australia. The countries involved depend on the providers and services selected by us or by the customer and may include the United States of America plus others we select from time-to-time.

Where required, we take reasonable steps to ensure overseas recipients handle personal information consistently with applicable Australian privacy requirements. Customers should also review the data-location and cross-border settings of Microsoft and any AI, automation or other service they connect to AccessEXL.

7. Security and data retention

7.1 We use reasonable technical and organisational safeguards designed to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, encryption in transit and at rest where appropriate, logging, monitoring, backups, secure development practices and personnel controls. No method of transmission or storage is completely secure.

7.2 Customers are responsible for the security of their Microsoft tenant, workbooks, endpoints, integrations and credentials, and for configuring only the access required.

7.3 We retain personal information only for as long as reasonably required for the purposes described in this policy, to provide the Service, meet contractual obligations, resolve disputes and satisfy legal, accounting and security requirements. Retention periods vary by data type.

7.4 Following account closure, Customer Data held by us is deleted or de-identified after 30 days, subject to legal obligations, active investigations and standard backup cycles. Workbook activity log entries (a record of which API calls were made against a connected workbook, and when) are retained for 30 days for Individual accounts and 1 year for Business accounts. Other diagnostic and security logs are retained for 30 days. Billing and transaction records may be retained for the period required by taxation and corporate laws. The customer's underlying workbook remains in its Microsoft environment. We do not store any Customer workbooks.

7.5 When personal information is no longer required, we take reasonable steps to destroy it or de-identify it, subject to lawful retention requirements.

8. Cookies, analytics and communications

8.1 Our websites and Service use necessary cookies and similar technologies for sign-in, security, preferences and core functionality. With your permission, we also use non-necessary cookies for analytics (to understand use and improve the Service) and to run the enquiry and contact forms embedded on some pages, which are provided by a third-party form and customer-relationship- management provider.

8.2 The cookie notice shown when you first visit lets you Accept All non-necessary cookies or reject them. Necessary cookies remain active regardless, because they support sign-in, security, preferences and core functionality. Non-necessary cookies, including those used by the enquiry and contact form embeds, are not set until you accept. You can change your choice at any time using the "Cookie preferences" link in the site footer, or control cookies through your browser settings, but blocking necessary cookies may prevent parts of the Service from working.

8.3 We may send operational communications needed to administer the Service. We may send marketing communications where permitted by law. You can opt out of marketing using the unsubscribe link or by contacting us. Opting out of marketing does not stop essential account, security, billing or service messages.

9. Access and correction

You may request access to personal information we hold about you or ask us to correct it by contacting the Privacy Officer using the details below. We may need to verify your identity. We will respond within a reasonable period and will explain any lawful reason for refusing or limiting a request. We do not charge for making a request, although in limited circumstances we may charge reasonable costs of providing access where permitted by law.

If the information forms part of Customer Data controlled by an AccessEXL customer, we may refer the request to that customer or assist it to respond.

10. Privacy complaints

If you believe we have mishandled personal information, contact our Privacy Officer with details of your concern. We will acknowledge the complaint, investigate it and aim to provide a response within 30 days. If the matter is complex, we will explain any expected delay.

If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au. You may also have rights to contact another privacy or data protection regulator.

11. Data breaches

We maintain processes for responding to suspected data breaches. Where the Notifiable Data Breaches scheme or another applicable law requires notification, we will notify the Office of the Australian Information Commissioner, affected individuals and/or relevant customers as required. We may also contact you with practical steps to reduce harm.

12. Third-party services and links

AccessEXL may connect to or link to services we do not control. Their handling of personal information is governed by their own terms and privacy policies. Customers should assess those services before enabling them and should not assume that AccessEXL's safeguards or this policy apply once information is disclosed to a customer-selected third party.

13. Children

AccessEXL is a business service and is not directed to children. Users must be at least 18 years old. If we learn that we collected a child's personal information contrary to this policy, we will take reasonable steps to delete it.

14. Changes to this policy

We may update this Privacy Policy as our practices, providers or legal obligations change. We will publish the updated version with a new effective date. If a change is material, we will provide additional notice where reasonable, such as by email or an in-product message.

15. Contact us

Privacy Officer
Access Analytic Solutions Pty Ltd (ACN 091 625 697)
Suite 143, Level 1, 580 Hay Street
Perth WA 6000, Australia
Email: info@accessanalytic.com.au
Phone: +61 8 6210 8500