Data flow and processing locations
Distinguish Australian storage, overseas AI processing, local conversion and identity capture.
Source reviewed Security and privacy documentation
The Privacy Policy describes documents and account data stored at rest in Australia and our own processing services in Sydney. Some external processing happens overseas. Use the product-specific route below when assessing your practice's data.
Workpapers
Loading diagram…
Diagram source
flowchart TB
accTitle: Workpapers data flow
accDescr: Original files stay in Australian private storage. Supported outbound text and file copies pass identifier controls before configured AI processing overseas; delivered work still needs accountant review.
U[Practice: authorised upload]
H[Practice: accountant review]
subgraph AU[Australia: source evidence]
S[(Private source files)]
R[Document recognition]
G[Outbound identifier controls]
end
subgraph External[External AI: location depends on provider]
AI[Configured analysis, build and review stages]
end
subgraph Delivery[Australia: workpaper process]
W[Build, review and delivery policy]
O[(Delivered workbook)]
end
U --> S --> R --> G
S -->|Supported file copies| G
G -->|Processed text, context and copies| AI
AI -->|Stage results| W
W --> O --> H
class G,W controlThis is the Workpapers route at a boundary level, not a network trace. The outbound controls differ between text and file formats; they do not make all remaining case information anonymous. Review may be disabled or degraded, and delivery can include outstanding findings. See AI processing and human review.
Our own recognition and identifier-removal services run in Australia. Before outbound AI processing, supported text and source files pass the relevant identifier controls. Case context, recognised text and processed source files can be provided to the configured AI services. The accountant's original source file remains a practice record; the outbound copy has a different purpose.
The policy names possible AI processing in the United States and China. Provider choice can vary by stage and practice configuration. Ask which providers apply to your practice; do not infer that from an old model name or the location of the worker that makes the request.
Other products
| Flow | File or content processing | What can be stored |
|---|---|---|
| Clients and client files | Authorised client/practice upload and preview | Client records and filed documents |
| Outlook | Mail is read from the member's connected Microsoft mailbox | Envelope index; a stored file when mail or attachments are explicitly or automatically filed |
| Sign | PDF stored for the request and signed through the request-specific page | Source/signed PDF, request state and signing events |
| Verify | The person provides ID images and biometric captures directly to Didit in the EU | BeforeMay's result summary and due-diligence records; not those biometric images |
| BAS Review | CSV transaction rows parsed in the browser | Client/period, filename, aggregate figures, counts and decisions keyed by hashed finding identifiers |
| Sift | Digital PDF conversion in the browser | The conversion keeps the work in browser memory; you download the result |
| Cloak | Digital PDF detection/redaction locally; a separate Australian OCR route for scans | Check the selected route's notice and API arrangement |
Providers and analytics
The policy's provider table includes infrastructure, AI, payments, email, identity and analytics providers. That table is the maintained list of processing purposes and locations; a service listed there is not necessarily used for every task.
Analytics are separate from document processing. The policy describes product identifiers and page/error information that analytics can receive, and states that client documents and their contents are not supplied to analytics. Optional third-party sign-in and mailbox connections have their own provider interaction.
Verify's distinct boundary
Loading diagram…
Diagram source
flowchart TB
accTitle: Verify identity evidence boundary
accDescr: The person gives ID images, selfie and liveness captures directly to Didit in the EU. BeforeMay stores a result summary and due-diligence records for the practice to assess.
P[Person opens a Verify request] --> N[Identity notice and consent]
N --> D[Didit: identity capture and check in the EU]
D -->|Result summary| B[(BeforeMay check record)]
B --> F[Practice assesses and records due diligence]
D --- I[ID images and biometric captures stay with Didit]
class N controlThe connector receives a provider notification and re-reads the result using its server credentials. The summary route above does not carry the ID images, selfie or liveness video into BeforeMay's private storage.
Workpapers' AI redaction does not apply to ID evidence a person gives directly to Didit: the provider needs to read the document to perform the check. Read the identity notice before asking a client to proceed. See Verify and the identity-specific section of the Privacy Policy.