For clients, prospective clients, representatives and other individuals
Entity : AIM S Australia Pty Ltd | ABN 21 159 602 276 | ACN 159 602 276
Trading names : AIM S Australia; AIMS Australia Tax Accountants
Professional status : Registered Tax Agent 24859230; CPA Public Practice; eligibility under the applicable CPA Australia Professional Standards Scheme confirmed by the firm, subject to ongoing scheme requirements
Contact: Level 30, 35 Collins Street, Melbourne VIC 3000 | 1300 11 24 67 | info@aimsaustralia.com.au | www.aimsaustralia.com.au
This schedule identifies the principal cloud and technology providers used by AIM S Australia Pty Ltd in delivering professional services. It supports transparent communication of provider purpose, information handled, likely geographic locations and safeguards. Provider infrastructure, subprocessors and account configurations may change. The firm reviews material changes and updates this schedule where reasonably required.
The listed arrangements are cloud or technology services. The firm does not currently outsource client professional work to an overseas contractor or external preparer. Account-specific provider configurations, subscriptions, access rights and data-region settings are maintained in the firm’s internal provider register and are reviewed periodically.
| Provider | Purpose | Information handled | Likely locations | Principal safeguards |
|---|---|---|---|---|
|
Seamless Ezy Onboard Pty Ltd trading as Seamless |
Client portal and onboarding; collection and exchange of client information and documents; identity-verification workflow where used. Information is stored as cloud-hosted portal records and uploaded files within the provider environment. | Identity/contact information, engagement information, documents, portal records and verification outcomes. Avoid retaining unnecessary identity-document copies. | Seamless represents that data hosting is in Australia. Provider personnel, integrations and subprocessors, including identity, messaging, support or development services, may access or process information from other locations unless the firm’s current contract confirms otherwise. | Restricted access; multifactor authentication where available; secure portal use; data minimisation; verification-related records; provider and integration review. |
|
Xero Tax Xero Australia Pty Limited for the Australian edition, subject to the firm’s current subscription terms |
Tax-return preparation, workpapers and schedules; electronic signatures and approvals; ATO lodgment and related practice workflow. Information is stored within the Xero cloud application, related logs, backups and authorised subprocessor environments. | Tax and identity information, TFNs, income and deduction records, returns, declarations, signatures, ATO communications and audit logs. | Xero and its subprocessors may process information in Australia, New Zealand, the United States and other locations identified in current Xero privacy, data-processing and subprocessor information. The precise locations may vary by service and subprocessor. | Role-based access; multifactor authentication; user and leaver controls; source verification; electronic approval records; provider security and incident terms; periodic access review. |
|
Dropbox Contracting Dropbox entity and configured data region under the firm account to be verified from current account records |
Document storage, synchronisation, controlled sharing, backup and retrieval. Information is stored in Dropbox cloud infrastructure and may also be synchronised to controlled firm devices if that feature is enabled. | Client source documents, correspondence, workpapers and metadata, potentially including TFN and sensitive information. | At-rest location depends on the firm’s plan and configured data region. Dropbox states storage servers are located in the United States and that Australia is available to eligible users, together with other listed regions. Support, metadata and subprocessors may involve other locations. | Firm-managed account; multifactor authentication where available; least privilege; controlled sharing; no public links; device controls; audit logs where available; retention/deletion and recovery controls; annual verification of the account plan and configured data region. |
| Provider | Purpose | Information handled | Likely locations | Principal safeguards |
|---|---|---|---|---|
|
Business email hosting service for @aimsaustralia.com.au |
Client and third-party communications, notifications and transfer of information where the secure portal is not required. Information is stored in hosted mailboxes and archives and may be downloaded to controlled firm devices. | Email addresses, messages, attachments, instructions, invoices and security metadata. | Email may be routed, filtered, stored, backed up or supported in Australia or overseas through internet infrastructure and provider subprocessors. The firm does not represent business email as an Australian-only service. Account-specific details are maintained in the internal provider register. | Business-domain email; multifactor authentication where available; anti-phishing controls; SPF/DKIM/DMARC where configured; restricted forwarding; secure portal for high-risk documents; independent verification of payment or bank-detail changes. |
| Unlisted technology service | Not approved to process identifiable client confidential information unless separately assessed and added to this schedule. | Public information or properly de-identified material only until approval. | Not applicable until assessed. | Provider, plan, data use, retention, access, training/use settings, security, subprocessors and locations must be assessed; competent human review required. |
Current position: none. AIM S Australia Pty Ltd does not currently use overseas contractors, offshore employees or external overseas preparers to perform client professional work. This statement does not mean that every cloud-provider employee or subprocessor is located in Australia; technology-provider access and processing are described above.
A material provider change, new country, new subprocessor, plan or data-region change, material security incident or new use of client confidential information triggers reassessment. The firm updates affected engagement or privacy disclosures where required.
This schedule should be read with: Terms of Engagement | Privacy Policy | Privacy Collection Notice | Professional and Regulatory Information