Privacy policy

Effective Date: 1 July 2026

This Privacy Policy explains how ACMO Pty Ltd collects, holds, uses and discloses personal information when individuals interact with ACMO, visit our websites, documentation portal, API documentation, use our mobile applications, communicate with our team, or access the ACMO All-in-One Business Suite and related services.

01About ACMO and this policy

ACMO Pty Ltd (ABN 53 632 100 433) is an Australian business that develops and provides cloud-based software and related services for document-driven finance and operational processes, including Accounts Payable, Accounts Receivable, Procure-to-Pay, Supplier Management, workflow, document processing and integration services.

In this Privacy Policy:

  • ACMO, we, us and our mean ACMO Pty Ltd;
  • Customer means an organisation that purchases, subscribes to, evaluates or otherwise uses an ACMO product or service;
  • Customer Data means information, documents, records, images, files, instructions and other content submitted to, transmitted through, generated within or made available to the Services by or for a Customer;
  • personal information has the meaning given under applicable privacy law and generally means information or an opinion about an identified individual or an individual who is reasonably identifiable; and
  • Services means ACMO websites, documentation portals, mobile applications, demonstrations, trials, support services, APIs, integrations and the ACMO All-in-One Business Suite.

This policy is intended to support ACMO's obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Where ACMO handles personal information relating to individuals in New Zealand and the New Zealand Privacy Act 2020 applies, we also handle that information in accordance with applicable New Zealand privacy requirements.

02When ACMO acts for a Customer

ACMO handles some personal information for its own business purposes, such as information about website visitors, prospects, customer contacts, partners, authorised users, job applicants and suppliers.

When a Customer submits or connects Customer Data to the Services, the Customer generally determines why the information is processed, which information is submitted, who may access it, how workflows are configured and how results are used. In those circumstances, ACMO generally handles the personal information as a service provider to the Customer and in accordance with the applicable customer agreement, the Customer's instructions and applicable law.

If your personal information appears in Customer Data, for example because you are an employee, approver, supplier, customer, contractor or other business contact of an ACMO Customer, you should usually direct access, correction or privacy requests to that Customer first. ACMO will assist the Customer with appropriate requests as required by law and the customer agreement.

If there is any inconsistency between this policy and a customer agreement concerning Customer Data, the customer agreement applies to the extent of the inconsistency.

03Personal information we collect and hold

The personal information ACMO collects and holds depends on how you interact with us, the modules and features used by a Customer, and the information that a Customer chooses to submit or connect to the Services. It may include the following categories.

3.1 Identity and business contact information

  • name, business email address, telephone number, job title, employer, business address and professional profile information;
  • details provided through contact, demonstration, event, webinar, newsletter, support or partner forms; and
  • records of meetings, enquiries, correspondence, feedback and other interactions with ACMO.

3.2 Account, profile and access information

  • username, business email address, display name and profile details;
  • organisation, business unit, role, group, permissions, approval authority and account status;
  • authentication, invitation, password-reset and session information; and
  • records of account creation, changes, access, administrative actions and security events.

3.3 Commercial and relationship information

  • information relating to proposals, subscriptions, contracts, orders, billing, payments, renewals and support arrangements;
  • customer, partner, supplier and service-provider contact records; and
  • information required to manage onboarding, implementation, training, support, professional services and business relationships.

3.4 Technical, usage and security information

  • IP address, device type, browser, operating system, application version, language, time zone and network information;
  • dates and times of access, pages and features viewed, actions taken, search activity, downloads and interaction data;
  • system, diagnostic, integration, API, security and audit logs; and
  • cookie identifiers and similar online identifiers, where used.

3.5 Information processed through the ACMO All-in-One Business Suite

Depending on the Customer's subscribed modules, configuration and connected systems, Customer Data may contain personal information in or associated with:

  • supplier, customer, employee, contractor, approver and other business-contact records;
  • invoices, credit notes, purchase orders, requisitions, goods receipts, supplier statements, remittance advices, expense claims and supporting documents;
  • bank transaction, payment, account and remittance information used for reconciliation, validation or cash allocation;
  • master data, accounting dimensions, delegation-of-authority rules, workflow assignments and approval records;
  • comments, attachments, exception notes, dispute or query information and communications generated through a workflow;
  • document images and data extracted, classified, validated, matched, coded, routed or generated by the Services; and
  • audit trails showing user and system actions, decisions, recommendations, status changes and integration events.

3.6 Mobile application information

  • mobile device and application information, session and notification information;
  • documents, images or scans selected or captured for upload; and
  • permissions that you choose to enable, such as camera, photo-library or notification access, where required for a feature.

3.7 Recruitment information

  • employment history, qualifications, skills, work eligibility and professional interests;
  • curriculum vitae, cover letter, interview notes, references and background-check information where lawful and relevant; and
  • communications relating to current or future employment or contracting opportunities.

3.8 Sensitive information

ACMO does not ordinarily require sensitive information for general website enquiries or routine business communications. However, documents or support materials submitted by a Customer may incidentally contain sensitive information. ACMO will handle sensitive information only where authorised, reasonably necessary and permitted by applicable law. Customers and users should avoid submitting sensitive or unnecessary personal information unless it is required for an authorised business purpose and appropriate safeguards are in place.

04How we collect personal information

We may collect personal information:

  • directly from you when you complete a form, create or use an account, upload information, contact support, attend an event, communicate with us or apply for a role;
  • from the Customer organisation that employs, engages, invites or authorises you to use the Services;
  • from Customer administrators, colleagues, suppliers, customers, referral partners or other business contacts;
  • from systems and services connected by a Customer, including email accounts, ERP systems, procurement systems, identity providers, banking or payment data sources, file locations and APIs;
  • automatically when you use our websites, applications or Services, through logs, cookies, analytics and similar technologies;
  • from publicly available business sources and professional networking platforms where lawful and appropriate; and
  • from service providers, partners, events, referrals or recruitment providers.

Where practicable, you may browse public areas of our website and documentation portal without identifying yourself. We may need identifying information where it is necessary to respond to an enquiry, provide access, authenticate a user, deliver the Services, meet security requirements or comply with law.

05Why we collect, hold, use and disclose personal information

ACMO may collect, hold, use and disclose personal information for purposes including to:

  • respond to enquiries, arrange demonstrations, provide information and manage sales, customer, partner and supplier relationships;
  • create and administer accounts, authenticate users, manage roles and permissions, deliver notifications and provide access to the Services;
  • configure, implement, integrate, host, operate, support, maintain, monitor and improve the Services;
  • receive, classify, extract, validate, match, code, reconcile, route, approve, report on or otherwise process documents and business transactions at a Customer's direction;
  • provide workflow recommendations, confidence scores, anomaly indicators and other assisted or automated functionality described in section 6;
  • provide technical support, investigate incidents, troubleshoot issues and communicate service or security information;
  • protect the confidentiality, integrity, availability and lawful use of the Services, including detecting, preventing and responding to fraud, misuse, unauthorised access, security threats and technical problems;
  • administer subscriptions, billing, payments, renewals, service levels, contracts and professional services;
  • understand use of the Services, improve performance and user experience, develop features and produce de-identified or aggregated analytics;
  • send product, event, educational or business communications where permitted and manage communication preferences;
  • assess job applicants and manage recruitment, employment and contractor relationships;
  • comply with law, regulatory requirements, court orders and lawful government requests, and establish, exercise or defend legal rights; and
  • support a business sale, acquisition, restructure, financing or due-diligence process subject to appropriate confidentiality and legal safeguards.

We may also use or disclose personal information for a related purpose that you would reasonably expect, with your consent, or where otherwise required or authorised by law.

06Automated processing and AI-assisted functionality

The Services may use configurable business rules, optical character recognition, machine learning, artificial intelligence and other automated processing to support document-driven finance and operational workflows.

Depending on the modules and settings enabled by a Customer, this may include:

  • classifying documents and extracting header, line-item and related information;
  • validating data, identifying duplicates and checking information against master data or connected systems;
  • matching invoices, purchase orders, goods receipts, supplier statements, remittance information, bank transactions and other records;
  • suggesting general-ledger coding, cost distributions, approvers, matches or workflow actions;
  • producing confidence or probability scores, warnings, exceptions, fraud indicators or document-tampering indicators; and
  • routing, revalidating or completing eligible workflow tasks where a Customer has enabled automated or straight-through processing and configured the relevant rules, thresholds and controls.

Automated outputs may be recommendations, classifications, risk indicators or workflow actions. Their use depends on Customer configuration, connected data and business rules. Customers are responsible for deciding which processes may be automated, setting appropriate thresholds and review controls, maintaining accurate source data, and determining how outputs are used in their business decisions.

ACMO does not independently make a Customer's payment, procurement, employment, supplier-engagement or approval decisions. Where a Customer uses the Services in a way that could significantly affect an individual's rights or interests, the Customer is responsible for meeting applicable transparency, review and decision-making obligations. ACMO will provide reasonable assistance in accordance with the customer agreement and applicable law.

ACMO may use de-identified and aggregated system-level or usage information to operate, analyse, secure and improve the Services. This does not include readable Customer documents or business content and is designed not to identify a Customer or individual. More specific rights or restrictions in a customer agreement prevail.

07Cookies, analytics and online technologies

Our websites and online services may use cookies, tags, pixels, local storage and similar technologies. These technologies may be used to:

  • provide essential website and security functions;
  • remember preferences and improve usability;
  • understand website traffic, performance and how visitors interact with content;
  • measure campaigns and the effectiveness of business communications; and
  • protect forms and services from automated abuse or malicious activity.

Information collected may include online identifiers, IP address, device and browser information, referral source, pages visited, interactions and timestamps. Some technologies may be provided by third parties and may result in information being processed outside Australia.

You can manage cookies through available website preference tools and your browser settings. Blocking some cookies may affect website or service functionality. ACMO will configure tracking technologies with regard to data minimisation and will not intentionally use public website forms to collect sensitive information for advertising or unrelated profiling purposes.

08Direct marketing and business communications

ACMO may use business contact information to send information about products, events, webinars, resources, service updates or other matters that may be relevant to your role or organisation, where permitted by law and consistent with your communication preferences.

Marketing communications will provide a clear way to unsubscribe or opt out. You may also contact us at privacy@acmo.com.au. Opting out of marketing does not prevent ACMO from sending necessary service, security, account, support, billing or contractual communications.

ACMO does not use sensitive information for direct marketing without appropriate consent or another lawful basis.

09Who we may disclose personal information to

ACMO may disclose personal information to the following recipients where reasonably necessary for the purposes described in this policy:

  • the relevant Customer, its administrators, authorised users and nominated contacts;
  • ACMO personnel, related entities, contractors and authorised support or engineering personnel who require access for their role;
  • cloud hosting, infrastructure, identity, communications, CRM, support, analytics, security, payment, recruitment and other technology or business service providers;
  • implementation, integration, referral and technology partners where a Customer requests or authorises their involvement;
  • third-party products, systems or services connected or enabled by a Customer;
  • professional advisers, auditors, insurers and financial institutions;
  • government agencies, regulators, courts, tribunals, law-enforcement bodies or other recipients where required or authorised by law; and
  • a prospective or actual acquirer, investor or transaction adviser in connection with a corporate transaction, subject to appropriate safeguards.

We require service providers and authorised recipients to handle personal information consistently with applicable contractual, confidentiality, security and privacy obligations.

10Data hosting, overseas access and cross-border disclosure

ACMO's primary cloud infrastructure and operational footprint are based in Australia. Customer Data for production SaaS environments is hosted in Australia unless otherwise agreed in writing with the Customer.

Authorised ACMO personnel and service providers may access or process personal information from outside Australia where this is reasonably necessary to provide support, engineering, security, administration or other services. Countries in which overseas recipients are currently likely to be located include India and the United States. Website, communications and business systems may also use providers operating in those countries.

For New Zealand Customers and individuals, hosting or processing in Australia is a cross-border handling arrangement. ACMO takes reasonable steps to use contractual, access-control, confidentiality and security measures appropriate to the circumstances and to comply with applicable Australian and New Zealand cross-border privacy requirements.

Specific data residency, authorised access, subprocessor and cross-border arrangements for a Customer may be set out in the applicable customer agreement, security documentation or collection notice. ACMO may update the country list in this policy if its operational or service-provider arrangements change.

11Security of personal information

ACMO uses administrative, technical and organisational safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. Depending on the information and service, these safeguards may include:

  • role-based access controls and access limited to authorised personnel;
  • authentication, credential and session controls;
  • segregation of customer environments and environment-scoped integrations;
  • logging, audit trails, monitoring and incident-response procedures;
  • secure transmission, backup, recovery and vulnerability-management practices;
  • security reviews and testing; and
  • contractual confidentiality, security and privacy obligations for personnel and service providers.

No method of electronic transmission or storage is completely secure. Customers and users are also responsible for protecting their devices, networks, mailboxes, identity systems, integrations and credentials, assigning appropriate roles and permissions, and promptly reporting suspected unauthorised access or security incidents.

12Data retention, deletion and de-identification

ACMO retains personal information for as long as reasonably necessary for the purposes for which it was collected, to provide and support the Services, meet contractual commitments, maintain security and audit records, resolve disputes, enforce agreements and comply with legal, accounting and regulatory obligations.

Retention, export, return and deletion of Customer Data are governed by the applicable customer agreement and Customer instructions. Information may remain for a limited period in backups, logs or disaster-recovery systems and will be protected and removed or overwritten in accordance with applicable retention processes.

When personal information is no longer required and ACMO is not legally or contractually required to retain it, we will take reasonable steps to destroy it or de-identify it. De-identified and aggregated information that no longer identifies an individual may be retained for analytics, security, service improvement and business purposes.

13Access, correction and other privacy requests

You may request access to personal information ACMO holds about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Depending on applicable law and the circumstances, you may also ask us to consider deletion, restriction, objection or withdrawal of consent.

To make a request, contact privacy@acmo.com.au and provide enough information for us to identify you and the information concerned. We may need to verify your identity and authority before acting on a request. We will respond within the timeframe required by applicable law and will explain if an exception permits or requires us to refuse or limit a request.

Where your information is contained in Customer Data, we may refer the request to the relevant Customer or ask you to contact that Customer. If a correction request is not accepted, ACMO may record a statement of the requested correction where required by law.

ACMO will not ordinarily charge for making a privacy request. We may charge a reasonable amount for providing access where permitted by law and will notify you in advance.

14Privacy complaints

If you have a concern or complaint about how ACMO has handled personal information, contact our Privacy Officer using the details in section 19. Please describe the issue and provide relevant information so that we can investigate it.

We will acknowledge and investigate the complaint, consult relevant teams or Customers where necessary, and provide a response within a reasonable period and the timeframe required by law.

If you are not satisfied with our response, you may contact:

  • the Office of the Australian Information Commissioner, for matters governed by Australian privacy law; or
  • the Office of the Privacy Commissioner in New Zealand, for matters governed by New Zealand privacy law.

15Data breaches

ACMO maintains processes for identifying, containing, investigating and responding to suspected privacy and security incidents. Where a breach is likely to result in serious harm and notification is required, ACMO will notify the relevant regulator and affected individuals in accordance with applicable law.

Where an incident involves Customer Data, ACMO will notify and cooperate with the relevant Customer in accordance with the customer agreement and applicable law so that responsibilities, communications and notifications can be coordinated appropriately.

Our websites and documentation may contain links to third-party websites or services. The privacy practices of those third parties are governed by their own privacy policies, and ACMO is not responsible for third-party content or practices that it does not control.

When a Customer enables an integration or directs ACMO to exchange information with another system or provider, ACMO will process and disclose the relevant information as necessary to operate that integration. The Customer is responsible for assessing the third party, establishing any required contractual or legal basis, and determining whether the integration is appropriate for its information and users.

17Children and young people

The Services are designed for business and organisational use and are not directed to children. ACMO does not knowingly seek personal information from children through general website forms. If Customer Data contains information about a child or young person, the relevant Customer is responsible for ensuring that the collection and use is lawful and appropriate, and ACMO will process the information in accordance with the customer agreement and applicable law.

18Changes to this Privacy Policy

We may update this Privacy Policy to reflect changes to law, regulatory guidance, the Services, technology, service providers or our information-handling practices. The current version and effective date will be published on our website. Where a change is material, we will take reasonable steps to provide additional notice where appropriate.

19Contact ACMO

Privacy Officer

ACMO Pty Ltd
ABN 53 632 100 433
Level 2, 25 Ryde Road
Pymble NSW 2073
Australia

Email: privacy@acmo.com.au
Telephone: +61 (02) 9060 3760
Website: www.acmo.com.au