01
Who we are
“Mushin”, “we”, “us” and “our” means Jesse Thomas Jenkins trading as Mushin Automation (ABN 21 848 052 726), a business in Sydney, NSW. Questions about this policy go to privacy@mushin.com.au.
02
What we collect
Four kinds of information, and nothing bought from a list:
- Audit start form details. Firm name, your name, work email, how many trust account audits the firm does a year, which bank the trust account is with, and anything you add. With it, the time of submission, your browser string and the referring page.
- Website review form details.Firm name, the firm's website address, its suburb, your name and email, and as with the start form, the time of submission, your browser string and the referring page. The suburb decides which local search the review checks. The review itself looks only at what the firm publishes publicly: its website, its Google Business Profile and public search results. It needs no logins and no access to anything private.
- Trust account documents.During an engagement, the documents uploaded through the per-audit link: an agent's reconciliation reports, trial balances, cash books, ledgers, journals and bank statements. These contain personal information about tenants, landlords, buyers and sellers who are not our clients and not yours; we treat all of it as confidential.
- Website analytics. Anonymised usage information (pages visited, referrer, approximate location) through Google Analytics and Vercel Web Analytics.
03
How we use it
- To send you the per-audit secure upload link and to run the engagement you asked for.
- To write the website review you asked for and email it to you.
- To produce the working papers and deliver them back to you.
- To answer questions about an engagement, and to tell you about material changes to this policy or to how your files are handled.
- To understand how the website performs.
We do not sell personal information, and we do not use trust account documents for anything other than the engagement they were uploaded for. In particular, they are not used to train any model, ours or anyone else's.
04
Trust account documents
This section is the same set of facts as the data-handling section of How it works, stated here so the two cannot drift.
- Where they are stored. Uploaded files are held and processed on Google Cloud in Sydney, Australia.
- What leaves Australia.One document per account-month, the reconciliation report, is sent to Anthropic's API in the United States so a model can read the balance figures printed on it. No bank statement, cash book, trial balance, ledger or journal is ever sent to a model or to any provider outside Australia.
- How long we keep them. Uploaded files, the generated CSVs and the run state are deleted 30 days after the working papers are delivered.
- Who else handles them. The sub-processors listed below, and no one else. Mushin is one person; there is no team and no offshore processing.
05
Sub-processors
Every provider that receives your files or your details, listed in full.
- Anthropic, PBC (United States). Model provider. Reads one document per account-month, the reconciliation report, to extract the five balance figures. Receives reconciliation reports only.
- Vercel Inc. (United States). Hosts this website. The audit start and website review forms pass through it in transit. Receives no trust account documents.
- Discord Inc. (United States). Notifications. Each form submission is posted to Mushin's own channel, so it holds what the form collected. Receives no trust account documents.
- Google Workspace (United States). Email. Carries correspondence, website reviews and the secure upload link, so it holds your name, firm and email address. Working papers are collected from the secure link, not sent as attachments. Receives no trust account documents.
- Google Analytics (United States). Website analytics only. Never sees a file or a form submission. Receives no trust account documents.
- Google Cloud (Sydney, Australia). Secure upload store and processing. Holds every uploaded file for the life of the engagement.
Anthropic's commercial API terms do not permit training on API inputs or outputs. Nothing about your engagement is used to improve a model.
07
Security
Upload links are per audit and are not reused. Files are transferred over encrypted connections and held with access limited to one person. Input files are never modified. No system is perfectly secure, and we do not claim otherwise; if we become aware of a breach affecting your documents we will tell you promptly and in writing.
08
Your rights
Under the Australian Privacy Principles, you can:
- Ask what personal information we hold about you.
- Ask us to correct it if it is wrong.
- Ask us to delete it, subject to any legal obligation to retain records.
- Make a privacy complaint. We will respond within a reasonable time.
Email privacy@mushin.com.au. If you are not satisfied with the response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.
10
Changes
If this policy changes, the “Last updated” date at the top changes with it. For a material change to how trust account documents are handled, current clients are told directly.
Questions about this page?
privacy@mushin.com.au