TECHNOLOGY, CLOUD AND PROVIDER SCHEDULE

Version-controlled provider disclosure supporting confidentiality, privacy and professional engagement requirements.

Legal entity AIM S AUSTRALIA PTY. LTD.
ABN / ACN ABN 21 159 602 276 | ACN 159 602 276
Trading names AIM S AUSTRALIA | AIMS Australia Tax Accountants
Registered Tax Agent number No. 24859230
Professional practice CPA Australia public practice; participation in the applicable CPA Australia Professional Standards Scheme, subject to continuing eligibility and Scheme terms
Principal place of business Level 30, 35 Collins Street, Melbourne VIC 3000 | 1300 11 24 67 | info@aimsaustralia.com.au | www.aimsaustralia.com.au
Contact 1300 11 24 67; info@aimsaustralia.com.au;
www.aimsaustralia.com.au

1. Purpose and status

Prospective-client document sharing for preliminary scoping. Before an engagement is accepted, AIMS may ask a prospective client to provide selected redacted documents through a restricted-access, client-controlled cloud folder or link, including Dropbox, Google Drive or Microsoft OneDrive. This is an intake/scoping channel, not authority for AIMS to commence substantive professional services or to treat the prospective client as having accepted the Provider Schedule for a later engagement.

At the preliminary stage, AIMS requests data minimisation: the prospective client should remove or mask TFNs, full dates of birth, bank/card details, login credentials, identity-document numbers and copies, and other information not reasonably necessary to assess scope. Shared links should be restricted to the intended AIMS recipient and should not be public. If AIMS later accepts the engagement, any provider use involving identifiable client-affairs information is governed by the accepted Engagement Letter, this Schedule and the applicable confidentiality/privacy framework.

This Schedule identifies the principal technology/cloud providers confirmed for AIMS’ standard professional-services workflow. It supports the disclosure and client-permission provisions in the Engagement Letter and Terms of Engagement and is designed to communicate provider, location and storage information relevant to APES 305 where applicable. It does not itself expand professional scope or constitute client permission.

Provider contracts, subprocessors, infrastructure and account configurations can change. AIMS maintains an internal provider due-diligence register and retains the version of this Schedule incorporated into or made available with an engagement. Where exact account-specific facts are not verified, this Schedule states the limitation rather than making an assumption.

2. Principal approved providers

Provider / service Principal AIMS use Information that may be processed Location / provider-position disclosure
Seamlss — Ezy Onboard Pty Ltd
ABN 75 644 225 945; ACN 644 225 945
Client onboarding, data collection, document exchange, identity/authority verification workflow, engagement acceptance/e-signing and related administration. Identity/contact information, engagement details, tax identifiers where required, uploaded records, verification information, correspondence and workflow metadata. Provider public materials state that personal data may be transferred to and stored in countries including Australia and New Zealand. Provider hosting/subprocessor arrangements may involve additional locations. AIMS does not represent Seamlss data as exclusively Australian-hosted unless account-specific evidence supports that statement.
Xero Tax / Xero Australian tax-return preparation, calculations, schedules, client declarations/e-signature where used, lodgment and tax-practice workflow. Taxpayer identity/contact data, TFNs and other tax identifiers where required, income/deduction/CGT and other taxation data, tax returns, schedules, declarations, ATO-related records and workflow metadata. Xero acts as a service provider/processor for subscriber-entered client data and publishes a current subprocessor list that includes entities in Australia, New Zealand, the United States, the United Kingdom, India, Singapore, Canada, South Africa and other locations as applicable to the services used. AIMS does not represent Xero processing as Australia-only and relies on current provider disclosures rather than a static exhaustive country list.
Google Workspace / Google
Applicable entity under AIMS’ account agreement
Business email, calendar/productivity and related communications used in operating the practice. Email addresses, correspondence, attachments and business/engagement metadata; sensitive documents may be restricted to nominated secure channels. Google operates global infrastructure and support/subprocessor arrangements. The applicable contracting or reseller entity is determined by AIMS’ actual account agreement and billing arrangement. AIMS does not represent Google Workspace information as stored or processed only in Australia unless an account-specific data-region configuration is verified.
Dropbox
Dropbox International Unlimited Company under the generally applicable terms for customers outside North America, subject to any account-specific agreement
Electronic document and working-paper storage, file sharing and secure collaboration. Client source documents, correspondence, workpapers, tax records, calculations, reports and other professional records stored in AIMS’ approved Dropbox team environment. AIMS’ account-specific Dropbox file-data-at-rest region has not yet been confirmed in writing. Dropbox states that storage servers are located in the United States and that additional storage servers are available in Australia, the European Union, Japan and the United Kingdom for eligible users. The selected server location concerns team file data while permanently at rest. AIMS therefore does not represent Dropbox file data, metadata, backups, support access or other processing as stored or processed only in Australia.
General-purpose AI tools
Restricted de-identified/public-information use only
General professional-support tasks such as research assistance, drafting, summarisation, issue spotting, document organisation, template development and quality-control assistance. A general-purpose AI service is not an AIMS system of record. Public information or information that has been appropriately de-identified, generalised and minimised so it is not identifiable or reasonably re-identifiable. Identifiable or reasonably re-identifiable client-affairs information is not submitted under AIMS’ standard policy. AI providers may process data in Australia and/or overseas depending on provider, account type, configuration, affiliates and subprocessors. Provider approval does not override AIMS’ de-identification rule. If material could still reasonably reveal or be linked to a client’s affairs, it must not be submitted.

Current provider information sources

 

These links are provided as current public sources and may change. AIMS’ internal provider due-diligence records and account-specific agreements/configurations prevail where they establish a different current fact.

3. Government and professional systems

AIMS also interacts with ATO and other government systems where authorised or required. Those disclosures arise under taxation law, client authority or another lawful basis and are not treated as discretionary technology-provider permission. AIMS may interact with the TPB, professional bodies, insurers, courts, tribunals or regulators where required or lawfully permitted.

4. Client permission under tax-practitioner confidentiality obligations

The client-specific Engagement Letter or another written authority contains the client permission required, where applicable, before AIMS discloses information relating to a client’s affairs to a third-party technology/cloud provider. The permission should identify the relevant provider or provider category, purpose, information involved and location information to the extent required and reasonably ascertainable.

This Schedule is a disclosure document and does not itself constitute consent or permission. AIMS obtains fresh or additional permission where a materially new provider, materially different professional outsourcing arrangement or materially different disclosure is not reasonably covered by the existing authority and fresh permission is required by law or professional standards.

5. No overseas professional preparation under the standard model

AIMS does not currently outsource client tax/accounting professional preparation or advice to overseas contractors under its standard service model. If that position changes, AIMS will address competence, supervision, professional responsibility, confidentiality, privacy, security, professional-indemnity, provider disclosure and client permission before client information is disclosed.

6. AI-enabled and unlisted technology

AIMS may use approved general-purpose artificial-intelligence-enabled tools only for general professional-support purposes, such as research assistance, drafting, summarisation, issue spotting, document organisation, template development and quality-control assistance. A general-purpose AI service is not an AIMS system of record and AI output is not a substitute for professional judgment; material output is subject to competent human review and verification before it is relied upon or communicated as professional work.

Under AIMS’ standard workflow, identifiable or reasonably re-identifiable client-affairs information is not submitted to a general-purpose AI service. Before any client-derived material is used with such a service, AIMS takes reasonable steps to remove, mask or generalise identifiers and to minimise the information so that the provider cannot reasonably associate it with a client or another individual. This includes, as applicable, names, TFNs, ABNs, dates of birth, addresses, contact details, bank details, identity documents, account or reference numbers, signatures, login credentials, property addresses and combinations of facts reasonably capable of re-identification.

De-identification does not displace Code item 6 or any other confidentiality obligation. If material could still reasonably reveal or be linked to a client’s affairs, it must not be submitted to a general-purpose AI service. AIMS’ standard policy does not provide a client-specific authorisation pathway that permits identifiable client-affairs information to be submitted to a general-purpose AI service.

The restriction above governs AIMS’ direct use of general-purpose AI services. Approved core software providers may themselves use affiliates or subprocessors, including AI-related subprocessors, as part of their services. AIMS treats that as a separate provider-governance issue: it reviews available subprocessor disclosures and relevant optional features, does not deliberately enable an optional AI feature to process identifiable client-affairs information unless the feature and provider arrangement have first been assessed, and obtains or refreshes client permission where required by Code item 6 or another applicable obligation.

Internal provider approval, security settings or client permission do not create an exception to this standard de-identified/public-information-only rule for a general-purpose AI service.

7. Security and access controls

Provider use is subject to AIMS’ access-control, multi-factor-authentication, least-privilege, secure-sharing, account/device review, retention, cyber-awareness and incident-response procedures as applicable. Provider security controls reduce but do not eliminate residual risk. AIMS assesses provider incidents under its confidentiality, privacy, data-breach, insurance and business-continuity procedures.

8. Subprocessors, overseas access and change management

Providers may use corporate affiliates and subprocessors and may change infrastructure or support arrangements over time. AIMS reviews material provider changes under its provider-governance process. Where APP 5 requires reasonably practicable overseas-country information, AIMS uses current provider information and this Schedule to communicate what is reasonably ascertainable without representing that a dynamic global provider architecture is fixed.

9. Version control and updates

This Schedule is current as at 7 September 2026. It is reviewed on material provider, contract, subprocessor, account-configuration, data-location, service-function or security changes and under AIMS’ periodic provider review cycle. The client file retains the version incorporated into or made available with the engagement where appropriate. Material changes are communicated and fresh client permission is obtained where required.

Effective / revision date:  7 September 2026

Liability limited by a scheme approved under Professional Standards Legislation.

Proudly supporting The Smith Family

Locations

Melbourne CBD
Level 30, 35 Collins Street, Melbourne VIC 3000

Caulfield South
Shop 1, 333 North Road, Caulfield South VIC 3162

The information on this website is general in nature and does not constitute tax, legal, financial, migration or other professional advice. Australian tax outcomes depend on the applicable law and each client’s specific facts and circumstances. Professional advice should be obtained before acting or relying on this information.
Liability limited by a scheme approved under Professional Standards Legislation.
Copyright © 2026 AIM S Australia Pty Ltd. | Trading as AIMS Australia Tax Accountants | ABN 21 159 602 276 | All rights reserved.