Hanno
PrivacyTerms

Privacy Statement

Last updated: 1 July 2026

Hanno (we, us, our) is a product operated by Desert Rose Investments Pty Ltd (ABN 93 672 354 022). We respect your privacy and handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This statement explains how we handle personal information across our website, application and API (the Service). Bank-feed data is also regulated under the Consumer Data Right and is covered by our CDR Policy.

1. Information we collect

  • Account information - your name, email, business name, ABN and role.
  • Financial information - ledger entries and invoices you create in the Service.
  • CDR data - the bank-account and transaction data retrieved through bank feeds under the Consumer Data Right (see section 3). This is a regulated category we handle under our CDR Policy.
  • Sign-in data - if you use Google or GitHub to sign in, we receive your email and basic profile from them.
  • API and usage data - API keys (stored only as a one-way hash), request logs, device and browser information, IP address, and how you use the Service.
  • Communications - messages you send us.

2. How we collect it

We collect information directly from you; automatically as you use the Service (cookies and logs); from sign-in providers you choose; and, once our CDR bank feeds go live, from Fiskil under the Consumer Data Right, with your consent (see section 3).

3. Bank data and the Consumer Data Right (CDR)

Status: our CDR bank-feed access is not yet live. Hanno is currently applying to access bank data under the Consumer Data Right as a CDR representative of Fiskil (Fiskil Pty Ltd), an Accredited Data Recipient that would act as our accredited principal. This arrangement has not been approved yet, and we do not collect CDR data today.

When it goes live, bank-account and transaction data will be retrieved through Fiskil under the CDR, only with your explicit consent. We will never see or store your bank login credentials - CDR access is token-based and read-only. We will collect only the CDR data reasonably needed for reconciliation and reporting (data minimisation), and your consents will be specific and time-limited: you will be able to review or withdraw them at any time. When you withdraw consent or it expires, we will stop collecting CDR data and, according to your election, delete or de-identify the CDR data we hold, and instruct Fiskil to do the same. Our handling of CDR data is (and will be) governed by our CDR Policy.

4. Why we use your information

  • To provide and operate the Service - bookkeeping, reconciliation and reporting.
  • To authenticate you and keep your account secure.
  • To generate AI-assisted suggestions that you review and approve (see section 6).
  • To provide support and send service-related messages.
  • To improve the Service, using de-identified or aggregated non-CDR data where practicable.
  • To comply with our legal obligations.

We use CDR (bank-feed) data only for the purposes you consented to - reconciliation and reporting. We never use CDR data to train any AI model, to improve the Service, or for direct marketing.

5. Who we share it with

We share personal information only with service providers that help us run the Service, each bound to protect it. We separate them by what they actually handle:

  • Providers that will handle your CDR (bank-feed) data once those feeds are live: Supabase (our database, hosted in Australia), Railway (our application hosting and compute), and Anthropic (AI features - see section 6, processed under a DPA, not used for training, retained no more than 30 days).
  • Other providers that do not receive CDR data: Cloudflare (DNS only), Resend (email delivery - account and notification emails), Sentry (error monitoring, configured to exclude your financial and CDR data), and your chosen sign-in providers (Google or GitHub).
  • Professional advisers, and law enforcement or regulators where required by law.
  • A buyer in connection with a sale of our business, subject to this statement.

Fiskil is the accredited conduit through which we would receive your CDR data once live (see section 3), not a party we disclose it to. We do not sell your personal information.

6. AI processing of your data

To generate suggestions (transaction coding, receipt reading) and answer your questions, we send the relevant data - such as transaction descriptions and amounts, receipt images, and the questions you ask - to our AI provider, Anthropic. Anthropic processes this data as our subprocessor under its Commercial Terms, which incorporate a Data Processing Addendum (with Standard Contractual Clauses). Under those terms, Anthropic does not use this data to train its models, and retains it for no more than 30 days (for abuse monitoring) before deletion. AI suggestions are proposals you review and approve; we do not make automated decisions about you. CDR (bank-feed) data sent for these features is used only to provide the service you consented to.

7. Overseas disclosure

Some of our providers may store or process data outside Australia (for example, our AI provider Anthropic processes data in the United States under Standard Contractual Clauses and its Data Processing Addendum). We take reasonable steps to ensure overseas recipients handle your information consistently with the APPs. Where practicable, your financial and CDR data is hosted in Australia (Supabase, Sydney region).

8. How we store and protect it

We use encryption in transit and at rest, access controls, hashed API keys and audit logging, and we never store your bank login credentials. No system is perfectly secure, so you are responsible for keeping your password and API keys safe and for activity under your account.

9. Accessing and correcting your information

You may request access to, or correction of, the personal information we hold about you by contacting us. We may need to verify your identity first, and will respond within a reasonable period.

10. Direct marketing

We may send you service-related messages at any time. We only send marketing with your consent, every marketing email includes an unsubscribe link, and we comply with the Spam Act 2003 (Cth). We never use CDR data for direct marketing.

11. Cookies

We use essential cookies to keep you signed in and to operate the Service, plus minimal analytics. You can control cookies through your browser settings.

12. Data breaches

We comply with the Notifiable Data Breaches scheme. If an eligible data breach occurs, we will notify you and the Office of the Australian Information Commissioner (OAIC) as required by law.

13. Retention and deletion

We keep personal information only for as long as needed for the purposes above or as required by law (for example, tax and record-keeping obligations). CDR data is deleted or de-identified when your consent ends, per your election. You can ask us to delete your account data at any time.

14. Complaints

If you have a privacy concern, contact us first at hello@hannohanno.com. If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au.

15. Changes to this statement

We may update this statement from time to time. The “last updated” date above shows the current version, and we will notify you of material changes.

16. Contact us

Hanno (Desert Rose Investments Pty Ltd, ABN 93 672 354 022) - hello@hannohanno.com.

HomePrivacyTerms