LBM Harsha LBM ← Back to site

Legal

Last updated August 2026

Privacy Terms Security Cookies
Please read this before relying on it. These are the operating terms for Harsha LBM as a service. They are not legal advice, and they have not been settled by external counsel. If you are procuring software for a practice, have your own adviser review them — and tell us anything that needs to change.

Privacy policy

This policy explains what we collect, why, and what we do with it. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What we collect

Your clients' information

Information your firm enters about its own clients belongs to your firm. For that data we act as a processor on your instructions: we store and transmit it so the platform works, and we do not use it for our own purposes, sell it, or disclose it except as set out below.

What we don't do

AI features

AI features are off until you enable them and supply your own provider key, so the relationship with that provider is yours. When a feature runs, only the content that feature needs is sent — for example a document's text for summarising. Providers are third parties operating under their own terms; if that is not acceptable to your firm, leave AI features disabled and the rest of the platform works unchanged.

Where data is held

Application data is stored in Australia. Documents go to the storage backend your firm chooses — local disk, Amazon S3, Cloudflare R2, OneDrive or Google Drive — so where those files live is your firm's decision. Credentials for those backends are encrypted at rest.

Disclosure

We disclose personal information only to service providers who help us operate the platform (hosting, email delivery, payment processing), where you direct us to, or where we are required by law. We will tell you about a legal compulsion unless we are prohibited from doing so.

Retention and deletion

We keep your data for as long as your account is active. On termination you can export everything, and we delete firm data within 90 days of a written request, except where we must retain records by law. Backups age out on their own cycle.

Access, correction and complaints

You can access and correct your information inside the application, or ask us at support@harsha.pro. If you are unhappy with how we have handled your information, contact us first — we will respond within 30 days. You can then complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Data breaches

We maintain a data breach response plan. Where a breach is likely to result in serious harm we will notify affected firms and the OAIC as required by the Notifiable Data Breaches scheme.

Terms of service

The agreement

By using Harsha LBM you agree to these terms. If you are agreeing on behalf of a firm, you confirm you are authorised to bind that firm.

Your responsibilities

The platform is a tool, not a practitioner. Deadline calculations, costs-disclosure thresholds, CPD tracking, trust reminders and AI output are aids. They do not constitute legal advice and they do not replace your own verification. You remain responsible for every date you diarise and every document you file.

Your data

Your firm owns its data. We claim no rights over it beyond what is needed to run the service for you. You can export it at any time, including after you cancel.

Availability

We work to keep the service available and to give notice of planned maintenance, but we do not currently offer a contractual uptime guarantee. If your firm needs a formal service level, talk to us and we will address it in a written agreement rather than imply one here.

Fees

Subscription fees are billed in advance in Australian dollars and exclude GST. Prices can change with 30 days' notice. Cancel at any time; the service continues to the end of the period you have paid for. We do not refund part-periods unless we have failed to deliver the service.

Third-party integrations

Some capabilities need a relationship your firm holds — PEXA requires PEXA Developer Platform accreditation, and Single Touch Payroll lodgement requires an ATO-registered provider. Where a feature depends on something we cannot supply, we say so in the application rather than implying it works.

Liability

Nothing here excludes rights you have under the Australian Consumer Law that cannot lawfully be excluded. Subject to that, our liability arising out of the service is limited to the fees you paid in the 12 months before the claim, and we are not liable for indirect or consequential loss.

Termination

Either party may terminate with 30 days' written notice. We may suspend an account immediately for non-payment or unlawful use. On termination you have 90 days to export your data.

Governing law

These terms are governed by the laws of Victoria, Australia.

Security

A plain description of the controls in place. Where something is not in place, it is not listed.

Access

Data protection

Auditability

What we have not done

We are not ISO 27001 or SOC 2 certified, and we have not undergone an independent penetration test. We would rather tell you that than let a badge imply otherwise. If your firm requires either before purchasing, contact us and we will discuss the timeline honestly.

Report a security issue to support@harsha.pro.

Cookies

We use few cookies and none of them are for advertising.

There are no advertising cookies, no third-party trackers and no cross-site profiling. Declining non-essential cookies leaves only the first two, and everything still works — you may simply need to re-set preferences such as theme.