4A Migration CloudLast updated: 13 August 2026
This Privacy Policy explains how 4A Consulting Services Pty Ltd (ABN 53 672 296 418) (“4A”, “we”, “us”, “our”) collects, uses, discloses, stores and protects personal information. 4A is a provider of Australian immigration assistance and operates the “4A Migration Cloud” case-management application at app.4acrm.com.au.
We handle personal information in accordance with the Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth). We do this both as a matter of commitment to our clients and customer firms and because, to the extent the Privacy Act applies to us, we are required to. As immigration assistance is provided by registered migration agents, we are also bound by the confidentiality and record-keeping obligations of the Code of Conduct for registered migration agents made under the Migration Act 1958 (Cth).
Our different roles. 4A acts in more than one capacity. When we provide immigration assistance to our own clients through our registered migration agent, we determine how personal information is handled for that purpose. When another migration practice (a “customer firm”) uses 4A Migration Cloud, that firm decides what client and matter information is entered and how it is used, and we handle that information as the firm’s service provider, on the firm’s instructions and under our agreement with the firm. We also handle information about the firm and its staff (account, billing, security and support information) for our own purposes as operator of the platform. This policy applies in addition to, and does not replace, a customer firm’s own privacy obligations to its clients.
Our compliance framework — applies to every feature. Every feature of the platform — including client and matter management, document handling and storage, connected email and cloud accounts, questionnaires and checklists, department form preparation and assisted ImmiAccount entry, VEVO checks, e-signing, payments, trust/clients’-account records, communications capture and the artificial-intelligence tools described in section 3 — is provided in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, the Notifiable Data Breaches scheme, the Migration Act 1958 (Cth), the Migration Agents Regulations and the Code of Conduct for registered migration agents, the requirements of the Department of Home Affairs for lodgement and identity verification, and other applicable Australian laws. In every case a registered migration agent remains professionally responsible for the advice given and the application lodged; the platform assists that agent and never replaces their judgement or supervision.
Depending on how you use our services, we may collect:
We use personal information to:
The platform includes optional features that use artificial intelligence to assist a registered migration agent. AI is used only to assist a human practitioner; it never makes a decision about a visa application, and its output is always reviewed by the responsible registered migration agent before it is relied upon, sent or lodged. The AI features are:
Documents are never sent to AI. Reading and extracting data from uploaded documents (for example a passport, ID, payslip or receipt) is performed entirely on our own servers in Australia using local optical-character-recognition. We do not send document images or files — including identity documents such as passports — to any external AI provider.
What information is provided to the AI, and to whom. The text-based AI features are delivered through the application programming interfaces (APIs) of established AI providers — OpenAI and/or Anthropic (the provider is configured by the firm using the firm’s own API key). Before any text is sent, it is de-identified: direct identifiers such as email addresses, phone numbers, passport and other reference numbers, and dates of birth are automatically removed and replaced with neutral placeholders. Depending on the feature used, the de-identified information sent to the AI provider may include:
Because de-identification is automated and pattern-based, we cannot guarantee that every incidental identifier (for example a name written in a free-text note) is removed in every case. It is designed to remove direct contact details, identity/reference numbers and dates before transmission.
How that information is handled by the AI provider. Information is transmitted to the AI provider over encrypted connections and is processed to produce the requested result. Under the API terms of OpenAI and Anthropic, data submitted through their APIs is not used to train their models, and is subject to limited retention for abuse-monitoring before deletion. We do not use AI providers that train on our data. AI providers may process data on servers outside Australia (including the United States); we take reasonable steps to ensure appropriate protection when this occurs (see section 8).
Your choices. A firm can turn AI features off entirely. Where offered, you may also decline the use of AI on your own matter at the time you sign your service agreement, and your choice is recorded and respected. Declining AI does not affect the standard of service you receive. Because AI can make mistakes, all AI output is treated as a draft for the practitioner to check — it is not advice in itself.
How our AI use complies with Australian law and professional obligations. Our use of AI is designed to meet the requirements that apply to registered migration agents and to the handling of personal information in Australia:
With your explicit authorisation, 4A Migration Cloud can connect to your Google account so that a firm can send its own client correspondence, capture inbound and sent client correspondence and file it to the correct matter, store matter documents in the firm’s own Google Drive, and create consultation and deadline events in the firm’s calendar. Only the account owner connects their own account, connection uses Google’s secure OAuth flow, and we never receive or store your Google password.
Scopes we request and what each is used for.
openid, email, profile) — to identify you and the connected account (Google account identifier, name and email address).gmail.send) — to send the firm’s own outbound client emails from the connected mailbox. This scope does not permit reading your mailbox.gmail.readonly), where the firm enables email capture — to read inbound and sent messages so the platform can identify the sender and subject, match the message to the correct client matter, and file the message and its attachments to that matter in the firm’s own connected cloud storage. The platform reads message metadata (sender, recipients, subject, dates), message bodies and attachments only to perform this filing; 4A does not retain the message body or attachments on its own servers (see “Where Google information is stored” below).drive.file) — a per-file scope that lets the application create and manage only the matter folders and files it creates or that you open with it. It does not give the application access to any other files in your Drive.calendar.events, calendar.freebusy) — to create and update consultation and deadline events on the connected calendar, and to read free/busy times so the public booking page can offer available slots. We do not read the content of your other calendar events.Where Google information is stored, and for how long. Processing occurs on our servers hosted in Sydney, Australia. When email capture is enabled, 4A reads a message to file it but does not retain the message content on its own servers. The message body and its attachments are written only to the relevant matter folder in the firm’s own connected cloud storage (for example the firm’s OneDrive or Google Drive); if no cloud storage is connected, the message is not copied and nothing is stored. In its own Australian database 4A keeps only the linking metadata needed to file correspondence and avoid duplicates — message identifiers, sender and recipient addresses, subject, dates, the folder it came from, and the matter it was filed to — together with a short file note recording that the message was filed. Documents created or opened via drive.file live in the firm’s own Google Drive. Calendar events live in the connected Google calendar. The linking metadata is retained as part of the client’s matter record for the period required by law and professional obligations, and is then securely deleted or de-identified; the filed message itself is held in, and controlled through, the firm’s own cloud storage.
OAuth tokens. To keep a connection working we store the OAuth access and refresh tokens Google issues. These are stored encrypted at rest and are used only to call the Google APIs for the features you authorised.
Disconnection, revocation and deletion. You can disconnect a Google account at any time from within the application, or revoke our access directly at myaccount.google.com/permissions. Disconnecting or revoking deletes the stored OAuth tokens and stops any further access to your Google account. Please note the distinction between credentials and matter data: revoking access removes our ability to connect, but information already filed into a client matter (for example an email or attachment saved to the matter before revocation) remains part of that matter record until it is deleted. To have Google-derived information already copied into a matter deleted, contact us at the address in section 14 or ask the responsible firm; we will delete or de-identify it unless we are required by law or professional obligation to retain it.
Human access. Access to a firm’s data, including Google-derived information, is role-based and limited to that firm’s own authorised users. 4A’s own personnel do not access customer, matter or captured email content in the ordinary course. Consistent with Google’s Limited Use requirements, a human will only access Google user data with your affirmative consent for specific messages, where necessary for security or to comply with applicable law, or where the data has been aggregated and anonymised for internal operations.
AI features and Google data. Google-derived information (emails, attachments and Drive files) is not sent to our AI providers. The AI features in section 3 operate on matter documents and facts that a practitioner works with in the platform; they do not ingest your connected mailbox, Drive or calendar.
Limited Use disclosure. 4A Migration Cloud’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google user data is not sold, is not used or transferred for advertising, is not transferred to data brokers, is not used to determine creditworthiness or for lending, and is not used for any purpose other than providing or improving the user-facing features you authorised. It is not transferred to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with appropriate notice. Humans do not read your Google data except in the limited circumstances described above.
Microsoft and other connected accounts. Where a firm connects Microsoft (Outlook mail via Mail.Read/Mail.Send, and OneDrive/SharePoint files via Files.ReadWrite/Sites.ReadWrite.All) or another storage provider, that information is handled on the same basis: used solely to deliver the feature the firm authorised, stored and protected as described in this policy, never sold and never used for advertising.
We use a small number of trusted service providers to operate the platform. Each processes only the data needed for its function, under contractual confidentiality and security obligations:
We do not sell personal information to anyone.
We disclose personal information only as necessary to provide our services, including to:
Some of our providers — including our AI providers, and Google and Microsoft — may store or process data on servers located outside Australia (including in the United States and other countries). Where personal information is disclosed overseas, we take reasonable steps to ensure the recipient handles it consistently with the Australian Privacy Principles, including through contractual protections. By using the AI and connected-account features you consent to this overseas processing for the purpose of delivering those features.
We do not make decisions that produce legal or similarly significant effects about you using solely automated processing. AI and automation assist our staff; a registered migration agent remains responsible for the advice, the content of any application, and the final decision to act.
You may request access to, or correction of, the personal information we hold about you. You can disconnect a connected Google, Microsoft or Xero account at any time within the application, or revoke our application’s access directly at myaccount.google.com/permissions (Google) or in your Microsoft account settings.
Where a matter concerns a minor (for example, a child included in a family application), we collect and handle their information only with the consent and involvement of a parent or guardian, and only as necessary for the immigration assistance being provided.
If you have a privacy concern, please contact us first (details below). If you are not satisfied, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. Complaints about immigration assistance may be made to the regulator of registered migration agents via the OMARA.
We may update this policy from time to time. The current version is always available at this page, with the “Last updated” date above.
4A Consulting Services Pty Ltd
ABN 53 672 296 418
Suite 602, Level 6/379-383 Pitt St, Sydney NSW 2000
Email: info@4aconsultingservices.com.au
Website: app.4acrm.com.au
See also our Terms of Service and Subprocessors.