Legal
Client Data Security Policy
Last updated: 27 July 2026
1. Purpose
This Client Data Security Policy describes how EASEMATE PTY LTD (ABN 11 700 394 681) protects agency and end-client information processed through Visa File Expert (“Visa File Expert”).
Visa File Expert is built for migration professionals who handle sensitive identity, visa, and document information. Protecting that data is central to how we design and operate the platform.
2. Australian data hosting
Primary application databases and file storage used by Visa File Expert are hosted on servers located in Australia. We use enterprise-grade cloud infrastructure, including secure object storage, to keep Customer Data within Australian hosting regions for core platform storage.
3. Optional Google Drive storage
Agencies and clients may choose to connect Google Drive inside the product so that files can be stored in or accessed from a connected Google account.
- Google Drive connection is optional and controlled by the user who authorises it.
- Files stored in Google Drive are subject to Google's security and privacy terms in addition to this policy.
- We use the connection only to provide the storage and document features you enable.
- You should disconnect Google Drive when it is no longer required and review sharing permissions in Google for sensitive files.
4. Access control
We protect access to client data through controls such as:
- Workspace isolation so firm data stays scoped to the authorised organisation.
- Role-based access control for staff permissions.
- Passwordless one-time-code login options for agents and clients.
- Two-step verification / authenticator options for agent login where enabled.
- Support for multiple agents with configurable roles.
5. Application and transmission security
- Encrypted connections (HTTPS/TLS) for web access to the Service.
- Authenticated API access for portal and agent sessions.
- Session and token controls designed to reduce unauthorised reuse.
- Operational monitoring and logging appropriate to investigate security events.
6. Document and matter data handling
Visa File Expert is designed so agencies can manage matters, checklists, agreements, billing artefacts, and portal uploads within authenticated workflows. Customer Data should only be accessed by users your organisation authorises.
Agencies remain responsible for verifying the identity of people they invite, reviewing permissions regularly, and ensuring uploaded content is appropriate for their professional and legal obligations.
7. Personnel and vendors
Access to production systems by Company personnel is limited to what is needed to operate, support, and secure the Service. Vendors that host or process data on our behalf are expected to maintain appropriate security and confidentiality commitments.
8. Incident response
If we become aware of a security incident that affects Customer Data, we will investigate, take steps to contain and remediate the issue, and notify affected customers as required by applicable law and our contractual obligations.
9. Customer security responsibilities
Customers should:
- Use strong device security and protect email inboxes used for one-time codes.
- Enable available multi-factor options for staff accounts.
- Grant least-privilege roles within the workspace.
- Review Google Drive sharing settings when that integration is used.
- Promptly remove access for departing staff or completed matters where appropriate.
- Notify us promptly of suspected unauthorised access.
10. Related policies
This policy should be read with our Privacy Policy and Terms of Service.
11. Contact
Security or data-protection questions:
EASEMATE PTY LTD — Visa File Expert
ABN 11 700 394 681
20 Toomey street, Vermont, Victoria - 3133 - Australia
sales@visafileexpert.com