Yes. You can attach documents, images or video guides directly to any question in a request so clients have everything they need to answer correctly, right there in the portal, without having to email your office to ask what you mean.
Resources / FAQ
Answers on security, billing, features and what your clients experience. If yours isn't here, ask us and we'll answer it directly.
01
New to Gatheroo? Here’s what you need to know before you begin. If you’d like to see it in action first, you can book a chat with one of the team.
Gatheroo is a secure client portal for professional services businesses that need a better way to collect information and documents from clients.
Instead of asking clients to email documents, fill out PDFs or reply to a chain of follow-up messages, you build a structured request, send your client a unique secure link, and Gatheroo guides them through providing exactly what you need, automatically following up until the request is complete.
Every request is encrypted, stored in Australia, and carries a timestamped audit trail. It’s built for businesses that handle sensitive client information and need a process they can stand behind.
Gatheroo is built for professional services businesses in Australia that collect sensitive information and documents from clients as a core part of what they do: accountants, mortgage brokers, financial planners, conveyancers, lawyers, HR and recruitment firms and similar practices.
If your current process relies on email, shared drives, or PDFs sent back and forth, and you’re increasingly aware that it doesn’t meet the security or compliance standard your business actually requires -> Gatheroo was designed for exactly that situation.
Gatheroo is used by businesses across accounting, mortgage broking, financial planning, conveyancing, legal, HR and recruitment, and other professional services fields.
If your business collects sensitive client information as part of how it operates and you need that process to be secure, consistent and auditable, Gatheroo is designed for you. If you’re unsure whether it’s the right fit, book a chat and we’ll tell you honestly.
Yes, all plans include a 14-day free trial. No credit card required. Most businesses are set up and sending their first request on the same day they sign up.
No. Gatheroo is designed to be set up and managed by the person responsible for client intake, not by an IT team.
Most businesses have their first request built and sent on the same day they sign up. There’s no integration project, no development work, and no lengthy onboarding process. If you can build a form, you can use Gatheroo.
Our how-to guides cover everything from setting up your first request to configuring reminders and managing your team’s access.
We also have an extensive templates library that enables you to “hit the ground running” and set up your first request quickly and easily.
Most businesses are set up and sending their first request within the same day. There’s no infrastructure to configure and no lengthy onboarding process.
If you’re starting from scratch, our ready-made templates give you a head start. They are designed for common professional services intake scenarios so you’re not building from a blank page.
02
Gatheroo is purpose-built for professional services businesses that collect sensitive information from clients. Here’s how it works in practice. For a full breakdown of what’s included on each plan, see our pricing page.
Yes. Every request carries a timestamped activity log. It records when a request was sent, when it was opened by the client, what was answered and when, and every comment or update made along the way.
That record builds itself as a natural output of your process. Nobody has to remember to document it. If you’re ever asked to demonstrate your client intake process to an auditor, a regulator, or your own leadership, that record is ready to produce with minimal preparation.
For businesses with AML/CTF obligations, KYC requirements, or simply an expectation that they can account for what was requested and received, that’s not a feature. It’s the point.
Gatheroo is a secure client portal for professional services businesses that need a better way to collect information and documents from clients.
Instead of asking clients to email documents, fill out PDFs or reply to a chain of follow-up messages, you build a structured request, send your client a unique secure link, and Gatheroo guides them through providing exactly what you need, automatically following up until the request is complete.
Every request is encrypted, stored in Australia, and carries a timestamped audit trail. It’s built for businesses that handle sensitive client information and need a process they can stand behind.
When you sign up to a paid plan, Gatheroo’s team will build a ready-to-use request list tailored to your business, based on what you commonly collect from clients. The number of built-for-you lists depends on your plan.
This is designed to get you collecting information securely from day one, without spending time building everything from scratch.
Gatheroo includes a full library of field types so you can collect exactly what you need, in exactly the right format:
Conditional logic means the next question adapts based on the answer a client gives to the previous one.
If a client selects “Yes, I have a business partner,” a follow-up question asking for their partner’s details appears automatically. If they select “No,” it doesn’t.
Clients only see what’s relevant to their situation, which means you receive what you need, and clients aren’t confused by questions that don’t apply to them.
Repeater fields let a client add as many entries as they need to a single question, without you having to guess how many lines to create.
For example: if you need five years of address history, a list of company directors, or a record of previous employers, you ask the question once and the client adds entries until the list is complete. No guessing, no incomplete submissions, no follow-up asking for the entry you missed.
Yes. All plans include your business logo and your own email domain, so clients receive requests from your address and see your brand in the portal.
A custom URL is available on the Custom plan. If that’s relevant to your setup, contact us to discuss.
Yes. Rather than a request going out the moment you finish building it, you can schedule delivery for a specific date and time, so clients receive it at the right moment in your workflow, not at 4:55 pm on Friday because that’s when you finished.
When you create a request, you set a due date and a reminder frequency. Gatheroo handles everything in between, sending reminders to your client automatically until the request is fully completed.
You’re notified the moment a client submits. No checking, no manual follow-up, no internal messages asking whether something has come in.
Yes. Clients can amend their answers if their circumstances change or if they need to correct something, without starting again or creating a new email chain. The activity log records any changes.
Yes. Once a request is complete, you can download all submitted files in a single action. No opening individual attachments, no saving files one by one.
Gatheroo integrates natively with Google Drive and OneDrive, so completed requests can sync automatically to the tools your team already uses. Our Zapier integration connects Gatheroo to 7,000+ apps. No development work required.
03
One of the most common questions we hear from businesses evaluating Gatheroo is: “Will my clients know how to use it?” Here’s what your clients experience.
Clients see a clean, guided portal showing the questions and file upload requests you’ve built, with any instructions you’ve attached displayed alongside the relevant field.
They can see a progress indicator showing how much they’ve completed and what’s still outstanding. If they need to stop and come back, their progress is saved. If they need to amend an answer, they can do that too.
The portal displays your business logo and sends from your email domain so clients see your brand throughout.
No. Clients don’t need to create an account, download anything, or remember a password.
They receive a unique secure link by email, and click through directly to their portal. Everything they need to complete the request is right there. The experience is designed to be simple enough that clients engage with it first time, without needing to call your office to ask how it works.
You can request that they also need a passcode to open the request for additional security, and this can be sent to their email or phone number.
Clients receive an initial email with their unique secure link when you send the request. If the request isn’t completed by the due date, Gatheroo sends automatic reminders at the frequency you’ve set.
All emails come from your domain once you’ve set it up, so they land in your client’s inbox as a message from your business.
Yes. The Gatheroo client portal is fully mobile-friendly. Clients can complete requests and upload documents from their phone or tablet without needing to be at a desktop.
Yes. Clients can start a request, save their progress, and return to complete it later. Their unique link remains active until the request is archived by your team.
Yes. You can attach documents, images or video guides directly to any question in a request so clients have everything they need to answer correctly, right there in the portal, without having to email your office to ask what you mean.
Clients can leave a comment directly on any individual field (question) within the request and your team can reply in the same place. Every conversation stays attached to the specific question it relates to, rather than spinning off into a separate email thread.
Your team can also use @mentions to tag a specific person, so nothing gets missed and the right person is notified.
Yes. When you send a request to multiple clients. For example, two directors of the same company: each client receives their own individual secure link.
They each complete what they need to on the list. There’s no shared login, no confusion about who submitted what.
04
Plans, payments and changes. Compare inclusions on the pricing page.
Yes, all plans include a 14-day free trial. No credit card required. Most businesses are set up and sending their first request on the same day they sign up.
Gatheroo plans are available on an monthly or annual basis. Pricing varies depending on the plan you select. You can compare all plans on our pricing page.
By paying annually, you’ll save on the equivalent monthly plan. Worth checking out before you commit to monthly billing.
Payment is made securely by credit or debit card. Your card will be charged at the frequency that matches your subscription: monthly or annually.
Once you’ve selected your plan, you’ll be prompted to enter your card details during checkout. We use Stripe as our payment gateway, so your payment details are handled to the same standard we apply to everything else in the platform.
Yes. You can change your plan at any time from the Billing Details section in your account settings. Upgrades take effect immediately; downgrades apply at the start of your next billing cycle.
Team members are included in your plan up to the limit for your subscription level. There’s no additional per-user charge within those limits.
If you need more users than your current plan allows, you’ll need to move to the next level. Pricing for each plan is on our pricing page. If you upgrade during your billing period, a pro-rata amount is applied to the first month for the unused portion of your previous plan.
No. Your subscription is linked to your billing period, either monthly or annually, and you can cancel at any time before the next cycle.
If you cancel, no further charges will be taken. Please note that no refund will be given for any unused portion of your subscription. You and your team can continue using Gatheroo uninterrupted until the end of your current billing period.
Log in to your Gatheroo account and navigate to Global Settings > Billing Details. From there, select “Cancel My Plan.”
Please note that only the Account Owner role can cancel the subscription. Once cancelled, no further charges will be taken, and no refund will be given for any unused portion. You and your team can continue using Gatheroo until the end of your current billing period.
05
Certification only counts if you can see the evidence behind it. Here’s what we’re certified to, who audits us, and what we can put in writing for your compliance team.
Yes. Gatheroo is built and operated within an information security management system certified to ISO/IEC 27001:2022, certificate 1357-I-1, issued to Kicking Pixels Pty Ltd by Global Compliance Certification Pty Ltd under JAS-ANZ accreditation.
The certified scope covers the provision of SaaS products and website planning, design and development, so Gatheroo sits inside the certification rather than alongside it. The certificate was issued on 26 March 2025 and runs to 25 March 2028, maintained through annual surveillance audits, with the next scheduled for Q1 2027.
ISO 27001 certifies how an organisation manages information security, not a software product in isolation. Gatheroo supports your compliance obligations; it doesn’t discharge them for you. A copy of the certificate is available on request.
A copy of our ISO/IEC 27001:2022 certificate is available on request, along with extracts from our Statement of Applicability. We don’t publish the full Statement of Applicability because it details our internal control implementation, but we’ll walk your security team through the parts relevant to your assessment. Email security@gatheroo.io.
On three levels. We run our own internal audit programme across the year, our leadership team formally reviews security performance and risk at management review, and an external certification body audits us annually. Findings from any of these are tracked as corrective actions through to closure.
We don’t run penetration tests on a fixed schedule. We run continuous automated security testing using AWS-native tooling, every code change is peer reviewed before release, and our controls are independently audited each year to maintain ISO 27001 certification. Where a client’s procurement process requires an independent penetration test, we’ll arrange one – talk to us at security@gatheroo.io.
Yes. We regularly complete vendor security questionnaires as part of client procurement. Send yours to security@gatheroo.io and we’ll return it completed, with supporting evidence where we can provide it.
Gatheroo gives you a secure, auditable client intake process. Australian data storage, encryption, two-factor access control and a full activity trail, supporting your obligations under Australian privacy and AML/CTF legislation.
If your business is in accounting, conveyancing, legal, mortgage broking or financial services, Tranche 2 of Australia’s AML/CTF reforms extends formal obligations to you. A documented, auditable KYC and client intake process isn’t an optional extra under that framework, it’s a baseline requirement.
Gatheroo doesn’t make your business compliant on its own. What it does is give you the structured intake process, the audit trail and the security controls that compliance requires, and that you can demonstrate clearly if you’re ever asked.
Contact us directly. We’d rather answer a specific question than have you decide on incomplete information.
For security, compliance or procurement questions (questionnaires, certificate copies, due diligence) email security@gatheroo.io. For general support, email help@gatheroo.io or book a chat.
06
Your clients’ documents are the whole point, so we’re specific about what happens to them. Where they’re stored, how they’re encrypted, how long we keep them, and what happens when you delete them.
All Gatheroo customer data is stored in Australia on Amazon Web Services infrastructure. It is not replicated to, or hosted in, any other jurisdiction.
A small number of Kicking Pixels personnel located outside Australia access production systems remotely to build and support the platform. They connect through a dedicated VPN with multi-factor authentication and role-based least-privilege access, every session is logged, and they are bound by the same screening, confidentiality and security obligations as our Australian team. The data itself remains stored in Australia at all times.
For businesses in regulated industries (financial services, accounting, legal, mortgage broking, conveyancing) data sovereignty matters, and Australian storage is a non-negotiable part of how Gatheroo operates.
Yes. Everything moving to and from Gatheroo – files, form submissions and page traffic – is encrypted in transit using TLS 1.2 or higher. Nothing travels in the clear.
Sensitive text fields such as Tax File Numbers are additionally encrypted at rest with field-level AES-128-GCM and are never stored as plain text. They’re decrypted only when your team views them, and always delivered back over an encrypted connection.
Uploaded files are encrypted at rest with AES-256 on Australian AWS storage. EC2 volumes and S3 are additionally encrypted at rest using AES-256 via AWS-managed keys.
You do. Your account data and everything your clients submit remain yours. We process it only to operate the service on your instructions, as set out in the Data Processing Agreement within our Terms and Conditions. We don’t sell it, share it for marketing, or use it for anything you haven’t asked for.
Yes. When you delete a request or a file in Gatheroo it is removed from the live platform immediately. There is no hidden archive and no soft-delete state you can’t see.
Deleted data can persist briefly in our encrypted operational backups, which run on a rolling seven-day cycle and are then overwritten. Those backups exist so we can restore your account after a failure, they aren’t searchable and aren’t used to retrieve individual deleted items.
You control what is retained and when it is deleted. That supports your obligations under the Australian Privacy Act, which requires personal information to be destroyed or de-identified once it is no longer needed.
Your account and its data are deleted 60 days after cancellation, which gives you time to export anything you need. Once deleted, data is purged from live systems and ages out of our seven-day backup cycle shortly afterwards. If you need it removed sooner, ask and we’ll action it.
Trial accounts are deleted automatically after 60 days of inactivity. Nothing is kept indefinitely just because a trial was started and abandoned.
No. We don’t use your data or your clients’ data to train AI models, and we don’t provide it to third-party AI tools that would. Where our team uses AI tooling internally, our policy permits only approved tools that contractually exclude inputs from model training.
Yes, and you already have it. Our DPA forms Part B of our Terms and Conditions and applies automatically, there’s nothing separate to negotiate or sign. It sets out your role as data controller and ours as processor, our sub-processors, breach notification, retention and deletion, and our commitment that customer data stays in Australia in the ordinary course of operating the service. If procurement needs a signed standalone copy, just ask.
Individuals can ask us to access, correct or delete personal information we hold about them. We respond to access requests within 30 days and correction requests within 14 days, and we assess deletion requests within 14 days and action them within 30. Where the information belongs to one of your clients, you are the controller – we’ll refer the request to you and support you in responding. Email privacy@gatheroo.io
07
Most security questions come down to one thing: who can reach your data, and how do you know. Here’s how access to Gatheroo is controlled, verified and logged, for your team and your clients alike.
Yes, and we’re specific about what that means.
All data in transit (files and form submissions alike) is encrypted using TLS 1.2. Sensitive text fields such as Tax File Numbers are additionally encrypted at rest using field-level AES-128-GCM, decrypted only when your team views them.
Uploaded files are encrypted at rest with AES-256 on Australian AWS storage. EC2 volumes and S3 are additionally encrypted at rest using AES-256 via AWS-managed keys.
Strong passwords are mandatory. Two-factor authentication is available on all plans by email passcode, and by SMS on Large plans.
Gatheroo is hosted on Amazon Web Services with all data stored in Australia. Access to production is role-based, least-privilege, multi-factor authenticated and logged.
Every code change is peer reviewed before release, and we run continuous automated security monitoring using AWS-native tooling including Inspector and GuardDuty. All of this operates inside our ISO/IEC 27001:2022 certified management system.
Yes. 2FA is available for both your team and your clients.
For your team, 2FA can be enabled from the My Account > 2FA section in your account settings. Once enabled, a 6-digit code is sent to your verified email address each time you log in.
For your clients, optional 2FA on a request via email is available on all plans. SMS-based 2FA is available on Large plans. This ensures that only the intended recipient can access a sensitive request and that access is recorded.
Each client receives a unique secure link to their portal. There are no shared logins, no shared access, and no version confusion between clients.
You can require clients to verify their identity via two-factor authentication (either by email code or if you are on a large plan you can opt to send this code by SMS) before they can access or submit any information. This means you always have a record of who accessed what and when, which is particularly relevant for businesses with KYC or identity verification obligations.
Passwords are never stored in readable form. They’re stored as salted one-way hashes, so they can’t be reversed or retrieved by anyone, including us. Strong passwords are enforced at sign-up, and we recommend enabling two-factor authentication on top.
Not currently. Gatheroo uses email and password with mandatory strong passwords, plus two-factor authentication by email on all plans and by SMS on Large plans. If SSO is a requirement for your organisation, tell us, it helps us prioritise.
Everyone who works on Gatheroo is a Kicking Pixels team member, not a subcontracted third party. Anyone granted privileged access to production is screened beforehand, including reference checks and verification of employment history. All personnel sign confidentiality agreements and complete security awareness training, refreshed as the threat landscape changes.
Access is revoked within 24 hours of a person leaving or changing role, and all assets are returned. Access rights across production systems are also reviewed on a scheduled basis, so accounts don’t quietly outlive the reason they were created.
Yes. Every request carries a timestamped activity log. It records when a request was sent, when it was opened by the client, what was answered and when, and every comment or update made along the way.
That record builds itself as a natural output of your process. Nobody has to remember to document it. If you’re ever asked to demonstrate your client intake process to an auditor, a regulator, or your own leadership, that record is ready to produce with minimal preparation.
For businesses with AML/CTF obligations, KYC requirements, or simply an expectation that they can account for what was requested and received, that’s not a feature. It’s the point.
08
The controls that matter most are the ones running every day, whether or not anyone is looking. Here’s how Gatheroo is built, backed up, patched and monitored, and what happens when something goes wrong.
All traffic to Gatheroo passes through an Application Load Balancer before it reaches any application server. The servers themselves are not directly accessible from the internet – only the load balancer accepts incoming connections.
SSH administrative access is restricted to a single authorised IP address. No other inbound access to the server is permitted.
The database is not exposed to the network at all. It runs on the same isolated server as the application and is only accessible locally, there is no network port open for database connections.
All of this is enforced through AWS security groups, which act as a strict firewall, only explicitly permitted traffic is allowed, everything else is blocked by default.
Gatheroo maintains automated backups of the application database, the application server and all stored files. Backups are held in Australia, encrypted, and retained on a rolling seven-day cycle, so we can restore to a point in time within that window.
Backups are verified monthly, reviewed quarterly, and put through a full restore test annually as part of our certified management system. Our target recovery time for Gatheroo is one hour.
We remediate on defined timeframes: critical and high severity within 30 days, medium within 90 days, low within 180 days, and emergency patches for actively exploited issues within 7 days. We monitor continuously using AWS-native tooling and review dependencies for known vulnerabilities as part of our release process.
Every change is peer reviewed by our Technical Lead before it can be merged, then moves through separate local, staging and pre-production environments before reaching production. Changes are tracked and releases can be rolled back. Nothing goes to production straight from a developer’s machine.
No. Testing uses synthetic or anonymised data only. Real client documents and real personal information are never copied into development, staging or test environments.
If a security incident affects your data, we’ll tell you. We acknowledge reported incidents within 4 business hours and aim to contain them within 8 business hours. Our Terms and Conditions commit us to notifying you within 72 hours of becoming aware of a breach affecting your data. Separately, where an incident is an eligible data breach under the Australian Privacy Act, we assess it and notify the OAIC and affected individuals as required, working with you as the controller of your clients’ information.
09
We can only be as secure as the providers we rely on, so we keep that list short and published. Here’s who we use, what they handle, and how you’ll hear about it if that changes.
The full list is published in our Trust Centre, including what each provider does and where it’s located. In short, Amazon Web Services hosts the platform in Australia and Stripe processes payments. Everything else we rely on is listed there with its role and location.
Yes. We give at least 30 days’ notice before adding or replacing a sub-processor that handles customer data, so you have time to review it. The current list is always published in our Trust Centre.
Every supplier that touches customer data is risk assessed before we engage them – security posture, data location, certifications and contractual protections. Assessments are recorded in our vendor risk register and reviewed on an ongoing basis, not just at onboarding.
No. All payments are processed by Stripe. Card numbers never touch Gatheroo’s systems and are never stored by us.