
PRIVACY.
INTRODUCTION
Collins Hume recognises the importance of safeguarding the information entrusted to us by clients and others who engage with our business.
As an accounting and professional services business, we may receive and hold information about individuals in connection with the services we deliver, our day-to-day operations, recruitment, supplier relationships, enquiries and use of our website.
This Privacy Policy outlines the approach we take to managing that information, including the circumstances in which it may be obtained, used, shared, retained, accessed or corrected.
Collins Hume is subject to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), which establish requirements for the management of personal information by organisations in Australia.
For the purposes of this Policy, references to “Collins Hume”, “we”, “our” and “us” mean Collins Hume and any related entities that are covered by this Policy.
This Policy is relevant to individuals whose personal information is held by Collins Hume, including clients, prospective clients, employees, contractors, job applicants, suppliers, professional contacts and other people who interact with the business.
Additional information about privacy may also be provided at the time information is collected or in connection with a particular service or activity. Any such notice should be considered together with this Policy.
HOW WE COLLECT, HOLD, USE AND MANAGE PERSONAL INFORMATION
What personal information do we collect and hold?
We collect and hold personal information where it is reasonably necessary for us to provide accounting, taxation, advisory and related professional services, operate our business, manage relationships with clients and suppliers, and meet our legal and professional obligations.
The types of personal information we may collect include:
-
name, residential and postal address, telephone number and email address;
-
date and place of birth;
-
employment information and organisational role;
-
financial information;
-
bank account details;
-
tax returns, tax file numbers and other taxation information;
-
credit information;
-
information provided in connection with accounting, taxation, advisory or other professional services;
-
information relating to prospective employees, employees and contractors;
-
information obtained through enquiries, events, business development activities or communications with us; and
-
any other personal information reasonably required for us to provide our services or conduct our business.
We may collect sensitive information where it is reasonably necessary for the services we provide, including where it is required to complete an application, verification or compliance process with a third party. Depending on the circumstances, this may include health information, information about religious beliefs or affiliations, political opinions, or membership of professional associations or trade unions.
We will only collect sensitive information with the individual’s consent, unless the collection is otherwise authorised or required by law. We will not collect or use sensitive information for purposes unrelated to the services we provide.
How do we collect personal information?
Where practicable, we collect personal information directly from the individual concerned.
Information may be provided to us through:
-
meetings and discussions with our team;
-
telephone calls and email correspondence;
-
forms, questionnaires and other documents;
-
our website, online portals and other electronic systems;
-
accounting, taxation and financial records supplied to us;
-
seminars, events and other business activities; and
-
applications for employment or engagement as a contractor.
We may also obtain personal information from other sources where this is appropriate, including:
-
clients who provide information about other individuals in connection with services we are performing;
-
government departments and agencies, including the Australian Taxation Office;
-
professional advisers, referral partners and other service providers;
-
suppliers and technology providers;
-
recruitment, reference, background checking and screening providers;
-
publicly available records and databases; and
-
other third parties authorised to provide information to us.
Where a client or other person provides us with personal information about another individual, we expect that they are authorised to provide that information to us.
If information reasonably required for a service is not provided, we may be unable to provide some or all of the requested services.
How do we hold and protect personal information?
Personal information may be held in electronic or physical form, including:
-
within our offices and secure filing systems;
-
on secure servers and cloud-based systems;
-
within accounting, taxation, document management and client management systems;
-
through secure client portals;
-
by authorised technology and data storage providers;
-
by authorised overseas service providers where required to support our business operations or deliver services; and
-
within other systems used to operate our business and deliver our services.
We maintain administrative, technical and physical safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
These measures may include:
-
controlled access to our premises;
-
individual user accounts and access permissions;
-
passwords, multi-factor authentication and other security controls;
-
secure servers, cloud environments and client portals;
-
monitoring and audit trails relating to system and document access;
-
secure handling and storage of confidential documentation;
-
data loss prevention and other information-security controls;
-
monitoring designed to identify malicious, fraudulent or suspicious electronic communications;
-
employee privacy and information-security training;
-
supervision of employees who regularly handle confidential or personal information;
-
procedures for identifying and responding to privacy incidents and complaints; and
-
oversight of privacy compliance within the business.
Access to personal information is limited to people who require it for legitimate business, professional or regulatory purposes.
Why do we collect, hold, use and disclose personal information?
We generally collect, hold, use and disclose personal information so that we can provide accounting, taxation, advisory and other professional services and properly manage our relationship with clients.
We may also use or disclose personal information where reasonably necessary to:
-
perform our obligations under client engagement terms and other agreements;
-
respond to enquiries, requests and instructions;
-
communicate with clients, prospective clients and other business contacts;
-
administer client matters and maintain client records;
-
verify identity and undertake client acceptance and due diligence procedures;
-
satisfy taxation, regulatory, professional and legal requirements;
-
undertake anti-money laundering, counter-terrorism financing, know-your-client, sanctions or other screening activities where applicable;
-
process invoices, manage accounts and recover outstanding amounts;
-
conduct internal reporting, risk management and business administration;
-
undertake quality assurance reviews, professional supervision, training and improvement activities;
-
develop, assess and improve our methodologies, systems, technology, products and services;
-
undertake research, benchmarking and internal analysis using information in a manner permitted by law;
-
protect our systems, information, personnel, clients and business from fraud, cyber threats, unauthorised access and other security risks;
-
recruit employees and contractors and manage employment or contractor relationships;
-
communicate information about services, developments or events that may be relevant to clients and business contacts;
-
manage a sale, acquisition, merger, restructure or transfer of all or part of our business or assets; and
-
comply with any other obligation or purpose permitted or required by law, regulation, professional standard or applicable rule.
Where appropriate, information may be aggregated or de-identified for internal analysis, research, service improvement or other legitimate business purposes.
Who may we disclose personal information to?
We may disclose personal information to third parties where reasonably necessary to provide our services, operate our business or meet our legal and professional obligations.
These third parties may include:
-
the Australian Taxation Office and other government or regulatory bodies;
-
professional advisers, including lawyers and consultants;
-
external auditors and quality reviewers;
-
insurers;
-
banks and payment service providers;
-
technology, software, cloud, cybersecurity and data storage providers;
-
identity verification, background checking and screening providers;
-
debt recovery and credit management providers;
-
document storage, mailing and administrative service providers;
-
event, travel and other business service providers;
-
recruitment providers;
-
referral partners and other professional service providers;
-
contractors, consultants and outsourced service providers engaged to assist us in providing services; and
-
other parties where disclosure is authorised or required by law.
In some circumstances, external service providers may have access to personal information while performing services for us. We take reasonable steps to ensure those providers handle personal information appropriately and only for the purposes for which access is provided.
Where identity verification or regulatory screening is required, limited personal information may be provided to an external verification provider or other authorised organisation for the purpose of confirming identity or satisfying legal and regulatory obligations. Such information is not provided for the purpose of assessing an individual's creditworthiness unless that is separately authorised or required.
Where personal information is disclosed to an overseas service provider or offshore resource, we take reasonable steps to manage that disclosure in accordance with applicable privacy requirements.
Managing personal information
We maintain internal processes designed to support appropriate handling of personal information at all stages of its use and management.
This includes:
-
monitoring compliance with our privacy obligations;
-
maintaining processes for responding to privacy enquiries and complaints;
-
reviewing access to systems containing personal information;
-
providing ongoing privacy and information-security training;
-
applying confidentiality requirements to employees, contractors and service providers;
-
reviewing the suitability and security of third-party service providers;
-
maintaining incident response and data breach procedures; and
-
reviewing our information-management practices as our business, technology and regulatory obligations change.
Where personal information is no longer required for a permitted purpose and we are not required to retain it by law or professional obligation, we take reasonable steps to securely destroy it or permanently de-identify it.
Anonymity and pseudonyms
In some circumstances, individuals may be able to interact with us anonymously or by using a pseudonym. However, because of the nature of accounting, taxation and financial services, we will often be required to establish or verify an individual's identity before providing services. This may arise from taxation laws, professional standards, regulatory requirements or the nature of the engagement itself.
Where an individual wishes to remain anonymous or use a pseudonym, they should raise this with us at the earliest opportunity so that we can determine whether this is practicable in the circumstances.
Professional obligations
As an accounting and professional services business, we are also subject to legal, regulatory and professional obligations that may affect how we collect, retain, use or disclose personal information. These requirements may include obligations relating to taxation, record keeping, professional standards, client identification, anti-money laundering and counter-terrorism financing requirements, confidentiality and regulatory reporting.
Marketing Information
We may use personal information we hold about clients, prospective clients and business contacts to provide information about our services, updates, events and other matters we consider may be relevant or of interest.
Personal information used for these purposes may be obtained through our existing or previous dealings with you, enquiries made to the business, or through your attendance at or participation in business events.
We will only use personal information for direct marketing where permitted by applicable privacy laws. We do not use sensitive information for marketing purposes without consent.
Marketing communications sent electronically will include a clear and simple way to unsubscribe. You may also ask us at any time to stop sending you marketing communications by contacting our Privacy Officer. We will action your request and cease using your personal information for direct marketing in accordance with applicable requirements.
Disclosure of information outside of Australia
We may disclose personal information to overseas service providers, including service providers located in India and other locations from time to time, who assist us in operating our business and delivering services to our clients.
Where personal information is disclosed outside Australia, we take reasonable steps to ensure that overseas recipients are subject to appropriate privacy, confidentiality and information security obligations and handle personal information consistently with applicable Australian privacy requirements.
We remain committed to protecting the confidentiality and security of personal information disclosed overseas and ensuring that appropriate safeguards are maintained.
How we manage your credit information
In the course of providing accounting or financial services, we may collect and hold the following kinds of credit information:
a. your identification information;
b. information about any credit that has been provided to you;
c. your repayment history;
d. information about your overdue payments;
e. if terms and conditions of your credit arrangements are varied;
f. if any court proceedings are initiated against you in relation to your credit activities;
g. information about any bankruptcy or debt agreements involving you;
h. any publicly available information about your credit worthiness; and
i. any information about you where you may have fraudulently or otherwise committed a serious credit infringement.
Where relevant to services we provide, we may collect credit information and personal information from credit reporting bodies. We may also collect personal information from other credit providers that collect information. Generally, we will only collect credit information where it is disclosed to us and is relevant in providing accounting or financial services. We may also collect the credit information to process payments.
Access and corrections to credit information, or for complaints about a breach or suspected breach of privacy contact our Privacy Officer.
ACCESS AND CORRECTION OF PERSONAL INFORMATION
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out-of-date, incomplete, irrelevant or misleading.
Requests should be directed to our Privacy Officer using the contact details below. We may need to verify your identity before providing access to personal information or making a correction. We will respond to requests within a reasonable period and provide access as soon as reasonably practicable, subject to the circumstances of the request and any applicable legal or professional obligations.
We may refuse access where permitted by law, including where the request is unreasonable, access would have an unreasonable impact on the privacy of another person, access would pose a serious threat to the life, health or safety of an individual or to public health or safety, access would compromise our professional obligations, or where another legal basis for refusal applies.
Where access is refused, we will provide reasons where required by law and advise of any available complaint options.
We may charge a reasonable fee for costs incurred in providing access to personal information. Any applicable fee will be advised before it is incurred.
Where personal information we hold is inaccurate, out-of-date, incomplete, irrelevant or misleading, we will take reasonable steps to correct it where appropriate.
COMPLAINTS
We are committed to providing high-quality professional services and responding appropriately to the needs and concerns of our clients including when dealing with privacy complaints.
Submission of a complaint about an alleged privacy breach can be made to our Privacy Officer. Complaints should preferably be submitted in writing to help ensure that all relevant information is complete and accurately recorded.
To review a complaint, the following information must be included:
-
Name and contact details;
-
Nature of your relationship with us;
-
Details of the complaint;
-
Relevant dates;
-
People involved; and
-
Any supporting information.
Response to a complaint will be made within 30 days, or in the event there is a delay a notification will be made clarifying the reason for the delayed response. When the review of a complaint has been completed a response will be provided and, where appropriate, advise of any available escalation or review options.
While we hope to be able to resolve complaints received without needing third party involvement, if the outcome of any complaint is not satisfactory, complaints can be referred to the Office of the Australian Information Commissioner.
PRIVACY OFFICER
Naomi Monk
mail@collinshume.com.au
PO Box 731, Ballina NSW 2478
(02) 6686 3000
EFFECT OF POLICY
Collins Hume may revise this Policy where necessary to account for changes in legal requirements, professional obligations, business operations or the way in which information is managed.
We may update, modify or remove this policy at any time without prior notice. Any changes to the privacy policy will be published on our website.
