STATEMENT OF PRIVACY POLICY

Last updated: July 2026

OUR COMMITMENT

At WLM Financial Services Pty Ltd (WLM) we recognise that your privacy is very important to you, and it is to us as well. We handle personal information provided by and about people every day. By personal information we mean information or an opinion about a person whose identity is apparent or can reasonably be ascertained.

We support the Australian Privacy Principles (APPs) set out in the Privacy Act 1988 (Cth) (Privacy Act). Our aim is to support and comply with the APPs. The information set out below is largely a summary of our objectives under the APPs.

We believe this Statement will address any concerns you may have about how the personal information you provide to WLM is collected, held, used, corrected, disclosed and transferred. You can obtain more information on request about the way we manage the personal information we hold. If you seek any further information, please contact us using the details below.

COLLECTION

As an accounting and advisory firm, we are subject to legislative and professional obligations that require us to obtain and hold information that personally identifies you, or contains information or an opinion about you (Personal Information). This may include:

  • your name, date of birth, address, telephone number and email address;
  • your bank account and payment details;
  • your tax file number and other government-related identifiers;
  • employment details and history;
  • details of your financial circumstances, including your assets and liabilities, income, expenditure and superannuation; and
  • any other information required to provide our accounting, taxation and advisory services.

To meet our obligations under Australia’s Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) laws, we may also collect information to verify your identity and, where relevant, the identity of people who control or benefit from a client, such as directors, trustees and beneficial owners.

If you operate a social media or other online account, we may collect your username and any other information or content you have made public in connection with that account.

We may also collect information about your interests and preferences, demographic information such as your age and location, and technical information such as your IP address and browser type. Generally this information is not personal information, as it cannot be used to identify you.

If you elect not to provide us with the personal information we request, we may be unable to provide our services to you fully and properly, and may need to end our engagement.

At or before the time we collect Personal Information from you, we will take reasonable steps to tell you why we are collecting it, who we might disclose it to, and what will happen if you do not provide it. Where reasonable and practicable, we will collect personal information about you only from you, and will give you the option of dealing with us anonymously where it is lawful and practicable to do so.

Once we hold personal information, we will take reasonable steps to keep it accurate, complete and up to date.

USE AND DISCLOSURE

We will not use or disclose Personal Information collected by us for any purpose other than:

  • the purposes for which it was provided, or secondary related purposes you would reasonably expect;
  • where you have consented to the use or disclosure; or
  • where the APPs authorise use or disclosure, including where required or authorised by law.

We may disclose your Personal Information to third parties who help us provide our services, such as our software and cloud service providers (see ‘Sending data overseas and third party websites’ below).

We are required by law to keep certain records and may be required to disclose information to regulators and government agencies, including the Australian Taxation Office, the Tax Practitioners Board, and, in connection with our AML/CTF obligations, AUSTRAC.

It is a condition of our arrangements with our team and service providers that they handle your personal information in accordance with this policy. We are not responsible for the privacy practices of third parties to whom we disclose information in accordance with this policy.

If we propose to sell our business, we may disclose your Personal Information to potential purchasers for the purpose of due diligence, in confidence and on the condition that it is not used or disclosed for any other purpose. If a sale proceeds, we may transfer your personal information to the purchaser, and you will be advised of any such transfer.

We may disclose your personal information to the extent required by law, including in connection with legal proceedings, or to establish, exercise or defend our legal rights.

You may withdraw your consent to our use or disclosure of your personal information at any time by contacting us using the details below. Withdrawing your consent may mean we are unable to provide our services to you.

ACCESS AND CORRECTION

Your Personal Information is generally held in your client file and may also be held in our computer systems. We take reasonable steps to protect it from misuse, loss, and unauthorised access, modification or disclosure, and we treat it as confidential.

You may at any time request access to the personal information we hold about you by contacting us using the details below. Subject to the exceptions permitted under the APPs, we will provide access by giving you copies, allowing you to inspect the information, or providing an accurate summary. We will require evidence of your identity before providing access. If we refuse access, we will give you our reasons.

If you believe any personal information we hold about you is inaccurate, incomplete or out of date, please contact us and, if we agree it requires correcting, we will take reasonable steps to correct it. If we do not agree, you may ask us to note your view alongside the information.

We will endeavour to respond to any request for access within 14 to 30 days, depending on the complexity of the request. If your request is urgent, please tell us.

SECURITY AND RETENTION

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. We destroy or de-identify personal information we no longer need.

Your personal information is stored in secure physical files and on secure cloud-based systems, some of which are provided by third parties located overseas (see ‘Sending data overseas and third party websites’). Paper files are stored in lockable cabinets. Access to our premises and systems is restricted to authorised personnel using security passes and passwords, and data is backed up and stored securely.

If you cease to be a client, we will retain your personal information in secure storage for the period required to meet our legislative and professional obligations, generally at least seven years, after which it will be destroyed or de-identified.

COOKIES AND WEBSITE ANALYTICS

When you visit our website, information may be recorded about your visit, such as the date and time, your server address, the pages you access, the time spent and your browser type.

We use cookies and similar technologies, including Google Analytics and HubSpot, to understand how visitors use our website, to improve it, and to support our marketing. Some of this information may be personal information. You can adjust your browser settings to reject cookies or to notify you when they are used, although some parts of the website may not work properly as a result.

When you complete a form, subscribe or contact us through the website, we collect the personal information you provide and store it in our customer relationship management system (HubSpot).

IDENTIFIERS

We will not adopt as our own any government-related identifiers that you provide to us, such as tax file numbers or Medicare numbers, and we will only use or disclose them as permitted by law.

ARTIFICIAL INTELLIGENCE AND AUTOMATED TOOLS

We use technology, including artificial intelligence (AI) and automated tools, to help us deliver, manage and improve our services, for example to organise documents, prepare drafts and analyse information. Where these tools process personal information, that information is handled in accordance with this policy.

We take reasonable steps to ensure that our AI and technology providers keep your information secure, and do not use it to train their own models except where we have authorised this. Our people review the outputs of these tools before they are relied on. Some of these tools are provided by third parties located overseas (see ‘Sending data overseas and third party websites’).

SENDING DATA OVERSEAS AND THIRD PARTY WEBSITES

Some of the service providers we use to store and process personal information are located overseas, or store data overseas. These include our practice management, accounting, productivity and customer relationship management providers, such as Karbon, Xero, Microsoft and HubSpot. Depending on the provider, your information may be stored or processed in countries including Australia, the United States and New Zealand. By providing your personal information to us, you consent to it being stored and processed overseas for the purposes set out in this policy. We take reasonable steps to ensure that overseas recipients handle your personal information consistently with the APPs.

If you reside overseas, you acknowledge and consent to your Personal Information being transferred to and held in Australia for the purposes set out in this policy.

Our website may contain links to third party websites. We are not responsible for the privacy practices of those websites, and we encourage you to review their privacy policies.

DATA BREACHES

If we experience a data breach that is likely to result in serious harm to any individual whose personal information we hold, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

COMPLAINTS RESOLUTION

We are committed to handling privacy complaints fairly and promptly.

If you wish to complain about a breach or potential breach of this privacy policy or the APPs, please contact us using the details below and ask that your complaint be directed to our Privacy Officer. We will acknowledge your complaint and use our best endeavours to resolve it. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992, which may investigate your complaint further.

CONTACT US

If you would like further information about this Statement or our privacy policy generally, please contact our Head of Risk, Amanda Rogers, using the details below:

Office:Level 20, 56 Pitt Street, Sydney NSW 2000
Postal:GPO Box 5025, Sydney NSW 2001
Telephone:(02) 9221 7777
Email:info@wlm.com.au

This policy will be reviewed from time to time to take account of new laws and changes to our operations. Any information we hold about you will be governed by our most current policy. We recommend you periodically review this policy for changes.

Further information about privacy in Australia is available from the Office of the Australian Information Commissioner at www.oaic.gov.au.