Book Appointment Book Appointment

Privacy Policy

PRIVACY POLICY

Effective date: 01 July 2026

1. About this Privacy Policy

Oracle Accounting Group is a business name of The Trustee for Oracle Group Trading Trust ABN 11 220 978 749.

In this Privacy Policy, Oracle Accounting Group, Oracle, we, us and our refer to The Trustee for Oracle Group Trading Trust trading as Oracle Accounting Group.

We respect the privacy and confidentiality of the personal information entrusted to us.

This Privacy Policy explains how we collect, hold, use, disclose, protect and otherwise manage personal information in connection with:

  • our accounting, taxation, bookkeeping, business advisory, superannuation, corporate secretarial and related professional services;
  • company, trust and other entity establishment and administration services;
  • our obligations as a registered tax practitioner;
  • services that are subject to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth);
  • client onboarding, identity verification and customer due diligence;
  • our website, client portals, online forms and electronic communications;
  • enquiries from prospective clients;
  • our marketing and newsletters; and
  • our general business operations.

We manage personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and other laws that apply to particular information we handle.

Where we handle tax file number information, we also comply with the Privacy (Tax File Number) Rule 2015.

2. What is personal information?

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form.

Some information may also be subject to additional protections under taxation, professional, confidentiality, anti-money laundering and other laws.

3. Types of personal information we may collect and hold

The information we collect depends on our relationship with you and the services we provide.

It may include:

Identification and contact information

  • name;
  • date of birth;
  • residential, postal and business addresses;
  • telephone numbers;
  • email addresses;
  • occupation and employment details;
  • citizenship, residency and tax residency information; and
  • signatures.

Government and regulatory identifiers

Where reasonably necessary for our services or required or authorised by law, we may collect information such as:

  • tax file numbers;
  • Australian Business Numbers;
  • Australian Company Numbers;
  • Director Identification Numbers;
  • passport details;
  • driver licence details;
  • Medicare or other identification information where relevant to an authorised identity verification process; and
  • information held by taxation, corporate or other government authorities.

We will not use or disclose government-related identifiers except as permitted or required by law.

Financial, taxation and accounting information

This may include:

  • income and expense information;
  • taxation records and returns;
  • financial statements;
  • accounting records;
  • bank account details and transaction information;
  • loan and finance information;
  • investments and asset holdings;
  • superannuation information;
  • payroll and employment information;
  • business records;
  • property and capital gains tax information;
  • trust, company and partnership information;
  • beneficiary, shareholder, director, trustee and associate information; and
  • information relevant to taxation, accounting, business or financial reporting obligations.

Identity verification and AML/CTF information

Where we provide a service subject to anti-money laundering and counter-terrorism financing requirements, or where identity verification is otherwise required, we may collect information including:

  • copies or details of identity documents;
  • identity verification results;
  • beneficial ownership and control information;
  • information about directors, trustees, shareholders, beneficiaries, settlors, partners or other relevant persons;
  • information regarding the nature and purpose of a business relationship or transaction;
  • source of funds or source of wealth information where required;
  • information relevant to politically exposed person or sanctions screening;
  • information relevant to customer risk assessments; and
  • other information reasonably necessary to satisfy our customer due diligence, ongoing customer due diligence, reporting and record-keeping obligations.

We will limit our collection of this information to information reasonably necessary for our functions, activities and legal obligations.

Information about other people

Clients sometimes provide us with information concerning:

  • spouses and family members;
  • employees and contractors;
  • business partners;
  • beneficiaries;
  • trustees;
  • directors and shareholders;
  • professional advisers; and
  • other persons relevant to the work we have been engaged to perform.

If you provide us with personal information about another person, you should ensure that you are authorised to provide it to us and, where appropriate, make that person aware that their information may be provided to and handled by us.

Website and technology information

When you access our website or electronic systems, we or our service providers may collect information including:

  • IP address;
  • device and browser information;
  • pages viewed;
  • dates and times of access;
  • referring websites;
  • website interaction information;
  • cookies and similar technologies; and
  • information submitted through online forms, client portals or booking systems.

Enquiries and communications

We may keep records of:

  • emails;
  • telephone calls;
  • SMS messages;
  • meetings;
  • correspondence;
  • online enquiries;
  • complaints; and
  • other communications with you.

4. How we collect personal information

We generally collect personal information directly from you.

This may occur when you:

  • become or seek to become a client;
  • complete an online or paper form;
  • provide identification documents;
  • communicate with us by telephone, email, SMS, videoconference or in person;
  • use our website or client portal;
  • provide documents or accounting records;
  • authorise us to obtain information from another person or organisation;
  • accept a proposal or engagement; or
  • subscribe to communications from us.

We may also collect personal information from third parties where reasonably necessary or authorised or required by law, including:

  • the Australian Taxation Office;
  • the Australian Securities and Investments Commission;
  • other Commonwealth, State or Territory authorities;
  • banks and financial institutions;
  • superannuation funds;
  • auditors;
  • lawyers and other professional advisers;
  • previous accountants or advisers;
  • employers;
  • related entities;
  • publicly available registers and databases;
  • identity verification, sanctions and customer due diligence service providers; and
  • other persons authorised by you.

In some circumstances we may receive unsolicited personal information. We will determine whether we could lawfully have collected that information and will take appropriate steps in accordance with applicable privacy requirements.

5. Why we collect, use and disclose personal information

We may collect, use and disclose personal information where reasonably necessary to:

  • respond to enquiries;
  • assess whether we can act for you;
  • establish and administer our professional relationship with you;
  • provide accounting, taxation, bookkeeping, payroll, business advisory and related services;
  • prepare and lodge taxation, business, superannuation and regulatory documents;
  • communicate with the ATO, ASIC and other authorities on your behalf where authorised;
  • establish or administer companies, trusts, self-managed superannuation funds or other entities;
  • provide registered-office, corporate secretarial or related services;
  • undertake identity verification;
  • perform customer due diligence and ongoing customer due diligence;
  • comply with AML/CTF obligations;
  • identify and manage conflicts of interest;
  • comply with professional and ethical obligations;
  • manage our practice, records, billing and debt recovery;
  • maintain, secure and improve our systems;
  • prevent or investigate fraud, unlawful activity or security incidents;
  • manage complaints, disputes, insurance matters and legal claims;
  • satisfy audit, quality-control and professional-review requirements;
  • comply with taxation, corporations, superannuation, AML/CTF, court, regulatory or other legal requirements; and
  • otherwise carry out activities reasonably connected with our professional practice.

We may also use personal information for another purpose where:

  • you have consented;
  • you would reasonably expect us to do so and the law permits it; or
  • the use or disclosure is otherwise required or authorised by law.

6. Anti-money laundering and counter-terrorism financing

From 1 July 2026, certain professional services commonly provided by accountants and trust and company service providers are regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006.

Where Oracle provides a designated service, we may be required to:

  • verify the identity of customers and relevant associated persons;
  • determine beneficial ownership and control;
  • understand the nature and purpose of the proposed service or business relationship;
  • assess and manage money laundering, terrorism financing and proliferation financing risk;
  • conduct ongoing customer due diligence;
  • obtain additional information where required;
  • maintain prescribed records; and
  • make reports or provide information to AUSTRAC or another authority where required or authorised by law.

The law may restrict our ability to tell a person about particular AML/CTF reports, investigations or information. Nothing in this Privacy Policy requires us to provide information where doing so would contravene those restrictions.

7. Tax File Numbers

Tax file numbers are protected by taxation and privacy legislation.

We will only collect, use or disclose a tax file number where permitted by law and where reasonably necessary for an authorised taxation, superannuation or related purpose.

We will not use a person's tax file number as our own general-purpose identifier.

8. Disclosure of information

We may disclose personal information where reasonably necessary to provide our services, administer our practice or comply with our obligations.

Recipients may include:

  • the ATO;
  • ASIC;
  • AUSTRAC;
  • the Tax Practitioners Board;
  • State and Territory revenue offices;
  • superannuation funds;
  • auditors;
  • banks and financial institutions;
  • lawyers and other professional advisers;
  • actuaries and other specialists;
  • insurers and insurance advisers;
  • government agencies, courts and regulators;
  • software, cloud-hosting, data-storage and IT-security providers;
  • client portal, document-management and electronic-signature providers;
  • identity verification and AML/CTF service providers;
  • communications, email, SMS, videoconference and booking providers;
  • bookkeeping, administrative or other external service providers engaged by us;
  • payment-processing and debt-recovery providers; and
  • other persons where you have authorised the disclosure or where it is required or authorised by law.

We do not sell personal information.

Our professional obligations of confidentiality continue to apply to client information.

Where we use third-party service providers, we take reasonable steps appropriate to the circumstances to protect the confidentiality and security of information made available to them.

9. Overseas disclosure and processing

Some third-party technology, cloud, software, communications, identity-verification or other service providers used by us may store or process information outside Australia, or may use related entities or subcontractors located overseas.

Accordingly, personal information may in some circumstances be disclosed to, accessed from or processed in countries outside Australia.

The particular countries may change from time to time because cloud and technology providers may use distributed infrastructure and international subcontractors.

Where practicable, information about the likely countries in which a particular provider processes personal information can be obtained from us on request.

Where APP 8 applies to an overseas disclosure, we will take reasonable steps required by law to ensure the overseas recipient does not breach the APPs, subject to applicable exceptions.

10. Outsourcing and external service providers

We may engage appropriately qualified external service providers to assist in delivering services or operating our practice.

Where an external provider is given access to confidential or personal information, we take reasonable steps appropriate to the nature of the information and the service to protect its confidentiality and security.

Our use of external service providers does not remove our professional obligations to our clients.

Where our engagement terms require specific notification or consent in relation to outsourcing or third-party service providers, those engagement terms will also apply.

11. Security

We take reasonable steps to protect personal information from:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Depending on the circumstances, our safeguards may include physical, technical and organisational measures such as:

  • access controls;
  • multi-factor authentication;
  • encryption;
  • secure cloud and client-portal systems;
  • staff access restrictions;
  • security monitoring;
  • backups;
  • confidentiality requirements;
  • staff training;
  • secure document handling; and
  • procedures for responding to suspected data breaches.

No method of electronic transmission or storage can be guaranteed to be completely secure. We therefore cannot guarantee absolute security.

12. Data breaches

We maintain procedures for identifying, assessing and responding to suspected or actual data breaches.

Where the Notifiable Data Breaches scheme or another applicable law requires notification of an eligible data breach, we will make the required notifications to affected individuals and the Office of the Australian Information Commissioner or other relevant regulator.

13. Retention and destruction

We retain records for as long as reasonably necessary to:

  • provide our services;
  • satisfy taxation and accounting requirements;
  • comply with professional standards;
  • comply with AML/CTF and other regulatory requirements;
  • maintain appropriate evidence of the work performed;
  • manage legal or insurance risks; and
  • comply with other legal obligations.

Different categories of information may be subject to different retention periods.

Where personal information is no longer required for a permitted purpose and we are not required or authorised by law to retain it, we will take reasonable steps to destroy or de-identify it.

This includes considering whether copies of identification documents collected for identity verification or AML/CTF purposes continue to be required.

14. Direct marketing and newsletters

We may send clients and other persons information about:

  • taxation or regulatory developments;
  • our services;
  • firm news;
  • seminars or events; and
  • other matters we reasonably believe may be relevant.

We will only send commercial electronic messages where we have an appropriate basis to do so.

Electronic marketing communications will identify us and provide an appropriate means of unsubscribing.

You may ask us at any time not to send marketing communications to you.

We will not require you to receive marketing communications as a condition of receiving our professional services unless the communication itself is necessary for those services.

Service, compliance, appointment, billing and other non-marketing communications may still be sent where reasonably necessary.

15. Cookies, analytics and website technologies

Our website and third-party service providers may use cookies, analytics tools and similar technologies.

These technologies may be used to:

  • operate the website;
  • remember preferences;
  • understand website usage;
  • maintain security;
  • diagnose technical problems;
  • measure website performance; and
  • improve our website and services.

You can generally control cookies through your browser settings. Disabling some cookies may affect the functionality of the website.

Third-party websites, embedded content and services accessed through our website are governed by their own privacy practices.

16. Links to other websites

Our website may contain links to websites operated by third parties.

We do not control those websites and this Privacy Policy does not govern their handling of personal information.

You should review the privacy policy of a third-party website before providing personal information through it.

17. Automated systems and significant decisions

We may use software, artificial intelligence or automated tools to assist with administrative, accounting, data-processing, quality-control or other functions.

We do not treat the output of an automated tool as replacing the professional judgement required of us where professional judgement is necessary.

From 10 December 2026, where we arrange for a computer program to use personal information in a manner that triggers the automated-decision disclosure requirements in APP 1, this Privacy Policy will include the information required by those provisions, including the relevant kinds of personal information and decisions.

This provision should not be read as stating that Oracle currently uses automated systems to make decisions that significantly affect an individual's rights or interests.

18. Access to personal information

You may request access to personal information that we hold about you.

Subject to exceptions permitted by law, we will take reasonable steps to provide access in an appropriate manner.

We may need to verify your identity before providing access.

In some circumstances we may refuse access or provide only limited access, including where required or permitted by law, where the information relates to another person, or where professional confidentiality, legal privilege, AML/CTF restrictions or other legal obligations apply.

Where required, we will explain the basis for refusing access.

19. Correction of personal information

We take reasonable steps to ensure that personal information we use and disclose is accurate, up to date, complete and relevant.

If you believe information we hold about you is incorrect, incomplete or out of date, please contact us and request correction.

We may need to verify your identity and the accuracy of the proposed correction.

20. Privacy enquiries and complaints

If you have a question, concern or complaint about our handling of personal information, please contact:

Privacy Officer
Oracle Accounting Group
Suite 31, Level 2
89–97 Jones Street
Ultimo NSW 2007

Postal address:
PO Box 577
Haberfield NSW 2045

You may also contact us through the Contact Us page on our website or by telephone on 02 9715 2977.

Please provide sufficient details for us to understand and investigate your concern.

We will acknowledge and investigate privacy complaints and seek to respond within a reasonable period.

If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).

21. Anonymity and pseudonymity

Where practicable and lawful, you may interact with us anonymously or using a pseudonym.

However, this will generally not be possible where:

  • we need to identify you in order to provide professional services;
  • we are required to verify your identity;
  • taxation or regulatory requirements require identification;
  • AML/CTF customer due diligence applies; or
  • it would otherwise be impracticable for us to deal with you without knowing your identity.

22. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to:

  • our services;
  • our information-handling practices;
  • technology;
  • professional requirements; or
  • applicable laws and regulations.

The current version will be published on our website and will show its effective or last-updated date.

Material changes will not retrospectively authorise a materially different use of personal information where consent or another legal basis would be required.

Last updated: 01 September 2026


Stay Connected

Stay Updated!

Join Our Newsletter Today

First Name
Last Name
Email Address