Last Updated: June 19, 2026
While we are based in Australia and primarily serve Australian clients, we recognize that some visitors and clients may be located in the European Union. We are committed to protecting personal data in accordance with the General Data Protection Regulation (GDPR) principles.
This page outlines your rights under GDPR and explains how we handle personal data for EU residents who interact with our services.
We process personal data under the following legal bases:
Contractual Necessity: When you engage our services, we process your personal information to fulfill our contractual obligations, including delivering financial consultations and communicating service details.
Legitimate Interest: We may process data where necessary for our legitimate business interests, such as improving services, preventing fraud, or maintaining security, provided these interests do not override your rights.
Consent: For certain types of processing, such as marketing communications or optional data collection, we rely on your explicit consent, which you may withdraw at any time.
Legal Obligation: We process data where required to comply with legal or regulatory obligations, including financial record-keeping requirements.
You have the right to request confirmation of whether we process your personal data and to obtain a copy of that data. We will provide this information in a clear, commonly used format within 30 days of your request.
If you believe personal data we hold about you is inaccurate or incomplete, you have the right to request correction. We will respond to rectification requests promptly and update our records accordingly.
Also known as the "right to be forgotten," you may request deletion of your personal data in certain circumstances, such as when data is no longer necessary for its original purpose or when you withdraw consent.
This right is not absolute. We may need to retain certain data to comply with legal obligations, such as financial record-keeping requirements that mandate retention periods.
You can request that we limit how we use your personal data in specific situations, such as when you contest the accuracy of data or when processing is unlawful but you prefer restriction to deletion.
Where technically feasible, you have the right to receive your personal data in a structured, commonly used, machine-readable format. You may also request that we transfer this data directly to another service provider.
You may object to processing of your personal data when we rely on legitimate interests as the legal basis. We will cease processing unless we demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.
We do not currently employ automated decision-making or profiling that produces legal effects or similarly significant impacts on individuals. If this changes, we will update this policy and ensure appropriate safeguards.
To exercise any of these rights, contact us at [email protected] with "GDPR Request" in the subject line. Please include sufficient detail to help us identify your data and understand your request.
We will respond to requests within 30 days. If we need additional time due to request complexity or volume, we will inform you and may extend the response period by up to two additional months.
We may request additional information to verify your identity before fulfilling certain requests, particularly those involving access to or deletion of personal data.
As an Australian-based service, your personal data is primarily stored and processed in Australia. If we transfer data outside the EU for processing or storage, we ensure appropriate safeguards are in place, such as standard contractual clauses approved by the European Commission.
We carefully select third-party service providers and require them to implement adequate data protection measures consistent with GDPR principles.
In the event of a data breach that poses a risk to your rights and freedoms, we will notify you and relevant supervisory authorities without undue delay, typically within 72 hours of becoming aware of the breach.
Notifications will include the nature of the breach, likely consequences, and measures we have taken or propose to take to address the breach and mitigate harm.
If you are located in the EU and have concerns about how we handle your personal data, you have the right to lodge a complaint with your local data protection authority. A list of EU supervisory authorities is available on the European Data Protection Board website.
We encourage you to contact us first so we can attempt to resolve your concerns directly, but you have the right to approach a supervisory authority at any time.
Our services are not directed to individuals under 16 years of age. We do not knowingly collect personal data from children. If we become aware that we have collected data from a child without parental consent, we will take steps to delete that information promptly.
While we are not legally required to appoint a Data Protection Officer, we have designated a privacy contact responsible for overseeing GDPR compliance matters. You may direct GDPR-related inquiries to [email protected].
We review and update our GDPR compliance practices regularly to reflect changes in regulations, technology, or business operations. Updates will be posted on this page with a revised date.
Significant changes affecting how we process EU resident data will be communicated directly where possible.
For GDPR-related questions, data subject requests, or privacy concerns, contact us at:
Email: [email protected]
Location: Melbourne, Victoria, Australia