Privacy Policy

Home / Privacy Policy

Privacy Policy

Tradewise Solutions Pty Ltd

Last updated: September 2026

1. Our commitment to privacy

Tradewise Solutions Pty Ltd (Tradewise Solutions, we, us or our) is an Australian accounting, taxation and business advisory practice.

We recognise that our clients entrust us with highly confidential personal, taxation, financial and business information. Protecting that information is an important part of our professional responsibilities.

This Privacy Policy explains how we collect, hold, use, disclose and protect personal information and how individuals may access or correct their information or make a privacy complaint.

We handle personal information in accordance with applicable laws and professional obligations, including where relevant:

  • the Privacy Act 1988 (Cth) and Australian Privacy Principles;
  • the Privacy (Tax File Number) Rule 2015;
  • the Tax Agent Services Act 2009 and the TPB Code of Professional Conduct;
  • applicable requirements and guidance of the Tax Practitioners Board;
  • applicable professional and ethical standards, including APES 110 Code of Ethics for Professional Accountants;
  • applicable taxation, corporations and superannuation legislation;
  • our obligations when acting as an ASIC registered agent; and
  • the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 and associated Rules where those obligations apply to services we provide.

APES 110 includes confidentiality as one of the fundamental principles applying to professional accountants.

2. What is personal information?

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Because of the nature of accounting and taxation services, some of the information we handle may be particularly sensitive or confidential.

The information we collect depends on our relationship with you and the services you request.

3. Types of personal information we may collect

We may collect and hold information including:

  • your name;
  • date of birth;
  • residential, postal and business addresses;
  • telephone numbers and email addresses;
  • occupation and employment information;
  • Tax File Number;
  • Australian Business Number;
  • Director Identification Number information where relevant;
  • identity verification information;
  • information contained in identification documents;
  • taxation information;
  • income and employment records;
  • bank account and financial information;
  • business accounting records;
  • financial statements and reports;
  • assets and liabilities;
  • investments and shareholdings;
  • property ownership and investment-property information;
  • directorships and company interests;
  • trust, partnership and company information;
  • superannuation and self-managed superannuation fund information;
  • payroll and employee information supplied to us in connection with client services;
  • loan and financing information;
  • transaction information;
  • correspondence with government agencies;
  • correspondence, emails, messages and records of communications with you;
  • information relating to professional engagements;
  • proof-of-identity and customer due diligence information;
  • information required for AML/CTF compliance where applicable;
  • information concerning beneficial owners, controllers, trustees, directors or other relevant persons associated with an entity; and
  • any other personal information reasonably necessary for us to provide our professional services or comply with legal and professional obligations.

Our existing policy already recognises that the practice handles tax, business and SMSF information, but this revised description more accurately reflects the range of information an accounting practice may handle.

4. Sensitive information

In limited circumstances, we may collect sensitive information where:

  • it is reasonably necessary for our functions or activities;
  • you have consented to the collection;
  • collection is authorised or required by law; or
  • another permitted situation applies.

Sensitive information may include information relating to health, criminal history or other matters where relevant to a particular engagement, employment process or legal or regulatory requirement.

We will not routinely collect sensitive information where it is unnecessary for the services being provided.

5. Tax File Number information

As a registered tax practice, we may be authorised to collect, use and disclose Tax File Numbers and TFN information.

TFN information is subject to specific legal protections.

We will only collect, use or disclose TFN information where permitted by taxation, superannuation or other applicable laws and the Privacy (Tax File Number) Rule 2015.

We take reasonable steps to:

  • limit access to TFN information to authorised persons;
  • protect TFN information against unauthorised access, use or disclosure;
  • avoid unnecessary disclosure of TFNs;
  • securely store TFN information; and
  • securely destroy or de-identify TFN information when we are no longer required or permitted to retain it.

TFN information will not be used for marketing purposes.

6. How we collect personal information

Where practicable, we collect personal information directly from you.

We may collect information when you:

  • contact us;
  • enquire about our services;
  • become a client;
  • complete an online or paper form;
  • provide records or documents;
  • communicate with us by telephone, email, post, SMS, video conference or other electronic means;
  • attend a meeting with us;
  • use our website;
  • upload information through a portal or electronic platform;
  • authorise another person to provide information on your behalf; or
  • otherwise interact with our practice.

Our current policy already identifies online forms, email, telephone and virtual conferencing as methods of collection.

7. Information collected from third parties

We may sometimes collect information about you from another person or organisation where this is authorised, reasonably necessary or permitted by law.

Sources may include:

  • the Australian Taxation Office;
  • Australian Securities and Investments Commission;
  • Australian Business Registry Services;
  • AUSTRAC;
  • other government departments or regulators;
  • your employer;
  • banks and financial institutions;
  • superannuation funds;
  • companies, trusts, partnerships or other entities with which you are associated;
  • your authorised representative;
  • lawyers;
  • financial advisers;
  • bookkeepers;
  • auditors;
  • finance brokers;
  • previous accountants or tax agents where authorised;
  • credit reporting or identity-verification services where lawfully used;
  • publicly available registers; and
  • other professional or service providers involved in an engagement.

Where required by the Australian Privacy Principles, we will take reasonable steps to notify you of relevant matters relating to collection.

APP 5 requires notification about matters such as the purposes of collection, usual disclosures, applicable laws and likely overseas disclosure.

8. Why we collect and use personal information

We may collect, hold and use personal information for purposes including:

  • providing accounting services;
  • preparing financial statements;
  • providing taxation services;
  • preparing and lodging tax returns;
  • preparing and lodging activity statements;
  • providing business advisory services;
  • providing bookkeeping or payroll services where engaged;
  • administering superannuation or SMSF-related engagements;
  • providing ASIC-related corporate services;
  • preparing and lodging documents with ASIC;
  • dealing with government agencies;
  • undertaking trust-account examination or audit-related engagements where applicable;
  • responding to enquiries;
  • establishing and administering client engagements;
  • verifying identity;
  • conducting customer due diligence;
  • identifying beneficial owners and controllers;
  • assessing money-laundering and terrorism-financing risk where required;
  • complying with AML/CTF obligations;
  • satisfying professional, ethical and regulatory requirements;
  • maintaining appropriate client records;
  • checking conflicts of interest;
  • managing independence requirements where applicable;
  • communicating with you;
  • providing invoices and administering payments;
  • managing our business;
  • maintaining, securing and improving our technology systems;
  • preventing fraud, identity theft and cybercrime;
  • managing complaints;
  • complying with legal obligations; and
  • protecting our legal and professional rights.

If you do not provide information reasonably required for these purposes, we may be unable to provide some or all of the requested services.

9. Professional confidentiality

In addition to our obligations under privacy law, we are subject to professional duties concerning confidentiality.

Information obtained through our professional relationships is treated as confidential.

We do not disclose information relating to a client’s affairs to a third party unless:

  • the client has provided the required permission;
  • disclosure is reasonably necessary and permitted as part of an authorised engagement;
  • we have a legal duty or legal authority to disclose it;
  • a professional right or duty to disclose applies; or
  • disclosure is otherwise permitted by applicable law and professional standards.

The TPB’s Code item 6 specifically provides that a registered tax practitioner must not disclose information relating to a client’s affairs to a third party without the client’s permission unless there is a legal duty to do so. The TPB regards outsourced providers and cloud-storage providers as potentially being third parties for this purpose.

Our professional confidentiality obligations may continue after a client engagement has ended.

10. Disclosure to third parties

Subject to our confidentiality obligations, we may disclose personal information where authorised, reasonably necessary to provide our services, or required or permitted by law.

Recipients may include:

  • Australian Taxation Office;
  • ASIC;
  • ABRS;
  • AUSTRAC;
  • state and Commonwealth government agencies;
  • courts and tribunals;
  • financial institutions;
  • superannuation funds;
  • lawyers;
  • auditors;
  • external examiners;
  • actuaries;
  • financial advisers;
  • finance brokers;
  • professional consultants;
  • identity-verification service providers;
  • software providers;
  • document-management providers;
  • secure cloud-storage providers;
  • information-technology and cybersecurity providers;
  • contractors assisting us in delivering services;
  • professional bodies where disclosure is authorised or required;
  • regulators and law-enforcement agencies; and
  • another professional adviser where you have authorised us to communicate with them.

We do not sell your personal information.

11. Outsourcing and service providers

We may use external service providers to assist in operating our practice and providing professional services.

Examples may include providers of:

  • accounting and taxation software;
  • document-management systems;
  • cloud storage;
  • email and communications services;
  • client portals;
  • electronic signatures;
  • identity verification;
  • cybersecurity services;
  • data backup;
  • website hosting;
  • practice-management systems; and
  • information technology support.

Where disclosure of client information to a third party requires client permission under our professional obligations, we will obtain or document that permission through an appropriate mechanism, which may include our engagement terms.

The TPB specifically states that outsourcing arrangements and offsite/cloud storage can constitute disclosure to a third party for confidentiality purposes.

12. Overseas recipients and storage

Some technology, cloud, software or service providers used by our practice may operate, process information or store information outside Australia.

Where personal information is likely to be disclosed to an overseas recipient, we will take reasonable steps to comply with applicable requirements of the Privacy Act, including APP 8.

Where practicable, our privacy notices will identify the countries in which overseas recipients are likely to be located.

OAIC guidance requires an APP Privacy Policy to state whether personal information is likely to be disclosed overseas and, where practicable, identify the countries concerned.

Before publishing this section, Tradewise Solutions should maintain a current list of any relevant overseas locations used by its principal cloud, software or outsourced providers.

13. AML/CTF information

Where we provide a service that is a designated service under Australian AML/CTF legislation, we may be required to collect and handle additional information.

This may include information needed to:

  • identify and verify customers;
  • identify and verify beneficial owners;
  • identify persons acting on behalf of customers;
  • understand ownership and control structures;
  • determine the nature and purpose of a business relationship;
  • assess money-laundering, terrorism-financing and proliferation-financing risks;
  • undertake ongoing customer due diligence;
  • monitor transactions or behaviour where required;
  • undertake enhanced customer due diligence where required;
  • comply with regulatory reporting requirements; and
  • maintain records required by AML/CTF legislation.

From 1 July 2026, the AML/CTF regime applies to relevant designated professional services provided by accountants, among other professional-service businesses.

14. AML/CTF disclosures and regulatory reporting

In some circumstances, AML/CTF legislation may require or authorise us to provide information to AUSTRAC or other relevant authorities.

This can include regulatory reporting required under the AML/CTF legislation.

Where we have a legal duty to provide information, we may make the required disclosure without seeking separate consent.

Nothing in this Privacy Policy limits or overrides our legal reporting obligations.

15. Suspicious matter information

Information relating to a suspicious matter is handled in accordance with applicable AML/CTF legislation and our internal AML/CTF procedures.

Access to such information is restricted to authorised persons and it may be disclosed where required or authorised by law.

AUSTRAC requires reporting entities to maintain procedures for identifying, reviewing and reporting suspicious matters.

16. Identity verification

We may verify your identity where necessary to:

  • protect against identity fraud;
  • meet ATO or TPB requirements;
  • meet ASIC-related requirements;
  • satisfy AML/CTF customer due diligence requirements;
  • meet other regulatory requirements; or
  • ensure that we act only on properly authorised instructions.

We may use electronic identity-verification providers where appropriate.

Where possible, we seek to avoid retaining unnecessary copies of identification documents.

The TPB does not generally require or recommend tax practitioners to retain copies of identity documents merely for TPB proof-of-identity purposes, although it does require appropriate records of the identity checks performed.

Where AML/CTF legislation applies, we retain the records required by that legislation.

17. Use of artificial intelligence and technology-assisted tools

We may use technology-assisted tools, including artificial intelligence tools, where appropriate in operating our practice or assisting with professional work.

Where such tools are used, we remain responsible for the professional services we provide.

We take reasonable steps to ensure that use of technology is consistent with our obligations concerning:

  • confidentiality;
  • privacy;
  • professional competence;
  • reasonable care;
  • supervision;
  • professional judgment;
  • record keeping; and
  • information security.

We do not regard the use of an AI tool as removing or reducing our professional responsibilities.

Where use of an external AI service would involve disclosure of identifiable client information to a third party, we will consider our legal and professional confidentiality obligations before such disclosure.

The TPB’s 2026 AI guidance specifically confirms that existing Code obligations concerning confidentiality, competence, reasonable care, record keeping, professional judgment and supervision continue to apply when AI is used.

18. Security of personal information

We take reasonable technical, organisational and physical steps to protect information from:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

Security measures may include, depending on the circumstances:

  • password protection;
  • multi-factor authentication;
  • restricted access permissions;
  • role-based access controls;
  • secure cloud infrastructure;
  • encrypted transmission or storage where appropriate;
  • cybersecurity software and monitoring;
  • secure backups;
  • staff confidentiality requirements;
  • staff training;
  • secure document disposal;
  • physical security;
  • access logging;
  • secure portals; and
  • due diligence over technology providers.

No electronic system can be guaranteed to be completely secure, but we take reasonable steps appropriate to the nature and sensitivity of the information we hold.

19. Data breaches

We maintain procedures for identifying, assessing and responding to suspected or actual data breaches.

Where a breach is likely to result in serious harm and the requirements of the Notifiable Data Breaches scheme are satisfied, we will take the steps required by the Privacy Act, which may include notifying affected individuals and the Office of the Australian Information Commissioner.

20. Record keeping and retention

We retain records for periods required by applicable laws, professional standards, regulatory requirements and legitimate business purposes.

Different records may therefore have different retention periods.

For example:

  • records relating to tax agent or BAS agent services that fall within the TPB record-keeping requirements must generally be retained for at least five years after the relevant service has been provided;
  • TPB proof-of-identity records are generally required to be retained for a minimum of five years after an engagement has ceased;
  • companies may be required under corporations legislation to retain particular financial records for seven years; the TPB also notes this separate ASIC record-keeping requirement;
  • AML/CTF records may be subject to seven-year retention periods, including customer due diligence and relevant transaction records.

Other statutory or professional retention requirements may also apply.

Accordingly, we do not apply a single retention period to every document or item of personal information.

When information is no longer required for any permitted purpose and we are not legally or professionally required to retain it, we take reasonable steps to destroy or permanently de-identify it.

This replaces the overly broad statement in the existing policy that all information is held for a statutory minimum of six years.

21. Website information

When you use our website, certain information may be collected automatically.

This may include:

  • IP address;
  • browser type;
  • device type;
  • operating system;
  • date and time of access;
  • referring website;
  • pages viewed;
  • website interactions; and
  • general location or usage information derived from technical data.

We may use this information for:

  • website operation;
  • cybersecurity;
  • fraud prevention;
  • diagnostics;
  • analytics;
  • website improvement;
  • user experience;
  • performance monitoring; and
  • measuring marketing effectiveness.

22. Cookies and analytics

Our website may use cookies and similar technologies.

Cookies may be used to:

  • enable website functionality;
  • remember preferences;
  • improve website performance;
  • understand how visitors use our website;
  • detect security threats;
  • measure website traffic; and
  • support marketing and analytics functions.

You can generally modify your browser settings to restrict or disable cookies. Some website functions may not operate correctly if cookies are disabled.

We may use analytics services, including services provided by third parties, subject to our privacy and confidentiality obligations.

23. Embedded content and third-party websites

Our website may include links to or embedded content from third-party services, including maps, videos, social networks or other websites.

Those services may collect information independently from us and are governed by their own privacy policies and practices.

We are not responsible for the privacy practices of external websites or services that we do not operate.

24. Online forms

Information submitted through our website forms may be used to:

  • respond to your enquiry;
  • assess whether we can assist you;
  • establish a professional engagement;
  • verify your identity;
  • undertake regulatory checks;
  • provide requested services; and
  • comply with our legal and professional obligations.

Where a form collects substantial personal information, we may provide a separate privacy collection notice explaining the particular collection.

A general Privacy Policy does not necessarily replace the notification obligations that arise when information is collected; APP 5 requires reasonable steps to notify individuals of relevant collection matters.

25. Direct marketing

Where permitted by law, we may use your contact information to send you information concerning:

  • taxation updates;
  • accounting or business information;
  • changes in law or regulation;
  • Tradewise Solutions services; and
  • other information that may reasonably be relevant to our clients.

You may opt out at any time by:

  • using an unsubscribe link contained in an electronic marketing communication; or
  • contacting us.

We will respect valid opt-out requests.

We will not use TFN information, identity documents, sensitive information or confidential taxation information for direct marketing.

26. Testimonials and reviews

Where you provide a testimonial or expressly authorise us to use a review, we may publish the information you have authorised for marketing purposes.

This may include your:

  • name;
  • business name;
  • photograph or image; and
  • testimonial or review.

We will only publish personally identifiable testimonial material where we have an appropriate basis to do so, including consent where required.

27. Social media

We may use social-media platforms such as LinkedIn, Facebook or Instagram to communicate with the public.

If you communicate with us through social media, we may receive personal information associated with that communication.

Social-media platforms separately collect and handle information under their own privacy policies.

Information you publish publicly on social media may be visible to other users.

28. Access to personal information

You may request access to personal information that we hold about you.

We may require reasonable evidence of your identity before providing access.

Access may be refused or limited where permitted or required by law, including where providing access would:

  • unreasonably affect another person’s privacy;
  • disclose legally privileged material;
  • reveal commercially sensitive information in circumstances protected by law;
  • prejudice an investigation; or
  • otherwise fall within an applicable legal exception.

Where required, we will provide reasons for refusing access.

29. Correction of personal information

We take reasonable steps to ensure personal information we use or disclose is accurate, up to date, complete and relevant.

If you believe information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it.

We may verify your identity and the requested correction before making changes.

30. Requests for deletion

You may contact us if you want information about whether personal information can be deleted.

A request for deletion does not override our obligations to retain records under taxation, TPB, corporations, AML/CTF, professional or other applicable laws.

Where we are legally required to retain information, we may be unable to delete it until the relevant retention period has expired.

31. Privacy complaints

If you believe we have mishandled your personal information or breached an applicable privacy obligation, please contact our Privacy Officer.

Your complaint should provide sufficient information for us to understand the issue and investigate it.

We will:

  • acknowledge the complaint;
  • assess and investigate the matter;
  • request further information if reasonably necessary; and
  • provide a response within a reasonable period.

If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).

The Australian Privacy Principles require privacy policies to explain both how individuals can complain and how the entity will deal with those complaints.

32. Professional and regulatory complaints

Depending on the nature of a matter, you may also have rights to contact an applicable professional or regulatory body.

Nothing in this Privacy Policy limits any right you may have to contact a regulator, professional body or government authority.

33. Changes to this Privacy Policy

We may update this Privacy Policy periodically to reflect changes in:

  • law;
  • professional standards;
  • regulatory requirements;
  • our services;
  • technology;
  • business practices; or
  • information-handling arrangements.

The current version will be published on our website together with the date it was last updated.

34. Contact us

If you:

  • have a question about this Privacy Policy;
  • wish to request access to personal information;
  • wish to correct your personal information;
  • wish to make a privacy complaint;
  • wish to withdraw from marketing communications; or
  • have another privacy-related enquiry,

please contact:

Privacy Officer
Tradewise Solutions Pty Ltd
105/566 St Kilda Road
Melbourne VIC 3004
Australia

Telephone: 1300 240 100
Email: info@tradewises.com.au

Scroll to Top