1. Overview
Protecting our clients’ privacy matters to us. To comply with the Privacy Act 1988 (Cth) (the Privacy Act) and as part of our commitment to keeping your personal and confidential information safe, we have established and implemented this Privacy Policy.
The Privacy Act requires us to handle your personal information in accordance with a set of national principles — the Australian Privacy Principles (APPs) — which regulate the collection, use, correction, disclosure and transfer of personal information about individuals by organisations like ours in the private sector.
This Policy explains our practices with respect to the collection, use and management of your personal information, and our approach to the APPs. It applies to the business activities of Rahali Corporation Pty Ltd, its subsidiaries and associates (referred to in this Policy as “Rahali”, “us”, “our” or “we”) carried on in Australia. Where there is any inconsistency between this Policy and our statutory duties under Australian law, the law prevails.
2. Definitions
| Australian law | An Act of the Commonwealth, a State or Territory, or regulations or another instrument made under such an Act. |
|---|---|
| APP | The Australian Privacy Principles set out in Schedule 1 of the Privacy Act. |
| Breach | An act or practice contrary to or inconsistent with the Privacy Act, including an APP. |
| Consent | Express consent or implied consent. |
| Health information | Personal information about an individual’s health, expressed wishes about future health services, or a health service provided to them. |
| Know Your Customer (KYC) | The process of verifying a customer’s identity, as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), using reliable and independent documents and information. |
| Notifiable Data Breaches Scheme | The scheme under Part IIIC of the Privacy Act requiring us to notify affected individuals and the Australian Information Commissioner where a data breach is likely to result in serious harm. |
| Overseas recipient | A person who receives personal information who is not in Australia, is not us or an associate of ours, and is not the individual concerned. |
| Personal information | Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in material form or not. |
| Sensitive information | Personal information about racial or ethnic origin; political, philosophical or religious beliefs; memberships or affiliations; sexual orientation or practices; criminal record; health or genetic information; or biometric information. |
| TFN | A tax file number as defined in Part VA of the Income Tax Assessment Act 1936 (Cth). |
3. What information do we collect?
We collect and hold your personal information to:
- provide advice, products and services to you;
- manage and administer your products and services;
- verify your identity; and
- let you know about other products and services that may be relevant to you.
We may ask you to provide personal information such as your name, email address, residential and/or postal address, date of birth, telephone number, occupation, bank account details, financial details, employer, and tax file number (TFN). This is primarily collected from application forms you complete, your use of our online facilities, or through ongoing communications with you or people you authorise to speak with us on your behalf.
In specific circumstances we will ask for your consent to provide sensitive information, such as:
- health information when you apply for insurance, or from medical practitioners when you make a claim;
- income information from employers when you apply for additional insurance protection or salary continuance insurance; and
- details of your dependants (as defined at section 10 of the Superannuation Industry (Supervision) Act 1993 (Cth)), to pay benefits in the event of your death.
Whenever you acquire a new product or service from us, we will require documents evidencing your identity — for example, a certified copy of your driver’s licence, passport or birth certificate. We will tell you where a legal requirement exists to collect this information, and the consequences of not providing it.
We will only solicit personal information about you where you have knowingly provided it to us, we believe you have authorised a third party to provide it, or we are legally obliged to obtain it. Relevant third parties may include your employer, accountant, solicitor, product issuer, or identity verification service providers used for KYC purposes.
4. How do we use your information?
We use your personal information for the purpose it was collected and for related purposes, including to:
- provide financial advice and credit assistance to you;
- establish and manage your investments, accounts and loans;
- implement your investment or lending instructions;
- establish and maintain insurance protection;
- process contributions, transfer monies or pay benefits;
- report on the performance of your account; and
- keep you up to date on other products and services that may interest you (you can unsubscribe from marketing communications at any time via the link in the message).
5. Who do we disclose your information to?
Where we disclose your personal information to external parties, strict controls apply to ensure it is held, used and disclosed in accordance with the APPs. We may disclose your information to:
- organisations involved in providing, managing or administering our products or services, such as actuaries, custodians, external dispute resolution services, insurers, investment managers, product issuers, alliance partners or mail houses;
- your financial adviser, employer (for employer-sponsored superannuation only), or a fund to which your benefit is transferred or rolled over;
- medical practitioners and other relevant professionals, where you have applied for insurance or made a disablement claim;
- your personal representative, or a person entitled to receive your death benefit;
- financial institutions that hold accounts for you;
- professional advisers appointed by us; and
- businesses that referred you to us.
We may also disclose your information where required or authorised by law (for example to the Australian Taxation Office or under a court order), where necessary to discharge our obligations, to assist law enforcement, or with your consent.
6. Will my information be disclosed overseas?
It is generally unlikely that we will disclose your personal information overseas. We may occasionally use third-party service providers or offshore outsourcing services, in which case the relevant countries will vary depending on the provider engaged at the time. Any overseas disclosure does not affect our commitment to protecting your information, and we will take reasonable steps to ensure any overseas recipient complies with the APPs — including seeking your consent or ensuring appropriate contractual protections are in place, in line with our obligations under Australian privacy law.
7. Access and correction of your information
You may request access to the personal information we hold about you (we may charge a reasonable fee to cover our costs). If we’re unable to give you access, we’ll explain why. We take reasonable steps to keep the personal information we hold accurate, complete, up to date and relevant.
You have a right to ask us to correct information you believe is inaccurate, incomplete, out of date, irrelevant or misleading. If we decline to make a correction, we’re required to give you written reasons and a statement on request. To access or correct your information, contact the Privacy Officer using the details in section 12.
8. Keeping your information secure
We maintain security systems, practices and procedures to safeguard your privacy, and may use cloud storage or third-party servers, subject to regular audit. People who handle your personal information are trained to protect it from unauthorised access, disclosure or misuse.
Internet risk: transmitting information over the internet carries inherent security risks. If you’d prefer not to transmit information through our website, you can contact us directly by phone or mail instead (see section 12).
Cookies: our website may use cookies and analytics tools that help us understand how the site is used. You can control cookies through your browser settings; declining cookies may affect some website functionality.
9. Retention of your information
We’re required by law to retain certain records for varying periods, and in some cases permanently. Where information is no longer required for the purpose it was collected, and retention is not required by law, we take reasonable steps to irrevocably destroy or de-identify it.
10. If you reside in the European Economic Area
If you reside in a country that is a member of the European Economic Area, in addition to your protections under the Privacy Act, you may be entitled to protections under the General Data Protection Regulation (EU) 2016/679 (GDPR), including in certain circumstances the right to have your personal information erased, to access it in an electronic and portable format, and to restrict or object to its processing. Complaints about a breach of the GDPR can be directed to the relevant local regulator in your European Economic Area country.
11. Complaints and data breaches
If you believe we’ve breached the APPs by mishandling your information, you may lodge a written complaint with the Privacy Officer (section 12). We will respond within 30 days of receipt.
If the Privacy Officer is unable to resolve your complaint, you may lodge a Privacy Complaint Form with the Office of the Australian Information Commissioner (OAIC).
In accordance with the Notifiable Data Breaches Scheme, if your personal information is involved in a data breach likely to result in serious harm, we will notify you and the Australian Information Commissioner.
12. Contacting the Privacy Officer
Privacy Officer
Rahali Corporation Pty Ltd
Mail: PO Box 23052, Docklands VIC 8012
Email: ranjit@rahali.com
Phone: 0414 502 171
13. Policy governance
Unless required earlier, this Policy is reviewed annually by the Privacy Officer. Amendments must be approved by the Rahali Corporation Pty Ltd Director(s). The most current version is always available on this page at rahali.com/privacy.html. Questions about this Policy should be directed to the Privacy Officer using the contact details above.