Purpose

Consent to Privacy Policy

Collection of personal information

Types of personal information we collect

  • Over the telephone or a video call (such as over Microsoft Teams, Zoom or Skype) e.g. when you contact our staff;
  • Through one of our digital platforms like our website, social media pages and app;
  • When you email or write to us; or
  • When you participate in a marketing campaign, competition or promotion (or a similar event) administered by us or our representatives. 
  • Name;
  • Date of birth;
  • Contact details (such as your email address, postal address, phone number);
  • Details relating to your use of any product and/or service offered by us;
  • Details of your enquiry;
  • Details of any preferences you tell us about (such as subscription preferences).
  • Publicly available sources e.g. via the internet;
  • Your professional advisers e.g. accountant.

Online device information and cookies

  • The date and time of visits;
  • Website page (or pages) viewed;
  • The website or app from which you accessed the internet and our website or other digital platform;
  • How you navigate through the website and interact with pages (including any fields completed in forms and applications completed (where applicable));
  • Information about your location;
  • Information about the device used to visit our digital platform; and
  • IP address (or addresses), and the type of web browser used;
  • Operating our contents management system;
  • Storing personal information for 90 days, so you do not have to re-enter information the next time you visit our website.

Purpose of collection and use of personal information

  • Check whether you are eligible for the product or services offered by us;
  • Facilitate those services, including helping you to find a financial adviser;
  • Verify your identity for security purposes;
  • Provide information that you request; and / or
  • Provide you with further information about our other products and services.

Storage and protection of your personal information

  • Access to information systems is controlled through identity and access management;
  • Our buildings are secured with a combination of locks, monitored alarms and cameras to prevent unauthorised access;
  • Employees are bound by internal information security policies and are required to keep information secure;
  • Employees are required to complete training about information security and privacy;
  • When we send information overseas or use service providers to process or store information, we put arrangements in place to protect your information;
  • We regularly monitor and review our compliance (and our service providers’ compliance) with internal policies and industry best practice;
  • We only keep information for as long as we need it, or as long as the law requires us to. We have a records management policy that governs how we manage our information and records to make sure we destroy any information that is outdated, irrelevant or unnecessary.

Cloud-based service providers

Timeframes for keeping personal information

If there is a privacy breach

  • Seek to quickly identify and secure the breach to prevent any further breaches and reduce the harm caused;
  • Assess the nature and severity of the breach, including the type of personal information involved and the risk of harm to affected individuals;
  • Advise and involve the appropriate authorities where criminal activity is suspected;
  • Where appropriate, notify any individuals who are affected by the breach (where possible, directly);
  • Where appropriate, put a notice on our website advising our clients of the breach; and
  • Notify the Privacy Commissioner.

Disclosure of your personal information

  • It is necessary to enable us to achieve the purpose that we collected the information for;
  • We are required or authorised by law or where we have a public duty to do so;
  • You have expressly consented to the disclosure or your consent can be reasonably inferred from the circumstances; or
  • We are permitted to disclose the information under the Privacy Act 2020.

Parties we may disclose your information to

  • Any out-sourced service provider who assists in the services we are required to carry out such as auditors and external compliance reviewers;
  • Our external dispute resolution service;
  • The Regulator;
  • Credit reporting and debt collecting organisations;
  • Invest Link’s related companies, including all Authorised Bodies.

Sending your information overseas

Third party websites

Domain name and email address

Right to access, correct and delete personal information

What happens if you do not provide us your information?

Changes to this Privacy Policy

Privacy Policy queries and concerns