Privacy Policy
Last updated: 26 March 2026 | Diwan & Co. (ABN 85 100 846 998)
Contents
- 1. Purpose of the Policy
- 2. Acknowledgement
- 3. Collection of Personal Information
- 4. How We Use Personal Information
- 5. Unsolicited Information
- 6. Disclosure of Personal Information
- 7. Overseas & Data Retention
- 8. Accessing Your Information
- 9. Exceptions Under Law
- 10. Information Security
- 11. Data Retention
- 12. Cloud Computing Services
- 13. Loss of Personal Information
- 14. Website Security
- 15. Credit Reporting
- 16. Updating Your Information
- 17. Privacy Enquiries
- 18. Privacy Complaints
- 19. Further Information
- 20. Changes to This Policy
1. Purpose of the Policy
This Privacy Policy applies to A The Trustee for The Diwan Discretionary Trust (ABN: 85 100 846 998) T/A Diwan & Co ("Diwan & Co") and describes the personal information that may be collected by us, the choices you make about your personal information and how we protect your information.
Diwan & Co is bound by the Privacy Act 1988 (Cth) ("Privacy Act"), including any relevant privacy code registered under the Privacy Act. Diwan & Co is committed to complying with the Privacy Act in relation to all personal information we collect and committed to protecting the privacy of personal information obtained through its professional service operations.
The Privacy Act incorporates the Australian Privacy Principles (APPs) which set out the way in which personal information must be treated. Disclosure of such information may be compelled by law (for example, under the Social Security Act 1991 (Cth)).
This Privacy Policy governs the Diwan & Co business and applies to any person for whom we currently hold, or may in the future collect, personal information (whether or not a client of Diwan & Co). This policy does not apply to matters which relate directly to the employee records of our current and former employees. In general terms, 'personal information' is information or opinions relating to a particular identifiable individual. Information or opinions are not personal information where they cannot be linked to a particular individual.
2. Acknowledgement of Diwan & Co's Privacy Policy
By accessing the website you accept the terms of this Privacy Policy and you understand that this Privacy Policy applies to information provided to us whether via the website or through any other means. By using the Diwan & Co website, you acknowledge to have read and understood this Privacy Policy. This Privacy Policy does not extend your rights or Diwan & Co obligations beyond those defined by the Privacy Act.
By your use of the website and our professional services, you consent to the collection, storage, use and disclosure of your personal information in accordance with this Privacy Policy and as otherwise permitted under the Privacy Act.
Should there be any inconsistencies between this policy and the Privacy Act, this Privacy Policy shall be interpreted to give effect and comply with the Privacy Act.
The Diwan & Co website contains links to non Diwan & Co websites. Diwan & Co is not responsible for the Privacy Policies of those other websites and Diwan & Co recommends that you should review the Privacy Policies of those other websites.
3. Collection of Personal Information
Diwan & Co collects personal information that is reasonably necessary for, or directly related to, its professional services. The types of personal information that Diwan & Co may collect and hold includes the following:
- Name
- Contact number
- Personal or Business email address
- Personal or Business mailing address
- Title
- Nature of business
- Financial records
- Financial information (including information about assets and investments, banking and credit card information)
- Tax File Numbers
- Qualifications, memberships and other accreditations
- Advice received from client or prospective client that may contain additional personal information, such as business-related connections and familial relationships
Diwan & Co only collects personal information that has been directly provided to Diwan & Co by clients or prospective clients, associates of clients, suppliers or potential suppliers, Diwan & Co employees or potential employees or otherwise personal information available in the public domain where such information will assist Diwan & Co with the provision of services to Diwan & Co's current or prospective clients. Personal information may have been provided in writing or verbally.
If clients or prospective clients do not provide personal information when requested, Diwan & Co may not be able to deliver the service that is required. Diwan & Co will endeavour to make this as clear as possible for each service. Diwan & Co will collect personal information from the user by lawful and fair means.
We manage the personal information we collect by implementing appropriate privacy management systems when dealing with your personal information, reviewing our privacy compliance from time to time and implementing security measures (such as unique usernames and passwords on our computer systems) to safeguard the personal information we collect. We will comply with our professional obligations (including confidentiality obligations) in dealing with your personal information at all times.
It is generally impracticable for Diwan & Co to deal with individuals on an anonymous basis or through the use of a pseudonym (an alias), although sometimes this is possible where it is lawful.
'Sensitive information' is a subset of personal information that includes personal information that could have serious ramifications for you if used inappropriately. You consent and agree that the sensitive information that we collect and hold about you will include any information necessary so that we can provide our professional services to you. We will not collect sensitive information without your consent unless permitted under the Privacy Act or in accordance with law.
4. How We Use Personal Information
The main purposes for which Diwan & Co collect, hold and use personal information are:
- To maintain contact with clients
- To keep clients and contacts informed of the services that Diwan & Co offers and of any current developments and updates such as changes of business hours
- For administration and management purposes
- To provide users with information about other services that Diwan & Co offers and that may be relevant to the user
- Other purposes that are related to Diwan & Co's business
If Diwan & Co collects, holds or uses personal information in ways other than as stated in this Privacy Policy, Diwan & Co will ensure to collect, hold or use personal information pursuant to the requirements of the Privacy Act.
Employee records are not generally subject to the Privacy Act and therefore this policy may not apply to the handling of information about employees of Diwan & Co.
5. Unsolicited Information
"Unsolicited" personal information is personal information about an individual that Diwan & Co has unintentionally received. This is not a common occurrence for Diwan & Co but when it does occur, Diwan & Co will seek to ensure to protect such personal information with the same rigour applied to personal information that Diwan & Co intended to collect.
6. Disclosure of Personal Information
Personal information is not disclosed to any third party unless the disclosure is:
- Required by law, rules and regulations and/or professional standards
- Necessary to provide the client or prospective clients with the product or service requested
- To protect the rights, property and personal safety of a Diwan & Co client, prospective client, the public and the interests of Diwan & Co
- Given with consent
Should it be necessary for Diwan & Co to forward personal information to third parties, Diwan & Co will make every effort to ensure that the confidentiality of the information is protected.
7. Overseas, Interstate and Data Retention Disclosures
Diwan & Co's Administration, Business Improvement, Accounting & Bookkeeping operations may occur interstate and/or overseas. All outsourced consultants who may require access to client records in order to carry out their duties are required to sign a host agreement before beginning any work on our behalf, and are bound by the Australian Privacy Principles as set out in section 7 of our privacy policy which is accessible at the bottom of our website home page www.diwanco.com.au.
As a result, Diwan & Co may at times require the exchange of personal information of Diwan & Co's clients and/or prospective clients between locations and firms. In the event that personal information is disclosed to overseas recipients, Diwan & Co will take all reasonable steps to ensure that any personal information is secure and is treated in accordance with the Australian Privacy Principles. The personal information may be transferred to countries whose privacy laws do not provide the same level of protection as compared to Australia's privacy laws.
We hold, or may hold your personal information electronically, physically, on our premises, in off-site storage facilities in Australia, by a third party data storage facilitator and/or provider in Australia and/or overseas (including but not limited to international cloud computing services in overseas countries including but not limited to Philippines and the United States Of America), through various third party providers such as: G-suite, AcuityScheduling, Xero suite, Airtable, Miro, MailerLite, Slack, Quickbooks, Teamwork Projects & Chat, SignNow, Docusign, Now Infinity, BGL, MYOB, Integrapay, Loom, Adobe, Office 365, Hubspot, Hubdoc, Dropbox, Practice Ignition, Integromat, UiPath, Dialpad Phone and Meetings, by an email filtering host in Australia and/or overseas, through internal servers, our website, private cloud, as well as on electronic storage devices, including DVD and USB.
Whilst we take reasonable steps to ensure that all personal information that we hold is secure from any unauthorised access, misuse or disclosure, no data transfer over the internet is ever one hundred percent (100%) secure and we cannot guarantee that personal information cannot be accessed by an unauthorised person or that unauthorised disclosures will not occur. If you send any information (including personal information) to us through the internet or through any other electronic means, you do so at your own risk.
You hereby consent to the disclosure of your personal information to overseas recipients in the knowledge that we will not take any steps to ensure that the overseas recipient deals with your personal information in accordance with the Australian Privacy Principles. Accordingly, should such overseas recipient handle the information in breach of the Australian Privacy Principles, you may not be able to seek redress in the overseas jurisdiction and we will not be accountable under the Privacy Act.
8. Accessing Your Personal Information
Users have the right to request access to the personal information that Diwan & Co holds about such user. This right is subject to certain exceptions allowed by law.
Upon your request and subject to applicable privacy laws, Diwan & Co will provide you with access to your personal information that is held by Diwan & Co. You must thoroughly identify the types of information you are requesting. Diwan & Co will deal with your request within a reasonable time — usually within 30 days from the date of the request. Diwan & Co may also recover from you any reasonable costs incurred in supplying you with access to your personal information.
9. Exceptions Under Law
You do not have an absolute right to access personal information. The law permits Diwan & Co to refuse your request to provide you with access to your personal information, such as circumstances where:
- Access would be unlawful
- Access would pose a serious threat to the life or health of any individual
- Access would have an unreasonable impact on the privacy of others
- Access may prejudice enforcement activities, a security function or commercial negotiations
10. Information Security
Diwan & Co will take all reasonable steps to protect against the loss, alteration and/or misuse of any personal information under Diwan & Co's control. Diwan & Co is committed to keeping your trust by protecting your personal information.
Diwan & Co employs the most appropriate technical, administrative and physical procedures to protect the security of your personal information. Diwan & Co only keeps personal information for as long as it is required for business purposes or by the law.
11. Data Retention
When you visit our website, our internet service provider may make a record of your visit and may record, amongst other things, matters such as your personal domain name (if relevant), the time and date of your visit to our website, and your internet address. Usually, but not always, this information is applied for statistical purposes.
When you visit the website, the server may attach a "cookie" to your computer's memory. Your browser stores cookie messages in a text file and sends these back to our website each time the browser requests a page from the website. From time to time, we may use cookies to measure usage periods accurately and to obtain an idea of which areas of our website attract traffic. If you do not wish to receive cookies, you may be able to alter your browser settings accordingly.
The website may link directly to websites operated by third parties. We encourage you to review the Privacy Policy (if any) of any third party sites, as we are not responsible for the content or practices of those third party sites or their Privacy Policies regarding the collection, storage, use and disclosure of your personal information.
12. Cloud Computing Services & Storage
We use or may use international cloud computing services and storage providers described within section 7. Access to such cloud service providers is encrypted, so that data and the personal information contained in such services is protected from unauthorised access.
Countries in which such data may be stored include (but are not limited to) Australia, United States of America and the Philippines. We conduct due diligence on proposed cloud computing service providers prior to engaging them and satisfy ourselves that the overseas recipient is subject to a law or binding scheme that has the effect of protecting the personal information in a way that, overall, is at least substantially similar to the way in which the Australian Privacy Principles protect the information.
We also use the enterprise version of LastPass to restrict staff from knowing the passwords for the cloud-based applications they are given access to. We have also locked down access to Diwan & Co's IP address to prevent staff from accessing any cloud services from outside the organisation.
13. Loss of Personal Information
Despite Diwan & Co's efforts to protect your personal information, there remains the possibility for a breach of security to occur. In accordance with the recommendations set out by the Tax Practitioners Board, Diwan & Co has established a data breach response plan and will follow the steps outlined in the plan in the event of loss of personal information.
A data breach occurs when the personal information that Diwan & Co holds of their clients is lost, accessed by unauthorised people, or disclosed outside due to malicious action (external and internal), human error or certain unforeseen circumstances. The response plan outlines the following steps:
- Step 1: Report and Contain — Client and Australian Information Commissioner (OAIC)
- Step 2: Assessment of the breach
- Step 3: Notifying the breach
- Step 4: Reviewing and Documenting
14. Website Security and Privacy
Diwan & Co will take all reasonable steps to have systems in place to ensure the security of your dealings with Diwan & Co at all times.
15. Credit Reporting
This section of the Privacy Policy details how we manage credit information and credit reporting and has been developed in accordance with the Privacy Act and the Credit Reporting Code (CRC). During the course of providing professional services to you, we may collect credit information that is necessary to provide you with the relevant professional service.
The main kind of credit information we collect is your identification information; however, in the course of providing the relevant professional service to you, we may be given (and subsequently hold) other kinds of credit information, including but not limited to: any publicly available information about your credit worthiness; any information about you where you may have fraudulently or otherwise committed a serious credit infringement; information about any credit that has been provided to you; your repayment history; information about your overdue payments; if terms and conditions of your credit arrangements are varied; if any Court proceedings are initiated against you in relation to your credit activities; information about any bankruptcy or debt agreements involving you; and certain administrative information relating to credit, such as account and customer numbers.
We hold and store credit information in the same manner as we collect and hold and store personal information. Our usual purpose for collecting, holding, using and disclosing credit information about you is to enable us to provide you with the professional service, to process payments, for our business purposes or otherwise as permitted by the Privacy Act or law.
We may disclose your credit information to Credit Reporting Bureaus (CRBs) for purposes permitted by the Privacy Act. We will give you at least fourteen (14) days written notice of our intention to disclose your information to a CRB.
You may request that we not use or disclose credit information for the purposes of direct marketing, by making such a request in writing to info@diwanco.com.au.
16. Updating Your Information
It is important that the personal information or credit information that we hold about you is up-to-date. Diwan & Co will take all reasonable steps to ensure that all personal information held by Diwan & Co remains accurate. If you advise Diwan & Co of any change of details, Diwan & Co will amend your records accordingly.
Where Diwan & Co is unable to update your information, Diwan & Co will provide an explanation as to why the information cannot be corrected.
17. Privacy Enquiries
If you wish to make an enquiry about your personal information that Diwan & Co collected, used or held, or make a complaint because you believe that Diwan & Co may have breached the Australian Privacy Principles, you can:
- Write to Diwan & Co at info@diwanco.com.au
- Call Diwan & Co on (03) 9125 0071
We will usually (but not always) grant you access to your personal information or credit information as soon as possible. To the extent permissible by law, we may deny access to personal information or credit information if your request is impractical or unreasonable, if providing access would have an unreasonable impact on the privacy of another person, or if there are other appropriately justified and/or legal grounds upon which to deny the request.
18. Privacy Complaints
If you wish to complain about an alleged privacy breach, you should follow the following process:
- The complaint must be firstly made to us in writing. We will have a reasonable time to respond to the complaint.
- In the unlikely event that the privacy issue cannot be resolved between us and yourself, you may take your complaint to the Office of the Australian Information Commissioner.
You may complain about a breach of privacy by contacting us using the contact details below:
- Write to Diwan & Co at info@diwanco.com.au
- Call Diwan & Co on (03) 9125 0071
19. Further Information on Privacy
You can obtain further general information about your privacy rights from the Office of the Australian Information Commissioner by:
- Calling their Privacy Hotline on 1300 363 992
- Visiting their website at www.oaic.gov.au
- Writing to: The Australian Information Commissioner, GPO Box 5288, Sydney NSW 2001
20. Changes to This Privacy Policy
We may update, modify or remove this policy at any time without prior notice, with any updated version of our privacy policy being posted on our website. You should review this Privacy Policy regularly to ensure that you are at all times aware of any variations made to this Privacy Policy. You agree that you will be deemed to have consented to such variations by your continued use of the website or our services following any such change. If you have any comments on the policy, please contact our privacy officer at info@diwanco.com.au.
Questions? Contact us at info@diwanco.com.au or call 03 9125 0071.
Back to Contact Form