Privacy Policy
Last updated: 1 January 2026
SMB Advisory Pty Ltd (SMB, we, us) is committed to protecting the privacy of personal information we collect and handle. This Privacy Policy explains how we manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
​
1. About this policy
This policy applies to personal information we collect and handle in the course of providing accounting, advisory and insolvency services, and through our website and
communications.
This policy should be read together with any privacy collection notices we provide at or
around the time we collect personal information (for example, in engagement documentation or forms or via our investigations).
​
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an
individual who is reasonably identifiable, whether true or not, and whether recorded in
material form or not.
We may also handle sensitive information (a subset of personal information) in limited
circumstances and generally only where authorised by law or with consent.
​
3. The types of personal information we collect
We collect only personal information that is reasonably necessary for our functions and
activities. Depending on your relationship with us, this may include:
​
-
Identity and contact details (name, address, email, phone)
-
Employment/professional details (role, organisation)
-
Information relevant to delivering our services (instructions, correspondence, file notes, records)
-
Financial and tax-related information (which may include tax file number information where permitted)
-
Identification details (for example, date/place of birth and driver licence details) where required for a legitimate purpose (such as verification of identity prior to accepting new engagements)
-
Website/technical information (IP address, device information, pages viewed, cookie identifiers)
Tax File Numbers (TFNs): Where we handle TFN information, we do so in accordance with the Privacy (Tax File Number) Rule 2015 and relevant taxation laws.
​
4. How we collect personal information
We generally collect personal information directly from you, including when you:
-
make an enquiry, engage us, or communicate with us
-
provide information during the course of a matter or appointment
-
use our website (including via cookies/analytics)
We may also collect personal information from third parties where it is unreasonable or impracticable to collect it directly from you, such as:
​
-
our clients (for example, where you are a creditor, director, employee or stakeholder)
-
other professional advisers involved in a matter
-
publicly available sources
If we cannot collect required information, we may be unable to provide services or respond fully to your request.
​
5. Why we collect, hold, use and disclose personal information
We use personal information for purposes including:
​
-
providing and administering our services and engagements
-
communicating with stakeholders (including creditors and other parties relevant to appointments)
-
responding to enquiries and requests
-
meeting legal, regulatory, professional and reporting obligations
-
internal administration, quality assurance, training and risk management
​
We generally use and disclose personal information for the primary purpose for which it is collected, and for related purposes you would reasonably expect.
​
6. Disclosure of personal information
We may disclose personal information to:
​
-
third-party service providers who assist us to operate our business (for example, IT, cloud hosting, document management, secure storage, and secure destruction providers), under confidentiality and privacy protections
-
professional advisers and specialist consultants engaged in connection with a matter
-
recruitment service providers (where you apply for a role with us)
-
regulators, courts, tribunals, law enforcement or other entities where required or authorised by law
We do not sell personal information or disclose it to third parties for their own direct
marketing purposes.
​
7. Overseas disclosure
Some of our third-party service providers may store or process personal information
outside Australia (for example, cloud and IT service providers). Where we disclose
personal information overseas, we take reasonable steps to ensure the overseas recipienthandles the information in a manner consistent with the APPs.
As at the date of this policy, all third-party service providers currently engaged by us utilise data centres located within Australia.
​
8. Direct marketing and opt-out
We may send updates about our services, events or insights that may be relevant to you.
You can opt out at any time by:
​
-
using the unsubscribe facility (where available), or
-
contacting us using the details in section 14.
​​
We will respect opt-out requests in accordance with the APPs.
​
9. Cookies and website analytics
Our website may use cookies and similar technologies to:
-
enable website functionality
-
analyse website traffic and usage
-
improve user experience
You can manage cookies through your browser settings. Some features of our website may not function properly if cookies are disabled.
Our website may include links to external sites. We are not responsible for the privacy
practices of those sites and encourage you to review their privacy policies.
​
10. Security of personal information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our safeguards may include a combination of:
-
access controls and authentication measures
-
secure storage and transmission practices (including encryption where appropriate)
-
staff training and confidentiality obligations
-
monitoring and maintenance of IT systems
-
secure physical storage and secure destruction processes
​
11. Data breaches (including Notifiable Data Breaches scheme)
Despite safeguards, data breaches can occur. A data breach may involve unauthorised
access to, unauthorised disclosure of, or loss of personal information.
We maintain an internal Data Breach Plan that sets out how we identify, contain, assess,
notify and review suspected and actual data breaches.
If we become aware of a suspected breach, we will take steps to:
-
Contain the breach where possible (for example, securing accounts or requesting deletion of misdirected information).
-
Assess the incident to determine whether it is an eligible data breach under the Notifiable Data Breaches (NDB) scheme (including whether serious harm is likely).
-
Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required, including providing information about the breach, the types of information involved, recommended steps individuals should take, and our contact details.
-
Review and improve controls and training following an incident.
If you believe a data breach may involve your information, contact us promptly (see section 14).
​
12. Accessing your personal information
You may request access to personal information we hold about you by contacting our
Privacy Officer. We will provide access unless an exception applies under the Privacy
Act/APPs (for example, where providing access would unreasonably impact another
person's privacy).
​
13. Correcting your personal information
If you believe the personal information we hold about you is inaccurate, out-of-date,
incomplete, irrelevant or misleading, contact us and we will take reasonable steps to
correct it.
​
14. Questions and complaints
If you have questions, concerns or a complaint about how we handle personal information, please contact our Privacy Officer. We will treat complaints confidentially, investigate, and respond within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian
Information Commissioner (OAIC).
Privacy Officer (SMB Advisory Pty Ltd)
Email: privacy@smbadvisory.com.au
Mail: Privacy Officer, SMB Advisory, Level 5, 100 Collins Street, Melbourne VIC 3000
Phone: (03) 9600 2100
​
15. Retention and disposal
We take reasonable steps to destroy or de-identify personal information when it is no
longer required for any lawful purpose, including legal, regulatory, dispute resolution, and professional obligations.
​
16. Changes to this policy
We may update this policy from time to time by publishing the updated version on our
website. The updated policy will apply from the effective date shown at the top.
.png)

