Privacy Policy

Privacy Policy

Aretex is committed to providing you with the highest level of service. As part of our commitment to you and your business, this policy outlines our ongoing obligations regarding how we manage your Personal Information.


We have adopted the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Privacy Act), as amended by the Privacy and Other Legislation Amendment Act 2024. The APPs govern the way in which we collect, use, disclose, store, secure and dispose of your Personal Information.


A copy of the Australian Privacy Principles may be obtained from the website of the Office of the Australian Information Commissioner at www.oaic.gov.au.

Aretex

Aretex is a Managed Services Provider, specialising in tailor-made accounting and financial management, IT and digital transformation, and business administration services. Integrating highly experienced professionals and expertise with technology, process and offshore talent to deliver you all the benefits of an offshore team, with an emphasis on delivering high-quality services.

Application of this Privacy Policy

This privacy policy applies to Personal Information we collect about our clients and their nominated contacts and representatives (including employees, trustees, company directors and officers, officers of co-operatives and associations, client's spouse and dependants) and to other individuals whose Personal Information we collect or that our clients or their representatives provide to us in the course of delivering our services. It also applies to applicants for positions with Aretex, and to our Australian employees.


In this policy 'we' or 'us' means Aretex Pty Ltd ABN 67 165 860 159 and its related bodies corporate.


Note: The handling of Personal Information relating to our Philippines-based employees is governed by a separate Employee Privacy Notice issued by Aretex Business Services, Inc. under the Philippine Data Privacy Act 2012. That notice is available to Philippines employees through the HR portal.


We may also provide you with separate privacy notices when we collect your Personal Information. These notices may outline additional uses and disclosures not detailed in this policy. If there is any inconsistency between these separate privacy notices and this privacy policy, you should rely on the information in those notices.



This privacy policy does not apply to any links to other websites you may find on our website. Always check the privacy policy of any website you access.

Your Personal Information

Personal Information has the meaning of s.6(1) of the Privacy Act. We will only ask for Personal Information that is relevant to our professional relationship with you and if it is reasonably necessary for us to be able to provide our ongoing services to you. We may ask you for your:

  • Name, address, telephone number, email and other contact details
  • Date of birth, gender and marital status
  • Financial and investment information
  • Government identifiers such as tax file number
  • Superannuation and insurance information
  • Your opinion about our services and our people
  • Occupation and employment details including past employment (regarding job applicants for positions with us)
  • Your sensitive information such as professional memberships, racial or ethnic origin, criminal record and health information (from job applicants or for certain services)

Anonymity and Pseudonymity

Under Australian Privacy Principle 2, individuals have the option of not identifying themselves, or of using a pseudonym, when dealing with us where it is lawful and practicable to do so.



However, in most cases Aretex is unable to provide its professional services to clients who do not identify themselves. This is because:

  • Our services involve the preparation of financial records and other regulated documents that require verified identity
  • We may be required by law to verify the identity of clients under applicable anti-money laundering, counter-terrorism financing, and taxation legislation
  • Effective service delivery requires us to attribute work and communications to an identified individual

Where anonymity or pseudonymity is lawful and practicable for a specific interaction (for example, a general website enquiry), we will allow it.

How We Collect Personal Information From You and From Others

Your Personal Information is obtained in many ways including correspondence by telephone and email, documents and integrations provided to us by you, via our website www.aretex.com.au, from your website, from media and publications, from other publicly available sources, from website cookies and tracking technologies (see 'Website Tracking and Cookies' below), and from third parties. We don’t guarantee the website links or policies of authorised third parties.


We may also collect Personal Information about you from our clients in the course of providing services to them. When you provide us with someone else's Personal Information you should only do so with their authority or consent or if you are required or authorised by law. You should also refer them to this privacy policy and any separate privacy notices we provide you.

 

Notifications at the Point of Collection


Where we collect your Personal Information directly (for example, through our website contact forms, client onboarding processes, or in person), we will take reasonable steps at or before the time of collection to notify you of:

  • the purposes for which we are collecting the information
  • whether the collection is required or authorised by law
  • the types of organisations to which we may disclose the information

This may be done by directing you to this privacy policy or by providing a separate collection notice at the point of collection.


Unsolicited Personal Information


We may receive Personal Information that we did not actively seek (for example, information included in documents provided to us in the course of client engagements or information provided about third parties). Where this occurs, we will, within a reasonable time, assess whether we could have collected that information under Australian Privacy Principle 3.



If we could not have collected the information under APP 3, and it is lawful and reasonable to do so, we will take reasonable steps to destroy or permanently de-identify that information. If we are unable to do so immediately, the information will be held securely and not used or disclosed except as required by law.

The Purposes For Which We Collect Your Personal Information

We collect, retain, use and disclose your Personal Information to enable us to provide our services, to respond to your inquiries, assess your employment application and to comply with the law.


Some of the purposes for which we use your Personal Information are to:

  • provide professional services to you or to other clients
  • communicate with you, including responding to your inquiries and feedback, keeping you informed of news and events, and sending you industry publications and other material that we think may be of interest to you
  • develop and provide systems and technology solutions for you
  • conduct client satisfaction feedback activities
  • conduct administration activities
  • manage our conflict of interest and independence obligations
  • undertake recruitment activities
  • comply with legislative and regulatory requirements including under the Corporations Act, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), and taxation and employment laws
  • marketing purposes (see the section below titled ‘Marketing our services to you’)



You may decide not to provide us with your Personal Information we ask for. However if you opt not to, or if you provide us with Personal Information that is inaccurate or incomplete, we may not be able to respond adequately to your inquiries or provide you with the services you or our other clients require.

Lawful Basis for Collecting and Using Personal Information

We collect and use your Personal Information on the following lawful basis under the Privacy Act 1988 (Cth):

  • Contract performance: where processing is necessary to provide the professional services you have engaged us to deliver, or to take steps at your request before entering into an engagement
  • Legal obligation: where we are required to collect or use Personal Information to comply with applicable laws, including taxation law, anti-money laundering obligations, corporations law, and employment law
  • Legitimate interests: where we have a legitimate business interest in using your information (for example, to improve our services or to protect our business), provided that interest is not overridden by your privacy interests
  • Consent: in limited circumstances where we specifically request your consent. You may withdraw consent at any time by contacting us using the details at the end of this policy. Withdrawal of consent will not affect the lawfulness of any processing carried out before withdrawal, and may affect our ability to provide certain services



In most cases, our primary lawful basis for processing Personal Information in the context of our professional services is contract performance or legal obligation. Consent is used only where specifically identified.

Sensitive Information

Sensitive information is defined in the Privacy Act to include information or opinion about such things as an individual’s racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.


Sensitive information will be used by us only:

  • For the primary purpose for which it was obtained
  • For a secondary purpose that is directly related to the primary purpose
  • With your consent; or
  • Where required or authorised by law

Government Identifiers

In the course of providing accounting, payroll and financial services, we may collect government-issued identifiers including tax file numbers, Australian Business Numbers, and other identifiers assigned by government agencies.



We handle government identifiers in accordance with Australian Privacy Principle 9. This means we will:

  • only collect, use or disclose a government identifier where required or authorised by law, or where it is reasonably necessary to verify your identity in connection with our professional services
  • not adopt a government identifier as our own identifier for you in our internal systems
  • not disclose a government identifier except as required or authorised by law, or with your consent


In particular, tax file numbers are handled in strict accordance with the Privacy (Tax File Number) Rule 2015 (Cth).

Third Parties

Where reasonable and practicable to do so, we will collect your Personal Information only from you. However, in some circumstances we may be provided with information by third parties. In such a case we will take reasonable steps to ensure that you are made aware of the information provided to us by the third party.

Disclosure of Personal Information

Your Personal Information may be disclosed in a number of circumstances including the following:

  • Third parties where you consent to the use or disclosure
  • Where required or authorised by law


We may disclose your Personal Information to the following categories of external organisations:

  • Information technology, artificial intelligence, and cloud service providers (for data hosting, software platforms and IT support)
  • Professional service providers engaged to assist with our service delivery
  • Mailing services
  • Billing and debt-recovery functions
  • Marketing and analytics service providers
  • Your representatives (e.g. authorised representatives, financial or legal advisors)
  • Government and regulatory authorities and other organisations, as required or authorised by law
  • Our related bodies corporate, including our Philippines-based delivery subsidiary


Where we engage third-party service providers, we take reasonable steps to ensure they are contractually bound to handle your Personal Information in accordance with the Australian Privacy Principles and our own privacy and security standards.

Overseas Disclosures

Aretex operates a managed services delivery model in which professional services are delivered by our team based in the Philippines. Our Philippines operations are conducted through a wholly-owned subsidiary and operate as an integrated part of our business, subject to the same policies, procedures and security standards as our Australian operations.


As part of our service delivery, your Personal Information may be accessed and processed by our team in the Philippines. All offshore access operates under controlled systems, role-based access, and contractual confidentiality obligations and is aligned with Australian Privacy Principles.


Your Personal Information may also be accessed by service providers located in other countries, including providers of cloud hosting, information technology, artificial intelligence and software services. Where we engage overseas service providers, we take reasonable steps to ensure they are bound by obligations to handle your Personal Information in a manner consistent with the Australian Privacy Principles.

The countries in which overseas recipients of your Personal Information are likely to be located include:

  • Philippines (wholly-owned delivery subsidiary)
  • Singapore, United Kingdon, Europe, United States (cloud and technology service providers)

Disclosure Required by Law

We may be required to disclose your Personal Information by law, for example under Court Orders or Statutory Notices, or under laws relating to sanctions, anti-money laundering or counter-terrorism financing, corporations law, taxation and employment.

Use of AI and Automated Tools in Service Delivery

Aretex uses artificial intelligence and automated tools to support the delivery of our services. These tools may assist with tasks such as document processing, workflow automation, and analysis.


Where AI tools process Personal Information, we take reasonable steps to ensure that:

  • the tools are used only for purposes consistent with the primary purpose for which the information was collected
  • your Personal Information is not used to train third-party AI models without your consent
  • any AI-assisted outputs that may affect you are subject to human review where appropriate


We maintain an internal AI Use Policy that governs how staff use AI tools when handling Personal Information. This policy is available to clients on request.

Marketing Our Services to You

Occasionally, we may also use and disclose your Personal Information to inform you about other services and products we provide or that other companies offer that we believe may be of interest or value to you.


If at any time you do not wish to receive direct marketing communications from us, you may opt out at any time by:

  • using the unsubscribe link provided on direct marketing related material
  • contacting us via the details listed at the end of this document


We will action your opt-out request as soon as practicable. We will not charge you for making an opt-out request, and we will not send you further direct marketing communications after your request has been processed without your updated consent to receiving them.

Website Tracking and Cookies

Cookies

Our website uses cookies, small text files placed on your device, to improve your browsing experience, analyse website traffic and understand how visitors interact with our site. Some cookies are essential for the website to function, while others help us improve our services and tailor content to your interests.


You can manage your cookie preferences through your browser settings. Disabling certain cookies may affect the functionality of our website.

Third Party Analytics and Advertising

We may allow third parties to use cookies and other technologies in order to advertise our services on other websites and social media platforms. We allow third party cookies from Google to inform, report, optimise and serve ads based on your visits to other websites.



These third-party services may collect information about your online activities over time and across different websites. We recommend reviewing the privacy policies of these third-party providers for further information about how they handle your data.

Web Pixels and Tracking Technologies

Our website and other communications including emails may contain small electronic images or code (sometimes called pixels, tags or beacons). These technologies allow us to count visitors, track whether emails have been opened, and develop statistical information about the content and features that most interest you.


These technologies collect certain information automatically, which may include your IP address and browsing behaviour. IP addresses constitute Personal Information under the Privacy Act. We collect this information for the purposes of understanding how our website is used and improving our services. We will not use information collected by these technologies for any secondary purpose without your consent.

Security of Personal Information

We take reasonable steps, including appropriate technical and organisational measures, to protect your Personal Information from misuse, interference and loss, and from unauthorised access, modification or disclosure.


Our security measures include:

  • operating in accordance with an ISO 27001-certified information security management system, which applies across our Australian and Philippines operations
  • implementing role-based access controls to limit access to Personal Information to authorised personnel who require it for their role and work assignments
  • using encryption and secure transmission protocols where appropriate
  • conducting regular staff training on privacy and information security obligations
  • maintaining documented policies and procedures for the handling of Personal Information
  • regularly reviewing and auditing our security practices
  • maintaining secure physical premises and IT infrastructure


When your Personal Information is no longer needed for the purpose for which it was obtained, we will take reasonable steps to destroy or permanently de-identify your Personal Information.


Data Retention


We retain Personal Information for as long as it is needed to fulfil the purposes for which it was collected, or as required by law. The retention periods that apply to different categories of Personal Information include:

  • Client financial records and working papers: minimum 7 years from the date of the last service, in accordance with taxation and corporations law requirements
  • Recruitment and job applicant records: retained for up to 12 months after the recruitment process is completed, unless you consent to us retaining your Personal Information for longer
  • Marketing and communication records: retained until you opt out of receiving marketing communications or we no longer require them
  • Website analytics data: retained in accordance with the policies of our third-party analytics providers


When Personal Information is no longer required, we will take reasonable steps to securely destroy or permanently de-identify it.

Notifiable Data Breaches

We maintain documented procedures for identifying, containing, assessing and responding to data breaches in accordance with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).

In the event of a data breach or suspected data breach, we will:

  • take immediate steps to contain the breach and mitigate potential harm
  • conduct a timely assessment to determine whether the breach constitutes an eligible data breach under s.26WA of the Privacy Act, completed as expeditiously as possible and in any case within 30 days of becoming aware of the suspected breach (s.26WH(2))
  • where we have reasonable grounds to believe an eligible data breach has occurred, notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable after forming that belief, and in any case within the 30-day outer boundary set by the NDB scheme (s.26WK)
  • include in that notification: our contact details, a description of the breach, the kind of Personal Information involved, and recommendations for steps individuals can take to protect themselves (s.26WL, s.26WM)
  • Work with our clients to mitigate the impact of the data breach


Aretex as Service Provider


Where Aretex accesses or processes Personal Information in client systems under our engagement letters or
Managed Services Agreement, Aretex may hold that Personal Information within the meaning of s.6(1) of the Privacy Act, even though the Personal Information was collected by the client. In such cases, Aretex may have independent NDB obligations in respect of that data.


Our managed services agreements and engagement letters specify the notification obligations of each party in the event of a suspected data breach involving client data. In all cases, Aretex will notify the relevant client of any suspected breach involving client data as soon as practicable, and in any case within 5 business days of becoming aware of the incident, to allow the client to meet their own notification obligations.   

Your Privacy Rights

The Privacy and Other Legislation Amendment Act 2024 introduced a statutory tort for serious invasions of privacy in Australia, which took effect on 11 December 2024. This provides individuals with a civil right of action where their privacy has been seriously invaded, including through misuse of Personal Information.


We take this obligation seriously and maintain robust data handling practices to protect your privacy. If you believe your privacy has been seriously invaded, you may wish to seek independent legal advice about your options. The complaint process described below remains the primary avenue for any privacy concerns.

Access to Your Personal Information

You may access the Personal Information we hold about you and request that it be updated and/or corrected, subject to certain exceptions. If you wish to access your Personal Information, please contact us in writing.


We will respond to your access request within 30 days of receiving it. If we are unable to provide access within this timeframe, we will notify you of the reasons for the delay and the expected timeframe for a response.


Aretex will not charge any fee for your access request, but may charge an administrative fee for providing a copy of your Personal Information.


In some circumstances, we may refuse to provide access to your Personal Information. If we do, we will provide you with written reasons for the refusal and information about how you can complain about the decision.


To protect your Personal Information, we may require identification from you before releasing the requested information.


Correction of Personal Information


If you believe that Personal Information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may ask us to correct it. We will take reasonable steps to correct the information.


If we have previously disclosed to a third party Personal Information that we subsequently correct, and you request that we notify that third party of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful (APP 13.3).



If we decline to correct the Personal Information, we will provide written reasons and information about how to complain.

Maintaining the Quality of Your Personal Information

It is important to us that your Personal Information is up to date. We will take reasonable steps to make sure that your Personal Information is accurate, complete and up-to-date. If you find that the information we have is not up to date or is inaccurate, please advise us as soon as practicable so we can update our records and ensure we can continue to provide quality services to you.

Automated Decision Making

We will update this section to reflect any automated decision-making processes we introduce that use your Personal Information to make decisions that could reasonably be expected to significantly affect your rights or interests, in accordance with Australian Privacy Principle 1.7.

Privacy Officer

Aretex has designated a Privacy Officer responsible for overseeing compliance with our privacy obligations and handling privacy enquiries and complaints.

You can contact our Privacy Officer using the contact details set out at the end of this policy. Please mark your correspondence for the attention of the Privacy Officer.

How We Handle Complaints

If you believe we have not complied with our privacy obligations, you can notify us in writing by either of the following methods:


We will acknowledge receipt of your complaint within 5 business days. We will investigate your complaint and aim to provide a substantive response within 30 days of receipt. We will need to verify your identity and we may need to ask you for further information. If we require additional time to investigate, we will notify you of the reasons for the delay and the expected timeframe for a response.


If you do not agree with our decision or how we have handled your complaint you can refer your complaint to the Office of the Australian Information Commissioner:

  • Online: www.oaic.gov.au
  • Phone: 1300 363 992
  • Mail: GPO Box 5218, Sydney NSW 2001

Policy Updates

We will update this policy as required to reflect changes to our privacy practices. We encourage you to check our website regularly for updates to our Privacy Policy.



This policy was updated March 2026.

How to Contact Us

You can contact us about this policy by:

  • Telephone: (02) 9188 4495
  • Email: privacy@aretex.com.au

Contact Us

Aretex

Address:

Level 11, 56 Berry St. North Sydney, NSW 2060

Phone:

(02) 9188 4495

Email:

info@aretex.com.au