Nanak Accountants & Associates
This policy explains how we collect, hold, use and disclose personal information in our accounting and tax practice, including overseas support and approved AI processing. It also explains how you can request access or correction, make a complaint and manage your choices.
Document control | Details |
|---|---|
Policy holder | Nanak Associates Pty Ltd trading as Nanak Accountants & Associates |
Version and effective date | 3.1 – 15/09/2026 |
Policy owner | Principal and Privacy Officer |
Review | At least annually and following material legal, system or service changes; automated decision disclosures to be reviewed before 10 December 2026. |
1.1 This policy applies to Nanak Associates Pty Ltd, trading as Nanak Accountants & Associates (we, us, our or the Firm), and to personal information handled for the Firm by its offices, employees, contractors and service providers. A separately incorporated business is covered only where it is expressly identified as a policy holder or acts on our behalf.
1.2 We adopt the Australian Privacy Principles (APPs) as our information handling standard and comply with the Privacy Act 1988 (Cth), the Privacy (Tax File Number) Rule 2015 and other privacy laws to the extent they apply. Our client confidentiality obligations under the Tax Agent Services Act 2009 (Cth) (TASA) apply independently of any small business exemption under the Privacy Act.
1.3 This policy operates alongside collection notices, our Artificial Intelligence Policy and your engagement agreement. A collection notice gives information relevant to a particular collection. A separate authority or consent records a permission where needed. Reading this policy, visiting our website or continuing to use our services does not, by itself, constitute consent to every practice described here.
1.4 No engagement term, consent or policy provision overrides an applicable legal duty or removes a right that cannot lawfully be excluded. A specific instruction may narrow a permitted use or disclosure; it cannot authorise conduct prohibited by law.
1.5 Personal information concerns an identified or reasonably identifiable individual, including an opinion whether true or not. Sensitive information has the meaning given in the Privacy Act. Our professional confidentiality obligations also protect information about companies, trusts and other clients that may not be personal information.
2.1 You may make a general enquiry anonymously or using a pseudonym where lawful and practicable. To provide client specific tax services, verify authority or comply with applicable identification obligations, we usually need to know who you are.
2.2 If you cannot provide conventional identity documents, contact us to discuss lawful alternative verification methods. We may be unable to provide a service if the required verification cannot be completed.
3.1 We collect information reasonably necessary for our services and practice administration. Depending on the engagement, this may include:
Category | Examples |
|---|---|
Identity and contact | Names, contact details, date of birth, tax residency, identity verification results and relevant identification details. |
Tax and financial | TFNs where lawfully required for the service, income, deductions, bank details, assets, liabilities, investments, capital gains and tax records. |
Business and related people | Ledgers, payroll, superannuation, entity structures and details of directors, trustees, beneficiaries, members, employees and authorised representatives. |
Engagement and communications | Instructions, correspondence, file notes, invoices, payment status and recordings or transcripts where collection has been notified and lawfully authorised. |
Due diligence | For services subject to AML/CTF obligations, beneficial ownership, source of funds or wealth, identity and relevant risk screening information. |
Website and digital | IP address, browser and device details, usage events, cookies, enquiries, booking details and information you submit through our online tools. |
Recruitment and suppliers | Applications, qualifications, employment history, references and contact or payment details relevant to the relationship. |
3.2 We collect sensitive information only where reasonably necessary and with valid consent, unless an applicable law permits collection without consent. Examples may include health information relevant to an agreed tax service or criminal record information required for lawful due diligence. We do not treat financial information as legally defined sensitive information merely because it is confidential; it nevertheless receives strong protection.
3.3 If you give us information about another individual, you must have a lawful basis and any authority needed to do so, and should provide that person with our privacy information where appropriate. We remain responsible for our own collection and notification obligations. Your authority as a director, employer or family member does not automatically permit every use of another individual’s information.
3.4 We assess unsolicited information within a reasonable period. If we could not lawfully have collected it, we destroy or de-identify it as soon as practicable where lawful and reasonable, subject to the rules for Commonwealth records and any other applicable retention duty.
3.5 If requested information is not provided, we may be unable to prepare accurate work, verify identity, lodge a document or accept or continue the engagement. We will explain the relevant consequence where practicable. The special position on providing a TFN is set out in clause 11.
4.1 We usually collect information from you through meetings, telephone calls, correspondence, forms, portals and other approved communication channels. We use lawful and fair collection methods.
4.2 Where lawful, reasonable and relevant, we also collect information from the ATO and other regulators, public registers, your accounting systems, authorised bank feeds, previous accountants, advisers, financial institutions, auditors, verification providers and people authorised to act for you.
4.3 At or before collection, or as soon as practicable afterwards, we take reasonable steps to explain the relevant purposes, usual disclosures, any applicable legal collection requirement and the consequences of not providing the information. Additional notices may apply to identity checks, payroll, recruitment, recording and online forms.
4.4 If a call or meeting is to be recorded or transcribed, including by an AI tool, we explain the purpose and relevant processing before activation and obtain any consent required by law. You may request an unrecorded conversation or another channel. We will not activate an optional recording or transcription where you decline it.
5.1 We use and disclose relevant information to provide the agreed accounting, tax, BAS, bookkeeping, payroll, SMSF, ASIC, registration and advisory services; communicate with you; verify identity and authority; prepare and lodge documents; administer billing; and manage lawful compliance, complaints, insurance and record keeping.
5.2 Internal supervision, quality review and practice administration are limited to lawful purposes and personnel who need the information. Training and service improvement use de-identified or synthetic examples wherever practicable. We do not use identifiable client files for unrelated training or model development merely because we hold them.
5.3 For a secondary purpose, we obtain consent or establish an applicable legal exception. Where we rely on reasonable expectations under APP 6, the purpose must be related to the primary purpose, or directly related for sensitive information. Client confidentiality under clause 9 must also be satisfied before a third party disclosure.
5.4 We do not sell personal information or provide it to other organisations for their own direct marketing. Disclosure during a proposed transfer of our practice is governed by clause 9.5.
6.1 Where an engagement involves a designated service under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), we handle information needed to meet the applicable obligations. Coverage depends on the actual service and statutory conditions. Routine tax return preparation or bookkeeping does not, by itself, make every engagement a designated service.
6.2 For a covered service, this may involve identifying and verifying clients, representatives and beneficial owners; assessing relevant risk; obtaining source of funds or wealth information where required; ongoing due diligence; retaining required records; and making reports or providing information to AUSTRAC as required by law. We do not provide a covered service unless the applicable due diligence requirements, including any lawful exception or timing rule, are satisfied.
6.3 Where anti tipping off or other laws restrict disclosure, we may be unable to explain particular enquiries, decisions or reports, or provide access to related information. We restrict disclosure only to the extent the law requires or permits and do not treat this clause as a general exemption from privacy obligations.
6.4 We distinguish records of verification from full copies of identity documents. We do not retain a full passport or licence copy solely on the assumption that AML/CTF or TPB rules always require it. Copies are removed when no longer lawfully needed, while required verification records are retained.
7.1 Our Artificial Intelligence Policy governs approved AI use, including data extraction, suggested classifications, anomaly detection, research, drafting and approved administrative assistance. It is available from us on request and, when published, through our website.
7.2 AI use must be approved for the particular task, account and data. Staff must minimise inputs and must not enter personal or client confidential information into unapproved or consumer AI accounts. Approval for client data requires controls on access, storage, retention, onward disclosure and provider training. A paid subscription alone is not approval.
7.3 Before client information is disclosed to an external AI provider, we obtain the relevant client’s informed permission unless a legal duty requires disclosure. We explain the recipient, purposes, relevant information, processing locations and material limitations. Separate privacy consents may also be necessary, including for sensitive information.
7.4 Our policy prohibits use of client information to train or improve a provider’s general models. Material AI output used in professional work must be checked against reliable evidence and applicable law by a competent person. The Firm remains responsible for the services it provides.
7.5 If we offer an AI chat or telephone assistant, we identify it as AI, explain the collection and provide a route to a person. Such assistants are restricted to approved information and administrative tasks. They are not authorised to give personalised tax advice, make binding commitments or lodge documents.
8.1 Our policy requires people to determine tax positions, approve lodgements, decide whether to accept clients, approve fees and decide reportable obligations. Autonomous AI decisions on these matters are not permitted.
8.2 Computer programs may nevertheless extract, calculate, classify, flag or summarise information that substantially and directly assists a person’s decision. Human review does not, by itself, mean that automated decision transparency requirements are inapplicable. Schedule 2 describes the relevant processing and human involvement.
8.3 APPs 1.7 to 1.9 commence on 10 December 2026. Where applicable, our disclosures will identify the kinds of personal information used, the kinds of decisions made solely by programs and the kinds of decisions substantially and directly assisted by programs, where the statutory threshold of significant effect on an individual’s rights or interests is met. We review these disclosures before commencement and whenever relevant processes change.
8.4 You may ask us about automated processing relevant to your matter and request that a person review an apparent error. Access to personal information and correction requests are handled under clause 18.
9.1 Under Code item 6 in section 30-10 of TASA, we must obtain a client’s permission before disclosing information about that client’s affairs to a third party, unless we have a legal duty to disclose it. A privacy law permission, a confidentiality agreement with a recipient or a professional membership requirement does not necessarily establish that legal duty.
9.2 Subject to clause 9.1 and applicable privacy law, recipients may include the ATO, ASIC, AUSTRAC, the TPB and state revenue authorities; superannuation funds, auditors and actuaries; your authorised advisers and financial institutions; our legal advisers and insurers; external quality reviewers; and approved accounting, hosting, IT, identity, payment, communications, AI and offshore support providers.
9.3 We record permissions through an engagement agreement, a separate authority or another clear communication. We explain what information is involved, to whom and where it will be disclosed, and for what purpose. Where a proposed disclosure falls outside an existing authority, we obtain further permission first. Each client in a joint or related engagement must give the authority relevant to their affairs.
9.4 Access by our personnel is restricted to their duties. We assess the legal and practical arrangements for contractors, related companies, overseas teams and software providers rather than assuming they are all part of the same legal entity. Providers handling information on our behalf must have appropriate confidentiality, security, use limitation and incident reporting arrangements.
9.5 For a proposed sale, merger or transfer of the practice, we use de-identified information for preliminary enquiries where possible. We do not release identifiable client files to a prospective purchaser or successor solely because they sign a confidentiality agreement. We first obtain the required client permission or establish a legal duty, and make secure transfer arrangements.
9.6 You may withdraw or narrow a permission prospectively by contacting us. We will explain any practical effect, including the availability of an alternative service arrangement. Withdrawal does not undo a lawful past disclosure or require destruction of records we must retain. It does not authorise continued disclosure where permission is required and has been withdrawn.
10.1 Our support arrangements include personnel in India. Information may also be processed, stored, backed up or accessed by overseas technology and support providers. Schedule 1 identifies the likely overseas locations by recipient category, so far as practicable. Offshore access is considered even where the main server is in Australia.
10.2 Before an overseas disclosure, we assess the recipient and arrangements and take the reasonable steps required by APP 8, including appropriate contractual and security controls. Where section 16C applies, we remain accountable for relevant handling by an overseas recipient.
10.3 We do not treat acceptance of this policy or a routine offshore processing authority as consent to waive APP 8.1 protections. Our standard arrangements rely on safeguards rather than a blanket APP 8.2(b) waiver. Any exceptional proposal to rely on that provision requires a separate explanation of its consequences and valid, specific consent.
10.4 We make reasonable enquiries into hosting, backups, support access and onward processing. If a location cannot practicably be identified, we explain the limitation rather than give an unsupported assurance that all data stays in Australia. Changes must be checked against existing client permissions before disclosure.
11.1 We collect and handle TFNs only for purposes authorised by taxation, superannuation or other applicable TFN legislation and the Privacy (Tax File Number) Rule 2015. At collection, we explain the relevant legal authority, purpose and consequence of not providing a TFN.
11.2 It is not an offence to decline to provide your TFN. However, we may be unable to provide a particular tax or superannuation service without it. We explain the consequence relevant to the service rather than assume the same consequence applies in every case.
11.3 We do not use a TFN as our general client identifier or as proof of identity, or for marketing or general AI prompts. Access is limited to personnel who need it for an authorised purpose. Client consent alone does not authorise a prohibited TFN use.
11.4 Other government related identifiers are not adopted as our own identifier and are used or disclosed only on a basis permitted by law. Please use our approved secure document channel for TFNs and identity documents, and do not put them in ordinary enquiry forms, public chats or email subject lines.
12.1 We take reasonable steps to keep information accurate, current and complete and, before use or disclosure, relevant to its purpose. This includes checking material extracted or generated by automated systems and recording unresolved discrepancies.
12.2 Please tell us promptly about changes to contact details, residency, bank details, ownership, officeholders and other facts relevant to your engagement. We may independently verify material changes before acting on them.
13.1 Information is held in electronic practice and document systems and, where needed, paper files. Our security requirements include access according to role, strong authentication and multi factor authentication for sensitive systems, appropriate encryption and secure transfer, protected devices, secure paper storage and safe disposal.
13.2 Our arrangements require personnel confidentiality, training, vendor assessment, monitoring, backups and incident response. Controls must be proportionate to the sensitivity and volume of information and must be reviewed when risks or systems change. Unapproved personal accounts and storage must not be used for client files.
13.3 No system can eliminate every risk. This does not reduce our obligation to take reasonable protective steps or exclude any responsibility imposed by law. Please contact us immediately if you suspect that information or an account connected with our services has been compromised.
14.1 We retain information only while lawfully needed. Retention depends on the record and the event that starts the period. Code Determination means the Tax Agent Services (Code of Professional Conduct) Determination 2024.
Record | Retention approach |
|---|---|
Tax agent service records | At least 5 years after the relevant service is complete under section 30 of the Code Determination. The scope and completion of the service may include related reviews, objections or appeals. |
Client identity check records | TPB guidance requires the record of checks for at least 5 years after the engagement ceases. This does not require keeping full identity document copies. |
AML/CTF due diligence records | Where applicable, 7 years after the business relationship ends or the occasional transaction is complete. |
AML/CTF transaction records | Where applicable, general transaction records for 7 years from creation; customer supplied transaction documents for 7 years from receipt. |
Other statutory or continuing records | Relevant taxation, company, trust, SMSF and employment rules may require different or longer periods. Asset history, deeds and governing records may remain needed throughout ownership or the life of the entity and afterwards. |
14.2 We review retention when services end and apply any lawful hold for a dispute, claim, investigation or court process. We do not retain every record indefinitely on the possibility that it may one day be useful.
14.3 When no permitted purpose or applicable retention exception remains, we take reasonable steps to destroy or irreversibly de-identify the information. We address provider copies and backups through controlled deletion cycles or by putting information beyond use pending deletion. Your statutory obligation to keep your own records continues independently of our arrangements.
15.1 Our incident process requires prompt containment, preservation of necessary evidence, assessment of affected information and action to reduce harm. It applies to incidents in our own systems and those of service providers.
15.2 Where there are reasonable grounds to suspect an eligible data breach under the Privacy Act, we conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within 30 calendar days after becoming aware of those grounds. The assessment period is not permission to delay action or a notification already required.
15.3 Where there are reasonable grounds to believe an eligible data breach has occurred, we notify the OAIC and affected individuals as required, as soon as practicable, subject to statutory exceptions. Notification includes the relevant circumstances, information involved and recommended protective steps.
15.4 We assess any separate duties to notify the ATO, TPB, other authorities, clients and insurers. A privacy incident does not automatically trigger every regulator’s reporting test; each applicable obligation and timeframe is assessed. TFN incidents receive particular attention.
16.1 We may send relevant updates, event invitations and information about our services where lawful. Commercial electronic messages require the consent and sender identification required by the Spam Act 2003 (Cth) and a working unsubscribe facility. Other direct marketing is subject to applicable APP 7 and Do Not Call rules.
16.2 You may opt out through the message facility or by contacting us. We give effect to electronic marketing unsubscribe requests within 5 working days and other marketing objections within a reasonable period, without charging a fee. We do not require account creation or unnecessary personal information to unsubscribe.
16.3 An opt out does not stop necessary engagement or legal communications. We do not add promotional material to such messages to avoid marketing rules. Sensitive information is not used for direct marketing without consent. Where required, we will tell you the source of marketing information on request.
17.1 Our website and online services may use cookies and similar technologies for essential functions, preferences, security, traffic measurement and, where enabled, advertising measurement. Website information may be collected directly by third party providers. The relevant notice and choices must reflect the tools actually deployed.
17.2 Optional tracking must be assessed before deployment, limited to necessary data and accompanied by any consent or opt out required by law. Tax records, TFNs, identity documents, portal contents and form responses must not be transmitted to advertising platforms. Analytics configurations must be checked for unintended disclosure through page addresses, events and forms.
17.3 You can use available site controls and browser settings to manage cookies. Blocking some cookies may affect functionality. Browser controls alone do not necessarily stop every form of tracking. Contact us for information about the tools used on our website.
17.4 Only provide information requested for the particular calculator or form. External sites have their own policies. Where we embed or select a third party service, we remain responsible for our own collection, disclosures and due diligence.
18.1 You may request access to or correction of personal information we hold about you by phone, email or writing. We verify your identity and any representative’s authority using information proportionate to the request. We respond within a reasonable period, ordinarily within 30 days, and explain any necessary extension.
18.2 We give access in the requested form where reasonable and practicable. Access may be restricted only on an applicable legal ground, such as protecting another person’s privacy or where disclosure would be unlawful. We consider redaction, an extract or another form of access where appropriate.
18.3 If access is refused, we provide written reasons unless unreasonable or unlawful to do so, and explain complaint options. Ownership of a workpaper, a confidentiality label or an unpaid invoice does not itself remove an applicable right of access to personal information within that record.
18.4 We do not charge for making an access request. Any charge for providing access must be permitted by law, reasonable and not excessive; we explain it in advance. We do not charge for correction requests or corrections.
18.5 We take reasonable steps to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. If you ask, we notify previous recipients of the correction unless impracticable or unlawful. If we refuse a correction, we give written reasons and complaint options and, on request, associate an appropriate statement of disagreement with the record.
18.6 You may ask us to delete information. We assess the request against the purposes and retention obligations in clause 14; there is no unconditional right to erase records that must lawfully be kept. Access and correction obligations also apply, where relevant, to personal information in AI inputs, outputs and retained transcripts.
19.1 Please contact the Privacy Officer using clause 21 and explain your concern and preferred outcome. We can assist you to record a verbal complaint. We aim to acknowledge it within 5 business days, investigate fairly and provide a substantive written response within 30 days. If more time is needed, we explain why and provide an expected response date.
19.2 If the matter remains unresolved, or you have not received a response, you may complain to the Office of the Australian Information Commissioner where it has jurisdiction. The OAIC generally expects you to give us an opportunity to respond first. Its privacy complaint process is available at www.oaic.gov.au/privacy/privacy-complaints; telephone 1300 363 992.
19.3 You may also raise a complaint about a tax agent service with the Tax Practitioners Board at www.tpb.gov.au/complaints. Nothing in this policy prevents a lawful complaint to a regulator or the exercise of another available legal remedy.
20.1 We review this policy at least annually and after material changes in law, systems, providers or services. The current policy is available at https://nanakaccountants.com.au/privacy-policy/ and a copy is available without charge on request.
20.2 Updates apply from the stated effective date. We take reasonable steps to explain material changes affecting information already held and obtain fresh permission where required. Publication of a revised policy does not retrospectively authorise a past disclosure or enlarge an existing consent.
Privacy Officer
Nanak Associates Pty Ltd trading as Nanak Accountants & Associates
Email: [email protected] | Phone: 1300 626 258
Postal address: 8 Tallis Cct Truganina VIC 3029
This schedule forms part of clause 10. Locations include relevant remote access and support, not only the primary hosting region.
Recipient category | Likely overseas countries | Purpose |
|---|---|---|
Offshore support personnel | India | Administration and accounting support under the Firm’s instructions and supervision. |
Accounting and practice platforms; document and email providers | Australia | Processing, hosting, backups, maintenance and support. |
Website, forms, booking, messaging, telephony and payment providers | Australia | Online functions, communications, appointment and payment administration. |
Identity and risk screening providers | Australia | Approved identity and applicable due diligence checks. |
Approved AI providers and their subprocessors | Australia] | Only the approved processing described in clause 7 and the engagement authority. |
We supply relevant provider names and processing details when seeking a disclosure authority. Where a country cannot practicably be identified after reasonable enquiries, we explain that limitation and the relevant safeguards. We update this schedule as our arrangements change.
The following processes may be used only where approved for the engagement. No autonomous AI decision is authorised by this schedule. The actual use of each process and its significance must be assessed under clause 8.
Process and information | Role of the program | Decision and human involvement |
|---|---|---|
Document extraction and transaction suggestions | Extracts or suggests entries and flags anomalies. | Supports bookkeeping, BAS and tax positions. Staff verify material entries, resolve flags and approve the resulting treatment. |
Research drafting and calculations | Summarises, drafts or calculates within approved controls. | Supports professional advice or return preparation. A competent reviewer verifies facts, sources and calculations and approves the work. |
Identity and risk screening where applicable | Returns verification results, possible matches or risk indicators. | Supports identity checks, client acceptance and compliance decisions. A person investigates matches and approves the outcome and any required report. |
Administrative assistance where enabled | Routes enquiries, suggests responses or offers available appointments. | Staff handle advice, complaints and exceptions. Binding engagement, fee and service eligibility decisions require a person. |