Privacy Policy

Our Commitment to Privacy 

At SuperGuardian, we are committed to delivering exceptional client service while respecting and protecting your privacy. We understand the importance of your personal and credit information and are dedicated to handling it in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). For more information about privacy in Australia, you can visit the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

This Privacy Policy outlines how we collect, use, store, disclose, and manage your personal and credit-related information. Updates to this policy will be published on our website, and we encourage you to check it regularly.


Security and Data Protection

SuperGuardian is committed to protecting the confidentiality, integrity, and availability of the personal information we hold. We comply with globally recognised cybersecurity and information security standards, including:

  • ISO/IEC 27001 – International standard for information security management
  • SOC Reporting Standards – Assuring strong internal controls
  • NIST Cybersecurity Framework – Supporting ongoing risk and data protection governance

These standards demonstrate our proactive approach to data security, and we regularly review and enhance our systems to ensure continued compliance and resilience.


Your Consent

We only collect, use, or disclose your personal information with your valid consent, which must be:

  • Voluntary
  • Informed
  • Current
  • Specific
  • Unambiguous
 

You have the right to withdraw your consent at any time by submitting a written request.


What Personal Information We Collect

We collect only the personal information necessary for our business activities, including:

·         Full name, contact details, date of birth

·         Tax file number, occupation, and financial records

·         Communications, enquiries, and service history

·         Information about dependants

·         Superannuation, investment, and bank records

·         Limited credit card details (not retained)


We may also collect credit-related information, such as:

·         Identification details (e.g., driver’s licence number)

·         Credit history or trade references

·         Information about your creditworthiness

·         Defaults and publicly available credit data


Document Verification Service (DVS)

We use the Document Verification Service (DVS) to verify identity using government-issued documents. This is required by law to meet anti-money laundering and identity verification obligations.

You have the right to:

  • Understand what information is collected and why
  • Decline to provide identification (noting it may limit our services)
  • Lodge complaints with us or the OAIC regarding the collection or use of your data


How We Collect Information

We collect personal information directly from you through:

  • Online and face-to-face interactions
  • Our website
  • Authorised third parties (with your consent)

You may choose not to authorise collection via third parties, which may impact our ability to deliver services.


How We Use Your Information

Primarily, your personal and credit information is used in order to provide our services to you.  We may also collect, hold and disclose your personal and credit information for the following purposes:

  • Provide services to you
  • Deliver personalised support and communication
  • Improve our website and services
  • Promote relevant products and services (unless you opt out)
  • Comply with regulatory obligations


We may also use the information for a purpose that is related to the primary purposes, if this use would be reasonably expected by you, or otherwise with your consent. You do not need to provide all the information requested by us, but this may prevent us from providing some or all of our products or services to you.


From time to time, we may provide you with direct marketing material. You can opt out of marketing communications at any time via email or unsubscribe links. We maintain an opt-out register to respect your preferences.


Disclosure of Information

In line with modern business practices common to many financial institutions and to meet your specific needs we may disclose your personal or credit information to the following organisations:

  • Superannuation funds, insurers, fund managers and other product providers
  • IT service providers and compliance consultants
  • Legal or financial representatives (as authorised)
  • Our offshore team in the Philippines (subject to equivalent privacy standards)
  • Government and regulatory bodies where legally required
  • Potential business acquirers (under strict confidentiality)

We do not share credit information with credit reporting agencies.


Storage and Security

Your information is stored securely in physical and digital formats and is accessible only to authorised personnel under confidentiality obligations.

We retain personal information for 7 years, as required by law. After this period, it is securely destroyed or de-identified.


Accuracy and Updates

SuperGuardian takes all reasonable precautions to ensure that the personal and credit information we collect, use and disclose is accurate, complete and up-to-date.

To ensure we can maintain this level of accuracy and completeness, we recommend that you:

  • inform us of any errors in your personal and credit information; and
  • update us with any changes to your personal or credit information as soon as possible.

If you provide inaccurate or incomplete information we may not be able to provide you with the products or services you are seeking.


Accessing Your Information

You have a right to access your personal or credit information, subject to certain exceptions allowed by law. We ask that you provide your request for access in writing, addressed to the Privacy Officer at the address set out in the “Complaints Resolutions” section, (for security reasons) and we will provide you with access to that personal or credit information. Access to the requested personal or credit information may include:

  • providing you with copies;
  • providing you with the opportunity for inspection; or
  • providing you with a summary.

If charges are applicable in providing access to you, we will disclose these charges to you prior to providing you with the information. Some exceptions exist where we will not provide you with access to your personal information, including if:

  • providing access would pose a serious threat to the life or health of a person;
  • providing access would have an unreasonable impact on the privacy of others;
  • the request for access is frivolous or vexatious;
  • the information is related to existing or anticipated legal proceedings between us and would not be discoverable in those proceedings;
  • providing access would reveal our intentions in relation to negotiations with you in such a way as to prejudice those negotiations;
  • providing access would be unlawful;
  • denying access is required or authorised by or under law;
  • providing access would be likely to prejudice certain operations by or on behalf of an enforcement body or an enforcement body requests that access not be provided on the grounds of national security.


Dealing Anonymously

Where lawful and practicable, you may interact with us anonymously or using a pseudonym (e.g., general enquiries).


Sensitive Information

We do not collect sensitive personal information (e.g., health, race, political views) unless:

  • You provide consent
  • It is required by law
  • It is necessary for a legal claim


Unsolicited Information

Without your consent we will not collect information about you that reveals your racial or ethnic origin, political opinions, religious or philosophical beliefs or affiliation, membership of professional or trade association, membership of a trade union, details of health, disability, sexual orientation, or criminal record. Should we ever undertake direct marketing, we will only use or disclose your sensitive information with your consent.

This is subject to some exceptions including when:

  • collection is required by law; and
  • the information is necessary for the establishment, exercise or defence of a legal claim.


Notifiable Data Breaches

SuperGuardian has a detailed Data Breach Response Plan to ensure prompt action in case of a data breach. If a breach is likely to result in serious harm:

  • Affected individuals and the OAIC will be notified within 72 hours
  • The breach will be investigated and remedial actions taken
  • Reports will be made to our executive team and Board


Privacy Impact Assessments (PIAs)

For high-risk data activities, such as sensitive data use or automated decision-making, we may undertake a Privacy Impact Assessment to evaluate and minimise risk.


Your Privacy Rights

You have the right to:

  • Access and correct your personal information
  • Withdraw consent
  • Lodge a complaint with us or the OAIC
  • Seek legal remedies in the event of a serious privacy breach


Website Use and Cookies

SuperGuardian’s website may provide links to third party websites. The use of your information by these third-party sites is not within our control and we cannot accept responsibility for the conduct of these organisations. Other websites are not subject to our privacy standards. You will need to contact or review those websites directly to ascertain their privacy policies.

You may register with us to receive newsletters and other information. By doing so, your name and email address will be collected and stored on our database. We take care to ensure that the personal information you give us on our website is protected. For example, our website has electronic security systems in place, including the use of firewalls and data encryption.

If you do not wish to receive any further information from us, or you wish to update your registration details, please email your request to us. We will endeavour to meet your request within 5 working days.

As is very common for companies, we use cookies on our website. Cookies are very small files which a website uses to identify you when you come back to the site and to store details about your use of the site. Cookies are not malicious programs that access or damage your computer. We use cookies to improve the experience of people using our website but you can instruct your web browser to refuse them.


Complaints and Contact Details

Please contact our Privacy Officer if you wish to complain about any breach or potential breach of your privacy rights. They will investigate the issue and determine the steps needed to resolve your complaint. We will contact you if we require any additional information from you and will notify you in writing of the determination of our Privacy Officer.


Joshua Williams
Chief Operating Officer

joshua@superguardian.com.au
1300 787 576

We will acknowledge and investigate your complaint, and respond in writing. If you are not satisfied with our response, you can escalate the complaint to the OAIC at www.oaic.gov.au.