Privacy Policy

Open and transparent management of personal information

We will manage personal information, including credit information, in an open and transparent manner. We ensure that individuals are notified at the time of collecting their personal information:

  • what type of personal information is being collected
  • who that personal information will be disclosed to
  • how we use that personal information

We are responsible for dealing with queries about access to, or correction of, personal information and any privacy-related complaints. We ensure employees are trained regularly on obligations under the Privacy Act, including the Australian Privacy Principles.

We periodically update this privacy policy and will provide a copy free of charge on request and in a suitable format.

Anonymity and pseudonymity

Generally, we are not able to deal with customers who do not wish to identify themselves. However, where possible and appropriate, we will provide information of a general nature to unidentified individuals.

Collection of personal information

We collect personal information for the following purposes:

  • arranging and assessing an application for credit
  • managing credit
  • providing individuals with products or services marketed by us and our associates
  • managing our relationship with individuals
  • protecting individuals and ourselves from error or fraud
  • complying with regulatory requirements

Types of personal information we may collect and hold

Identification and contact details

We may collect personal information for identification purposes including contact details (for example name, address, phone number, email and other personal contact information), date of birth, occupation and employment history, and family status and relationship information (including cohabitants, dependants and the ages of those individuals in your household).

From time to time we may collect information that contains government identifiers which could include your tax file number. We do not use or disclose this information other than as required by law.

Financial information

We may collect financial information relating to your overall financial position for the purposes of our loan assessment. This may include bank statements (for example transaction and savings statements), credit card or store card statements, and information about your assets and liabilities.

Credit reporting information

We may collect credit reporting information including credit reports from credit reporting bodies. These reports may disclose repayment history with loans and financial liabilities, information about overdue payments and defaults, and information related to adverse credit history including infringements, insolvency or bankruptcy, court proceedings and other publicly available information.

We use credit-related information to assess eligibility to be provided with finance. The credit-related information available on credit reports is generally exchanged between credit and finance providers and credit reporting bodies.

Sensitive information

We may collect sensitive information if an individual is referred to an insurance agency or applies for an insurance-related product where the insurer may have affiliations with our business. Insurance products that may require sensitive information include life insurance, income protection, TPD and similar products.

It is unlikely we will need to collect sensitive information for applications relating to credit activities, but this may occur periodically. We only collect sensitive information directly from the individual, with consent, and only use it for the purpose for which it is provided. This may include information about religion, ethnicity, health information, criminal record or biometric information.

How we collect personal information

Where possible, we collect personal information directly from the individual. We may collect information when you fill out a form, speak with us by phone, or use our website. We may also use electronic means such as email or SMS to communicate with you and to verify your details.

Website activity and internet activity

When you access our website, we may monitor your use of the site to verify you and to provide information to you. This also helps us improve our services. We may collect information when you interact with us through social media channels. We do not expect personal information, including financial information, to be shared in social media forums and recommend secure channels for transmitting personal and sensitive information.

To improve our services and products, we may collect de-identified information from web users. This may include IP addresses or geographical information to help ensure the security of our web applications.

Unsolicited personal information

If we receive unsolicited personal information, we will determine whether we could have collected it by lawful and fair means and whether it relates to one of the purposes set out above. If we could not have collected it lawfully and fairly, or it does not relate to our purposes, we will destroy the personal information.

Notification of the collection of personal information

When we first collect personal information, we will notify the individual that we have collected their personal information. We will require individuals to consent to our use and disclosure of their personal information.

This notification will provide information about:

  • the purposes of collecting personal information and credit information
  • the entities we usually disclose personal information or credit information to
  • what happens if the individual chooses not to provide personal information
  • direct marketing that may be undertaken by us or any associates
  • our privacy policy and where it can be found
  • any disclosure of personal information to an overseas entity

If we know we are likely to disclose personal information to another identifiable entity, we will usually notify the individual of:

  • the identity and contact details of that organisation
  • why the information may be disclosed to that organisation

Direct marketing

We notify individuals at the time of collecting their personal information that it may be used by us and associated businesses for direct marketing purposes.

All direct marketing communications will include a prominent statement explaining how to opt out. For email communications, we will include an unsubscribe function.

We keep appropriate records to ensure individuals who opt out do not receive direct marketing communications. We do not charge a fee to unsubscribe. We do not sell personal information and we do not use sensitive information for direct marketing.

If we purchase personal information for direct marketing, we will conduct due diligence to ensure appropriate consents have been obtained.

Cross-border disclosure of personal information

We may disclose personal information to overseas organisations contracted to us for audits of loan files to ensure legislative, regulatory and industry expectations are met. We may store information in the cloud or other networked or electronic storage.

We may use cloud storage and IT servers that may be located overseas. As electronic storage can be accessed from various countries via an internet connection, it is not always practicable to know in which country information may be held.

Adoption, use or disclosure of government related identifiers

We do not use government related identifiers to identify individuals.

We may receive tax file numbers in the course of assessing an application for credit. We do not use or disclose tax file numbers for any purpose when engaging in credit activities.

Quality of personal information

We rely on individuals to help ensure personal information is accurate, up to date and complete. If we become aware information is inaccurate, out of date or incomplete, such as when mail is returned, we will update our systems accordingly.

Security of personal information

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Controls may include:

  • access restrictions using physical and electronic barriers
  • training of representatives on confidentiality
  • education of representatives in recognising possible cyber intrusions
  • governance around providing information to third parties
  • ICT security measures including firewalls, malware scanning and data encryption

Paper records are accessible only to employees and others as needed and are held in an office that is locked and security protected at night.

We keep personal information only for as long as reasonably necessary for the purpose it was collected or to comply with legal or ethical reporting and document retention requirements. We take reasonable steps to destroy personal information or de-identify it if it is no longer needed.

Access to personal information

Individuals may request access to personal information we hold about them. We will not charge a fee for requesting access where it is reasonable and practicable to do so.

We will verify identity prior to disclosing any personal information. When an individual requests access, we will search our customer relationship database and check whether there are paper records containing personal information.

Disclosure and access of information

We will not provide access where it is unreasonable or impracticable, or where the request would likely:

  • pose a serious threat to life, health or safety of any individual, or to public health or public safety
  • unreasonably impact the privacy of other individuals
  • be frivolous or vexatious
  • relate to anticipated legal proceedings where access should occur through discovery
  • reveal our intentions in negotiations in a way that would prejudice those negotiations
  • be unlawful or in breach of an Australian law
  • prejudice appropriate action relating to unlawful activity or misconduct connected with our functions or activities
  • prejudice an enforcement related activity of an enforcement body such as ASIC
  • reveal commercially sensitive information

We will usually respond to access requests within 7 days. Depending on the request, we may provide the information at the time the request is made. If a large amount is requested or it cannot be dealt with immediately, we will advise what personal information we hold and provide details of that information.

We will comply with reasonable requests to provide information in the requested format. If we do not provide access, we will give written reasons and advise the individual about our IDR and EDR options.

Correction of personal information

If we hold personal information and we are reasonably satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading, or we receive a request to correct it, we will take reasonable steps to correct the information.

If we correct information we have previously disclosed, we will take reasonable steps to notify the entity to which it was disclosed. We may not always make corrections. If we refuse a correction request, we will provide reasons and details of our IDR and EDR procedures.

If, after refusal, an individual requests we associate a statement with the record, we will take reasonable steps to do so.

What happens if you want to complain

If you have concerns about whether we have complied with the Privacy Act or this privacy policy, contact our Privacy Representative by email at compliance@spfgroup.com.au or by phone on 08 9286 6888.

Examples include internet privacy complaints, security breaches and misuse of personal information. Your complaint will be considered through our internal complaints resolution process and we will respond with a decision within 30 days.

If you remain dissatisfied, you may contact:

  • The Australian Financial Complaints Authority (AFCA).
    Phone 1800 931 678.
    Email info@afca.org.au. Mail GPO Box 3, Melbourne VIC 3001.
  • Office of the Australian Information Commissioner (OAIC).
    Website www.oaic.gov.au.
    Phone 1300 363 992.

Spam or telemarketing issues may be referred by the OAIC to the Australian Communications and Media Authority (ACMA).