HRM Accounting Pty LtdPrivacy Policy
HRM Accounting Pty Ltd (ABN 29 688 280 435) (“HRM Accounting”, “we”, “our” or “us”) is committed to protecting and managing your personal information in accordance with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) and other applicable privacy laws.
The APPs provide a framework that supports the rights and obligations around the collection, holding, use, access to and correction of personal information. They apply equally to information held in paper and electronic form.
This document is our Privacy Policy. It explains how we collect, use, hold, store and disclose your personal information, and how you can access or correct it or make a complaint.
In this Privacy Policy, “you”, “your” or “client” refers to any individual about whom we collect personal information. Broadly, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in material form.Sensitive information is a special category of personal information — such as health information, or membership of a professional association — that attracts a higher level of protection under the APPs and generally requires your consent before we collect it.
By submitting information to us, engaging our services, or accessing our website or social media channels, you consent to us collecting and managing your personal information in accordance with this Privacy Policy.
About HRM Accounting
HRM Accounting is an Australian public accounting practice based in Brendale, Queensland. We are a Chartered Accounting firm (CA ANZ) and a Registered Tax Agent. We provide services including:• accounting and taxation;• business advisory and tax planning;• self managed superannuation fund (SMSF) administration and compliance;• company, trust and partnership compliance;• ASIC registered agent services; and• bookkeeping and management reporting.
We deliver our services through face-to-face and virtual meetings, our website (“Website”), email, telephone and related social media channels.Information provided on our Website or social media channels is general in nature, does not take into account your individual circumstances, and should not be relied upon as accounting, taxation or legal advice. We provide tailored advice only through a formal engagement.
This policy is effective from the date below. We may update it from time to time and will post the current version on our Website. Amendments take effect once posted, so please review this policy periodically.
What information do we collect about you?
Personal information
The personal information we collect varies with the nature of your dealings with us and the services you request. It may include:• Contact and identity details: your name, date of birth, address, email address and telephone details.• Financial information: your income, occupation, business and accounting records, expenditure and related financial details.• Identification documents: your driver licence, passport or other photographic identification.• Entity and family structure information: details of companies, trusts, partnerships and SMSFs you are associated with, and related parties.• Payment details: bank account and billing information used to process payments and issue invoices.• Website and device information: information collected when you use our Website, including IP address, browser and device type, pages visited and cookie data (see below).• Employment information: where you apply for a role with us, your contact details, qualifications, work history and information from referees.• Other information: any other information you provide, or authorise us to collect, in the course of your dealings with us.
Sensitive information and government identifiers
In providing our services we may collect certain sensitive information and government-related identifiers, including your Tax File Number (TFN). These are subject to additional protections under the Privacy Act, the TFN Rule and related laws.
We collect TFNs and other sensitive information only where reasonably necessary to provide our services or to meet our legal obligations, and we use them only for those permitted purposes. Where the law requires your consent before collection, we will obtain it.
Anti-Money Laundering and Counter-Terrorism Financing
As a provider of designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (“AML/CTF Act”), we are required to collect and verify identity information about our clients and, where relevant, their beneficial owners and associated parties. This may include identity documents, source of funds or wealth information, and the outcome of politically exposed person (PEP) and sanctions screening.
We collect, use, retain and disclose this information to meet our obligations under the AML/CTF Act, including customer due diligence, ongoing monitoring and record-keeping, and may disclose it to the Australian Transaction Reports and Analysis Centre (AUSTRAC) and other authorities as required by law. We are generally prohibited by law from telling you if a report about a matter has been made to AUSTRAC.
Consent and capacity
Where we require your consent to collect, use or disclose personal information and we are unsure whether you have capacity to provide it, we may seek consent from a person able to act on your behalf, such as a parent or legal guardian, an attorney under an enduring power of attorney, or another person recognised at law.You may decline to provide the personal information we request, but this may mean we are unable to provide you with some or all of our services.
Anonymity
Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym — for example, when making a general enquiry. For most of our dealings, however, we will need your name, contact details and sufficient information about your matter to assist you properly, and it is generally not practicable for us to act for you anonymously on an ongoing basis.
How and where do we collect your information?
We generally collect personal information directly from you — in meetings, by telephone, by email, through our Website forms, or through the secure client portal and software we use to deliver our services.
We also collect information through our practice software and systems, which may include:• Xero and Xero Practice Manager (XPM) — accounting, tax and practice management;• BGL CAS 360 — company and trust register management and ASIC compliance;• Microsoft 365 (including OneDrive) — email, document storage, collaboration and secure backup;• Adobe (e-signature) — electronic signing of documents; and• identity verification and screening tools — used for client onboarding and AML/CTF obligations.
Each of these providers maintains its own privacy and security practices. We take reasonable steps to use reputable providers and, where possible, to keep data within Australia.Website forms, analytics and cookies
When you submit an enquiry through a form on our Website, we collect the information you provide together with technical information such as your IP address, browser and device type.
We use Google Analytics and Google Business Profile (Google My Business) to understand how visitors find and use our Website and listing. These tools may collect anonymised information such as IP address, device and browser type, pages viewed, time on page, referral source and approximate location (city). This information is generally not personal information because you are not reasonably identifiable from it.
You can read about how Google handles data at https://policies.google.com/privacy, and opt out of Google Analytics at https://tools.google.com/dlpage/gaoptout.Our Website uses cookies, including Google Analytics cookies, to help us understand how visitors use the site. You can manage or delete cookies through your browser settings, though some parts of the Website may not function properly if cookies are disabled.
Social media
We use channels such as Facebook, Instagram and LinkedIn to communicate with the public. When you interact with us through these channels we collect the information you provide. Each platform has its own privacy policy governing its handling of your information.
Government online services
As your tax and accounting representative, we interact with government online services on your behalf, including the ATO’s Online services for agents, ASIC, and government digital identity systems such as myGovID / myID and Relationship Authorisation Manager (RAM). In doing so we may access, collect, use and submit your personal and financial information to these services as authorised by you and as required to provide our services and meet our legal obligations. Your information is handled by those government agencies in accordance with their own privacy policies.
Third parties
We may also collect personal information about you from third parties, for example an authorised representative acting on your behalf, your other professional advisers (such as your solicitor or financial adviser), referral partners, recruitment providers and referees, and payment service providers. If we receive information about you that we did not request, we will deal with it in accordance with the APPs and may de-identify or destroy it.
Why do we collect, hold, use and disclose your information?
Primary purposesWe collect and use personal information for the purposes for which it is provided, which may include:• providing accounting, taxation, advisory and compliance services to you and your entities;• communicating with you and confirming your identity;• responding to your requests, enquiries and complaints;• administering our engagement with you, including billing and account management;• meeting our professional, regulatory and legal obligations (including obligations to the ATO, ASIC, the Tax Practitioners Board, CA ANZ and AUSTRAC); and• any other purpose you would reasonably expect, or to which you have consented.
Secondary purposesWe may also use your information for related secondary purposes that you would reasonably expect, such as administrative functions, internal record-keeping, quality and risk management, and — where permitted — informing you about our services and relevant updates.
Use of artificial intelligence tools
In delivering our services we may use artificial intelligence (AI) tools to assist with tasks such as research, drafting, data analysis and document preparation. Where client information is processed using these tools, we do so under appropriate confidentiality and data-security arrangements, and we do not permit client information to be used to train publicly available AI models.
AI tools are used to assist our professional work, not to replace it. All advice and deliverables remain subject to the review and professional judgement of a Chartered Accountant. Your engagement letter contains our specific terms regarding the use of AI, and this Privacy Policy should be read together with it.
Who do we disclose your information to?
In the course of providing our services, we may disclose your personal information to:• the Australian Taxation Office, ASIC, the Tax Practitioners Board, AUSTRAC and other regulators, courts and authorities, as required or authorised by law;• your other advisers and representatives where you authorise us to do so, or where reasonably necessary to provide our services;• contractors, agents and software providers who assist us in operating our practice (such as those listed above);• referral and commercial partners, under appropriate arrangements and with disclosure where required; and• payment service providers who process transactions on our behalf.
We take reasonable steps to ensure that third parties to whom we disclose personal information handle it consistently with the APPs and this Privacy Policy, and use it only for the purpose for which it was provided.
Overseas disclosureSome of the software providers we use may store or process data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure your information is handled consistently with the APPs. We do not always know, and may be unable to specify, the countries in which overseas recipients are located. Where we engage a provider that stores data overseas, we seek providers that apply protections substantially similar to the APPs.
How do we hold and protect your information?
We operate a paperless practice and hold your information primarily in electronic form within secure, access-controlled systems. We take reasonable steps to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including:• multi-factor authentication on our core systems;• endpoint protection and anti-malware software, kept up to date;• controlled, role-based access to client information;• encrypted transmission and a secure client portal for sharing documents;• regular, encrypted data backup to secure cloud storage; and• confidentiality obligations for all personnel and contractors.
No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect your information, we cannot guarantee absolute security.
We maintain a data breach response plan. If we become aware of a data breach that is likely to result in serious harm to any individual whose information we hold, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable, in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
We retain personal information for as long as necessary to provide our services and to meet our legal, professional and record-keeping obligations. When we no longer require it and are not required by law to keep it, we take reasonable steps to destroy or de-identify it.
Accessing and correcting your information
You may request access to, or correction of, the personal information we hold about you at any time by contacting us using the details below. We will respond within a reasonable time and in accordance with the APPs.
We do not charge for making a request, but we may charge reasonable costs for providing access (for example, the time and expense of compiling information). If we decline a request, we will give you our reasons and, for a correction request, will note your requested correction with the relevant information.
Please help us keep your information accurate and up to date by letting us know if your details change or if you notice any errors.
Direct marketingWe may use your information to tell you about our services and relevant updates. You can opt out at any time by contacting us or using the unsubscribe function in our communications. If you opt out, we may still contact you about your ongoing engagement with us. We comply with the Spam Act 2003 (Cth).
ComplaintsIf you have a question or concern about how we have handled your personal information, please contact us using the details below. We will acknowledge your complaint and aim to respond within a reasonable time, usually within 30 days. If a matter is complex and requires longer, we will let you know.
If you are not satisfied with our response, or you believe we may have breached the APPs, you may complain to the Office of the Australian Information Commissioner (OAIC): telephone 1300 363 992, or online at www.oaic.gov.au.
How to contact us
All privacy enquiries and complaints should be directed to:HRM Accounting Pty LtdAttention: Privacy OfficerSuite 2, Building 3, 205 Leitchs Road, Brendale QLD 4500Phone: 0426 402 521Email: hemant.m@hrmaccounting.com.au
This Privacy Policy was last updated on 24 June 2026.