Important information · Draft
Privacy Policy
This page is an unapproved placeholder for legal and privacy review. It must be completed for AFC’s actual data practices before launch.
1. Scope and legal status
This page is a drafting framework, not an approved privacy policy. Confirm the legal entity responsible for personal information, the jurisdictions in which it operates, and whether the Privacy Act 1988 (Cth), the Australian Privacy Principles or any other privacy obligations apply.
Insert an effective date, version number and approved definitions before publication.
2. Information AFC may collect
The website enquiry form is designed to collect basic contact details, postcode, preferred contact method, broad financial goals, intended timing, an optional message, referral source and campaign attribution fields. Document any other information collected by telephone, email, meetings, cookies, analytics tools or introduced providers before launch.
Do not submit tax file numbers, banking passwords, full account or card numbers, superannuation member numbers, identity documents or exact financial balances through the website form.
3. How information is collected
Describe approved collection channels, including direct enquiries, website forms, telephone calls, referrals and any third-party technology. Explain when information may be collected from another person and how notice or consent will be handled.
Add approved cookie, analytics and spam-protection disclosures after the relevant tools and consent mechanism have been selected.
4. Purposes for using information
Confirm and describe each permitted purpose, which may include responding to an enquiry, understanding the category of support requested, arranging an introduction with permission, administering the relationship, maintaining security and meeting legal obligations.
Add separate, approved wording for marketing communications, consent, unsubscribe options and any secondary use of information.
5. Disclosure and referral introductions
Set out when AFC may disclose information to a third-party professional or financial-services organisation, what information may be shared, and how the person will be told the provider’s identity and purpose of disclosure. The final process must align with the consent presented at collection.
Identify other recipient categories, such as technology, hosting, professional advisory or regulatory providers, only after those arrangements have been confirmed. Do not claim that providers are vetted or licensed unless the relevant process and wording are approved.
6. Storage, security and retention
Document where personal information is stored, the security controls that actually apply, who may access it, the retention periods used and how information is deleted or de-identified. Do not publish absolute security guarantees.
Confirm whether any service provider stores or accesses information outside Australia and, if so, add the required countries, safeguards and disclosures.
7. Access and correction
Add the verified process for requesting access to or correction of personal information, including identity-verification steps, possible lawful exceptions, any fees and expected response time.
8. Privacy questions and complaints
Add the privacy contact, internal complaint steps and confirmed response time. Explain any external escalation rights only after the applicable regulator, scheme and contact details have been verified.