Legal
Privacy Policy
1. Legislation
The Privacy Act 1988 (Cth) (Privacy Act) requires entities bound by the Australian Privacy Principles (APPs) to have a privacy policy. The Office of the Australian Information Commissioner (OAIC) is responsible for the privacy functions conferred by the Privacy Act.
2. What kinds of personal information are collected and held?
Royal Oak Capital Pty Ltd (Royal Oak) may be required to collect and hold personal information in order to provide services to our clients. Generally, the kinds of personal information we may collect include your name, home address, work address, email address, telephone number and signature.
When recruiting employees or appointing contractors, Royal Oak may collect and hold personal information such as the individual's name, contact details, date of birth, citizenship, employment references, credit and criminal records, regulatory accreditation (such as RG 146 accreditation for advisers), driver's licence information, and education and employment history. Once appointed, we will also collect and hold tax file numbers, financial information relating to the appointment, and banking details for payments.
3. How is it collected?
For our clients, personal information is mainly collected via meetings, telephone, email or correspondence, and online forms.
4. Why we collect, hold, use and disclose personal information
Royal Oak collects, holds, uses and discloses clients' personal information for the purposes of providing financial products or services, and complying with our regulatory and legal requirements, including under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, the Corporations Act 2001, the Australian Securities and Investments Commission Act 2001, the Bankruptcy Act 1966, the Tax Laws Amendment (Implementation of the FATCA Agreement) Act 2014, the Tax Laws Amendment (Implementation of the Common Reporting Standard) Act 2016, and applicable taxation law.
5. How is it held?
We respect the personal information you have entrusted to us and we have a responsibility to manage and protect that information. Your personal information will be stored in a secure environment, in hard copy, electronically or both. With the exceptions detailed in this policy, your information will only be available to employees of Royal Oak or our service providers on a need-to-know basis in order to perform their obligations and duties. Reasonable steps to protect personal information include technical and organisational measures consistent with APP 11.
6. What happens if personal information security is breached?
We implement corrective plans if our security measures are breached or your personal information is lost or inadvertently accessed by an unauthorised person. You and the Australian Information Commissioner will be advised if we assess that the data breach is likely to cause you serious harm. We monitor developments in Australian privacy law — including the reforms introduced by the Privacy and Other Legislation Amendment Act 2024 (Cth), such as the statutory tort for serious invasions of privacy and the criminal offences for doxxing — and maintain our practices accordingly.
7. How do you access your personal information and seek correction of it?
Should you wish to know what personal information Royal Oak holds about you, you may request to view this information by contacting our Privacy Officer:
Alex Gismondi
Ground Floor, 1 Cambridge Street, West Leederville WA 6007
Telephone: (08) 6280 1130
Email: alex@royaloakcapital.com.au
The Privacy Officer will promptly investigate your privacy enquiry and provide you with appropriate answers where required. Should you discover that any information is outdated, incorrect or incomplete, you may request to have the personal information corrected and Royal Oak will promptly update our records. You may also contact the Privacy Officer if you have any questions about our compliance with the Privacy Act 1988 (Cth).
8. How can I complain about a breach of my privacy?
If you wish to make a complaint about our handling of your personal information, you should contact the Royal Oak Privacy Officer as set out above. If we cannot resolve your complaint, you may raise your issue with the Office of the Australian Information Commissioner. All privacy breaches that have resulted in, or are likely to result in, serious harm to any affected individual are 'eligible data breaches' which must be reported by Royal Oak to the Office of the Australian Information Commissioner.
9. To whom might it be disclosed?
Generally, Royal Oak will only disclose your personal information for the purposes of providing our financial products or services to you. This may include disclosing your personal information to related entities of Royal Oak and to third parties where necessary to provide you with our financial products or services. These third parties may include government departments and regulatory authorities, and may also include our auditors, insurers, custodians, IT providers and third-party administrators (service providers).
We may disclose personal information to overseas recipients in order to provide our financial products and/or services. Before disclosing any personal information to an overseas recipient, Royal Oak will take reasonable steps to ensure the overseas recipient complies with the Australian Privacy Principles or is bound by a substantially similar privacy regime, or we will obtain your consent to the overseas disclosure, or the disclosure will be required or authorised by law.
10. Is sensitive personal information collected?
Royal Oak will not collect sensitive personal information about clients. Sensitive personal information is information about an individual's racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information or biometric templates.
11. Notifiable data breaches
Royal Oak is required to notify individuals and the Office of the Australian Information Commissioner about 'eligible data breaches'. An eligible data breach occurs when: there is unauthorised access to or disclosure of personal information held by us (or information is lost in circumstances where unauthorised access or disclosure is likely to occur); this is likely to result in serious harm to any of the individuals to whom the information relates; and we have been unable to prevent the likely risk of serious harm with remedial action. We will conduct an assessment if it is not clear whether a suspected data breach meets these criteria.
12. Automated decision-making
Where a computer program (including artificial intelligence) substantially makes, or does a thing substantially or directly related to making, a decision that could reasonably be expected to significantly affect your rights or interests, Royal Oak will disclose in this policy the kinds of personal information used in the operation of that program and the kinds of decisions made. Royal Oak does not currently use automated decision-making systems of this kind in relation to clients.
13. Training
Royal Oak staff receive regular training on the importance of compliance with the Privacy Act and our internal privacy practices.
14. Additional information
Further information on privacy in Australia may be obtained by visiting the website of the Office of the Australian Information Commissioner atoaic.gov.au. We regularly review OAIC guidance to keep informed of issues and developments in privacy law and our changing legal obligations.
Royal Oak Asset Management Pty Ltd (CAR No. 1297058) and Alex Gismondi (AR No. 1297050) are authorised representatives of Wholesale Securities Pty Ltd (ABN 89 601 790 470, AFSL No. 466877).