PRIVACY POLICY

Personal information, TFNs, cloud services and data security

Legal entity AIM S AUSTRALIA PTY. LTD.
ABN / ACN ABN 21 159 602 276 | ACN 159 602 276
Trading names AIM S AUSTRALIA | AIMS Australia Tax Accountants
Registered Tax Agent number No. 24859230
Professional practice CPA Australia public practice; participation in the applicable CPA Australia Professional Standards Scheme, subject to continuing eligibility and Scheme terms
Principal place of business Level 30, 35 Collins Street, Melbourne VIC 3000 | 1300 11 24 67 | info@aimsaustralia.com.au | www.aimsaustralia.com.au
Contact 1300 11 24 67; info@aimsaustralia.com.au;
www.aimsaustralia.com.au

1. Purpose and application

This Privacy Policy explains how AIM S AUSTRALIA PTY. LTD. (AIMS), carrying on business under the registered business names AIM S Australia and AIMS Australia Tax Accountants, manages personal information in operating its Australian tax accounting practice.

Where the Privacy Act 1988 and Australian Privacy Principles (APPs) apply to AIMS or a particular activity, AIMS complies with them. AIMS is also subject to separate confidentiality, TFN, taxation, professional and security obligations that may apply independently of the APPs. TFN information is subject to the Privacy (Tax File Number) Rule 2015 when AIMS is a TFN recipient. This Policy is a transparency statement and does not itself expand the application of the Privacy Act or form part of an engagement contract unless expressly incorporated.

This Policy is not a substitute for a collection notice. The Privacy Collection Notice provides collection-specific information at or before collection, or as soon as practicable afterwards where required.

2. Privacy contact

Privacy Officer: info@aimsaustralia.com.au | 1300 11 24 67 | Level 30, 35 Collins Street, Melbourne VIC 3000.

3. Personal information AIMS may hold

The information held depends on the service and may include identity/contact details; tax and government identifiers; residency/travel information; employment, business, property, investment, banking and transaction information; tax returns and ATO records; foreign income/tax records; family/relationship information relevant to tax law; correspondence and advice; engagement/payment information; proof-of-identity verification records; and system/security metadata.

AIMS seeks to collect and retain only information reasonably necessary for its functions, professional obligations, accepted services or another lawful purpose.

4. Sensitive information and TFNs

AIMS collects sensitive information only where reasonably necessary for its functions and lawfully permitted, including where consent or another legal basis is required.

TFNs are collected, used, disclosed, secured and destroyed in accordance with applicable TFN-law requirements. AIMS does not adopt a TFN as its own general-purpose client identifier and does not disclose TFN information except where lawfully permitted.

5. How AIMS collects information

Pre-engagement enquiries and preliminary scoping. AIMS may collect limited information from prospective clients before an engagement exists. This may include non-sensitive responses provided by email and selected redacted documents supplied for the limited purpose of understanding the proposed matter, assessing whether AIMS has capacity and can accept it, identifying likely scope and information requirements, and preparing a proposed fixed fee and written scope.

Where preliminary documents are reasonably required, AIMS may invite the prospective client to use a restricted-access, client-controlled Dropbox, Google Drive or Microsoft OneDrive folder or link. AIMS asks prospective clients to minimise the information provided and redact unnecessary sensitive identifiers, such as TFNs, full dates of birth, bank/card details, login credentials and identity-document numbers or copies. Preliminary material is handled under this Policy even if AIMS ultimately declines the engagement.

AIMS does not treat preliminary scoping as authority to access ATO records, link a taxpayer to AIMS, lodge documents, provide personalised tax advice or commence substantive professional work. Those steps require the applicable engagement, identity/authority and payment conditions and any separate ATO or client approval required by law or ATO procedure.

AIMS may collect personal information directly from individuals; through Seamlss, email, telephone, forms and secure document-transfer systems; from authorised representatives; from the ATO or other government bodies under authority/law; from predecessor advisers or specialists with appropriate authority; from public registers; and from other sources relevant to a proposed or accepted professional service.

AIMS provides or makes available a Privacy Collection Notice at or before collection, or as soon as practicable afterwards where required.

6. Unsolicited information

If AIMS receives unsolicited personal information, it will consider whether the information could lawfully have been collected. If not, and if it is lawful and reasonable to do so, AIMS will destroy or de-identify it. Information required to be retained by law or forming part of a record that must be kept is handled according to the applicable requirement.

7. Purposes for which information is used

AIMS uses personal information for client acceptance and continuance; identity/authority verification; delivery and quality control of professional services; ATO/government interactions; client communications and approvals; engagement/fee administration; recordkeeping; security/fraud prevention; legal and professional compliance; complaints, claims and insurance; business continuity; training/quality management where appropriate; and other purposes reasonably expected or otherwise authorised by law.

8. Disclosure and professional confidentiality

AIMS may disclose information to recipients reasonably necessary for those purposes and permitted by law, including the ATO, approved technology/cloud providers, authorised AIMS personnel, insurers or professional reviewers where permitted, lawyers/specialists, service providers and regulators, courts or tribunals.

Unless AIMS has the client’s permission or a legal duty to disclose, AIMS does not disclose information relating to a client’s affairs to a third party. Where permission is required for material technology/cloud providers, AIMS obtains it through the client Engagement Letter or another written authority. Privacy notice acknowledgement is not used as a substitute for that permission.

9. Technology, cloud providers and AI-enabled tools

The Technology, Cloud and Provider Schedule identifies AIMS’ principal confirmed technology providers and the information/function involved. Provider arrangements are subject to due diligence, access control and change management.

AIMS may use approved general-purpose artificial-intelligence-enabled tools only for general professional-support purposes, such as research assistance, drafting, summarisation, issue spotting, document organisation, template development and quality-control assistance. A general-purpose AI service is not an AIMS system of record and AI output is not a substitute for professional judgment; material output is subject to competent human review and verification before it is relied upon or communicated as professional work.

Under AIMS’ standard workflow, identifiable or reasonably re-identifiable client-affairs information is not submitted to a general-purpose AI service. Before any client-derived material is used with such a service, AIMS takes reasonable steps to remove, mask or generalise identifiers and to minimise the information so that the provider cannot reasonably associate it with a client or another individual. This includes, as applicable, names, TFNs, ABNs, dates of birth, addresses, contact details, bank details, identity documents, account or reference numbers, signatures, login credentials, property addresses and combinations of facts reasonably capable of re-identification.

De-identification does not displace Code item 6 or any other confidentiality obligation. If material could still reasonably reveal or be linked to a client’s affairs, it must not be submitted to a general-purpose AI service. AIMS’ standard policy does not provide a client-specific authorisation pathway that permits identifiable client-affairs information to be submitted to a general-purpose AI service.

This direct-use restriction does not amount to a representation that an approved core software provider never uses AI-related subprocessors within its own service. Such vendor arrangements are assessed under AIMS’ provider-governance process, including available subprocessor information, feature configuration, confidentiality and client-permission requirements.

10. Overseas processing and cross-border disclosure

Some approved providers and their subprocessors may store, route, back up, access or support information outside Australia. The Provider Schedule identifies reasonably ascertainable countries or regions and known account-specific limitations where practicable.

Where APP 8 applies to a disclosure to an overseas recipient, AIMS takes the reasonable steps required in the circumstances unless an exception applies. AIMS also assesses confidentiality and security risk for overseas processing or provider access even where the arrangement is not legally characterised as an APP 8 disclosure.

11. Security

AIMS takes reasonable steps appropriate to its size, services and information risks to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Controls include approved systems, role-based access, authentication and multi-factor authentication where supported and required by firm policy, secure sharing channels, endpoint/account controls, provider governance, staff confidentiality obligations, backup/availability controls, cyber awareness, incident escalation and periodic review.

No internet-connected system can be guaranteed absolutely secure, and this Policy does not make such a guarantee.

12. Data breaches

AIMS maintains an incident and data-breach response process. Suspected breaches are contained, investigated and assessed. Where the Notifiable Data Breaches scheme applies and an eligible data breach is established, AIMS will make notifications required by the Privacy Act, including to affected individuals and the OAIC as applicable. AIMS will also consider any separate TPB, insurer, professional-body or contractual notification obligation.

13. Data quality

AIMS takes reasonable steps to keep personal information accurate, complete and up to date where relevant to its use or disclosure. Clients should promptly notify AIMS of changed contact details, residency, authority, bank details or other facts material to an engagement.

14. Access and correction

Individuals may request access to or correction of personal information held by AIMS. AIMS will respond within a reasonable period and may verify identity before release. Access may be refused or limited where an applicable legal exception, confidentiality obligation, privilege or another person’s rights require it. Where appropriate, AIMS will provide reasons and available complaint mechanisms.

15. Retention, destruction and de-identification

AIMS retains information for periods required or reasonably justified by taxation law, the Tax Agent Services framework, proof-of-identity evidence requirements, professional standards, insurance, disputes/claims, limitation periods, CGT/history records and other lawful purposes.

Required records of tax agent services are generally retained for at least five years after the relevant service is provided; some information must be retained longer. Proof-of-identity verification records are retained for the period required by applicable TPB guidance. When information is no longer reasonably required and no exception applies, AIMS takes reasonable steps to securely destroy or de-identify it.

16. Identity documents and verification evidence

AIMS seeks to avoid unnecessary duplication or long-term retention of identity-document images. Where professional requirements can be satisfied by recording the verification method, date, result and sufficient details rather than retaining the identity-document copy, AIMS prefers that approach, subject to law, provider constraints and engagement risk.

17. Anonymity and pseudonymity

Where lawful and practicable, an individual may interact with AIMS anonymously or using a pseudonym for a general enquiry. Tax agent services, identity verification, ATO interaction and many engagement functions ordinarily require verified identity and cannot be provided anonymously.

18. Direct marketing

AIMS may use contact information for service updates or marketing where permitted by law. Commercial electronic messages are managed consistently with the Spam Act 2003 where it applies, including applicable consent, sender-identification and functional-unsubscribe requirements. Individuals may opt out of marketing communications at any time using the unsubscribe mechanism or by contacting AIMS. Service, engagement, regulatory, security and transactional communications may still be sent where relevant and lawful.

19. Website cookies and analytics

AIMS’ websites may use cookies, analytics and similar technologies for security, functionality, performance and analytics. Where consent or choice is required by applicable law or platform settings, AIMS will provide the relevant control. Browser settings may also allow users to restrict cookies, although this can affect website functionality.

20. Government-related identifiers

AIMS does not adopt, use or disclose a government-related identifier as its own identifier except where authorised by law or otherwise permitted. TFNs receive the additional protections described in this Policy.

21. Overseas clients and foreign privacy law

AIMS provides Australian professional services and this Policy addresses Australian privacy and professional obligations. A client’s presence overseas may cause another mandatory privacy law to apply to a particular processing activity. AIMS will assess material obligations that apply to AIMS; this Policy is not a representation that AIMS has voluntarily assumed every foreign privacy regime merely because a client is overseas.

22. Automated decision transparency from 10 December 2026

New APP 1 privacy-policy requirements concerning certain decisions made or substantially assisted by computer programs commence on 10 December 2026. AIMS will assess its relevant systems before those provisions commence and will update this Policy with the information required by APP 1.7 to 1.9 if, and to the extent, those provisions apply to AIMS’ arrangements and decisions.

23. Complaints

Privacy enquiries or complaints should be sent to the Privacy Officer at info@aimsaustralia.com.au. AIMS will investigate and respond under its complaints and incident procedures. Where the Privacy Act provides a right to complain to the OAIC after AIMS has had a reasonable opportunity to respond, that right is preserved.

24. Changes and version control

This Policy is current as at 7 September 2026. AIMS reviews it on material provider, service, legal, security or business changes and under its regulatory review cycle. The current approved version is published or made readily available, and superseded versions are retained internally for appropriate audit evidence.

A material change will not be applied retrospectively in a manner that is unlawful or inconsistent with the purpose for which information was collected.

AIM S AUSTRALIA PTY. LTD.

Effective / revision date:  7 September 2026

Liability limited by a scheme approved under Professional Standards Legislation.

Proudly supporting The Smith Family

Locations

Melbourne CBD
Level 30, 35 Collins Street, Melbourne VIC 3000

Caulfield South
Shop 1, 333 North Road, Caulfield South VIC 3162

The information on this website is general in nature and does not constitute tax, legal, financial, migration or other professional advice. Australian tax outcomes depend on the applicable law and each client’s specific facts and circumstances. Professional advice should be obtained before acting or relying on this information.
Liability limited by a scheme approved under Professional Standards Legislation.
Copyright © 2026 AIM S Australia Pty Ltd. | Trading as AIMS Australia Tax Accountants | ABN 21 159 602 276 | All rights reserved.