Legal

Privacy policy

We are committed to protecting your privacy. This policy explains how we handle personal information collected through this website and our services.

01

What kinds of personal information is collected and held?

Compliance & Risk Services Pty Ltd (Compliance & Risk Services) does not collect personal information from its clients or users of our website.


Some personal information may be collected by users of our web-based tool, CRS-Certus. Users of CRS-Certus are responsible for the collection, management, protection and destruction of any personal information they collect and hold on CRS-Certus. Compliance & Risk Services has no control of information gathered, stored, used and destroyed by users of CRS-Certus.


The types of information stored by users of CRS-Certus may possibly include personal information such as:

  • Your name, home address, work address, email address, telephone number and signature.
  • Other identification verification information, including photographic information from documents including your birth certificate, passport; driver’s licence, pension card, citizenship certificate, tax notice assessment, Medicare card and utilities notices
  • Financial information about your sources of wealth and purpose of investment; and
  • Tax information including your tax file number (TFN)


When recruiting employees or appointing contractors Compliance & Risk Services may collect and hold personal information such as: the individual’s name, contact details, date of birth, citizenship, employment references, civil credit and criminal records, regulatory accreditation (such as RG 146 accreditation persons who may provide general financial product advice to retail clients) driver’s licence information, education and employment history.

Once appointed we will also collect and hold TFNs, financial information relating to the appointing and banking details for payments.

02

How is it collected?

Users of CRS-Certus may collect personal information directly from their clients and upload that into databases comprising the service.

Compliance & Risk Services may collect personal information from employees by request.

03

Why we collect, hold, use and disclose clients' personal information?

Users of CRS-Certus may collect hold, use and disclose personal information for the purposes of evidencing controls and practices relating to the:

  • Provision of financial products or services; and
  • Complying with our regulatory or legal requirements, including:
    • the Anti-Money Laundering & Counter-Terrorism Act 2006
    • the Corporations Act 2001
    • the Australian Securities and Investments Commission Act 2001
    • the Bankruptcy Act 1966
    • the Tax Laws Amendment (Implementation of the FATCA Agreement) Act 2014
    • the Tax Laws Amendment (Implementation of the Common Reporting Standard) Act 2016; and
    • other applicable taxation law.

04

How is it held?

Personal information is stored in a secure environment on CRS-Certus.

Personal information is only made available to users of CRS-Certus and, if permitted by those users, employees of Compliance & Risk Services on a need-to-know basis to perform their obligations and duties.

Compliance & Risk Services maintains information security standards and requires similar standards to be maintained by our service providers. Cybersecurity is monitored through our enterprise risk management framework and we consider both technical and organisational measures when we developed our IT systems and data controls.

05

What happens if personal information security is breached?

We will implement corrective plans if our security measures are breached or your personal information is lost or inadvertently accessed by an unauthorised person. The priority of any plan would be to secure your personal information if it is lost or accessed where possible. If this is not possible, we will inform you of the loss or access and we will undertake an assessment of the potential impact on you. We will inform you and the OIAC within 30 days of discovery if we assess the data breach is likely to cause you serious harm.

06

How do you access your personal information and seek correction of it?

Should you wish to know what personal information Compliance & Risk Services holds on you, you may request to view this information by contacting our Privacy Officer:

Name: Privacy Officer
Address: Suite 2, Level 47, 80 Collins Street (North Tower) Melbourne, VIC, 3000
Tel no.: 03 9663 4456
Email: info@wpflora.online

The Privacy Officer will promptly investigate your privacy enquiry and provide you with appropriate answers where required. Should you discover that any information is outdated, incorrect or incomplete you may request to have the personal information corrected and Compliance & Risk Services will promptly update our records. You may also contact the Privacy Officer if you have any questions on our compliance with the Privacy Act 1988 (Cth).

07

How can I complain about a breach of my privacy?

If you wish to make a complaint about our handling of your personal information you should contact the Compliance & Risk Services Privacy Officer as referred to above. If we cannot resolve your complaint then you may raise your issue with the OIAC.

All privacy breaches that have resulted in or are likely to result in serious harm to any individual affected are ‘eligible data breaches‘ which must be reported by Compliance & Risk Services to the Office of the Australian Information Commissioner.

08

To whom might it be disclosed?

Compliance & Risk Services will only disclose personal information collected and held by us to a government authority if required to or compelled by law.

09

Is sensitive personal information collected?

Compliance & Risk Services will not collect sensitive personal information on clients. Sensitive personal information is information about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information or biometric templates.

10

Notifiable Data Breaches

Compliance & Risk Services is required to notify individuals and the Office of the Australian Information Commissioner about eligible data breaches. An eligible data breach occurs when the following criteria are met:

  • There is unauthorised access to or disclosure of personal information held by us (or information is lost in circumstances where unauthorised access or disclosure is likely to occur).
  • This is likely to result in serious harm to any of the individuals to whom the information relates.
  • We have been unable to prevent the likely risk of serious harm with remedial action.


We will conduct an assessment if it is not clear if a suspected data breach meets these criteria. The assessment will determine whether the breach is an eligible data breach that triggers notification obligations.

If your personal information is compromised by an eligible data breach we will inform you about that matter as soon as practicably possible.

11

Destruction of personal information

We will not hold your personal information any longer than is required by law.

12

Additional information

Further information on privacy in Australia may be obtained by visiting the website of the Office of the Australian Information Commissioner (OAIC) at: http://www.oaic.gov.au/. We regularly review the OAIC website to keep informed of issues and developments in privacy law and changing legal obligations.

13

Staff training

We will provide training to our employees and relevant contractors on this policy at least annually.

14

Review

We will review this policy at least annually or more frequently if required by law reform.

— End of Policy —