Appointments should be booked in advance

PRIVACY POLICY

Personal information, tax file numbers, cloud services and data security

Entity AIM S Australia Pty Ltd | ABN 21 159 602 276 | ACN 159 602 276
Trading names AIM S Australia; AIMS Australia Tax Accountants
Professional status Registered Tax Agent 24859230; CPA Public Practice status current as at 11 July 2026 (confirmed by the firm); eligibility under the applicable CPA Australia Professional Standards Scheme confirmed by the firm, subject to ongoing scheme requirements
Contact Level 30, 35 Collins Street, Melbourne VIC 3000 | 1300 11 24 67 | info@aimsaustralia.com.au | www.aimsaustralia.com.au
Document date: 11 July 2026

1. Purpose and status of this policy

This policy explains how AIM S Australia Pty Ltd collects, holds, uses, discloses, secures, accesses, corrects, retains and destroys personal information in providing tax and related professional services and operating its practice.

Where the Privacy Act 1988 and Australian Privacy Principles (APPs) apply to the firm or a particular activity, we comply with them. Independently, the Privacy (Tax File Number) Rule 2015 applies to the handling of TFN information by a TFN recipient, and professional confidentiality obligations apply to client information. The firm adopts the controls described in this policy as its minimum privacy framework even where a particular APP exemption may otherwise be available.

The firm does not currently provide professional designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006. If the firm’s service profile changes, it will assess the resulting privacy and regulatory obligations before commencing the service and update this policy and collection notices where required.

This policy is not a substitute for a collection notice. The separate Privacy Collection Notice is provided at or before collection, or as soon as practicable afterwards, to explain the circumstances of a particular collection.

 

2. Who we are and how to contact us

Legal entity AIM S Australia Pty Ltd, ABN 21 159 602 276, ACN 159 602 276
Trading names AIM S Australia; AIMS Australia Tax Accountants
Registered tax agent 24859230
Principal place of business Level 30, 35 Collins Street, Melbourne VIC 3000
Privacy contact Privacy Officer - info@aimsaustralia.com.au - 1300 11 24 67
Website www.aimsaustralia.com.au

3. Personal information we may collect

The information required depends on the engagement. We may collect:

  • identity and contact information, including name, date of birth, address, citizenship, residency, passport or visa information and authorised representatives;
  • government identifiers and taxation information, including TFN, ABN, ATO account, income statement, PAYG, Medicare, study-loan and superannuation information;
  • financial information, including bank details, payment records, income, expenses, loans, assets, liabilities, ownership interests and tax payments;
  • employment, business, trust, partnership, company and superannuation information;
  • property, rental, capital gains, shares, managed funds, employee share schemes, crypto exchanges, wallets, transaction records and blockchain addresses;
  • foreign income, foreign tax, travel, accommodation, family, employment and other facts relevant to Australian tax residency or treaty analysis;
  • spouse, dependant, family and related-party information relevant to a service;
  • health or other sensitive information only where relevant, such as information needed for a Medicare levy exemption or another lawful tax purpose;
  • identity-verification, authority, ownership and sanctions information where reasonably required for tax-practice risk management or by law;
  • communications, call notes, emails, portal records, signatures, declarations, approvals, complaints and advice
    records;website, device, security, access-log, cookie and analytics information; and
  • other information reasonably necessary for an agreed professional service or a legal, professional, security or administrative obligation.

We seek to collect only the information reasonably required for the relevant purpose and ask clients not to provide unnecessary full identity documents, TFNs, health information or third-party information.

Where APP 3 requires consent to collect sensitive information, we seek informed consent unless a permitted general situation or another lawful exception applies. Acceptance of general engagement terms is not treated as blanket consent to collect unrelated sensitive information.

4. Tax file numbers and government identifiers

TFN information is collected, recorded, used and disclosed only where permitted by taxation, personal assistance or superannuation law. We do not use a TFN as our general client identifier. Quoting an individual’s TFN is generally voluntary and it is not an offence to refuse; however, without it we may be unable to identify the correct ATO account, access authorised records, prepare or lodge a return or provide a requested taxation service. When requesting a TFN, we identify the law or taxation-law framework authorising the request, the purpose, the voluntary nature of
quotation and the practical consequences of refusal. 

If a document contains a TFN that is not required for the relevant purpose, the sender should redact it. We restrict access to TFN information, use secure exchange methods, and securely destroy or permanently de-identify TFN information when it is no longer lawfully required or necessary for an authorised purpose.

Other government identifiers are not adopted as our own identifier except where authorised by law or reasonably necessary to verify identity or perform a regulated function.

5. How we collect information

We collect information directly from the individual where reasonable and practicable, including through engagement forms, questionnaires, meetings, telephone, email, secure portals, document uploads, electronic signatures and payment systems.

We may also collect information from an authorised representative, spouse or family member, employer, bookkeeper, lawyer, financial adviser, migration agent, foreign tax adviser, property manager, bank, broker, exchange, wallet record, insurer, valuer, government body, public register, the ATO or another source the client authorises or that law permits.

Where we collect information about a person from someone else, we take reasonable steps to notify the person of relevant collection matters where required, unless an exception applies. Clients must have authority to provide third-party information and should provide only what is relevant.

6. Unsolicited personal information

If we receive personal information we did not request, we assess whether we could lawfully have collected it. If not, and no law requires retention, we will take reasonable steps to destroy or de-identify it. Before destruction, we may retain a minimal record needed to document the decision or meet a legal hold.

7. Why we collect, hold, use and disclose information

We use personal information for purposes including:

  • assessing and accepting an engagement, verifying identity and authority, checking conflicts and managing risk;
  • preparing and lodging tax returns, activity statements and related documents;
  • providing tax advice and preparing calculations, schedules, workpapers and correspondence;
  • accessing and communicating with the ATO and other authorities as authorised;
  • conducting quality review, supervision, training, risk management, insurance, complaints handling and professional compliance;
  • preventing fraud, protecting systems, investigating security events and responding to data breaches;
  • complying with taxation, TPB, professional, privacy, TFN, sanctions, court, regulator and other legal obligations;
  • engaging and managing approved software, cloud, IT, cybersecurity, payment, document, signature, specialist and professional providers;
  • billing, receiving payment, accounting, recordkeeping and administering the practice; and
  • sending service communications and, where permitted, relevant marketing or tax updates.

We do not sell client personal information. We do not use client information for an unrelated purpose unless authorised or permitted by law.

8. Privacy Collection Notice

At or before collection, or as soon as practicable afterwards, we provide or make the individual aware of the APP 5 matters relevant to the collection. These include our identity and contact details, the circumstances and purposes of collection, any legal authority, consequences of non-collection, usual disclosures, overseas recipients, and how to access, correct or complain.

A general privacy policy is available continuously, but it does not replace a contextual collection notice. A fresh or supplemental notice may be required where the purpose, source, recipient, overseas location or technology use changes materially.

9. Disclosure to government and professional bodies

We may disclose information to the ATO, TPB, ASIC, ABR, Services Australia, State or Territory revenue authorities,courts, tribunals, law-enforcement bodies or other regulators where authorised by the client or required or permitted by law.

We may disclose information to CPA Australia or another applicable professional body’s quality-review or disciplinary processes, professional indemnity insurers, external quality reviewers, lawyers or other professional advisers where reasonably necessary and subject to an applicable professional duty or right, client authority where required, confidentiality, legal privilege and data-minimisation safeguards.

10. Service providers and professional advisers

We use approved providers for tax software, client portals, cloud storage, email, electronic signatures, practice management, workflow, backup, cybersecurity, IT support, payments, identity verification, document processing and other professional or administrative functions.

The current Technology, Cloud and Provider Schedule supplements this policy and identifies the principal providers used by the firm, their purpose, relevant information categories and likely processing locations. It is supplied or linked where relevant to an engagement and is also available on request. The firm currently uses Seamless as its client portal, Dropbox for document storage, Xero Tax for tax-return preparation, electronic signatures and lodgment, and email for communications.

The approved schedule is incorporated into this policy by reference and is made available with engagement documents or on request. The version supplied or linked must match the schedule actually approved for use.

A provider may act under our control as a contracted processor or may be an independent recipient, depending on the arrangement. We assess this distinction rather than assuming every cloud use is or is not a legal disclosure.

11. Overseas access, storage and disclosure

Some approved providers may store, route, back up, access or support information outside Australia. Based on currently published provider information and subject to the firm’s actual account configurations, likely overseas processing or recipient locations may include New Zealand, the United States, the United Kingdom, Japan and countries in the European Union. Xero states that personal data may be transferred to and processed in Australia, New Zealand and the United States. Dropbox states that storage servers are located across the United States and, for eligible users, may also be available in Australia, the European Union, Japan and the United Kingdom. The current Provider Schedule records known account-specific settings and is updated where reasonably practicable. Where a provider uses numerous or changing countries or subprocessors, the schedule may link to the provider’s controlled country or subprocessor list and record why further country identification is impracticable.

Before a disclosure to an overseas recipient subject to APP 8, we take reasonable steps required in the circumstances to ensure the recipient does not breach the APPs, unless a statutory exception applies. Overseas storage or processing does not necessarily constitute a disclosure for APP 8 purposes; the legal character depends on whether information is made accessible outside the firm and released from its effective control. Safeguards may include enforceable contractual terms, security assessment, access restrictions, audit rights, subprocessor controls, incident notification, return or deletion obligations and review of local legal risk.

Client consent is not used as a blanket substitute for reasonable safeguards. Where informed consent is relied on for an APP 8 exception, the individual will be told the practical consequence, including that the firm may not be accountable under the Privacy Act for the overseas recipient’s conduct in the same way.

12. Overseas contractors and outsourced professional work

The firm does not currently use overseas contractors, offshore employees or external overseas preparers to perform client professional work. This does not mean that every cloud-provider employee, support person or subprocessor is located in Australia; technology-provider access and processing are described in the current Technology, Cloud and Provider Schedule.

Before any future outsourcing of professional work begins, the firm will assess professional confidentiality, APES 305 disclosure, supervision, competence, privacy, cybersecurity, conflicts, data location and client-authorisation requirements.

13. Unlisted technology services

No unlisted general-purpose technology service is authorised to process identifiable client confidential information unless the firm first assesses the provider, plan, purpose, data use, retention, access, security, subprocessors and processing locations and updates the applicable Provider Schedule and client disclosure. Until then, such a service may be used only with public information or material that has been properly de-identified. Any resulting output must be subject to competent human verification before it is used in professional work.

14. Identity, authority and sanctions information

We may collect identity, representative, authority, ownership, transaction and sanctions information where reasonably required to verify the client, prevent fraud, protect the tax system or comply with law and professional obligations.

The firm’s current services do not include professional designated services under the AML/CTF Act.

15. Data quality

We take reasonable steps to ensure personal information used or disclosed is accurate, current, complete and relevant for its purpose. Clients should notify us promptly of changes or errors. We may compare information with ATO, public, provider or source records where authorised and appropriate.

16. Security

We use risk-based administrative, physical and technical controls, which may include role-based access, multifactor authentication, encryption, secure portals, device management, logging, backups, patching, endpoint protection, staff screening and training, provider due diligence, incident response, segregation of duties and secure destruction.

No system is completely secure. We continually assess controls having regard to the information’s sensitivity, volume, location, threat environment, provider arrangements and foreseeable harm. Clients should use nominated secure channels and independently verify unusual payment or account-change instructions.

17. Data breaches

Suspected breaches are managed under the firm’s incident and data-breach response plan. We will contain the incident, preserve evidence, assess affected information and likely harm, remediate risk, document decisions and notify affected individuals and the OAIC where the Notifiable Data Breaches scheme requires it.

The NDB scheme can apply to a TFN recipient for a breach involving TFN information even where the entity is not otherwise subject to every APP. Other regulator, insurer, contractual or professional notifications may also be required.

18. Access and correction

An individual may request access to personal information we hold and correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading by contacting the Privacy Officer. We will verify identity and respond within a reasonable period.

Access or correction may be refused or limited where the law permits, including where it would unreasonably affect another person’s privacy, reveal privileged material, prejudice legal proceedings, expose a confidential commercial evaluation or be unlawful. We will ordinarily give written reasons and available complaint options.

Where corrected information was previously disclosed and the individual requests notification, we will take reasonable steps to notify the recipient unless impracticable or unlawful.

19. Retention and secure destruction

We retain information only for as long as reasonably necessary for the relevant purpose or required by law, professional standards, insurance, quality, dispute, litigation hold or another legitimate obligation. Different records have different periods; the firm applies a documented retention schedule rather than a single blanket period.

Examples include taxation and TPB client records, company and employee records, professional working papers, signed declarations, advice records, billing and complaints. Records concerning CGT assets, carried-forward losses or an unresolved dispute may need to be retained longer than a general period.

When information is no longer needed and no exception applies, we take reasonable steps to securely destroy or de-identify it, including copies and provider-held data within our control. Backup deletion may occur through controlled expiry cycles.

20. Anonymity and pseudonymity

A person may enquire anonymously or under a pseudonym where lawful and practicable. Most tax agent services require reliable identity, authority and taxpayer information, so the service may not be available unless the person is identified.

21. Direct marketing

We may send tax updates or information about our services where permitted by the Privacy Act, Spam Act 2003 and other applicable law. Commercial electronic messages will identify the sender and include a functional unsubscribe facility. We do not infer consent merely from receiving confidential tax information.

Unsubscribing from marketing does not stop necessary engagement, security, billing, legal or regulatory communications.

22. Website, cookies and analytics

Our website may use cookies, logs, analytics, security services and embedded content. These may collect IP address, device, browser, pages viewed, referrer, time and interaction data. The website cookie or tracking notice must identify material third-party tools and choices. Tracking technologies must not collect sensitive or confidential client data beyond what is disclosed and justified.

23. Privacy complaints

Send a privacy complaint to the Privacy Officer at info@aimsaustralia.com.au. Please identify the conduct, date, affected information, supporting material and preferred outcome. We will acknowledge, investigate and keep appropriate records. We aim to respond within 30 days, but will tell you if complexity or another lawful reason requires more time.

If you remain dissatisfied, you may complain to the Office of the Australian Information Commissioner. Other regulators or remedies may also be available depending on the issue.

24. Changes and version control

We may update this policy when law, services, technology, providers or practices change. The current approved version and effective date will be published or made readily available.

A material change will not be applied retrospectively in a manner that is unlawful or inconsistent with the purpose for which information was collected.

AIMS Australia Tax Accountants

CPA public practice and registered tax agents assisting clients in Australia and overseas with specialist Australian tax matters.

Location

Melbourne CBD

Level 30, 35 Collins Street, Melbourne VIC 3000

Caulfield South

Shop 1, 333 North Road, Caulfield South VIC 3162

The information on this website is general in nature and does not constitute tax advice. Australian tax outcomes depend on each client’s specific facts and circumstances. Clients should obtain professional advice before making tax, residency, CGT or lodgement decisions.

Liability limited by a scheme approved under Professional Standards Legislation.

Copyright © 2026 AIMS Australia Tax Accountants. All rights reserved.

CPA public practice and registered tax agents assisting clients in Australia and overseas with specialist Australian tax matters.

ABN 21 159 602 276

Registered Tax Agent No. 24859230

Contact

Locations

Melbourne CBD
Level 30, 35 Collins Street, Melbourne VIC 3000

Caulfield South
Shop 1, 333 North Road, Caulfield South VIC 3162

The information on this website is general in nature and does not constitute personal tax advice. Australian tax outcomes depend on each client’s specific facts and circumstances. Clients should obtain professional advice before making residency, CGT or lodgement decisions.
Liability limited by a scheme approved under Professional Standards Legislation.
Copyright © 2026 AIMS AUSTRALIA Tax Accountants. All rights reserved.