Privacy Policy
1. Scope of the Policy
This Privacy Policy explains how Ashleigh Maree Clark Trading As Cruzy Accounting And Taxation (ABN 25 115 894 370) (referred to as “Cruzy Accounting And Taxation”, "we", "us", or "our") manages personal information. It also describes your rights to access and correct personal information we hold about you, and how you can make a complaint about our management of your personal information.
This policy applies to personal information collected from clients, prospective clients, and associated individuals (including directors, officers, shareholders, beneficial owners, controllers, authorised representatives, and other associated persons) in the course of providing accounting, taxation, bookkeeping, and business advisory services. This policy is in addition to our professional obligations of confidentiality to clients and other parties arising from professional standards, ethical codes, and contractual retainers. This Privacy Policy does not apply to information we collect about businesses, companies or other institutions, however it does apply to information about the individuals in those businesses, companies or institutions that we store. Individuals under the age of 18 years must not use our website and services without their parent or legal guardian’s consent.
We have adopted this Privacy Policy to ensure that we have standards in place to protect the personal information or other information that we collect about individuals that is necessary and incidental to providing the systems and services that we offer, and the normal day-to-day operations of our business. This Privacy Policy follows the standards of the Australian Privacy Principles (APPs) set by the Australian Government for the handling of Personal Information or other information under the Privacy Act 1988 (Cth) (the Act). By publishing this Privacy Policy, we aim to make it easy for our clients and the public to understand what personal information we collect and store, why we do so, how we receive and obtain that information, and the rights an individual has with respect to their personal information in our possession. We may do things in addition to what is stated in this Privacy Policy to comply with the APPs, and nothing in this Privacy Policy shall deem us to have not complied with the APPs.
2. Application of Privacy Laws
Statutorily Regulated Data: This comprises all personal information collected, held, used, or disclosed solely for the purposes of, or in connection with, our compliance obligations under the applicable anti-money laundering and counter-terrorism financing legislation. This includes identity verification documents, beneficial ownership structures, and customer due diligence records. Such data must be managed in strict accordance with the APPs.
Non-Regulated Commercial Data: This comprises standard commercial, accounting, taxation, and bookkeeping data collected in the ordinary course of our professional engagement.
We have elected to treat all personal information managed across our entire operations, including both Statutorily Regulated Data and Non-Regulated Commercial Data, as if it were fully subject to the APPs. This ensures a single, robust, unified data protection standard across our practice.
3. Types of Personal Information Collected
In the course of conducting our business and providing professional services, it is necessary for us to collect personal information. This information allows us to identify who an individual is, contact them in the ordinary course of business, transact with them, and fulfill our professional obligations. References to “personal information” means information as it is defined in the Privacy Act, and all forms of such information, physical and digital, whether collected or stored electronically or in hardcopy.
The types of personal information we may collect and hold include, without limitation:
Identity Information: Full name, date of birth, gender, signature, photographic identification (such as a driver's licence or passport), and offices or directorships held.
Contact Information: Residential, business, and postal addresses, email addresses, telephone numbers, and fax numbers.
Professional and Business Information: Occupation, employer, job title, professional qualifications, business structures, trust deeds, partnership agreements, and business holdings.
Financial Information: Bank account details, billing information, payment card details, financial statements, assets and liabilities, transaction histories, source of funds, and tax file numbers (TFNs).
Matter-Related Information: Information relevant to our Services, such as your accounting, taxation, bookkeeping, or advisory matters, or the matters of our clients.
Communication Records: Records of correspondence, emails, telephone calls, and meetings with you or your representatives. We may collect any personal correspondence that you sends us, or that is sent to us by others about your activities.
Statistical Information. We may collect information about an individual’s online and offline preferences, habits, movements, trends, decisions, associations, memberships, finances, purchases and other information for statistical purposes.
Website and Technical Data: IP addresses, browser types, device information, pages visited, and cookies collected during your interactions with our websites, including www.cruzyaccountingandtaxation.com. We may also collect non-Personal Information about an individual such as information regarding their computer, network and browser. This may include their IP address, for example for electronic signature of documents. Where non-Personal Information is collected the Australian Privacy Principles do not apply.
Sensitive Information: Where necessary and authorised by law or with your consent, we may collect sensitive information such as professional or trade association memberships (which may be used to verify your occupation), political affiliations or exposures (to determine if you are a politically exposed person), or health information (where relevant to the Services, such as preparation of taxation returns, deadline extension or other submissions to the Australian Taxation Office, medical expenses tax offsets).
4. Customer Due Diligence and Identity Verification
We are required to verify your identity and collect specific personal information under the applicable anti-money laundering and counter-terrorism financing legislation (including the Anti-Money Laundering And Counter-Terrorism Financing Act 2006 (Cth)) (AML/CTF Regime) when we provide certain designated services. The AML/CTF Regime requires customer due diligence (CDD) which is more extensive than our standard commercial onboarding and is subject to strict handling rules under Australian law.
The specific information collected for CDD generally includes:
Your full name, date of birth, and residential address.
Photographic identification documents, such as a passport, driver's licence, or national identity card, including unique document identifiers.
Information regarding the beneficial ownership of any corporate entity, trust, or partnership on behalf of which you are instructing us, including trust deeds, company registers, and corporate control structures.
Information regarding your source of wealth and source of funds to manage potential financial crime risks associated with the provision of our services.
Information regarding whether you, or any beneficial owner of your organisation, is a politically exposed person (PEP) or subject to international sanctions.
If we are unable to collect and verify the CDD information, we are prohibited by law from commencing or continuing to provide designated services to you, and we may be required to place restrictions on the scope of our engagement or to terminate our relationship with you.
5. Methods of Information Collection
We collect personal information through lawful and fair means, and generally directly from you, as the individual concerned, unless it is unreasonable or impracticable to do so. Information is typically collected in the following circumstances:
Direct Collection: When you register to use our services, complete client onboarding forms, provide identity documents, upload information to our secure client portals, correspond with us including via email or post, speak with us on the telephone, meet with us in person, or generally when dealing with us. When you accesses us through the internet we may collect information using cookies (if relevant – you can adjust the browser’s setting to accept or reject cookies) or analytical services.
Indirect Collection: We may collect personal information about you from third parties, including:
o Our clients, where we collect information about associates, employees, or beneficiaries in the course of providing professional services;
o Third-party identity verification service providers engaged to verify your identity on our behalf;
o When an individual supplies us with goods or services;
o Publicly available sources, including the internet, corporate registers, land registries, trust registers, and professional directories;
o Financial institutions, banks, or professional intermediaries (such as financial planners or legal representatives) who introduce you to us; and
o Recruitment agencies, previous employers, and background check providers (for job applicants).
If you provide us with personal information about another person (such as an employee, trustee, director, shareholder, partner, or beneficiary), you warrant and confirm that you are authorised to do so and that you have taken all necessary steps to notify that person of the matters set out in this Privacy Policy, and obtained any required consents, permissions, or rights, so that we may collect, use, and disclose that information for the purposes described herein.
Where we obtain personal information without an individual's knowledge (such as by accidental acquisition from a client's records), we will, within a reasonable period, determine whether we could have lawfully collected the information. If not, we will securely destroy or de-identify the information as soon as practicable, provided it is lawful and reasonable to do so.
As there are many circumstances in which we may collect information both electronically and physically, we will endeavour to ensure you are always aware of when your Personal Information is being collected.
6. Primary and Secondary Purposes of Collection and Use
We collect, hold, use, and disclose personal information for the primary purpose of providing professional services, including but not limited accounting, taxation, bookkeeping, and advisory services, and operating our professional practice. This includes:
Verifying your identity and conducting statutory customer due diligence;
Providing professional advice, preparing statements and returns, and administering financial accounts;
Managing client matters, maintaining files, and administering our practice;
Billing, processing payments, and collecting fees, including pursuing our rights under any engagement agreement; and
Complying with our legal, professional, regulatory, and insurance obligations.
We may also use and disclose personal information for secondary purposes that are directly related to our primary purposes, including:
Maintaining and developing our ongoing relationship with you, including sending client updates, newsletters, and invitations to seminars. You may opt out of receiving these communications at any time by contacting our Privacy Officer or using the unsubscribe function on an email;
Conducting internal reporting, business analysis, and quality assurance;
Improving our services, systems, and software platforms;
Enforcing our contractual rights and recovering outstanding debts; and
Managing risks, obtaining professional advice, and maintaining appropriate professional indemnity insurance coverage.
Opting “out” of personal information collection
You may opt to not have us collect your Personal Information or other information. If you do not provide the requested personal information we may be unable to verify your identity, commence or continue acting for you, or we may need to place restrictions on the scope of services we can provide.
Anonymity and Pseudonyms. Wherever it is lawful and practicable, you have the option of interacting with us anonymously or by using a pseudonym. For example, you may make general enquiries about our services or browse our website without identifying yourself. However, please note that once you formally engage our services, we are legally required to verify your identity, and it will be impracticable for us to assist you with the Services we offer without your real identity.
7. Cloud Software
In providing our accounting and bookkeeping services, we utilise and integrate with major third-party cloud-based accounting and financial management platforms, including Xero and other approved software applications. Your personal and financial information is synchronised, processed, and stored within these third-party cloud environments.
We take reasonable steps to ensure that our cloud software vendors are reputable and maintain robust security standards. However, these cloud platforms operate as independent data controllers and processors. The storage of data within these platforms is subject to the independent privacy policies, security protocols, and terms of service of the respective platform providers. We strongly advise and encourage you to review the independent privacy policies of these platform providers, including:
Xero's Privacy Policy (available on Xero's website - https://www.xero.com/au).
We are not responsible for the privacy or security practices of these third-party platform providers, and any data stored or processed through these platforms is subject to their respective security frameworks.
8. Artificial Intelligence and Automated Decision-Making Disclosures
We may utilise artificial intelligence (AI), machine learning, and automated decision-making (ADM) technologies to enhance the efficiency, accuracy, and delivery of our accounting, bookkeeping, and other services. This includes the use of automated transaction matching, optical character recognition (OCR) for receipt and invoice processing, automated tax categorisation, and data analytics tools. We implement strict safeguards to protect client confidentiality and data security when utilising these technologies:
No Public Model Training: We do not permit your personal or financial information to be used to train public, open-source, or third-party artificial intelligence models. All AI tools utilised by us are deployed within secure, private enterprise environments where data is encrypted and access is strictly restricted.
Human Control and Review: We do not rely solely on automated decision-making for any outcomes that have tax law or significant financial effects on you. All AI-generated analyses, tax categorisations, and financial reports are subject to review, verification, and sign-off by a qualified professional of our firm.
Confidentiality Safeguards: Any third-party AI service providers we engage are enterprise grade and under strict contractual obligations of confidentiality, data protection, and security, at least equivalent to the standards set out in this Privacy Policy.
9. Disclosure of Personal Information to Third Parties
We may disclose personal information to third parties to facilitate the primary and secondary purposes of collection outlined above at ‘Primary and Secondary Purposes of Collection and Use’. All disclosures are made subject to our strict professional duties of confidentiality, ethical codes (including our Code of Professional Conduct under the Tax Agents Services Act 2009 (Cth), and the APES 110 Code of Ethics for Professional Accountants), and other relevant professional rules. We may disclose personal information to:
Other professional advisers engaged in relation to your matters, including (as applicable) accountants, bookkeepers, BAS agents, Tax Agents, barristers, legal practitioners, financial planners, auditors, and business valuers;
Courts, tribunals, and government or regulatory bodies (including the Australian Taxation Office, the Australian Securities and Investments Commission, and financial intelligence units) where required or authorised by law;
Our professional indemnity insurers, professional regulator (Tax Practitioners Board), legal advisers, and auditors for risk management, compliance, and insurance purposes;
Debt collection agencies and legal representatives in the event of non-payment of Our Fees or any Disbursements;
Service providers who assist us in operating our business, including IT service providers, secure data storage and archiving companies, client portal providers, and marketing agencies;
Related entities within our corporate group (as applicable); and
Any person or entity you expressly or impliedly authorise us to disclose your information to.
There are some circumstances in which we must disclose an individual’s information, including:
Where we reasonably believe that an individual may be engaged in fraudulent, deceptive or unlawful activity that a governmental authority should be made aware of;
As required by any law (including the Privacy Act and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)); and/or
In order to sell our business (in that we may need to transfer Personal Information to a new owner).
10. Cross-Border Data Transfers and Offshore Processing
We may disclose personal information to recipients located outside Australia where it is reasonably necessary, convenient, or efficient to facilitate the purposes of collection, holding, use, and disclosure outlined in this policy. This includes the use of cloud software, cloud storage, and overseas software servers.
· CLOUD SERVER LOCATIONS. Our use of cloud-based software platforms (including Xero and Microsoft 365) means that your personal and financial information may be stored on secure servers located in overseas jurisdictions, including the United States of America, Canada, and the United Kingdom.
We take reasonable steps to ensure that any overseas recipient of your personal information handles it in accordance with standards equivalent to the APPs. This includes executing comprehensive service level agreements, confidentiality undertakings, and data processing agreements that require the overseas recipient to implement robust security measures and protect your data from unauthorised access, modification, or disclosure.
11. Data Security, Retention, and Destruction
We may hold your personal information in both physical and electronic formats. We take all reasonable steps and implement robust technical and organisational measures to protect your personal information from misuse, interference, loss, and from unauthorised access, modification, or disclosure. These measures include:
The use of secure physical facilities with restricted access control (such as lockable filing);
The implementation of advanced cybersecurity protocols, including multi-factor authentication (MFA), secure socket layer (SSL) encryption, and database encryption for data in transit and at rest;
Restricting access to personal information to authorised personnel who require access to perform their professional duties; and
Regular cybersecurity training and awareness programmes for all personnel.
We retain personal information for as long as necessary to fulfill the purposes for which it was collected, to comply with our statutory obligations under tax administration and other laws (which generally require records to be kept for a minimum of 5 years, and up to 7 years), and to ensure that pertinent evidence remains available if reasonably required for professional indemnity or legal dispute purposes.
Once personal information is no longer required for any authorised purpose and we are not legally required to retain it, we will take reasonable steps to securely destroy, shred, or permanently de-identify the information in accordance with secure data destruction protocols.
12. Access to and Correction of Personal Information
You have the right to request access to the personal information we hold about you, and to request that we correct any errors, inaccuracies, or out-of-date details. To make an access or correction request, please contact our Privacy Officer in writing using the contact details provided below at ‘13.Complaints, Dispute Resolution, and Contact Details’. We will take reasonable steps to verify your identity before granting access or making corrections to protect client confidentiality.
Subject to the Australian Privacy Principles, you have the right to request from us the Personal Information or other information that we have about you, and we have an obligation to provide you with such information within 28 days of receiving your written request, subject to you having completed identity verification.
Where you cannot update your own information in your request we will correct any errors in the Personal Information or other information we hold about you within seven (7) calendar days of receiving written notice from you about those errors, subject to you having completed identity verification.
It is your responsibility to provide us with accurate and truthful Personal Information or other information. We cannot be liable for any information that is provided to us that is incorrect.
We may charge you a reasonable fee for our costs incurred in meeting any of your requests to disclose the Personal Information or other information we hold about you. We will inform you of any applicable fees before processing your request.
We may refuse to grant access to personal information where:
we are prohibited from providing access by law, court order, or our professional duties of confidentiality to other clients; and
in certain circumstances permitted by law, such as where:
o Providing access would pose a serious threat to the life, health, or safety of any individual;
o Providing access would have an unreasonable impact on the privacy of other individuals;
o The request is frivolous or vexatious;
o The information relates to existing or anticipated legal proceedings between us and you, and would not be accessible through legal discovery; or
o Providing access would reveal our commercially sensitive decision-making processes.
If we refuse your access or correction request, we will:
Provide you with written reasons for the refusal (unless it is unreasonable to do so or otherwise prohibited by law to specify those reasons); and
Provide details of how you may lodge a complaint regarding the decision.
We take reasonable steps to ensure that the personal information we hold during the currency of your matter is accurate, up-to-date, complete, and relevant. Records held after the completion of our work for you (i.e. after our engagement ends) will not be monitored or updated unless further instructions are issued by you.
Unauthorised Access: If we become aware of any unauthorised access to your Personal Information or other information, we will inform you at the earliest practical opportunity once we have established what was accessed and how it was accessed.
13. Complaints, Dispute Resolution, and Contact Details
If you have any questions about this Privacy Policy, or if you wish to lodge a formal complaint regarding a potential breach of your privacy or our handling of your personal information, please address your complaint in writing to our designated Privacy Officer:
PRIVACY OFFICER CONTACT DETAILS
Contact: Ashleigh Clark, Privacy Officer, Cruzy Accounting And Taxation (ABN 25 115 894 370)
Post: 9 Goyder Way, Lakelands WA 6180
Email: admin@cruzyaccountingandtaxation.com
Telephone: 0461 476 977
If you have a dispute regarding your Personal Information or other information, you must first attempt to resolve the issue directly with us.
We ask that you provide full details of your concern or complaint in writing including your reply email address or postal address. We will handle all complaints through our structured internal dispute resolution process:
Acknowledgement: We will acknowledge receipt of your complaint in writing within 5 business days.
Investigation: Our Privacy Officer will conduct a thorough investigation into the matters raised in your complaint, reviewing our data logs, security protocols, and personnel actions.
Response: We aim to provide a comprehensive written response, including our findings and any proposed remedial actions, within 30 days of receiving your complaint. If we require additional time due to the complexity of the investigation, we will keep you informed of our progress.
If you are not satisfied with our internal response or the resolution of your complaint, you may escalate the dispute to the relevant professional accounting body or to the federal privacy regulator:
Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Post: GPO Box 5218, Sydney NSW 2001
Policy Last Reviewed: 17/07/2026
Liability limited by a scheme approved under Professional Standards Legislation.
