PRIVACY POLICY
Aquila Super Pty Ltd (ABN 50 102 006 486) (“we”, “our”, “us”) is bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (Privacy Act). This Policy explains how we collect, use, store, disclose and protect your personal information, and how you can contact us about privacy matters.
We may update this Policy from time to time. The most current version will always be available on our website. If we make any material changes, we will notify you by posting an updated version on our website and, where appropriate, contacting you directly via your nominated contact details.
If you have any questions, concerns, or complaints, please contact our Privacy Officer.
Privacy Officer: Tamara Orman
Email: admin@aquilasuper.com
Postal address: GPO Box 543, Canberra ACT 2601
Security frameworks
Aquila Super is committed to maintaining confidentiality, integrity, and availability of personal information. We hold ISO/IEC 27001:2022 certification (Certificate No. 21185), governed by an Information Security Management System (ISMS), and apply recognised information security frameworks and controls that are regularly reviewed and updated.
What information we collect
We may collect personal information directly from you, from third parties (such as service providers, regulators, or authorised representatives), and from publicly available sources where permitted by law. We collect this information to enable us to provide services, meet legal obligations, and manage our business operations.
At or before the time of collection (or as soon as practicable afterwards), we will take reasonable steps to ensure you are aware of:
- why we are collecting your personal information;
- how we may use and disclose it;
- the consequences if the information is not provided; and
- how you can access or correct your information.
In the course of providing our services, we collect personal and other information about our clients, prospective clients, fund members, trustees, directors, employees, contractors, service providers and other business contacts, and how they interact with us and our services. When you provide us with your personal information, you are agreeing to our collection and handling of that information in accordance with this Privacy Policy.
We collect personal information through a number of mechanisms, including:
- Contact details (name, address, email, phone number);
- Date of birth, occupation, dependants;
- Tax File Number (TFN);
- Financial information (bank details, investments, superannuation);
- Business details (e.g. ABN).
We may also collect sensitive information (such as health information) where it is necessary to provide our services and where you have consented or we are otherwise permitted by law. You have the option of not identifying yourself, or interacting with us using a pseudonym, to make general enquiries about our services; however, we will not be able to provide services to you without the information we need.
Australian data hosting (no offshoring)
We store and process personal information in Australia. Our core systems — including our Microsoft 365 environment and our Salesforce client portal — are hosted in Australian data centres, and our managed backups are held in a secured private cloud. We do not offshore our SMSF administration, accounting or audit work, and all of our staff are located in Australia. Some global software providers we use may, in limited circumstances, access information from outside Australia (for example, to provide technical support); where this occurs, we take reasonable steps under the APPs to ensure the recipient handles your information consistently with the Privacy Act, and we remain accountable for that information.
Information collected automatically
We may collect information through cookies and similar technologies, including IP address and device information, browser and usage data, and website interaction behaviour.
Communications
We collect information when you communicate with us via email, phone, forms, or other channels.
Your client portal account
Where applicable, we provide our client portal through Salesforce, one of the world’s leading secure cloud platforms. Your portal data is hosted in Australia on Salesforce’s Australian infrastructure, consistent with our onshore data commitment. In limited circumstances, Salesforce may access or process data from outside Australia to operate or support the platform; where this occurs, that access is governed by contractual and security safeguards and we remain accountable for your information.
Salesforce maintains a high standard of independently certified security, including ISO/IEC 27001 certification and SOC 2 and SOC 3 attestations. The portal is protected by measures including encryption of data in transit and at rest, multi-factor authentication, role-based and multi-user access controls, audit-trail logging of activity, and automatic session timeouts.
Tax agent services
For clients who nominate us to act as their registered tax agent, we prepare and lodge documents on their behalf, including SMSF annual returns and Transfer Balance Account Reports (TBAR). To provide these services, we use third-party software providers — such as BGL, Class Super, Xero Tax and the ATO Tax Agent Portal — and in doing so may disclose information relating to your tax affairs to those providers. All such work is carried out in Australia. In nominating us as your tax agent, you consent to this disclosure, which we handle in accordance with this Policy and our obligations as a registered tax agent.
Recruitment information
If you apply for a role with us, we may collect information from you, recruiters or job platforms to assess your application.
How we use your information
We use personal information for purposes including:
- Providing and managing our SMSF administration, accounting and audit services;
- Identity verification and compliance obligations;
- Client communication and support;
- Financial administration and billing;
- Internal reporting, analytics, and service improvement; and
- Legal and regulatory compliance.
We may also use or disclose information where required or authorised by law or where you have provided consent.
No automated decision-making
We do not use automated decision-making. Every decision that affects you — including any decision about your fund, your services or your compliance obligations — is made by a qualified professional, not by a computer or an AI system. Where we use AI tools, they only ever assist our team with tasks like organising data and processing documents, and a person always reviews the outcome and remains responsible for it. AI supports our people; it never replaces their judgement.
Disclosure of personal information
We will never sell your personal information. We may disclose personal information to third parties including:
- Superannuation funds, insurers, and financial product providers;
- Identity verification providers;
- IT, cloud, compliance, and professional service providers;
- Legal and financial advisers (authorised representatives);
- Other entities within the Aquila network; and
- Government and regulatory bodies where required or authorised by law.
We require our service providers and personnel to be bound by confidentiality obligations and to implement appropriate safeguards to protect your information.
Storage, security and retention
We will take reasonable steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. We do this by:
- Putting in place physical, electronic and procedural safeguards in line with industry standards;
- Requiring third-party providers to have acceptable security measures to keep personal information secure;
- Limiting access to the information we collect about you (role-based, least-privilege access with multi-factor authentication);
- Imposing confidentiality obligations on our employees;
- Providing privacy and security training to those responsible for handling your personal information;
- Applying data-loss-prevention (DLP) and data-classification controls, continuous security monitoring, and documented incident-response and business-continuity arrangements; and
- Only providing access to personal information once proper identification has been given.
When we store your data, we use industry-standard encryption technologies to protect personal information both at rest and in transit. This includes encryption of data stored in our systems using strong cryptographic controls (such as AES-256 or equivalent) and encryption of data transmitted over networks using secure protocols (such as TLS). Access to encrypted data is restricted to authorised personnel only and managed in accordance with our information security policies and recognised security frameworks.
While we take all steps reasonable in the circumstances to protect your information, in the unlikely event a data breach occurs, we will notify you in accordance with our obligations under the Privacy Act.
If we no longer require your personal information, and are not legally required to retain it, we will take reasonable steps to destroy or de-identify it. We retain personal information only for as long as it is required for the purposes for which it was collected, or as required by law. This may include retaining financial and transactional records for a minimum period required under taxation, corporate, superannuation or regulatory laws (including up to 7 years where applicable). After this period, information is securely destroyed or de-identified.
Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF)
Aquila Super is a reporting entity under, and is subject to obligations imposed by, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act). To comply with these obligations, we are required to undertake customer due diligence and may:
- collect and verify identification information (Know Your Customer (KYC) procedures);
- monitor transactions and client activity for suspicious or unusual behaviour;
- conduct ongoing customer due diligence (CDD);
- request additional information regarding source of funds or source of wealth; and
- report suspicious matters to the Australian Transaction Reports and Analysis Centre (AUSTRAC), where required by law.
We may be required by law to collect, use, and disclose personal information for AML/CTF compliance purposes without your consent. Failure to provide requested information may result in delays in onboarding or the inability to provide services. Where we engage third-party providers to assist with AML/CTF compliance, they are required to handle personal information securely and in accordance with strict confidentiality obligations.
Access and correction
You may request access to or correction of your personal information by contacting our Privacy Officer. We will:
- Respond within 30 days where practicable;
- Require identity verification before release; and
- Provide reasons if access is refused.
We may charge reasonable administrative costs for providing access (excluding the request itself).
Complaints
If you believe we have breached your privacy rights, please contact our Privacy Officer in writing with details of your complaint. We will:
- Acknowledge and investigate your complaint;
- Respond within a reasonable timeframe; and
- Request identity verification where necessary.
If you are not satisfied with our response, you may contact:
Office of the Australian Information Commissioner (OAIC)
GPO Box 5288, Sydney NSW 2001
www.oaic.gov.au | 1300 363 992
Notifiable Data Breaches
In the event of a data breach that is likely to result in serious harm, we will:
- promptly assess and contain the breach;
- take remedial action where possible;
- notify affected individuals and the OAIC as required under the Notifiable Data Breaches scheme; and
- implement measures to reduce the likelihood of recurrence.
Notifications will be made as soon as practicable in accordance with our obligations under the Privacy Act.
Cookies and website analytics
We use cookies and similar technologies to support website functionality, improve user experience, and analyse website performance. These technologies may collect information such as IP address and device information, browser type and usage behaviour, and website interaction data. We do not use cookies for third-party advertising or behavioural advertising purposes. You can manage or disable cookies through your browser settings; however, some features of our website may not function correctly if cookies are disabled.
Privacy Impact Assessments
We may conduct Privacy Impact Assessments for high-risk activities involving personal information to identify and mitigate privacy risks.
Governing law
This Policy is governed by the laws of the Australian Capital Territory and the Commonwealth of Australia.
V3.0 updated August 2026