Privacy Policy

Effective date 25 September 2026

This policy explains how HBG Tax and Accounting Pty Ltd collects, holds, uses and discloses personal information when providing accounting, taxation, advisory, SMSF, corporate compliance and related professional services

1. About this policy
HBG Tax and Accounting Pty Ltd ACN 608 428 520, trading as Heaney Business Group (HBG, we, us or our), is committed to protecting personal information and handling it in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Tax File Number Rule 2015 and other applicable laws and professional obligations.

This policy applies to personal information we collect through our professional services, offices, website, client portals, communications and other business activities.

2. Personal information we collect
The personal information we collect depends on our relationship with you and the services requested. It may include:
• identity and contact information, including names, dates of birth, addresses, telephone numbers, email addresses and identity documents;
• Tax File Numbers, Australian Business Numbers, Australian Company Numbers, ASIC and other government identifiers;
• financial, accounting, banking, investment, superannuation, insurance, asset, liability and transaction information;
• income, employment, payroll, contractor and employee information;
• business ownership, corporate structure, trust, partnership, director, shareholder, trustee and beneficiary information;
• information concerning beneficial owners, persons acting on behalf of a customer, politically exposed persons, sanctions screening, source of funds and source of wealth where required for AML/CTF purposes;
• information about family members, dependants, spouses, business associates, employees, representatives and other related persons where relevant to the services;
• communications, instructions, documents and records supplied to us or created while providing services;
• billing, payment and debt-recovery information; and
• website and technology information such as IP address, device and browser information, pages visited, referring pages, server logs and cookies.

We may collect sensitive information where it is reasonably necessary for our services or legal obligations and where we have consent or another lawful basis to do so.

3. How we collect personal information
We usually collect personal information directly from you, including through meetings, telephone calls, email, forms, our website, client portals and documents you provide.

We may also collect information from your authorised representatives and related entities, employers, employees, previous advisers, accountants, auditors, lawyers, financial advisers, finance brokers, banks and financial institutions, superannuation funds, insurers, software providers, identity-verification providers, publicly available sources and government bodies or registers such as the Australian Taxation Office and ASIC.
If you provide personal information about another person, you must ensure you are authorised to provide it and, where required, have informed that person that their information may be provided to and handled by us.

4. Why we collect and use personal information
We may collect, hold, use and disclose personal information to:
• provide accounting, taxation, bookkeeping, advisory, SMSF, corporate compliance and related services;
• identify clients and other relevant persons and manage our client relationships;
• prepare and lodge returns, statements, reports, forms and other documents;
• communicate with you, respond to enquiries and provide information relevant to our services;
• manage engagements, workflow, billing, payment arrangements, complaints and debt recovery;
• meet legal, regulatory, taxation, professional, ethical, insurance, quality-management and record-keeping obligations;
• comply with anti-money laundering and counter-terrorism financing obligations;
• maintain, secure, improve and administer our systems, website and business operations;
• manage risk, prevent fraud, investigate suspected misconduct and respond to legal claims; and
• send service updates, newsletters or marketing communications where permitted by law.

If we cannot collect information reasonably required for a service or legal obligation, we may be unable to commence or continue providing that service.

5. Disclosure of personal information
We may disclose personal information where reasonably necessary for the purposes described in this policy, including to:
• our directors, employees and authorised personnel;
• contractors and outsourced service providers assisting with accounting, bookkeeping, compliance, data processing and workpaper preparation;
• independent auditors and external professionals such as lawyers, financial advisers, finance brokers, valuers, actuaries and insurers where authorised or otherwise permitted by law;
• technology, cloud hosting, client portal, document management, practice management, communications, electronic signing, identity-verification, cybersecurity and AI-assisted service providers;
• the Australian Taxation Office, ASIC, AUSTRAC and other government, regulatory, law-enforcement or revenue authorities where authorised or required;
• CPA Australia and its authorised reviewers for quality review or professional standards purposes;
• our professional advisers, insurers, auditors, bankers, debt collectors and legal representatives; and
• another party with your consent or where otherwise authorised or required by law.

We do not sell personal information.

6. Overseas processing and cloud services
We use cloud-based and outsourced services to operate our practice and provide services efficiently. Client documents managed through SuiteFiles are stored by Microsoft. Our Microsoft 365 administration records show Australia as the current and committed geography for Exchange Online, SharePoint and OneDrive. Microsoft Teams currently reports Asia Pacific as its current geography and Australia as its committed geography. Exchange Online Protection and Viva Connections currently report Australia, while Microsoft 365 Copilot does not show a specific location. Accordingly, we do not represent that all Microsoft 365 information is stored exclusively in Australia. SuiteFiles may also process or store limited information required for backup, operational, support or related purposes using service providers located in Australia and other countries, including Singapore, the United Kingdom, countries in Europe and the United States.

Our independent Microsoft 365 backups are provided through Datto SaaS Protection. Our Datto tenancy is hosted on an Australian node and the relevant backup data is stored in Australia.

Our endpoint security is protected and monitored through SentinelOne. The managed SentinelOne platform used for HBG is hosted on a United States region instance. Security-related information may therefore be stored, processed or accessed in the United States.

We also use outsourced accounting and support personnel located in India. Personal information may be accessed or processed in India where reasonably necessary for those personnel to assist us.

We may use BGLiD, integrated with CAS 360, to verify identity and conduct AML/CTF screening. Depending on the verification required, BGLiD may process government-issued identity documents, biometric verification information, beneficial ownership information, politically exposed person and sanctions screening results, risk assessment information, source-of-funds or source-of-wealth information and corporate registry data. BGL advises that BGLiD is powered by FrankieOne and may use third-party and global identity, screening and registry data sources. Where we request that an identity document be stored in CAS 360, consent will be obtained where required. The countries in which particular verification information is processed may depend on the providers and checks used.

Some technology providers may store, process, back up or provide technical support for information from locations outside Australia. Where personal information is disclosed overseas, we take reasonable steps to select reputable providers and require appropriate privacy, confidentiality and security safeguards. Further information about the likely location of a particular provider is available on request.

7. Artificial intelligence and technology-assisted tools
We primarily use Microsoft 365 Copilot within our business environment for technology-assisted work. The Director may also use other approved artificial intelligence tools for limited general research, analysis or drafting where appropriate. These tools may assist with document processing, data extraction, research, analysis, drafting, workflow automation and quality control.

We take reasonable steps to assess the privacy, confidentiality and security arrangements of tools used for professional work. We do not knowingly enter client-identifying, confidential, sensitive or personal information into a publicly accessible or consumer AI service unless we have determined that appropriate privacy, confidentiality and data-security protections apply.

AI output does not replace professional judgement. Where AI assists with a professional service, the resulting work is subject to appropriate review by our personnel before it is relied upon or provided to a client.

8. AML CTF information
Where we provide a designated service under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), we may collect and verify information about customers, beneficial owners, trustees, beneficiaries, persons acting on behalf of a customer, authority to act, politically exposed persons, sanctions, the nature and purpose of a relationship or transaction, and source of funds or source of wealth.

We may use electronic identity-verification services and reliable independent sources to verify this information. We may also be required to retain information or disclose information or reports to AUSTRAC or another government or law-enforcement authority. In some circumstances, the law may prevent us from informing a person about a report or disclosure.

9. Tax File Numbers
We collect, use, disclose, store and destroy Tax File Number information only as authorised by taxation, superannuation and personal assistance laws and in accordance with the Tax File Number Rule 2015. Tax File Numbers are not used as a general identifier.

10. Security
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include role-based access, multi-factor authentication, secure portals, encryption and security controls provided by our technology providers, backups, staff training, confidentiality obligations, monitoring and incident-response procedures.

No electronic transmission or storage system is completely secure. Clients should use secure portals or other approved methods when sending sensitive information and notify us promptly if they believe information has been sent to the wrong recipient or an account has been compromised.

11. Retention and destruction
We retain personal information and professional records for as long as reasonably required to provide services and meet legal, taxation, AML/CTF, professional, insurance and risk-management obligations.
Retention periods vary. For example, AML/CTF customer due diligence records may need to be retained for at least seven years after the relevant business relationship ends. When information is no longer required, we take reasonable steps to securely destroy it or permanently de-identify it, subject to our legal and professional obligations.

12. Access and correction
You may request access to personal information we hold about you or ask us to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading. We may need to verify your identity before responding.
We will respond within a reasonable period. In some circumstances, access or correction may be refused as permitted by law. If so, we will generally explain the reason and the available complaint process.

13. Privacy complaints
If you have a concern or complaint about how we have handled personal information, please contact Gemma Heaney, our Director and Privacy Officer, using the details at the end of this policy. Please provide enough information for us to understand and investigate the issue.

We will acknowledge the complaint, investigate it and aim to provide a response within 30 days. If you are dissatisfied with our response, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au.

14. Data breaches
We maintain procedures for responding to suspected privacy and security incidents. Where a data breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will notify affected individuals and the Office of the Australian Information Commissioner as required by law.

15. Website cookies and analytics
Our website may use cookies and similar technologies that are necessary to operate, secure and maintain the website. You can usually control cookies through your browser settings, although disabling cookies may affect some website functions.

Our website hosting and support providers may collect technical logs and use cookies or similar technologies that are necessary to operate, secure, back up and maintain the website. We do not currently use Google Analytics, Microsoft Clarity or similar website analytics or advertising tracking tools. If this changes, we will update this policy and, where required, provide appropriate information and choices concerning the relevant cookies or tracking technologies.

Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites and encourage visitors to review their privacy policies.

16. Marketing communications
We may send clients and contacts information about our services, regulatory changes, events or other matters we believe may be relevant. You may unsubscribe from marketing emails using the unsubscribe link or by contacting us. We may still send service-related or legally required communications.

17. Changes to this policy
We may update this policy when our practices, service providers or legal obligations change. The current version will be published on our website with its effective date.

Contact us
Gemma Heaney | B.Com FCPA CTA SSA®
Director and Privacy Officer
HBG Tax and Accounting Pty Ltd trading as Heaney Business Group
Email: [email protected]
Telephone: 08 9594 1963
Rockingham office: Unit 7, 12 Belgravia Terrace, Rockingham WA 6168
Atwell office: Unit 2, 2 Lanao Way, Atwell WA 6164
Postal address: PO Box 366, Rockingham WA 6968

Scroll to Top
Call Now Button