Privacy Policy

Last Updated: August 4, 2026

Laura Gail Robertson trading as TEAM SMSF AUDIT (ABN 94 450 561 575) (“I”, “me”, “my”) values and respects the privacy of the people I deal with. I operate as a sole-trader public accounting and audit practice and provide my services under the registered business name TEAM SMSF AUDIT, including through my website at teamfinancial.org. I am committed to protecting your privacy and complying with the Privacy Act 1988 (Cth) (the Privacy Act), including the Australian Privacy Principles (APPs), and other applicable privacy laws and regulations.

As a public accounting and audit practice, I also handle your personal information in accordance with my professional and legal obligations, including those of the Institute of Public Accountants (IPA), the Tax Practitioners Board (TPB), the Australian Securities and Investments Commission (ASIC) and the Australian Taxation Office (ATO).

This Privacy Policy (the Policy) describes how I collect, hold, use and disclose your personal information, and how I maintain the quality and security of your personal information.

What is personal information?

“Personal information” means any information or opinion, whether true or not, and whether recorded in a material form or not, about an identified individual or an individual who is reasonably identifiable. In general terms, this includes information or an opinion that personally identifies you either directly (for example, your name) or indirectly.

What personal information do I collect?

The personal information I collect about you depends on the nature of your dealings with me and the services I provide to you. It may include:

  • name, and the names of related individuals such as company officers, trustees, members, beneficiaries and business associates;
  • mailing or street address, email address and telephone numbers;
  • date of birth;
  • tax file number (TFN) and Australian Business Number (ABN) — see “Tax file numbers” below;
  • financial information, including income, expenses, assets, liabilities, bank account and investment details, superannuation and self-managed superannuation fund (SMSF) records, and transaction histories;
  • payroll and employment information, including for Single Touch Payroll (STP) purposes;
  • identity verification information (for example, from a driver licence or passport) where required to meet my professional, registration or client-verification obligations; and
  • any other information you provide to me in the course of engaging me or that is relevant to the services I provide to you.

Personal information about other individuals

In the course of providing my services, I may collect and handle personal information about individuals other than the person or entity that engages me. For example, when I provide payroll and Single Touch Payroll services for a bookkeeping client, I handle personal information about that client’s employees; and when I conduct an audit, I may access personal information held in a client’s cloud accounting or superannuation systems. I handle this information only for the purpose of providing the relevant service, and in accordance with this Policy and my professional obligations.

Tax file numbers

Because of the taxation, BAS, bookkeeping and superannuation services I provide, I may collect and handle tax file numbers. I treat TFN information as particularly sensitive and handle it strictly in accordance with the Privacy Act and the Privacy (Tax File Number) Rule 2015. I only use or disclose your TFN for authorised purposes — principally to meet your and my taxation and superannuation obligations — and I take reasonable steps to protect it from misuse, loss and unauthorised access. You are not obliged to provide your TFN, but if you choose not to, I may be unable to provide some services to you.

Sensitive information

I do not generally seek to collect “sensitive information” as defined in the Privacy Act (which includes information about your racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of a professional or trade association, criminal record, or health information). Occasionally, sensitive information may be provided to me in the course of an engagement — for example, health or personal circumstances relevant to an SMSF member, an estate, or a not-for-profit entity I audit.

Where I do collect sensitive information, I will do so only with your consent, or where the collection is required or authorised by law, or is otherwise permitted under the Privacy Act, and I take appropriate measures to protect the security of that information.

You do not have to provide me with your personal information. Where practicable, I will give you the option of dealing with me anonymously or by using a pseudonym. However, given the nature of professional accounting and audit services, if you choose to deal with me in this way, or choose not to provide me with your personal information, I may not be able to provide you with my services or otherwise interact with you.

How do I collect your personal information?

I collect your personal information directly from you when you:

  • interact with me over the phone, by email, in person or online;
  • engage me to provide accounting, taxation, BAS, bookkeeping, payroll, SMSF administration, audit or advisory services;
  • complete my client screening, engagement or authority forms;
  • provide me with documents and records relevant to your engagement; or
  • otherwise provide information to me in the course of my dealings with you.

Collecting personal information from third parties

I may also collect your personal information from third parties or through publicly available sources where it is necessary for the services I provide. For example, I may collect your personal information from:

  • your accountant, financial adviser, or the person or firm who referred you to me;
  • SMSF trustees, members, employers, or other parties connected with your engagement;
  • the ATO, ASIC and other government agencies and regulators;
  • financial institutions, superannuation funds, and investment platforms; and
  • accounting, superannuation and record-keeping software used in connection with your engagement.

I collect your personal information from these third parties so that I can provide, administer and complete the services you or the entity you are connected with have engaged me to perform, and to meet my related professional and legal obligations.

How do I use your personal information?

I use personal information for purposes connected with my functions and activities, including to:

  • provide you with the accounting, taxation, BAS, bookkeeping, payroll, SMSF administration, audit and advisory services you request;
  • communicate with you and respond to your enquiries;
  • verify your identity and carry out client acceptance and continuance procedures;
  • meet my professional, ethical, registration and legal obligations, including obligations to the IPA, TPB, ASIC and ATO;
  • administer my practice, including billing, record-keeping and quality management; and
  • improve the quality of the services I offer.

Disclosure of personal information to third parties

I may disclose your personal information to third parties in accordance with this Policy where you would reasonably expect me to do so to provide my services and meet my obligations. For example, I may disclose your personal information to:

  • the ATO, ASIC, the TPB and other government agencies and regulators, as required or authorised in connection with my services;
  • my third-party software and IT service providers, including cloud accounting, superannuation and document-management platforms (for example, Microsoft 365 / OneDrive, BGL SF360, HandiSoft Superfund, Xero, MYOB and QuickBooks);
  • external reviewers or specialists engaged to assist with technical review, quality inspection or business continuity, who are bound by confidentiality obligations;
  • my professional advisers and my professional indemnity insurer; and
  • other parties to whom you authorise me to disclose your information, or where disclosure is required or authorised by law.

I take reasonable steps to ensure that third parties to whom I disclose personal information are subject to appropriate confidentiality and privacy obligations.

Transfer of personal information overseas

I use cloud-based software and storage providers to store and process information. My primary storage provider, Microsoft (Microsoft 365 and OneDrive), stores my core data at rest in its Australian data centres, located in New South Wales and Victoria. However, some supporting services, functions and telemetry associated with these and other third-party platforms I use may be processed or stored outside Australia, including in the United States. This means some of your personal information may be held or processed overseas.

Where I disclose your personal information to third parties overseas, I will take reasonable steps to ensure that data security and appropriate privacy practices are maintained. I will only disclose to overseas third parties if:

  • you have consented to the disclosure;
  • I reasonably believe the overseas recipient is subject to a law or binding scheme that is, overall, substantially similar to the APPs and can be enforced; or
  • the disclosure is required or authorised by an Australian law or court / tribunal order.

How do I protect your personal information?

I take reasonable steps to ensure that the personal information I hold about you is kept confidential and secure, including by:

  • restricting access to personal information to those who need it to provide services to you — as a sole practitioner, this is very limited;
  • storing records in secured cloud-based systems (Microsoft 365 / OneDrive) with access controls and backup;
  • using multi-factor authentication where available;
  • maintaining up-to-date security software (for example, anti-virus and firewall protection); and
  • maintaining cyber liability insurance in addition to my professional indemnity insurance.

If I become aware of a data breach that is likely to result in serious harm, I will respond in accordance with my obligations under the Notifiable Data Breaches scheme in the Privacy Act.

Online activity

Cookies

My website (https://teamfinancial.org) is built on the WordPress platform. WordPress and any plugins I use may place cookies on your device. A cookie is a small file of letters and numbers that a website puts on your device if you allow it. Cookies may be used to enable website functionality and to help me understand how visitors use my site so I can improve it. I do not use cookies to identify you personally. If you do not wish to use cookies, you can adjust your browser settings so that cookies are not automatically downloaded; however, blocking cookies may affect your browsing experience and the website’s functionality.

Direct marketing

I may send you information about my services or matters I consider may be of interest to you where you have requested or consented to receive such communications, in accordance with applicable laws including the Spam Act 2003 (Cth). You may opt out of receiving these communications at any time by following the unsubscribe instructions in the relevant communication or by contacting me using the details in the “How to contact me” section below.

Retention of personal information

I will not keep your personal information for longer than I need to. In most cases, I retain your personal information for the duration of your relationship with me and for as long afterwards as I am required to keep it to comply with applicable laws, professional standards and record-keeping obligations. For taxation and professional engagement records, I generally retain records for at least seven years, and in some cases longer where the law or the type of engagement requires. When I no longer need your personal information, I take reasonable steps to destroy or de-identify it securely.

How to access and correct your personal information

I take reasonable steps to ensure that the personal information I hold about you is accurate, complete and up to date. If you wish to access or correct the personal information I hold about you, please contact me using the details in the “How to contact me” section below. I will usually respond to your request within 30 days. I may need to verify your identity before processing your request, and there are some circumstances in which I may be unable to provide access or make a correction, in which case I will explain why.

Links to third party sites

My website may contain links to websites operated by third parties. If you access a third party website through my website, personal information may be collected by that third party website. I make no representations or warranties in relation to the privacy practices of any third party website and I am not responsible for the privacy policies or content of any third party website. I encourage you to read the privacy policies of any third party website you visit.

Inquiries and complaints

If you have a complaint about how I have handled your personal information, please contact me using the details below. I may require proof of your identity and full details of your request before I can process your complaint.

I will endeavour to respond to your complaint within 30 days. If you are not satisfied with my response, you have the right to contact the Office of the Australian Information Commissioner (OAIC) at http://www.oaic.gov.au to lodge a complaint.

How to contact me

If you have a question or concern about my handling of your personal information or this Policy, you can contact me, as Privacy Officer, as follows:

Privacy Officer: Laura Robertson, MIPA

Email: laurar@teamfinancial.org

Phone: 0415 489 286

Post: 59A Benowa Street, Tamborine Mountain QLD 4272

This Policy will be reviewed from time to time and may be updated to reflect changes in my practice or the law. The current version is available on request.