Privacy Policy
Privacy Policy
Effective Date: 18 September 2026
1. Introduction
We are committed to treating the personal information we collect in accordance with the Australian Privacy Principles (“APPs”) in the Privacy Act 1988 (Cth) (“the Privacy Act”). This Privacy Policy sets out how we, Bio101 Financial Advisory Pty Ltd [ABN 81 605 915 839] ( “Bio101”, “us”, “we”, and “our”) collect and handle personal information. The term “personal information” shall have the same meaning as ascribed to it under the Privacy Act and the APPs – broadly speaking, personal information includes information, or opinions, that could identify an individual. What is personal information will vary, depending on whether a person can be identified or is reasonably identifiable in the circumstances.
We may need to update this Privacy Policy from time to time to reflect our current privacy practices or changes in the law, regulations and/or professional standards. When we make any changes to this Privacy Policy, we will post the updated policy on our website. We recommend that you check our website regularly for any update to our Privacy Policy.
This Privacy Policy should be read together with our letter of engagement, applicable terms and conditions, service agreements and/or our website (“Terms and Conditions”).
2. Personal Information
The types of personal information (or opinions) we collect must be reasonably necessary for one or more of our functions or activities under our engagement with you, which will depend on the nature of our engagement with you. Examples of such information may include:
(a) General identification information such as names, job title, occupation, and gender;
(b) Contact details such as personal address, email address, business address, person and business phone numbers (including mobile phone numbers) and IP addresses;
(c) Biographical and identity information which may confirm your identity, authority to act or regulatory status, including your director identification number, date of birth, tax identification number, e-signatures, government-issued identification details (such as drivers licence, passport or national identity card details, country of domicile and/or nationality or place of birth;
(d) Educational qualifications, employment history, employee records, salary and referee reports;
(e) Information relating to your financial situation, source of funds, source of wealth, assets, liabilities and related risk or suitability information;
(f) Information relating to due diligence conducted in accordance with our obligations under applicable law (including anti-money laundering and counterterrorism financing law (“AML/CTF”)), which includes without limitation beneficial ownership and corporate control details, information to verify authority to act, source of funds, source of wealth, politically exposed person (PEP) status, sanctions check records, and other information reasonably required for us to comply with our obligations;
(g) Other financial information such as credit card and bank account details, tax file number, shareholdings and details of investments (e.g. if you have shares, units, managed funds or other investments, details of dividend payments and distributions from managed funds, any investment gains or losses from the disposal of shares, units and rental properties, including associated income and expenditure);
(h) Details of superannuation and insurance arrangements; and
(i) Visa or work permit status and related information.
It may be necessary for us to collect some forms of sensitive information about you to provide the specific services to you under our engagement with you. Sensitive information includes (but is not limited to) information such as about a person’s race, sexual orientation, disability, ethnic origin, political opinions, health, religious or philosophical beliefs and criminal history. We will only collect and use sensitive information with your prior written consent, in accordance with applicable laws or in a de-identified aggregated manner.
3. Collecting Personal Information
Generally, we collect your personal information from you directly, for example, when we deal with you in person or over the phone, when you send us correspondence (including via email), when you complete a questionnaire, form or survey or when you subscribe to our publications or engage with our accounts or posts on social media and networking sites.
Where it is unreasonable or impractical to collect your personal information from you directly or where you have consented for us to do so, we may collect your personal information from outside sources. This may include public information (including information available through ASIC or the ASX, public posts to social networking sites such as LinkedIn, or where we conduct background checks, including when requested on your behalf or as required to satisfy our legal and regulatory obligations) and commercially available information. Outside sources may also include information gained from a third party. For example, we may collect your personal information from your company or another intermediary, a previous employer, your referees, or your personal representatives.
We will notify you before, or as soon as possible after, we collect your personal information.
We may also collect your data automatically (for example, through cookies) where such data is not personal information. This data may include your type of device, operating system, type of internet browser and your use of our website. Further details are set out under “Cookies”.
We may also collect personal information through secure client onboarding, identity verification, due diligence processes to satisfy our obligations under applicable law (including without limitation for AML/CTF compliance), recruitment, human resources, practice management, document management, analytics, workflow automation, artificial intelligence or other technology platforms used to support our services, operations, risk management and compliance obligations.
4. Holding and processing Personal Information
We hold personal information in both hard copy and electronic formats. In some cases, we engage third parties to store, process or manage electronic data on our behalf and provide related support, including providers of cloud storage, IT infrastructure, email, practice management, client onboarding, identity verification, AML/CTF compliance, HR, recruitment, analytics, artificial intelligence and other software or technology providers.
We take reasonable security and organisational measures to protect the personal information we hold against loss, misuse, interference, unauthorised access of disclosure. These measures include restriction of access, firewalls, data encryption, passwords, multi-factor authentication and other appropriate technical and organisational safeguards (including staff training on privacy and security obligations).
We also implement policies and processes which govern document retention. We seek to ensure that personal information is kept as current as possible, and that irrelevant or excessive data (including personal information) is deleted or made anonymous as soon as reasonably practicable after we cease to use that data under our engagement (for more information see information under “data retention” heading below). However, some personal information may be retained for varying time periods in order to comply with legal and regulatory obligations and for other legitimate business reasons.
5. Purpose for collecting, holding, using and disclosing personal information
We will only collect and use your personal information if it is collected by means which are lawful and fair under the circumstances and:
(a) If permitted under applicable laws, that the personal information is collected for a lawful purpose directly related to us providing our services within a reasonable scope; and/or
(b) The personal information collected is adequate and not excessive in relation to that purpose; and/or
(c) If required by applicable laws, where you have given consent.
A lawful purpose is when we have a business or commercial reason to use your personal information, so long as this use is not overridden by your own rights and applicable law.
The purposes for which your personal data may be used are as follows:
1 To provide, improve and properly manage our products and services, including:
• preparing a proposal for services we offer;
• providing the services we offer;
• developing new products and services;
• responding to requests or queries;
• verifying your identity;
• to conduct surveys; and
• seeking your feedback.
(b) To provide the services under the Terms and Conditions or any other contract;
(c) To maintain contact with our clients and keep them informed of our services, industry developments, seminars and other events;
(d) For administrative purposes, including:
• processing payment transactions;
• charging and billing;
• detecting or preventing fraud;
• dealing with any complaints or feedback; and
• identifying breaches of our terms and conditions of engagement.
(e) For purposes relating to the employment of our personnel or our Clients’ personnel, contractors and sub-contractors, including recruitment, pre-employment screening, contacting referees, processing applications, administering psychometric testing or other assessments, assessing suitability for current or future positions, background checks, onboarding, workforce administration and analytics such as understanding whether we are reaching a diverse range of candidates. We may use recruitment, HR, assessment, workflow automation, analytics or AI-enabled tools to assist these activities (including as described elsewhere in this Privacy Policy), subject to appropriate review and oversight where the outcome may significantly affect an individual;
• providing internal services or benefits to our staff.
(f) For governance and compliance purposes including:
• managing any quality, conduct or risk management issues including conflict of interest or independence (including auditor independence) obligations or situations;
• meeting regulatory obligations, including without limitation tax, corporations law, professional standards, privacy, AML/CTF compliance, reporting and record-keeping obligations; and
• any other thing where we are required to or authorised by legislation or industry code, direction or standard to do so;
(g) To identify, assess, investigate, monitor and report (as applicable) complaints, conflicts, fraud, suspicious matters, prohibited activities, sanctions concerns, money laundering, terrorism financing, proliferation financing, bribery, corruption and other illegal or improper activities;
(h) For development and analytics purposes to develop our expertise and know how, including:
• for benchmarking purposes;
• development, analytics and business intelligence functions including web site trend and performance analysis;
• quality assurance; and
• other purposes related to our business; and
(i) For any other purpose you provide us with your personal information.
(j) To verify identity, authority to act, beneficial ownership, control, source of funds, source of wealth, transaction purpose and other client due diligence matters where required or appropriate for legal, regulatory, professional, risk management or AML/CTF purposes.
AI and decision-support tools
We may use secure technology, workflow automation, analytics, artificial intelligence, rules-based systems or other computer programs to help us provide services, manage risk, comply with legal and regulatory obligations and administer recruitment, employment and client onboarding processes. These tools may use personal information to assist with tasks such as identity verification, client due diligence, AML/CTF risk assessment, sanctions or watchlist screening, conflict checks, fraud detection, recruitment administration, candidate assessment, shortlisting, onboarding, workflow allocation, quality assurance and business analytics. The personal information that may be used in these tools includes the name, date of birth, home and work address, qualifications and employment history of an individual.
We may use software, AI and other technology tools to help with client onboarding, identity verification, risk management, fraud prevention and regulatory compliance in connection with our business and legal obligations. Tools that are used for these purposes primarily collate and summarise information and do not include decision-making functions or recommendations.
Tools used in connection with recruitment may include automated decision-making functions, such as rejecting candidates who do not hold qualifications that are necessary to perform the role under consideration.
Any use of artificial intelligence technologies will be conducted in accordance with the Privacy Act and the APPs.
Where these tools are used to support decisions that may significantly affect an individual, we will describe the types of information used and the types of decisions involved in this Privacy Policy (including as updated from time to time). Other than as described in this Privacy Policy, all decisions remain subject to appropriate human review and determination.
6. Sharing personal information
Subject to confidentiality obligations (as applicable), we may share your personal information with, or transfer it to, the following parties:
(a) Any of your agents, advisers, or intermediaries you inform us about;
(b) Third parties we contract with to assist in delivering the services to you;
(c) Our professional advisors where it is necessary for us to obtain their advice or assistance, including lawyers, accountants, bookkeepers, tax advisors, IT or public relations advisors;
(d) Our bankers, insurers and insurance brokers;
(e) Our data storage providers and any other software providers that we require to perform our services, which may be in other jurisdictions (refer to “transfer and processing of your personal information cross-border” for further details);
(f) Third parties and their advisors if we consider selling all or part of our business to such third parties;
(g) Other parties including government or regulatory bodies (for example, the Australian Taxation Office, the Australian Securities and Investments Commission, AUSTRAC, professional regulatory bodies, and the Australian Securities Exchange), professional or industry bodies or agencies, as part of an engagement or as required or authorised by law, regulation, professional obligation, industry code or standard, including foreign authorities or regulators relevant or applicable for the purposes of our provision of services; and
(h) Other parties when you ask us to do so or when you consent to that disclosure.
7. Transfer and processing of your personal information cross-border
Subject to confidentiality obligations (as applicable), we may transfer, store, access or process your personal information in Australia or other jurisdictions.
If we transfer your information to a jurisdiction which does not offer an equivalent level of protection to our jurisdiction, we will take reasonable steps to ensure appropriate safeguards and security measures are in place.
To protect your information we will:
(a) Use technical and organisational data security safeguards; and
(b) Use contractual confidentiality requirements in our agreements with third parties; and
(c) Make sure the jurisdiction we are transferring your information to has equivalent data protection laws or seek your consent to the transfer.
We will only transfer your information outside of Australia where:
(a) the jurisdiction we are transferring your information to, in our reasonable view, provides adequate protection for personal information; and/or
(b) we have entered into a suitable contract with the recipient; and/or
(c) the transfer is required or authorised by law; and/or
(d) we have informed you of the potential consequences and you have consented to the transfer.
8. Marketing
Subject to your consent, we may use your personal information to send you, whether directly from us or through appointed agents or third parties, updates (by email, text message, telephone or post) about our services, including exclusive offers, promotions or new services or information we think may be relevant to you (e.g., a newsletter).
You have the right to opt out of receiving promotional or direct marketing communications at any time, including by using the ‘unsubscribe’ link in emails.
We may ask you to confirm or update your marketing preferences if you instruct us to provide further services in the future, or if there are changes in the law, regulation, or the structure of our business.
9. Quality and security of personal information
We will take reasonable steps to:
(a) ensure the information we collect, use, and/or disclose is accurate, up-to-date, complete and relevant; and
(b) protect it from misuse, interference, loss, unauthorised access, modification or disclosure.
When we no longer need your information for any purpose permitted under this Privacy Policy, subject to any legal, regulatory, professional, AML/CTF, tax or dispute-related requirement to keep a record of or retain it, we will take reasonable steps to de-identify or destroy your information.
10. Access to personal information and corrections
General Access
Subject to limited exceptions set out in applicable laws and regulations, we will provide you with access to any information we hold about you on request within a reasonable time. You can reach out to us through our ‘Contact Information’ section to request your information.
Where there are costs associated with granting your general request for access, we may charge you a reasonable fee for providing you access to your information.
If we refuse to give you access to any information we hold about you, we will provide you with a notice setting out the reasons why, and how you may complain about the refusal.
Correction of Inaccuracies
If any of your details change or if you believe that any personal information Bio101 has collected about you is inaccurate you can contact us via our ‘Contact Information’ below and we will take reasonable steps to correct it in accordance with the requirements of the Privacy Act.
If we are otherwise made aware or become satisfied that information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, we will take reasonable steps to correct it in accordance with the requirements of the Privacy Act. Where we have disclosed the incorrect information, where lawful to do so we will notify the recipients of such incorrect information.
If we refuse to correct any information we hold about you, you may request we associate that information with a statement that the information is inaccurate, out-of-date, incomplete, irrelevant or misleading, and we shall take reasonable steps to do so.
We will not pass on any costs, or charge you any fees, for a request to correct information and/or associate a statement of incorrectness with the information.
11. Complaints
You can notify us of any complaint you may have about our handling of your personal information via our ‘Contact Information’ below. Following your initial contact, you may be asked to set out further details of your complaint in writing. We will acknowledge and consider your complaint within a reasonable time and, where appropriate, will advise you of the general reasons for the outcome of the complaint and any steps we propose to take in respect of your complaint.
While we hope that we will be able to resolve any complaints you may have without needing to involve third parties, if you are not satisfied with the outcome of your complaint, you can refer your complaint to the Office of the Australian Information Commissioner (“OAIC”) (please refer to details on the OAIC website at: www.oaic.gov.au).
12. Contact information
If you have any questions in relation to this Privacy Policy or our management of your personal information, including any of the requests you may make under the Privacy Act and above Privacy Policy, you can contact us by email at admin@bio101.com or at:
Bio101, Suite 1.01 / 117 Camberwell Road
HAWTHORN EAST VIC 3123
13. Cookies
Our website may use cookies and similar technologies to operate the website, understand website usage, improve performance, remember preferences and support security, analytics or other website functionality. Some cookies may be provided by third party service providers. Each type of web browser provides ways to restrict and delete cookies and the manufacturers of each web browser provide resources to assist you with monitoring, deleting and/or restricting cookies. The deletion or restriction of cookies may, however, hinder your access to certain aspects of this website.
14. Data retention
We will cease processing and using your personal information as soon as possible after you cancel or terminate any engagement with us, subject to keeping copies of your data:
(a) As reasonably necessary for archival purposes;
(b) For use in actual or potential dispute/s;
(c) To comply with applicable laws and regulations;
(d) To enforce any agreement we have with you;
(e) For protecting our rights, property, safety, or those of our employees; and/or
(f) For discharging any functions, obligations and responsibilities we may have.
We may store your information in our local servers and databases or use third party cloud vendors and data processors for as long as we are required or permitted to do so. We will have suitable contractual arrangements in place.
In most cases we will retain your information for a period of at least seven years from the termination of our agreement with you, or for a longer period where reasonably necessary or required for legal, regulatory, tax, professional, AML/CTF, insurance, archival, audit, dispute-related or legitimate business reasons.