Privacy Policy
1. About this Policy
1.1. SRMC Pty Ltd respects your right to privacy and is committed to safeguarding the privacy of our clients, prospective clients, website visitors and other individuals we deal with. We adhere to the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth), as amended, including by the Privacy and Other Legislation Amendment Act 2024. This Policy sets out how we collect, hold, use and disclose personal information, and the rights you have in relation to it.
1.2. “Personal information” has the meaning given in the Privacy Act 1988 (Cth) — information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
1.3. This Policy applies to personal information we collect and hold in the course of providing debt agreement administration and related personal insolvency services, which we provide as a Debt Agreement Administrator regulated by the Australian Financial Security Authority (AFSA), and in the course of operating our websites.
2. Collection of Personal Information
2.1. We collect personal information you provide to us directly, including when you enquire about or apply for our services, enter into a Debt Agreement or related arrangement, communicate with us by phone, email, post or through our website, or otherwise interact with us.
2.2. The kinds of personal information we may collect include your name, contact details, date of birth, identification and verification documents, financial information (including income, assets, liabilities and creditor details), employment information, and any other information reasonably necessary to assess, administer or vary a Debt Agreement or provide related services.
2.3. We may collect sensitive information (as defined in the Privacy Act) only where necessary and with your consent, or as otherwise permitted by law — for example, health information relevant to a hardship variation.
2.4. Where reasonably practicable, we collect personal information directly from you. We may also collect personal information from third parties, including your creditors, referral partners, financial counsellors, credit reporting bodies, and AFSA, where necessary for the purposes set out in this Policy or as required by law.
2.5. If you provide us with personal information about another individual (for example, a co-debtor, guarantor, or dependant), you must ensure you are authorised to do so and that they are aware of this Policy.
3. How We Collect Your Personal Information
3.1. We collect personal information in a variety of ways, including when you interact with us electronically or in person, when you access our website, when you engage with our identity verification and onboarding processes, and when we administer your Debt Agreement or other services.
3.2. As part of our regulatory obligations, we are required to carry out identity verification checks (including under Anti-Money Laundering and Counter-Terrorism Financing legislation) and to maintain accurate records for AFSA's regulatory and audit purposes.
4. Use of Your Personal Information
4.1. We use personal information to assess your eligibility for, administer, and vary Debt Agreements and related services, to communicate with you and your creditors, to comply with our legal and regulatory obligations (including to AFSA), and to manage and improve our services.
4.2. We may also use your personal information to tell you about other products or services we or our related entities offer that may be relevant to you, in accordance with your marketing preferences (see Section 7).
4.3. We may contact you by telephone, email, SMS, mail or other electronic means.
5. Automated Decision-Making
5.1. Where we use a computer program to make a decision, or a substantial and discernible part of a decision, that could reasonably be expected to significantly affect your rights or interests — for example, an automated eligibility screening step in our onboarding process — we will describe in this section the kinds of personal information used in that process, and the kinds of decisions affected.
5.2. As at the date of this Policy, we do not use any computer program or automated tool to make, or to materially contribute to, a decision about a client's eligibility, Debt Agreement terms, or account status. All such decisions are made by our staff. If this changes in the future, we will update this Policy to describe the kinds of personal information used and the kinds of decisions affected.
6. Disclosure of Your Personal Information
6.1. We may disclose your personal information to our employees, officers, insurers, professional advisers, agents, suppliers or subcontractors (including our IT service providers and software platforms used to administer Debt Agreements), insofar as reasonably necessary for the purposes set out in this Policy.
6.2. We may disclose your personal information to your creditors and their representatives, to the extent necessary to administer your Debt Agreement.
6.3. We disclose personal information to AFSA as required by our obligations as a regulated Debt Agreement Administrator, and may disclose personal information to comply with a legal requirement, such as a law, regulation, court order, subpoena, warrant, in the course of a legal proceeding, or in response to a law enforcement agency request.
6.4. We may use your personal information to protect the copyright, trademarks, legal rights, property or safety of SRMC, our websites, our clients, or third parties.
6.5. If there is a change of control of our business, or a sale or transfer of business assets, we may transfer, to the extent permissible by law, personal information contained in our databases to the incoming party, who will be required to handle that information in accordance with this Policy or an equivalent policy.
6.6. Where we disclose personal information to an overseas recipient, we will take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles in relation to that information, as required by APP 8.
7. Direct Marketing
7.1. We may use your personal information to send you information about products and services that may be of interest to you. You may opt out of receiving marketing communications at any time by contacting us using the details in Section 12, or by using the opt-out or unsubscribe facility provided in the communication itself. We will process your request promptly.
8. Security of Your Personal Information
8.1. We are committed to ensuring that the personal information we hold is secure. We have implemented physical, electronic, and managerial safeguards designed to protect personal information from misuse, interference, loss, unauthorised access, modification, and disclosure, appropriate to the sensitivity of the information we hold as a regulated financial services provider.
8.2. Where personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, and we are not required by law to retain it, we will take reasonable steps to destroy or de-identify it.
8.3. The transmission and exchange of information over the internet carries inherent risk. While we take reasonable steps to safeguard information you transmit to us or receive from us, we cannot guarantee its security in transit.
9. Notifiable Data Breaches
9.1. If we experience a data breach that is likely to result in serious harm to individuals whose personal information is involved, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC), in accordance with our obligations under Part IIIC of the Privacy Act 1988 (Cth).
10. Access to and Correction of Your Personal Information
10.1. You may request access to the personal information we hold about you, in accordance with the Privacy Act. A reasonable administrative fee may apply to the provision of information in some circumstances. To request access, or if you believe any information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, please contact us using the details in Section 12.
10.2. We will respond to access and correction requests within a reasonable period, and in any event within 30 days, consistent with OAIC guidance.
10.3. We may refuse to provide access to, or correct, personal information in certain circumstances permitted under the Privacy Act, and will explain our reasons if we do so.
11. Complaints About Privacy
11.1. If you have a complaint about how we have handled your personal information, please contact us using the details in Section 12. We take privacy complaints seriously and will investigate and respond to your complaint within a reasonable period, and in any event within 30 days.
11.2. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au, or by calling 1300 363 992. Complaints concerning our conduct as a regulated Debt Agreement Administrator may also be raised with AFSA.
12. Contact Us
If you have any questions about this Policy, or wish to make a request or complaint, please contact us:
-
Post: PO Box 5140, GCMC QLD 9726
-
Address: Level 4, 140 Bundall Road, Bundall QLD 4217
-
Phone: 1300 781 850
-
Email: srmc@srmc.com.au
13. Changes to This Policy
13.1. We may change this Policy from time to time. Any changes will be effective immediately upon posting the updated Policy on our website. We encourage you to review this Policy periodically.
