Privacy Statement
Our privacy commitment to you
Stropro Operations Pty Ltd (ABN 28 633 603 399) trading as “Stropro” (“we”, “us”, “our”) operates the Stropro platform and website (www.stropro.com). We are a Corporate Authorised Representative (AR No. 1293257) of Stropro Compliance Pty Ltd (ABN 74 640 214 740), which holds Australian Financial Services Licence No.533443. We are committed to respecting your privacy rights and safeguarding your personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act), including the Australian Privacy Principles (APPs).
This Privacy Statement explains how we collect, hold, use and disclose personal information, how you may access and correct personal information we hold about you, and how you may make a privacy complaint.
We provide financial services to wholesale clients only. However, this Privacy Statement applies to personal information we collect about clients and their representatives, directors, beneficial owners, employees, job applicants, service providers, website users and other individuals who deal with us.
Collection of Personal Information
The personal information we collect depends on how you deal with us. We may collect personal information when you contact us, use our website, complete an application or other form, apply for or receive our services, attend an event, apply for a role with us, or otherwise deal with us.
Personal information we collect may include your name, contact details, date of birth, identification details, employment and business information, financial and transaction information, communications with us, information in applications, forms, surveys, complaints and enquiries, and website, device and usage information.
Where relevant to our services or legal obligations, we may collect information needed to verify identity and authority, carry out due diligence, and meet anti-money laundering and counter-terrorism financing, tax, regulatory and other legal requirements.
We may collect personal information directly from you or from third parties, including your employer or representative, related bodies corporate, professional advisers, counterparties, referees, publicly available sources, identity-verification providers, service providers, and government or regulatory bodies.
We collect personal information only where it is reasonably necessary for our functions or activities, or where otherwise permitted or required by law.
Definition of Personal Information
Personal information, as defined by the Privacy Act, is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
Use and Disclosure of Personal Information
We use and disclose personal information to respond to enquiries, manage complaints, provide and administer our services, verify identity and authority, carry out due diligence, manage our business relationships and meet our legal and regulatory obligations.
We may also use and disclose personal information to protect our systems and business, prevent and investigate fraud, misconduct, security incidents and unlawful activity, recruit and engage personnel, and improve our services, systems andwebsite.
We use or disclose personal information for the purpose for which it was collected, for related purposes you would reasonably expect, where you consent, where required or authorised by law, or otherwise as permitted by the Privacy Act. ‘Sensitive information’ has a special meaning under the Privacy Act. We generally do not collect sensitive information unless it is reasonably necessary for our activities and we have your consent, or we are otherwise permitted or required to collect it by law.
Legal Requirements
We may collect, use or disclose personal information where required or authorised by law. This may include compliance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), tax laws, financial-services laws, court orders and requests from regulators or law-enforcement agencies. Where required, we will take reasonable steps to notify you of the collection of your personal information, the purposes for which we collect it, and other matters required by the Privacy Act.
Anonymity and Pseudonymity
While dealings with us will often require identification, we respect your right to deal with us anonymously or by pseudonym where this is lawful and practicable. This may not be possible where we need to verify your identity, provide financial services, meet legal obligations or deal with a transaction or request.
Information provided by a third party
If a third party, such as your financial or personal representative, provides us with your personal information, they should do so only if they have your authority or consent, or are otherwise legally permitted or required to do so.
Where we collect personal information from a third party, we will take reasonable steps to ensure you are made aware of the matters required by the Privacy Act. If we receive unsolicited personal information, we will assess whether we could have collected it under the APPs. If not, we will de-identify or destroy it as soon as reasonably practicable, unless we are required or permitted by law to keep it.
Security of Personal Information
We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our safeguards may include access controls, staff training, secure systems, encryption, firewalls, security monitoring and contractual controls with service providers, as appropriate to the nature of the information we hold.
We keep personal information only for as long as it is needed for a purpose for which we may use or disclose it, unless we are required or permitted by law to retain it. When personal information is no longer needed, we will take reasonable steps to destroy or de-identify it.
Disclosure to Third Parties
Your personal information may be disclosed to third parties in the course of providing our services, operating our business, or where required or permitted by law. These third parties may include our related bodies corporate, directors, employees, authorised representatives, professional advisers, technology and cloud-service providers, identity-verification providers, payment providers, financial institutions, counterparties, regulators and government authorities.
We take reasonable steps to ensure that service providers handle personal information appropriately and only for authorised purposes.
Sending Information Overseas
Some of our service providers, including cloud-hosting, communications and technology providers, may be located outside Australia or may access personal information from outside Australia.
As at the date of this Privacy Statement, the only confirmed overseas recipient location is:
- Luxembourg (Clearstream)
We do not currently disclose personal information to any other confirmed overseas recipients. If this changes, we will update this Privacy Statement.
Before disclosing personal information overseas, we will take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to that information, unless an exception under the Privacy Act applies.
Marketing and Third-Party Disclosure Restrictions
We may use your personal information to send you information about our services where permitted by law. We do not sell, rent or trade personal information to third parties for their direct-marketing purposes.
You may ask us to stop sending you direct marketing at any time by using the unsubscribe facility in the communication or contacting us using the details below.
We will not charge you for making an opt-out request, and we will process your request within a reasonable period.
Cookies and Website Analytics
Our website may use cookies and similar technologies to operate the website, remember preferences, understand website use and improve our services.
We may use an analytics provider. This provider may collect information such as IP address, device information, browser type, pages visited, time spent on pages and referring websites.
You can manage or disable cookies through your browser settings. If you disable cookies, some parts of our website may not work as intended.
Eligible Data Breach
If we become aware of a loss of, or unauthorised access to or disclosure of, personal information, we will assess whether the incident is likely to result in serious harm to one or more individuals.
If there has been an eligible data breach, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable, as required by law. We will also take reasonable steps to contain and respond to the incident.
Access and Correction of Personal Information
We take reasonable steps to make sure the personal information we hold is accurate, up to date and complete. This includes keeping our records current and correcting information when we become aware it is wrong.
You have the right to request access to personal information we hold about you and to ask us to correct personal information that you believe is inaccurate, out-of-date, incomplete, irrelevant or misleading.
You can request access or correction by contacting our Privacy Officer using the details below. We may ask you to verify your identity before responding to your request.
We will respond within a reasonable period and, where reasonable and practicable, provide access in the way you request. We may charge a reasonable fee for giving access, but not for making a request.
If we refuse access or correction, we will provide written reasons where required by law and tell you about available complaint procedures. If we do not agree to correct information, you may ask us to associate a statement with the information noting that you believe it is inaccurate, out-of-date, incomplete, irrelevant or misleading.
Government-related Identifiers
We will not adopt, use or disclose a government-related identifier as our own identifier of an individual unless permitted or required by law.
Changes to Privacy Statement
This Privacy Statement may be updated to reflect changes in the Privacy Act, our privacy practices or our business. The current version will be available on our website at www.stropro.com. You may request a copy of this Privacy Statement from us free of charge.
Enquiries and Complaints
We handle privacy-related enquiries and complaints seriously and confidentially. If you have a question about this Privacy Statement, wish to make a complaint, or believe your privacy has been breached, please contact our Privacy Officer and provide enough detail for us to understand and investigate the issue.
We will investigate your complaint and provide a written response within a reasonable period. If we need more time, we will keep you informed. If you are dissatisfied with our response, you may contact the Office of the Australian
Information Commissioner (OAIC) at www.oaic.gov.au.