Privacy Policy
1. About This Policy
WMS Solutions Pty Ltd trading as WMS Tax & Advisory (‘WMS’, ‘we’, ‘us’, ‘our’) is an accounting and tax advisory practice based in Queensland, Australia. WMS Solutions Pty Ltd is the entity responsible for the personal information handled under this policy.
We are committed to protecting the personal information we collect, hold, use and disclose in the course of our business. This policy explains how we manage personal information in accordance with the Privacy Act 1988 (Cth) (‘Privacy Act’) and the Australian Privacy Principles (‘APPs’).
From 1 July 2026, WMS will be a ‘reporting entity’ under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (‘AML/CTF Act’). As a result, the Privacy Act applies to our handling of personal information for the purposes of, or in connection with, our AML/CTF obligations, as well as our broader business activities.
This policy covers personal information about our clients, prospective clients, suppliers, contractors and other individuals who interact with us. A separate Employee Privacy Notice applies to our employees and is available from the Privacy Officer on request.
This policy reflects our genuine commitment to privacy. We may update this policy from time to time to reflect changes in our practices or legal obligations. The current version will always be available on our website and upon request. We will communicate any material changes to affected individuals where practicable.
2. Who Is Responsible for Privacy at WMS?
WMS has appointed its Chief Operating Officer as Privacy Officer, responsible for overseeing our compliance with this policy and the APPs. The Privacy Officer is your first point of contact for any privacy-related enquiry, complaint, or request.
Contact details:
- Privacy Officer: Chief Operating Officer
- Email: privacy@wmsadvisory.com.au
- Telephone: 07 5556 3300
3. What Personal Information Do We Collect?
We collect personal information that is reasonably necessary for the functions and activities described in this policy. We do not collect more personal information than we need.
3.1 General client and business contact information
- Names, addresses, telephone numbers and email addresses
- Date of birth and occupation
- ABN, ACN and other business identification details
- Financial information including income, assets, liabilities and transaction records
- Tax file numbers (handled in accordance with the Privacy (Tax File Number) Rule 2015)
- Superannuation and insurance details
- Details of trusts, companies, partnerships and self-managed superannuation funds
3.2 Information collected for AML/CTF compliance
From 1 July 2026, we are required by the AML/CTF Act and AML/CTF Rules to collect certain personal information for customer due diligence (‘CDD’) and related compliance purposes. This information may include:
- Full name, date of birth and residential address
- Identity document details (such as passport number, driver’s licence number and expiry date)
- Beneficial ownership information (including details of third parties connected to our clients)
- Source of wealth and source of funds information
- Information required to determine whether a person is a politically exposed person or subject to sanctions
- Personnel due diligence information for relevant staff and contractors
We collect this information because we are required or authorised to do so by the AML/CTF Act and AML/CTF Rules. We limit our collection to what is reasonably necessary to meet our obligations. We will not conduct customer due diligence where we have not reasonably concluded that a designated service will be provided.
We do not retain scanned copies or photocopies of identity documents. Where we sight identity documents for verification purposes, we record only the specific details required for compliance (name, date of birth, document type, document number, expiry date and verification outcome).
3.3 Sensitive information
Some personal information we collect may be ‘sensitive information’ under the Privacy Act, which is subject to a higher level of protection. Sensitive information we may collect includes:
- Racial or ethnic origin
- Political opinions or membership of a political association
- Religious or philosophical beliefs
- Membership of a professional, trade association or trade union
- Criminal record
- Health information
- Biometric information (where used for identity verification purposes)
We collect sensitive information only where required or authorised by law (including the AML/CTF Act), or where you have consented to its collection. Where biometric verification is used by an identity verification provider on our behalf, we will notify you in advance and obtain your consent, or confirm that a lawful exception applies, before proceeding.
3.4 Website and digital information
When you visit our website, we may collect non-identifying usage data through cookies and analytics tools, including browser type, pages visited, session duration and referring website. This information does not identify you individually. See section 8 for further detail.
4. How Do We Collect Personal Information?
We collect most personal information directly from you – for example, when you engage us, complete an onboarding form, communicate with us by email or telephone, or sign documents electronically via our signing platform.
We may also collect personal information about you from:
- Other individuals connected to your matter (such as a spouse, business partner or beneficial owner), where it is unreasonable or impracticable to collect the information directly from you
- Third parties engaged to assist with identity verification or due diligence
- Publicly available sources such as ASIC registers, the Australian Business Register or court records
- Government agencies, including the ATO, ASIC and AUSTRAC, where we are authorised to do so
You have a right to deal with us anonymously or using a pseudonym where it is lawful and practicable to do so. However, given the nature of tax and accounting services, this will generally not be possible.
There may be circumstances where the AML/CTF Act prevents us from notifying you that we are collecting certain information. This is to comply with our obligations to avoid ‘tipping off’ in connection with a suspicious matter report or investigation.
5. Why Do We Collect and Use Personal Information?
We collect, hold, use and disclose personal information for the following purposes:
- Providing tax, accounting, advisory, SMSF and related professional services to our clients
- Complying with our obligations under the AML/CTF Act and AML/CTF Rules, including customer due diligence, ongoing monitoring, suspicious matter reporting and record-keeping
- Complying with obligations under the Tax Agent Services Act 2009 (Cth), the Income Tax Assessment Acts, superannuation legislation and other applicable laws
- Communicating with you about your engagement and providing updates relevant to your affairs
- Sending marketing communications where you have not opted out (see section 10)
- Maintaining and improving our systems, services and operations
- Using AI tools to help us prepare, deliver and administer our services and communications, with our people reviewing AI-assisted work before it is relied on
- Managing our contractual and professional obligations, including invoicing and fee recovery
- Reporting to regulatory bodies including the ATO, ASIC, AUSTRAC and other agencies as required by law
- Responding to privacy complaints and access or correction requests
Where we use or disclose personal information for a purpose other than the primary purpose for which it was collected, we will only do so where an exception applies under APP 6 – for example, where required or authorised by law, or where you would reasonably expect the secondary use.
6. Disclosure of Personal Information
We may disclose personal information to:
- The Australian Taxation Office (ATO), ASIC, AUSTRAC and other government or regulatory bodies as required by law
- Our professional indemnity insurers, legal advisers and consultants in connection with managing our practice
- Third-party identity verification providers engaged to assist us with AML/CTF customer due diligence
- Cloud-based service providers who assist us to deliver our services
- Other professional advisers (such as legal practitioners or financial advisers) where you have authorised us to liaise with them on your behalf
- Any person or entity where required or authorised by Australian law, including in response to a court order
Our online payment facility is provided through a third-party payment gateway operated by National Australia Bank (NAB). When you make a payment, your payment details are handled by NAB in accordance with NAB’s privacy policy. WMS does not store your card details.
We are required by the AML/CTF Act to report suspicious matters to AUSTRAC. We are prohibited by law from disclosing to you that a suspicious matter report has been or may be made about your affairs. This is the ‘tipping off’ obligation and overrides any general disclosure or access rights you may otherwise have.
7. Overseas Disclosure of Personal Information
WMS uses cloud computing services including AI tools to help deliver and manage our services. Some providers of these services, and the data centres and sub-processors they use, may be located outside Australia. Where located outside of Australia, personal information is primarily stored in the United States and may be processed in other countries, including South Korea and Ireland, as well as other locations in Europe and the Asia Pacific region. Some providers do not publish a complete list of every country in which their sub-processors may operate; in those cases we have named the countries known to us and identified the broader regions in which processing may occur.
Before disclosing personal information to any overseas recipient, we take reasonable steps to ensure the recipient handles it in accordance with the APPs. Where we are required by the AML/CTF Act to disclose personal information overseas (for example, through reporting obligations), that disclosure is authorised by Australian law.
You may obtain further information about how we manage cross-border disclosures by contacting our Privacy Officer.
8. Cookies and Website Technologies
Our website uses cookies and similar technologies, some of which are provided through third-party cloud computing services. Cookies are small text files placed on your device that help us operate our website and understand how visitors use it.
8.1 Types of cookies we use
- Essential / functional cookies: Required to operate our website, client portal and payment facility. These cannot be disabled without impairing website functionality.
- Analytics cookies: Collect non-identifying usage data such as pages visited, session duration and browser type. Some of this data is processed by analytics providers that may be located overseas. You can opt out of analytics cookies through your browser settings or the analytics provider’s opt-out tools.
- Client portal cookies: Our client portal uses session authentication cookies that are essential for secure login and are deleted when you close your browser.
- Payment cookies: Our online payment facility uses cookies to process secure online payments. WMS does not store your card details.
You can manage and disable cookies through your browser settings. Blocking essential cookies may prevent you from accessing our client portal or using the payment facility.
We do not use cookies to collect sensitive information or to serve targeted advertising.
9. Client Accounting Software
We subscribe to cloud-based accounting software on behalf of some clients and hold those files as the subscriber. In this arrangement, WMS is responsible (as the data controller) for the personal information held within those files, and the software provider acts as a data processor on our behalf.
This means that the personal information of your customers, employees, suppliers and other third parties that you enter into your accounting file is subject to WMS’s privacy obligations under this policy. The software provider’s own privacy notice governs its handling of your information as a subscriber, but does not cover the personal data held within client files.
We take reasonable steps to ensure the provider maintains appropriate security and privacy standards. If you have questions about personal information held in your accounting file, please contact the Privacy Officer.
10. Marketing Communications
We may contact you with relevant information about our services, tax developments and events. If you do not wish to receive marketing communications from us, you can opt out at any time by:
- Clicking the unsubscribe link in any electronic communication
- Emailing privacy@wmsadvisory.com.au with your request
If you opt out of marketing communications, we may still contact you for the purposes of managing your engagement and meeting our professional and legal obligations.
11. How We Protect Personal Information
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These measures include:
- Multi-factor authentication on all systems holding personal information
- Role-based access controls limiting access to authorised staff
- Encrypted data transmission and secure storage
- Regular staff training on privacy and information security obligations
- Contractual privacy and security obligations imposed on all third-party service providers
- Periodic review of our privacy and security controls
Despite these measures, no method of electronic storage or transmission is completely secure. In the event of a data breach that is likely to result in serious harm, we will respond in accordance with our data breach response plan and our obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner (‘OAIC’) as required.
12. Retention and Destruction of Personal Information
We retain personal information for as long as it is needed for the purpose for which it was collected, or as required by law. Key retention periods include:
- AML/CTF records: 7 years from the end of the business relationship or from the date of the last occasional transaction, in accordance with section 111 of the AML/CTF Act
- Tax and accounting records: in accordance with ATO requirements and applicable tax legislation (typically 5-7 years depending on record type)
- Company and trust records: as required by the Corporations Act 2001 (Cth) and relevant trust legislation
- General business records: as required by applicable law or professional standards
When personal information is no longer needed and no legal retention obligation applies, we take reasonable steps to destroy or de-identify it securely.
We do not retain scanned or photocopied identity documents. Where identity documents are sighted for verification purposes, we record only the specific details required to demonstrate compliance with our obligations.
13. Accessing Your Personal Information
You have the right to request access to personal information we hold about you. To make an access request, please contact the Privacy Officer using the details in section 2.
We will respond to your request within 30 days. Where access is granted, we may charge a reasonable fee to cover the cost of retrieving and providing the information.
We may decline to provide access in limited circumstances, including:
- Where providing access would be unlawful – for example, where it would breach our tipping-off obligations under the AML/CTF Act
- Where access would prejudice an investigation or enforcement activity
- Where the request relates to information about another individual whose privacy would be unreasonably impacted
If we decline your request, we will provide you with written reasons (unless doing so would itself be unlawful) and information about how to make a complaint.
14. Correcting Your Personal Information
If you believe personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may request that we correct it.
We will take reasonable steps to correct the information within 30 days of your request. This is particularly important for Know Your Customer (‘KYC’) information held for AML/CTF purposes, as we have parallel obligations to maintain accurate and current customer records.
If we are unable to correct the information, we will explain why and advise you of your right to make a complaint.
15. Privacy Complaints
If you have a complaint about how we have handled your personal information, please contact the Privacy Officer using the details in section 2. We will:
- Acknowledge your complaint promptly
- Investigate your complaint and take reasonable steps to resolve it
- Provide you with a substantive response within 30 days
If you are not satisfied with our response, you may lodge a complaint with the OAIC at www.oaic.gov.au. The OAIC is Australia’s independent privacy regulator and can investigate complaints about interference with privacy by APP entities.
16. Contact Us
For all privacy-related enquiries, complaints, access requests and correction requests:
- Privacy Officer: Chief Operating Officer
- Email: privacy@wmsadvisory.com.au
- Telephone: 07 5556 3300
This policy was last updated in June 2026.