Privacy policy

Effective date: September 2026

Last updated: September 2026

Spectrum Business Management Pty Ltd (ABN 64 645 222 126) (“we”, “us”, “our” or “Spectrum”) is committed to protecting the privacy of personal information we hold. This Privacy Policy explains how we collect, hold, use and disclose personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in that Act, including recent updates concerning the use of artificial intelligence and automated decision-making.

We provide bookkeeping, accounting and related business support services. Because we handle Tax File Number (TFN) information in the course of providing these services, we are bound by the Australian Privacy Principles regardless of our annual turnover: the small business exemption that may otherwise apply to businesses with turnover under $3 million does not apply to us.

This policy applies to personal information collected through our website www.spectrumbm.com.au, and through our ordinary business dealings with clients, prospective clients, suppliers and other individuals.

1. What personal information we collect

The kinds of personal information we collect and hold depend on the nature of our dealings with you, and may include:

  • Identity information, such as your name, date of birth, and contact details (address, email address, phone number).
  • Financial information, such as bank account details, income, expenses, assets and liabilities, invoices, receipts and other transaction records needed to provide bookkeeping and accounting services.
  • Tax-related information, including your Tax File Number (TFN), Australian Business Number (ABN), and information provided to or received from the Australian Taxation Office (ATO) and other government agencies.
  • Employment and payroll information, such as employee details, wage and superannuation records, where we assist with payroll or payment-run processing on a client’s behalf.
  • Business information: details about your business structure, operations and dealings that are relevant to the services we provide.
  • Website and technical information, such as IP address, browser type, device information and browsing behaviour on our website, collected through cookies and similar technologies (see Section 8).
  • Correspondence: records of communications between you and us, including emails, phone calls and meeting notes.

We do not generally seek to collect sensitive information (such as health information, racial or ethnic origin, or criminal record information) as defined under the Privacy Act. If we are ever required to collect sensitive information, for example as part of an employee’s payroll or workers’ compensation record, we will only do so with consent, or as otherwise permitted by law, and will handle it in accordance with the higher standard of protection the APPs require for sensitive information.

2. How we collect personal information

Wherever reasonable and practicable, we collect personal information directly from you. We may collect personal information:

  • Directly from you: when you engage us, complete a form, send us correspondence, or provide documents and records for the purpose of our engagement.
  • Through our website: via contact or enquiry forms, and automatically through cookies and analytics tools (see Section 8).
  • From third parties, such as your accountant, financial adviser, employer, the ATO or other government agencies, financial institutions, or cloud-based software providers, where you have consented to this or it is otherwise necessary for us to provide our services.
  • From publicly available sources, such as ASIC or ABN Lookup records, where relevant to verifying business details.

If we receive unsolicited personal information that we did not seek to collect and could not have lawfully collected, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.

3. Purposes for which we collect, hold, use and disclose personal information

We collect, hold, use and disclose personal information for purposes including to:

  • provide bookkeeping, accounting, payroll and related business support services to our clients;
  • prepare and lodge documents with the ATO and other regulatory bodies on your behalf;
  • manage and administer our engagement with you, including invoicing and billing;
  • communicate with you about our services, and respond to enquiries or requests;
  • comply with our legal and regulatory obligations, including under taxation, anti-money laundering and corporations law;
  • improve our services, systems and website; and
  • for any other purpose disclosed to you at the time of collection, or to which you have consented.

We will not use or disclose personal information for a purpose other than the primary purpose of collection unless an exception under APP 6 applies (for example, you have consented, the secondary purpose is related and reasonably expected, or the use or disclosure is required or authorised by law).

4. Use of artificial intelligence

We may use commercially available artificial intelligence (AI) tools, including AI-enabled features within our accounting and bookkeeping software and general-purpose AI assistants, to help us work more efficiently. This section explains how we approach AI use and personal information, consistent with the Office of the Australian Information Commissioner’s (OAIC) guidance on AI and privacy.

4.1 How we use AI in our practice

  • We may use AI-enabled functionality built into our accounting, bookkeeping and practice management software (for example, to assist with data entry, categorisation of transactions, drafting correspondence, or summarising documents).
  • Where an AI tool is used in a way that involves your personal information, we take reasonable steps to use only reputable, commercially available providers, and to understand and manage how those providers handle any information submitted to them.
  • We do not input sensitive information (such as health information) into general-purpose generative AI tools, and we take care to avoid submitting more personal information to an AI tool than is reasonably necessary for the task at hand.
  • We do not use client data, including your personal information, to train third-party generative AI models, and we seek to use tools and settings (where available) that prevent our input data from being used by the provider to train their underlying models.
  • Outputs generated with the assistance of AI tools are reviewed by a member of our team before being relied upon or provided to you. We do not treat AI-generated outputs as automatically accurate or complete.

4.2 Automated decision-making

From 10 December 2026, amendments to Australian Privacy Principle 1 require organisations to disclose, in their privacy policy, the kinds of personal information used, and the kinds of decisions made, by computer programs where those decisions could reasonably be expected to significantly affect an individual’s rights or interests.

Currently, we do not use any computer program or AI system to make automated decisions about individuals that significantly affect their rights or interests. All substantive decisions relevant to our services, including the preparation, review and lodgement of financial and taxation information and any decision that could affect you or your business, are made or reviewed by a qualified member of our team. AI and other software tools are used only to support and inform that human decision-making, not to replace it.

If this changes, we will update this policy before implementing any such automated decision-making, and will disclose the kinds of personal information used and the kinds of decisions involved, in line with our obligations under APP 1.

5. Disclosure of personal information

We may disclose personal information to:

  • the Australian Taxation Office and other government or regulatory bodies, where required for the services we provide or by law;
  • your other professional advisers (such as your accountant, financial planner or legal adviser), where you have authorised us to do so;
  • third-party service providers who assist us in operating our business, such as cloud-based accounting and bookkeeping software providers, IT support providers, and payment processors, on a confidential basis and only for the purposes for which we engage them;
  • our professional advisers, such as our own accountant, auditor or lawyer, where reasonably necessary;
  • any other party where you have consented, or where the disclosure is required or authorised by law.

We do not sell personal information to third parties, and we do not disclose personal information to third parties for their own direct marketing purposes.

6. Disclosure of personal information overseas

Some of the cloud-based software and AI-enabled tools we use to provide our services (for example, cloud accounting, bookkeeping and file-storage platforms) may store or process personal information on servers located outside Australia.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the overseas recipient does not breach the Australian Privacy Principles in relation to that information, including by reviewing the privacy and security practices of our software providers. Where required by APP 8.1, we remain accountable for the acts and practices of overseas recipients in relation to your personal information, unless an exception under the Privacy Act applies.

7. Storage and security

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include:

  • storing electronic records in secure, access-controlled and encrypted cloud-based systems provided by reputable software vendors;
  • restricting access to personal information to team members who need it to perform their role;
  • using multi-factor authentication and strong password practices for our systems;
  • securely destroying or de-identifying personal information when it is no longer required for any purpose for which it may be used or disclosed under the APPs, subject to our legal record-keeping obligations (including ATO requirements to retain certain records for at least five years).

If we experience a data breach that is likely to result in serious harm to individuals whose personal information is involved, we will comply with our notification obligations under the Notifiable Data Breaches (NDB) scheme, including notifying affected individuals and the OAIC where required.

8. Cookies and website analytics

Our website may use cookies and similar technologies to understand how visitors use our site and to improve its functionality. Cookies are small files stored on your device that may collect information such as your IP address, browser type, pages visited and time spent on our site.

Most web browsers allow you to control or disable cookies through their settings. If you disable cookies, some features of our website may not function as intended. We do not use cookies to collect sensitive information, and any information collected through website analytics is used only in de-identified or aggregated form to help us understand and improve our services, unless you have separately provided personal information to us (for example, via a contact form).

9. Access to and correction of personal information

You may request access to the personal information we hold about you, and ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, please contact us using the details in Section 11. We will respond to your request within a reasonable period (generally within 30 days).

We may need to verify your identity before providing access to, or correcting, personal information. In some circumstances permitted under the Privacy Act, we may need to refuse a request for access or correction. If so, we will provide written reasons for the refusal and information about how you may complain about the refusal.

10. How to make a complaint

If you have a concern or complaint about how we have handled your personal information, please contact us using the details below. We will investigate your complaint and aim to respond within a reasonable timeframe, generally within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

11. Contact us

If you have any questions about this Privacy Policy, or wish to access or correct your personal information, or make a complaint, please contact us at:

12. Changes to this policy

We may update this Privacy Policy from time to time to reflect changes in our practices, or changes in the law (including future guidance or requirements relating to artificial intelligence and automated decision-making). The current version of this policy will always be available on our website, together with its effective date.