Privacy Policy

Version 2.0 · Effective July 2026
How iInvest Trading & Advisory Pty Ltd collects, uses, discloses and protects personal information, and the privacy rights available to individuals under Australian law.
Governing policy document · Version 2.0 · Effective July 2026
iInvest Trading & Advisory is a Corporate Authorised Representative (No. 431611) of Zodiac Securities Pty Ltd (AFSL No. 398350).
Download as PDF
1

Purpose, Scope and Privacy Framework

1.Purpose

iInvest Trading & Advisory Pty Ltd ('iInvest', 'we', 'our' or 'us') is committed to protecting the privacy, confidentiality and security of personal information entrusted to us by clients, prospective clients, authorised agents, employees, contractors and business partners. This Privacy Policy explains how we collect, use, disclose, store, protect and manage personal information and the rights available to individuals under Australian privacy law.

2.Scope

This Policy applies to all personal information collected or held by iInvest regardless of whether it is obtained through meetings, telephone calls, email, written correspondence, our website, the Client Portal, secure messaging, financial advisory services, research requests, AI-assisted services, webinars, recruitment activities or other interactions. It applies to information held electronically, digitally or in hard copy.

3.Relationship with the Client Portal

This Privacy Policy applies across all business operations. Where a client accesses the iInvest Client Portal, the separate Client Portal Privacy Policy supplements this Policy by describing Portal-specific privacy practices, authentication, electronic records and technology controls.

4.Privacy Principles

iInvest manages personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Notifiable Data Breaches Scheme, the Corporations Act 2001 (Cth), the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and other applicable laws. Privacy obligations are embedded within our governance, risk management and compliance framework.

5.Our Privacy Commitment

We are committed to collecting only the information reasonably necessary to provide our services, maintaining accurate records, protecting information from misuse, interference, loss and unauthorised access, retaining information only as long as required, securely destroying or de-identifying information when no longer required, and maintaining appropriate governance, employee training and technical safeguards.
Key Principles
  • Collect personal information lawfully, fairly and transparently.
  • Use and disclose information only for legitimate business purposes or as permitted by law.
  • Protect personal information using appropriate administrative, technical and physical safeguards.
  • Provide individuals with access to and correction of their personal information where required.
  • Regularly review our privacy framework to reflect changes in law, technology and business operations.

6.Collection of Personal Information

iInvest collects personal information that is reasonably necessary to provide financial products and services, comply with legal obligations, administer client relationships and operate secure digital services. Information may be collected directly from individuals or, where permitted, from authorised representatives, professional advisers, product issuers, market participants, identity verification providers and other lawful sources.

7.Types of Personal Information

Depending on the services provided, we may collect identification and contact details, financial information, account information, transaction history, portfolio information, communications, research requests, Client Portal activity, authentication records and any other information reasonably necessary to provide our services or comply with applicable laws.

8.Purpose for Collection, Use and Disclosure

Personal information is collected, held, used and disclosed only for legitimate business purposes. These include establishing and administering accounts, verifying identity, complying with AML/CTF obligations, providing financial advisory and investment services, facilitating transactions, communicating with clients, maintaining records, delivering research, operating the Client Portal, improving services, managing risk, detecting fraud, resolving complaints and complying with legal and regulatory obligations.
Primary Uses of Personal Information
  • Establishing and maintaining client relationships.
  • Providing financial advisory services, research and investment services.
  • Arranging for the execution, settlement and administration of financial product transactions.
  • Operating and securing the Client Portal.
  • Authenticating users and maintaining secure access.
  • Responding to enquiries and providing client support.
  • Meeting legal, regulatory and taxation obligations.
  • Preventing fraud, financial crime and cyber threats.
  • Undertaking compliance monitoring, internal audit and quality assurance.
  • Improving products, services and client experience.

9.Authorised Agent Access

Where a client has appointed an Authorised Agent to access specified information or perform authorized functions on their behalf, iInvest may provide the Authorised Agent with access to information consistent with the authority in place.
It is the responsibility of the client to inform iInvest if that authority is amended or revoked at any time.

10.Artificial Intelligence and Digital Services

iInvest may use approved artificial intelligence technologies to support research, market commentary, educational material, portfolio analytics, document summarisation and client support. AI-generated content is intended to assist advisers and clients and should not be relied upon as personal financial advice unless expressly stated. Human oversight is applied to AI-generated content, which is treated as a draft for adviser review and is not provided to clients as advice until reviewed and adopted by an authorised adviser. iInvest does not enter personal information into AI tools. Where AI assistance is used, information is de-identified first so that no individual can be identified, and the information shared is limited to what is reasonably necessary to provide the relevant service. Where iInvest uses AI tools under commercial arrangements, it does so under contractual terms, including a data processing agreement, that prevent information being used to train AI models.
AI-generated content is provided to advisers as a draft only. It is not shared with clients until an authorised adviser has reviewed and adopted it. Personal information is not entered into AI tools; information is de-identified before any use with an AI tool. It is not used to train AI models.

11.Electronic Records and Client Portal Activity

The Client Portal automatically creates electronic records necessary to provide secure digital services and demonstrate client activity. These records may include authentication events, login history, secure messages, electronic acknowledgements and agreements, consent records, documents accessed, research requests, AI interactions, account activity and audit logs. These records may be retained as evidence of client communications, instructions and consent where permitted by law.

12.Disclosure of Personal Information

iInvest does not sell personal information. Personal information is disclosed only where authorised by the individual, reasonably necessary to provide requested services, required or authorised by law, or otherwise permitted under the Privacy Act. We seek to disclose only the minimum information reasonably necessary for the relevant purpose.
Information may be disclosed to:
  • Financial market participants including brokers, custodians, clearing and settlement providers, registries, issuers, fund managers and investment platforms.
  • Professional advisers including legal advisers, auditors, tax advisers, compliance consultants and insurers.
  • Technology providers supplying cloud hosting, authentication, cybersecurity, secure communications, document management and AI services.
  • Government agencies, regulators, courts and law enforcement bodies where required by law.

13.Overseas Disclosure

Some approved technology providers may process or store information outside Australia. Before any overseas disclosure, iInvest takes reasonable steps under APP 8 to ensure the overseas recipient does not breach the Australian Privacy Principles, assessed case by case and supported by contractual, technical and organisational safeguards. iInvest does not rely on any assumption that an overseas country's laws are substantially similar to the APPs unless that country has been prescribed for that purpose under the Privacy Act.
2

Website, Client Portal and Information Security

14.Website and Client Portal

iInvest provides digital services through its public website and secure Client Portal. The public website provides general information about our business, products and services. The Client Portal is a secure authenticated environment that enables eligible clients to access account information, portfolio reports, investment research, secure communications, electronic documents and other authorised services. As new digital services are introduced, this Privacy Policy will be updated where they materially affect the handling of personal information.

15.Digital Interactions

When individuals use our website or Client Portal, certain technical information may be collected automatically to facilitate secure operation and improve performance. This may include IP addresses, browser and device information, operating system details, session identifiers, timestamps, page interactions, downloads, authentication events, search activity, error logs and other technical information reasonably necessary to maintain our digital services.

16.Cookies and Similar Technologies

The website and Client Portal use cookies, encrypted session identifiers and similar technologies to authenticate users, maintain secure sessions, remember preferences, improve functionality, measure performance and protect against fraud and cyber threats. Essential security cookies are required for the operation of the Client Portal. Where analytics technologies are used, information is used in an aggregated or de-identified form wherever practicable.

17.Information Security

iInvest maintains administrative, technical and physical safeguards designed to protect personal information throughout its lifecycle. Our security framework is risk-based and reflects the sensitivity of the information we hold, recognised industry practices, evolving cyber threats and applicable regulatory expectations.
Examples of security measures include:
  • Encryption of information in transit and at rest.
  • Multi-factor authentication and secure identity verification.
  • Role-based access controls and least-privilege access.
  • Audit logging and security event monitoring.
  • Network, endpoint and malware protection.
  • Vulnerability management and penetration testing.
  • Secure software development and change management.
  • Business continuity, disaster recovery and secure backups.
  • Supplier due diligence and ongoing technology risk management.
  • Employee confidentiality obligations and regular cybersecurity awareness training.

18.Client Responsibilities

Clients also play an important role in protecting their personal information. Clients should safeguard usernames, passwords and authentication devices, enable multi-factor authentication where available, keep their contact details current, monitor account activity, install security updates on their devices and notify iInvest immediately if they suspect unauthorised access or fraudulent activity.

19.Third-Party Websites and Digital Services

Our website and/or electronic communications may contain links to third-party websites or services, including social media. The organisations behind such platforms/websites maintain their own privacy policies and security practices. iInvest is not responsible for the privacy practices of external organisations that are outside our control. Individuals should review the privacy policies of third-party services before providing personal information.
3

Data Retention and Individual Rights

20.Data Retention

iInvest retains personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, comply with legal and regulatory obligations, resolve disputes, protect legitimate business interests and satisfy record keeping requirements under applicable financial services legislation.
The retention period varies depending upon the nature of the information, legal obligations, regulatory requirements and operational needs. Information retained may include identification records, customer due diligence documentation, account records, portfolio information, transaction history, communications, research requests, Client Portal activity, audit logs, authentication records, AI interaction records, compliance records, complaint files and litigation records.
Where required by law, certain records may be retained after a client relationship has ended. Where records are held in third-party or AI-assisted systems, iInvest ensures records it is required to retain are held in its own systems independently of those third-party retention settings.

21.Secure Destruction and De-identification

When personal information is no longer required and there is no legal or regulatory obligation to retain it, iInvest will take reasonable steps, including both technical and organisational measures, to securely destroy or permanently de-identify the information.
Destruction methods may include secure deletion of electronic records, cryptographic erasure, destruction of storage media, secure disposal of paper records and de-identification techniques designed to minimise the risk of reconstruction or unauthorised recovery.

22.Access to Personal Information

Individuals may request access to personal information held by iInvest by contacting our Privacy Officer.
Before providing access, reasonable proof of identity may be required to protect the privacy of clients and the integrity of our records.
Access will generally be provided within a reasonable period unless an exception permitted under the Privacy Act applies. Access may be refused or limited where disclosure would unreasonably affect another person's privacy, prejudice legal proceedings, compromise law enforcement activities, reveal commercially sensitive information, prejudice regulatory investigations or otherwise be permitted by law.

23.Correction of Personal Information

iInvest takes reasonable steps to ensure personal information remains accurate, complete, relevant and up to date. Individuals who believe their information is inaccurate, incomplete or out of date should notify us as soon as practicable. Where appropriate, we will investigate and correct the information or, if required by law, associate a statement with the record.

24.Marketing Communications

From time to time, iInvest may provide investment research, newsletters, market commentary, educational material, seminar invitations, product information and information regarding enhancements to our services.
Individuals may opt out of receiving marketing communications at any time. Operational communications relating to account administration, security notifications, regulatory disclosures, legal notices and service updates will continue to be provided where necessary.
Your Privacy Rights
  • Request access to personal information held by iInvest.
  • Request correction of inaccurate, incomplete or outdated personal information.
  • Withdraw consent where processing is based on consent (subject to legal and contractual obligations).
  • Opt out of direct marketing communications.
  • Make a privacy complaint if you believe your information has not been handled in accordance with applicable privacy laws.
  • Receive information regarding how your privacy complaint has been investigated and resolved.
4

Governance, Privacy Complaints and Data Breach Response

25.Privacy Governance

Protecting personal information forms part of iInvest's governance, risk management and compliance framework. Responsibility for privacy extends across the organisation, including directors, management, authorised representatives, employees, contractors and service providers who handle personal information.
Senior management oversees the implementation of this Privacy Policy, information security controls, privacy risk management, regulatory compliance, supplier oversight, incident response and continuous improvement. Material privacy risks and significant incidents may be reported to the Board where appropriate.

26.Data Breach Response

iInvest maintains a data breach response plan to help identify, contain, assess and respond to actual or suspected data breaches involving personal information. Where iInvest reasonably believes an eligible data breach has occurred, being a data breach likely to result in serious harm to one or more individuals that cannot be remediated, iInvest will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act. Not every data breach is notifiable; each suspected breach is assessed on its own facts. Following any data breach, iInvest reviews the incident and its response to reduce the risk of recurrence.

27.Privacy by Design

iInvest seeks to incorporate privacy considerations into the design, development and implementation of new products, services, technology solutions and business processes. Where appropriate, projects will consider data minimisation, lawful collection, security, retention, third-party disclosures, overseas processing, AI-related privacy considerations and compliance with the Australian Privacy Principles before implementation.

28.Employee Responsibilities

Employees, representatives, authorised representatives, contractors and consultants with access to personal information are expected to maintain confidentiality, use information only for authorised purposes, comply with this Privacy Policy and associated information security policies, report suspected privacy incidents promptly, complete mandatory privacy and cybersecurity training, and protect authentication credentials. Access to personal information is limited to individuals requiring access to perform their legitimate business responsibilities.

29.Policy Review and Changes

This Privacy Policy is reviewed periodically and whenever significant changes occur to legislation, regulatory guidance, technology, cybersecurity risks, business operations, products, services or privacy expectations.
The current version of the Policy will be made available on the iInvest website and, where appropriate, through the Client Portal. Where material changes are made, affected individuals may be notified by electronic communication or other appropriate means.

30.Contacting iInvest

Questions regarding this Privacy Policy, requests for access or correction of personal information, data breach enquiries or privacy complaints should be directed to:
Privacy Officer
iInvest Trading & Advisory Pty Ltd
11 West Street
Burleigh Heads QLD 4220
Telephone: (07) 5520 8788
Email: info@iinvestadvisory.com

31.Privacy Complaints

iInvest is committed to resolving privacy concerns promptly, fairly and transparently.
Privacy complaints should be submitted to the Privacy Officer with sufficient information to enable investigation. We will acknowledge receipt, investigate the relevant circumstances, review available evidence, consult relevant personnel where required and advise the complainant of the outcome.
If a complaint cannot be resolved satisfactorily, individuals may refer the matter to the Office of the Australian Information Commissioner (OAIC) or another external dispute resolution body where appropriate.
If a privacy complaint is not resolved to an individual's satisfaction, they may take it to the Office of the Australian Information Commissioner (OAIC) or another external dispute resolution body at any time.
iInvest Trading & Advisory Pty Ltd · Privacy Policy · Version 2.0 · Effective July 2026
iInvest Trading & Advisory is a Corporate Authorised Representative (No. 431611) of Zodiac Securities Pty Ltd (AFSL No. 398350).