Privacy Policy

1. We respect your privacy

1.1 Gilfam Tech Pty Ltd trading as “Wingr” (Wingr, we, us or our) respects your right to privacy and is committed to safeguarding the privacy of our clients, prospective clients, referrers, suppliers and website visitors.

1.2 We handle personal information in accordance with the Privacy Act 1988 (Cth) to the extent it applies to us, including where we collect, use or disclose personal information in connection with services regulated under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). As a matter of practice, we aim to apply privacy standards consistently across our business more broadly.

1.3 This policy explains how we collect, hold, use, disclose and protect personal information, and how you may request access to or correction of personal information held by us or make a complaint.

1.4 In this policy, personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true, and whether or not it is recorded in a material form.

2. Collection of personal information

2.1 We may collect personal information that is reasonably necessary for our business activities and for the services we provide, including professional accounting, bookkeeping, taxation, business advisory, company and trust establishment services, registered office or registered agent services, and related administrative and compliance services.

2.2 The personal information we collect may include your name, date of birth, contact details, address, email address, telephone number, tax file number information where permitted, identification information, director or shareholder details, business and financial information, billing and payment information, employment or payroll information, information concerning your identity documents, beneficial ownership and control information, and other information relevant to the services you request from us.

2.3 We may also collect information about your interactions with us, including correspondence, notes of conversations, appointment records, feedback, website usage information, IP address, browser type and device information.

2.4 In some circumstances we may collect sensitive information or government related identifiers where this is reasonably necessary and authorised or required by law, including for client due diligence, identity verification, sanctions screening, fraud prevention, or compliance with taxation or AML/CTF obligations.

2.5 If you provide us with personal information about another person, you should take reasonable steps to ensure that the person is aware that you have provided their information to us and of the matters set out in this policy.

3. How we collect your personal information

3.1 We collect personal information in a variety of ways, including when you:

        1. contact us by phone, email, online form, social media, post or in person;
        2. become a client, enquire about our services, accept a proposal, or otherwise engage us;
        3. provide records, identification documents, forms, checklists, questionnaires or supporting documents;
        4. interact with us through accounting, bookkeeping, payroll, tax, lodgement or document management platforms;
        5. visit our website or use our online systems; or
        6. otherwise deal with us in connection with our services or business operations.

3.2 We may also collect personal information from third parties where it is lawful and reasonable to do so, including from your authorised representatives, referees, banks, professional advisers, government agencies, public registers, identity verification providers, sanctions screening providers, payroll or bookkeeping systems or cloud software providers.

3.3 If we receive personal information from a third party, we will handle that information in accordance with this policy.

4. Use of your personal information

4.1 We may use personal information collected from you for the primary purpose of providing services to you and managing our relationship with you.

4.2 This includes using personal information to:

        1. verify identity and authority to act;
        2. assess whether and how we can provide services to you;
        3. provide accounting, tax, advisory, setup, registration, compliance and related services;
        4. communicate with you, respond to enquiries and provide updates;
        5. arrange billing, collect payment and manage accounts;
        6. maintain records, quality control processes and internal administration;
        7. meet legal, professional and regulatory obligations, including obligations under taxation laws, the Tax Agent Services Act 2009 (Cth), the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), sanctions laws and applicable professional standards;
        8. manage risk, security, fraud prevention and dispute resolution;
        9. improve our systems, services and client experience; and
        10. where permitted by law, inform you about additional services or opportunities that may be relevant to you.

4.3 We may contact you by telephone, email, SMS, secure portal, post or other reasonable means.

4.4 We will not use or disclose personal information for a secondary purpose unless that use or disclosure is permitted by law, reasonably expected in the circumstances, or you have otherwise consented.

5. Disclosure of your personal information

5.1 We may disclose personal information to our employees, contractors, officers, insurers, professional advisers, consultants, auditors, software providers, identity verification providers, cloud hosting providers, outsourced service providers, related service providers, and other third parties where reasonably necessary for the purposes set out in this policy.

5.2 We may disclose personal information where required or authorised by law, including to the Australian Taxation Office, ASIC, AUSTRAC, the Tax Practitioners Board, courts, tribunals, law enforcement agencies, regulators or other government authorities.

5.3 We may disclose personal information to third party specialists or other public practitioners where we consider that appropriate to obtain advice or assistance needed to provide services to you.

5.4 We may disclose personal information in connection with our quality assurance or professional obligations, including where engagement files are made available to CPA Australia Ltd for the purposes of a CPA Australia Best Practice Program assessment, where applicable.

5.5 In delivering our services, we use a range of cloud-based platforms, automated tools and, in some cases, artificial intelligence assisted tools to support activities such as document processing, workflow management, data extraction, transaction coding support, analysis, quality review, drafting assistance and administrative efficiency. We only use these systems where reasonably necessary to provide our services and for legitimate business purposes. We take reasonable steps to ensure that the providers of these systems maintain appropriate privacy, confidentiality and security standards, and that personal information is handled in a manner consistent with applicable privacy and professional obligations.

5.6 Some of the third parties or systems we use may store or process information outside Australia. Our data storage and processing locations may include Australia, the United States, the European Union, the United Kingdom, the Philippines and such other countries as may apply to our service providers from time to time. Where we disclose personal information to overseas recipients, we take all reasonable steps to ensure that the recipients are subject to privacy, confidentiality and security obligations appropriate to the nature of the information.

5.7 If there is a change of control in our business or a sale, transfer or restructure of business assets, personal information may be disclosed to actual or prospective purchasers, financiers, advisers or counterparties for due diligence and transaction purposes, subject to appropriate confidentiality arrangements.

5.8 We do not sell personal information.

6. Security of your personal information

6.1 We take reasonable steps to protect the personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure.

6.2 These steps may include physical security measures, staff access controls, password protection, multifactor authentication, device management controls, secure cloud platforms, backups, encryption where available, confidentiality obligations, training and process controls.

6.3 We retain personal information for as long as reasonably necessary for the purposes for which it was collected, and to comply with legal, accounting, professional, taxation, AML/CTF and record-keeping obligations.

6.4 Retention periods may vary depending on the type of engagement, the information involved and legal requirements. In many cases, records relating to professional services will be retained for at least 5 years, and in some cases longer where required or prudent.

6.5 When personal information is no longer reasonably required, we will take reasonable steps to destroy it or de-identify it, subject to any legal obligation or lawful need to retain it.

6.6 While we take reasonable steps to protect information, no method of transmission or storage is completely secure. The transmission of information to and from us is at your own risk.

6.7 If we become aware of an eligible data breach affecting personal information, we will assess the incident and take such steps as are required or appropriate in the circumstances, including notification where required by law.

7. Access to your personal information

7.1 You may request access to personal information we hold about you and request correction of personal information that is inaccurate, out-of-date, incomplete, irrelevant or misleading.

7.2 Requests for access or correction should be made in writing to hello@wingr.com.au.

7.3 We may require you to verify your identity before granting access or making a correction.

7.4 We will respond within a reasonable period. In some circumstances, the law permits us to refuse access or correction, in whole or in part. If we do so, we will provide reasons where required.

7.5 We do not generally charge for making a request, but we may charge a reasonable administrative fee for providing access where permitted by law.

8. Complaints about privacy

8.1 If you have a complaint about how we have handled your personal information, please contact us in writing at hello@wingr.com.au or PO Box 514, Mount Gravatt, Queensland 4122.

8.2 Please provide sufficient detail about the complaint so that we can investigate it.

8.3 We will consider your complaint and respond within a reasonable period.

8.4 If you are not satisfied with our response, you may be able to make a complaint to the Office of the Australian Information Commissioner.

9. Changes to Privacy Policy

9.1 We may amend this policy from time to time to reflect changes to our business practices, legal obligations or the services and technologies we use.

9.2 The current version of this policy will be made available on our website or otherwise provided on request.

10. Website

10.1 When you visit our website, we may collect certain technical and usage information such as browser type, operating system, pages viewed, referring website, time of visit and IP address.

10.2 We may use cookies and similar technologies to recognise repeat visits, improve website performance, understand usage patterns and support service delivery. Most web browsers allow you to refuse or manage cookies, although this may affect website functionality.

10.3 Our website may include links to third party websites or services. We are not responsible for the privacy practices of those third parties and encourage you to review their privacy policies.

10.4 Where we use website forms, client portals, scheduling tools or similar systems, information submitted through those tools will be handled in accordance with this policy and any additional collection notice provided at the point of collection.

Last reviewed 23 June 2026