The SMSF Academy Pty Ltd trading as Smarter SMSF

Version 2.0  |  Effective 1 September 2026  |  Replaces Version 1.0 dated 23 February 2024

 

1. About this policy

The SMSF Academy Pty Ltd (ABN 53 146 136 521, ACN 146 136 521) trading as Smarter SMSF (we, us, our) is committed to protecting your privacy. This Privacy Policy explains how we collect, hold, use, disclose and protect Personal Information, and how you can access it, correct it, or complain about the way we have handled it.

This policy applies to Personal Information we collect through:

  • our website at https://smartersmsf.com (Website);
  • our subscriber platform, including the Admin Console and any client portal accessed through https://sso.smartersmsf.com (Platform);
  • the documentation, education and related services we provide to subscribers; and
  • our provision of Designated Services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).

We are a reporting entity under the AML/CTF Act. Since 1 July 2026 we have been required by law to identify and verify our customers, to collect and keep certain Personal Information, and in some cases to report it to the Australian Transaction Reports and Analysis Centre (AUSTRAC). Sections 5 to 9 explain what this means for you.

We handle Personal Information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs).

We also provide a separate Privacy Collection Notice at the point we collect customer due diligence information. That notice should be read together with this policy.

We also provide a separate Privacy Collection Notice at the point we collect customer due diligence information, available at https://smartersmsf.com/privacy-collection-notice/. That notice should be read together with this policy.


2. Types of information

Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true, and whether or not it is recorded in a material form.

If information does not disclose your identity, and your identity cannot reasonably be ascertained from it, in most cases it will not be Personal Information and this policy will not apply to it.

Sensitive Information is a subset of Personal Information. It includes information or an opinion about your racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or professional body, criminal record, health information, and biometric information used for automated biometric verification or identification, and biometric templates.

Some of the information we are required to collect under the AML/CTF Act is Sensitive Information. In particular:

  • biometric information collected when your identity is verified electronically (section 6);
  • information about whether you are a politically exposed person, which may reveal political affiliations; and
  • information produced by sanctions and adverse media screening, which may reveal criminal record information.

We collect and handle Sensitive Information only with your consent, or where the collection is required or authorised by or under an Australian law (including the AML/CTF Act). We then use it only for the primary purpose for which it was obtained, for a directly related secondary purpose, or as otherwise permitted by the Privacy Act.


3. What information we collect

3.1 Website and subscriber information

Full name, company or firm details, email address, phone number, postal and business address, occupation or title, payment and billing information, login credentials for the Platform, and records of your dealings with us including subscriptions, orders, support enquiries and event attendance.

3.2 Customer due diligence information

Where we provide a Designated Service, the AML/CTF Act requires us to collect and verify information about our customers and, in some cases, about other individuals connected with them. This may include:

  • full name, date of birth and residential address;
  • details taken from an identification document, such as the document type, issuing body, document number and expiry date (see section 7 — we do not retain copies of these documents);
  • the results of electronic identity verification, including document validation and biometric face matching (section 6);
  • information about beneficial owners, and the ownership and control structure of a company, trust or fund;
  • whether you are a politically exposed person, and the results of politically exposed person, sanctions and adverse media screening;
  • the purpose and intended nature of our business relationship with you; and
  • where enhanced customer due diligence applies, information about your source of funds and source of wealth.

3.3 Information about people who are not our subscribers

Our subscribers are generally accounting, advice and legal firms who order documents for their own clients. In providing a Designated Service we therefore collect Personal Information about individuals who are not themselves our subscribers — including trustees, directors, shareholders, members, beneficiaries, appointors and beneficial owners.

If you are one of those individuals, we usually collect your Personal Information from the firm that has engaged us rather than from you directly. We take reasonable steps to make you aware of this policy and of our Privacy Collection Notice (https://smartersmsf.com/privacy-collection-notice/), and the firm that engages us is required to provide them to you.

3.4 Technical information

IP address, device and browser type, pages visited, referring pages and other usage data collected through cookies and analytics tools.


4. Cookies, analytics and website tracking

A cookie is a small data file stored on your device that allows us to recognise your browser. We and our service providers use cookies and similar technologies on the Website for the following purposes:

  • Essential and functional — keeping you signed in, remembering items in your cart, and maintaining your session.
  • Analytics — Google Analytics and Google Tag Manager, which tell us how our pages are found and used.
  • Advertising measurement — Google conversion tracking, which tells us whether a visit followed one of our advertisements.
  • Attribution — recording how you arrived at our site, such as the search or referral that brought you.
  • Marketing automation — our customer relationship management platform records the pages you visit and links that activity to your contact record with us.
  • Support and product notices — our help widget and product announcement tool.

Payment card details entered on the Website are handled by our payment gateway and are not stored on our systems.

Because our marketing automation and session recording tools can link website activity to your contact record, we treat that activity as Personal Information under this policy. You can set your browser to refuse or delete cookies, but parts of the Website and Platform may not work properly if you do.


5. Why we collect customer due diligence information

We collect the information described in section 3.2 because we are required or authorised to do so by law — principally the AML/CTF Act and the Anti-Money Laundering and Counter-Terrorism Financing Rules. We do not rely on your consent as the basis for collecting it, although we do rely on your consent for the biometric verification described in section 6.

We collect it in order to:

  • identify and verify our customers and their beneficial owners before we provide a Designated Service;
  • assess and manage money laundering and terrorism financing risk;
  • monitor our business relationship with you on an ongoing basis;
  • meet our reporting obligations to AUSTRAC; and
  • keep the records the AML/CTF Act requires us to keep.

If you do not provide this information, we cannot provide the Designated Service. This is not a commercial preference. The AML/CTF Act prohibits us from providing a Designated Service until customer due diligence has been completed.

The Designated Services we provide currently include SMSF establishments, limited recourse borrowing arrangement bare trusts, discretionary and unit trusts, company incorporations, and changes of trustee.


6. Identity verification and biometric information

We verify identity in one of two ways, depending on the arrangement the firm engaging us has in place.

6.1 Verification by your accountant, adviser or lawyer

Where the firm that engages us has its own AML/CTF program and has entered into a reliance or customer due diligence arrangement with us, that firm carries out the identity verification and provides the resulting information and records to us. We remain responsible under the AML/CTF Act for ensuring your identity is verified. We may ask the firm to provide the underlying records, and we assess and monitor these arrangements on an ongoing basis.

6.2 Electronic verification

Otherwise, your identity is verified electronically through our identity verification provider, VerifiMe. VerifiMe is an accredited Gateway Service Provider for the Australian Government’s Identity Verification Services. The process involves:

  • collecting your name, residential address and date of birth;
  • capturing an image of one or more government-issued identification documents, checking them for authenticity, and matching them against government records through the Identity Verification Services;
  • where we have requested face verification, recording a short video or photograph of your face, checking that a live person is present, and comparing your face biometrically against the photograph on your identification document; and
  • screening your details against politically exposed person, sanctions and adverse media sources.

Where additional information is needed — for example to establish the ownership structure of a company or trust, or your source of funds — you may be asked to provide supporting documents through the same process.

6.3 Your consent

Biometric information is Sensitive Information. We, or our provider, will ask for your express consent before any biometric check is carried out and before any check is made against the Australian Government’s Identity Verification Services. You can withdraw your consent at any time. If you do, we may be unable to verify your identity electronically, and section 6.5 will apply.

6.4 What happens to your biometric information and your documents

Our provider carries out the checks and returns an identity status to us — confirmation of whether verification succeeded, together with the risk assessment outcome. We do not receive, view or store your identification documents, your facial image or your biometric template.

Your documents are held securely by the provider and are made available to us only where we request access for audit or regulatory purposes, and where your permissions allow it.

6.5 If you cannot complete electronic verification

Electronic verification through our provider is the only method we offer directly. If you are unable to complete it, or you do not consent to biometric verification, please contact us or speak to the firm that engaged us.

Depending on the circumstances, your identity may be able to be verified through document-based processes, or by your accountant, adviser or lawyer under a reliance arrangement (section 6.1).

If your identity cannot be verified, we are unable to provide the Designated Service and the order will not proceed.

6.6 Your identity wallet and your control over it

When your identity is verified electronically, the provider creates an identity wallet for you. Your verified details are held in that wallet, and you grant permission for an organisation such as us to see your identity status. You can view your permissions and revoke them at any time through the provider’s platform, and you can reuse your verified identity with other organisations that use the same service rather than verifying from the beginning again.

If you revoke our permission, we lose access to your wallet for the future. It does not remove the records we have already made. The AML/CTF Act requires us to keep records of the customer due diligence we have carried out for seven years, and we are not able to delete them on request. Section 12 explains our retention obligations and section 13 explains your access and correction rights.


7. Identification documents and government identifiers

We record details taken from your identification document — such as the document type, issuing body, document number and expiry date — because the AML/CTF Act requires us to keep a record of the information we used to verify your identity.

We do not retain copies of identification documents such as driver licences and passports. Where a copy or image is created during the verification process, it is not stored in our systems.

Some of these details are government related identifiers. The Privacy Act generally restricts the use and disclosure of government related identifiers. We use and disclose them only where required or authorised by or under an Australian law (including the AML/CTF Act), or as otherwise permitted by the Privacy Act.


8. How we use and disclose your Personal Information

8.1 General

We use Personal Information to operate the Website and Platform, provide and support our services, process orders and payments, respond to enquiries, run events and education, and keep you informed about developments in our business.

8.2 Service providers

We disclose Personal Information to service providers who assist us to operate the Website, Platform and our services — including our identity verification provider, screening data providers, hosting and infrastructure providers, payment processors, and maintenance and support personnel acting in the ordinary course of their duties.

We require these providers to enter written agreements that: (1) require compliance with the Privacy Act and, where relevant, the AML/CTF Act; (2) require security measures at least equivalent to our own; (3) restrict use of Personal Information to the purpose for which it was disclosed; and (4) impose our data retention and destruction requirements. Where a provider assists us to meet an AML/CTF obligation, we assess and monitor them on an ongoing basis, and we remain responsible for that obligation.

8.3 The firm that engages us

Where a firm orders a Designated Service on your behalf, we disclose to that firm information about the status and outcome of your customer due diligence so that they can complete their engagement with you.

8.4 AUSTRAC, regulators and law enforcement

We disclose Personal Information to AUSTRAC where the AML/CTF Act requires, including in suspicious matter reports and in response to statutory notices. We may also disclose Personal Information to law enforcement, regulatory and government agencies where we are required or authorised by law to do so.

8.5 We may be prohibited by law from telling you

The AML/CTF Act makes it an offence for us to disclose to you, or to anyone else, that we have formed a suspicion, that we have made or are considering making a suspicious matter report, or related information, where that disclosure could reasonably be expected to prejudice an investigation. This is known as tipping off.

This means that in some circumstances we may be legally unable to tell you why we have asked for further information, why a service has been delayed or declined, or whether we hold particular information about you. Where that is the case, we will not be able to explain our reasons, and we may be required to refuse a request for access under section 12.

8.6 Direct marketing

We use your contact details to send you information about our services, events and developments in our business where you have opted in to receive it, or where you would reasonably expect to receive it having regard to how we obtained your details. We do not use Sensitive Information for direct marketing, and we do not use customer due diligence information for direct marketing.

Every marketing message includes a simple unsubscribe method. You can opt out at any time by using it, or by contacting us using the details in section 16.

8.7 We do not sell your Personal Information

We do not sell, trade or rent your Personal Information. The disclosures described in this section are made in order to provide our services, or because the law requires them.


9. Automated processes and decision-making

Our Platform applies automated checks to orders for Designated Services. These include screening against politically exposed person, sanctions and targeted financial sanctions lists, and the flagging of unusual order patterns and higher-risk jurisdictions.

These checks may cause an order to be held for review or trigger a request for further information. They do not by themselves determine an outcome that affects you. Any decision to delay, decline or discontinue a service is reviewed by our AML/CTF Compliance Officer before it takes effect. Our Compliance Officer can review, override or escalate any automated assessment, and every manual intervention is recorded in an audit trail.

Automated screening can produce false matches — for example, where your name is similar to a name on a list. Where that happens we will ask you for further information so the match can be resolved, unless section 8.5 prevents us from doing so.


10. Disclosure outside Australia

10.1 Customer due diligence information stays in Australia

Your customer due diligence information is not disclosed outside Australia. Our identity verification provider stores personal information on servers located in Australia. The cloud infrastructure on which our Platform runs, and the document management system in which we store customer due diligence records — including reliance agreements — are also located in Australia.

This covers the information we collect to verify your identity, any biometric information, any image of an identification document, and the records we are required to keep to meet our AML/CTF obligations.

10.2 Our other service providers

Our email and customer relationship management platform stores Australian customer data in Australia.

One of our service providers is located outside Australia: our support and knowledge base platform, which stores and processes information in the United States. The information disclosed to it is subscriber and contact information — such as your name, firm details and your correspondence with us — and not customer due diligence information.

10.3 How we protect information disclosed overseas

Before we disclose Personal Information to an overseas recipient, we take reasonable steps to ensure that the recipient does not breach the APPs in relation to that information, including through the contractual requirements described in section 8.2. Under APP 8 we generally remain accountable for the handling of that information by an overseas recipient.

We may also disclose Personal Information outside Australia where we are required or authorised to do so by or under an Australian law.


11. Security

We store Personal Information in a way that reasonably protects it from misuse, interference and loss, and from unauthorised access, modification or disclosure. Our measures include encryption of data in transit and at rest, access controls, restricted-access systems, and regular review of our security arrangements.

Records containing customer due diligence information, internal suspicious activity reports and suspicious matter reports are held with additional protections. These include limiting access to authorised personnel on a need-to-know basis, avoiding unnecessary copies, and secure destruction at the end of the applicable retention period.

No method of transmission or electronic storage is completely secure. While we take reasonable steps to protect your Personal Information, we cannot guarantee the security of information transmitted to us electronically.

We will never ask you for your password or full payment card details by email. If you receive a message purporting to be from us that does, please report it to us using the details in section 16.


12. How long we keep your information

We keep Personal Information for as long as we need it for the purpose for which it was collected, and for as long as the law requires. The principal retention periods are:

Type of information How long we keep it
Customer due diligence records, including identity verification records and screening results 7 years after we stop providing Designated Services to the customer
Records of a Designated Service or transaction 7 years after the transaction
Suspicious matter reports and related records 7 years after the report is made
AML/CTF program, governance and training records 7 years after the record ceases to be current
Subscriber account, order and billing records 7 years after the account is closed [TO CONFIRM against tax and corporate record obligations]

 

Retention periods for AML/CTF records are set by law. We cannot delete these records on request during the retention period, even if you close your account or ask us to do so. Our full schedule is maintained in our AML/CTF Document Destruction Schedule.

Our identity verification provider separately retains verification records under its own arrangements. That does not reduce our obligation: we keep our own record of the customer due diligence we have carried out, so that we can produce it if required, independently of your permissions on the provider’s platform.

When we no longer need Personal Information, and we are not required by law to keep it, we take reasonable steps to destroy it or to de-identify it securely.


13. Access and correction

Under APP 12 you may request access to the Personal Information we hold about you. Under APP 13 you may ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading.

To make a request, contact our Privacy Officer using the details in section 16. We will ask you to verify your identity before giving access. We will respond within 30 days. There is no charge for making a request; we may charge a reasonable fee for giving access, and we will tell you the amount before we proceed.

Exceptions. We may refuse access or correction where the Privacy Act permits, and we will give you written reasons where we do. In addition:

  • the AML/CTF Act may prohibit us from confirming whether we hold, or from giving you access to, information relating to a suspicion or a suspicious matter report (see section 8.5); and
  • where the law prohibits us from giving reasons, we will not be able to explain the basis of our refusal.

Correcting your Personal Information does not remove our record of information we previously held, where the AML/CTF Act requires us to keep that record.


14. Data breaches

If we suffer a data breach that is likely to result in serious harm to any individual whose Personal Information is involved, we will notify the affected individuals and the Office of the Australian Information Commissioner as soon as practicable, in accordance with the Notifiable Data Breaches scheme under the Privacy Act.


15. Complaints

If you have a complaint about the way we have handled your Personal Information, please contact our Privacy Officer using the details in section 16. Setting out your concern in writing helps us investigate it properly.

We will acknowledge your complaint within 5 business days and respond within 30 days. We may ask you for further information to clarify your concerns. If we agree that your complaint is well founded, we will work with you to put it right.

If you are not satisfied with our response, you can refer the matter to the Office of the Australian Information Commissioner:

  • Phone 1300 363 992
  • Email enquiries@oaic.gov.au
  • Online www.oaic.gov.au
  • Post GPO Box 5218, Sydney NSW 2001

16. How to contact us

For any privacy query, to request access or correction, or to make a complaint:

Privacy Officer Aaron Dunn
Email privacy@smartersmsf.com
Phone 1300 95 94 76
Post PO Box 25, Flinders Lane VIC 8009

 

For questions specifically about customer due diligence or our AML/CTF obligations, contact compliance@smartersmsf.com.


17. Changes to this policy

We review this policy at least annually and whenever our practices or the law change. Previous versions are always stored and available upon request. Where a change is material, we will tell subscribers before it takes effect.

 

Version Date Summary of change
1.0 23 Feb 2024 Website privacy statement.
2.0 1 September 2026 Scope widened to the Platform and Designated Services. AML/CTF customer due diligence, biometric verification, AUSTRAC disclosure, tipping off, retention, overseas disclosure and automated processing sections added.