Last updated: September
2026
HY Accounting (“HYA”,
“we”, “us”, “our”) is a registered tax agent practice. We are bound by the
Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), the
Privacy (Tax File Number) Rule 2015, the Tax Agent Services Act 2009 (TASA) and
the Code of Professional Conduct, and the AML/CTF Act 2006 (Cth).
This policy explains
what personal information we collect, why, how we use and protect it, how we
use AI tools in delivering our services, and how you can access, correct or
query the information we hold about you.
This policy applies
alongside the privacy terms set out in our Engagement Letter, which forms part
of our agreement with each client. Where this policy and an individual
Engagement Letter differ on a specific point, the Engagement Letter governs
that client’s engagement.
In the course of
providing tax agent, accounting and advisory services, we may collect:
●
Identity information: name, date of birth, contact details,
residential and business address, and identity verification documents.
●
Government identifiers: Tax File Numbers (TFNs) and other
government-issued identification numbers.
●
Financial information: income, assets, liabilities, banking
details, superannuation and insurance details, and business or entity financial
records.
●
Business and entity information: details of companies, trusts,
partnerships and SMSFs, including directors, shareholders, beneficiaries and
trustees.
●
Information about your business or personal circumstances
relevant to the services we provide.
We are a TFN recipient
for the purposes of the Privacy (Tax File Number) Rule 2015, and we handle TFNs
in accordance with that Rule regardless of our annual turnover.
We collect personal
information directly from you or your authorised representatives, in the course
of providing our services, through our engagement process, or from third
parties where you have consented or the law permits it – for example, from the
ATO, ASIC, superannuation funds, or other professionals engaged in your
affairs.
We use your personal
information to provide the tax agent, accounting and advisory services you have
engaged us for, and for directly related purposes including:
●
preparing and lodging tax returns, activity statements and other
statutory documents;
●
providing accounting, bookkeeping and advisory services;
●
internal administration and record-keeping;
●
meeting our obligations under the AML/CTF Act 2006 (Cth) (see
section 8); and
●
responding to your requests and communicating with you about
your engagement.
We may disclose your
information to third parties engaged for administrative or business-management
purposes, on a confidential basis, and to other professionals involved in your
affairs where you have authorised this – for example, a financial adviser, solicitor,
or licensed wealth adviser.
We do not use or
disclose your personal information for any purpose other than the primary
purpose for which it was collected, or a directly related secondary purpose you
would reasonably expect.
We use AI tools to
support our team in delivering your services. AI assists our work; it does not
replace professional judgement, and it does not make decisions about your tax
position, lodgements, or advice. Every AI-assisted output is reviewed and approved
by a qualified team member before it is used or communicated to you.
The AI tools we have
sanctioned for use in delivering your services are:
●
Claude (Anthropic PBC, United States) – our primary AI tool,
operated under commercial terms. Your data is never used to train Anthropic’s
AI models. Inputs and outputs are automatically deleted from Anthropic’s
systems within 30 days. A Data Processing Agreement is in place between HYA and
Anthropic, which is how we meet our obligations under APP 8 when your
information is disclosed to this overseas recipient.
●
Nylon – used for tax and legal research only. No client
financial data is processed through this tool.
●
Microsoft 365 (including our internal system, Hani) – in
delivering your services, our systems may access documents, correspondence and
records held within our Microsoft 365 environment that are relevant to your
engagement.
No other AI tool is
sanctioned for use with client data. This includes AI features that may be
available within platforms we use for other purposes — those features are not
approved for client work. We do not use free or consumer-grade AI tools with
client data, and Tax File Numbers are never entered into any AI tool under any
circumstances.
By engaging us, you
consent to our use of AI tools as described above. If you would like specific
elements of your engagement conducted without AI assistance, you may tell us in
writing and we will consider this on a case-by-case basis. We will notify you
of any material change to the AI tools we use that affects how your personal
information is handled.
The Privacy Act 1988 (Cth) introduces new transparency
obligations for automated decision-making from December 2026. Our AI tools are
used in an advisory and support capacity only — they do not make autonomous
decisions about your tax position or affairs — and we will update this policy
ahead of that date to the extent it applies to any of our processes.
We engage offshore team
members to assist in delivering our services. At the date of this policy, our
offshore team members are located in the Philippines, Malaysia and India. The
countries we engage from may change over time as our service needs change; we
maintain a current list, which is available on request, and we will update this
policy where that list changes materially.
Offshore team members
are subject to the same privacy and confidentiality obligations as our
Australian-based team, access client data only through our firm-managed
systems, and use only our sanctioned AI tools under the same controls described
in section 5.
Before engaging any
third party or offshore provider in relation to your affairs, we will seek your
approval, and we take reasonable steps to ensure that any overseas recipient of
your personal information handles it in a manner consistent with the Australian
Privacy Principles – principally through binding contractual obligations,
including the Anthropic Data Processing Agreement referred to in section 5.
You should be aware
that where your information is handled overseas, it may not receive the same
statutory protections it would in Australia, notwithstanding the contractual
steps we take.
We maintain
enterprise-grade security across the firm, including endpoint protection,
network security, email security, identity and access management, and device
management, extending to our offshore locations. Access to client information
is restricted on a need-to-know basis.
No system can be
guaranteed completely secure, and we cannot guarantee the security of
information transmitted electronically, including over the internet.
If a data breach occurs
that is likely to result in serious harm to affected individuals, we will
assess our obligations under the Notifiable Data Breaches scheme (Part IIIC of
the Privacy Act 1988) and notify affected clients and the OAIC where required.
From 1 July 2026, we
are required by law to verify client identity before providing certain
professional services, under the AML/CTF Act 2006 (Cth) as amended by the
AML/CTF Amendment Act 2024.
●
We will ask for identity documents and information before
beginning certain services. The requirement depends on entity type (individual,
company, trust or SMSF).
●
This information must be collected before the relevant service
can be provided. If we cannot verify your identity, we may be unable to act.
●
For clients engaged before 1 July 2026, identity verification is
required when you next request a designated service, not from the date of your
original engagement.
●
Information collected for this purpose is retained for a minimum
of seven years.
●
We may be legally required to report certain matters to AUSTRAC.
We cannot tell you if or when a report has been made about you, and we cannot
be held liable for a report made in good faith under the Act.
We retain personal
information for as long as necessary to provide our services, meet our
professional and statutory obligations (including the minimum seven-year
retention referred to in section 8), or as otherwise required by law, after
which it is securely destroyed or de-identified.
You may request access
to the personal information we hold about you, or ask us to correct information
that is inaccurate, out of date, incomplete or misleading, by contacting our
Privacy Compliance Officer using the details in section 12. We may need to
verify your identity before actioning a request, and will respond within a
reasonable timeframe.
If you have a concern
about how we have handled your personal information, please raise it with us
first, using the contact details in section 12, so we can try to resolve it
directly. We will investigate and respond within a reasonable timeframe.
If you are not
satisfied with our response, you may contact:
●
the Institute of Public Accountants (IPA) at
publicaccountants.org.au;
●
the Tax Practitioners Board (TPB) at tpb.gov.au/complaints; or
●
the Office of the Australian Information Commissioner (OAIC) at
www.oaic.gov.au or 1300 363 992.
For privacy questions,
access and correction requests, or complaints, please contact our Privacy
Compliance Officer:
●
Email: support@hyaccounting.com.au
●
Post: PO Box 300, Doonside, NSW 2767
We may update this
Privacy Policy from time to time to reflect changes in our practices, the
services we provide, our use of AI tools, or legal requirements. The updated
policy will be posted on our website with a revised “last updated” date.
© 2026 HY Accounting. Built with love by Insiteful.
Liability limited by a scheme approved under Professional Standards Legislation.