1. Our Commitment to Your Privacy
Keep It Simple Super (referred to as "we", "us", or "our") is committed to protecting your privacy and ensuring the absolute confidentiality of your personal, financial, and sensitive information.
We are bound by the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act). This Privacy Policy explains how we collect, use, disclose, and secure your personal information in the course of providing Self-Managed Super Fund (SMSF) accounting, establishment, administration, and compliance services.
This policy applies to all personal information collected through our direct client engagement, our website at lifetimesmsf.com.au, and any other channel through which you interact with us.
2. The Kinds of Personal Information We Collect
To effectively manage your SMSF and satisfy our strict legal obligations as an AUSTRAC-regulated reporting entity, we must collect detailed personal and sensitive information. This includes:
Identity and Verification Information (KYC)
-
Full names, dates of birth, gender, and residential addresses.
-
Certified copies of government-issued photo identification such as passports and driver's licences.
Corporate and Trust Structures
-
Details regarding corporate trustees, trust deeds, directors, and the identities of ultimate beneficial owners (anyone owning or controlling 25% or more of the fund or related entities).
Government Identifiers
-
Tax File Numbers (TFNs), Australian Business Numbers (ABNs), and Director Identification Numbers.
Financial and Investment Data
-
Bank account details, share portfolios, crypto-asset addresses, property deeds, contribution histories, and source of funds or wealth documentation.
Sensitive Information
-
Superannuation death benefit nominations (which may reveal family relationships or structures) and insurance policy details.
We only collect sensitive information where it is reasonably necessary for our functions or where you have consented, as required under APP 3.3 of the Privacy Act 1988 (Cth).
3. How We Collect Your Personal Information
We collect personal information directly from you through application forms, face-to-face meetings, financial documents, emails, phone calls, or our secure client portals.
We may also collect information from third parties with your explicit consent, or where required by law to verify your identity under AML/CTF rules, including from:
-
Your financial planner, mortgage broker, or investment adviser.
-
The Australian Taxation Office (ATO) via our Registered Tax Agent portal.
-
Your fund's bank, stockbroker, or wrap platform providers.
-
Public registers, credit reporting bodies, or independent electronic identity verification (eIDV) services.
Where it is reasonable and practicable to do so, we will only collect personal information directly from you.
4. Collection of Information via Our Website
When you visit lifetimesmsf.com.au, we may collect certain non-personal and technical data automatically. This may include:
-
Your IP address and general geographic location.
-
Browser type, operating system, and device information.
-
Pages visited, time spent on pages, and referral URLs.
-
Information submitted through contact forms or booking tools (such as our Calendly booking link).
Cookies
Our website may use cookies and similar tracking technologies to improve your browsing experience, analyse site traffic, and support marketing activities. Cookies are small text files stored on your device.
You can configure your browser to refuse cookies or to notify you when cookies are being sent. However, doing so may affect the functionality of parts of our website.
We do not use our website to collect sensitive personal information without your explicit consent.
5. Purposes for Which We Collect, Hold, and Use Information
We collect, hold, and use your information strictly for professional purposes, including:
-
Establishing, restructuring, and administering your SMSF.
-
Completing Customer Due Diligence (CDD) and identity verification as mandated by the AML/CTF Act.
-
Preparing annual financial statements, member statements, and tax returns.
-
Facilitating the mandatory independent annual SMSF audit.
-
Communicating with regulatory bodies (ATO, ASIC, and AUSTRAC) on your behalf.
-
Complying with our legal obligations under the Superannuation Industry (Supervision) Act 1993 (SIS Act) and the Income Tax Assessment Act 1997.
-
Sending you service-related communications, compliance reminders, and educational materials relevant to your SMSF (see Section 9 regarding direct marketing).
6. Disclosure of Personal Information
We do not sell, rent, or trade your personal information. However, to fulfil our professional and statutory duties, we may disclose your information to:
-
Approved SMSF Auditors: To conduct the legally required annual audit of your fund.
-
Government and Regulatory Authorities: The ATO, ASIC, and AUSTRAC (Australian Transaction Reports and Analysis Centre), including the submission of mandatory Threshold Transaction Reports (TTRs) or Suspicious Matter Reports (SMRs).
-
Software Providers: Secured, cloud-based SMSF accounting platforms (including BGL Simple Fund 360 and BGL CAS 360) used to process your data.
-
Legal and Financial Professionals: Actuaries (for pension certificates) or legal professionals (for trust deed updates), with your prior consent.
Cross-Border Disclosures
We may use third-party service providers or outsourced processing hubs located overseas to assist with SMSF administration. Where data is shared overseas, we take all reasonable steps to ensure those recipients maintain data protection standards equivalent to the APPs.
⚠ AUSTRAC Tipping-Off Restriction: We are legally prohibited from disclosing whether a Suspicious Matter Report (SMR) or any related AUSTRAC report has been filed. Any such disclosure constitutes a criminal offence under s.123 of the AML/CTF Act 2006. This restriction takes precedence over any access request.
7. Storage and Security of Personal Information
We hold your information in a combination of secure electronic cloud storage and, where necessary, physical files. We implement institutional-grade security measures, including:
-
Multi-factor authentication (MFA) for all system access.
-
Data encryption at rest and in transit.
-
Restricted staff access on a need-to-know basis.
-
Robust firewalls and intrusion detection to protect against data breaches, loss, or unauthorised access.
Notifiable Data Breaches
In the unlikely event of a data breach involving your personal information that is likely to result in serious harm, we will immediately contain the breach, assess the risk, and notify both you and the Office of the Australian Information Commissioner (OAIC) in accordance with our legal obligations under the Notifiable Data Breaches (NDB) scheme.
8. Retention and Destruction of Personal Information
We retain your personal information only for as long as is necessary to fulfil the purposes for which it was collected, and to satisfy our legal, regulatory, and professional obligations.
Minimum Retention Periods
Record Type Minimum Retention Period Authority
KYC / Identity Verification Records 7 years from end of client relationship AML/CTF Act s.106
SMSF Financial Statements and Tax Records 7 years from date of preparation Income Tax Assessment Act 1997
AML/CTF Transaction Records (TTRs/SMRs) 7 years from date of transaction or report AML/CTF Act s.107
Trust Deeds and Establishment Documents Indefinitely (or 7 years post wind-up) SIS Act
General Client Correspondence 7 years from end of engagement Professional Standards
Destruction and De-identification
Once the applicable retention period has expired and there is no ongoing legal, regulatory, or dispute-related reason to retain your information, we will take reasonable steps to destroy or permanently de-identify your personal information.
-
Electronic records are permanently deleted using secure erasure protocols that prevent recovery.
-
Physical records are destroyed using cross-cut shredding by an approved secure destruction provider.
-
Records subject to an active AUSTRAC investigation, legal hold, or dispute will not be destroyed until that matter is fully resolved, regardless of the standard retention period.
Client Requests for Early Deletion
Where a client requests deletion of their personal information before the expiry of the applicable retention period, we are unable to comply where retention is required by law. We will notify you of this limitation and the earliest date on which destruction can occur.
9. Tax File Numbers (TFNs)
We are authorised to collect and use TFNs solely for the purpose of fulfilling tax agent duties and SMSF regulatory reporting. Your TFN is treated with a heightened level of security and in strict accordance with the TFN Guidelines issued under the Privacy Act 1988 (Cth).
We will never use your TFN for any purpose beyond those permitted under applicable legislation, and will not disclose your TFN to any third party except as required by law.
10. Direct Marketing
We may use your contact details to send you service-related communications and educational materials relevant to SMSF compliance, legislative changes, and our services. These communications are not considered direct marketing where they relate directly to the administration services we provide to you.
If we wish to use your information for direct marketing purposes beyond the scope of our engagement, we will seek your consent first. You have the right to opt out of direct marketing communications at any time by:
-
Clicking the unsubscribe link in any marketing email.
-
Contacting our Privacy Officer using the details in Section 12.
We will give effect to any opt-out request within a reasonable time and at no cost to you.
11. Access to and Correction of Your Information
You have the right to request access to the personal information we hold about you, and to request corrections if you believe the information is inaccurate, incomplete, or out of date.
⚠ AML/CTF Legal Restriction: Your right to access personal information is not absolute. We are legally permitted or required to refuse access where doing so would breach other Australian laws. We cannot disclose any information, files, or internal notes relating to disclosures, investigations, or reports made to AUSTRAC. Disclosure of such information constitutes a criminal "tipping off" offence under the AML/CTF Act.
To make an access or correction request, please contact our Privacy Officer using the details in Section 12. We will respond within 30 days.
Where we refuse access or decline to make a correction, we will provide written reasons and information about how you may complain about that decision.
12. Privacy Officer and Complaints
If you have any questions about this policy, or if you believe we have breached our privacy obligations, please contact us:
-
Privacy Officer: Julie Taylor
-
Email: jt@keepitsimplesuper.com.au
-
Phone: 1300 031 943
-
Postal Address: PO Box 4301 Bay Village NSW 2261
We take privacy complaints seriously and will investigate and respond within 30 days. If you remain unsatisfied with our response, you have the right to escalate your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
13. Children and Minors
Our services are not directed at, and we do not knowingly collect personal information from, children under the age of 18 unless that information is provided in the context of an SMSF membership or trust structure that includes a minor (for example, a death benefit nomination referencing a dependent child).
Where personal information relating to a minor is collected in an SMSF context, it is treated with the same standard of protection as all other personal information held by us. If you believe we hold information about a minor that should not have been collected, please contact our Privacy Officer.
14. Updates to This Policy
We review this policy at least annually to ensure it remains current with changes to privacy legislation, AML/CTF regulations, and our business practices.
Where we make material changes to this policy, we will notify existing clients by email and publish the updated version on our website at lifetimesmsf.com.au. The version number and effective date at the top of this document will be updated accordingly.
Continued use of our services following notification of changes constitutes your acceptance of the updated policy.
Liability limited by a Scheme approved under the Professional Standards Legislation.
Copyright © Lifetime SMSF Pty Ltd. All rights reserved.
