Effective: 23 July 2026
Octet Finance Pty Ltd (ACN 124 477 916) and Octet Finance (Qld) Pty Ltd (ACN 632 841 564 and NZBN 9429052164910) (“we”, “us”, “our”) collect and manage personal information as described in this policy. We manage information about individuals. Those individuals include clients to whom we may provide or may have provided a facility; guarantors of both individual and company clients and individuals who may provide a guarantee; individuals who may sell goods or services to a client; individuals who are or become customers of a client; and individuals that are associates of entities that do any of those things.
Your privacy is important to us. We respect your right to be aware of who has information about you, what they are doing with it and why, and who else they are sharing it with. We adopted a privacy compliance culture that cements this relationship with you. To the have extent applicable, we are committed to complying with:
(a) the Privacy Act 1988 (Australia);
(b) the Privacy Regulations 2025 (Australia);
(c) the Privacy (Credit Reporting) Code 2025 (Australia);
(d) the Privacy Act 2020 (New Zealand); and
(e) the Credit Reporting Privacy Code 2020 (New Zealand),
together Privacy Law.
This privacy policy is the privacy policy which we must have in accordance with Australian Privacy Principle 1.3 and incorporates our policy about the management of credit information and credit eligibility information which we must have in accordance with section 21B(3) of the Privacy Act 1988 (Australia).
Due to the employee records exemption in the Privacy Act 1988 (Australia), this privacy policy does not apply to our past or current employee records. We handle these records with the utmost care and responsibility and comply with the obligations that may apply to employees’ personal information under other applicable laws.
This privacy policy explains how we manage personal information which is not credit information or credit eligibility information. In particular it explains, in relation to that personal information:
This privacy policy also explains how we manage credit information and credit eligibility information. In particular it explains, in relation to that information:
We collect and hold credit information about individuals who are clients, guarantors, a seller of goods or services to clients, a customer of clients, or associates of any of them. This information includes:
We obtain credit reporting information about individuals who are clients, guarantors, a seller of goods or services to clients, a customer of clients or associates of any of them from credit reporting bodies. Credit reporting information includes:
We only obtain credit reporting information from credit reporting bodies to the extent we are entitled to obtain it under applicable Privacy Law. We might, for example, need to obtain the individual’s prior authorisation.
We may disclose credit information (such as identification information) about an individual to a credit reporting body. The credit reporting body may include that information in the reports it provides to other credit providers.
We disclose credit information to the following credit reporting body:
Equifax Pty Ltd
That credit reporting -body is required to have a policy which explains how it will manage credit-related personal information. If an individual would like to read the policy of the credit reporting body he or she should visit the credit reporting body’s website and follow the “Privacy” links, or the individual can contact the credit reporting body direct for further information.
Our policy about the management of credit related personal information is contained in this privacy policy but if an individual would like to receive it as a separate document he or she can request a copy by contacting our Privacy Contact Officer at the address specified below.
An individual has the right to request that the credit reporting body exclude his or her credit reporting information from any permissible direct marketing activities we may ask it to perform.
The individual also has the right to request that the credit reporting body not use or disclose his or her credit reporting information if the individual believes that he or she has been, or is likely to be, the victim of fraud (for example, the individual suspects someone is using his or her identity details to apply for credit). The individual must contact the credit reporting body direct should this be the case.
The personal information, other than credit information and credit reporting information, we collect and hold varies depending on the person we are dealing with and the reason why we are dealing with them. We collect this general personal information from individuals who are clients, guarantors, sellers of goods or services to clients, customers of clients, prospective employees, contractors, suppliers, brokers, introducers, merchants, agents, professional advisers, mercantile agents, mailing houses, call centre operators, archivers and service providers, or associates of any of them. This information will generally include the individual’s name and contact details, and information about the individual’s arrangements and transactions with us, and the management of accounts with us. In respect of Australian individuals, we will only collect sensitive information about an individual with the individual’s consent or when permissible under Australian law.
Under various laws we will be (or may be) authorised or required to collect personal information about an individual. These laws include the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Personal Property Securities Act 2009, Corporations Act 2001, Charter of the United Nations Act 1945, Autonomous Sanctions Act 2011, Income Tax Assessment Act 1997, Income Tax Assessment Act 1936, Income Tax Regulations 1936, Tax Administration Act 1953, Tax Administration Regulations 1976, A New Tax System (Goods and Services Tax) Act 1999 and the Australian Securities and Investments Commission Act 2001 as those laws are amended and includes any associated regulations and New Zealand equivalent laws.
We may collect and hold personal information about an individual for the purposes of verifying the individual’s identity and complying with applicable laws, including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Australia) and the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (New Zealand). To assist with these processes, we utilise the services of a third-party identity verification and compliance provider, Frankie Financial Pty Ltd (ACN 623 506 892) (trading as “FrankieOne”). Where we use FrankieOne, the personal information we collect and hold may include:
This personal information may be collected directly from the individual or via secure digital interfaces provided by FrankieOne. The information is disclosed to FrankieOne for the purpose of verifying the individual's identity, undertaking document verification checks (including through government and third -party data sources), and assisting us to meet our legal and regulatory obligations. FrankieOne collects, uses and processes this personal information as our service provider in connection with the identity verification services it provides to us.
FrankieOne is required to have a policy which explains how it will manage the collection of personal information. If an individual would like to read a FrankieOne policy the individual should visit its website and follow the “Privacy” links, or the individual can contact FrankieOne for further information.
We collect personal information, other than credit eligibility information, about individuals in a variety of ways including in the loan application process and completed loan documents, in contracts with third parties, in person, via a link to an accounting package or other data base, via a website, via mobile app, on the phone, and from other finance organisations that are authorised to provide such information under their own Privacy Policies. We may obtain the information from the individual or from persons acting on the individual’s behalf. When it is possible and practical, we will collect the information direct from the individual. When it is not practical or reasonable to do so, we will collect the information from a third party. The third party could be an authorised representative (such as a broker, agent, accountant or lawyer), another financial institution, a referee, an employer or a government body, a person that requests a facility from us, a credit reporting body, broker or other introducers, or a public register. When the individual sells goods or services to a client, is a customer of a client or is an associate of a client we may obtain the information from the client.
When New Zealand law applies, the personal information will be collected from the individual concerned unless an exception from the Privacy Act 1920 (New Zealand), Information Privacy Principle 2, applies.
The main consequence for you if all or some of the personal information is not collected by us is that we may be unable to process your (or the person’s) application; we may decide not to provide a facility or we may decide to restrict or end a facility; we may not be able to complete a transaction in which you are involved, for example as a supplier or prospective employee; or we may not give access to the Octet platform.
When New Zealand law applies, you must, before providing personal information to us about other individuals:
The credit eligibility information is obtained from a credit reporting body.
We take all reasonable steps to ensure that an individual’s personal information which we hold is protected from misuse, interference or loss and from unauthorised access, modification or disclosure.
We do this by having physical, electronic and procedural safeguards which protect the personal information we hold. For example, the personal information is stored in secure office premises or in secure archiving facilities and logins and passwords are required to access electronic databases. Our staff are required to maintain the confidentiality of personal information and access to personal information is restricted to persons who require access to perform their duties.
We will retain an individual’s personal information for as long as necessary with regard to the purpose for which we collected it, and to comply with our legal obligations.
We collect, hold, use and disclose credit information and credit eligibility information on individuals for purposes permitted by law which are reasonably necessary for our business activities. Those purposes include:
We do not hold any CP derived information.
We collect personal information about individuals which is not credit information or credit eligibility information:
To provide our facilities in the most cost effective and efficient way we may decide to utilise the services of others. For example, we may use a mailing house to send monthly statements, we may use a data processing firm to manage data we hold including personal information and as outlined above, we may use a service provider to assist in identity verification. We also disclose information to our related bodies corporate and other finance businesses as required under the arrangements we have with them, to operate our business. If this requires that we disclose personal information we will require that those persons respect your right of privacy.
Personal information may also be used or disclosed to tell an individual about products or services that may be of interest to that individual. If the individual does not want his or her personal information used for these direct marketing purposes the individual should tell us. He or she can “opt-out” of direct marketing by sending an e-mail to privacy@octet.com or by writing to us at:
An individual may access personal information (including credit eligibility information) about the individual which we hold. The individual can obtain that access by contacting our privacy contact officer as follows:
We will need to verify the individual’s identity before giving access. We will usually provide the requested personal information within 30 days of receiving the request. There is no charge to make a request but we may levy an administration fee for providing access.
If there is a reason why we do not make the requested personal information available we will provide our reason in writing.
If an individual considers that any personal information which we hold about the individual is incorrect in any way the individual may ask us to correct that personal information. To seek the correction please contact our Privacy Contact Officer on the telephone number or at the e-mail or postal address above.
In certain situations, we may decide not to agree to a request to correct personal information. We will tell you in writing why we have not agreed to the correction request.
We recognise our obligations under the applicable Privacy Law to assess suspected data breaches and, where required, notify affected individuals and the relevant privacy regulator of an eligible data breach (Australia) or notifiable privacy breach (New Zealand). We will provide any required notifications as soon as reasonably practicable in accordance with the applicable Privacy Law.
Where we have reasonable grounds to believe that an eligible data breach or a notifiable data breach has occurred under the applicable Privacy Law, we will, as soon as reasonably practicable:
We maintain an internal data breach response procedure. Any suspected data breach should be reported immediately to our Privacy Contact Officer at the above contact details. We will take all reasonable steps to contain any breach and mitigate its impact.
We have an internal dispute resolution system that covers complaints. That system complies with ISO 10002-2006 Customer Satisfaction – Guidelines for Complaints Handling in Organisations: sections 4, 5.1, 6.4, 8.1 and 8.2. If an individual considers that we have failed to comply with applicable Privacy Law he or she should contact our Privacy Contact Officer on the telephone number or at the email or postal address above. We will then follow our internal dispute resolution system. We will acknowledge the complaint within 7 days. A decision will be made and advised within 30 days or a longer period as may be agreed with the individual.
If the individual is not satisfied with the decision he or she may make a complaint to the Office of the Australian Information Commissioner (the “OAIC”) or the New Zealand Office of the Privacy Commissioner (the “OPC”).
The contact details for the OAIC are:
The contact details for the OPC are:
We will only disclose personal information to overseas recipients or to persons that do not have an Australian or New Zealand link when this is necessary for the purpose for which the information was collected or a purpose connected with the purpose for which the information was collected which the individual would reasonably expect us to use or disclose the information. For example, if the seller of goods or services to the client or the Octet financial institution which has an agreement with the seller is located overseas we may need to send the client’s information overseas so that we can confirm that a bona fide contract has been entered into between the client and the seller or to make a payment to the seller or the Octet financial institution. If there is a dispute between the client and the seller we may need to provide information to a person located overseas to assist in the resolution of that dispute. Whenever we disclose personal information overseas, we will comply with the applicable Privacy Law.
We may use service providers located overseas. We may provide personal information to the service provider so that the service provider can provide a service to us.
It is not practicable to specify the list of countries other than Australia or New Zealand in which the recipient could be located as this will largely depend on the sellers with whom the client decides to contract.
In this privacy policy:
“associate” means a person who is or may become an officer, trustee or employee of the client, the guarantor, a seller of goods or services to the client or a customer of the client;
“client” means a person (such as a company, sole trader or partnership) to whom we have provided a facility including the provision of commercial credit and includes a person who has applied for, or may apply for, a facility of that type;
“guarantor” means a person who has guaranteed, or may guarantee, the obligations which a person (such as a buyer, client or borrower) has or may have to us; and
“we”, “us” and “our” means Octet Finance Pty Ltd (ACN 124 477 916) and Octet Finance (Qld) Pty Ltd (ACN 632 841 564 and NZBN 9429052164910).
Words which are defined in the applicable Privacy Law have the same meaning in this privacy policy.