Privacy Policy

Effective: 23 July 2026

Octet Finance Pty Ltd (ACN 124 477 916) and Octet Finance (Qld) Pty Ltd (ACN 632 841 564 and NZBN 9429052164910) (“we”, “us”, “our”) collect and manage personal information as described in this policy. We manage information about individuals. Those individuals include clients to whom we may provide or may have provided a facility; guarantors of both individual and company clients and individuals who may provide a guarantee; individuals who may sell goods or services to a client; individuals who are or become customers of a client; and individuals that are associates of entities that do any of those things.

Our privacy assurance to you

Your privacy is important to us. We respect your right to be aware of who has information about you, what they are doing with it and why, and who else they are sharing it with. We adopted a privacy compliance culture that cements this relationship with you. To the have extent applicable, we are committed to complying with:

(a) the Privacy Act 1988 (Australia);

(b) the Privacy Regulations 2025 (Australia);

(c) the Privacy (Credit Reporting) Code 2025 (Australia);

(d) the Privacy Act 2020 (New Zealand); and

(e) the Credit Reporting Privacy Code 2020 (New Zealand),

together Privacy Law.

This privacy policy is the privacy policy which we must have in accordance with Australian Privacy Principle 1.3 and incorporates our policy about the management of credit information and credit eligibility information which we must have in accordance with section 21B(3) of the Privacy Act 1988 (Australia).

Due to the employee records exemption in the Privacy Act 1988 (Australia), this privacy policy does not apply to our past or current employee records. We handle these records with the utmost care and responsibility and comply with the obligations that may apply to employees’ personal information under other applicable laws.

Overview

This privacy policy explains how we manage personal information which is not credit information or credit eligibility information. In particular it explains, in relation to that personal information:

  • the kinds of personal information we collect and hold;
  • how we collect the personal information;
  • the purposes for which we collect, hold, use and disclose the personal information;
  • how an individual may access personal information about the individual that we hold and seek the correction of that information;
  • how an individual may complain about a breach of applicable Privacy Law and how we may deal with the complaint; and
  • whether we are likely to disclose the personal information to overseas recipients and the countries where those recipients are likely to be located (if it is practicable to specify those countries).

This privacy policy also explains how we manage credit information and credit eligibility information. In particular it explains, in relation to that information:

  • the kinds of credit information we collect and hold and how we collect and hold that information;
  • the kinds of credit eligibility information we hold and how we hold that information;
  • the kinds of CP derived information that we usually derive from credit reporting information disclosed to us by a credit reporting body under applicable Privacy Law;
  • the purpose for which we collect, hold, use and disclose credit information and credit eligibility information;
  • how an individual may access credit eligibility information about the individual that we hold;
  • how an individual may seek the correction of credit information or credit eligibility information about the individual that we hold;
  • how an individual may complain about our failure to comply with applicable Privacy Law;
  • how we will deal with the complaint; and
  • whether we are likely to disclose credit information or credit eligibility information to entities which do not have an Australian or New Zealand link.
The kinds of personal information we collect and hold
The information we collect and hold

We collect and hold credit information about individuals who are clients, guarantors, a seller of goods or services to clients, a customer of clients, or associates of any of them. This information includes:

  • identification information, such as the individual’s name, address and date of birth;
  • the note we make of the disclosure of credit information we make to a credit reporting body so that we can obtain credit information from the credit reporting body;
  • the type of commercial credit and the amount of credit sought in an application that has been made by the individual and in connection with which we have made an information request;
  • court proceedings information about the individual, this is information about a judgment of an Australian court against the individual in proceedings (other than criminal proceedings) that relate to any credit that has been provided to, or applied for by, the individual; and
  • personal insolvency information about the individual, this is information that is entered or recorded in the National Personal Insolvency Index that relates to bankruptcy of the individual, a debt agreement proposal given by the individual, a personal insolvency agreement executed by the individual, a direction given (or an order made) under section 50 of the Bankruptcy Act 1966 (or for New Zealand purposes, the Insolvency Act 2006) that relates to the property of the individual or an authority signed under section 188 of the Bankruptcy Act 1966 that relates to the property of the individual.
Credit reporting information and credit information

We obtain credit reporting information about individuals who are clients, guarantors, a seller of goods or services to clients, a customer of clients or associates of any of them from credit reporting bodies. Credit reporting information includes:

  • the credit information outlined above but which relates to the individual’s dealings with other credit providers;
  • consumer credit liability information, default information, payment information, new arrangement information and publicly available information concerning consumer credit which the individual has obtained from other credit providers; and
  • credit worthiness information about the individual that credit reporting bodies derive from the above information. This could include credit scores, risk ratings and other evaluations.

We only obtain credit reporting information from credit reporting bodies to the extent we are entitled to obtain it under applicable Privacy Law. We might, for example, need to obtain the individual’s prior authorisation.

We may disclose credit information (such as identification information) about an individual to a credit reporting body. The credit reporting body may include that information in the reports it provides to other credit providers.

We disclose credit information to the following credit reporting body:

Equifax Pty Ltd

Australia
Website: www.equifax.com.au
Mail: PO Box 964, North Sydney NSW 2059


New Zealand
Website: www.mycreditfile.co.nz
Mail: Private Bag 92156, Victoria Street West, Auckland 1142


That credit reporting -body is required to have a policy which explains how it will manage credit-related personal information. If an individual would like to read the policy of the credit reporting body he or she should visit the credit reporting body’s website and follow the “Privacy” links, or the individual can contact the credit reporting body direct for further information.

Our policy about the management of credit related personal information is contained in this privacy policy but if an individual would like to receive it as a separate document he or she can request a copy by contacting our Privacy Contact Officer at the address specified below.

An individual has the right to request that the credit reporting body exclude his or her credit reporting information from any permissible direct marketing activities we may ask it to perform.

The individual also has the right to request that the credit reporting body not use or disclose his or her credit reporting information if the individual believes that he or she has been, or is likely to be, the victim of fraud (for example, the individual suspects someone is using his or her identity details to apply for credit). The individual must contact the credit reporting body direct should this be the case.

Other personal information

The personal information, other than credit information and credit reporting information, we collect and hold varies depending on the person we are dealing with and the reason why we are dealing with them. We collect this general personal information from individuals who are clients, guarantors, sellers of goods or services to clients, customers of clients, prospective employees, contractors, suppliers, brokers, introducers, merchants, agents, professional advisers, mercantile agents, mailing houses, call centre operators, archivers and service providers, or associates of any of them. This information will generally include the individual’s name and contact details, and information about the individual’s arrangements and transactions with us, and the management of accounts with us. In respect of Australian individuals, we will only collect sensitive information about an individual with the individual’s consent or when permissible under Australian law.

Under various laws we will be (or may be) authorised or required to collect personal information about an individual. These laws include the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, Personal Property Securities Act 2009, Corporations Act 2001, Charter of the United Nations Act 1945, Autonomous Sanctions Act 2011, Income Tax Assessment Act 1997, Income Tax Assessment Act 1936, Income Tax Regulations 1936, Tax Administration Act 1953, Tax Administration Regulations 1976, A New Tax System (Goods and Services Tax) Act 1999 and the Australian Securities and Investments Commission Act 2001 as those laws are amended and includes any associated regulations and New Zealand equivalent laws.

FrankieOne

We may collect and hold personal information about an individual for the purposes of verifying the individual’s identity and complying with applicable laws, including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Australia) and the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 (New Zealand). To assist with these processes, we utilise the services of a third-party identity verification and compliance provider, Frankie Financial Pty Ltd (ACN 623 506 892) (trading as “FrankieOne”). Where we use FrankieOne, the personal information we collect and hold may include:

  • identification information, such as the individual’s name, date of birth, residential address and contact details;
  • information contained in identity documents (for example, a driver’s licence, passport or other government-issued identification), including document numbers, expiry dates and issuing authorities;
  • biometric information, such as a facial image or selfie, and related verification data used to confirm that the individual is the holder of the identity document;
  • information derived from the verification process, including the results of identity checks, document authentication checks and fraud or risk assessments; and
  • technical and transactional information associated with the identity verification process, such as device information, IP address and the time and method of verification.

This personal information may be collected directly from the individual or via secure digital interfaces provided by FrankieOne. The information is disclosed to FrankieOne for the purpose of verifying the individual's identity, undertaking document verification checks (including through government and third -party data sources), and assisting us to meet our legal and regulatory obligations. FrankieOne collects, uses and processes this personal information as our service provider in connection with the identity verification services it provides to us.

FrankieOne is required to have a policy which explains how it will manage the collection of personal information. If an individual would like to read a FrankieOne policy the individual should visit its website and follow the “Privacy” links, or the individual can contact FrankieOne for further information.

How we collect personal information

We collect personal information, other than credit eligibility information, about individuals in a variety of ways including in the loan application process and completed loan documents, in contracts with third parties, in person, via a link to an accounting package or other data base, via a website, via mobile app, on the phone, and from other finance organisations that are authorised to provide such information under their own Privacy Policies. We may obtain the information from the individual or from persons acting on the individual’s behalf. When it is possible and practical, we will collect the information direct from the individual. When it is not practical or reasonable to do so, we will collect the information from a third party. The third party could be an authorised representative (such as a broker, agent, accountant or lawyer), another financial institution, a referee, an employer or a government body, a person that requests a facility from us, a credit reporting body, broker or other introducers, or a public register. When the individual sells goods or services to a client, is a customer of a client or is an associate of a client we may obtain the information from the client.

When New Zealand law applies, the personal information will be collected from the individual concerned unless an exception from the Privacy Act 1920 (New Zealand), Information Privacy Principle 2, applies.

The main consequence for you if all or some of the personal information is not collected by us is that we may be unable to process your (or the person’s) application; we may decide not to provide a facility or we may decide to restrict or end a facility; we may not be able to complete a transaction in which you are involved, for example as a supplier or prospective employee; or we may not give access to the Octet platform.

When New Zealand law applies, you must, before providing personal information to us about other individuals:

  • obtain consent from the relevant individual to do so; and
  • notify those individuals about the provision of their personal information and the contents of this Privacy Policy.

The credit eligibility information is obtained from a credit reporting body.

How we hold credit information and credit eligibility information

We take all reasonable steps to ensure that an individual’s personal information which we hold is protected from misuse, interference or loss and from unauthorised access, modification or disclosure.

We do this by having physical, electronic and procedural safeguards which protect the personal information we hold. For example, the personal information is stored in secure office premises or in secure archiving facilities and logins and passwords are required to access electronic databases. Our staff are required to maintain the confidentiality of personal information and access to personal information is restricted to persons who require access to perform their duties.

We will retain an individual’s personal information for as long as necessary with regard to the purpose for which we collected it, and to comply with our legal obligations.

The purposes for which we collect, hold, use and disclose personal information
Credit information and credit eligibility information

We collect, hold, use and disclose credit information and credit eligibility information on individuals for purposes permitted by law which are reasonably necessary for our business activities. Those purposes include:

  • if the individual is a client, to determine if we should provide a facility which includes the provision of commercial credit to the individual and, if we decide to provide it, to assist in the provision of the facility. This includes the assessment of the application, managing the account, recovering money and dealing with security the individual gives and to procure the issue of loyalty points to the client;
  • if the individual is a guarantor, to determine whether we should accept a guarantee from the individual and, if the guarantee is given, to deal with or enforce our rights under the guarantee and any security which may be given to secure it;
  • if the individual is a customer of a client, to assess and verify the debt which the client sells to us or in which the client gives us a security interest, to collect the debt, to enforce the debt and any security which may be given to secure payment of the debt and to procure the issue of loyalty points to the customer;
  • if the individual sells goods or services to the client, to record the contract entered into between the seller and the client and to disburse amounts we lend to the client by making payment to the seller or the Octet financial institution which has entered into a contract with the seller;
  • if the individual is an associate of the client, to determine if we should provide a facility which includes the provision of commercial credit to the client and to assist in the provision of that facility;
  • if the individual is an associate of a customer of the client, to assist us to verify the debt owed by the customer and to collect and enforce the debt. For example, we may record the name and office phone number of a person in the customer’s accounts payable department and telephone that person to verify the debt;
  • if the individual is an associate of a person who sells goods or services, to record the contract entered into between the seller and the client, to confirm that there is a bona fide contract between the seller and the client and to disburse amounts we lend to the client by making payment to the seller or the Octet financial institution which has entered into a contract with the seller;
  • to assist in the management and enforcement of the facilities we provide, for data analysis and internal management;
  • to provide information to credit reporting bodies to the extent this is permitted by the applicable Privacy Law;
  • to undertake securitisation activities, raise funds, participate in online payment processing, assign debts and other rights, enter into insurance arrangements (for example insurance policies for amounts owed to us) and provide information to and obtain information from insurers;
  • to deal with complaints and legal proceedings;
  • to meet our legal and regulatory requirements; and
  • to assist other credit providers by giving personal information to them in accordance with an authorisation which the individual has provided to them or us.

We do not hold any CP derived information.

Other information

We collect personal information about individuals which is not credit information or credit eligibility information:

  • to determine whether we should provide a facility which includes the provision of commercial credit and, if we decide to provide it, to assist in the provision of the facility. This includes the assessment of the application, managing the account, recovering money, dealing with security you give and procuring the issue of loyalty points;
  • to determine whether we should provide a facility which includes the provision of commercial credit to a person with which you are associated (for example as a director or shareholder) and to assist in the provision of the facility. If a guarantee may be given we are collecting the personal information to determine whether we should accept it and, when it is given, we collect the personal information to deal with or enforce our rights under the guarantee and any security which may be given to secure it; 
  • to determine whether we should allow the individual or a person with whom the individual is associated to use the Octet platform to, amongst other things, communicate with persons who may obtain commercial credit from us; 
  • so that we can manage and administer the facilities which we provide; 
  • so that we can procure the issue of loyalty points as contemplated by the facility and other agreements we are a party to; and
  • for other purposes required for us to manage our business, such as providing required reports to other finance businesses that we deal with, meeting prudential and other legal and accounting requirements, marketing, internal audit and reporting and business management, bundling up loans, market analysis and strategy, debt collection and assessing prospective employees, business partners and suppliers.


Service providers and other products

To provide our facilities in the most cost effective and efficient way we may decide to utilise the services of others. For example, we may use a mailing house to send monthly statements, we may use a data processing firm to manage data we hold including personal information and as outlined above, we may use a service provider to assist in identity verification. We also disclose information to our related bodies corporate and other finance businesses as required under the arrangements we have with them, to operate our business. If this requires that we disclose personal information we will require that those persons respect your right of privacy.

Personal information may also be used or disclosed to tell an individual about products or services that may be of interest to that individual. If the individual does not want his or her personal information used for these direct marketing purposes the individual should tell us. He or she can “opt-out” of direct marketing by sending an e-mail to privacy@octet.com or by writing to us at:

Privacy Contact Officer
Octet Finance Pty Ltd
Level 3
10-14 Waterloo Street
Surry Hills NSW 2010

How an individual may access personal information

An individual may access personal information (including credit eligibility information) about the individual which we hold. The individual can obtain that access by contacting our privacy contact officer as follows:

Telephone: +61 2 9356 6300

E-mail: privacy@octet.com

Mail:
Privacy Contact Officer
Octet Finance Pty Ltd
Level 3
10-14 Waterloo Street
Surry Hills NSW 2010

 

We will need to verify the individual’s identity before giving access. We will usually provide the requested personal information within 30 days of receiving the request. There is no charge to make a request but we may levy an administration fee for providing access.

If there is a reason why we do not make the requested personal information available we will provide our reason in writing.

How an individual may seek the correction of personal information

If an individual considers that any personal information which we hold about the individual is incorrect in any way the individual may ask us to correct that personal information. To seek the correction please contact our Privacy Contact Officer on the telephone number or at the e-mail or postal address above.

In certain situations, we may decide not to agree to a request to correct personal information. We will tell you in writing why we have not agreed to the correction request.

Notification of data breaches

We recognise our obligations under the applicable Privacy Law to assess suspected data breaches and, where required, notify affected individuals and the relevant privacy regulator of an eligible data breach (Australia) or notifiable privacy breach (New Zealand). We will provide any required notifications as soon as reasonably practicable in accordance with the applicable Privacy Law.

Where we have reasonable grounds to believe that an eligible data breach or a notifiable data breach has occurred under the applicable Privacy Law, we will, as soon as reasonably practicable:

  • notify the Australian Information Commissioner or the New Zealand Office of the Privacy Commissioner (as applicable), where required by the applicable Privacy Law;
  • notify affected individuals, where required by the applicable Privacy Law; and
  • provide to the individual, where required by the applicable Privacy Law, information about the nature of the breach, the personal information involved, and the steps individuals can take to minimise any potential harm. If it is not practicable to notify each individual directly, we will publish a statement on our website and take reasonable steps to publicise it.

We maintain an internal data breach response procedure. Any suspected data breach should be reported immediately to our Privacy Contact Officer at the above contact details. We will take all reasonable steps to contain any breach and mitigate its impact.

How an individual may complain and how we will deal with the complaint

We have an internal dispute resolution system that covers complaints. That system complies with ISO 10002-2006 Customer Satisfaction – Guidelines for Complaints Handling in Organisations: sections 4, 5.1, 6.4, 8.1 and 8.2. If an individual considers that we have failed to comply with applicable Privacy Law he or she should contact our Privacy Contact Officer on the telephone number or at the email or postal address above. We will then follow our internal dispute resolution system. We will acknowledge the complaint within 7 days. A decision will be made and advised within 30 days or a longer period as may be agreed with the individual.

If the individual is not satisfied with the decision he or she may make a complaint to the Office of the Australian Information Commissioner (the “OAIC”) or the New Zealand Office of the Privacy Commissioner (the “OPC”). 

The contact details for the OAIC are:

Telephone: 1300 363 992

Facsimile: (02) 6123 5145

Website: www.oaic.gov.au

Mail:
The Office of the Australian Information Commissioner
GPO Box 5288
Sydney NSW 2001

 

The contact details for the OPC are:

Telephone: 0800 803 909 

Email: enquiries@privacy.org.nz

Website: www.privacy.org.nz

Mail:
PO Box 10 094
Wellington 6140
Disclosure of personal information to overseas recipients

We will only disclose personal information to overseas recipients or to persons that do not have an Australian or New Zealand link when this is necessary for the purpose for which the information was collected or a purpose connected with the purpose for which the information was collected which the individual would reasonably expect us to use or disclose the information. For example, if the seller of goods or services to the client or the Octet financial institution which has an agreement with the seller is located overseas we may need to send the client’s information overseas so that we can confirm that a bona fide contract has been entered into between the client and the seller or to make a payment to the seller or the Octet financial institution. If there is a dispute between the client and the seller we may need to provide information to a person located overseas to assist in the resolution of that dispute.  Whenever we disclose personal information overseas, we will comply with the applicable Privacy Law.

We may use service providers located overseas.  We may provide personal information to the service provider so that the service provider can provide a service to us.

It is not practicable to specify the list of countries other than Australia or New Zealand in which the recipient could be located as this will largely depend on the sellers with whom the client decides to contract.  

Definitions

In this privacy policy:

“associate” means a person who is or may become an officer, trustee or employee of the client, the guarantor, a seller of goods or services to the client or a customer of the client;

“client” means a person (such as a company, sole trader or partnership) to whom we have provided a facility including the provision of commercial credit and includes a person who has applied for, or may apply for, a facility of that type;

“guarantor” means a person who has guaranteed, or may guarantee, the obligations which a person (such as a buyer, client or borrower) has or may have to us; and

“we”, “us” and “our” means Octet Finance Pty Ltd (ACN 124 477 916) and Octet Finance (Qld) Pty Ltd (ACN 632 841 564 and NZBN 9429052164910).

Words which are defined in the applicable Privacy Law have the same meaning in this privacy policy.