Privacy policy
Granor Capital Pty Ltd (ABN 46 689 733 284, Corporate Authorised Representative No. 1316761 of Investup Securities Pty Ltd ABN 79 670 384 924, AFSL No. 557683)
Important Notice – Wholesale Investors Only
This Privacy Policy applies to the handling of personal information collected through this website and in connection with Granor Capital’s wholesale investment and lending services.
This website and our services are intended exclusively for wholesale investors as defined under section 761G of the Corporations Act 2001 (Cth).
By accessing this website or providing any personal information to us, you confirm that you are a wholesale investor. If you are not a wholesale investor, you must not access this website or provide us with any personal information.
All information we collect is handled in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
SECTION A – INTRODUCTION
1. INTRODUCTION
1.1 Granor Capital Pty Ltd (“Granor Capital”,”company” “we”, “us” or “our”) is committed to protecting your privacy and handling your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. Granor Capital has adopted this Privacy Policy (“Policy”) to manage personal information in an open and transparent manner.
1.2 The provisions of this Policy will assist Granor Capital in complying with the requirements of the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles in protecting the personal information Granor Capital holds about its clients.
WHEN DOES THIS POLICY APPLY?
2.1 This Policy applies to all representatives and employees of Granor Capital at all times and the requirements remain in force on an ongoing basis.
GLOSSARY
TERM | DEFINITION |
APP entity | means an agency or organisation as defined in section 6 of the Privacy Act. |
Australian law | means |
Collects | Granor Capital collects personal information only for inclusion in a record or generally available publication. |
Court/tribunal order | means an order, direction or other instrument made by: |
De-identified | personal information is de-identified if the information is no longer about an identifiable individual or an individual who is reasonably identifiable. |
Eligible Data Breach | An eligible data breach occurs: |
Employee | means a person who is engaged under a contract to perform services for and on behalf of Granor Capital. Employee includes individuals, contractors, consultants, advisors and any third-party representative engaged by Granor Capital. |
Holds | Granor Capital holds personal information if it has possession or control of a record that contains the personal information. |
Identifier of an individual | means a number, letter or symbol, or a combination of any or all of those things, that is used to identify the individual or to verify the identity of the individual, but does not include: (a) the individual’s name; or |
Permitted general situation | As defined in s16A of the Privacy Act |
Permitted health situation | As defined in s16B of the Privacy Act |
Personal information means | Means information or an opinion about an identified individual, or an individual who is reasonably identifiable: |
Sensitive information | Means i. racial or ethnic origin; or ii. political opinions; or iii. membership of a political association; or iv. religious beliefs or affiliations; or v. philosophical beliefs; or vi. membership of a professional or trade association; or vii. membership of a trade union; or viii. sexual orientation or practices; or ix. criminal record; that is also personal information; or (b) health information about an individual; or |
SECTION B – CONSIDERATION OF PERSONAL INFORMATION PRIVACY
PRIVACY STATEMENT
4.1 Granor Capital’s Compliance Officer must ensure that at all times the provisions of this policy are implemented in the day to day running of Granor Capital.
4.2 The Compliance Officer must ensure that at all times this Policy:
(a) is current and reflects the latest applicable Australian laws; and
(b) contains the following information:
(i) the kinds of personal information that Granor Capital collects and holds;
(ii) how Granor Capital collects and holds personal information;
(iii) the purposes for which Granor Capital collects, holds, uses and discloses personal information;
(iv) how an individual may complain about a breach of the Australian Privacy Principles, or other relevant legislation that binds Granor Capital, and how Granor Capital will deal with such a complaint;
(v) whether Granor Capital is likely to disclose personal information to overseas recipients;
(vi) if Granor Capital is likely to disclose personal information to overseas recipients, the countries in which such recipients are likely to be located if it is practicable to specify those countries in this policy.
4.3 Granor Capital must ensure that the Granor Capital’s Privacy Policy is available free of charge and in such form as appropriate. Granor Capital will make the Privacy Policy available on its website.
4.4 If the Privacy Policy is requested in a particular form, Granor Capital will take such steps as are reasonable to provide the Privacy Policy in the form requested.
SECTION C – COLLECTION OF PERSONAL INFORMATION (SOLICITED PERSONAL INFORMATION)
PERSONAL INFORMATION (OTHER THAN SENSITIVE INFORMATION)
5.1 This Section C applies to the collection of personal information that is solicited by Granor Capital.
5.2 Granor Capital must not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of Granor Capital’s functions or activities.
5.3 Granor Capital’s functions or activities include:
(a) Provision of wholesale investment products including:
- Mortgage fund;
- Property trust;
- Other wholesale funds;
(b) Provision of general advice relating to investment products of Granor Capital.
SENSITIVE INFORMATION
6.1 Granor Capital must not collect sensitive information about an individual unless:
(a) the individual consents to the collection of the information and the information is reasonably necessary for one or more of Granor Capital’s functions or activities (as described in section 5.3); or
(b) the collection of the information is required or authorised by or under an Australian law or a Court/Tribunal order; or
(c) a permitted general situation exists in relation to the collection of the information by Granor Capital; or
(d) a permitted health situation exists in relation to the collection of the information by Granor Capital.
MEANS OF COLLECTION
7.1 Granor Capital must only collect personal information by lawful and fair means.
7.2 Granor Capital must only collect personal information about an individual from the individual (rather than someone else), unless it is unreasonable or impracticable to do so or the individual has instructed Granor Capital to liaise with someone else.
7.3 Granor Capital will collect personal information from an individual when:
(a) Granor Capital’s Application Form is completed;
(b) a Client provides the information to Granor Capital ’s representatives over the telephone or via email;
(c) a Client provides the information to Granor Capital on the website;
(d) an Employee commences employment with Granor Capital.
INFORMATION COLLECTED BY GRANOR CAPITAL
8.1 The information Granor Capital collects may include the following:
(a) name;
(b) date of birth;
(c) postal or email address; or
(d) phone numbers;
(e) other information Granor Capital considers necessary to their functions and activities.
PURPOSE OF COLLECTION
9.1 If an individual is acquiring or has acquired a product or service from Granor Capital, the individual’s personal information will be collected and held for the purposes of:
(a) checking whether an individual is eligible for Granor Capital’s product or service;
(b) providing the individual with Granor Capital’s product or service;
(c) managing and administering Granor Capital’s product or service;
(d) protecting against fraud, crime or other activity which may cause harm in relation to Granor Capital’s products or services;
(e) complying with legislative and regulatory requirements in any jurisdiction;
(f) to assist Granor Capital in the running of its business;
(g) maintaining personal information for Granor Capital Employees;
9.2 Granor Capital may also collect personal information for the purposes of letting an individual know about products or services that might better serve their needs or other opportunities in which they may be interested. Please refer to Section G for further information.
SECTION D – COLLECTION OF PERSONAL INFORMATION (UNSOLICITED PERSONAL INFORMATION)
DEALING WITH UNSOLICITED PERSONAL INFORMATION
10.1 If Granor Capital:
(a) receives personal information about an individual; and
(b) the information is not solicited by Granor Capital
Granor Capital must, within a reasonable period after receiving the information, determine whether or not it was permitted to collect the information under Section C above.
10.2 Granor Capital may use or disclose the personal information for the purposes of making the determination under paragraph 10.1.
10.3 If Granor Capital:
(a) determines that it could not have collected the personal information; and
(b) the information is not contained in a Commonwealth record,
Granor Capital must as soon as practicable, destroy the information or ensure that the information is de-identified, only if it is lawful and reasonable to do so.
SECTION E – NOTIFICATION OF THE COLLECTION OF PERSONAL INFORMATION
NOTIFICATION OF COLLECTION
11.1 This section 11 applies to:
(a) solicited information; and
(b) unsolicited information to which section 10 does not apply.
11.2 Granor Capital must notify the individual of the following matters in the Privacy Statement:
(a) Granor Capital’s identity and contact details;
(b) if Granor Capital collects the personal information from a third party or the individual is not aware that Granor Capital has collected the personal information, the fact that Granor Capital so collects, or has collected the information and the circumstances of that collection;
(c) if the collection of the personal information is required or authorised by or under an Australian law or a Court/Tribunal order, the fact that the collection is so required or authorised (including the details of the law or court);
(d) the purposes for which Granor Capital collects the personal information;
(e) the main consequences (if any) for the individual if the information is not collected by Granor Capital;
(f) any other entities to which Granor Capital usually discloses personal information of the kind collected by Granor Capital;
(g) that Granor Capital’s Privacy Statement and this Privacy Policy contains information about how the individual may access the personal information about the individual that is held by Granor Capital and seek correction of such information;
(h) that Granor Capital’s Privacy Statement contains information about how the individual may complain about a breach of the Australian Privacy Principles and how Granor Capital will deal with such a complaint;
(i) whether Granor Capital will disclose the personal information to overseas recipients; and
(j) if Granor Capital discloses the personal information to overseas recipients – the countries in which such recipients will be located if it is practicable to specify those countries in the notification or to otherwise make the individual aware of them.
SECTION F – USE OR DISCLOSURE OF PERSONAL INFORMATION
USE OR DISCLOSURE
12.1 Where Granor Capital holds personal information about an individual that was collected for a particular purpose (“the primary purpose”), Granor Capital must not use or disclose the information for another purpose (“the secondary purpose”) unless:
(a) the individual has consented to the use or disclosure of the information; or
(b) the individual would reasonably expect Granor Capital to use or disclose the information for the secondary purpose and the secondary purpose is:
- directly related to the primary purpose (if the information is sensitive information); or
- related to the primary purpose (if the information is not sensitive information);
(c) the use or disclosure of the information is required or authorised by or under an Australian law or a Court/Tribunal order; or
(d) a permitted general situation exists in relation to the use or disclosure of the information by Granor Capital; or
(e) Granor Capital reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.
12.2 Where Granor Capital uses or discloses personal information in accordance with section 12.1(e), Granor Capital will keep a copy of this disclosure (e.g.: the email or letter used to do so).
12.3 This section 12 does not apply to:
(a) personal information for the purposes of direct marketing; or
(b) government related identifiers.
12.4 If Granor Capital collects personal information from a related body corporate, this section 12 applies as if Granor Capital’s primary purpose for the collection was the primary purpose for which the related body corporate collected the information.
12.5 Employees of Granor Capital must ensure that all information obtained in the course of their contractual arrangement with Granor Capital remains confidential and must not be disclosed to any third party except as outlined in this Policy.
WHO DOES GRANOR CAPITAL DISCLOSE PERSONAL INFORMATION TO?
13.1 Granor Capital may disclose personal information collected from clients, prospective clients and Employees to the following:
(a) organisations involved in providing, managing or administering Granor Capital’s product or service such as third-party suppliers, e.g. printers, posting services, and our advisers;
(b) organisations involved in maintaining, reviewing and developing Granor Capital’s business systems, procedures and infrastructure, including testing or upgrading Granor Capital’s computer systems;
(c) organisations involved in a corporate re-organisation;
(d) organisations involved in the payments system, including financial institutions, merchants and payment organisations;
(e) organisations involved in product planning and development;
(f) other organisations, who jointly with Granor Capital’s, provide its products or services;
(g) authorised representatives who provide Granor Capital’s products or services on its behalf;
(h) the individual’s representatives, including your legal advisers;
(i) debt collectors;
(j) Granor Capital’s financial advisers, legal advisers or auditors;
(k) fraud bureaus or other organisations to identify, investigate or prevent fraud or other misconduct;
(l) external dispute resolution schemes; or
(m) regulatory bodies, government agencies and law enforcement bodies in any jurisdiction.
SECTION G – DIRECT MARKETING
DIRECT MARKETING
14.1 Granor Capital must not use or disclose the personal information it holds about an individual for the purpose of direct marketing.
EXCEPTION – PERSONAL INFORMATION OTHER THAN SENSITIVE INFORMATION
15.1 Granor Capital may use or disclose personal information (other than sensitive information) about an individual for the purposes of direct marketing if:
(a) Granor Capital collected the information from the individual; and the individual would reasonably expect Granor Capital to use or disclose the information for that purpose; or
(b) Granor Capital has collected the information from a third party; and either: (i) Granor Capital has obtained the individual’s consent to the use or disclose the information for the purpose of direct marketing; or (ii) it is impracticable for Granor Capital to obtain the individual’s consent; and
(c) Granor Capital provides a simple way for the individual to opt out of receiving direct marketing communications from Granor Capital;
(d) each direct marketing communication with the individual Granor Capital:
(i) includes a prominent statement that the individual may make such a request; or
(ii) directs the individual’s attention to the fact that the individual may make such a request; and
(e) the individual has not made a request to opt out of receiving direct marketing.
EXCEPTION – SENSITIVE INFORMATION
16.1 Granor Capital may use or disclose sensitive information about an individual for the purpose of direct marketing if the individual has consented to the use or disclosure of the information for that purpose.
REQUESTS TO STOP DIRECT MARKETING
17.1 Where Granor Capital uses or discloses personal information about an individual for the purposes of direct marketing by Granor Capital or facilitating direct marketing by another organisation, the individual may request:
(a) that Granor Capital no longer provide them with direct marketing communications;
(b) that Granor Capital does not use or disclose the individual’s personal information for the purpose of facilitating direct marketing by another organisation;
(c) that Granor Capital provides the source of the personal information.
17.2 Where Granor Capital receives a request from an individual under section 17.1, Granor Capital will:
(a) give effect to the request under section 17.1(a) or 17.1(b) within a reasonable period after the request is made and free of charge; and
(b) notify the individual of the source of the information, if the individual requests it, unless it is impracticable or unreasonable to do so.
17.3 This Section G does not apply to the extent that the following laws apply:
(a) the Do Not Call Register Act 2006;
(b) the Spam Act 2003; or
(c) any other Act of the Commonwealth of Australia.
SECTION H – CROSS BORDER DISCLOSURE OF PERSONAL INFORMATION
DISCLOSING PERSONAL INFORMATION TO CROSS BORDER RECIPIENTS
18.1 Where Granor Capital discloses personal information about an individual to a recipient who is not in Australia and who is not Granor Capital or the individual, Granor Capital must ensure that the overseas recipient does not breach the Australian Privacy Principles (with the exception of APP1).
18.2 Section 18.1 does not apply where:
(a) Granor Capital reasonably believes that:
(i) information is subject to a law or binding scheme that has the effect of protecting the information in a way that is at least substantially similar to the way in which the Australian Privacy Principles protect the information; and
(ii) there are mechanisms that the individual can access to take action to enforce that protection of the law or binding scheme; or
(b) both of the following apply:
(i) Granor Capital has informed the individual that if they consent to the disclosure of information Granor Capital will not take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles; and
(ii) after being so informed, the individual consents to disclosure;
(c) the disclosure of the information is required or authorised by or under an Australian law or a Court/Tribunal order; or
(d) a permitted general situation (other than the situation referred to in item 4 or 5 of the table in subsection 16A (1) Privacy Act) exists in relation to the disclosure of the information by Granor Capital.
SECTION I – ADOPTION, USE OR DISCLOSURE OF GOVERNMENT IDENTIFIERS
ADOPTION OF GOVERNMENT RELATED IDENTIFIERS
19.1 Granor Capital must not adopt a government related identifier of an individual as its own identifier unless:
(a) Granor Capital is required or authorised by or under an Australian law or a Court/Tribunal order to do so; or
(b) the identifier, Granor Capital and the circumstances of the adoption are prescribed by regulations.
USE OR DISCLOSURE OF GOVERNMENT RELATED IDENTIFIERS
20.1 Before using or disclosing a government related identifier of an individual, Granor Capital must ensure that such use or disclosure is:
(a) reasonably necessary for Granor Capital to verify the identity of the individual for the purposes of the organisation’s activities or functions;
(b) reasonably necessary for the organisation to fulfil its obligations to an agency or a State or Territory authority;
(c) required or authorised by or under an Australian law or a Court/Tribunal order;
(d) within a permitted general situation (other than the situation referred to in item 4 or 5 of the table in subsection 16A (1) Privacy Act;
(e) reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
(f) the identifier, Granor Capital and the circumstances of the adoption are prescribed by regulations.
SECTION J – INTEGRITY OF PERSONAL INFORMATION
QUALITY OF PERSONAL INFORMATION
21.1 Granor Capital will ensure that the personal information it collects and the personal information it uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up to date, complete and relevant.
SECURITY OF PERSONAL INFORMATION
22.1 Granor Capital will ensure that it protects any personal information it holds from misuse, interference, loss, unauthorised access, modification and disclosure.
22.2 Granor Capital will take reasonable steps to destroy or de-identify any personal information it holds where:
(a) Granor Capital no longer needs the personal information for any purpose for which the information may be used or disclosed by Granor Capital;
(b) the information is not contained in a Commonwealth record;
(c) Granor Capital is not required to retain that information under an Australian law, or a Court/Tribunal order.
STORAGE OF PERSONAL INFORMATION
23.1 Granor Capital stores personal information in different ways, including:
(a) hard copy on site at Granor Capital’s head office;
(b) electronically secure data centres which are located in Australia and owned by either Granor Capital or external service providers;
(c) Granor Capital’s secure offsite storage facilities.
SECTION K – ACCESS TO, AND CORRECTION OF, PERSONAL INFORMATION
ACCESS
24.1 Granor Capital must give an individual access to the personal information it holds about the individual if so requested by the individual.
24.2 Granor Capital must respond to any request for access to personal information within a reasonable period after the request is made.
24.3 Granor Capital must give access to the information in the manner requested by the individual, if it is reasonable and practicable to do so and must take such steps as are reasonable in the circumstances to give access in a way that meets the needs of Granor Capital and the individual.
24.4 Granor Capital must not charge an individual for making a request and must not impose excessive charges for the individual to access their personal information.
EXCEPTIONS
25.1 Granor Capital is not required to give an individual access to their personal information if:
(a) Granor Capital reasonably believes that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety;
(b) giving access would have an unreasonable impact on the privacy of other individuals;
(c) the request for access if frivolous or vexatious;
(d) the information relates to existing or anticipated legal proceedings between Granor Capital and the individual, and would not be accessible by the process of discovery in those proceedings;
(e) giving access would reveal intentions of Granor Capital in relation to negotiations with the individual in such a way as to prejudice those negotiations;
(f) giving access would be unlawful;
(g) denying access is required or authorised by or under an Australian law or a Court/Tribunal order;
(h) Granor Capital has reason that unlawful activity, or misconduct of a serious nature, that relates to our functions or activities has been, or may be engaged in and giving access would be likely to prejudice the taking of appropriate action in relation to the matter;
(i) giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
(j) giving access would reveal evaluative information generated within Granor Capital in connection with a commercially sensitive decision-making process.
REFUSAL TO GIVE ACCESS
26.1 If Granor Capital refuses to give access in accordance with section 24 or to give access in the manner requested by the individual, Granor Capital will give the individual a written notice that sets out:
(a) the reasons for the refusal except to the extent that, having regard to the grounds for the refusal, it would be unreasonable to do so; and
(b) the mechanisms available to complain about the refusal; and
(c) any other matter prescribed by the regulations.
26.2 Where Granor Capital refuses to give access under section 25.1(j) Granor Capital may include an explanation of the commercially sensitive decision in its written notice of the reasons for denial.
SECTION L – CORRECTION OF PERSONAL INFORMATION
CORRECTION OF INFORMATION
27.1 Granor Capital must take reasonable steps to correct all personal information, having regard to the purpose for which the information is held where:
(a) Granor Capital is satisfied the information is inaccurate, out of date, incomplete, irrelevant or misleading; or
(b) the individual requests Granor Capital corrects the information.
27.2 Where Granor Capital corrects personal information about an individual that Granor Capital previously disclosed to another APP entity and the individual requests Granor Capital to notify the other APP entity of the correction, Granor Capital must take reasonable steps to give that notification, unless it is impracticable or unlawful to do so.
REFUSAL TO CORRECT INFORMATION
28.1 If Granor Capital refuses to correct personal information as requested by the individual, Granor Capital will give the individual a written notice that sets out:
(a) the reasons for the refusal except to the extent that it would be unreasonable to do so; and
(b) the mechanisms available to complain about the refusal; and
(c) any other matter prescribed by the regulations.
REQUEST FROM A CLIENT TO ASSOCIATE A STATEMENT WITH THEIR INFORMATION
29.1 If:
(a) Granor Capital refuses to correct personal information as requested by the individual; and
(b) the individual requests that Granor Capital associate a statement noting that the information is inaccurate, out of date, incomplete, irrelevant or misleading, with the individual’s information, Granor Capital must take such steps as are reasonable in the circumstances to associate the statement (as described in section
29.1. (b) with the individual’s personal information. The statement should be associated with the information in such a way that will make the statement apparent to users of the information.
DEALING WITH REQUESTS
30.1
Granor Capital must:
(a) respond to requests under this Section L within a reasonable period after the request is made; and
(b) must not charge the individual for the making of the request, for correcting the personal information or for associating the statement with the personal information.
SECTION M – MISCELLANEOUS
NOTIFIABLE DATA BREACHES SCHEME
31.1 Under the Privacy Amendment (Notifiable Data Breaches) Act 2017 (“Privacy Amendment Act”) Granor Capital is required to notify the Office of the Australian Information Commissioner (“OAIC”) in relation to all eligible data breaches.
31.2 Granor Capital must notify the OAIC by lodging a Notifiable Data Breach Form soon as practicable. The Notifiable Data Breach Form is available at the following link: https://forms.business.gov.au/smartforms/landing.htm?formCode=OAIC-NDB.
31.3 Under the Privacy Amendment Act, Granor Capital must also promptly inform clients whose personal information has been compromised by the eligible data breach that a breach of their personal information has occurred.
31.4 Granor Capital has also developed a Data Breach Response Plan in accordance with the OAIC’s guidelines to ensure the timely notification of all clients affected by any eligible data breach.
POLICY BREACHES
32.1 Breaches of this Policy may lead to disciplinary action being taken against the relevant party, including dismissal in serious cases and may also result in prosecution under the law where that act is illegal. This may include re-assessment of bonus qualification, termination of employment and/or fines (in accordance with the Privacy Act).
32.2 Staff are trained internally on compliance and their regulatory obligation to Granor Capital. They are encouraged to respond appropriately to and report all breaches of the law and other incidents of non-compliance, including Granor Capital’s policies, and seek guidance if they are unsure.
32.3 Staff must report breaches of this Policy directly to the Compliance Officer.
RETENTION OF FORMS
33.1 The Compliance Officer will retain the completed forms for seven (7) years in accordance with Granor Capital’s Document Retention Policy. The completed forms are retained for future reference and review.
33.2 As part of their training, all staff are made aware of the need to practice thorough and up to date record keeping, not only as a way of meeting Granor Capital’s compliance obligations, but as a way of minimising risk.
POLICY REVIEW
34.1 Granor Capital’s Privacy Policy will be reviewed on at least an annual basis by the Compliance Officer of Granor Capital, having regard to the changing circumstances of Granor Capital. The Compliance Officer will then report to the Director and/or the executive management team on compliance with this Policy.
Issued by Granor Capital Pty Ltd (Corporate Authorised Representative No. 1316761 of Investup Securities Pty Ltd ABN 79 670 384 924, AFSL No. 557683)
We use cookies to enhance your browsing experience, analyse site traffic, and personalise content. By clicking "Accept", you agree to our use of cookies. You can manage your preferences by adjusting your browser settings. For more details, see our Privacy Policy.
