Your information, protected.

How Triple Eight Advisory collects, uses, stores and discloses personal information. Written in plain language, and consistent with the Privacy Act 1988 and the Australian Privacy Principles.

Governing law
Privacy Act 1988 (Cth)
Framework
Australian Privacy Principles
Data residency
Australia
Review cycle
Annual
Last updated: 14 March 2026 Effective: 1 April 2026
01

Overview

Triple Eight (888) Advisory Pty Ltd ("Triple Eight", "we", "us" or "our") is committed to protecting the privacy of every client, contact and visitor. This policy explains what personal information we collect, why we collect it, how we handle it, and the choices available to you.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs). As a Registered Tax Agent we are also bound by the Code of Professional Conduct administered by the Tax Practitioners Board, which imposes additional confidentiality obligations on everything you tell us.

This policy applies to our website, our client portal, and every advisory, tax, audit and wealth engagement we undertake.

02

Information we collect

The information we collect depends on your relationship with us. We only collect what we reasonably need to deliver our services and meet our legal obligations.

Client and engagement information

  • Name, date of birth, contact details and residential or business address.
  • Tax file numbers, ABNs, and other government identifiers where required to lodge on your behalf.
  • Financial records. Income, deductions, assets, liabilities, bank and investment statements.
  • Superannuation and SMSF details, estate planning and succession information.
  • Identity verification documents collected under our AML/CTF obligations.

Website and portal information

  • Details you submit through enquiry, consultation booking or subscription forms.
  • Technical data such as IP address, browser type, device and referring page.
  • Usage analytics that tell us which pages and resources are most useful.

Sensitive information

We generally do not collect sensitive information. Where an engagement requires it, for example health information relevant to an insurance or estate matter. We will collect it only with your consent and only for that specific purpose.

03

How we collect information

Wherever it is reasonable and practicable, we collect personal information directly from you, in meetings, over the phone, through our secure client portal, or in documents you provide.

In some circumstances we collect information from third parties, including the Australian Taxation Office, your previous accountant or adviser, banks and lenders, superannuation funds, ASIC, and your legal representatives. Where we do, we take reasonable steps to make sure you know the information has been collected and why.

04

Why we use your information

We use personal information for the following purposes:

  • Providing tax, accounting, audit, business advisory and wealth services.
  • Preparing and lodging returns, statements and reports with regulators on your behalf.
  • Verifying your identity and meeting AML/CTF and other statutory obligations.
  • Administering our engagement. Billing, correspondence and record keeping.
  • Responding to your enquiries and booking consultations.
  • Sending you insights, updates and event invitations where you have opted in.
  • Improving our website, services and client experience.

We will not use your personal information for a purpose unrelated to those above unless you would reasonably expect it, you have consented, or the law requires or permits it.

05

Who we disclose it to

We do not sell personal information. We disclose it only where necessary to deliver our services or comply with the law, including to:

  • The Australian Taxation Office, ASIC, AUSTRAC and other regulators.
  • Your other professional advisers, lawyers, brokers, bankers, financial planners, where you have authorised us to do so.
  • Software and infrastructure providers who host or process data on our behalf under contract.
  • Our professional indemnity insurers, external auditors and legal advisers where required.
  • Any person or body where disclosure is required or authorised by law.

Every third-party provider we engage is bound by confidentiality obligations and may use your information only for the purpose we have engaged them for.

06

How we keep it secure

We maintain physical, technical and administrative controls designed to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure. These include:

  • Encryption of data in transit and at rest.
  • Mandatory multi-factor authentication on every internal system and client portal.
  • Role-based, least-privilege access limited to your engagement team and reviewed quarterly.
  • Annual security training for all staff and a documented incident-response plan.
  • Secure disposal of physical records and certified destruction of digital media.

Client data is hosted in Australian data centres that are ISO 27001 certified. We do not routinely transfer personal information overseas. If an engagement ever requires it, we will tell you first and take reasonable steps to ensure the recipient handles it consistently with the APPs.

07

How long we keep it

We retain records for as long as necessary to provide our services and to meet our legal and professional obligations. Taxation and corporate records are generally retained for a minimum of five years after the relevant transaction or the end of the engagement, and in some cases longer where a specific law requires it.

When information is no longer required and we are not legally obliged to keep it, we destroy or de-identify it securely.

08

Accessing and correcting your information

You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete or misleading.

To make a request, contact our Privacy Officer using the details in section 10. We will verify your identity and respond within 30 days. Access is free, although we may charge a reasonable fee for retrieving and copying extensive records. We will always tell you the cost before proceeding.

There are limited circumstances in which we may decline a request, for example where giving access would unreasonably affect another person's privacy or where the law requires us to refuse. If we decline, we will explain why in writing and tell you how to complain.

09

Cookies and website analytics

Our website uses cookies, small text files stored on your device, to keep the site working properly, remember your preferences and understand how visitors use our content.

  • Essential cookies enable core functions such as navigation and secure portal access. The site cannot function without them.
  • Analytics cookies help us measure traffic and improve our resources. The data is aggregated and does not identify you personally.

You can control or delete cookies through your browser settings. Blocking essential cookies may affect how parts of the site work.

10

Complaints and contact

If you believe we have breached the Australian Privacy Principles or mishandled your information, please tell us. Complaints are taken seriously and reviewed by a partner independent of the engagement.

Privacy Officer

Triple Eight (888) Advisory
9A/49 Hay St, Subiaco WA 6008
Email: tripleeightadvisory.com.au
Phone: (08) 6114 4520

We will acknowledge your complaint within five business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may refer the matter to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992.

11

Changes to this policy

We review this policy at least annually and may update it to reflect changes in our services, technology or the law. The current version is always published on this page with its effective date.

Where a change materially affects how we handle your personal information, we will notify affected clients directly before it takes effect.

Questions about this privacy policy?

Our compliance team responds to written enquiries within two business days. You can also request a signed PDF copy for your records.