Privacy Policy
Hesperia is committed to handling your personal information openly and responsibly, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
Hesperia may change this policy from time to time by updating this page.
Last updated: September 2026
1.1 Hesperia Property Pty Ltd ACN 641 894 340, Hesperia Projects Pty Ltd ACN 626 002 140, Hesperia Funds Management Pty Ltd ACN 631 092 969, Hesperia Real Estate Pty Ltd (ACN 655 945 207) its subsidiaries, its related bodies corporate or its related entities or trusts (“Hesperia“, “we” “us” “our“) is committed to managing personal information in accordance with the requirements of the Privacy Act 1988 (Cth) (“Privacy Act“) and the Australian Privacy Principles (APPs).
1.2 This Privacy Policy (“Privacy Policy“) explains how Hesperia collects, stores, uses, discloses and manages your personal information.
1.3 In this Privacy Policy, “you” and “your” refers to any individual about whom Hesperia collects personal information.
1.4 By providing personal information to Hesperia, you consent to Hesperia’s collection, use, storage, disclosure and management of your personal information in accordance with the Privacy Act and this Policy.
1.5 This Policy applies any time Hesperia collects personal information from you.
1.6 Hesperia must ensure that Hesperia’s Privacy Policy is available free of charge and in such form as appropriate.
1.7 If the Privacy Policy is requested in a particular form, Hesperia will take such steps as are reasonable to provide the Privacy Policy in the form requested.
2.1 Hesperia’s Privacy Compliance Officer must ensure that at all times the provisions of this policy are implemented in the day-to-day running of Hesperia.
2.2 The Privacy Compliance Officer must ensure that at all times this Policy:
a) is current and reflects the latest applicable Australian laws; and
b) contains the following information:
I. the kinds of personal information that Hesperia collects and holds;
II. how Hesperia collects and holds personal information;
III. the purposes for which Hesperia collects, holds, uses and discloses personal information;
IV. how an individual may complain about a breach of the Australian Privacy Principles, or other relevant legislation that binds Hesperia, and how Hesperia will deal with such a complaint;
V. whether Hesperia is likely to disclose personal information to overseas recipients; and
VI. if Hesperia is likely to disclose personal information to overseas recipients, the countries in which such recipients are likely to be located if it is practicable to specify those countries in this policy.
3.1 Clauses 4 to 7 apply to the collection of personal information that is solicited by Hesperia.
3.2 Hesperia will not collect personal information (other than Sensitive Information) unless the information is reasonably necessary for one or more of Hesperia’s functions or activities.
Hesperia will not collect Sensitive Information about you unless:
a) you consent to the collection of the information and the information is reasonably necessary for one or more of Hesperia’s functions or activities;
b) the collection of the information is required or authorised by or under an Australian law or a Court/Tribunal order;
c) a permitted general situation exists in relation to the collection of the information by Hesperia; or
d) a permitted health situation exists in relation to the collection of the information by Hesperia.
5.1 Hesperia will only collect personal information by lawful and fair means.
5.2 Hesperia will, wherever possible, only collect personal information about an individual from the individual (rather than someone else), unless it is unreasonable or impracticable to do so or the individual has instructed Hesperia to liaise with someone else.
5.3 Hesperia will collect personal information in various ways including:
a) from correspondence and forms submitted by you;
b) when you use the Hesperia website or applications (or any website or applications of an entity controlled by Hesperia);
c) when you communicate or interact with Hesperia either directly or indirectly, including by phone, email, face to face or online meetings, online or social media interaction;
d) as part of any registration, subscription or application process;
e) in the course of Hesperia providing services;
f) when you participate in our surveys, competitions, loyalty programs or promotion;
g) when you apply for a position with us through our recruitment process;
h) from third parties which Hesperia works with;
i) through publicly available information services;
j) marketing agencies;
k) credit reporting bodies, law enforcement and government entities;
l) other individuals (for example employment references); and
m) when Hesperia is required to collect the information by regulatory requirements or requirements pursuant to the AML/CTF Act.
5.4 You can always decline to give Hesperia any personal information Hesperia requests, but that may mean Hesperia cannot provide you with some or all of the services you have requested. If you have any concerns about personal information we have requested, please contact Hesperia.
6.1 The personal information Hesperia collects may include the following types of information:
a) information to verify your identity including your name, date of birth, gender, address, email address, telephone number or government issued identification documents;
b) tax file numbers;
c) financial information including bank accounts, credit card details, your income and third party sourced credit checks;
d) employment application including employment history, referee contact details, tax file number and tax related information and other information provided as part of our recruitment and employee on-boarding process;
e) your preference of our products, services, facilities and lifestyle activities;
f) your device ID, device type, geo-location information, IP address, browsing information and any personal information provided directly or indirectly via our websites, Wi-Fi services, mobile applications, cookies, usage data (via analytics); and
g) other information Hesperia considers necessary to their functions and activities.
6.2 You can always decline to give Hesperia any personal information it requests, but that may mean we cannot provide you with some or all of the services you have requested. If you have any concerns about personal information we have requested, please let us know.
6.3 Hesperia will provide individuals with the opportunity of remaining anonymous or using a pseudonym in their dealings with us where it is lawful and practicable (for example, when making a general enquiry). Generally, it is not practicable or lawful for Hesperia to deal with individuals anonymously or pseudonymously on an ongoing basis. If we do not collect personal information about you, you may be unable to utilise our services or participate in our events, programs or activities.
6.4 In connection with Hesperia’s internal recruitment and employment process and its ongoing employment of any individuals, Hesperia may also collect information about an individual and their work over the course of their employment with Hesperia (or, for contractors, during the performance of a contract with Hesperia). This may include details of employment contracts, reporting lines, remuneration, performance reviews, disciplinary and grievance investigations, attendance and leave records, training records, expenses, and the use of Hesperia’s property and equipment (including computers, swipe cards, telephone systems, email and software).
7.1 Hesperia collects personal information reasonably necessary to carry out its business, to assess and manage our clients’ needs, and provide services or products. Hesperia may also collect information to fulfil administrative functions associated with these services, for example billing, entering into contracts with you and/or third parties and managing client relationships.
7.2 The purposes for which Hesperia usually collects and uses personal information depends on the nature of your interaction with us, but may include:
a) checking whether an individual is eligible for Hesperia’s product or service;
b) verifying an individual’s identity;
c) providing the individual with Hesperia’s product or service;
d) marketing products to an individual;
e) managing and administering Hesperia’s product or service;
f) protecting against fraud, crime or other activity which may cause harm in relation to Hesperia’s products or services;
g) to consider the suitability of prospective employees;
h) in respect of employees of Hesperia, managing the employment relationship, including performance management, disciplinary and grievance processes;
i) doing business with you; or
j) complying with legislative and regulatory requirements in any jurisdiction and any applicable legal obligations
k) to assist Hesperia in the running of its business.
7.3 Hesperia may also collect personal information for the purposes of letting an individual know about products or services that might better serve their needs or other opportunities in which they may be interested.
7.4 Hesperia also collects and uses personal information for market research purposes and to innovate our delivery of products and services.
7.5 We may collect your personal information to verify your identity and comply with our other obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act). Where Hesperia collects information for such purpose, it will only collect information that is reasonably necessary of it to comply with its obligations under the AML/CTF Act.
7.6 Where required under the Privacy Act, Hesperia will provide a specific collection notice to you at the point of collection with specific details of the collection.
8.1 If Hesperia:
a) receives personal information about an individual
b) The information is not solicited by Hesperia
c) Hesperia will, within a reasonable period after receiving the information, determine whether or not it was permitted to collect the information.
8.2 Hesperia may use or disclose the personal information for the purposes of making the determination under clause 8.1.
8.3 If Hesperia:
a) determines that it could not have collected the personal information
b) the information is not contained in a Commonwealth record
Hesperia must as soon as practicable, destroy the information or ensure that the information is de-identified, only if it is lawful and reasonable to do so.
9.1 The purposes for which we may use and disclose your personal information will depend on the services we are providing you. For example, if you have engaged us to deliver a service, we may disclose information about you to service providers where this is relevant to our services.
9.2 If you are a customer or participant in an event, we may disclose your personal information to our clients and venues where this is reasonably necessary for, and relevant to, the delivery of the event. We may use images or audio-visual recordings which identify you for promotional purposes where you would reasonably expect this to occur.
9.3 Hesperia may disclose information to third parties we engage in order to provide our services, including contractors and service providers used for data processing, data analysis, customer satisfaction surveys, information technology services and support, website maintenance or development, printing, archiving, mail-outs, and market research.
9.4 Hesperia will also use and disclose personal information for a range of administrative, management and operational purposes. This includes:
a) administering billing and payments and debt recovery;
b) planning, managing, monitoring and evaluating our services;
c) quality improvement activities;
d) statistical analysis and reporting;
e) training staff, contractors and other workers;
f) risk management and management of legal liabilities and claims (for example, liaising with insurers and legal representatives);
g) responding to enquiries and complaints regarding our services;
h) obtaining advice from consultants and other professional advisers; and
i) responding to subpoenas and other legal orders and obligations.
9.5 Where Hesperia holds personal information about an individual that was collected for a particular purpose (“the primary purpose“), Hesperia will not use or disclose the information for another purpose (“the secondary purpose“) unless:
a) the individual has consented to the use or disclosure of the information;
b) the individual would reasonably expect Hesperia to use or disclose the information for the secondary purpose and the secondary purpose is:
I. directly related to the primary purpose (if the information is Sensitive Information); or
II. related to the primary purpose (if the information is not Sensitive Information);
c) the use or disclosure of the information is required or authorised by or under an Australian law or a Court/Tribunal order;
d) a permitted general situation exists in relation to the use or disclosure of the information by Hesperia; or
e) Hesperia reasonably believes that the use or disclosure of the information is reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body.
9.6 Where Hesperia uses or discloses personal information in accordance with clause 9.5(e), Hesperia will keep a copy of this disclosure (for example the email or letter used to do so).
9.7 This clause 9 does not apply to:
a) personal information for the purposes of direct marketing; or
b) government related identifiers.
9.8 If Hesperia collects personal information from a related body corporate, this clause 9 applies as if Hesperia’s primary purpose for the collection was the primary purpose for which the related body corporate collected the information.
9.9 Hesperia may use Artificial Intelligence (AI) systems or tools to support its business operations. We use trusted enterprise solutions and use best endeavors to maintain control and security over your personal information. This includes AI created in house and hosted by third parties. Hesperia may include the following types of information when using AI:
a) non-sensitive business data that supports operational processes;
b) anonymised personal information (being information that has undergone a de-identification process to remove personally identifiable information) to prepare reports and statistics for relevant business operations; or
c) information collected for the primary purpose of using AI or otherwise with your consent.
9.10 Hesperia recognises the significance of aligning with the Office of the Australian Information Commissioner (OAIC)’s guidance on the responsible use of AI and the protection of personal information. We are committed to taking reasonable steps to ensure that any AI-based processes utilised in the business incorporate appropriate governance, transparency, and risk assessment.
9.11 We actively work to identify and mitigate against potential biases in the operation of AI systems and ensure usage of AI systems complies with the relevant laws.
9.12 We ensure that any personal information processed through AI systems is handled in compliance with the Australian Privacy Principles (APPs) and that data minimisation principles are upheld.
9.13 We maintain accountability for our use of AI by implementing oversight mechanisms, including human reviews of all decisions made by AI systems.
9.14 Individuals have the right to know how their personal information is used in AI decision-making processes and can request explanations about decisions made via automated processes.
10.1 Hesperia may disclose personal information collected from clients and prospective clients to the following:
a) organisations involved in providing, managing or administering Hesperia’s product or service such as third-party suppliers, e.g. printers, posting services, and our advisers;
b) organisations involved in maintaining, reviewing and developing Hesperia’s business systems, procedures and infrastructure, including testing or upgrading Hesperia’s computer systems;
c) organisations involved in a corporate re-organisation;
d) organisations involved in the payments system, including financial institutions, merchants and payment organisations;
e) organisations involved in product planning and development;
f) other organisations, who jointly with Hesperia, provide its products or services and service providers and individuals who assist Hesperia in providing its services or managing its operations;
g) authorised representatives who provide Hesperia’s products or services on its behalf;
h) the individual’s representatives, including your legal advisers;
i) debt collectors;
j) Hesperia’s financial advisers, legal advisers or auditors;
k) fraud bureaus or other organisations to identify, investigate or prevent fraud or other misconduct;
l) external dispute resolution schemes; and
m) regulatory bodies, government agencies and law enforcement bodies in any jurisdiction.
10.2 Without limiting clause 10.1, where required or authorised by law, Hesperia may collect, use and disclose your personal information for the purposes of complying with its obligations under the AML/CTF Act, the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 and related regulatory requirements. This may include using or disclosing personal information for customer and investor due diligence, identity verification, sanctions and politically exposed person screening, transaction monitoring, suspicious matter reporting, responding to regulatory requests or directions, and making disclosures to AUSTRAC, law enforcement bodies, government agencies, regulators and service providers who assist Hesperia to comply with those obligations.
10.3 We may disclose your personal information to the following overseas recipients:
a) related entities;
b) companies and service providers who assist us in providing services or perform functions on our behalf, such as hosting and data storage providers; and
c) where we are required or authorised by law to do so.
10.4 The recipients are likely to be based in the United States.
10.5 Unless we have your consent, or an exception under the APPs applies, we will only disclose your personal information to overseas recipients where we have taken reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to your personal information or if Hesperia reasonably considers that recipient of the information is subject to a law, or binding scheme, that has the effect of protecting the information in a way that, overall, is at least substantially similar to the way in which the APPs protect the information.
11.1 Hesperia may use or disclose your personal information for the purpose of informing you about our services, upcoming promotions and events, or other opportunities that may interest you by way of direct marketing. We may send you direct marketing communications and information about our services, opportunities, or events that we consider may be of interest to you if you have requested or consented to receive such communications.
11.2 Direct marketing communications may be sent in various forms, including by telephone, post, email, SMS, via social media or any other form of electronic communication, in accordance with applicable marketing laws including the Spam Act 2003 (Cth). You consent to us sending you those direct marketing communications by any of those methods. If you indicate a preference for a method of communication, we will endeavour to use that method whenever practical to do so.
11.3 You may opt-out of receiving marketing communications from us at any time by either following the instructions to ‘unsubscribe’ set out in the relevant communication or contacting us using the details set out below in the “Complaints” section of this policy. In addition, we may also use your personal information or disclose your personal information to third parties for the purposes of advertising, including online behavioural advertising, website personalisation, and to provide targeted or retargeted advertising content to you (including through third party websites).
11.4 If you opt-out of receiving marketing material from us, Hesperia may still contact you in relation to its ongoing relationship with you or as required by law.
12.1 Where Hesperia uses or discloses personal information about an individual for the purposes of direct marketing by Hesperia or facilitating direct marketing by another organisation, the individual may request:
a) that Hesperia no longer provide them with direct marketing communications by way of the process set out in clause 11;
b) that Hesperia does not use or disclose the individual’s personal information for the purpose of facilitating direct marketing by another organisation; or
c) that Hesperia provides the source of the personal information.
12.2 Where Hesperia receives a request from an individual under clause 12.1 Hesperia will:
a) give effect to the request under clause 12.1(a) or 12.1(b) within a reasonable period after the request is made and free of charge; and
b) notify the individual of the source of the information, if the individual requests it, unless it is impracticable or unreasonable to do so.
12.3 Clause 12 does not apply to the extent that the following laws apply:
a) the Do Not Call Register Act 2006;
b) the Spam Act 2003; or
c) any other Act of the Commonwealth of Australia.
Hesperia will not adopt a government related identifier of an individual as its own identifier unless:
a) Hesperia is required or authorised by or under an Australian law or a Court/Tribunal order to do so; or
b) the identifier, Hesperia and the circumstances of the adoption are prescribed by regulations.
14.1 Before using or disclosing a government related identifier of an individual, Hesperia must ensure that such use or disclosure is:
a) reasonably necessary for Hesperia to verify the identity of the individual for the purposes of the organisation’s activities or functions;
b) reasonably necessary for the organisation to fulfil its obligations to an agency or a State or Territory authority
c) required or authorised by or under an Australian law or a Court/Tribunal order;
d) within a permitted general situation (other than the situation referred to in item 4 or 5 of the table in subsection 16A (1) Privacy Act;
e) reasonably necessary for one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
f) the identifier, Hesperia and the circumstances of the adoption are prescribed by regulations.
14.2 Hesperia may collect, hold, use and disclose your tax file number (TFN) and TFN information where authorised by taxation law or other applicable law, including for the purposes of administering investments, verifying your tax status, reporting to the Australian Taxation Office, applying withholding tax requirements and complying with Hesperia’s legal and regulatory obligations.
14.3 This may include disclosure to the Australian Taxation Office, Hesperia’s related bodies corporate, service providers, professional advisers, custodians, administrators, registry providers and other persons where required or authorised by law or reasonably necessary for the purposes described in this Privacy Policy.
14.4 You are not required by law to provide your TFN in connection with an investment, but if you do not provide your TFN or claim an exemption this may have financial impact including requiring Hesperia to withhold tax at the applicable marginal rate or as otherwise required by law.
14.5 Hesperia will not adopt your TFN as its own identifier and will take reasonable steps to protect TFN information from misuse, interference, loss, unauthorised access, modification and disclosure.
14.6 Hesperia will securely destroy or de-identify TFN information when it is no longer required by law to be retained, and is no longer necessary for a purpose it was collected or in accordance with applicable law.
Hesperia will take reasonable steps to ensure that the personal information it collects and the personal information it uses or discloses is, having regard to the purpose of the use or disclosure, accurate, up to date, complete and relevant. Individuals should ensure that all personal information provided to Hesperia is accurate and up to date.
16.1 Hesperia will take reasonable steps to ensure that it protects the personal information it holds about you and keeps it confidential and secure, including by:
a) having robust physical security of our premises, databases and records;
b) taking measures to restrict access to only personnel who need that personal information to provide services to you or otherwise deal with you;
c) having technological measures in place including, where appropriate, anti-virus and anti-malware software, firewalls, secure user authentication mechanisms, encryption of data in transit and at rest, system monitoring and logging, and secure backup and recovery controls; and
d) adopting organisational and operational safeguards to support data security, including documented policies and procedures, staff training and awareness, risk-based oversight of information handling practices, appropriate management of third-party service providers, and procedures to respond to data security incidents.
16.2 Hesperia will take reasonable steps to destroy or de-identify any personal information it holds where:
a) Hesperia no longer needs the personal information for any purpose for which the information may be used or disclosed by Hesperia;
b) the information is not contained in a Commonwealth record; or
c) Hesperia is not required to retain that information under an Australian law, or a Court/Tribunal order.
16.3 Where required by applicable law, we will notify you, and the OAIC and/or other relevant regulatory authorities, of data breaches affecting your personal information.
17.1 Hesperia stores personal information in different ways, including:
a) hard copy on site at Hesperia’s head office; and
b) electronically secure data centres which are owned by either Hesperia or trusted third party external service providers based in Australia and overseas, particularly in the United States and Germany.
17.2 Before disclosing personal information overseas, Hesperia takes reasonable steps, including contractual privacy and security obligations, vendor due diligence and ongoing oversight, to ensure recipients handle personal information consistently with the APPs.
17.3 The third-party external service providers are subject to both Australian and overseas laws that may require the disclosure of your information (in limited circumstances) to government authorities in Australia and overseas.
17.4 The third-party external services do not have access to, nor do they use, your information for any purpose other than providing the services required by Hesperia and its customers and for the service providers to maintain their own services.
17.5 In order to ensure Hesperia protects any personal information it holds from misuse, interference, loss, unauthorised access, modification and disclosure, Hesperia implements the following procedure/system:
a) access to information systems is controlled through identity and access management;
b) employees are bound by internal information securities policies and are required to keep information secure
c) all employees are required to complete training about information security;
d) maintaining physical security over paper and electronic data stores, such as through locks and security systems at our premises;
e) Hesperia maintains computer and network security, for example, we use firewalls (security measures for the Internet) and other security systems such as user identifiers and passwords to control access to our computer systems; and
f) Hesperia regularly monitors and reviews its compliance with internal policies and industry best practice.
17.6 Our websites do not necessarily use encryption or other technologies to ensure the secure transmission of information via the internet. Users of our websites are encouraged to exercise care in sending personal information via the internet.
18.1 Hesperia may employ automated decision-making processes that utilise personal information to assist in making determinations about individuals.
18.2 These automated systems process the following categories of personal information:
a) identification and contact details (such as name, address, email and phone number);
b) transaction and contractual information;
c) application and eligibility information; and
d) engagement and interaction data, and other information relevant to assessing eligibility, priority, access, or status.
18.3 The purpose of utilising the automated systems within Hesperia’s business includes:
a) to assess eligibility for particular products, services or offerings;
b) prioritise or allocate access to products or services;
c) apply or administer incentives or benefits;
d) manage applications and contractual processes; and
e) support compliance with business rules, and improve operational efficiency and consistency in decision-making.
18.4 The automated systems are instructed to use predefined business rules, thresholds, eligibility criteria, status indicators, and data-driven analysis to determine outcomes and decision-making rationale.
18.5 Automated processes may be used to assist in making the following types of decisions:
a) decisions relating to eligibility or ineligibility;
b) approval or refusal of applications;
c) prioritisation or sequencing of access;
d) application or removal of incentives or benefits; and
e) progression or restriction within a process or service.
18.6 These decisions may affect an individual’s access to products or services, contractual rights or opportunities, eligibility for benefits or incentives, timing or priority of engagement, or ability to proceed with certain transactions or processes.
18.7 You have the right to:
a) request human intervention in any automated decision-making process;
b) express your point of view regarding an automated decision;
c) contest any decision made solely through automated processing; and
d) obtain an explanation of how the automated decision was reached.
18.8 We implement the following measures to ensure fairness and accuracy:
a) regular testing and validation of automated systems;
b) human oversight of automated decision-making processes;
c) documentation of decision-making criteria and outcomes; and
d) regular reviews of automated system performance.
18.9 Upon request, we will provide:
a) information about the existence of automated decision-making;
b) meaningful information about the logic involved;
c) the significance and potential consequences of such processing; or
d) options for seeking review of automated decisions.
18.10 We will:
a) regularly review and update our automated decision-making systems;
b) notify individuals of significant changes to automated processes;
c) maintain records of system modifications and improvements; and
d) ensure ongoing compliance with privacy legislation.
19.1 You are entitled to access your personal information held by Hesperia on request. To request access to your personal information please contact our privacy officer (using the contact details set out below.
19.2 Hesperia must give an individual access to the personal information it holds about the individual if so requested by the individual.
19.3 Hesperia must respond to any request for access to personal information within a reasonable period after the request is made.
19.4 Hesperia must give access to the information in the manner requested by the individual, if it is reasonable and practicable to do so and must take such steps as are reasonable in the circumstances to give access in a way that meets the needs of Hesperia and the individual.
19.5 Hesperia must not charge an individual for making a request and must not impose excessive charges for the individual to access their personal information.
Hesperia is not required to give an individual access to their personal information if:
a) Hesperia reasonably believes that giving access would pose a serious threat to the life, health or safety of any individual, or to public health or public safety;
b) giving access would have an unreasonable impact on the privacy of other individuals;
c) the request for access if frivolous or vexatious;
d) the information relates to existing or anticipated legal proceedings between Hesperia and the individual, and would not be accessible by the process of discovery in those proceedings;
e) giving access would reveal intentions of Hesperia in relation to negotiations with the individual in such a way as to prejudice those negotiations;
f) giving access would be unlawful;
g) denying access is required or authorised by or under an Australian law or a Court/Tribunal order;
h) Hesperia has reason that unlawful activity, or misconduct of a serious nature, that relates to our functions or activities has been, or may be engaged in and giving access would be likely to prejudice the taking of appropriate action in relation to the matter;
i) giving access would be likely to prejudice one or more enforcement related activities conducted by, or on behalf of, an enforcement body; or
j) giving access would reveal evaluative information generated within Hesperia in connection with a commercially sensitive decision-making process.
21.1 If Hesperia refuses to give access in accordance with clause 20 or to give access in the manner requested by the individual, Hesperia will give the individual a written notice that sets out:
a) the reasons for the refusal except to the extent that, having regard to the grounds for the refusal, it would be unreasonable to do so;
b) the mechanisms available to complain about the refusal; and
c) any other matter prescribed by the regulations.
21.2 Where Hesperia refuses to give access under clause 20(j) Hesperia may include an explanation of the commercially sensitive decision in its written notice of the reasons for denial.
22.1 If you wish to correct any personal information held about you by Hesperia, you can contact our privacy officer (using the contact details below).
22.2 Hesperia must take reasonable steps to correct all personal information, having regard to the purpose for which the information is held where:
a) Hesperia is satisfied the information is inaccurate, out of date, incomplete, irrelevant or misleading
b) the individual requests Hesperia corrects the information.
22.3 You should let us know if you notice errors or discrepancies in information we hold about you and letting us know if your personal details change.
22.4 Where Hesperia corrects personal information about an individual that Hesperia previously disclosed to another APP entity and the individual requests Hesperia to notify the other APP entity of the correction, Hesperia must take reasonable steps to give that notification, unless it is impracticable or unlawful to do so.
Hesperia may decline your request to access or correct your personal information in certain circumstances in accordance with the APPs. If Hesperia refuses to correct personal information as requested by the individual, Hesperia will give the individual a written notice that sets out:
a) the reasons for the refusal except to the extent that it would be unreasonable to do so;
b) the mechanisms available to complain about the refusal; and
c) any other matter prescribed by the regulations.
If:
a) Hesperia refuses to correct personal information as requested by the individual; and
b) the individual requests that Hesperia associate a statement noting that the information is inaccurate, out of date, incomplete, irrelevant or misleading, with the individual’s information,
then Hesperia must take such steps as are reasonable in the circumstances to associate the statement (as described in clause (b)with the individual’s personal information. The statement should be associated with the information in such a way that will make the statement apparent to users of the information.
Hesperia must:
a) respond to requests under clause 24 within a reasonable period after the request is made; and
b) must not charge the individual for the making of the request, for correcting the personal information or for associating the statement with the personal information.
26.1 Hesperia offers an internal complaint resolution scheme to all persons from which we collect, store and use personal information. Should you have a privacy complaint, you can contact Hesperia’s Privacy Compliance Officer to discuss your concerns using the following contact details:
a) Email: privacy@hesperia.com.au
b) Post:
Privacy Compliance Officer
Hesperia
Level 3, 338 Barker Road
SUBIACO WA 6008
26.2 If your complaint relates to a financial service or product provided by Hesperia Funds Management Pty Ltd, we may refer the complaint to Hesperia Funds Management Pty Ltd’s internal dispute resolution function for handling in accordance with clause 26.10.
26.3 To assist Hesperia in helping customers, Hesperia asks customers to follow a simple two- step process:
a) gather all supporting documents relating to the complaint; and
b) contact Hesperia to review your situation and if possible, resolve your complaint immediately.
26.4 Hesperia will rectify any breach if the complaint is justified and takes necessary steps to resolve the issue.
26.5 Subject to clauses 26.5 and 26.10, we will generally respond to your complaint within a week.
26.6 Subject to clauses 26.10, if your complaint requires more detailed consideration or investigation, we will acknowledge receipt of your complaint within a week and endeavor to complete our investigation into your complaint promptly. We may ask you to provide further information about your complaint and the outcome you are seeking. We will then typically gather relevant facts, locate and review relevant documents and speak with individuals involved.
26.7 In certain situations, to deal with a complaint it may be necessary to consult with third parties. However, any disclosure of personal information to third parties will be provided with the customer’s authority and consent.
26.8 Subject to clauses 26.10, the complaint will be investigated, and the decision sent to the customer usually within thirty (30) days unless the customer has agreed to a longer time. If a complaint cannot be resolved within the agreed time frame, if the matter is more complex, our investigation takes longer or a decision could not be made within thirty (30) days of receipt, a notification will be sent to the customer setting out the reasons and specifying a new date when the customer can expect a decision or resolution.
26.9 If the customer is not satisfied with Hesperia’s internal privacy practices or the outcome in respect to the complaint, or you consider that Hesperia may have breached the APPs or the Privacy Act, you may approach the OAIC with your complaint by using the details on their website located here: https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us#section-how-to-lodge-a-complaint-with-us
26.10 If your complaint relates to a financial service or product provided by Hesperia Funds Management Pty Ltd, Hesperia Funds Management Pty Ltd will handle the complaint in accordance with its internal dispute resolution procedures and applicable financial services laws and regulatory guidance.
27.1 Under the Privacy Amendment (Notifiable Data Breaches) Act 2017 (“Privacy Amendment Act”) Hesperia is required to notify the Office of the Australian Information Commissioner (“OAIC”) in relation to all eligible data breaches.
27.2 Hesperia must notify the OAIC by lodging a Notifiable Data Breach Form as soon as practicable.
27.3 Under the Privacy Amendment Act, Hesperia must also promptly inform clients whose personal information has been compromised by the eligible data breach that a breach of their personal information has occurred.
27.4 Hesperia may also disclose, use or collect personal information as required or permitted by any applicable declaration pursuant to Part IIIC Division 5 of the Privacy Act.
28.1 The AML/CTF Act is aimed at addressing money laundering in Australia and the threat to national security caused by terrorism.
28.2 The AML/CTF Act requires Hesperia to collect and verify certain know-your-customer information about investors and other relevant persons, and to identify and assess money laundering, terrorism financing and proliferation financing risks. This may include collecting and verifying information about your identity, the nature and purpose of your investment or relationship with Hesperia, your source of funds, source of wealth, occupation or employment details, tax residency, beneficial ownership or control, and any other information Hesperia reasonably considers necessary or appropriate to comply with its legal and regulatory obligations. Hesperia may verify information using documents, data or other information from reliable and independent sources. This may include identity documents, electronic verification services, government or commercial databases, information from third-party service providers, or other information or evidence that Hesperia considers appropriate having regard to the relevant legal requirements and the assessed money laundering, terrorism financing and proliferation financing risk.
28.3 Details of what identification information and documentation an individual is required to provide are set out in transactional based forms. Hesperia may also contact you to follow up and clarify certain information. Under this legislation, Hesperia is also required to monitor transactions to identify any suspicious activity within any of our investment products.
28.4 As required under the AML/CTF Act, Hesperia may, in its absolute discretion, without notice to you, disclose or otherwise report details of any transaction or activity, or proposed transaction or activity (including any personal information) to AUSTRAC, law enforcement bodies or other the relevant regulators or reporting body.
29.1 You may visit our websites without identifying yourself. If you identify yourself (for example, by providing your contact details in an enquiry), any personal information you provide to Hesperia will be managed in accordance with this Policy.
29.2 Hesperia may use cookies on its website from time to time. Cookies are text files placed in your computer’s browser to store your preferences. Cookies, by themselves, do not tell Hesperia an individual’s email address or other personally identifiable information.
29.3 If and when an individual chooses to provide Hesperia’s website with personal information, this information may be linked to the data stored in the cookie. The information stored by Hesperia cookies may be used to offer our products and services directly to you and distinguish you from other users in order to better serve you when you revisit our website.
29.4 You can use the settings in your browser to control how your browser deals with cookies. However, in doing so, you may be unable to access certain pages or content on our website.
29.5 Hesperia’s websites may contain links to third-party websites. Hesperia is not responsible for the content or privacy practices of websites that are linked to our website.
29.6 Our website uses Google Analytics to better understand visitor traffic, so we can improve our services. Although this data is mostly anonymous, it is possible that under certain circumstances it may connect it to you.
30.1 Hesperia uses Google reCAPTCHA to help protect our forms and services from spam and abuse. reCAPTCHA is a service provided by Google LLC (“Google”), which uses automated analysis of user behaviour (including cookies, IP address, device and browser information, mouse movements and form interaction data) to distinguish humans from robots.
30.2 Data collected by reCAPTCHA is sent to and processed by Google for security purposes in accordance with Google’s Privacy Policy and Terms of Service which can be accessed via the following links:
a) https://policies.google.com/privacy
b) https://policies.google.com/terms
30.3 If you use or access our website or any other Hesperia online platforms, you accept such processing of your data.
30.4 Hesperia is not liable for and does not control how Google uses your information and you may review Google’s policies by visiting their website.
30.5 Our website and this policy contains hyperlinks to other websites operated by third parties. You accept that Hesperia has no control over, and is not responsible for, any material contained on any third-party websites. You may be required to comply with all requirements of any third party over the conditions of use of that third party’s website.
31.1 Breaches of this Policy may lead to disciplinary action being taken against the relevant party, including dismissal in serious cases and may also result in prosecution under the law where that act is illegal. This may include re-assessment of bonus qualification, termination of employment and/or fines (in accordance with the Privacy Act).
31.2 Staff are trained internally on compliance and their regulatory obligation to Hesperia. They are encouraged to respond appropriately to and report all breaches of the law and other incidents of non-compliance, including Hesperia’s policies, and seek guidance if they are unsure.
31.3 Staff must report breaches of this Policy directly to the Privacy Compliance Officer.
32.1 The Privacy Compliance Officer will retain the completed forms for seven (7) years in accordance with Hesperia’s document retention policy. The completed forms are retained for future reference and review.
32.2 As part of their training, all staff are made aware of the need to practice thorough and up to date record keeping, not only as a way of meeting Hesperia’s compliance obligations, but as a way of minimising risk.
All staff are required to comply with and follow all requirements set out in this Policy and all associated procedures. Disciplinary action may be taken in instances of an intentional breach of any aspect of this Policy, up to and including:
Staff are trained internally on compliance and their regulatory obligation to Hesperia. They are encouraged to respond appropriately to and report all breaches of the law and other incidents of non-compliance, including Hesperia’s policies, and seek guidance if they are unsure. Staff must report breaches of this Policy directly to the Privacy Compliance Officer.
Unless exceptional circumstances require an interim review, this Policy will be reviewed annually to ensure its relevance and effectiveness. The review will consider organisational changes, operational requirements and applicable legislative or regulatory updates. Amendments will be made as necessary to maintain compliance and alignment with company objectives.
APP Entity: an agency or organisation as defined in Section 6 of the Privacy Act.
Australian law:
Court/tribunal order: an order, direction or other instrument made by:
and includes an order, direction or other instrument that is of an interim or interlocutory nature.
De-identified personal information: Information is de-identified if the information is no longer about an identifiable individual or an individual who is reasonably identifiable.
Eligible Data Breach: occurs when
Identifier of an individual: a number, letter or symbol, or a combination of any or all of those things, that is used to identify the individual or to verify the identity of the individual, but does not include:
Permitted general situation: See s16A of the Privacy Act.
Permitted health situation: See s16B of the Privacy Act.
Personal information: information or an opinion about an identified individual, or an individual who is reasonably identifiable:
Privacy Compliance Officer: the person nominated by Hesperia to act as the compliance officer for Hesperia.
Sensitive Information: