Privacy Policy
Last updated: 26 August 2026
1. About this Privacy Policy
Anchorpoint Business Advisory (Anchorpoint, we, us or our) is committed to protecting privacy and handling personal information responsibly.
We manage personal information in accordance with applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), where they apply.
Whether or not those requirements apply to a particular activity, we aim to handle personal information consistently with the APPs as a matter of good practice.
This Privacy Policy explains the types of personal information we may collect, how we collect, hold, use and disclose it, how we protect it, how long we retain it, and how you can contact our Privacy Officer or make a privacy complaint.
2. What personal information we collect
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Depending on our relationship with you and the services we are providing, we may collect:
your name and contact details, including email address and telephone number;
your business, employer, position or role;
professional background, experience, skills or qualifications;
information provided through enquiries, correspondence, meetings or interviews;
responses to surveys, questionnaires, workshops or assessments;
information about roles, responsibilities, skills, capability, development or workplace experience;
information contained in business records provided to us as part of a client engagement;
billing, invoicing and payment information;
feedback about our services;
information provided when booking a meeting, registering for an event, subscribing to communications or downloading a resource; and
technical information associated with use of our website, such as IP address, browser, device and website usage information.
3. Sensitive information
Sensitive information is a category of personal information that may include health information, racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of a trade union or professional association, criminal record and other information defined as sensitive information under applicable privacy law.
We do not generally seek to collect sensitive information unless it is reasonably necessary for the work we have been engaged to undertake and you have consented where required, or collection is otherwise permitted or required by law.
Where we hold sensitive information, we will only use or disclose it for the purpose for which it was collected, for a directly related purpose where permitted, with consent, or where required or authorised by law.
4. How we collect personal information
We may collect personal information:
directly from you during meetings, interviews, workshops, telephone calls, emails, SMS or other correspondence;
through our website at www.apbusinessadvisory.com;
through forms, surveys, questionnaires, assessments or booking tools;
through social media or professional networking platforms;
from your employer, organisation or another client where relevant to an engagement;
from referrals and introductions;
from publicly available sources, including websites, professional profiles, media and publications; and
from professional advisers, service providers or other third parties where permitted.
When appropriate, we will explain why information is being collected and how we plan to use it.
5. Information provided to us by clients
As a business adviser, Anchorpoint may receive personal information about a client's employees, contractors, customers, suppliers or other individuals.
This may occur through business reviews, employee surveys, skills and capability assessments, organisational reviews, workforce planning, workshops, interviews, performance-related work or other advisory activities.
Where a client provides personal information about another individual, the client is responsible for ensuring it has authority to provide that information to us and has completed any notification, consultation or consent requirements that apply.
Unless otherwise agreed in writing, we will handle personal information provided by or on behalf of a client only to deliver the agreed services, meet our legal and professional obligations, or for another purpose permitted or required by law.
We will not use that information for our own unrelated marketing or commercial purposes.
We may provide findings, reports and recommendations to our client. Where practicable, we will use aggregated or de-identified information in reports, particularly where information has been collected through interviews, surveys, workshops, assessments or workforce reviews.
Where individual responses are used in reporting, we will take reasonable steps to limit identification. We will only identify an individual where this is necessary for the agreed services, permitted or required by law, or the individual has been informed that their identity may be disclosed in connection with the engagement.
At the end of an engagement, we will retain, return, destroy or de-identify client-provided information in accordance with the relevant agreement, our legal obligations and our retention practices.
6. Why we collect, use and disclose personal information
We may collect, hold, use and disclose personal information to:
respond to enquiries and manage prospective and existing client relationships;
provide business advisory and consulting services;
understand a client's business, team and operating environment;
conduct interviews, surveys, workshops, assessments and reviews;
develop recommendations, reports, roadmaps, scorecards, process maps and other client deliverables;
communicate with clients and relevant stakeholders;
manage appointments, contracts, service agreements, invoicing and payments;
manage suppliers, contractors and professional advisers;
improve our services and obtain feedback;
send relevant marketing or business communications where permitted;
meet legal, regulatory, insurance, accounting and record-keeping requirements; and
protect our legal rights and legitimate business interests.
Where practicable, we will use aggregated or de-identified information for analysis, reporting, presentations and case studies.
We will not identify an individual or client in a case study, testimonial or promotional material without their prior consent.
7. Who we may disclose personal information to
We do not sell personal information to third parties.
We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy, including to:
employees, contractors, associates or specialist advisers engaged by Anchorpoint to assist with an engagement, subject to confidentiality and privacy obligations;
accountants, lawyers, insurers and other professional advisers;
technology, cloud storage, document management, communication, survey, scheduling, accounting, payment, website hosting, analytics, customer relationship management and other service providers that support our business or the delivery of our services;
a client, where the information relates to services being provided to that client and disclosure is consistent with the agreed engagement scope;
government agencies, regulators, courts or law enforcement bodies where required or authorised by law; or
another party where you have consented to the disclosure.
We seek to limit disclosures to the information reasonably necessary for the relevant purpose.
We require our service providers and subcontractors to handle personal information only for authorised purposes and to apply reasonable security safeguards appropriate to the services they provide.
8. Technology providers and overseas handling
Anchorpoint uses third-party technology and cloud-based services to operate our business and deliver services.
These services may include email and productivity tools, cloud storage, document management, video conferencing, survey platforms, website hosting, analytics, booking tools, accounting and payment systems, customer relationship management systems and AI-enabled productivity tools.
Our use of AI-enabled tools is also described in Section 9.
Some providers may store, process, support or back up personal information outside Australia. Depending on the service providers we use and their infrastructure, personal information may be handled in Australia, the United States and other countries in which those providers or their subcontractors operate.
Before disclosing personal information to an overseas recipient, we will take reasonable steps appropriate to the circumstances to ensure that the recipient handles the information consistently with applicable privacy obligations.
These steps may include supplier due diligence, contractual protections, access controls, security configuration and assessment of the privacy and security measures used by service providers.
We maintain records of the principal technology providers used in our business. You may contact our Privacy Officer if you would like further information about whether personal information we hold about you is likely to be handled outside Australia.
9. AI-enabled tools
We may use AI-enabled tools to support research, administration, document drafting, analysis and service delivery.
We will take reasonable steps to ensure that our use of these tools is consistent with our privacy, confidentiality and contractual obligations.
We will not enter identifiable client-confidential information, employee survey responses, personnel records, health information or other sensitive information into publicly available AI tools unless this has been expressly approved under the relevant client engagement and we have implemented appropriate privacy, security and confidentiality safeguards.
Where AI-enabled tools are used in connection with client services, we may use de-identified, aggregated or fictionalised information where practicable.
10. Website, cookies and third-party links
When you visit our website, certain technical information may be collected automatically, including IP address, browser type, device information, pages viewed, date and time of visits, referring website and general website usage information.
Our website and service providers may use cookies and similar technologies to operate the website, understand website use, improve functionality and measure performance.
These technologies may collect information such as device type, browser type, IP address, pages visited, approximate location, referring website and interactions with our website or communications.
You can manage or restrict cookies through your browser settings. Where required by applicable law, we will provide an appropriate cookie notice, consent mechanism or other privacy notice when you visit our website.
Restricting cookies may affect some website functionality.
Our website or communications may contain links to third-party websites or services. Anchorpoint Business Advisory is not responsible for the privacy practices, content or availability of those third parties.
We encourage you to review their privacy policies before providing personal information.
11. Marketing communications
We may send you information about Anchorpoint services, resources, events, insights or other business updates by email, SMS, telephone, post, social media or professional networking platforms where you have consented or where we are otherwise permitted to do so by law.
You may opt out of receiving marketing communications at any time by using the unsubscribe facility in an electronic communication, adjusting relevant platform settings, or contacting our Privacy Officer at privacy@apbusinessadvisory.com.
We will process opt-out requests as soon as reasonably practicable.
Opting out of marketing communications will not prevent us from contacting you about an existing engagement, enquiry, appointment, contract, invoice, service issue or other non-marketing matter.
12. Security of personal information
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
Depending on the nature and sensitivity of the information, our controls may include:
multi-factor authentication for business systems where available;
password-protected devices, systems and accounts;
role-based or need-to-know access restrictions;
cloud storage and technology providers selected with regard to their security, privacy and reliability measures;
encryption or secure transmission methods where appropriate;
confidentiality obligations for employees, contractors and specialist advisers;
secure document-sharing, storage, disposal and destruction practices;
regular software, device and account-security updates; and
processes to identify, contain, assess and respond to suspected privacy or security incidents.
No method of electronic transmission or storage is completely secure, so we cannot guarantee absolute security.
13. Retention and destruction
We retain personal information only for as long as it is reasonably necessary to provide our services, manage an engagement, respond to enquiries, meet legal, accounting, taxation, insurance, professional-indemnity, contractual or record-keeping obligations, resolve disputes or enforce our agreements.
Retention periods may vary depending on the type of information, the nature of the engagement and applicable obligations.
For example, we may retain engagement records, working papers, correspondence and financial records after an engagement has ended where this is reasonably required for professional, legal, insurance or accounting purposes.
When personal information is no longer reasonably required, we will take reasonable steps to securely destroy, delete or de-identify it, unless we are required or permitted to retain it.
If you would like information about the retention period that may apply to your personal information, please contact our Privacy Officer.
14. Access and correction
You may request access to personal information we hold about you, or ask us to correct personal information that you believe is inaccurate, incomplete, out of date, irrelevant or misleading.
To make an access or correction request, please contact our Privacy Officer using the contact details in Section 16.
We may ask you to verify your identity before providing access or making a correction.
There may be circumstances in which we cannot provide access to some or all requested information, including where providing access would unreasonably affect the privacy of others, reveal confidential commercial information, prejudice legal proceedings, be unlawful, or otherwise be permitted or required by law.
If we refuse access or correction, we will provide written reasons where required and explain available complaint options.
We aim to acknowledge an access or correction request within a reasonable time and respond within 30 days. If we need additional time, we will let you know why and when we expect to respond.
We do not charge a fee for making an access request. If responding to a request would involve substantial administrative work, we may discuss any reasonable costs with you before proceeding, where permitted.
15. Data breaches
If we become aware of suspected unauthorised access to, unauthorised disclosure of, or loss of personal information, we will promptly assess the circumstances and take reasonable steps to contain and manage the incident.
Our response may include securing systems or records, revoking access, recovering information, investigating the cause and scope of the incident, assessing the risk of serious harm, notifying affected clients where relevant, and taking steps to reduce the risk of recurrence.
Where we determine that an eligible data breach has occurred and notification is required by applicable law, we will notify affected individuals and the Office of the Australian Information Commissioner as soon as practicable.
We maintain internal procedures for managing suspected data breaches and privacy incidents.
16. Privacy complaints and enquiries
If you have a question, concern or complaint about how we have handled your personal information, please contact:
Privacy Officer
Anchorpoint Business Advisory
Email: privacy@apbusinessadvisory.com
Website: www.apbusinessadvisory.com
We will acknowledge your privacy complaint within a reasonable time, investigate it fairly and take reasonable steps to resolve it.
We aim to provide a substantive response within 30 days. If we cannot do so, we will let you know why and provide an expected response date.
If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner.
We encourage you to contact us first so that we have an opportunity to investigate and seek to resolve your concern.
17. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our business, technology, services or legal obligations.
The current version will be published on our website.
Last updated: 26 August 2026