Legal

Privacy Policy

Athena Accounting & Advisory Services Pty Ltd
ABN 28 698 967 225

Effective date: 24th June 2026

Athena Accounting & Advisory Services Pty Ltd (ABN 28 698 967 225) ("Athena"), is committed to protecting your privacy and handling your personal information in an open and transparent way.

This Privacy Policy explains how we collect, use, store, disclose and protect your personal information, and how you can access or correct it. It applies to information we collect through our website (athenaaccounting.com.au), in the course of providing our accounting, taxation and advisory services, and through any other dealings you have with us.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), the Privacy (Tax File Number) Rule 2015, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), and the professional and confidentiality obligations that apply to us as Chartered Accountants and a Registered Tax Agent.

Section 1

What is personal information?

"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable. Some personal information we collect is "sensitive information" (for example, information that may be revealed through identity verification), which is given additional protection under the Privacy Act.

Section 2

The personal information we collect

The information we collect depends on our relationship with you and the services we provide. It may include:

  • Identity and contact details — name, date of birth, residential and postal address, email address, and phone numbers.
  • Tax and financial information — Tax File Numbers (TFNs), Australian Business Numbers, income, expenses, assets, liabilities, bank account details, superannuation details, and other information needed to prepare returns, financial statements and advice.
  • Identity verification information — copies of identity documents (such as a driver licence or passport) and related details collected to verify your identity, including for our obligations under anti-money laundering and counter-terrorism financing law.
  • Information about associated parties — where relevant to an engagement, information about your family members, business partners, beneficiaries, directors, shareholders or employees.
  • Engagement and correspondence records — notes, instructions, advice, file records and communications between us.
  • Website and technical information — when you use our website, we may collect technical data such as your IP address, browser type, device information, and pages visited, including through cookies and analytics tools (see section 8).
Section 3

How we collect personal information

Wherever reasonable and practicable, we collect personal information directly from you — for example, through our website, by email or phone, in meetings, or in the documents you provide to us.

We may also collect personal information from third parties where you would reasonably expect us to, or where you have consented, including from:

  • the Australian Taxation Office (ATO) and other government agencies;
  • your previous accountant or adviser (including, on transition of an existing client file to our practice);
  • your bank, financial institutions, financial planners, lenders or insurers;
  • accounting and practice software you authorise us to access (such as Xero); and
  • publicly available sources such as ASIC and other registers.

If we receive unsolicited personal information that we are not permitted to collect, we will deal with it in accordance with the APPs.

Section 4

Why we collect, hold and use your personal information

We collect, hold and use personal information so that we can:

  • provide accounting, taxation, business advisory and related services to you;
  • prepare and lodge tax returns, business activity statements, financial statements and other documents, and liaise with the ATO and other authorities on your behalf;
  • verify your identity and meet our obligations under anti-money laundering and counter-terrorism financing law (see section 6);
  • manage and administer our engagement with you, including billing and account management;
  • respond to your enquiries and communicate with you about your affairs;
  • comply with our legal, professional and regulatory obligations; and
  • where permitted, send you information about our services and updates we think may be relevant to you (see section 10).

We will only use your personal information for the purpose for which it was collected, a directly related purpose you would reasonably expect, or another purpose you have consented to or that is required or authorised by law.

Section 5

Tax File Number information

As a Registered Tax Agent, we collect and handle TFNs. We treat TFN information as highly sensitive and handle it strictly in accordance with the Privacy (Tax File Number) Rule 2015 and the Privacy Act.

We only use and disclose TFN information for permitted tax-related purposes, we take reasonable steps to protect it from misuse, loss and unauthorised access, and we do not use a TFN to identify you or as a general record-keeping reference. You are not legally required to provide your TFN, but without it we may be unable to complete certain lodgements or you may be subject to higher rates of tax withholding.

Section 6

Anti-money laundering and counter-terrorism financing

We collect and retain identity verification information to meet our obligations under anti-money laundering and counter-terrorism financing law. We may be required by law to report certain matters to AUSTRAC (the Australian Transaction Reports and Analysis Centre), and where we are legally obliged to make such a report we may be prohibited from telling you that we have done so.

Section 7

Who we disclose your personal information to

We treat your information as confidential and do not sell it. We may disclose your personal information to:

  • the ATO and other government agencies and regulators (such as ASIC, AUSTRAC and the Tax Practitioners Board) where required or authorised;
  • third-party service providers who help us deliver our services, including Xero (our cloud-based accounting software), and our practice management, document storage, IT and cyber-security providers and professional advisers;
  • other parties you authorise us to deal with, such as your bank, lawyer, financial planner, auditor or lender;
  • a purchaser or successor of our practice, in connection with the sale or transfer of our business (subject to appropriate confidentiality arrangements); and
  • any other person where you have consented, or where disclosure is required or authorised by law.

We require our service providers to handle personal information consistently with the Privacy Act and to use it only for the purposes for which we engage them.

Section 8

Cookies and our website

Our website uses cookies and similar technologies to help it function, to remember your preferences, and to understand how visitors use the site (for example, through web analytics tools). This may involve collecting information such as your IP address, browser type and the pages you visit.

You can set your browser to refuse cookies or to alert you when cookies are being used, although some parts of the website may not work properly as a result. Our website may also contain links to third-party websites; we are not responsible for the privacy practices of those sites and encourage you to review their policies.

Section 9

Overseas disclosure

We use Xero, cloud-based accounting software, to maintain client ledgers and records, along with other cloud-based service providers to deliver our services. These providers may store or process personal information on servers located outside Australia, including in locations such as New Zealand and the United States. The service providers we engage are set out in our engagement Terms. Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles.

Section 10

Direct marketing

From time to time we may use your contact details to send you information about our services, technical updates or newsletters we think may be useful to you. Every marketing communication will include a simple way to opt out, and you can ask us at any time to stop sending you marketing material by contacting us using the details in section 16. We do not use sensitive information for direct marketing without your consent.

Section 11

How we store and protect your information

We hold personal information in both electronic and (where applicable) physical form. We take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure, including through measures such as access controls, multi-factor authentication, encryption, secure storage, staff confidentiality obligations and the use of reputable software providers.

Section 12

Data breaches

We are subject to the Notifiable Data Breaches scheme under the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to any individual whose information we hold, we will assess the breach and, where required, notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.

Section 13

How long we keep your information

We keep personal information only for as long as it is needed for the purposes set out in this policy, or for as long as we are required to retain it by law or our professional obligations (for example, taxation, corporations and anti-money laundering record-keeping requirements, which generally require records to be kept for at least five to seven years). When information is no longer needed, we take reasonable steps to destroy it or de-identify it securely.

Section 14

Accessing and correcting your information

You have the right to ask us for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact us using the details in section 16. We will respond within a reasonable period.

We will generally provide access, but there are some circumstances in which the law permits us to refuse — for example, where giving access would be unlawful, where it relates to legal proceedings, or where another exception under the Privacy Act applies. If we refuse access or a correction, we will explain why in writing and tell you how you can complain.