Privacy Policy
1. What information do we collect?
The kind of Personal Information that we collect from you will depend on how you use the website. The Personal Information which we collect and hold about you may include:
2. Types of information
The Privacy Act 1998 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.
Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:
(a) whether the information or opinion is true or not; and
(b) (ii) whether the information or opinion is recorded in a material form or not.
If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as “Personal Information” and will not be subject to this privacy policy.
Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.
Sensitive Information will be used by us only:
(a) for the primary purpose for which it was obtained;
(b) for a secondary purpose that is directly related to the primary purpose; and
(c) with your consent or where required or authorised by law.
(a) We may collect Personal Information from you whenever you input such information into the Website, related app or provide it to Us in any other way.
(b) We use cookies and implement robust security measures to protect your data. All data collected through cookies is encrypted using industry-standard AES-256 encryption and transmitted via secure HTTPS protocols. Our security measures include:
(c) We use different types of cookies including essential cookies for Website functionality,
analytical cookies to improve user experience, and marketing cookies that may be set by third parties. These cookies are retained for up to 90 days and can be managed through your browser settings. Third-party cookies are subject to their respective privacy policies, which we encourage you to review.
(d) We only collect Sensitive Information in specific circumstances where:
4. Purpose of collection
(a) We collect Personal Information for the following specific purposes and retention periods:
We only collect and use Personal Information that is reasonably necessary for these purposes. All retention periods are regularly reviewed and data is securely deleted when no longer required.
(b) We only disclose Personal Information to service providers who have contractually agreed to:
(c) We will only send you direct marketing communications after receiving your explicit consent through our opt-in process. During account registration or loan application, you will be given clear options to choose whether you wish to receive marketing communications. You can modify these choices at any time. We do not use sensitive Personal Information in direct marketing activity. All marketing communications will include an unsubscribe option and clear information about how to manage your preferences.
(d) You can manage your marketing preferences through your account settings or by contacting our Privacy Officer at [email protected]. Marketing communications may include:
5. Security, Access and correction
(a) We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure. When we no longer require your Personal Information for the purpose for which we obtained it, we will take reasonable steps to destroy and anonymise or de-identify it. Most of the Personal Information that is stored in our client files and records will be kept for a maximum of 7 years to fulfill our record keeping obligations.
We implement industry-standard security measures including encryption, access controls, and secure data centers to protect your Personal Information. When deletion is required, we use secure erasure methods including digital shredding and physical destruction of storage media. For digital records, we employ a 90-day retention period for active data and 2-year retention period for archived data, after which automated purge protocols permanently remove the information using government-approved secure deletion standards.
(b) The Australian Privacy Principles:
(i) permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
(ii) allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
(c) Where you would like to obtain such access, please contact us in writing on the contact details set out at the bottom of this privacy policy.
6. Complaint procedure
If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us as on the contact details set out at the bottom of this policy. All complaints will be considered by the Compliance Officer and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.
7. Documentation and Response Timeline
We will acknowledge receipt of your complaint within 2 business days and provide you with a reference number. Our privacy team will investigate your complaint and maintain detailed records of all communications and findings. We aim to resolve all privacy complaints within 30 business days. If additional time is required, we will notify you in writing. All complaint documentation will be retained for 24 months following resolution. If the matter requires escalation, our Privacy Officer will personally review your case within 5 business days of the escalation request.
8. Overseas transfer
Your Personal Information may be transferred to recipients located in the European Economic Area (EEA) and the United Kingdom. These transfers are governed by Standard Contractual Clauses (SCCs) approved by the European Commission and the UK Information Commissioner's Office. Recipients must comply with the General Data Protection Regulation (GDPR) and equivalent UK data protection laws, which provide robust protection for Personal Information.
These jurisdictions maintain data protection standards that meet or exceed the Australian Privacy Principles, including:
9. How to contact us about privacy
If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: [email protected].
PropertyLoan.info is not a credit provider. We connect users with licensed mortgage brokers and may receive referral commissions. All information is handled per our Privacy Policy and the Australian Privacy Principles.