Stone Leaf Capital
Return to the firm

Privacy

Privacy Policy

Stone Leaf Capital Securities Limited (ACN 667 580 734) is committed to protecting the personal information it holds. This policy explains the kinds of personal information we collect, how we collect and hold it, the purposes for which we use and disclose it, and how you can access or correct your information or make a complaint. It is designed to meet our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

Issued by

Stone Leaf Capital Securities Limited
ACN 667 580 734

Effective

23 March 2026 · Version 2

Purpose

Purpose and scope

As part of maintaining the highest levels of professional conduct, Stone Leaf Capital Securities Limited ACN 667 580 734 (the Company) has adopted this Privacy Policy to manage personal information in a professional and compliant manner. In this policy, the Business means the Company and any related bodies corporate that may exist from time to time.

This policy assists the Business in complying with the Privacy Act 1988 (Cth) (the Act) and the Australian Privacy Principles in protecting the personal information the Business holds about its clients. It applies to all directors, officers and employees of the Business and remains in force on an ongoing basis. Where the Business relies on a third party for compliance with this policy, it will ensure that reliance is permissible under, and complies with, applicable law and is consistent with this policy.

Collection

What personal information we collect

The Business will not collect personal information (other than sensitive information) unless the information is reasonably necessary for one or more of its functions or activities. The information we collect may include:

  • name;
  • date of birth;
  • postal or email address;
  • phone numbers; or
  • other information the Business considers necessary to its functions and activities.

Sensitive information — which includes information about your health, racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, membership of a professional or trade association or a trade union, sexual orientation or practices, criminal record, and genetic or biometric information — is only collected where you consent and the information is reasonably necessary for our functions or activities, where the collection is required or authorised by law or a court or tribunal order, or where a permitted general or health situation applies.

How we collect

How we collect personal information

The Business collects personal information only by lawful and fair means, and collects it from you directly wherever it is reasonable and practicable to do so (unless you have asked us to deal with someone else on your behalf). We will generally collect personal information from you when:

  • you complete one of our application forms;
  • you provide information to our representatives by telephone or email; or
  • you provide information to us through our website.

Purpose of use

Why we collect, hold and use it

If you are acquiring, or have acquired, a product or service from the Business, your personal information will be collected and held for the purposes of:

  • checking whether you are eligible for our services;
  • providing you with our services;
  • managing and administering our services;
  • protecting against fraud, crime or other activity that may cause harm in relation to our services;
  • complying with legislative and regulatory requirements in any jurisdiction; and
  • assisting us in the running of our business.

We may also collect personal information to let you know about products or services that might better serve your needs, or other opportunities in which you may be interested.

Quality & security

Quality and security of your information

The Business takes reasonable steps to ensure that the personal information it collects, and the information it uses or discloses, is — having regard to the purpose of the use or disclosure — accurate, up to date, complete and relevant.

We protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure.

We store personal information in hard or electronic copy at our head office, and in electronically secure data centres that are located in Australia and owned by external service providers. To protect your information we, among other things:

  • control access to our information systems through identity and access management;
  • require employees to keep information secure under internal information-security policies;
  • require all employees to complete information-security training; and
  • regularly monitor and review our compliance with internal policies and industry best practice.

We take reasonable steps to destroy or de-identify personal information when we no longer need it for any purpose for which it may be used or disclosed, the information is not contained in a Commonwealth record, and we are not required to retain it under Australian law, our own policies (including our Document Retention Policy) or a court or tribunal order.

Use & disclosure

How we use and disclose information

Where the Business holds personal information collected for a particular purpose (the primary purpose), it will not use or disclose the information for another purpose (a secondary purpose) unless: you have consented; you would reasonably expect us to use or disclose it for the secondary purpose, and that purpose is related (or, for sensitive information, directly related) to the primary purpose; the use or disclosure is required or authorised by or under an Australian law or a court or tribunal order; a permitted general situation exists; or we reasonably believe the use or disclosure is reasonably necessary for an enforcement-related activity conducted by or on behalf of an enforcement body.

We may disclose personal information collected from clients and prospective clients to:

  • organisations involved in providing, managing or administering our services, such as third-party suppliers (for example printers and postal services) and our advisers;
  • organisations involved in maintaining, reviewing and developing our systems, procedures and infrastructure, including testing or upgrading our computer systems;
  • organisations involved in a corporate reorganisation;
  • organisations involved in the payments system, including financial institutions, merchants and payment organisations;
  • organisations involved in product planning and development;
  • other organisations that, jointly with us, provide our services;
  • authorised representatives who provide our services on our behalf;
  • your representatives, including your legal advisers;
  • our financial advisers, legal advisers or auditors;
  • fraud bureaus or other organisations that identify, investigate or prevent fraud or other misconduct;
  • external dispute resolution schemes; and
  • regulatory bodies, government agencies and law enforcement bodies in any jurisdiction.

Where we use or disclose personal information, we keep a record of that disclosure.

Direct marketing

Direct marketing and your choices

We will not use or disclose your personal information for the purpose of direct marketing without consent, except as permitted by the Australian Privacy Principles. Every direct-marketing communication will include a prominent statement that you may opt out, or will draw your attention to that right.

You may ask us to stop sending you direct-marketing communications, to stop using or disclosing your information to facilitate direct marketing by other organisations, or to tell you the source of your personal information. We will give effect to your request within a reasonable period and free of charge, and will tell you the source of the information if you ask (unless it is impracticable or unreasonable to do so). This does not limit your separate rights under the Do Not Call Register Act 2006 (Cth) or the Spam Act 2003 (Cth).

Overseas

Disclosure to overseas recipients

If we disclose personal information to a recipient outside Australia (other than to you or to us), we take reasonable steps to ensure the overseas recipient does not breach the Australian Privacy Principles, except where the information is subject to a substantially similar law or binding scheme that you can enforce, where you have consented after being informed that we will not take those steps, where the disclosure is required or authorised by law or a court or tribunal order, or where a permitted general situation applies.

Identifiers

Government related identifiers

We will not adopt a government related identifier (such as a tax file number) as our own identifier unless we are required or authorised to do so by or under an Australian law or a court or tribunal order, or where prescribed by regulations. Separately, we will not use or disclose such an identifier except where this is permitted under the Privacy Act — for example where it is reasonably necessary to verify your identity for our functions, to meet our obligations to an agency or authority, or where required or authorised by law.

Access

Accessing your personal information

You may request access to the personal information we hold about you, and we will respond within a reasonable period. We will give access in the manner you request where it is reasonable and practicable to do so, and we will not charge you for making a request or impose excessive charges for access.

There are limited circumstances in which we may decline access — for example where giving access would pose a serious threat to life, health or safety; would have an unreasonable impact on the privacy of others; relates to existing or anticipated legal proceedings; would be unlawful; or would prejudice an enforcement-related activity — among other limited grounds set out in the Privacy Act. If we refuse access, we will give you written reasons (except where it would be unreasonable to do so) and tell you how to complain about the refusal.

Correction

Correcting your personal information

We take reasonable steps to correct the personal information we hold where we are satisfied it is inaccurate, out of date, incomplete, irrelevant or misleading, or where you ask us to correct it. If we have disclosed information to another entity and you ask us to notify that entity of a correction, we will take reasonable steps to do so unless it is impracticable or unlawful.

If we refuse to correct your information, we will give you written reasons and tell you how to complain. You may also ask us to associate with your information a statement that you consider it inaccurate, out of date, incomplete, irrelevant or misleading, and we will take reasonable steps to do so. We will not charge you for making a request, for correcting the information, or for associating a statement.

Data breaches

Notifiable data breaches

Under the Privacy Amendment (Notifiable Data Breaches) Act 2017, the Business is required to notify the Office of the Australian Information Commissioner (OAIC), and to promptly inform affected individuals, where an eligible data breach occurs — that is, where there is unauthorised access to or disclosure of, or loss of, personal information we hold that is likely to result in serious harm and we cannot prevent that risk through remedial action. We maintain a Data Breach Response Plan, developed in line with OAIC guidance, to ensure affected clients are notified in a timely way.

Unsolicited

Unsolicited personal information

If we receive personal information about you that we did not solicit, we will within a reasonable period determine whether we could have collected it. If we could not have collected the information and it is not contained in a Commonwealth record, we will destroy it or ensure it is de-identified, as soon as practicable, where it is lawful and reasonable to do so.

Governance

Governance and review

This policy is effective from the latest review date shown above and supersedes all previous documents, practices and policies relevant to privacy. It is reviewed at least annually by the Business's Compliance Officer, having regard to the changing circumstances of the Business and any changes in applicable Australian law. Staff are trained on their privacy and compliance obligations and are required to report breaches of this policy to the Managing Director.

Contact

Contact us or make a privacy complaint

Privacy enquiries

To access or correct your personal information, to opt out of direct marketing, or to make a privacy complaint, contact us at [email protected] or by post to Level 35, Riparian Plaza, 71 Eagle Street, Brisbane QLD 4000.

We will handle your complaint in accordance with our Complaints Handling and Dispute Resolution Policy. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner at oaic.gov.au.