
PRIVACY & DATA MANAGEMENT POLICY
Perpetuity Capital Pty Ltd
AFSL 405364
Last updated: September 2026
1. Our Commitment To Privacy
Perpetuity Capital Pty Ltd (“Perpetuity Capital”, “Perpetuity”, “we”, “us” or “our”) respects the privacy of individuals and is committed to protecting the personal information entrusted to us.
We handle personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), the Notifiable Data Breaches Scheme, and other applicable Australian laws and regulatory requirements.
This Privacy & Data Management Policy explains how we collect, hold, use, disclose, protect and manage personal information.
It applies to personal information collected through our website, our advisory and financial services activities, our business relationships, correspondence, meetings, transactions and other interactions with us.
2. Who We Are
Perpetuity Capital is an Australian corporate advisory and financial services business providing services that may include:
-
corporate advisory and mergers and acquisitions;
-
debt and equity capital raising;
-
financial and transaction advisory;
-
funds management and investment-related activities;
-
financial licensing and authorised representative services;
-
restructuring and strategic advisory; and
-
related financial and professional services.
Perpetuity Capital Holds Australian Financial Services Licence AFSL 405364.
Our principal contact details are:
Perpetuity Capital Pty Ltd
Suite level 4, 123 Clarence St
Sydney NSW 2000
Australia
Email: info@perpetuity.com.au
3. Personal Information We May Collect
The types of personal information we collect depend on the nature of our relationship with you and may include:
-
your name, title, date of birth and contact details;
-
residential, business or postal address;
-
email address and telephone number;
-
employment, professional and business information;
-
directorships, shareholdings and other corporate interests;
-
identification documents and information required to verify identity;
-
information required for know-your-client, anti-money laundering, sanctions, fraud prevention, due diligence and compliance purposes;
-
financial, banking, investment, asset, liability and transaction information;
-
tax-related information where relevant;
-
information relating to companies, trusts, partnerships or other entities with which you are associated;
-
information contained in correspondence, applications, agreements, transaction documents and other records provided to us;
-
information concerning investment preferences, objectives or circumstances where relevant to the services being provided;
-
records of meetings, telephone calls and electronic communications where lawfully created or retained;
-
information relating to complaints, disputes or regulatory matters;
-
information provided when applying for employment or engagement with us; and
-
technical information generated when you use our website or electronic systems.
In some circumstances, we may collect sensitive information as defined by the Privacy Act. We will only collect sensitive information where permitted by law, including where you have consented and the information is reasonably necessary for our functions or activities, or where another legal exception applies.
4. How We Collect Personal Information
We generally collect personal information directly from you, including when you:
-
contact or correspond with us;
-
visit our website or submit an online enquiry;
-
engage us to provide services;
-
seek to become an investor, client, authorised representative, business partner, supplier or service provider;
-
participate in a transaction in which we are involved;
-
provide documents or information as part of a due diligence, capital raising, investment or advisory process;
-
attend meetings, presentations or events; or
-
apply for employment or engagement with us.
We may also collect personal information from third parties where appropriate and lawful, including:
-
companies or organisations with which you are associated;
-
professional advisers, accountants, lawyers, brokers, financial institutions and other transaction participants;
-
authorised representatives and business partners;
-
government agencies and regulators;
-
publicly available sources, including corporate registers and professional or business directories;
-
identity verification, compliance, credit, fraud prevention and due diligence service providers; and
-
other persons or organisations involved in a transaction or proposed transaction.
If we receive unsolicited personal information, we will determine whether we could lawfully have collected that information. If not, we will take reasonable steps to destroy or de-identify it where required by law.
5. Why We Collect, Hold & Use Personal Information
We may collect, hold, use and disclose personal information for purposes including:
-
providing corporate advisory, financial and investment-related services;
-
assessing and managing prospective and existing client relationships;
-
undertaking transactions, investments, capital raisings, mergers, acquisitions, divestments and financing arrangements;
-
establishing and administering investment structures and funds;
-
managing authorised representatives and AFSL-related activities;
-
conducting due diligence, identity verification and compliance checks;
-
satisfying legal, regulatory, licensing, risk management and governance obligations;
-
communicating with clients, investors, counterparties and professional advisers;
-
administering contracts and business relationships;
-
processing payments, fees and other transactions;
-
maintaining our business records;
-
managing risk, security, fraud prevention and information security;
-
handling enquiries, complaints, disputes and legal proceedings;
-
managing employment, contractor and recruitment matters;
-
improving our services, systems and business operations;
-
conducting research and business analysis;
-
communicating information about our services and business activities where permitted by law; and
-
complying with applicable laws, court orders and requests or requirements of regulators and government authorities.
We will generally use personal information for the purpose for which it was collected, a related purpose that you would reasonably expect, a purpose to which you have consented, or otherwise where permitted or required by law.
6. If You Dont Provide Personal Information
Where practicable, you may interact with us anonymously or using a pseudonym.
However, because of the nature of financial services and corporate transactions, we will often need to know your identity.
If required personal information is not provided, we may be unable to provide particular services, complete a transaction, establish or continue a business relationship, satisfy our compliance obligations or respond fully to your request.
7. Disclosure Of Personal Information
We do not sell personal information.
We may disclose personal information where reasonably necessary for our business activities or where permitted or required by law, including to:
-
our related companies and associated entities;
-
authorised representatives;
-
clients, investors, lenders and prospective transaction counterparties where appropriate;
-
banks, financiers, brokers, investment institutions and financial service providers;
-
fund administrators, registries, custodians and investment service providers;
-
accountants, lawyers, auditors, consultants and other professional advisers;
-
technology, cloud computing, cybersecurity, data storage and communications providers;
-
identity verification, compliance, due diligence and fraud prevention providers;
-
insurers and insurance advisers;
-
regulators, government agencies, courts and law enforcement authorities;
-
parties involved in actual or proposed mergers, acquisitions, financing, investments, restructuring or other corporate transactions; and
-
other parties where you have consented to the disclosure or where disclosure is authorised or required by law.
Where information is provided to external service providers, we seek to limit the information provided to what is reasonably necessary for the relevant purpose.
8. Overseas Disclosure & Storage
Our business and transactions may have an international component. Personal information may therefore be disclosed to, accessed by, or stored with organisations located outside Australia.
These may include overseas investors, lenders, transaction counterparties, professional advisers, financial institutions and technology or cloud service providers.
The countries involved will depend on the particular transaction, service provider or business relationship.
Where practicable, we will inform individuals of countries in which overseas recipients are likely to be located. Where we disclose personal information overseas, we will take reasonable steps as required by the Australian Privacy Principles to ensure that the information is appropriately protected.
Where overseas cloud or technology providers process information on our behalf while the information remains under our effective control, we will seek to maintain appropriate contractual, technical and organisational protections.
9. Data Security
We recognise that information security is an essential part of privacy management.
We take reasonable technical, physical and organisational measures appropriate to the nature of the information and the risks involved to protect personal information from:
-
misuse;
-
interference;
-
loss;
-
unauthorised access;
-
unauthorised modification; and
-
unauthorised disclosure.
Our security measures may include, as appropriate:
-
access controls and user authentication;
-
role-based access to information;
-
password and authentication controls;
-
secure cloud and information technology systems;
-
cybersecurity protections and monitoring;
-
encryption and secure transmission methods where appropriate;
-
data backup and recovery arrangements;
-
physical security;
-
staff confidentiality obligations;
-
privacy and cybersecurity awareness;
-
management of third-party technology and service providers; and
-
incident response and data breach procedures.
No electronic system is completely immune from security risks. We therefore regularly consider the nature of the information we hold, emerging risks and whether our security controls remain appropriate.
10. Data Retention & Destruction
We retain personal information only for as long as reasonably necessary for our business, legal, regulatory, contractual, risk management and record-keeping requirements.
Retention periods may vary depending upon the nature of the information and the purpose for which it is held.
11. Data Breaches
Perpetuity Capital maintains procedures for responding to actual or suspected data breaches.
Where a suspected breach occurs, we will take appropriate steps to:
-
contain the incident;
-
investigate what occurred;
-
assess the nature and extent of information affected;
-
assess the potential consequences for affected individuals;
-
take appropriate remedial action; and
-
implement measures designed to reduce the risk of recurrence.
Where a data breach is an eligible data breach under the Notifiable Data Breaches Scheme, we will notify the Office of the Australian Information Commissioner and affected individuals as required by law.
12. Website, Cookies and Analytics
When you use our website, certain technical information may be collected automatically, including:
-
IP address;
-
browser and device information;
-
date and time of access;
-
pages visited;
-
referring website;
-
website usage and interaction information; and
-
cookies or similar technologies.
We may use this information to operate and secure our website, understand how visitors use it, improve website performance and functionality, and measure the effectiveness of our communications.
Our website may use cookies and third-party analytics or technology services. You may be able to restrict or disable cookies through your browser settings, although doing so may affect some website functionality.
Where third-party services collect or process information, their own privacy policies may also apply.
13. Direct Marketing
Where permitted by law, we may use personal information to communicate with you about Perpetuity Capital, our services, transactions, events or opportunities that we reasonably believe may be relevant to you.
We will comply with applicable privacy and electronic communications laws, including the Privacy Act and Spam Act 2003 (Cth).
You may opt out of receiving direct marketing communications at any time by using the unsubscribe facility included in an electronic communication or by contacting us at info@perpetuity.com.au.
We will not use sensitive information for direct marketing without the consent required by law.
14. Automation Decision-Making & Artificial Intelligence
We may use technology, automation and artificial intelligence tools to assist with administrative, analytical, compliance, research or business processes.
We do not intend to rely solely on automated systems to make decisions that significantly affect an individual's rights or interests unless appropriate safeguards are in place and the use is permitted by applicable law.
Where the Privacy Act requires us to disclose information about automated decision-making involving personal information, we will provide the required information in this Policy, including the types of personal information used and the types of decisions made or substantially assisted by automated systems.
We will review this section as Australian requirements concerning automated decision-making develop or change.
15. Accuracy Of Personal Information
We take reasonable steps to ensure that personal information we collect, use and disclose is accurate, complete, up to date and relevant for the purpose for which it is being used or disclosed.
We encourage you to notify us if your personal information changes or if you believe information we hold about you is inaccurate or incomplete.
16. Accessing Your Personal Information
You may request access to personal information that we hold about you.
Requests should be made using the contact details below.
We will respond to requests within the periods required by applicable law. In some circumstances, the Privacy Act permits us to refuse access to some or all of the information requested. If this occurs, we will generally provide written reasons where required by law.
We may take reasonable steps to verify your identity before providing access.
17. Correcting Personal Information
If you believe that personal information we hold about you is inaccurate, out of date, incomplete, irrelevant or misleading, you may request that we correct it.
We will take reasonable steps to consider and, where appropriate, make the requested correction in accordance with the Privacy Act.
18. Privacy Complaints
If you believe that we have not handled your personal information appropriately or have breached the Australian Privacy Principles, please contact us.
Privacy Officer
Perpetuity Capital Pty Ltd
Level 4, 123 Clarence St
Sydney NSW 2000
Australia
Email: info@perpetuity.com.au
Please provide sufficient details for us to understand and investigate your concern.
We will acknowledge and investigate privacy complaints and seek to respond within a reasonable period.
If you are not satisfied with our response, you may be entitled to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
Information about privacy rights and complaints is available from the OAIC.
19. Third-Party Websites
Our website may contain links to websites operated by third parties.
Perpetuity Capital is not responsible for the privacy, security or information-handling practices of third-party websites. We recommend reviewing the privacy policies of those organisations before providing them with personal information.
20. Governance & Accountability
We seek to incorporate privacy and data protection into our governance, risk management and business processes.
This includes, where appropriate:
-
allocating responsibility for privacy management;
-
reviewing privacy and cybersecurity risks;
-
restricting access to personal information to persons who require it;
-
assessing third-party service providers that handle personal information;
-
maintaining procedures for responding to privacy incidents and data breaches;
-
providing appropriate privacy and information-security awareness to personnel; and
-
periodically reviewing our information-handling practices.
21. Changes To This Policy
We may amend this Privacy & Data Management Policy from time to time to reflect changes in our business, technology, information-handling practices or legal and regulatory requirements.
The current version will be published on our website and will state the date on which it was last updated.
We encourage you to review this Policy periodically.
22. Contact Us
Questions, requests or complaints regarding privacy or the management of personal information should be directed to:
Privacy Officer
Perpetuity Capital Pty Ltd
Level 4, 123 Clarence St
Sydney NSW 2000
Australia
Email: info@perpetuity.com.au
AFSL 405364
Last updated: September 2026