LINK

Privacy

Privacy Policy

Applies to all LINK-branded divisions

Version 3.1 · Effective 13 August 2026 · Last updated 1 September 2026

This policy explains how LINK collects, holds, uses and discloses your personal information, and how you can access it, correct it, or raise a concern. LINK is committed to managing your personal information openly and transparently, and to complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Credit information is also subject to additional rules in Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2025.

Who this policy covers

LINK is a group of related professional services businesses. The companies listed below are the entities that collect and hold your personal information and that are responsible under the Privacy Act; “LINK” is the brand under which they operate. The privacy function is run centrally by The Link Collective Pty Ltd (TLC) on behalf of those entities. This policy applies to personal information handled by each of the following LINK-branded divisions:

The LINK-branded entities operating these divisions are:

Our online services (GST Register, ABN Assist, CGT Clearance and DASPA) operate under separate policies published on their own websites.

The personal information we collect and hold

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. Depending on the services you use, we may collect and hold:

How we collect your information

You do not have to identify yourself for general enquiries where it is lawful and practicable to remain anonymous. To deliver our services we usually need to collect personal information, and we collect it in these ways:

When we collect your personal information we take reasonable steps to tell you why we are collecting it and how we will handle it.

Why we collect, hold, use and disclose your information

We collect, hold, use and disclose your personal information to:

We use and disclose your personal information only for the purpose we collected it, for a directly related purpose you would reasonably expect, or where you consent or the law requires or authorises it.

Who we disclose your information to

We may disclose your personal information to:

We do not sell your personal information.

Overseas disclosure

Some of the software and cloud services we use to deliver our services are provided by businesses located outside Australia, and some of our team members are located overseas. As a result, your personal information may be disclosed to, or accessible by, recipients in the following countries:

Separately from the countries above, our Microsoft 365 environment holds our core data in Australia, but certain Microsoft services may process information outside Australia. Microsoft Teams content is currently held in the Asia Pacific region pending migration to Australia, and Microsoft does not provide a committed processing location for all services, such as mail filtering. Where Microsoft does not identify a specific country, we are not able to name one.

Many of the providers we rely on for core client information keep that information in Australia, including our lending aggregator (Connective), the credit reporting body we use (Equifax), our open banking provider (Frollo) and the database behind our client portal. Our document management system stores files inside our own Microsoft 365 environment rather than holding a separate copy.

We take reasonable steps to ensure overseas recipients handle your personal information consistently with the Australian Privacy Principles.

Sensitive information

Sensitive information, such as health information and biometric information, is given extra protection under the Privacy Act. We collect it only where it is reasonably necessary for a service and with your consent. This most often arises in two situations: financial planning and insurance advice, where health information may be needed to arrange cover; and electronic identity verification, where a photograph of your identity document and, in some cases, a facial image match are used to confirm who you are. We use an electronic identity verification provider for this, Didit, which hosts this information in the European Economic Area. Didit shows you a privacy notice and asks for your consent before it collects that information. Those providers ask for your consent before collecting that information, and that consent covers our collection and use of it for verifying your identity. We keep a record of that consent. We apply stronger security to sensitive information and use it only for the purpose you provided it.

Tax file numbers and government identifiers

Tax file numbers are protected by the Privacy (Tax File Number) Rule 2015 in addition to the APPs. We collect them only where authorised, use them only for lawful taxation, superannuation or assistance purposes, and do not disclose them except as authorised by law. We keep them secure and do not use them to identify you generally.

Credit information (LINK Advance)

If you use LINK Advance for lending or finance broking, we collect, use and disclose credit information to help arrange finance for you. Before we obtain a credit report about you, we obtain your written consent as part of the credit assessment process, which we capture in our lending system. We obtain credit reporting information through the credit reporting arrangements available to us via our lending aggregator, Connective, with the report provided to us by the credit reporting body (Equifax). We also disclose your information to lenders, and to Connective, which holds it in Australia. With your separate consent, we may receive your banking data through the Consumer Data Right (Open Banking), where Frollo, as an accredited data recipient, discloses that data to us as your nominated trusted adviser. Once that data is disclosed to us it is handled under this policy and the Privacy Act rather than under the Consumer Data Right protections. Credit information is subject to additional rules in Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2025. You can ask to access and correct the credit information we hold about you, and you can complain about how we handle it (see Complaints below). As a provider of credit assistance we are also a member of the Australian Financial Complaints Authority (AFCA).

Licensee and aggregator arrangements

Some LINK services are provided under the licence of another business. Where that applies, both we and that business hold your information: we disclose it to them as part of delivering the service, and we also keep our own records in our systems. If you want to access or correct your information, contact our Privacy Officer and we will tell you which information we hold and which is held by the licensee or aggregator.

You can obtain these businesses' privacy policies from them directly.

Artificial intelligence and technology tools

We use software and, in some cases, artificial intelligence tools to help us deliver our services efficiently. Some of these tools are provided by businesses located overseas (see Overseas disclosure). We take reasonable steps to protect the confidentiality of your information when we use them and to configure them appropriately. Where we use these tools to help prepare advice, correspondence or analysis, the work is reviewed by a person before it is relied on.

Automated decision-making

Some of our processes use a computer program to make a decision, or to do something that feeds into a decision. We set out below the kinds of personal information those programs use and the kinds of decisions involved. We are describing this now, ahead of the disclosure becoming mandatory on 10 December 2026.

Decisions made by a computer program

Electronic identity verification. When we verify who you are, the provider's system compares the identity document you supply and, in some cases, a facial image, and returns a result. That result is produced by the program rather than by a person. If verification does not succeed we may not be able to act for you, although you can contact us and we will look at it. The information used is your identity document, your facial image where that applies, and the identity details you have given us.

Things a computer program does that feed into a decision

In some parts of our business, software sorts, checks or pre-assesses information before a person makes a decision. Where that happens it can influence the outcome even though a person decides. The areas where this may apply are:

Property applications, where software may organise, sort or check tenancy application information before it is considered. The information used is the details in the application, including your identity, contact, employment, income and rental history.

Lending, where software may check or pre-assess your information against lender requirements before an application is prepared or submitted. The information used is your identity, income, expenses, assets, liabilities, banking and credit information.

Online applications, where our systems may validate the information you enter and, in some cases, prevent an application proceeding until it is corrected. The information used is the details you enter in the form.

We keep this under review as our systems change, and we will update this section as our assessment is completed. If you would like to know whether a decision affecting you involved a computer program, contact our Privacy Officer.

How we hold and protect your information

We hold your personal information mainly in electronic form within our Microsoft 365 environment and connected business systems. Our Microsoft 365 tenant is committed to Australian data storage, and our email, SharePoint and OneDrive data is held in Australia. We take reasonable steps to protect your information from misuse, interference and loss, and from unauthorised access, modification or disclosure, including access controls, multi-factor authentication, and staff training. We keep personal information only for as long as we need it or are required to keep it by law (for example, tax, financial, credit and tenancy records), and then take reasonable steps to destroy or de-identify it.

Direct marketing

We may send you information about LINK services that may be relevant to you, where you would reasonably expect us to or where you have consented. Every marketing message tells you how to opt out, and you can also opt out at any time by contacting us. We action opt-outs promptly and do not charge for them. We do not use sensitive information for marketing without your consent, and we do not sell or supply your details to other organisations for their own marketing. Where we collect your details in person, such as at an open home, and may later use them to contact you about our services, we tell you at the time. Separately, where a client engages LINK Creative or LINK Marketing to run marketing using their own customer list, we handle that list on the client's instructions and only for their campaign. The client is responsible for having the right to use those details. Our marketing is also subject to the Spam Act 2003 and the Do Not Call Register Act 2006.

Cookies and website analytics

Our websites use cookies and similar technologies. What runs on each site differs, and changes as we rebuild them. Some of our sites use Google Analytics and Google Ads to understand how the site is used and to measure our advertising. Some also use a Meta pixel, which measures our advertising on Facebook and Instagram and allows us to show ads to people who have visited the site, and some use the Microsoft advertising tag or a session recording tool. These set cookies and share information with those providers, who are located overseas. Our rebuilt sites currently use Vercel Analytics, which does not set cookies and does not track you across sites. We do not use cookie consent banners. You can refuse cookies in your browser settings, though some parts of a site may then not work as well. You can also opt out of Google Analytics on every site that uses it with Google's browser add-on at tools.google.com/dlpage/gaoptout, control advertising personalisation at myadcenter.google.com, and manage Meta's advertising settings at facebook.com/adpreferences. If you would like to know exactly what runs on a particular site, contact our Privacy Officer and we will tell you.

If a data breach occurs

LINK has a data breach response plan. If a data breach affecting your personal information is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme.

How to access and correct your information

You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. To make a request, contact our Privacy Officer using the details below. We will respond within a reasonable time and will verify your identity before giving access. In most cases access is free; we will tell you in advance if a reasonable cost applies. If we cannot give access or make a correction, we will explain why in writing.

How to make a privacy complaint

If you think we have mishandled your personal information or breached the APPs, or your credit information, please contact our Privacy Officer. We will acknowledge your complaint promptly, investigate it, and give you a written response, usually within 30 days. If you are not satisfied, you can complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or on 1300 363 992. For credit-related complaints, you may also be able to take the matter to the Australian Financial Complaints Authority (AFCA).

Contact us

For any privacy question, request or complaint, contact:

Changes to this policy

We may update this policy from time to time. The current version is always available free of charge at link.com.au/privacy. This version is effective from 13 August 2026.

What runs on link.com.au

The section above says what runs on each site differs. On this one, here is the answer in full.

The calculators do their maths in your browser. Every figure you enter into the pay calculator, the novated lease calculator or any of the others is worked out on your own device. Your salary, your car price and your study loan are never sent to us and never stored. That is why a shared result link carries the numbers in the URL — the page rebuilds the answer from the link, because we do not have a copy. The one exception is a form you fill in deliberately: if you request a novated lease quote, the figures you modelled are sent with it, and only after you tick a box saying so, which names who receives them.

What we record when you visit. On the calculator pages we log the page you landed on, the time, your IP address, the approximate city your connection resolves to, the site that referred you, whether you are on a phone or a computer, how long you stayed, and which controls you used — for example that you switched to Hourly, or opened the lease section. We record the names of those controls and never the values you typed into them. We use it to understand whether the tools are useful and where people get stuck. It is kept for 30 days and then deleted.

Cookies on this site. This site sets no advertising or tracking cookies. There are two functional ones: a session cookie if you unlock an internal or password-protected page, and your theme preference. Neither identifies you. We use Vercel's analytics, which does not use cookies. Other LINK sites run analytics and advertising tags, as the section above describes.

The tools described in that last section: the pay calculator and everything under it.