Privacy Policy
Vellum Advisory
This Privacy Policy explains how Vellum Advisory ("Vellum", "we", "us" or "our") collects, holds, uses and discloses your personal information, including credit-related information. It applies to information collected offline and online, including through our website www.vellumadvisory.com.au (Site).
We are bound by the Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs) and, in relation to credit-related information, Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code 2014 (CR Code).
Vellum Advisory is a registered business name of HSB Wealth Pty Ltd (ABN 17 701 025 612).
What personal information we collect
As a finance and mortgage advisory business, the personal information we collect is more detailed than most consumer services. Depending on your dealings with us, it may include:
Your name, date of birth and contact details (email, phone, residential and postal address);
Identification information (driver licence, passport, and other documents required to verify your identity under our AML/CTF obligations);
Financial information — income, employment, assets, liabilities, expenses, bank statements, tax returns, Notices of Assessment, BAS and accountant-prepared financials;
Details of your business, including structure, trading history and ownership, where you are self-employed or borrowing through an entity;
Credit-related information (see section 3 below);
Details of the loans, products and services you have enquired about or that we have arranged for you;
Records of our communications with you;
Where relevant, information about guarantors, co-borrowers, directors and beneficial owners connected to your application; and
Limited technical information necessary to operate and secure our Site (for example, basic server logs)
Where you provide us with personal information about another person (for example a co-borrower, guarantor or accountant), you confirm you are authorised to do so and that you have made that person aware of this Privacy Policy.
How we collect personal information
We generally collect personal information directly from you — through enquiries, fact-find and application forms, our Site, phone, email and meetings.
We may also collect it from third parties, including your accountant, financial adviser, conveyancer or solicitor; lenders and referral partners; credit reporting bodies; and publicly available sources, where it is reasonable and practicable to do so.
Credit related information
In providing credit assistance, we collect, hold, use and disclose credit information and credit eligibility information as defined in the Privacy Act. This may include:
Identification information;
Information about applications you have made for credit or that we have submitted on your behalf;
Your repayment history and current or past credit accounts;
Default and payment information;
Court proceedings and insolvency information;
Credit scores, ratings, assessments and summaries derived from a credit report; and
Publicly available information relevant to your creditworthiness.
We deal with the credit reporting body Equifax. Our handling of this information is set out in the Credit Reporting Statement at section 7.
Why we collect, hold, use and disclose your information
We use your personal and credit-related information to:
Assess your objectives, requirements and financial situation and provide credit assistance;
Prepare, submit and manage loan applications with lenders on your behalf;
Verify your identity and meet our AML/CTF and responsible lending obligations;
Provide ongoing strategy, reviews and portfolio management across the life of your loans;
Administer our relationship with you and maintain our records;
Improve our services; and
Comply with our legal and regulatory obligations, our aggregator and lender requirements, and to resolve disputes.
If you do not provide the information we request, we may be unable to assist you or arrange finance on your behalf.
Who we disclose your information to
We may disclose your personal and credit-related information to:
Lenders, credit providers and private lenders on our panel, for the purpose of arranging and managing your finance;
Our aggregator and the software platforms through which applications are lodged and compliance is recorded;
The credit reporting body referred to in section 7;
Our employees and contractors, including third-party administrative and loan-processing contractors, some of whom may be located overseas (see section 6);
Third-party service providers, including IT, cloud hosting, data storage, identity verification and document management providers;
Your professional advisers (accountant, solicitor, conveyancer, financial adviser) where you have authorised us to do so;
Insurers, valuers, mortgage insurers and settlement agents connected to your transaction;
Referral partners, where you have been introduced to us or where you consent to a referral; and
Courts, tribunals, regulators and law enforcement, as required or authorised by law
We do not sell your personal information.
Sending information overseas
Some of our contractors and service providers — including administrative and loan-processing contractors, and IT, cloud-hosting and data-storage providers — may be located overseas, or may store or access data outside Australia. Where this occurs, your personal information (which may include financial and credit-related information) may be accessed, processed or stored outside Australia.
Some of these countries may not have privacy laws substantially similar to the APPs. Where we disclose your information overseas, we take reasonable steps under APP 8 to ensure it is handled consistently with this Policy, including through contractual arrangements and access controls.
Credit Reporting Statement
This section sets out how we manage credit-related information under Part IIIA of the Privacy Act and the CR Code.
Collection and disclosure to a CRB. We may disclose your credit information to a credit reporting body (CRB), and the CRB may include that information in reports provided to other credit providers to assist them in assessing your creditworthiness. When you apply for or guarantee credit through us, the CRB may create or update a credit information file about you. The CRB we deal with is Equifax.
CRB policy. Equifax has a policy about how it manages credit reporting information, available on its website. You can contact Equifax to obtain a copy.
Pre-screening. You may request the CRB not to use your credit reporting information for the purposes of pre-screening direct marketing on behalf of a credit provider.
Suspected fraud (ban period). If you believe you have been, or are likely to be, a victim of fraud (including identity fraud), you may request the CRB not to use or disclose your credit reporting information. The CRB must not use or disclose that information during a ban period unless you consent or it is required by law.
Access and correction. You may request access to the credit-related information we hold about you and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. We do not charge for making a correction request, and we will not charge a fee simply for making a request for access. If you request a correction, we will respond within the time required by law and, where appropriate, consult with the relevant CRB or credit provider.
Complaints. If you have a complaint about how we have handled your credit-related information, you may contact us using the details in section 15. Our complaints process is set out in that section.
Automated decision making and use of AI
Vellum uses technology, including automated tools and artificial intelligence, to support parts of our work — for example, organising and analysing information, researching lender policy, preparing documentation and producing preliminary assessments to assist our advisers.
Where personal information is used by these tools, it is used to assist our team. Our credit recommendations and the credit assistance we provide involve human review and professional judgement by our advisers, and are not made solely by automated means. Decisions on whether to approve credit are made by lenders under their own policies and processes.
The categories of personal information that may be used by our automated tools include the identification, financial and credit-related information described in sections 1 and 3, for the purposes described in section 4. We keep our use of these tools under review to ensure our practices remain consistent with our obligations under the Privacy Act, including the automated decision-making transparency requirements in APP 1.
Sensitive information
Some information is given a higher level of protection under the APPs as sensitive information (for example, health information). We do not generally collect sensitive information.
If we ever need to collect it, we will do so only where it is reasonably necessary for our functions and, generally, with your consent, and we will use and disclose it only for the purpose for which it was collected, for a directly related secondary purpose, or as otherwise required or authorised by law.
Data quality and retention
We take reasonable steps to ensure the personal information we hold is accurate, up to date and complete. We retain your information for as long as necessary to provide our services, to meet our legal, regulatory, aggregator and lender record-keeping obligations (which in the credit industry are generally lengthy), and to resolve disputes. When information is no longer required, we take reasonable steps to destroy or de-identify it.
Cookies
Our Site may use essential cookies that are necessary for it to function. We do not use advertising or analytics cookies, tracking pixels or third-party retargeting tools on our Site.
You can manage or disable cookies through your browser settings, though some parts of the Site may not function properly as a result.
Security
We take reasonable physical, electronic and organisational steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. No method of transmission or storage is completely secure, and transmission of information to us is at your own risk. We maintain data breach response procedures consistent with the Notifiable Data Breaches scheme.
Accessing and correcting your information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details in section 15.
There is no fee for making a request. We may recover reasonable costs of giving access (for example, for retrieving and providing extensive records), and we will tell you about any such cost before proceeding. We will respond within a reasonable period and, if we refuse access or correction, we will give you reasons and information about how to complain.
Your choices
You do not have to provide personal information to us, and you may deal with us anonymously where it is lawful and practicable. However, in most cases we will be unable to provide credit assistance or arrange finance without the information described in this Policy.
Complaints and contacting us
If you have a question about this Policy, wish to access or correct your information, or want to make a privacy complaint, please contact our Privacy Officer:
Privacy Officer — Vellum Advisory 1/470 St Pauls Terrace, Fortitude Valley QLD 4006 Email: vellum@vellumadvisory.com.au
How we handle complaints. We will acknowledge your complaint and investigate it, and respond to you in writing within a reasonable period (generally within 30 days). If your complaint relates to credit reporting information, we may need to consult with a CRB or another credit provider.
If you are not satisfied. If we do not resolve your complaint to your satisfaction, you may refer it to the Office of the Australian Information Commissioner (OAIC) — Website: oaic.gov.au | Phone: 1300 363 992.
Links to other websites
Our Site may contain links to third-party websites. We are not responsible for the privacy practices of those sites, which are not governed by this Policy.
Changes to this Policy
We may update this Policy from time to time by publishing the amended version on our Site. Material changes will be indicated by an updated effective date below.
Effective date: 14 August 2026