We are committed to protecting your privacy in accordance with the Privacy Act 1988 and the Australian Privacy Principles.
This Privacy and Credit Information Policy describes how Allsorts of Loans ("we", "us", "our"), Carter McLean Pty Ltd ATF Adventurer Finance Solutions Unit Trust, Australian Credit Licence 491549, manages your personal, sensitive, and credit-related information. We are committed to protecting client data in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), Part IIIA of the Privacy Act, the Privacy (Credit Reporting) Code 2024 (CR Code), and the National Consumer Credit Protection Act 2009 (NCCP).
As an independent credit licence holder managed directly by its appointed Responsible Managers, we gather, verify, and store credit-related client data directly to perform credit assistance.
To deliver lending services across our lending suite — including consumer mortgages, commercial options, and asset or equipment finance — we collect and hold the following:
Where practicable, we obtain information directly from you via application documents, electronic entries on our website forms, digital communications, and direct consultation. We also collect information from authorised third-party industry channels:
3A. Information Collected via Website Forms and Calculators
When you enter information into financial calculators, borrowing estimators, or digital contact fields on our website, we capture those specific elements. This data is transferred to our business environment via encrypted security routes. If you abandon an online form prior to final submission, the information you have entered may still be collected and retained securely to help resolve your lending enquiry.
3B. Cookies, Digital Tracking and Analytics
Our website deploys technical cookies and analytical tracking tags to monitor traffic and analyse browsing behaviour.
We process your data to perform authorised credit assistance procedures under our licence, which include:
4A. Use of Automated Decision-Making Systems
We use digital calculation software, loan filters, and evaluation matrices owned by our lenders and aggregators to cross-reference your financial data against lending rules. These systems calculate product suitability. Final recommendations or loan filing actions are never isolated to automated routines — they require assessment by our Responsible Managers. You may request an explanation of how any automated tools contributed to a decision that affects you, and you may request human review.
In line with the Privacy Act 1988 (Cth) automated decision-making transparency requirements (APP 1.7, commencing 10 December 2026), we advise that: the kinds of personal information used in this process are your financial position, credit information and credit eligibility information described in Section 2; the kinds of decisions involved are preliminary product suitability and serviceability filtering only, not a final credit decision; and no automated system makes, or is authorised to make, a final decision to approve, decline, or price your loan — that decision is always made by a lender's credit team or by your Responsible Manager. You may contact our Privacy Officer to request further information about, or a review of, any automated process used in connection with your application.
We do not trade, rent, or lease your personal data. Information is shared strictly to arrange the specific loans or asset finance you request, through the following channels:
Access to our premises and computer systems is restricted through locks, password protection, internet firewalls and routers.
We operate within secure cloud databases hosted in Australia. However, platform networks, software providers, or credit providers on our lender panels may process data elements or house infrastructure overseas — frequently including New Zealand, the Philippines, India, the United Kingdom, or the United States. When data leaves Australian borders, we take precautions to ensure handling is consistent with the Australian Privacy Principles.
Our current service providers include OneDrive, Microsoft 365, Exchange, Xero, Adobe and our Customer Relationship Management (CRM) platform and Aggregator Software and payments systems. In some cases, our CRM provider does not disclose the specific jurisdictions in which its servers or authorised support teams are located. Where this occurs, we take reasonable steps to assess the provider's privacy and security framework (including encryption, access controls and audit logging) and implement contractual and procedural controls to mitigate risk. We remain responsible for your personal information in accordance with the APPs and will update this statement if further location details become available.
We apply electronic, technological, and logical controls to protect your files from data loss, unauthorised adjustment, or external interception. Files are held within password-protected, encrypted business systems using multi-factor authentication and role-based access. In accordance with the NCCP Act, complete client records are securely archived for a mandatory minimum of seven (7) years after our last dealing with you, after which they are thoroughly destroyed or permanently de-identified.
Photographic identification documents: In line with the reformed Anti-Money Laundering and Counter-Terrorism Financing Act and OAIC guidance applying to identity verification records collected on or after 31 March 2026, we do not retain copies or images of photographic identity documents (such as driver's licences and passports) once your identity has been verified. Instead, we retain a structured record of the verification — including the document type, document number, expiry date, verification method and outcome — for the statutory seven (7) year retention period. Copies of identity documents collected before 31 March 2026 may continue to be held for the pre-existing statutory retention period, after which they are securely destroyed or permanently de-identified.
We assess all suspected data breaches within 30 days to determine whether they are notifiable under the Notifiable Data Breaches (NDB) Scheme. If we become aware of a data breach likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the NDB Scheme.
You may request access to the personal and credit information we hold about you, by contacting our Privacy Officer at admin@allsortsofloans.com.au and providing enough information to allow us to identify you. If any information is found to be out of date, inaccurate, or incomplete, you may lodge a correction request. We address correction requests at no charge, with a standard turnaround of 30 days, and will correct, amend or delete any personal information that we agree is inaccurate.
If you are a customer or a potential customer, from time to time we may contact you with information about products and services offered by us, which we think may be of interest to you. When we contact you it may be by mail, telephone, email or SMS.
You may opt out of receiving promotional communications from us by using the unsubscribe link within each email or emailing us to have your contact information removed from our promotional email list or registration database. Although opt-out requests are usually processed immediately, please allow ten (10) business days for a removal request to be processed. Even after you opt out from receiving promotional messages from us, you will continue to receive messages from us regarding our services.
For any enquiries regarding this policy, or to lodge a formal complaint regarding a data handling matter, please contact our Privacy Officer directly:
Privacy Officer — Allsorts of Loans
Carter McLean Pty Ltd ATF Adventurer Finance Solutions Unit Trust
ACL 491549
admin@allsortsofloans.com.au
We will investigate your complaint and provide a written response within 30 days.
External escalation to the Privacy Commissioner
If you receive no reply within 30 days, or if you remain unsatisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):
Phone: 1300 363 992
Website: www.oaic.gov.au
Post: GPO Box 5288, Sydney NSW 2001
For disputes relating to service delivery, fees, or loan products, please refer to the dispute resolution process outlined in our Credit Guide, which details our escalation pathway to the Australian Financial Complaints Authority (AFCA), our External Dispute Resolution scheme, Membership 38764.
If you consent to us doing so, we may obtain a report or information about your consumer or commercial credit worthiness from a Credit Reporting Body (CRB), and we may disclose personal information such as your name, date of birth, driver's licence and address to the CRB to obtain an assessment of whether that personal information matches the information held by it. See Schedule 2 of our Credit Guide for the contact details of each CRB we work with.
Under Part IIIA of the Privacy Act and the CR Code, you should also be aware that:
For more information on your privacy rights please visit www.oaic.gov.au.