Privacy Policy
How we collect, hold, use and disclose personal information — and how you can access it, correct it, or complain.
01About this policy
Brizo Cap Pty Ltd ABN 72 637 641 895 (Brizo, we, us, our) respects your privacy. This policy explains how we collect, hold, use and disclose personal information, and how you can access, correct or complain about our handling of it.
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the thirteen Australian Privacy Principles (APPs). This policy applies to www.brizo.com.au and to our advisory and consulting services.
By using the Website or engaging our services, you consent to the handling of your personal information as described here.
02What personal information we collect
We collect only the personal information reasonably necessary for our functions and activities. This ordinarily includes:
- Contact and identity information — name, business name, position or title, email address, telephone number, and postal or business address.
- Enquiry and engagement information — the content of your enquiry or booking request, the nature of your business, indicative revenue range, your objectives (for example, whether you are considering a capital raise or a sale), and your preferred timing.
- Business and financial information provided during an engagement — financial statements, management accounts, tax records, contracts, shareholder and capitalisation details, and operational documents. This material commonly contains personal information about directors, shareholders, employees and other individuals.
- Meeting and correspondence records — notes of calls and meetings, email and message correspondence, and file records.
- Technical and Website information — IP address, browser type and version, device and operating system, referring page, pages visited, time and duration of visit, and similar analytics data.
03Sensitive information
We do not seek sensitive information as defined in the Privacy Act (such as health information, or information about racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record).
If sensitive information is provided to us incidentally within business records, we will handle it in accordance with APP 3 and this policy, and will not use or disclose it for any purpose other than the purpose for which it was provided, unless required or authorised by law.
04How we collect personal information
We collect personal information directly from you wherever reasonably practicable — through the booking form or scheduling tool on the Website, by email or telephone, in meetings, and through documents you provide during an engagement.
We may also collect personal information from third parties, including publicly available sources such as ASIC and ABN registers, company websites and professional networking platforms; your professional advisers (accountants, lawyers, brokers) where you have authorised this; and referrers who introduce you to us.
Collection about third parties
If you provide us with personal information about another individual (for example a co-director, shareholder or employee), you must ensure you are entitled to do so and that the individual is aware of this policy and how their information will be handled.
Unsolicited information
If we receive personal information we did not solicit and could not have collected under APP 3, we will destroy or de-identify it if lawful and reasonable to do so.
05Anonymity and pseudonymity
You may browse the Website without identifying yourself. However, we generally cannot respond to enquiries, arrange a readiness assessment, or deliver advisory services without knowing who you are and who you represent.
06Why we collect, hold and use personal information
We use personal information to:
- (a) respond to enquiries and arrange and conduct readiness assessments;
- (b) assess whether an engagement is appropriate and provide our advisory and consulting services;
- (c) prepare deliverables including readiness assessments, gap analyses, information memoranda, investor materials and data room indexes;
- (d) communicate with you and your advisers about a matter;
- (e) issue invoices, process payments and maintain financial records;
- (f) maintain client records and manage conflicts of interest;
- (g) improve the Website and our services, including through analytics;
- (h) send you information about our services where you have consented or would reasonably expect it; and
- (i) comply with our legal, regulatory, insurance and professional obligations.
We will not use personal information for a secondary purpose unless you would reasonably expect it and it is related to the primary purpose (or, for sensitive information, directly related), you have consented, or it is required or authorised by law.
07Direct marketing
We may send you information about our services by email. Every marketing communication includes an unsubscribe facility, and you may opt out at any time by using that facility or contacting us at jeremy@brizo.com.au. We will action opt-out requests promptly and at no cost.
We do not sell, rent or trade personal information to third parties for their marketing purposes.
08Disclosure of personal information
Confidentiality
Confidentiality is central to our work. We do not disclose your personal or business information to investors, acquirers or any counterparty without your prior written instruction. Where you instruct us to approach counterparties, disclosure occurs on the basis you approve, ordinarily subject to a confidentiality agreement.
We may otherwise disclose personal information to:
- (a) our personnel, contractors and professional advisers who need it to perform their role;
- (b) your own advisers (accountants, lawyers, bankers) where you have authorised this;
- (c) service providers who support our business, including cloud hosting, email and productivity platforms, scheduling and booking tools, virtual data room providers, accounting and invoicing software, customer relationship management systems, and analytics providers;
- (d) our insurers and professional indemnity advisers; and
- (e) a court, tribunal, regulator or government agency where required or authorised by law.
Where we engage service providers, we take reasonable steps to require them to handle personal information consistently with the APPs.
09Overseas disclosure
Some of our service providers store or process data outside Australia. Based on our current arrangements, the likely countries include the United States and other jurisdictions in which major cloud, email, scheduling and data room providers operate data centres, which may include the European Union, the United Kingdom and Singapore.
Before disclosing personal information to an overseas recipient we take steps reasonable in the circumstances to ensure the recipient does not breach the APPs, including through contractual commitments and by selecting providers with recognised security and privacy standards. Where practicable we select providers offering Australian data residency.
10Security, storage and retention
We hold personal information in electronic form on secured systems and, where relevant, in physical files at our premises. We take reasonable steps to protect it from misuse, interference and loss, and from unauthorised access, modification or disclosure. Measures include access controls and authentication, encryption in transit, restricted permissions on data rooms and shared files, confidentiality obligations on personnel, and secure disposal practices.
No method of transmission or storage is completely secure. Information you send us by email or over the internet is transmitted at your own risk.
Notifiable data breaches
If we become aware of unauthorised access to, disclosure of, or loss of personal information likely to result in serious harm, we will assess the incident and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by Part IIIC of the Privacy Act.
Retention
We retain personal information for as long as necessary for the purposes for which it was collected and to meet our legal, professional, insurance and record-keeping obligations — ordinarily at least seven years after an engagement ends. When no longer required, we destroy or de-identify it by secure means.
12Third-party links
The Website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites, and we encourage you to read their privacy policies.
13Accessing and correcting your personal information
You may request access to the personal information we hold about you, and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Requests should be made to jeremy@brizo.com.au.
We will require reasonable proof of identity. We aim to respond within 30 days. Access is generally provided free of charge, although we may charge a reasonable fee for the cost of retrieval and supply in the case of extensive requests (we will tell you before any fee is incurred).
We may refuse access or correction in limited circumstances permitted by the APPs — for example where granting access would unreasonably affect another person's privacy, relate to anticipated legal proceedings, or be unlawful. If we refuse, we will give you written reasons and explain how to complain. If we refuse to correct information, you may ask us to attach a statement noting your view, and we will take reasonable steps to do so.
14Complaints
If you believe we have breached the APPs or otherwise mishandled your personal information, please contact us first:
Privacy Officer
Brizo Cap Pty Ltd[POSTAL_ADDRESS]Email: jeremy@brizo.com.au
Please set out the nature of your complaint and how you would like it resolved. We will acknowledge your complaint promptly, investigate it, and respond in writing — ordinarily within 30 days.
If you are not satisfied with our response, you may refer the matter to the OAIC:
Office of the Australian Information Commissioner
GPO Box 10163, Sydney NSW 2001Phone: 1300 363 992Website: www.oaic.gov.au
15Changes to this policy
We may update this policy from time to time. The current version is always published at www.brizo.com.au with the "last updated" date shown above. Material changes will be highlighted on the Website.