Legal
Privacy Policy
How we collect, use, disclose and protect personal information — including credit-related information — in the course of our commercial lending.
GreyRok Capital Pty Ltd ABN 55 699 478 067 ACN 699 478 067 (Company, we, us or our) is committed to protecting your personal information.
This Privacy Policy explains how we manage personal information and how to contact us if you have any further queries about how we do this. This Policy does not apply to how we handle personal information about our employees.
Background
We are a short-term commercial lender providing secured and unsecured loans to companies and sole traders for business purposes (Lending Services). In the course of providing our Lending Services, we collect and handle personal information about individuals including:
- directors, officers, shareholders and other authorised representatives of borrower entities;
- guarantors (including personal guarantors) of borrower obligations;
- sole traders who borrow for business purposes; and
- other individuals whose personal information is provided to us in connection with a loan application or ongoing loan management (including ultimate beneficial owners of a borrower entity)
(together, Relevant Individuals).
Functions
Our principal function is the provision of short-term commercial loans to companies and sole traders. In connection with this function, we assess loan applications, conduct credit and identity checks, manage loan accounts, enforce our security interests, and comply with our regulatory obligations including under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
In undertaking our functions and activities we may handle personal information about Relevant Individuals. We comply with the thirteen Australian Privacy Principles (APPs) in the Privacy Act 1988 (Cth) (the Act) except where the Act does not require this. The APPs regulate how to handle personal information throughout its life cycle, from collection to use and disclosure, storage, accessibility and disposal.
Personal information is information or an opinion, in any form and whether true or not, about an identified individual or an individual who is reasonably identifiable. Special rules apply for collecting personal information which is sensitive information. This includes health information and information about a person’s race, ethnic origin, political opinions, membership of political, professional or trade associations, religious or philosophical beliefs, sexual orientation or practices and criminal history.
The kind of personal information we collect and hold
Depending on the nature of your relationship with us (for example, whether you are a sole trader borrowing from us, or a director or officer of a borrower, or a guarantor), we may collect one or more of the following items of personal information:
- your full name, date of birth, residential address, postal address, email address and telephone number;
- your position or role in relation to the borrower entity (e.g. director, officer, shareholder, secretary, beneficial owner or guarantor);
- information contained in identification documents (such as passport, driver’s licence, or other government-issued identity documents) for the purposes of identity verification under the AML/CTF Act;
- financial information including business financial statements, bank statements, tax returns, details of assets and liabilities, and income information relevant to your capacity as a guarantor or sole trader borrower;
- details of your shareholding or beneficial ownership interest in a borrower entity;
- information about your business activities, industry, and business history (where you are a sole trader or director of a borrower);
- information obtained from credit reporting bodies, including credit reports, credit scores, and credit history;
- information obtained from commercial credit reporting bureaus, including business credit reports, payment default and court action data, and business risk scores;
- information obtained from our AML/CTF identification verification and screening service provider, including the results of identity verification checks, Politically Exposed Person (PEP) screening, sanctions screening, and adverse media checks;
- communication records (such as correspondence, telephone calls and emails in relation to your loan application or account);
- information about your criminal history or any involvement in fraud, money laundering or terrorism financing (where permitted or required by law); and
- any other information you or the borrower voluntarily provides to us in connection with a loan application or the ongoing management of a loan.
How we collect and hold personal information
To the extent required by the Act:
- we will not collect personal information about you unless that information is reasonably necessary for one or more of our functions or activities; and
- we will collect personal information only by lawful and fair means.
When we collect personal information directly from you, we will take reasonable steps at or before the time of collection to ensure that you are aware of certain key matters, such as the purposes for which we are collecting the information, the organisations (or types of organisations) to which we would normally disclose information of that kind, the fact that you are able to access the information and how to contact us.
The purposes for which we handle personal information
If we use or disclose your personal information for a purpose (the “secondary purpose”) other than the main reason for which it was originally collected (the “primary purpose”), to the extent required by the Act, we will ensure that:
- the secondary purpose is related to the primary purpose of collection (and directly related in the case of sensitive information), and you would reasonably expect that we would use or disclose your information in that way;
- you have consented to the use or disclosure of your personal information for the secondary purpose;
- the use or disclosure is required or authorised by or under law; or
- the use or disclosure is otherwise permitted by the Act (for example, as a necessary part of an investigation of suspected unlawful activity).
The purpose for which we use your personal information depends on your relationship with us. We may use and disclose your personal information for one or more of the following purposes.
Specific purposes of collection, use and disclosure
We may use and disclose your personal information for the following purposes:
- to assess and process loan applications, including assessing the creditworthiness of a borrower, guarantor or sole trader;
- to verify the identity of Relevant Individuals in accordance with our obligations under the AML/CTF Act, including by disclosing personal information to our AML/CTF identification verification and screening service provider;
- to conduct ongoing customer due diligence, including transaction monitoring, PEP screening, sanctions screening and adverse media checks, as required by the AML/CTF Act;
- to manage and administer existing loan accounts, including processing repayments, managing arrears, and enforcing our rights under loan agreements and security documents;
- to obtain and assess credit reports and other credit-related information from credit reporting bodies;
- to obtain and assess commercial credit reports and business risk information from commercial credit reporting bureaus;
- to disclose information to credit reporting bodies about your credit account and repayment history in accordance with Part IIIA of the Act;
- to comply with our reporting obligations under the AML/CTF Act, including by making reports to the Australian Transaction Reports and Analysis Centre (AUSTRAC);
- to respond to requests from law enforcement agencies, regulatory bodies, or as otherwise required or authorised by law;
- to disclose personal information to our professional advisers, including lawyers, accountants and auditors;
- to disclose personal information to debt collection agents or legal service providers in connection with the recovery of amounts owed to us;
- to manage any complaints, disputes or legal proceedings; and
- for any other purpose that is related to our Lending Services and that you would reasonably expect.
Disclosure to our AML/CTF service provider
We use a third-party service provider to assist us in meeting our customer identification and verification obligations under the AML/CTF Act (AML/CTF Service Provider). Our AML/CTF Service Provider is Equifax Australia Information Services and Solutions Pty Limited (ABN 26 000 602 862) (Equifax), which provides identity verification and screening services through its IDMatrix product (www.equifax.com.au/idmatrix).
We disclose personal information (including your name, date of birth, address, and identification document details) to our AML/CTF Service Provider for the purposes of:
- verifying your identity against government-issued identity documents and other reliable data sources;
- conducting screening against sanctions lists, PEP databases, and law enforcement watchlists; and
- conducting adverse media checks relevant to money laundering, terrorism financing, fraud, or other serious criminal activity.
Equifax is also one of the credit reporting bodies to which we may disclose, and from which we may obtain, credit information about you (see Disclosure of credit information to CRBs below). The personal information we disclose to Equifax for identity verification and screening purposes under the AML/CTF Act is disclosed for a separate purpose from credit reporting, and is dealt with in this section of our Privacy Policy rather than in our Credit Reporting Privacy Policy.
Our AML/CTF Service Provider may retain personal information in accordance with its own privacy policy and legal obligations. Equifax’s privacy policy is available at www.equifax.com.au/privacy and its credit reporting policy at www.equifax.com.au/credit-reporting-policy. The results of identity verification and screening checks conducted by our AML/CTF Service Provider are disclosed back to us and held as part of your file.
Data quality and security
To the extent required by the Act, we will take reasonable steps to:
- make sure that the personal information that we collect, use and disclose is accurate, complete, and up to date;
- protect the personal information that we hold from misuse, interference and loss and from unauthorised access, modification or disclosure; and
- destroy or permanently de-identify personal information that is no longer needed for any purpose that is permitted by the Act (subject to any record-keeping requirements under the AML/CTF Act or other applicable laws).
The reasonable steps we take for the purposes of ensuring the security of personal information include both technical and organisational measures.
Transfer of personal information overseas
We may transfer personal information overseas in the course of using service providers (including our AML/CTF Service Provider and cloud-based IT systems) whose facilities may use computer servers located outside Australia. It is not always practicable for us to specify where those computer servers are based. If we transfer personal information in this way, we will take reasonable steps to ensure that any overseas recipient does not breach the APPs in relation to the disclosed personal information.
This obligation will not apply if:
- we reasonably believe that the recipient of the information is subject to legal obligations that have the effect of protecting the information in a way that, overall, is at least substantially similar to protection under the APPs and there are mechanisms that you can access to enforce that protection;
- you give us consent to disclose your personal information to an overseas recipient, expressly or by implication, after you are expressly informed by us that if you consent we will not be required to take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information; or
- we are legally authorised to do so.
Access and correction of your personal information
Please contact our Privacy Officer at admin@greyrokcapital.com if you would like to access or correct the personal information that we hold about you. We will generally provide you with access to your personal information if practicable (although a fee may be imposed) and will take reasonable steps to amend any personal information that is incorrect. In some circumstances, we may not permit access to your personal information, or may refuse to correct your personal information, in which case we will provide you with reasons for this decision.
Questions or complaints
Please contact our Privacy Officer at admin@greyrokcapital.com if you have any questions or complaints about the personal information that we hold about you or the way we handle that personal information. We will acknowledge your question or complaint as soon as possible and will seek to address any question or complaint within 14 days after that.
Notifiable data breaches
If there is a loss, or unauthorised access or disclosure of your personal information that is likely to result in serious harm to you, we will investigate and notify you and the Australian Information Commissioner as soon as practicable, in accordance with the Act.
Automated decisions
This section of the policy applies if:
- we have arranged for a computer program to make, or do a thing that is substantially and directly related to making, a decision; and
- the decision could reasonably be expected to significantly affect the rights or interests of an individual; and
- personal information about the individual is used in the operation of the computer program to make the decision or do the thing that is substantially and directly related to making the decision.
We use a proprietary, internally developed credit assessment system that scores and ranks loan applications to assist our credit team in making lending decisions. The system does not make final credit decisions — all approvals and declines are made by our credit staff. The following information about our automated processing is provided in accordance with the Act:
- Personal information used: business financial statements, bank statements, business turnover, length of time in trading, number of dishonours and defaults on record, individual credit scores of directors, guarantors or sole traders, and results of identity verification and AML/CTF screening checks; and
- Decisions made solely by the system: none — all credit decisions are made by our credit staff; and
- Decisions substantially assisted by the system: loan approval and decline decisions — the system produces a score and ranking for each application that is used by our credit team as an input to their assessment.
Part two
Credit Reporting Privacy Policy
This section of our Privacy Policy applies to our activities as a credit provider under Part IIIA of the Privacy Act 1988 (Cth) and the Privacy (Credit Reporting) Code 2025 (CR Code). It explains how we manage credit-related personal information, including credit information and credit eligibility information (together, credit-related information). This section should be read together with the rest of our Privacy Policy.
Credit checks
If you make an application to the Company for credit, or you are a guarantor for a borrower applying for credit, the Company can do a credit check without asking for your consent. A credit check is when the Company asks a Credit Reporting Body (CRB) for information about the loans you’ve applied for and taken out in the past, and how you’ve managed those loans. The CRB will record the fact that the Company has done a credit check. This will show on your credit report as a ‘credit enquiry’ and may be disclosed to other credit providers to assist them in assessing your credit worthiness or used in the calculation of your credit score by the CRB.
When a credit enquiry is recorded on your credit report, it can affect your credit score in different ways. It might go up, down, or stay the same. This depends on factors like the type of credit you’re applying for, how many other credit checks you’ve had recently, and other details in your report. An enquiry is more likely to lower your credit score if you make a lot of credit applications in a short time.
Types of credit-related information we collect and disclose
In our capacity as a credit provider, we may collect, hold, use and disclose the following types of credit-related information about you:
- identification information (such as your name, address, date of birth and employer);
- financial hardship information (information about financial hardship arrangements);
- default information (information about overdue payments of 60 days or more where specific conditions are met);
- new arrangement information (information about new credit arrangements following a default);
- payment information (information that an overdue amount in relation to a default has been paid);
- court proceedings information (information about credit-related court judgments);
- personal insolvency information (information about bankruptcies or debt agreements);
- publicly available information relating to your credit worthiness; and
- credit eligibility information (information disclosed to us by a CRB, including credit scores derived from credit reporting information held by the CRB).
Disclosure of credit information to CRBs
We may disclose credit information about you to, and collect credit information about you from, the following CRBs:
Equifax Australia Information Services and Solutions Pty Limited
ABN 26 000 602 862 · Equifax Public Access, GPO Box 964, North Sydney NSW 2059
Telephone 13 83 32 · www.equifax.com.au
Credit reporting policy: www.equifax.com.au/credit-reporting-policy
Experian Australia Credit Services Pty Ltd
ACN 150 305 838, which now incorporates illion · Experian Public Access Centre, PO Box 7405, St Kilda Road, Melbourne VIC 3004
Telephone 1300 783 684 · www.experian.com.au
Credit reporting policy: experian.com.au/privacy-policy-terms-conditions
You can contact the CRBs listed above to obtain a copy of your credit report, request a correction, or ask the CRB not to use your credit reporting information for the purposes of pre-screening or direct marketing by a credit provider. You may also request that a CRB not use or disclose your credit reporting information for a period if you believe on reasonable grounds that you have been, or are likely to be, a victim of fraud (a ban period).
Commercial credit reporting bureaus
We also use a commercial credit reporting bureau to obtain and, where relevant, report commercial credit information about borrower entities and sole traders, including payment defaults, court actions, insolvency notices and business risk scores. That bureau is:
Creditor Watch Pty Limited trading as CreditorWatch
ACN 144 644 244 · GPO Box 276, Sydney NSW 2001
Telephone 1300 50 13 12 · privacy@creditorwatch.com.au · www.creditorwatch.com.au
Commercial credit information is not regulated by Part IIIA of the Act or the CR Code. Where commercial credit information includes personal information about you — for example, because you are a sole trader, or because your details appear in a commercial credit report as a director or guarantor — we handle that information in accordance with the APPs and the balance of this Privacy Policy. You can contact CreditorWatch directly using the details above to request access to, or correction of, information it holds about you.
Purposes for which we use and disclose credit-related information
We may use and disclose your credit-related information for the following purposes:
- to assess your application for credit or the credit application of a borrower for which you are a guarantor;
- to manage an existing credit account, including collecting overdue payments;
- to assist you if you notify us that you are experiencing financial hardship;
- to deal with a serious credit infringement that you may have committed; and
- as otherwise permitted or required by the Act or the CR Code.
For example, if you fail to meet your payment obligations to us in relation to consumer credit, if you commit a serious credit infringement in relation to consumer credit provided by us, or if you enter into a financial hardship arrangement, we may be entitled to disclose this information to CRBs.
Access to and correction of credit-related information
You may request access to the credit-related information we hold about you, or ask us to correct that information, by contacting our Privacy Officer at admin@greyrokcapital.com. We will respond to access and correction requests within the timeframes required by the Act and the CR Code. If we refuse to provide access or make a correction, we will provide you with written reasons and information about how you can make a complaint.
Complaints about credit reporting
If you have a complaint about how we have handled your credit-related information, please contact our Privacy Officer at admin@greyrokcapital.com. We will acknowledge your complaint within 7 days and will investigate and respond to your complaint within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Australian Information Commissioner at www.oaic.gov.au.
Security of credit-related information
We will take reasonable steps to protect credit-related information from misuse, interference and loss, and from unauthorised access, modification or disclosure. We will destroy or de-identify credit-related information that is no longer needed for any purpose permitted by the Act or the CR Code.
Changes
We may change this Privacy Policy from time to time. The current version of this Policy is available at www.greyrokcapital.com and will be made available upon request by contacting our Privacy Officer at admin@greyrokcapital.com.
Contact us
If you have any queries about our Privacy Policy, or about the way we manage your personal information, you can:
- email us at admin@greyrokcapital.com; or
- visit our website at www.greyrokcapital.com.