About This Policy
Sidra Wealth Pty Ltd (ABN 11 693 910 600) (“Sidra Wealth”, “we”, “us”, “our”) is a financial advice practice. Financial advice is provided by Mounir Terfas (Authorised Representative No. 1318837), an authorised representative of PGW Financial Services Pty Ltd (AFSL 384713), operating through Sidra Wealth Pty Ltd (Corporate Authorised Representative No. 1320045).
We are committed to protecting your privacy and to handling your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and our obligations under the Corporations Act 2001 (Cth) and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
This policy explains how we collect, hold, use and disclose personal information:
- on our website, sidrawealth.com.au, including our contact and enquiry forms and our online booking page;
- on our secure client portal at portal.sidrawealth.com.au, where clients complete their risk profile and fact-find; and
- in the course of providing financial advice services.
In short: we collect only what we need to advise you well and to meet our legal obligations, we protect it carefully, and we never sell, rent or trade your personal information.
Anonymity and pseudonymity
You can browse our website without identifying yourself, and you may make a general enquiry using a pseudonym if you wish. However, if you become a client we are required by law (including the AML/CTF Act) to verify your identity, so we cannot provide financial advice services anonymously.
The Personal Information We Collect
The personal information we collect depends on how you deal with us. A website visitor asking a general question shares far less with us than a client receiving comprehensive advice.
If you contact us or book a consultation
- Your name, email address and phone number
- The topic of your enquiry and the message you send us
- If you book a consultation through our booking page, the appointment details you provide
If you become a client
- Identity information: full name, date of birth, gender, residential and postal addresses, and copies of identification documents we are required to verify under the AML/CTF Act
- Contact information: email address and phone numbers
- Government identifiers: Tax File Number (TFN), Medicare number, Centrelink Customer Reference Number (CRN) and Australian Business Number (ABN), where relevant to your advice
- Financial information: employment details, income, assets and liabilities, superannuation fund details and balances, investment holdings, insurance policies, and Centrelink benefits and entitlements
- Estate planning information: will and power of attorney status, and beneficiary nominations
- Risk profile: your responses to our risk profile questionnaire and your assessed risk category
Sensitive information
Some of what we collect may be “sensitive information” under the Privacy Act, and we collect it only with your consent:
- Health information, where it is relevant to personal insurance advice (for example, life, disability, trauma or income protection cover)
- Your values, beliefs or faith-based preferences, where you choose to share them so that we can align our advice and investment screening with them
We use sensitive information only for the purpose for which you provided it.
Technical information
When you use our website or client portal, we automatically collect technical data such as your IP address, browser type, pages visited, session timestamps and activity logs. Cookies and analytics are explained in the “Our Website, Cookies and Analytics” section below.
Unsolicited information
If we receive personal information we did not ask for and determine we could not have collected it under the APPs, we will destroy or de-identify it as soon as practicable, where it is lawful to do so.
How and Why We Collect It
How we collect
- Directly from you: in meetings and phone calls, by email, through the forms on our website, through our booking page, and through the risk profile and fact-find you complete on our client portal
- From third parties you authorise: such as your accountant, lawyer, superannuation fund, insurer or investment platform, when you ask us to obtain information on your behalf
- Automatically: technical data collected when you use our website or portal
We will not collect personal information about you without your knowledge or consent unless it is required or authorised by law.
Why we collect
We collect, hold and use your personal information to:
- understand your objectives, financial situation and needs, and provide you with personal financial advice
- prepare your Statement of Advice and other advice documents
- assess your risk profile and the suitability of strategies and products
- implement advice you have agreed to, including arranging products with providers
- verify your identity as required under the AML/CTF Act
- meet our record-keeping, supervision and reporting obligations under the Corporations Act and our arrangements with our licensee
- respond to your enquiries, manage bookings and administer our relationship with you
We use or disclose your personal information for another purpose only where you have consented, where you would reasonably expect it and it is related to the primary purpose, or where it is required or authorised by law.
Direct marketing
We may send you information about our services and insights where you have asked for it or would reasonably expect it. You can opt out at any time by using the unsubscribe link in the communication or by contacting our Privacy Officer, and we will stop promptly.
We never sell, rent or trade your personal information to anyone for marketing purposes.
Tax File Numbers and Government Identifiers
We take special care with your Tax File Number, as required by the Taxation Administration Act 1953 (Cth) and the Privacy (Tax File Number) Rule 2015:
- Providing your TFN is voluntary. You are not required to give it to us.
- If you choose not to provide it, we may not be able to complete certain parts of your financial plan, and tax may be withheld from some investment income at a higher rate.
- We use your TFN only for lawful purposes connected with your financial advice, superannuation, investments and taxation, and we disclose it only as permitted by taxation, superannuation or related law (for example, to your superannuation fund at your direction).
- We protect it. On our client portal your TFN is encrypted at rest and masked on screen.
In accordance with APP 9, we do not use government identifiers such as your TFN, Medicare number or CRN as our own identifier for you, and we use or disclose them only as permitted by law.
Our Website, Cookies and Analytics
Analytics and advertising
Our website uses Google Tag Manager to manage measurement and advertising tags. Through it we use:
- Google Analytics 4, which uses cookies to help us understand how visitors use our site (pages visited, time on site, approximate location derived from your IP address). This information is aggregated and does not identify you to us.
- Google Ads, including remarketing tags, which may be used to measure our advertising and to show you our ads on other websites after you visit ours.
You can manage or refuse cookies in your browser settings, opt out of Google Analytics using Google’s opt-out browser add-on (tools.google.com/dlpage/gaoptout), and control ad personalisation at adssettings.google.com. These services are provided by Google LLC and are subject to Google’s own privacy policy.
Booking a consultation
Our booking page uses Google Calendar’s appointment scheduling service. When you book, the details you enter (such as your name, email address and chosen time) are collected by Google and shared with us to manage your appointment, and are handled by Google under Google’s privacy policy.
Embedded media and links
Some media on our website is delivered through Cloudinary, a content delivery service, which receives technical data such as your IP address in order to serve the content. Our website may also link to third-party websites; we are not responsible for their privacy practices, and we encourage you to read their policies.
The Client Portal
If you engage us (or ask to begin the process), we will invite you to our secure client portal at portal.sidrawealth.com.au to complete your risk profile and fact-find, and to upload supporting documents. The portal is built with security at its core:
- Passwordless sign-in: you access the portal through secure, time-limited links sent to your email address, so there is no client password to steal; only a cryptographic hash of each link’s token is stored
- Session protection: sessions expire after 30 minutes of inactivity and 4 hours overall
- Encryption in transit: all traffic between your browser and the portal is encrypted using TLS (HTTPS)
- Encryption at rest: highly sensitive fields, including your TFN, Medicare number and CRN, are additionally encrypted at field level using AES-256 encryption
- Australian data residency: the portal database is hosted with Supabase in the Sydney, Australia region
- Controlled uploads: document uploads are limited to PDF and image formats, capped at 10 MB, and stored in a private storage bucket
- Audit trail: an append-only audit log records significant actions on your file
How We Hold and Protect Your Information
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification or disclosure.
- Website enquiries are transmitted over encrypted connections (HTTPS), stored in a secure database, and forwarded to your adviser by email so we can respond to you.
- Client records are held in our practice systems, including reputable cloud services (such as Google Workspace) protected by access controls, with access limited to your adviser and those who need it to support your advice.
- Portal data is protected by the safeguards described in “The Client Portal” above.
No method of transmission or storage is completely secure. If you suspect any misuse or loss of your personal information, please contact our Privacy Officer immediately.
How long we keep it
| Records | How long we keep them |
|---|---|
| Advice records (fact-find, risk profile, advice documents, file notes) | At least 7 years after our advice relationship ends, as required under the Corporations Act |
| Identity verification records | At least 7 years after our relationship ends, as required under the AML/CTF Act |
| Website enquiries and leads | Only as long as needed to respond and to keep ordinary business records |
| Audit and technical logs | As long as needed for security, compliance and dispute resolution |
When personal information is no longer needed for any purpose for which it may lawfully be used or disclosed, and we are no longer required to retain it, we take reasonable steps to destroy or de-identify it.
Notifiable data breaches
If a data breach occurs that is likely to result in serious harm to you, we will act in accordance with the Notifiable Data Breaches scheme in the Privacy Act: we will take immediate steps to contain and assess the breach, and notify you and the Office of the Australian Information Commissioner (OAIC) where the law requires it.
Who We Share It With
We disclose your personal information only where it is necessary for your advice, where you have authorised it, or where the law requires it:
- Our licensee, PGW Financial Services Pty Ltd (AFSL 384713), for supervision, compliance, audit and complaints handling connected with the advice we provide as its authorised representative
- Product providers, such as superannuation funds, investment platforms and insurers, where needed to implement advice you have accepted or to obtain information you have authorised us to collect
- Professional advisers you authorise, such as your accountant or lawyer
- Regulators and government bodies, including ASIC, the ATO and AUSTRAC, where required or authorised by law
- Service providers that help us run our practice, such as website and database hosting, email delivery, appointment scheduling and productivity software, under arrangements that restrict their use of your information to providing those services
- The Australian Financial Complaints Authority (AFCA) or other dispute resolution bodies, if needed to deal with a complaint
Overseas disclosure
Your client file and the portal database are held in Australia. Some of the technology providers we use, however, are based overseas or may store limited data on servers outside Australia (for example, in the United States):
- Google LLC (United States): website analytics and advertising, appointment scheduling, and practice productivity services
- Resend Inc. (United States): delivery of transactional emails, such as enquiry notifications and secure portal sign-in links
- Website hosting and content delivery providers, whose infrastructure may process website enquiry data and technical data outside Australia
In accordance with APP 8, before disclosing personal information to an overseas recipient we take reasonable steps to ensure it will be handled consistently with the APPs, and we remain accountable for it. We do not otherwise send your personal information overseas without your consent unless the law permits it.
Access, Correction and Complaints
Access and correction
You may ask us at any time for access to the personal information we hold about you (APP 12) or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). To do so, contact our Privacy Officer using the details at the end of this policy. We will:
- acknowledge your request within 7 days;
- respond within 30 days;
- provide access in the manner you request where it is reasonable and practicable to do so; and
- give you written reasons if we refuse access or correction, together with the complaint options available to you.
There is no fee for making a request or for correcting your information. If compiling access to your information requires substantial effort, we may charge a reasonable fee for providing it, and we will tell you the amount before we proceed.
Privacy complaints
If you believe we have mishandled your personal information or breached the APPs:
- Contact our Privacy Officer using the details at the end of this policy. We will acknowledge your complaint within 7 days and aim to investigate and respond within 30 days.
- Office of the Australian Information Commissioner (OAIC). If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au or on 1300 363 992.
Complaints about our services
Complaints about the financial services we provide are handled under the process in our Financial Services Guide: raise the matter with your adviser, or write to our licensee, PGW Financial Services Pty Ltd, GPO Box 2241, Brisbane QLD 4001. If your complaint is not resolved to your satisfaction, you can contact the Australian Financial Complaints Authority (AFCA), of which PGW Financial Services is a member, at afca.org.au or on 1800 931 678.
Changes and Contact
Changes to this policy
We may update this policy from time to time to reflect changes in our practices, technology or the law. The current version is always available at sidrawealth.com.au, and the version date below is revised whenever the policy changes. Where a change is significant, we will take reasonable steps to bring it to your attention.
Contact us
Privacy Officer
Sidra Wealth Pty Ltd
ABN 11 693 910 600
Email: privacy@sidrawealth.com.au
Phone: (02) 9053 0615
Address: 5 Martin Place, Sydney NSW 2000
Website: www.sidrawealth.com.au
Licensee: PGW Financial Services Pty Ltd (AFSL 384713), Level 19, 144 Edward Street, Brisbane City QLD 4000
You can also request a copy of this policy free of charge by contacting us.
This policy was last updated on 31 July 2026 (Version 2.0). It replaces the March 2026 edition.