Privacy Policy
Gresham Partners Group Limited (ABN 75 003 856 933) and its wholly owned subsidiaries (together, Gresham) respect the privacy of people we deal with and are committed to protecting the information provided to us by clients, employees, contractors, service providers, visitors to this website and other persons. This Privacy Policy explains how Gresham handles personal information and complies with the requirements of the Privacy Act 1988 (Cth) (as amended) (Privacy Act), including the Australian Privacy Principles (APPs). If you have any questions relating to this policy, please e-mail privacy@gresham.au.
1. Collecting information about you
Gresham may collect personal information from clients, investors, shareholders and other individuals, including employees, contractors, job applicants and website visitors.
“Personal information” is information or an opinion relating to a natural person who is identified or reasonably identifiable. We collect this information when it is necessary for our business purposes.
“Sensitive information” is a specific category of personal information and includes information or an opinion about an individual’s racial or ethnic origin, political opinions, membership of a political association, religious beliefs or affiliations, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, and biometric or genetic information. Gresham will only collect sensitive information where it is reasonably necessary for our functions, and with your consent or as otherwise permitted by law.
Types of personal information we collect
The main types of personal information Gresham collects are:
- identifying information, such as your name and date of birth;
- contact information, such as your address, email address and telephone number; and
- financial details, such as your investments and transactions with us.
In some circumstances, we are authorised by tax laws or the Privacy Act to collect other information about you, such as your securityholder reference number (SRN) or tax file number (TFN).
Anti-money laundering and counter-terrorism financing compliance
We may be required to collect and use your personal data in order to comply with applicable anti-money laundering and counter-terrorism financing laws. These laws include, in relation to Australia, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth).
These obligations may require that we collect and verify information regarding you, your organisation and individuals associated with your organisation, or acting on yours or your organisation’s behalf. We may collect this information at the time when you first become a client and throughout our ongoing relationship. The information we obtain is required to meet our legal obligations and to enable us to conduct our customer or client due diligence process.
Depending on how your organisation is structured, the personal data we collect may include personal data regarding directors, partners, beneficial owners and others, such as:
- identity and contact details;
- information supporting verification of identity (such as driver’s licences, passports or other government-issued identification);
- your role, position or relationship with your organisation or another organisation;
- directorships and other officeholder positions;
- background checks and associated details including sanctions screening and politically exposed person screening information;
- sensitive information including criminal history details and information regarding political allegiances or affiliations; and
- other information that facilitates compliance with our anti-money laundering and counter-terrorism financing obligations.
How we collect information
We collect most of the above information directly from you where possible. This information may be provided by you in forms you fill out (including online), in face-to-face meetings, in e-mail messages you send us, via our website, or during telephone conversations. In some cases we may collect your personal information from:
- publicly available sources of information, such as public registers, LinkedIn and other online networks or platforms;
- our service providers, such as credit reporting bodies and companies that provide fraud prevention reports, identity verification or due diligence services;
- other organisations that, jointly with us, administer a Gresham managed fund;
- your agents and delegates, such as a broker, legal representative, or persons holding a power of attorney; or
- a bank.
If you contact us, we may keep a record of that contact.
When you use our website, we may collect other information about you, such as your IP address and information stored in cookies.
If you do not provide us with personal information we request from you, we may be unable to provide you with our full range of services.
2. Using and disclosing your personal information
When we may use your personal information
Gresham’s purpose in collecting, holding, using and disclosing information about you is generally: to provide you with information or services that you request; for a reasonably expected secondary purpose; as permitted under the law, including the Privacy Act; and as otherwise specified in this Privacy Policy. We may use your personal information for:
- any purpose for which you consent;
- offering and providing products or services to you (including to your organisation);
- administering and managing products and services for you (including your organisation);
- operating and carrying on Gresham’s business;
- conducting a client, investor, employment, or contractual relationship with you;
- undertaking risk management functions as part of our operations;
- providing you with information about Gresham and its products and services;
- conducting a client survey regarding our products and services (including potential products and services) or performance;
- communicating with you to manage any enquiries or complaints; or
- otherwise, in connection with Gresham carrying out its business or operations.
When we may disclose your personal information
In some cases, we may be required to disclose your personal information to regulators, such as AUSTRAC, ASIC or the Australian Taxation Office.
We use service providers to help us maximise the quality and efficiency of our services and our business operations. This means individuals and organisations outside of Gresham, such as IT service providers, registry and fund administration providers, website hosts and back-up service providers, cloud service providers, and AI platform operators, will sometimes have access to personal information held by Gresham and may use it on behalf of Gresham. We require our service providers to adhere to strict privacy guidelines and only use this information for authorised purposes.
Gresham may also disclose your personal information:
- to fulfil our legal and regulatory obligations, in Australia or any other jurisdiction, including but not limited to statutory and regulatory requirements, reporting, taxation, audit requirements, anti-money laundering, counter-terrorism financing and sanctions requirements, or in connection with legal or investigative proceedings;
- to a third party for a legal or regulatory requirement or request; or in accordance with laws, regulations, or the rules of any relevant exchange, depository or clearing house;
- to our financial institution and any financial institution or intermediary with which you or your organisation engage or propose to engage in connection with our services;
- to our officers, employees, agents, subcontractors, advisers, auditors, insurers, consultants and associates in connection with the conduct of our business, as permitted by law, or
- as outlined in the terms and conditions of any specific products or services (such as our Gresham managed funds) or in our terms of engagement with you.
In connection with our business operations, personal information held by Gresham may be disclosed to, or processed by, recipients located outside Australia. This includes our use of third-party technology, cloud computing, software-as-a-service and AI enterprise tool providers, which may store or process data in overseas locations including the United States, United Kingdom, Singapore and New Zealand.
Where we disclose personal information to overseas recipients, Gresham takes reasonable steps to protect that information. The nature of those steps depends on the circumstances and may include: entering into contractual data protection obligations with the recipient where practicable; selecting providers that maintain recognised global security certifications; reviewing the recipient’s published privacy and data security terms; and using available data governance and residency controls offered by the provider. Where it is not practicable to negotiate specific data residency or privacy terms — for example, with major established cloud infrastructure, software-as-a-service or AI enterprise platform providers — Gresham conducts due diligence of the provider’s published terms, applicable regulatory frameworks, and security certifications as its reasonable steps.
3. Employee information
Employee records are not generally subject to the Privacy Act, and therefore this Privacy Policy does not apply to the handling of information about employees by Gresham. For information about our practices relating to employee information, please contact us directly.
4. Job applicants
If you apply for a job at Gresham, we may collect personal information from you or from recruitment agencies for the purpose of assessing and processing your application. This information may include your name and contact details, information about your previous and current employment, and other information relating to your suitability for employment. In some circumstances and if you consent, Gresham may collect sensitive information about you, such as information about your health, membership of a professional or trade association, or criminal record, where appropriate and where this is reasonably necessary for one of our functions or activities.
5. Marketing
When you provide your personal information to us, we may use this information, such as your email address or telephone number, to contact you on an ongoing basis in order to:
- provide you with updated information about our products and services; or
- provide you with information about other products and services which you may have an interest in.
If you are receiving promotional information about Gresham and do not wish to receive this information any longer, you may remove your name from our mailing list either by e-mailing us at privacy@gresham.au and asking to be removed from our mailing list.
6. Our website privacy practices
We sometimes use cookie technology on our website to provide information and services to website visitors. Cookies are pieces of information that a website transfers to your computer’s hard disk for record keeping purposes and are a necessary part of facilitating online transactions. Most web browsers are set to accept cookies. Cookies are useful to estimate the number of visitors and determine overall traffic patterns through our website.
If you do not wish to receive any cookies you may set your browser to refuse cookies. This may mean you will not be able to take full advantage of the services on the website.
For the purposes of viewing certain parts of our website, you may be required to provide log-in information. You are responsible for the security and confidentiality of this information.
7. Artificial intelligence and technology tools
Gresham may use certain commercially available artificial intelligence tools and services – including machine learning, generative AI and other forms of automated processing (together, AI) – to help deliver its services, and carry out its business and administrative operations. Examples of activities for which AI may be used include conducting research, analysing and summarising documents and data, preparing drafts of written material, and the automation of routine administrative tasks. Where we use AI in this way, the personal information that you provide to us, or that we hold about you, may be processed using those AI tools. Personal information that is generated or inferred about you by an AI tool is treated as personal information for the purposes of this Privacy Policy and the Privacy Act.
Where personal information is processed by or input into AI tools, Gresham takes reasonable steps to ensure that:
- AI tools are deployed under enterprise terms that include appropriate privacy and security protections;
- your personal information will not be used to train third-party AI models without Gresham’s express authorisation;
- AI-generated outputs containing personal information are reviewed by Gresham staff before being relied upon; and
- sensitive personal information is not entered into publicly available AI tools (such as consumer-facing AI chatbots).
Gresham does not use AI tools to make decisions, solely or substantially in an automated manner, that could reasonably be expected to significantly affect your rights or interests.
Some AI tools are provided by third parties and may involve the storage and processing of personal information on servers located outside Australia (including, without limitation, in the United States). The section above headed “Using and disclosing your personal information” applies to any such disclosure.
8. Storage and security of your personal information
Gresham will take such steps as are reasonable in the circumstances to protect the personal information we hold about you from misuse, interference and loss, and from unauthorised access, modification or disclosure. keep secure any personal information which we hold about you, and to keep this information accurate, up-to-date and complete.
Personal information may be stored in, or processed using, cloud services or AI platforms managed by third-party providers, including providers located or operating overseas. We evaluate cloud service providers to ensure they maintain appropriate controls to protect the confidentiality, integrity and availability of personal information and we require those providers to be bound by appropriate confidentiality and data protection obligations.
No data transmission over the internet can be guaranteed to be 100% secure, so Gresham cannot give an absolute assurance that the information you provide to us via the internet will be secure at all times. If a data breach occurs that is likely to result in serious harm to affected individuals, Gresham will notify those individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
9. You can access the information we keep about you
If at any time you want to know what personal information we hold about you, you are welcome to request access to your record by e-mailing us at privacy@gresham.au. We will respond to a request for access within a reasonable time after the request is made, and we will provide access to the personal information we hold in the manner you request, where it is reasonable and practicable to do so. .
10. Correcting your personal information
If at any time you wish to correct the personal information we hold about you, please contact us by e-mailing us at privacy@gresham.au.
If you request us to correct any inaccurate personal information we may have about you or request us to restrict our ongoing use of your personal information, we will do if this if practicable and we are legally entitled to do so in the circumstances.
Where we no longer require personal information we hold about you for any purpose for which it may be used or disclosed under this Privacy Policy, and we are not required to retain it under any law, we will take reasonable steps to destroy or de-identify that information. If you would like us to review whether personal information we hold about you should be destroyed or de-identified, please contact us at privacy@gresham.au.
11. What to do if you have a complaint or question
You may contact us by e-mailing us at privacy@gresham.au if you have a complaint about a breach of the APPs or any privacy code which may bind us or how we have handled your personal information.
If Gresham becomes aware of any ongoing concerns or problems concerning our privacy practices, we will contact you about the issue, investigate the issue, and take all reasonable steps to work with you to resolve the issue. If you are dissatisfied with the response that you receive from us, you may make a complaint to the OAIC.