Privacy Policy

March 2026

1. INTRODUCTION

Koda Capital Pty Ltd ("Koda") understands that individuals may be concerned about how we deal with their personal information. Our aim is to deliver the best possible service, and we will only collect the information necessary to enable us to do so.

2. OBJECTIVE

The purpose of this Privacy Statement (Statement) is to ensure that Koda provides open and transparent advice to individuals about the way in which any personal information that is collected and held by Koda is appropriately managed, and to ensure that Koda meets the standards and requirements set by the Privacy Act 1988 (Cth) (Privacy Act) and Australian Privacy Principles (APPs).

This Statement is in a format to be distributed to individuals through a website link.

3. OVERVIEW

3.1 What Personal Information is collected?

The types of personal information that are collected and held by Koda includes information used to identify the client, their financial position and any other related information necessary to provide the client with business services. This may include, but is not limited to:

  • name;
  • contact details;
  • bank account information;
  • tax file number;
  • passport or drivers’ licence;
  • nationality;
  • business structures;
  • employment information;
  • source of wealth; and
  • investment information.

In addition, Koda is required to collect and hold personal information under the Anti-Money Laundering and Counter Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and the Foreign Account Tax Compliance Act 2010 (USA), which may include sensitive information in certain circumstances.

As part of our recruitment process, we may collect personal information from potential employees and their referees. We may also collect sensitive information about potential employees as part of a background checking process. With consent, this information may be disclosed to and obtained from third party agencies that we engage to conduct probity checks on our behalf.

Unless otherwise advised by a potential candidate, we may keep information on file for any future vacancies.  Candidates can request at any time, in writing to the Head of Human Resources, for us to destroy their personal information.

3.2 Consent

Koda will collect, use, and disclose personal information in accordance with the Privacy Act and the APPs. This will include obtaining consent where required by law. If a relevant individual does not provide some or all of the personal information requested by Koda, or does not consent to the use, holding or disclosure of personal information where consent is required, Koda may not be able to provide the products or services required.

3.3 Collection of Personal Information

Koda can only collect personal information that is reasonably necessary to provide the services it offers and what is required by law. Collection of information that is not reasonably necessary can increase risks in relation to data breaches. 

The way in which Koda will collect personal information provided by the client includes, the following:

  • face to face or online meetings with clients;
  • the recording of telephone calls;
  • collection of document copies; and
  • Koda’s website and systems.

Identity Verification

To comply with our legal obligations under the AML/CTF Act 2006, we verify an individual’s identity using electronic matching services.

Electronic Matching: We disclose an individual’s personal and document details (such as name, date of birth, and ID numbers) to our service provider, FrankieOne. FrankieOne facilitates a match against official government records via the Document Verification Service (DVS). This is a "match/no-match" service that confirms whether the details provided match the records held by the government agency that issued the document. We provide a manual review process for any identity matching decisions that may adversely affect access to services.

Consent and Use: We only conduct these checks with an individual’s express consent. The results are used strictly for identity verification and fraud prevention; we do not use this information for marketing or profiling.

Declining Consent: If an individual does not wish to provide express consent for an electronic check, they can contact us to discuss alternative manual verification methods. Note that declining consent may delay or prevent us from providing a client with services.

In some circumstances, Koda may gather personal information about the client from a third party or from publicly available information. The third parties from whom the business may acquire personal information include, but are not limited to;

  • information service providers;
  • credit agencies;
  • lawyers;
  • accountants and financial advisers;
  • fund managers; and/ or
  • intermediaries and spouses.

Should a third party provide Koda with a client’s personal information, it is assumed that the client has provided consent for that third party to do so, unless Koda is notified otherwise.

3.4 Use and Disclosure of Personal Information

Generally, Koda can only use or disclose personal information that is in context of carrying out the originally intended functions or services.

3.4.1 Use of Personal Information

The purposes for which clients’ personal information will be used depends on the relationship with the client and the nature of the products and services the client requires. For example, personal information may be used to:

  • provide clients with products and services in accordance with Koda’s obligations;
  • administer and improve the products and services provided to Koda’s clients;
  • offer the client further products and services (which may include using client’s information for marketing purposes, unless told otherwise); and
  • comply with legal and regulatory obligations under the Corporations Act 2001 and the Proceeds of Crime Act 2002, the AML/CTF Act, the Foreign Tax Compliance Act, the rules of relevant stock exchanges and ASIC or any other relevant legislation or regulation.

We also use personal information when recruiting staff or contractors.

3.4.2 Disclosure of Personal Information

When a client provides Koda with their personal information, they are acknowledging and agreeing that their personal information may be disclosed to any of the following third parties to provide investor and financial services:

  • any person for the purposes described in any of Koda agreements with the client;
  • the issuer or seller of a financial product or its registry provider (or to both), if the client has instructed Koda to acquire the financial product and its terms require Koda to provide the client’s personal information;
  • any regulatory, governmental organisation or industry or legal body which governs the conduct of any part of the Koda business in any jurisdiction or as required by law or regulation. Whilst not exhaustive, Koda may need to disclose personal information to regulatory bodies such as ASIC and relevant stock exchanges;
  • any other third party provided that Koda obtains the client’s prior written consent; and
  • as otherwise permitted or required by law.

3.4.2.1 Disclosure of Personal Information to Related Bodies and Other Countries

When an individual provides their personal information to Koda, they are acknowledging and agreeing that this personal information may be transferred between related bodies corporate or to third parties who supply products and services to Koda. Koda will only disclose the personal information for the primary purpose for which it was collected.

These related body corporates and third parties to whom Personal Information may be transferred, may be located throughout the world and may be registered and governed by laws outside the Australian jurisdictions. As such, the laws regulating a related body corporate may differ to Australian laws and may apply a greater or lesser standard of protection for personal information.

Should an individual’s personal information be transferred to a jurisdiction with inadequate privacy protection (i.e. such protection does not provide a level of protection equivalent to that provided by Australian privacy regulation), Koda will take reasonable steps to ensure that the relevant overseas recipient does not breach the Privacy Act or APPs in relation to such personal information. Alternatively, Koda may seek the individual’s consent to the transfer.

3.4.2.1 Use of Artificial Intelligence

Koda may utilise Artificial Intelligence (AI) in providing its services.

AI tools used by Koda are required to be approved by Responsible Managers and Chief Technology Officer before they are permitted for use within Koda. If personal data is required to be used within Koda AI tools, it will be used within the protective guidelines of the Electronic Communications Policy. Koda does not input sensitive information into publicly available generative AI tools.

3.5 Storage of Personal Information

Personal information is held in a secure environment either in writing, electronically or both. Security measures are in place at Koda that are intended to protect personal information held from misuse, interference and loss, and from unauthorised access, modification or disclosure.

An individual is entitled to request details on the exact nature of where and how their personal information is held by contacting Koda.

Personal information will only be available to Koda employees on a need-to-know basis to perform their duties.

3.6 Deletion of Personal Information

An individual can request the destruction or de-identification of their personal information within a reasonable time.

Koda must destroy or de-identify personal information that is no longer required for a specified purpose.

3.7 Access to Personal Information and Complaints

Should an individual wish to know what personal information Koda holds, they may request to view this personal information by contacting Koda’s Privacy Officer:

Koda Privacy Officer
Address: level 8, 20 Bond Street, Sydney, NSW 2000
Email: info@kodacapital.com.au

3.8 Koda Websites

Koda’s website utilises "cookies". A cookie is an electronic mechanism which can trace access and use of Personal Information contained within websites. By using any Koda website, the individual is consenting to the use of cookies. Any personal information obtained through the use of cookies may be used to enhance the products and services that we provide.

3.9 Sensitive Information

Koda may be required to collect sensitive information about clients in order to provide advice, products or services. Koda will only collect sensitive information with client consent or as otherwise permitted by law.

3.10 Government Related Identifiers

Koda may be required to collect government related identifiers of a client in order to provide a product or service. In particular, Koda may collect government related identifiers to verify a client’s identity in accordance with the AML/CTF Act.

4. NOTIFIABLE DATA BREACHES

As a regulated entity, Koda is required to comply with the Notifiable Data Breaches scheme under the Privacy Act. The scheme requires Koda to notify affected individuals and OAIC when a data breach involving personal information is likely to result in serious harm.

For more information about notifiable data breaches please visit oaic.gov.au or via telephone on 1300 363 992.