Legal & Compliance

Privacy Policy

How WilliamThomas&Co. collects, uses, and protects your personal information in accordance with the Australian Privacy Principles.

Effective Date: March 2026  |  Version 1.0

About this Policy: This Privacy Policy applies to Alison Purdy trading as WilliamThomas&Co. (ABN 67 477 422 151) (“we”, “us”, “our”). We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Policy explains how we handle personal information collected through our website and in the course of providing our services.

1. Who We Are

WilliamThomas&Co. is an Australian AML/CTF compliance consultancy providing advisory, program development, training, and review services to businesses navigating AUSTRAC's Tranche II reforms and broader AML/CTF obligations. We operate across Australia on a consulting basis.

Business Name: WilliamThomas&Co.

Legal Identity: Alison Purdy T/A WilliamThomas&Co.

ABN: 67 477 422 151

Website: williamthomasandco.com.au

Email: alison@williamthomasandco.com.au

Location: Australia-Wide

2. What Personal Information We Collect

We collect personal information that is reasonably necessary to provide our services and communicate with you. The types of personal information we may collect include:

Information You Provide Directly

Information We Collect Automatically

Sensitive Information

We do not intentionally collect sensitive information (as defined by the Privacy Act, including health information, criminal record information, or financial information beyond what is reasonably necessary for our compliance advisory services). If you share sensitive information with us in the course of an engagement, we will handle it with heightened care and in accordance with this Policy.

3. How and Why We Collect Personal Information

We collect personal information by lawful and fair means, and only where it is reasonably necessary for one or more of the following purposes:

Where we collect personal information from you indirectly (for example, where a business provides us with contact details for a key personnel member), we will take reasonable steps to notify that individual of the collection as soon as practicable.

4. How We Use and Disclose Personal Information

We use personal information only for the primary purpose for which it was collected, or for a directly related secondary purpose that you would reasonably expect, or where you have consented to another use.

We may disclose your personal information to:

We do not sell, rent, or trade your personal information to third parties for marketing or commercial purposes.

5. Overseas Disclosure

Some of the third-party platforms and tools we use to operate our business (including cloud storage, email, and website analytics) may store or process data on servers located outside Australia. Where this occurs, we take reasonable steps to ensure those providers maintain privacy and security standards consistent with the Australian Privacy Principles.

By providing us with your personal information, you acknowledge that your information may be transferred to and stored in countries outside Australia. We will not disclose your personal information to an overseas recipient unless we have taken reasonable steps to ensure the recipient handles your information in accordance with the APPs, or you have consented to the disclosure.

6. Security of Personal Information

We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

If we no longer need your personal information and are not required by law to retain it, we will take reasonable steps to destroy or de-identify it securely.

While we take these precautions, no data transmission over the internet is entirely secure. We cannot guarantee the absolute security of information transmitted to us via our website or email.

7. Your Rights — Accessing and Correcting Your Information

Under the Australian Privacy Principles, you have the right to:

To make an access or correction request, please contact us using the details in Section 10 below. We will respond to your request within a reasonable time, generally within 30 days. We may ask you to verify your identity before processing your request. We will not charge a fee for making a request, but we may charge a reasonable fee to cover the cost of providing access where permitted by law.

We may decline an access or correction request in limited circumstances permitted by the Privacy Act — for example, where providing access would have an unreasonable impact on the privacy of another individual. Where we decline, we will give you written reasons.

8. Complaints

If you believe we have handled your personal information in a manner that does not comply with the Privacy Act or the Australian Privacy Principles, we encourage you to contact us in the first instance so we can attempt to resolve your concern.

How to make a privacy complaint: Please contact us at alison@williamthomasandco.com.au with the subject line “Privacy Complaint”. We will acknowledge your complaint within 5 business days and endeavour to resolve it within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

9. Cookies and Website Analytics

Our website uses cookies and similar tracking technologies to improve your browsing experience and understand how visitors use our site. Cookies are small text files stored on your device by your browser.

We use the following types of cookies:

You can control or delete cookies through your browser settings. Disabling certain cookies may affect the functionality of our website.

10. Contact Us

For any privacy-related enquiries, access or correction requests, or complaints, please contact:

Privacy Officer

Alison Purdy T/A WilliamThomas&Co.

ABN 67 477 422 151

Email: alison@williamthomasandco.com.au

Website: williamthomasandco.com.au

11. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, services, or applicable law. The current version will always be published on this page with the effective date noted at the top. We encourage you to review this Policy periodically.

Material changes to this Policy will be notified to active clients via email where reasonably practicable.

Governing Law: This Privacy Policy is governed by the laws of Australia. Our privacy obligations are regulated by the Privacy Act 1988 (Cth) and the Australian Privacy Principles. For more information about your privacy rights in Australia, visit www.oaic.gov.au.