NJ & Associates
HOME
ABOUT
CONTACT
SERVICES
  • Accounting
  • Taxation
  • Bookkeeping
  • Business Advisory
  • EMDG
NEWS
CLIENT PORTAL
NJ & Associates
HOME
ABOUT
CONTACT
SERVICES
  • Accounting
  • Taxation
  • Bookkeeping
  • Business Advisory
  • EMDG
NEWS
CLIENT PORTAL
More
  • HOME
  • ABOUT
  • CONTACT
  • SERVICES
    • Accounting
    • Taxation
    • Bookkeeping
    • Business Advisory
    • EMDG
  • NEWS
  • CLIENT PORTAL
  • HOME
  • ABOUT
  • CONTACT
  • SERVICES
    • Accounting
    • Taxation
    • Bookkeeping
    • Business Advisory
    • EMDG
  • NEWS
  • CLIENT PORTAL

PRIVACY POLICY

Harper Link Pty Ltd ABN 66 633 367 423 trading as NJ & Associates ("NJ & Associates", "we", "us", "our")

Version 2.0 | Effective date: 03 August 2026 | Last updated: 03 August 2026 


1. Application

1.1 This policy applies to Personal Information handled by NJ & Associates, an Australian accounting and tax practice, in connection with its clients and persons connected with them, visitors to njaa.com.au, job applicants, and any other individual whose Personal Information it handles.

1.2 In this policy, "Personal Information", "Sensitive Information" and "APPs"have the meanings given in the Privacy Act 1988 (Cth) ("Privacy Act"); "AML/CTF Act" means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth); "TFN"means tax file number.

1.3 We comply with the Privacy Act and the APPs to the extent they apply to us, including where we handle Personal Information for or in connection with our obligations under the AML/CTF Act, and with the Privacy (Tax File Number) Rule 2015 when handling individual TFN information. We apply the practices described in this policy to Personal Information we handle generally.

1.4 This policy describes our general Personal Information handling practices. It may be supplemented by collection notices provided at or around the time we collect Personal Information, including notices relating to client onboarding, AML/CTF customer due diligence, identity verification, website enquiries and recruitment.


2. Collection of Personal Information

2.1 The Personal Information we collect depends on the nature of your dealings with us and may include: 

(a) identity and contact details, including name, date of birth, address, contact details and occupation; 

(b) financial and taxation information, including income, expenses, assets, liabilities, bank account details, superannuation details, TFNs, and records required to prepare accounts, returns and lodgements; 

(c) identity verification information collected under clause 5; 

(d) information concerning persons connected with a client, including directors, shareholders, beneficiaries, partners, employees and family members, where relevant to the services; 

(e) website and technical data, including IP address, device and browser information and usage data collected through cookies and analytics; and 

(f) recruitment information from job applicants.

2.2 Identity verification information may include facial images or biometric information where an electronic verification process uses facial matching or liveness checks. Such information is collected only where reasonably necessary and with consent or as otherwise permitted by law.

2.3 We collect Sensitive Information only where it is reasonable necessary for one or more of our functions or activities, including providing professional services, recruitment, identity verification and legal or regulatory compliance, and with consent, or where collection is otherwise required or authorised by law.

2.4 Where you provide us with Personal Information about another individual, you must be authorised to do so and should inform that individual of this policy. This clause does not limit any notification obligation we owe directly to that individual.

2.5 You may deal with us anonymously or under a pseudonym in respect of general enquiries. For most professional services this is not practicable, as we are required to identify our clients and persons acting for them.

2.6 We collect and use TFNs only for purposes authorised by taxation, personal assistance and superannuation law, restrict access to personnel who require them, and do not use or disclose TFN information for any other purpose.


3. Method of Collection and Holding

3.1 We collect Personal Information primarily from the individual concerned, in person or by telephone, email, client portal or written forms and records. With authority, we also collect Personal Information from third parties, including the Australian Taxation Office and other government agencies, ASIC, financial institutions (through authorised data feeds), previous or other advisers, and accredited data recipients under the Consumer Data Right where we are nominated as trusted adviser.

3.2 We hold Personal Information in cloud-based professional software used for accounting, taxation, document management, entity administration, identity verification, approvals and billing. Some providers may store, process, or permit access to personal information outside Australia, including United States, Japan, Ireland and the Netherlands. A current list of the relevant countries is available on request.

3.3 We maintain an internal record of the providers we use, relevant overseas locations and applicable privacy and security protections. Further information may be available on request, subject to confidentiality and security considerations.


4. Purposes of Collection, Use and Disclosure

4.1 We collect, hold, use and disclose Personal Information for the following purposes: 

(a) providing accounting, taxation, bookkeeping, business advisory, payroll, entity administration and related services, including preparation and lodgement of documents with the Australian Taxation Office, ASIC, state revenue offices and other authorities; 

(b) complying with our legal and professional obligations, including under the Tax Agent Services Act 2009 (Cth), the AML/CTF Act, and the professional standards of CPA Australia and the Accounting Professional & Ethical Standards Board; 

(c) identity verification, fraud prevention and conflict checks; 

(d) assessing and maintaining client engagements; 

(e) practice administration, including billing, record keeping, quality reviews, insurance, dispute handling, debt recovery, cybersecurity and incident management, and business continuity; and 

(f) communications, including occasional service updates where permitted by law.

4.2 Each commercial electronic communication we send will include a functional unsubscribe facility, and you may opt out of such communications at any time by using that facility or by contacting us.

4.3 We do not sell Personal Information. We do not use Sensitive Information or TFN information for marketing.


5. Anti-Money Laundering and Counter-Terrorism Financing

5.1 Where we provide a designated service as a reporting entity under the AML/CTF Act, we must comply with applicable customer due diligence, ongoing monitoring, personnel due diligence where applicable, record-keeping and reporting obligations.

Where we act as an authorised agent of another reporting entity, we may carry out customer-identification or identity-verification procedures on that reporting entity’s behalf and handle Personal Information to the extent reasonably necessary for those procedures and associated record-keeping.

Not every accounting or taxation service is a designated service. Verification requirements may extend to beneficial owners, controlling persons and persons acting on a client’s behalf.

5.2 We collect and retain the identifying information, verification results and supporting records reasonably necessary to meet our applicable obligations.

We do not ordinarily retain copies of full identity documents solely for AML/CTF record-keeping purposes. We may retain a copy or extract where it is reasonably necessary for another permitted purpose, or where retention is required or authorised by law or a court or tribunal order.

Where copies are retained, access is restricted and the information is protected in accordance with this policy. We take reasonable steps to destroy or de-identify copies when they are no longer required for a permitted purpose.

5.3 Where applicable, verification may be conducted using electronic identity verification technology. Depending on the verification process, identity information may be checked against government verification services, sanctions lists, watchlists, adverse-media sources and other verification databases.

This may involve information being matched against databases held outside Australia, even where the underlying verification record is stored in Australia.

5.4 The AML/CTF Act may prohibit us from disclosing information concerning a suspicious matter report or related matters where the statutory tipping-off prohibition applies. This may limit the information we are able to provide concerning particular actions or decisions.

5.5 AML/CTF records are retained for the periods required by law, generally seven years. The commencement of the retention period depends on the type of record. Customer due diligence records are generally retained for seven years after the end of the business relationship or the last occasional transaction; transaction records are generally retained for seven years after the transaction is completed; and relevant AML/CTF program records are generally retained for seven years after they cease to be relevant.


6. Disclosure

6.1 Subject to our legal and professional confidentiality obligations, we disclose Personal Information only as necessary for the purposes in clause 4, with consent, or where required or authorised by law, to: 

(a) our personnel and contractors, subject to confidentiality obligations; 

(b) the software and cloud service providers referred to in clause 3.2; 

(c) the Australian Taxation Office, ASIC, AUSTRAC, state revenue offices and other regulators; 

(d) CPA Australia, where information is required for its Best Practice Program or another professional review, subject to applicable law, professional confidentiality requirements and any required authority or consent; 

(e) our legal advisers, accountants, auditors, insurers, insurance brokers and claims advisers, where reasonably necessary for advice, risk management, dispute handling or insurance purposes; 

(f) financial institutions and payment providers, for billing; and 

(g) courts, tribunals and law enforcement bodies, where required or permitted by law.


7. Cross-border Disclosure

7.1 Certain providers referred to in clause 3.2 store, process, transmit or access Personal Information outside Australia, in the countries identified in that clause. Our identity verification provider may additionally match Personal Information against databases held outside Australia as described in clause 5.3.

7.2 Where Personal Information is disclosed to an overseas recipient, we take reasonable steps appropriate to the circumstances to protect it, which may include provider due diligence, security assessments and contractual privacy and security safeguards, consistent with the APPs.


8. Retention

8.1 Records of tax agent services are retained for not less than five years after the relevant service has been provided, in accordance with applicable tax-practitioner record-keeping obligations; our practice policy is to retain engagement records for seven years. AML/CTF records are retained in accordance with clause 5.5. Other records may be retained for different periods where required by taxation, corporations, employment, professional, insurance, litigation or other legal obligations, or while a dispute, engagement or legal hold subsists.

8.2 Where no continuing purpose or legal requirement applies, we take reasonable steps to destroy or de-identify Personal Information.


9. Security and Data Breaches

9.1 We take reasonable steps to protect Personal Information from misuse, interference, loss, and unauthorised access, modification or disclosure, including access controls, encryption in transit, multi-factor authentication and personnel confidentiality obligations, and we engage reputable service providers selected through a risk-based assessment process. 

9.2 No transmission over the internet is completely secure, and we cannot guarantee the security of information in transit. This clause does not limit our obligation to take reasonable steps to protect Personal Information.

9.3 Where the Notifiable Data Breaches scheme applies, we will assess suspected eligible data breaches and notify the Office of the Australian Information Commissioner and affected individuals where required by law.


10. Access and Correction

10.1 You may request access to the Personal Information we hold about you. No charge applies for making a request. We may charge a reasonable, non-excessive fee for providing access and will advise you of any proposed fee in advance. We will generally respond within 30 days. Where access is refused on a ground permitted by law, we will ordinarily provide written reasons and available complaint mechanisms.

10.2 You may request correction of Personal Information that is inaccurate, out of date, incomplete, irrelevant or misleading. No charge applies to a correction request or correction. We will take reasonable steps to correct Personal Information promptly.


11. Complaints

11.1 Complaints concerning our handling of Personal Information may be made to the contact in clause 14. We will acknowledge a complaint within 5 business days and aim to provide a substantive response within 30 days; complex matters may require additional time.

11.2 If you are dissatisfied with our response, you may complain to the Office of the Australian Information Commissioner (www.oaic.gov.au).


12. Website and Cookies

12.1 Cookies and similar technologies may collect information about your browser, device, IP address and use of our website. This information may not directly identify you by name but may identify or distinguish your device or be combined with other information. We use Google Analytics to understand how our website is used, and associated information may be processed outside Australia by Google and its service providers.

12.2 You may disable cookies through your browser settings; parts of the website may not function as a result. Third-party websites linked from our website are not governed by this policy.


13. Amendments

13.1 We may amend this policy from time to time. The current version, with its version number and effective date, is published at njaa.com.au/privacy-policy. Where appropriate, we may notify current clients of material changes through direct communications or our client portal.


14. Contact

Privacy Officer 

Harper Link Pty Ltd ABN 66 633 367 423 

T/A NJ & Associates 

LV 17, 1 Denison Street, North Sydney NSW 2060 

Email: admin@njaa.com.au 

Telephone: +61 2 9073 3126

Website: njaa.com.au

  • HOME
  • ABOUT
  • CONTACT
  • NEWS
  • CLIENT PORTAL
  • Privacy Policy
  • Disclaimer

NJ & ASSOCIATES

AU Office: Suite 1739, 1 Denison Street, North Sydney NSW 2060 | NZ Office: Level 3 Candida Office Complex, 61 Constellation Drive, Rosedale, Auckland 0632, NZ

Copyright © 2026 NJ & Associates - All Rights Reserved.

Powered by

This website uses cookies.

We use cookies to analyze website traffic and optimize your website experience. By accepting our use of cookies, your data will be aggregated with all other user data.

Accept

Welcome to NJ & Associates

Discover what NJ can contribute to your growth. Explore your possibilities today.

Learn more