mulgamoney

Legal

Privacy policy

Draft v1 — this wording has not completed legal review and is a placeholder only
PRIVACY POLICY [LEGAL REVIEW REQUIRED — draft for counsel; bracketed items must be resolved and approval recorded in the admin console before publication.] Mulga Finance Pty Ltd (trading as Mulga Money) · ABN 18 689 117 995 · Australian credit licence 573780 Version 1.0 — DRAFT FOR LEGAL REVIEW · Effective date: [TO BE SET ON COUNSEL APPROVAL] 1. About this policy Mulga Finance Pty Ltd, trading as Mulga Money (“Mulga”, “we”, “us”), provides lease-to-own finance for e-bikes. We are bound by the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and — because we are a credit provider — by Part IIIA of the Privacy Act and the Privacy (Credit Reporting) Code (CR Code). This policy explains what personal information we collect, why, who we share it with, how we protect it, and the rights you have. It applies to our website, our application and account platform, and every product we offer. We have tried to write it the way we write everything: plainly. If anything is unclear, ask us — contact details are in section 14. 2. The short version - We collect only what we need to lawfully assess your application and manage your lease. - A person, not a machine, makes every credit decision about you. - Your information is stored and processed in Australia. - We never sell personal information, and we don’t share it for anyone else’s marketing. - The store where you choose your bike never sees your income, documents or credit information — only a coarse application status. - Every time our staff view an identity document, that access is recorded in a tamper-evident log. - You can access and correct your information, and complain to us, the OAIC or AFCA — all free. 3. What we collect Depending on how you deal with us, we may collect: - Identity and contact details — your name, date of birth, residential address, email and phone number. - Government identifiers — details and images of your driver licence, passport or Medicare card, used only to verify who you are. We do not use government identifiers as our own customer identifier. - Financial information — your employment, income, living expenses, housing costs, dependants and other credit commitments, and documents that evidence them such as payslips or bank statements — including, if you choose it, read-only account information shared through Open Banking (the Consumer Data Right). We never see or store your bank login. - Credit information — information from a credit reporting body, collected only with your recorded consent (see section 8). - Payment details — the account name, BSB and account number for your weekly direct debit. We store these only in masked form; full details are held by our payments provider. - Your interactions with us — the exact wording and version of each consent you give and when you gave it, your electronic signature (the name you typed, the document fingerprint, and the IP address and device used), correspondence, and records of any hardship request or complaint. - Technical information — IP address, browser and device type, and a session cookie used to keep you signed in. We do not use advertising or cross-site tracking cookies. You can deal with us anonymously or by pseudonym for general enquiries, but the law requires us to identify you before we can assess an application or provide credit. 4. How we collect it - Directly from you, when you apply, use your account, or contact us. - From our partner retailer, when store staff start an application for you: they give us only your name, email address and the bike you chose. - From third parties — a credit reporting body (only with your recorded consent); identity-verification checks against external data sources such as the Australian Electoral Roll, ASIC records and Australian tenancy databases; and sanctions and politically-exposed-person screening services. - Generated by us — assessment records, the written reasons for decisions, payment history and account records. 5. Why we collect and use it We collect, hold and use personal information to: - assess whether a lease is suitable for you and whether you can afford it, as the National Consumer Credit Protection Act 2009 requires of us; - verify your identity against at least two independent data sources, and screen against sanctions and politically-exposed-person lists, as anti-money-laundering and counter-terrorism financing laws require; - set up and manage your lease — payments, statements, the transfer of ownership to you, and any variation you request; - assess and respond to financial hardship requests, and receive, investigate and resolve complaints; - detect and prevent fraud and keep our systems secure; - comply with our legal obligations and cooperate with regulators; and - improve our products and service, using de-identified information wherever possible. We will only send you marketing about our own products — such as telling you when applications open or a new product launches — if you have asked us to, and every message will include a working unsubscribe. We do not sell personal information and we do not share it with third parties for their marketing. 6. Who we share it with We share personal information only as needed to run the business you’ve asked us to do business with: - Credit reporting bodies, as described in section 8. - Identity-verification and screening providers (currently NameScan for sanctions and politically-exposed-person screening), to confirm who you are and meet our AML/CTF obligations. - Open Banking (CDR) providers, if you choose to share bank account data that way — handled under the Consumer Data Right rules. - Our partner retailer — but only a coarse status such as “In progress” or “Ready to release”, and confirmation that release is authorised. Store staff never receive your income, expenses, documents, credit information or the reasons for any decision. - Payments and direct-debit providers, to process your weekly payments. - Professional advisers — our lawyers, accountants and auditors — under confidentiality obligations. - Technology providers that host our systems in Australia, under contracts requiring them to protect your information. - The Australian Financial Complaints Authority (AFCA), if you take a complaint there, and regulators and government bodies such as ASIC, the OAIC and AUSTRAC where the law requires or permits. - Anyone you authorise us to share with. [LEGAL REVIEW: confirm the Consumer Data Right access model (accredited person, CDR representative or trusted adviser) before launch, and name the final verification/screening vendors.] 7. Overseas disclosure Your personal information is stored and processed in Australia. We do not routinely disclose personal information overseas. If that ever changes, we will only do so in accordance with APP 8 — which generally means taking reasonable steps to ensure the overseas recipient handles your information consistently with the APPs — and we will update this policy first. [LEGAL REVIEW: confirm the final vendor list is entirely Australian-resident, or name the countries involved.] 8. Credit reporting — the details Part IIIA requires us to tell you As a credit provider, we may — with your recorded consent — obtain a credit report about you from a credit reporting body (CRB) to assess your application, and we may disclose certain credit information about you to a CRB. The kinds of credit-related information involved can include identification details, the fact that you have applied for or hold credit with us, repayment history and financial hardship information, payment defaults, serious credit infringements, and publicly available information such as court judgments or insolvency records. [LEGAL REVIEW: confirm which kinds of information Mulga will actually disclose — in particular whether repayment history and default information will be reported for this consumer lease — to match the executed CRB agreement.] The CRB we use is: [TO BE CONFIRMED — name the contracted CRB(s) here]. The credit reporting bodies operating in Australia are Equifax (equifax.com.au, 13 8332), illion (illion.com.au, 13 2333) and Experian (experian.com.au, 1300 783 684). Each publishes its own credit reporting policy on its website. Things the law wants you to know: - A CRB may include the information we give it in reports it provides to other credit providers to help them assess your creditworthiness. - If you fail to meet your payment obligations, or we reasonably believe you have committed a serious credit infringement, we may be entitled to disclose that to a CRB. - You can access the credit information we hold about you, and the information a CRB holds, free of charge, and ask for corrections — see section 11. - You can ask a CRB not to use your credit information for pre-screening you for direct marketing by credit providers. - If you believe you have been, or are likely to be, a victim of fraud (including identity fraud), you can ask a CRB to place a ban period on your credit information. - You can complain to us about how we handle your credit information, and if you are not satisfied, to AFCA or the OAIC — all free (see section 13). 9. How we protect it - Information is encrypted in transit and at rest, and identity documents live in private Australian storage that is never publicly accessible — every retrieval goes through an access-checked endpoint. - Staff access is role-based and minimal; retail-partner staff structurally cannot access financial information; staff sign in with multi-factor authentication. - Every staff view of an identity document, and every significant action on your file, is written to an append-only audit log that cannot be edited or deleted. - Passwords are hashed with a modern memory-hard algorithm; sessions are short-lived and revocable. If a data breach occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires, and tell you plainly what happened and what we are doing about it. 10. How long we keep it We keep personal information for as long as we need it for the purposes above and as long as the law requires — credit and anti-money-laundering legislation generally require us to keep records for around seven years after our relationship ends. After that, we destroy it or de-identify it. [LEGAL REVIEW: confirm the retention schedule per record type.] 11. Access and correction You can ask for a copy of the personal information we hold about you, and ask us to correct anything inaccurate, out of date, incomplete or misleading. Requests are free. Email our Privacy Officer (section 14); we will verify it’s really you, then respond within 30 days. In your account you can already see your applications, the consents you gave (word for word), your agreement and your payment history. If we correct credit-related information, we will tell any CRB or credit provider we previously gave it to. If we ever refuse a request — the Privacy Act allows this only in limited circumstances — we will tell you why in writing and how to complain about the refusal. 12. Cookies and our website Our platform uses one strictly necessary cookie: a session cookie that keeps you signed in, which is deleted when the session ends. We do not use advertising cookies, cross-site trackers, or third-party analytics that profile you. Our pre-launch informational pages set no cookies at all. 13. Complaints about privacy If you think we have mishandled your personal information, complain to our Privacy Officer (section 14). We will acknowledge your complaint within one business day and give you a written response within 30 days. If you are not satisfied with our response, you can go — free of charge — to the Office of the Australian Information Commissioner (oaic.gov.au, 1300 363 992) or, for complaints involving credit information, to the Australian Financial Complaints Authority (afca.org.au, 1800 931 678). We are an AFCA member. 14. Contact us Privacy Officer, Mulga Finance Pty Ltd — privacy@mulgamoney.com. A postal address for privacy correspondence is available on request. [OPERATIONS: create the privacy@ mailbox, or change this address, before publication.] 15. Changes to this policy We review this policy at least annually and whenever our practices change. The current version, with its version number and effective date, is always published on our website; material changes will be flagged there. This document is version 1.0.

Version 1 · draft