Public APP Privacy Policy | Version 1.0 | Last updated 16 July 2026.
1. Document control
|
Version |
Date |
Change summary |
Document owner |
|
1.0 |
16 July 2026 |
Initial controlled issue. Added a document version identifier and change register. |
Privacy Officer |
2. About this policy
Business Sales Group (ABN 77 307 146 231) operates business-broking services under the Business Sales Group, NQ Business Sales, FNQ Business Sales, CQ Business Sales and SEQ Business Sales names (we, us, our). We are committed to protecting personal information and managing it openly and transparently.
We are bound by the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs). Where applicable to our services, we also handle information in accordance with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the Identity Verification Services Act 2023 (Cth), and associated requirements.
The current version of this policy is available free of charge at https://www.businesssalesgroup.com.au/privacy-policy/. You may ask us to provide it in another accessible form.
3. Changes to this policy
We may update this policy when our practices, providers or legal obligations change. The current version and its last-updated date will be published on our website. From 10 December 2026, we will also include any additional disclosures required by APP 1 concerning substantially automated decisions that may significantly affect an individual's rights or interests, if those requirements apply to our activities.
4. Personal information we collect
The information we collect depends on whether you are a buyer, seller, client, prospective client, adviser, service provider or other person dealing with us. It may include:
- identity and contact information: name, date and place of birth, residential or business address, email address, telephone number, occupation and employment details
- government identity information: driver licence, passport, Medicare card, birth or marriage certificate and other government-issued identifier details and document images
- biometric information: facial images, video or still images and biometric information created from those images for identity verification, including facial-match and liveness results
- buyer information: acquisition criteria, preferred industries and locations, budget, financing position, purchase readiness, business interests and enquiry history
- seller and transaction information: business ownership, financial and operational information, property information, authorities, agreements, offers, negotiations and settlement information
- compliance information: customer due diligence, beneficial ownership, source-of-funds or source-of-wealth information, risk assessments, sanctions and politically exposed person screening results
- technical information: IP address, device and browser information, connection records, website activity and device-location information where permission is granted
- communications: emails, telephone notes, correspondence, complaints and records of consent
Biometric information used for automated identity verification is sensitive information. We only arrange for it to be collected where reasonably necessary and after specific, express consent, unless an applicable law provides otherwise.
5. How we collect and hold information
We generally collect information directly from you through buyer registrations, confidentiality agreements, seller information statements, appointment forms, identity-verification journeys, website forms, email, telephone, meetings and other correspondence.
We may also collect information from your authorised representatives, sellers or buyers, advisers, other agents, identity-verification and screening providers, government and public registers, listing platforms and other lawful public sources.
Information may be held in secure electronic systems, email, cloud storage, our customer and transaction records, AMLHub and authorised service-provider systems, and in physical files where necessary.
6. Why we collect, use and disclose information
We collect, hold, use and disclose personal information to provide business-broking and related services; manage buyer and seller enquiries; assess and progress transactions; communicate with clients and advisers; protect confidential business information; verify identity; conduct customer due diligence and risk assessments; meet legal, regulatory, reporting and record-keeping obligations; prevent fraud and misuse; manage complaints; administer our business; and improve our services.
We only collect personal information that is reasonably necessary for our functions and activities, or where collection is required or authorised by law.
7. Remote electronic identity verification
When we verify your identity remotely, we use APLYiD's electronic identity-verification service through AMLHub. APLYiD may collect and process information on our behalf, including photographs of your identity document, information extracted from it, a photograph or video image of your face, biometric information derived from that image, facial-match and liveness results, your address, device and connection information, IP address and device-location information where permission is granted.
The process may verify identity-document details through an Australian Government identity-document verification system, including the Document Verification Service (DVS). Information is matched against records held by the relevant document issuer and a match outcome is returned. We do not receive a copy of the government record.
The remote process presents privacy information and obtains express consent before biometric verification and any DVS check. If you do not consent, contact us to discuss whether an alternative verification method, such as verification in person, is available. We may be unable to provide a service if we cannot complete an identity check required by law.
8. Disclosure of personal information
We may disclose personal information where reasonably necessary to sellers, prospective buyers and their authorised advisers; our personnel and authorised representatives; AMLHub, APLYiD, DataZoo and other identity-verification, screening or compliance providers; government document issuers and the DVS; solicitors, accountants, auditors, insurers and other professional advisers; website, CRM, email, hosting, cloud-storage, IT and communications providers; listing and marketing platforms; regulators, courts, tribunals, law-enforcement bodies and government agencies; and other parties where you consent or where disclosure is required or authorised by law.
We do not sell personal information.
9. Overseas processing and disclosure
Some service providers may process or store information outside Australia. For the Australian APLYiD service, APLYiD states that personal information is processed in Australia or New Zealand. Information may also be disclosed to New Zealand in connection with verification assistance, and other countries may be involved where an overseas identity document or service provider is used.
Where APP 8 applies, we take reasonable steps to ensure overseas recipients handle personal information consistently with the APPs. Provider locations can change; you may contact our Privacy Officer for current information relevant to your circumstances.
10. Direct marketing
We may use contact details to send information about listings or services where permitted by law and where we reasonably believe it may be relevant. You may opt out at any time using an unsubscribe facility or by contacting us. Opting out of marketing does not stop essential transaction or service communications.
11. Security and retention
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Measures include access controls, secure service providers, staff confidentiality obligations, authentication, encryption where appropriate and secure disposal practices.
We retain information only while it is needed for the purposes described in this policy or to meet legal, regulatory and record-keeping obligations. When information is no longer required, we take reasonable steps to delete or de-identify it. We maintain procedures for assessing and responding to eligible data breaches under the Notifiable Data Breaches scheme.
12. Access and correction
You may ask to access personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact the Privacy Officer using the details below. We may need to verify your identity before acting on a request.
We will respond within a reasonable period. We do not charge for making a request or correcting information. A reasonable charge may apply for providing access, but we will tell you before incurring that cost. If access or correction is refused, we will generally provide written reasons and available complaint options, unless the law permits otherwise.
13. Privacy complaints
If you believe we have breached the Privacy Act, an APP or a registered APP code, contact our Privacy Officer and describe the issue and the outcome you seek. We will acknowledge the complaint promptly, investigate it fairly and aim to provide a substantive response within 30 calendar days. If more time is reasonably required, we will explain why and provide an updated timeframe.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner at https://www.oaic.gov.au or telephone 1300 363 992.
14. Contact details
Privacy Officer, Business Sales Group
Email: denny@businesssalesgroup.com.au
Telephone: 0409 639 366
Website: https://www.businesssalesgroup.com.au
Postal correspondence: please contact the Privacy Officer by email or telephone for the current postal address.