Introduction
Rhodes Financial Group is the collective trading name for the following entities:
- Rhodes Asset Management Limited ACN 165 917 813 | AFSL 464772 (rhodesam.com.au)
- Rhodes Financing Solutions Pty Ltd ACN 651 843 828 (rhodesfs.com.au)
Rhodes Financial Group (RFG), referred to in this document as ‘we’, ‘us’ or ‘our’, is committed to managing your personal information in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth) and in accordance with other applicable rules and laws.
This document sets out our policies for managing your personal information and is referred to as our Privacy Policy. It explains how we collect, hold, use, disclose and protect personal information.
What information do we collect about you?
The personal information we collect will vary depending on the circumstances of collection and the kind of product or service you request from us. Because RFG encompasses RAM, an Australian financial services licensee and the responsible entity of registered managed investment schemes, as well as RFS, a provider of lending-related services, the information we collect is broader than basic contact details and will typically include:
- Identity and contact information — your name, date of birth, residential address and contact details;
- Customer identification and verification information — information and documents we are required to collect and verify under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), such as details of government-issued identification (for example, a driver licence or passport), and information about the beneficial owners, directors, trustees or controlling persons of companies, trusts and self-managed superannuation funds;
- Financial information — bank account details, investment amounts and unit holdings, distribution and payment records and, for borrowers, loan, security and repayment information;
- Tax file numbers (TFNs) — where you choose to provide it in connection with an investment, your TFN. TFNs are collected, used and disclosed only as permitted by taxation law and the Privacy (Tax File Number) Rule 2015;
- Source of funds and transaction information — where required under AML/CTF laws, information about the source of your funds or wealth and the nature and purpose of your dealings with us; and
- Other information — any additional personal information you provide to us or authorise us to collect.
We may collect personal information directly from you (for example, through application forms), from your authorised representatives or advisers, from electronic identity verification and screening service providers we engage to meet our AML/CTF obligations, and from publicly available sources such as government registers.
We may also collect information based on how you use our websites. We use “cookies” and other data collection methods to collect information on website activity, such as the number of visitors and the number of pages viewed. This information is collected to analyse and improve our website and to record statistics on web traffic. Some of this website activity data may be combined with other personal information you have provided to us, such as through an enquiry or application form, including for the online advertising and marketing measurement purposes described below.
We do not actively seek to collect sensitive information (for example, health information or information about any criminal record) unless it is necessary for our business purposes. If we do have to collect sensitive information, we will only collect, use and disclose it in accordance with privacy laws.
How do we use and disclose your personal information?
We collect, use and disclose personal information as reasonably necessary to carry out our business and to provide our products and services, including: process applications, establish and administer investments and loans, verify your identity, communicate with you, and manage complaints and enquiries.
We also use and disclose your personal information to comply with our legal obligations, including under Australian taxation laws, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the Corporations Act 2001 (Cth) and other applicable laws. This may involve disclosing personal information to regulators, law enforcement agencies and government bodies, including the Australian Securities and Investments Commission (ASIC), the Australian Transaction Reports and Analysis Centre (AUSTRAC) and the Australian Taxation Office (ATO).
We may disclose personal information to third parties who assist us in operating our business, including registry, custody, administration and technology service providers, identity verification and screening service providers, and our professional advisers (such as auditors and lawyers). These providers are required to handle personal information in accordance with the Privacy Act and our contractual requirements, and only for the purposes for which it is disclosed.
Additionally, your personal information may be used for secondary purposes such as providing you with promotional and marketing material. You can notify us at any time if you do not wish to receive such material. Where we collect your personal information for a specific purpose not contemplated in this Privacy Policy, we will provide you with a collection notice which explains the primary purpose and any related secondary purposes for which your personal information is being collected.
We may also disclose your personal information to third-party advertising and analytics platforms, such as Google and Meta, for the purposes of measuring the effectiveness of our marketing, understanding how visitors interact with our website, and matching website enquiries to online advertising campaigns. Where this occurs, personal information such as your name, email address or phone number may be converted into a de-identified, encrypted format (commonly known as “hashing”) before being shared, so that it cannot be read by us or by the platform in its original form. You can contact us at any time if you do not wish for your personal information to be used in this way.
Do we disclose personal information to overseas recipients?
Yes. We use the services of overseas-based personnel engaged through a service company to assist with administrative, accounting and operational support functions. As a result, some personal information we hold may be accessed from, and is therefore disclosed to, a recipient in Vietnam.
Before personal information is made accessible from overseas, we take reasonable steps to ensure the overseas recipient handles it in a manner consistent with the Australian Privacy Principles. These steps include contractual arrangements governed by Australian law that impose privacy, confidentiality and data-handling obligations, restricting access to the minimum information necessary for the relevant function, technical controls that aim to prevent the local storage of information outside our systems, and regular training and review.
Our core business systems and cloud platforms are hosted in Australia. Apart from the overseas access described above, we do not otherwise routinely disclose personal information to overseas recipients. If this changes, we will update this Privacy Policy to identify the relevant countries.
In addition, some of the third-party advertising and analytics platforms referred to above, such as Google and Meta, may store or process personal information on servers located overseas, including in the United States. We take reasonable steps to ensure these providers handle personal information in a manner consistent with the Australian Privacy Principles.
How do we store, protect and retain your personal information?
We take all reasonable steps to protect your personal information from misuse, loss, unauthorised access, interference, modification or disclosure.
We maintain physical, electronic and procedural safeguards to protect the information we hold. For example, personal information is stored in secured offices and protected by security measures such as secure authentication, password controls, multi-factor authentication, encryption, firewalls and anti-virus technology. Access to personal information is restricted to staff whose role requires it, and all personnel are required to maintain strict confidentiality regarding the personal information of our investors and borrowers.
If a data breach occurs that is likely to result in serious harm to individuals, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
We retain personal information only for as long as it is required for our functions and to meet our legal obligations. Certain records must be retained for minimum periods under law — for example, customer identification and transaction records must be kept for seven years under AML/CTF legislation, and various records must be retained under the Corporations Act. When personal information is no longer required for any lawful purpose, we take reasonable steps to permanently destroy or de-identify it using secure methods, in accordance with our Data Retention & Identifiable Data Deletion Policy and all applicable laws.
Automated decision-making
We may use automated tools to assist in assessing applications and conducting customer due diligence, such as electronic identity verification and screening services. Where such tools are used, they may draw on identity and contact information, customer identification and verification information, and financial information we hold. Final decisions, including decisions about investments, loans and customer due diligence, are made by our personnel. We do not use computer programs to make decisions that could reasonably be expected to significantly affect your rights or interests without human involvement. If our use of automated tools changes, we will update this Privacy Policy to describe the kinds of decisions involved and the kinds of personal information used, in accordance with the Privacy Act.
Accessing and updating your personal information
If you require access to, or wish to update, your personal information, please contact us:
- By phone: 1300 425 594
By email: admin@rhodesam.com.au - By post: Rhodes Financial Group, PO Box 1753, Capalaba QLD 4157
If you believe that the personal information we hold about you is inaccurate, incomplete or out of date, you should contact us to correct this information. We aim to promptly update any personal information that is inaccurate, incomplete or out of date.
If we refuse to correct your personal information, we will provide you with a written notice that sets out the reasons for our refusal (unless it would be unreasonable to provide those reasons) and a statement on what you can do if you are not satisfied with our response.
Complaints and feedback
If you wish to make a complaint about a breach of the Privacy Act, the Australian Privacy Principles or a privacy code that applies to us, please contact us as set out below and we will take reasonable steps to investigate the complaint and respond to you.
If you have any queries or concerns about our Privacy Policy or the way we handle your personal information, please contact us:
- By phone: 1300 425 594
- By email: complaints@rhodesam.com.au
- By post: Rhodes Financial Group, PO Box 1753, Capalaba QLD 4157
Australian Privacy Commissioner
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC): Telephone 1300 363 992, email enquiries@oaic.gov.au.
For more information about privacy in general, you can visit the OAIC’s website at www.oaic.gov.au.
Changes to this Privacy Policy
This Privacy Policy is dated 6th August 2026. This document replaces any other Privacy Policy published by us, including the version dated 13 May 2026. We may make changes to this Policy from time to time. We encourage you to review our website regularly to ensure that you are reviewing the most current version of our Privacy Policy.