Kasa Investment Partners — Privacy Policy
Last updated: July 2026
1. Introduction
1.1 About this policy
Kasa Investment Partners Pty Ltd (Kasa, we, us) holds Australian Financial Services Licence 520524 and provides a wholesale, global-equities Managed Discretionary Account (MDA) service. Kasa is an APP entity under the Privacy Act 1988 (Cth) and is bound by the Australian Privacy Principles (APPs) in Schedule 1 of that Act.
This is the APP Privacy Policy adopted by Kasa's sole director as required by APP 1.3. It sets out how Kasa collects, holds, uses, discloses, secures and gives access to personal information, and how to make a complaint. Kasa makes this policy available free of charge.
The Privacy Act's employee-records exemption means this policy does not apply to the personal information of current or former Kasa employees used for employment purposes. It does apply to unsuccessful job applicants.
1.2 Definitions
- Australian Privacy Principles (APPs) — the principles in Schedule 1 of the Privacy Act 1988 (Cth).
- Personal information — information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
- Sensitive information — a sub-set of personal information including information about racial or ethnic origin, political opinions/associations, religious or philosophical beliefs, trade/professional association or union membership, sexual orientation or practices, criminal record, and health or genetic information.
- Eligible data breach — has the meaning in Part IIIC of the Privacy Act (the Notifiable Data Breach scheme).
- Privacy Officer — the person in section 9.
2. APP 1 — Open and transparent management of personal information
Kasa manages personal information openly and transparently and complies with the APPs. This policy describes the personal information we collect and hold; how we collect, hold, use and disclose it; how an individual may access or correct it; how to complain about a breach of the APPs and how we handle complaints; and whether we are likely to disclose personal information overseas (and to which countries, where practicable).
Automated decision-making. Kasa does not use computer programs to make, or to substantially assist in making, decisions that could reasonably be expected to significantly affect an individual's rights or interests. If that position changes, this policy will be updated to describe the kinds of personal information used and the kinds of decisions made.
3. APP 2 — Anonymity and pseudonymity
Given Kasa's services and its obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), clients cannot deal with us anonymously or under a pseudonym. General enquiries may be made anonymously, but if the personal information required by the client onboarding process is not provided we may be unable to provide, or may have to withdraw, our services.
4. Collection (APP 3, 4, 5)
APP 3 — Solicited information. We collect only personal information that is reasonably necessary for our functions, by lawful and fair means. We collect sensitive information only with consent and where reasonably necessary.
APP 4 — Unsolicited information. Where we receive unsolicited personal information we could not have collected under APP 3, we destroy or de-identify it as soon as practicable if lawful and reasonable to do so.
APP 5 — Notification. At or before the time we collect personal information, we take reasonable steps to notify the individual of: our identity and contact details; the fact and circumstances of collection; whether collection is required or authorised by law; the purposes of collection; the main consequences if the information is not collected; the entities we usually disclose such information to; that this policy explains how to access/correct information and how to complain; and whether we are likely to disclose the information overseas and, if practicable, the countries involved.
5. Use and disclosure (APP 6, 7, 8, 9)
APP 6 — Use or disclosure. We use personal information only for the purpose for which it was collected, a directly related purpose the individual would reasonably expect, or as consented to or required/authorised by law. Typical purposes: providing financial services; establishing and administering accounts and investments; implementing investment instructions and processing withdrawals; reporting investment performance; keeping clients informed about our services; monitoring and improving our services; processing employment applications; and meeting legal and regulatory obligations.
We may disclose personal information to service providers acting for Kasa — including our MDA custodian and executing broker (Interactive Brokers Australia Pty Ltd, AFSL 453554), and providers of auditing, IT and cloud, banking, mail/archival, and financial or legal advisory services — and to third parties where required or authorised by law. We do not otherwise disclose personal information to external parties.
APP 7 — Direct marketing. We do not use or disclose personal information for direct marketing without consent or a reasonable expectation, and we always provide a simple opt-out.
APP 8 — Cross-border disclosure. Kasa's client accounts are held with Interactive Brokers Australia. Personal information may be disclosed to overseas recipients for the purpose of Kasa providing or receiving essential services (likely including the United States — the Interactive Brokers group and cloud/email providers). Where we disclose personal information overseas we take reasonable steps to ensure the recipient handles it consistently with the APPs, and we identify the relevant countries where practicable.
APP 9 — Government identifiers. We do not adopt, use or disclose a government-related identifier (e.g., Tax File Number, Medicare number) except as required or authorised by law.
6. Integrity and security (APP 10, 11)
APP 10 — Quality. We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up to date and complete.
APP 11 — Security. We take reasonable steps — including technical and organisational measures — to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These include: access controls and multi-factor authentication on our systems; encryption of data in transit and at rest where available; due diligence on service providers that handle personal information (including Interactive Brokers and our cloud/email provider); secure document storage and a clean-desk practice; and de-identifying or destroying personal information we no longer need for any lawful purpose.
7. Notifiable data breaches
Kasa complies with the Notifiable Data Breach scheme (Part IIIC of the Privacy Act). If we suspect an eligible data breach — unauthorised access to, disclosure of, or loss of personal information that is likely to result in serious harm to an affected individual — we will assess it expeditiously (and, where required, within 30 days), take reasonable steps to contain and remediate it, and, where it is an eligible data breach, notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable. The Privacy Officer maintains a record of breaches and assessments.
8. Access and correction (APP 12, 13)
APP 12 — Access. Individuals may request access to the personal information we hold about them by writing to the Privacy Officer. We respond within 30 days and provide access in the manner requested where reasonable and practicable. In limited circumstances the law permits us to refuse access (for example, where access would pose a serious threat to life, health or safety, or where the request is frivolous or vexatious); if we refuse we give written reasons and explain how to complain. A reasonable access fee may apply where permitted by law.
APP 13 — Correction. We take reasonable steps to keep personal information accurate, up to date, complete, relevant and not misleading. Individuals may request a correction by writing to the Privacy Officer; we respond within 30 days, and if we refuse we give written reasons and explain how to complain.
9. Contact and complaints
Privacy Officer: Alipasha Razzaghipour Address: Suite 4, 8/92A Mona Vale Road, Warriewood NSW 2102 Phone: +61 481 217 566 Email: [email protected]
If you have a question or wish to complain about how we have handled your personal information, please contact the Privacy Officer. We will acknowledge and investigate your complaint and respond within a reasonable time. If your concern is not resolved to your satisfaction, you may contact the Office of the Australian Information Commissioner (OAIC) on 1300 363 992 or at www.oaic.gov.au.
10. Website users and cookies
If you visit our website, our systems may record the date and time of your visit, the pages accessed and information downloaded, for statistical, reporting and maintenance purposes. Our website may use cookies; most browsers let you erase or block cookies, though some parts of the site may not function fully without them. No internet transmission is fully secure, so we cannot warrant the security of information sent to or from us online. Our website may link to other sites whose privacy practices we do not control.
11. Changes to this policy
We may update this policy from time to time. The current version is published and dated above.