Who we are: Candid Property Pty Ltd (ABN: 91 682 820 471). Licence No. 4866990. We respect your privacy. This Policy explains how we collect, use, disclose and protect personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1) Introduction and Scope
Candid Property Pty Ltd ("Candid Property", "we", "us", "our") is a boutique buyer's agency operating in and around Ipswich, Queensland. We help clients buy property, and in doing so we collect and handle personal information about buyers, sellers, and other parties connected to a transaction.
This policy explains what personal information we collect, why we collect it, how we store and protect it, who we might share it with, and how you can access or correct your information. It applies to all personal information handled by Candid Property, whether collected through our website, in person, by phone, by email, or through any other channel.
We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in that Act. As a Queensland-licensed real estate business, we also comply with obligations under the Property Occupations Act 2014 (Qld) and related regulations concerning record keeping and client authorisations. From 1 July 2026, Candid Property is also a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the AML/CTF Act), and this policy sets out how personal information collected for that purpose is handled. We are bound by the Privacy Act regardless of our size, both because of our AML/CTF reporting obligations and because we may sometimes receive a payment from a professional we refer you to if that referral results in a successfully completed contract, which itself removes any small business exemption that might otherwise apply.
2) What personal information we collect
The personal information we collect depends on the nature of our relationship with you. It may include:
General client information
Full name, date of birth, contact details (address, phone, email)
Employment details and financial capacity information relevant to a property search or purchase
Property preferences, budget, and search criteria
Correspondence and notes from meetings, calls, and emails
Transaction-related information
Details of properties inspected, offers made, and contracts entered into
Information about lenders, solicitors, conveyancers, and financial arrangements connected to a purchase
Details relevant to government and Defence homeownership entitlements we assist with, including but not limited to the Defence Home Ownership Assistance Scheme (DHOAS), the Home Purchase Assistance Scheme (HPAS), the Home Purchase or Sale Expenses Allowance (HPSEA), the First Home Owner Grant (FHOG), the First Home Guarantee (5% deposit scheme), and the First Home Super Saver (FHSS) Scheme, where a client has asked us to help navigate these or similar schemes
Identity verification and AML/CTF information
Where a matter is captured by the AML/CTF Act (currently anticipated from Form 6 signing for buyer's agency engagements), we are required to collect and verify:
Certified copies or sightings of government-issued identification (such as a driver licence or passport)
Proof of address
Source of funds information
Beneficial ownership information, where a client is acting on behalf of a trust, company, or other entity, including details of individuals who ultimately own or control that entity
Politically exposed person (PEP) status, where relevant
We only collect the information reasonably necessary for the purpose of providing our services or meeting a legal obligation. We do not collect sensitive information (such as health information) unless it is directly relevant to a transaction and you have provided it voluntarily. If you do not provide the identification, source of funds, or beneficial ownership information required under the AML/CTF Act, we will not be able to service you on a matter that requires it.
3) Why we collect your personal information
We collect and use personal information to:
Provide buyer's agency services, including property search, negotiation, and purchase support
Communicate with you about your search, transactions, and our services
Liaise with third parties involved in a transaction on your behalf
Meet our legal and regulatory obligations, including under the AML/CTF Act and Queensland real estate licensing requirements
Verify your identity and, where applicable, the beneficial ownership of an entity you represent
Maintain accurate business and financial records
Improve our services and, where you have consented, send you relevant updates or marketing
We will not use your personal information for a purpose other than the one it was collected for unless the APPs allow it, for example where a secondary purpose is related to the primary purpose and you would reasonably expect it, or where required by law.
4) How we collect your information
We collect personal information directly from you wherever practicable, through:
Our website enquiry forms and email correspondence
Phone calls and in-person meetings
Signed engagement documents, including the Buyer's Agency Agreement and Form 6
Online advertising platforms, including but not limited to Meta and Google, where you have opted in to being contacted through them
Third-party lead generation providers, who pass on your contact details to us in relation to our buyer's agency services
We may also collect information from third parties in the course of a transaction, including real estate agents, lenders, solicitors and conveyancers, local councils, and publicly available property and title records. Where we collect information from a third party, we take reasonable steps to ensure you are aware this policy applies.
5) How we store and protect your information
We take the security of your personal information seriously and apply reasonable technical and organisational measures to protect it from misuse, interference, loss, and unauthorised access, modification, or disclosure. This includes:
Storing digital records in secure, access-controlled cloud systems (including Google Workspace) protected by passwords and, where available, multi-factor authentication
Limiting access to personal information to what is needed for a person's role. As a small business, personal information is primarily accessed by our director, with limited access extended to contracted service providers under confidentiality obligations where necessary
Encrypting our laptops and protecting them with passwords. If a device is lost or stolen, it can be remotely disabled to prevent access by opportunistic intruders
Not holding identification documents collected for AML/CTF purposes on our own servers or devices. These are collected and verified through our dedicated AML/CTF verification provider, which applies its own stringent security measures to the records it holds on our behalf
Maintaining a secure backup of client records separate from our primary system, so that records remain available and protected even if our main account is lost, compromised, or inaccessible
Destroying or de-identifying personal information once it is no longer needed, except where we are required by law to retain it. Client and transaction information is retained in our CRM for the life of the company, so that we can maintain an accurate client history and support ongoing client management and client relations. If Candid Property ceases trading, these records are retained in a secure offline backup for a further 7 years for audit purposes. Enquiry and lead information is retained for an ongoing relationship purpose and reviewed every 3 years. Identification documents held by our AML/CTF verification provider are destroyed by that provider once no longer required under the AML/CTF Act
Use of artificial intelligence tools
Candid Property uses artificial intelligence and generative AI tools to support parts of our business operations, including Claude (Anthropic) and Gemini within Google Workspace (Google). These tools are used under commercial business agreements, not free consumer-grade access, and personal information may be processed through them as part of our normal workflows, such as drafting correspondence, research, and file management connected to your matter.
We only use AI providers under commercial terms that exclude our data being used to train their models, and we take reasonable steps to satisfy ourselves these providers meet protections equivalent to the APPs. We do not use free, consumer-grade AI tools for client information. Personal information you provide may also be held in our CRM as part of our normal business records, consistent with the storage and retention arrangements set out earlier in this section.
6) Access to and correction of your personal information
You have the right to request access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete, or misleading.
To make a request, contact our Privacy Officer using the details in section 12. We will respond within a reasonable period, generally within 30 days. We may need to verify your identity before releasing information. In some circumstances permitted under the Privacy Act, such as where access would unreasonably impact the privacy of another person, we may need to limit or refuse access, and we will explain our reasons if this occurs.
There is generally no charge for making a request, though we may charge a reasonable fee to cover the cost of retrieving and providing access to information in some cases.
7) Disclosure to Third Parties
We disclose personal information to third parties only where necessary to provide our services, where you have consented, or where required by law. Depending on the nature of your matter, this may include:
Real estate agents and vendors, in the course of making enquiries, inspections, and offers
Solicitors and conveyancers acting on a transaction
Lenders, mortgage brokers, and financial institutions, where relevant to your purchase
Local councils and government bodies, for property, planning, or rates enquiries
Building and pest inspectors and other contracted service providers
AUSTRAC (the Australian Transaction Reports and Analysis Centre), where we are required to report under the AML/CTF Act
Our professional advisers, such as our accountant or legal counsel, where necessary for the operation of our business
Regulatory or law enforcement bodies, where required or authorised by law
Where we refer you to another professional, such as a solicitor, conveyancer, mortgage broker, or building and pest inspector, we only pass on your details with your permission at the time of referral. We do not share your information with a referred professional without first confirming you want to be put in touch with them. We do not accept referral fees simply for making an introduction. In some cases, a professional we refer you to may pay us if their engagement with you results in a successfully completed contract. Where this applies, we will tell you before passing on your details, so you can decide whether to proceed.
We do not sell your personal information to third parties. Some of the platforms we use to run our business, including Google Workspace (storage, email, and Gemini) and our CRM, along with Claude (Anthropic) and Meta (advertising), may store or process data on servers located overseas, principally in the United States. We only use providers with their own privacy and security commitments, and as set out in section 5, our AI providers are engaged under commercial agreements that exclude our data being used for their model training. We take reasonable steps to satisfy ourselves these providers handle personal information consistently with the APPs, though we note this reliance is a practical limit on our direct control once data leaves Australia.
Marketing use of client stories and images
We sometimes feature real client testimonials, reviews, results, case studies, or images in our marketing, including on our website and social media. We only do this with your specific, informed consent obtained before publication, and we will confirm what will be used and where before it goes live. You can withdraw this consent and ask us to remove published material at any time by contacting our Privacy Officer.
8) Cookies & digital data
Our website may use cookies and similar tracking technologies to understand how visitors use our site and to improve your experience. Cookies may collect information such as your IP address, browser type, pages visited, and time spent on our site.
You can manage or disable cookies through your browser settings, though this may affect how our website functions. We may also use website analytics and advertising tools (such as Meta advertising) that collect information about your interaction with our online content. Where these tools are used for marketing purposes, you can opt out by contacting us or adjusting your platform preferences.
9) AML/CTF compliance: Collection, use, and retention
As a reporting entity under the AML/CTF Act, Candid Property is required to conduct customer due diligence (CDD) on clients before or during the course of certain transactions. This includes verifying identity, and where a client acts through a trust, company, or other structure, identifying the beneficial owners of that entity.
Information collected for AML/CTF purposes is:
Collected only to the extent required to meet our legal obligations
Collected and held by our dedicated AML/CTF verification provider rather than on our own servers or devices, and accessed only by personnel who need it to meet our compliance obligations
Retained by that provider for as long as required under the AML/CTF Act, and destroyed once no longer required
Disclosed to AUSTRAC where we are required to submit a report, such as a suspicious matter report, and in these circumstances we may be legally prohibited from informing you that a report has been made ("tipping off")
Our general client and transaction records, separate from AML/CTF identification documents, are retained in our CRM for the life of the company, and in a secure offline backup for 7 years after the company ceases trading, as set out in section 5.
Where AML/CTF obligations require us to retain or disclose information despite a general request for access, correction, or deletion under section 6, we will explain the legal basis for this to the extent we are permitted to do so.
10) Data breach notification
If we become aware that personal information we hold has been subject to unauthorised access, disclosure, or loss, and this is likely to result in serious harm to an individual, we will act in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act. This means we will investigate promptly, take steps to contain and remediate the breach, and where required, notify affected individuals and the Office of the Australian Information Commissioner (OAIC) of the breach, its likely consequences, and the steps we recommend you take.
If you are affected, we will contact you by email and by phone to explain what information may have been involved and what we are doing about it. We do not hold identification documents on our own servers or devices (see section 5), and our AML/CTF verification provider maintains its own security measures over the records it holds on our behalf.
11) Complaints
If you believe we have breached the Privacy Act, the APPs, or this policy, you can lodge a complaint with our Privacy Officer using the contact details below. Please provide enough detail for us to investigate properly.
We will acknowledge your complaint within a reasonable period and aim to resolve it within 30 days. If you are not satisfied with our response, or if you would prefer to raise the matter externally, you can contact the Office of the Australian Information Commissioner (OAIC):
Website: www.oaic.gov.au
Phone: 1300 363 992
12) Contact us / Privacy Officer
Questions, requests, or complaints about this policy or how we handle your personal information can be directed to:
Privacy Officer
Candid Property Pty Ltd
Jason Neumann, Director
Email: [email protected]
Phone: 0421 250 954
13) Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our services, or the law, including future AML/CTF Tranche 2 guidance as it develops. This policy will be reviewed at least once every 12 months, or sooner if there is a material change to our obligations. The current version will always be available on our website, with the effective date shown at the top of this document.