PRIVACY

Privacy Policy

How Morbanx collects, uses, stores and discloses personal information.

Effective date: 12 July 2026

Morbanx Pty Ltd as trustee for the A R Larcombe Family Trust ABN 93 362 515 953

1. About this Privacy Policy

This Privacy Policy explains how Morbanx Pty Ltd as trustee for the A R Larcombe Family Trust ABN 93 362 515 953 (Morbanx, we, us and our) collects, holds, uses, discloses, secures and otherwise manages personal information.

This Policy applies to Morbanx generally, including its mortgage-broking activities, Morbanx Aggregation, its websites, digital services, broker and business relationships, employment and contractor activities, and other dealings with individuals.

Morbanx is a corporate credit representative of Mortgage Specialists Pty Ltd ABN 48 612 422 178, trading as Specialist Finance Group, Australian Credit Licence 387025.

This Policy also includes information about how we manage credit-related information collected in connection with an application for credit or a credit facility.

2. Our privacy commitment

We understand the importance of protecting personal information and are committed to handling it in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, applicable credit-reporting requirements and other relevant laws.

We aim to manage personal information in an open and transparent manner and to collect, use and disclose it only where reasonably necessary for our functions and activities, as authorised or required by law, or with the individual’s consent.

By providing personal information to us, an individual acknowledges that we may collect, use and disclose that information as described in this Policy and in any collection notice, consent, authority or other arrangement that applies to the relevant service.

3. Who this Policy applies to

This Policy may apply to personal information about:

  • mortgage-broking clients, prospective clients, guarantors, applicants and other persons connected with a credit application;
  • mortgage brokers, prospective brokers, credit representatives and representatives of broker businesses;
  • referrers, business partners, service providers, professional advisers and industry contacts;
  • users of our websites, calculators, forms, resources, communities and digital services;
  • employees, contractors, applicants and other people who work with or apply to work with Morbanx; and
  • other individuals with whom Morbanx deals in the course of its business.

4. Anonymity and pseudonymity

Where it is lawful and practicable, individuals may deal with us anonymously or using a pseudonym. For example, we may provide general information without requiring identification.

However, we will usually need to identify an individual where we provide mortgage-broking or credit assistance services, assess an application, perform compliance or due-diligence checks, enter into an aggregation or other contractual relationship, or otherwise need identity information to comply with legal, regulatory, lender, licensee or operational requirements.

5. Personal information we may collect

The personal information we collect depends on the nature of our relationship with the individual and may include:

Identity and contact information

  • name, residential and postal address, email address, telephone number and other contact details;
  • date of birth, gender and identity-verification information;
  • government-issued identification details and copies of identification documents;
  • occupation, employment history, business details and professional qualifications;
  • family, household and relationship information relevant to a credit application or service; and
  • signatures, consents and authorities.

Financial and credit information

  • income, expenses, assets, liabilities, savings and other information about an individual’s financial position;
  • bank statements, transaction records, credit-card or store-card statements and loan statements;
  • credit applications, credit limits, repayment history, defaults, hardship information and other credit-related information;
  • credit reports and information obtained from credit reporting bodies;
  • information about insolvency, bankruptcy, court proceedings and publicly available records; and
  • information relating to the purpose, structure and proposed terms of a credit application.

Broker and aggregation information

  • business ownership, structure, trading names and Australian Business Number details;
  • credit representative, licence, membership and accreditation information;
  • employment history, qualifications, continuing professional development and compliance records;
  • lender-panel usage, business volumes, pipeline, commission and operational information;
  • professional indemnity, cyber insurance and other insurance information;
  • references, background checks and onboarding information;
  • information about complaints, incidents, audits, file reviews and remediation; and
  • information provided in connection with broker support, training, business planning or community participation.

Website and technology information

  • IP address, device information, browser type, operating system and approximate location;
  • website pages viewed, links selected, forms submitted and interactions with our digital services;
  • cookies, analytics identifiers and similar technologies;
  • appointment and enquiry information; and
  • communications through email, SMS, telephone, video meeting, social media or other digital channels.

Sensitive information

We may collect sensitive information where it is reasonably necessary for our functions or activities and the individual has consented, or where collection is otherwise authorised or required by law.

Sensitive information may include health information, criminal-record information, biometric information, racial or ethnic origin, religious beliefs or other sensitive information relevant to a service, insurance referral, compliance assessment, background check or legal requirement.

We will use sensitive information only for the purpose for which it was collected, or as otherwise permitted by law.

Government-related identifiers

We may receive government-related identifiers, including tax file numbers, where they appear in documents provided to us. We do not adopt a government-related identifier as our own identifier and will use or disclose such information only where authorised or required by law.

6. How we collect personal information

We may collect personal information:

  • directly from the individual, including through forms, interviews, telephone calls, email, SMS, meetings, websites and digital applications;
  • from a joint applicant, guarantor, family member, representative or authorised person;
  • from employers, accountants, lawyers, conveyancers, real estate agents, financial advisers or other professional advisers;
  • from lenders, credit providers, mortgage insurers, valuers, credit reporting bodies and other finance-industry participants;
  • from Specialist Finance Group and other licensee, aggregation, compliance and technology providers;
  • from brokers, referrers, business partners and service providers;
  • from government agencies, regulators, registers and publicly available sources;
  • from social media and other online sources where it is lawful and appropriate to do so; and
  • automatically through use of our websites and digital services.

7. Unsolicited personal information

If we receive personal information that we did not request, we will determine whether we could have collected it lawfully and whether it is reasonably necessary for one or more of our functions or activities.

If we could not have collected the information, and we are not required or authorised by law to retain it, we will take reasonable steps to destroy or de-identify it.

8. Why we collect, hold, use and disclose personal information

We may collect, hold, use and disclose personal information for purposes including:

Mortgage broking and credit assistance

  • responding to enquiries and determining whether we may be able to assist;
  • assessing, preparing, submitting and managing applications for credit or related services;
  • identifying suitable lenders or products and communicating with lenders and service providers;
  • obtaining valuations, credit reports, identity checks and other supporting information;
  • managing credit applications, settlements, variations, reviews and ongoing client relationships;
  • complying with responsible-lending, disclosure, record-keeping and other credit obligations; and
  • protecting clients and Morbanx from fraud, error and unlawful activity.

Aggregation and broker services

  • assessing enquiries and applications from brokers and broker businesses;
  • conducting onboarding, due diligence, compliance and eligibility checks;
  • supporting lender accreditation, licence and credit-representative processes;
  • providing broker support, training, professional development, technology and community services;
  • managing commissions, fees, systems, access and operational matters;
  • conducting audits, file reviews, risk monitoring and quality assurance;
  • responding to complaints, incidents and compliance matters; and
  • managing the aggregation relationship and related contractual obligations.

Business and administration

  • managing our relationship with individuals and organisations;
  • communicating about services, appointments, events, training and business matters;
  • maintaining records and administering contracts;
  • improving our websites, systems, resources and services;
  • managing employees, contractors and recruitment;
  • obtaining professional, legal, accounting, compliance or technology advice;
  • meeting taxation, accounting, insurance and audit requirements; and
  • complying with laws, court orders, regulatory obligations and lawful requests.

9. What happens if personal information is not provided

Individuals are generally not required to provide personal information to us. However, if required information is not provided, we may be unable to respond fully to an enquiry, verify identity, assess or submit a credit application, provide mortgage-broking or aggregation services, satisfy compliance requirements, enter into an agreement, or otherwise continue the relevant relationship.

10. Notification at the time of collection

When we collect personal information, we may provide a collection notice or consent that explains matters including the purpose of collection, the consequences of not providing information, the types of entities to which information may be disclosed, direct marketing, overseas disclosure, and how to access this Policy or make a complaint.

A collection notice, consent, authority or service-specific document may contain additional information and should be read together with this Policy.

11. Use and disclosure of personal information

We generally use and disclose personal information for the primary purpose for which it was collected, for a related purpose that would reasonably be expected, with the individual’s consent, or as otherwise authorised or required by law.

Depending on the relevant service, we may disclose personal information to:

  • lenders, credit providers, lessors, mortgage insurers and other product providers;
  • credit reporting bodies, identity-verification providers and fraud-prevention services;
  • valuers, conveyancers, lawyers, accountants, financial advisers, real estate agents and other professional advisers;
  • Specialist Finance Group and other licensee, compliance, aggregation and audit providers;
  • lender business-development managers and accreditation teams;
  • technology, cloud, communications, document-management, booking, CRM, cybersecurity and data-storage providers;
  • payment, commission and accounting service providers;
  • insurers, claims managers and professional indemnity providers;
  • government agencies, regulators, courts, tribunals, law-enforcement bodies and dispute-resolution bodies;
  • related entities, contractors, consultants and other service providers; and
  • other persons or organisations where the individual has consented or disclosure is authorised or required by law.

12. Credit-related information

This section applies where we collect or handle credit-related information in connection with a consumer credit application, credit assistance or related service.

Credit-related information may include:

  • identification information;
  • consumer credit liability information;
  • repayment history information;
  • financial hardship information;
  • default information;
  • payment information;
  • new arrangement information;
  • court proceedings and personal insolvency information;
  • publicly available information;
  • credit scores, credit reports and creditworthiness assessments; and
  • information derived from information disclosed by a credit reporting body.

We may obtain credit-related information from credit reporting bodies and disclose information to lenders, credit providers, mortgage insurers and other authorised recipients for the purposes of assessing and managing credit applications, verifying information, preventing fraud and complying with legal or regulatory obligations.

The credit reporting bodies used in a particular application may be identified in the relevant privacy consent or collection notice. Individuals may contact those bodies directly for information about their credit-reporting policies, access and correction rights, and fraud-ban arrangements.

Morbanx does not ordinarily act as a credit reporting body and does not itself maintain a consumer credit-reporting database.

13. Direct marketing

We may use personal information to send information about products, services, training, events, resources or opportunities that we reasonably believe may be relevant, where permitted by law.

Marketing communications will provide a way to opt out. We do not charge individuals for opting out and will take reasonable steps to ensure that opt-out requests are actioned.

We do not sell personal information. We do not use sensitive information for direct marketing unless permitted by law and with appropriate consent.

14. Website, cookies and analytics

When an individual uses our websites or digital services, we may collect technical and usage information through cookies, analytics tools, server logs and similar technologies.

This information may be used to:

  • operate and secure the website;
  • remember preferences and improve usability;
  • understand website traffic and engagement;
  • measure the effectiveness of content and communications;
  • diagnose technical issues; and
  • protect against fraud, misuse and unauthorised access.

Browser settings may allow users to block or delete cookies. Some website functions may not operate correctly if cookies are disabled.

15. Social media and public channels

We may collect information when individuals interact with us through social media or other public channels. Individuals should not provide financial, identity, client, confidential or sensitive information through a public forum.

Information shared publicly may be accessible to the social-media provider and other users and will also be subject to the provider’s privacy practices.

16. Cross-border disclosure and overseas storage

We may use cloud, technology, document-processing, audit or other service providers that store or access personal information outside Australia.

Because electronic and cloud services may use distributed infrastructure, the countries in which information is stored or accessed may vary and may not always be practicable to identify in advance.

Where required by law, we will take reasonable steps to ensure that an overseas recipient handles personal information in a manner consistent with applicable Australian privacy requirements, unless an exception applies.

17. Data quality

We take reasonable steps to ensure that personal information we collect, use and disclose is accurate, up to date, complete and relevant for the purpose for which it is used.

Individuals should tell us if their information changes or if they believe information we hold is inaccurate, out of date, incomplete, irrelevant or misleading.

18. Security and retention

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.

Security measures may include:

  • physical and electronic access controls;
  • passwords, authentication controls and access restrictions;
  • firewalls, malware protection, encryption and system monitoring;
  • secure document and data-storage arrangements;
  • staff and representative training;
  • confidentiality obligations;
  • service-provider due diligence and contractual controls;
  • cybersecurity, incident-response and business-continuity processes; and
  • governance over disclosure and access to information.

No method of electronic transmission or storage is completely secure. We cannot guarantee absolute security, but we will take reasonable steps appropriate to the nature of the information and the risks involved.

We retain personal information for as long as reasonably necessary for the purpose for which it was collected, to manage our relationships, or to comply with legal, regulatory, contractual, insurance, audit and record-retention requirements.

When personal information is no longer required and we are not legally required to retain it, we will take reasonable steps to destroy or de-identify it.

19. Data breaches

If we become aware of a suspected or actual data breach, we will assess and respond to it in accordance with our legal obligations and incident-response procedures.

Where the Notifiable Data Breaches scheme or another legal requirement applies, we will notify affected individuals and the Office of the Australian Information Commissioner as required.

20. Access to personal information

Individuals may request access to personal information we hold about them. We will take reasonable steps to verify identity before providing access.

We will generally respond within a reasonable period. We will not charge for making a request, although in some circumstances we may charge a reasonable cost for providing access where permitted by law.

Access may be refused or limited where permitted by law, including where access would unreasonably affect another person’s privacy, pose a serious threat to health or safety, relate to existing or anticipated legal proceedings, reveal commercially sensitive evaluative information, be unlawful, or prejudice an investigation or enforcement activity.

If access is refused, we will provide written reasons where required and explain available complaint mechanisms.

21. Correction of personal information

Individuals may ask us to correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.

If we correct information that has previously been disclosed, we will take reasonable steps to notify the recipient where required and practicable.

If we refuse a correction request, we will provide written reasons where required and explain available complaint mechanisms. An individual may also request that we associate a statement with the information recording that the individual considers it inaccurate.

22. Privacy complaints

An individual who believes that we have not complied with the Privacy Act, the Australian Privacy Principles, this Policy or an applicable credit-reporting obligation may make a complaint to our Privacy Representative:

Emailcompliance@spfgroup.com.au
Telephone08 9286 6888
PostPO Box 397, West Perth WA 6872
AttentionPrivacy Representative

Please provide sufficient details to allow us to understand and investigate the complaint. We will acknowledge and consider the complaint through our internal complaints-resolution process and aim to provide a response within 30 days, subject to any shorter period required by law.

If the individual remains dissatisfied, the complaint may be referred to the Australian Financial Complaints Authority where the matter is within its jurisdiction, or to the Office of the Australian Information Commissioner.

Australian Financial Complaints Authority (AFCA)

Office of the Australian Information Commissioner (OAIC)

Issues involving spam or telemarketing may be referred to the Australian Communications and Media Authority.

23. Contacting Morbanx

Questions, access requests or correction requests relating to this Policy may also be directed to:

EntityMorbanx Pty Ltd as trustee for the A R Larcombe Family Trust ABN 93 362 515 953
Telephone1300 131 909
Emailloans@morbanx.com.au
Websitewww.morbanx.com.au

24. Changes to this Policy

We may update this Policy from time to time to reflect changes to our business, services, technology, legal obligations or privacy practices.

The current version will be published on our website and will state its effective date. We encourage individuals to review the Policy periodically.

25. Further information

Further information about privacy rights and obligations is available from the Office of the Australian Information Commissioner.