Privacy Policy Lexden Financial Services Ltd
June 2026
1. Statement of Policy
1.1 Objectives
This Privacy Policy deals with the collection, security, use and disclosure of personal information gathered by Lexden Financial Services Ltd (AFS Licence No: 237628) pursuant to the Privacy Act 1988 (Cth) (Privacy Act) including the Australian Privacy Principles (APPs). Lexden Financial Services Ltd (Lexden) is committed to ensuring the confidentiality and security of any of your personal information that is disclosed to us.
1.2 Application
This Policy explains how Lexden, in its capacity as Responsible Entity of a registered retail managed investment scheme, may collect, use, share and retain information about you, and the choices you have in relation to the collection and use of your personal information.
1.3 Amendments
Any amendments to this Privacy Policy will be posted on our website.
2. Collection of Personal Information
Lexden collects personal information through a variety of methods and contact points during its business. In some cases, we may also collect personal information through third parties or intermediaries.
The type of information collected may include the following:
- Name, gender and date of birth;
- Contact details;
- Tax File Number and taxation records
We will take steps that are reasonable in the circumstances to destroy or de-identify documents that we do not require for the purposes of providing services to you. We are only permitted to retain the minimum information that we require. When you visit our website, we may use ‘cookies’ or similar technologies to collect data. A cookie is a small file, typically of letters and numbers, downloaded onto a device when you access a website. Our website collects the following information from users:
- your server address;
- your top-level domain name (e.g., .com, .gov.au, etc.)
- the date and time of your visit to the site;
- the pages you accessed;
- the previous site you have visited; and
- the type of browser you are using.
In addition, we may have to collect certain information about you where we are required to do so by law.
This includes the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), also known as the AML/CTF Act requires us as a reporting entity to collect personal information to verify your identity, ascertain whether you might be a politically exposed person, and assess whether you present a risk from a money laundering or terrorism financing perspective, prior to providing certain services to you. This was recently amended.
For investors who provided identity documents prior to 31 March 2026, Lexden retains copies of those documents for 7 years from the end of the investor relationship or the date of the last transaction.
For investors who provide identity documents after 31 March 2026, in accordance with the PrivacyAct 1988 (Cth), Lexden does not retain copies of source identity documents following the completion of identity verification, only the data extracted from the identity document is retained.
2.1 Anonymity
The Privacy Act allows you to choose to remain anonymous or use a pseudonym in your dealings with Lexden. For example, you may choose not to provide your name or contact details if enquiring about a product or service. However, this option will not be available to you where it is impractical or unlawful for us to provide a service or product without verifying your identity.
2.2 Unsolicited Information
There may be instances where Lexden comes into possession of personal information that it has not requested. If this occurs, we may be permitted to record or use this information if the information could have been collected through the ordinary course of our business for the purposes of providing you the financial service or financial product. However, if the information was not collected for the purpose of providing the financial services, we will take reasonable steps to destroy or de-identify it.
3. Management of Personal Information
Personal information that is collected may be stored electronically or in hard copy. Such personal information may be held directly by us or by an administrator, or by a third party, which we have engaged to provide services.
We have implemented processes and systems to ensure that personal information is protected and used only for the purposes for which it was collected. Australian Privacy Principle 11.1 requires us to take active measures to ensure the security of personal information that we hold, and to actively consider whether it is permitted to retain personal information.
We ensure that we have measures to handle data that we collect:
- Database system access is controlled via secure access controls including password complexity, Multi-Factor Authentication (MFA).
- Third party application security is reflected in outsourcing agreements to reflect relevant privacy law obligations which require the third parties to have adequate procedures to detect and respond to cyber security incidents;
- Internal access to client records including government related identifiers such as tax file numbers and our databases is restricted based on employees’ roles and responsibilities;
- Authorisation processes are in place for change to access;
- Password encryptions and regular changes to passwords apply; and
- Client records in hard copy format are secured and archived where appropriate.
Identity Document Handling
Where Lexden is required to verify your identity for AML/CTF purposes, you will be asked to provide a copy of an identity document such as a passport or driver’s licence. Once received, Lexden completes the following data fields based on the identity document: full name, date of birth, residential address, document type, document number, document expiry date, date received and recorded, and the name of the staff member who recorded the information. The data is stored in a secure location, accessible only by authorised personnel.
Lexden retains personal information only for as long as it is required for the purpose for which it was collected or as required by law. Identity document copies collected prior to 31 March 2026 are subject to a documented destruction schedule and are permanently destroyed upon expiry of the applicable retention period. Where Lexden is no longer required to maintain any other personal information and does not need to rely on it, Lexden will promptly and securely destroy or de-identify it. Where records are held by a third party, Lexden will take reasonable steps to ensure the personal information is destroyed or de-identified in accordance with the same standards.
4. Notifiable Data Breaches
Lexden is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).
An eligible data breach occurs where there has been unauthorised access to, disclosure of, or loss of personal information held by Lexden, and a reasonable person would conclude that this is likely to result in serious harm to one or more affected individuals.
Where Lexden determines that an eligible data breach has occurred, Lexden will notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable. Where AML/CTF tipping-off restrictions under the AML/CTF Act apply, notifications will be managed in a manner consistent with those restrictions.
5. Use and Disclosure of Personal Information
We collect, hold, and disclose your personal information for the following purposes:
- as a necessary part of providing our services to you;
- to promote and market our products and services to you or provide you with information that we believe may be of interest to you (unless as directed otherwise);
- to help us research the needs of our customers and to market our services with a better understanding of your needs and the needs of customers generally;
- to allow us to provide advertising material to you regarding us, our services and other business partners (unless as directed otherwise); and
- other purposes related to any of the above.
We will only use your information for the purposes for which it was collected (primary purposes) or a purpose related to the primary purpose, if this use would be reasonably expected by you, or otherwise, with your consent.
6. Disclosure to Third Parties
We may disclose your information to necessary third parties, who assist us to provide, manage and administer our services. Information provided to third parties will be dealt with in accordance with that entity’s privacy policy, which must comply with the Privacy Act and Australian Privacy Principles.
People we may disclose your information to include:
- third parties that provide goods and services to us or through us;
- third parties, such as marketing and digital agencies, who may send to you our e-newsletters on our behalf;
- our website host or software application providers;
- Government authorities such as the ATO; and
- Our AML/CTF compliance service provider.
We will only disclose your personal information to a third party if:
- you have provided consent to the disclosure to us or the third party; or
- the disclosure is related to the purpose for which it was collected; or
- it is required by law or order of an Australian court or tribunal; or
- exceptional circumstances apply, such as an imminent risk to health.
The disclosure must only be information that relates to the primary purpose for which the information was collected.
We may need to share some of your information with organisations outside of Australia if we have service providers located overseas. We may also store your information in networked or electronic systems. Because the information may be accessed from various countries through an internet connection, it may not always be practicable to know from which country your information is being accessed. If your information is stored elsewhere, disclosures may occur in countries other than Australia and we are legally responsible for any data losses and breaches.
We will not disclose information to an overseas recipient unless:
- we have taken reasonable steps to ensure that the overseas recipient complies with the Australian Privacy Principles,
- we have obtained consent from the investor individual and/or entity, and/or
- the disclosure is required or permitted by law.
Currently there is no overseas recipient.
7. Providing Access to Personal Information
You are entitled to have access to and seek correction of any personal information that we may hold about you. We require that requests for access to or to update or correct your personal information, be in writing, outlining the details of your request. Such requests should be addressed to the Privacy Officer via the details provided in this Policy.
We will take appropriate steps to verify your identity (or verify that you act as an authorised agent of the individual concerned) before granting a request to access your personal information.
We will respond to your request for access to your personal information within a reasonable time after you make the request and if access is granted, access will be provided within 30 days from your request. We will, on request, provide you with access to your personal information or update or correct your personal information, unless we are lawfully prohibited from granting such a request.
A few examples of data request prohibitions include where:
- giving access would be unlawful;
- we are required or authorised by law or a court/tribunal order to deny access; or
- giving access is likely to prejudice one or more enforcement related activities conducted by an enforcement body.
Where your request for access is accepted, we will provide you with access to your personal information in a manner, as requested by you, providing it is reasonable to do so.
Your request for correction will be dealt with within 30 days, or such longer period as agreed by you. If we deny your request, we will provide you with a written notice outlining reasons for the refusal and the process for making a complaint about the refusal to grant your request.
Upon accepting a request for correction of your personal information, we will take all steps that are reasonable in the circumstances, having regard to the purpose for which your information is held, to correct your personal information.
8. Complaints Handling Process
If you believe that we have breached a term of this Policy or the Privacy Act, you may submit a complaint to us. Any written complaint can be emailed or posted to us using the contact details set out below. You must include your contact details for us to contact you regarding your complaint.
Our Privacy Officer will consider your complaint and respond as soon as reasonably possible, but not more than 30 days from receiving the complaint.
If you are unsatisfied with the outcome of your complaint you may refer your complaint to the Office of the Australian Information Commissioner.
9. Contact Us
If you wish to:
- gain access to your personal information; or
- make a complaint about a breach of this policy; or
- contact us with a query about how your information is collected and/or used; or
- contact us regarding any other matter concerning this Policy,
you may speak directly with our staff who will do their best to resolve your issue. Alternatively, you can write to us or send us an email so that our Privacy Officer can consider the matter. We will respond to you as soon as reasonably possible.
If you do not wish to receive direct marketing from us, please contact our Privacy Officer via the details below. Our contact details are as follows:
Privacy Officer
Contact: [email protected]
Phone: 03 9982 4540
Postal address:
The Privacy Officer, Lexden Financial Services Ltd
Level 15/28 Freshwater Pl, Southbank VIC 3006
For more information on privacy see the Office of the Australian Information Commissioner’s website at: www.oaic.gov.au.