1INTRODUCTION
This Privacy Policy explains how The Trustee for Ug Lea Family Trust trading as Very Lucky Ventures, ABN 26 847 081 003 (Very Lucky Ventures, we, us or our) collects, holds, uses and discloses Personal Information and how individuals may access or correct their Personal Information or make a privacy complaint.
We are committed to managing Personal Information in an open and transparent manner and in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable privacy laws.
This Privacy Policy applies to Personal Information we handle in connection with our business, including our website, client portal, applications, advisory and implementation services, events, communications and interactions with clients, prospective clients and other individuals.
This Privacy Policy should be read together with any collection notice or other privacy information we provide when collecting Personal Information.
Where we rely on consent to collect, use or disclose Personal Information, that consent may be withdrawn subject to applicable law and any consequences of withdrawal. Our handling of Personal Information is not based on consent merely because an individual has received or read this Privacy Policy.
We may update this Privacy Policy from time to time to reflect changes to our business, information-handling practices or legal obligations. The current version will be made available on our website and will identify its effective date.
For material changes, we will take reasonable steps to provide appropriate notice before the changes take effect where required or appropriate.
In this Privacy Policy:
(a)Client Data means information provided or made available to us by or on behalf of a client, or collected through the client’s use of the Services;
(b)Derived Data means data, insights, features, metrics or other information generated from Client Data;
(c)De-identified Data means information that has been aggregated, anonymised or otherwise processed so that no individual or client business is reasonably identifiable; and
(d)Model Improvements means models, algorithms, parameters, weights, configurations, methods and other improvements developed through the permitted use of Client Data, Derived Data or De-identified Data.
2TYPES OF PERSONAL INFORMATION WE COLLECT
(a)The types of Personal Information we collect depend on how you interact with us and the Services you use, and may include:
(i)identity and contact information, including your name, mailing or street address, email address, telephone number, occupation, role and contact preferences;
(ii)business and professional information, including information about your business, its operations, personnel, systems, clients and commercial circumstances;
(iii)financial information relating to you or your business, including revenue, expenses, profit and loss, balance sheet information, investments, savings, debts, tax position, accounts receivable and accounts payable;
(iv)personnel information contained in information made available to us by client businesses or through connected third-party platforms, including staff names, roles, remuneration, payroll information and other employment-related information;
(v)information obtained through third-party platforms that you or an authorised person connect to or authorise us to access, including accounting, CRM, practice-management, productivity and other business systems;
(vi)meeting and communication information, including correspondence, enquiries, notes, recordings, transcripts and summaries of meetings and other communications with us;
(vii)payment and transaction information, including payment method, transaction amount and date and, where applicable, direct debit authority information, although we do not ordinarily store full payment card details;
(viii)information provided through surveys, questionnaires, forms, events, training courses, promotions or other interactions with us;
(ix)technical and usage information, including IP address, device type, operating system, browser type, language settings, pages visited, links clicked and information about how you use our website, portal, applications and other online services;
(x)marketing and engagement information, including your communication preferences and your interactions with our website, emails and other marketing communications;
(xi)information about other individuals that you provide or make available to us where relevant to the Services; and
(xii)any other Personal Information you provide to us, or that we collect with your consent or where otherwise permitted or required by law.
(b)We do not actively seek Sensitive Information. However, Sensitive Information may be included incidentally in information provided to us, information obtained through connected third-party platforms or meeting records. Where we receive Sensitive Information, we will handle it in accordance with applicable privacy laws and only to the extent reasonably necessary for the relevant purpose.
3PERSONAL INFORMATION OF MINORS
(a)Our website, portal, applications and Services are designed for businesses and their advisers and are not directed at individuals under 18 years of age.
(b)We do not knowingly collect Personal Information directly from individuals under 18 in connection with the provision of our Services.
(c)Personal Information relating to individuals under 18 may nevertheless be included incidentally in information provided to us by a client business or obtained through a connected third-party platform, including where the individual is an employee or other Personnel of that business.
(d)Where we receive Personal Information relating to an individual under 18, we will handle that information in accordance with applicable privacy laws and only to the extent reasonably necessary for the purpose for which it was provided or collected.
4HOW WE COLLECT PERSONAL INFORMATION
(a)We may collect Personal Information directly from you or from third parties where this is reasonably necessary for our functions and activities and permitted by law.
(b)We may collect Personal Information when you:
(i)contact or communicate with us through our website, portal, applications, email, telephone, SMS, social media or other channels;
(ii)enquire about, purchase or receive our Services;
(iii)register for or use our portal, applications, training courses, events or other services;
(iv)complete a form, survey, questionnaire or other document;
(v)attend a meeting or other interaction with us;
(vi)make a payment or otherwise transact with us; or
(vii)interact with our website, emails, content, advertising or other online services.
(c)We may also collect Personal Information from:
(i)your employer, business, business partners, advisers or other persons authorised to provide information to us;
(ii)people or organisations that refer you or your business to us;
(iii)third-party software and platforms that you or an authorised person connect to, or authorise us to access, including accounting, CRM, practice-management and other business systems;
(iv)service providers that assist us in operating our business or providing the Services; and
(v)publicly available sources where collection is permitted by law.
(d)Where you or an authorised person connects a third-party platform to our systems, we may collect information through that platform’s available integration, API or other authorised access method. Where direct access is required for the Services and an appropriate integration is unavailable, access may instead be provided through credentials or permissions made available to us by or on behalf of the relevant client.
(e)We may use cookies, analytics technologies and similar tools when you interact with our website and other online services. These technologies may collect technical, usage and engagement information and may allow activity to be associated with an identified contact where applicable.
(f)Further information about the cookies and similar technologies we use, including how you can manage them, is set out in our Cookies Policy. (g)Where required by applicable privacy laws, we will take reasonable steps at or before the time we collect Personal Information, or as soon as practicable afterwards, to notify individuals of relevant matters concerning the collection and handling of their Personal Information.
5HOW WE USE PERSONAL INFORMATION
We may collect, hold, use and disclose Personal Information for purposes reasonably necessary for our business and the provision of our Services, including to:
(a)provide, administer, personalise and support our Services, portal and applications;
(b)perform business advisory, analysis, benchmarking, implementation, training and related services;
(c)access, analyse and work with information contained in third-party systems that a client has authorised us to access;
(d)prepare reports, recommendations, presentations, plans, benchmarks and other deliverables;
(e)prepare for, conduct, record, transcribe, summarise and document meetings and communications, obtaining consent or otherwise complying with applicable recording and surveillance laws where required;
(f)maintain client, contact and business records and administer our relationship with clients and prospective clients;
(g)process payments, issue invoices and manage accounts;
(h)communicate with you about the Services, your account, meetings, events and administrative matters;
(i)operate, secure, maintain, analyse and improve our website, portal, applications, Services and business processes, including by using Client Data, Derived Data and De-identified Data for internal research and analytics and to develop, train, fine-tune, test, evaluate and improve our internal machine-learning models, algorithms and related tools, subject to the safeguards and restrictions described under AI and Automated Tools;
(j)create aggregated and de-identified statistics, insights and industry benchmarks that do not identify an individual, client or client business;
(k)manage enquiries, complaints, disputes and legal or regulatory matters;
(l)detect, prevent and respond to fraud, misuse, security incidents and other unlawful or inappropriate activity;
(m)comply with applicable laws, regulatory requirements and lawful requests from courts, regulators or government authorities; and
(n)carry out any other purpose notified to you at the time of collection or otherwise permitted or required by law.
5.1AI AND AUTOMATED TOOLS
(a)We may use artificial intelligence, automated systems and other technology-assisted tools in providing and administering our Services, including for meeting recording, transcription and summarisation, analysis, preparation of materials, internal coding or technical assistance used to provide or support the Services, and other business or advisory support.
(b)Where these tools process Personal Information or client confidential information, we take reasonable steps to ensure that the processing is consistent with this Privacy Policy, our contractual confidentiality obligations, any applicable data processing addendum and applicable privacy laws, and apply reasonable safeguards appropriate to the information and use, which may include aggregation, de-identification, pseudonymisation, data minimisation, access controls, segregation and security monitoring.
(c)We may use Client Data and Derived Data to develop, train, fine-tune, test, evaluate and improve machine-learning models, algorithms and related tools used internally to provide, support and improve the Services, provided that we do not use Client Data for those purposes in a manner inconsistent with this Privacy Policy, any applicable data processing addendum, our contractual confidentiality obligations or applicable privacy laws.
(d)A client may identify specific categories of Client Data in writing as restricted from model training, and we will not use those categories for new training activities after a reasonable implementation period, although we may continue to use De-identified Data and retain Model Improvements that do not disclose or enable reconstruction of the restricted Client Data. We will not permit an artificial intelligence service provider to use identifiable Client Data to train or improve its general-purpose models unless the relevant client has expressly authorised that use or applicable law otherwise permits it.
(e)We may create, use, disclose and commercialise De-identified Data, including aggregated analytics, benchmarks, outputs and insights, without attribution where the information does not reasonably identify you, your business or any individual. As between a client and us, the client retains its rights in its Client Data and client-specific confidential trade secrets, and we retain all rights in our models, algorithms, tools, methods, Derived Data and Model Improvements, except that our ownership does not extend to Client Data or permit us to disclose or reconstruct a client’s confidential trade secrets.
5.2DIRECT MARKETING
(a)We may use Personal Information to send you information about our Services, events, programs and offers where permitted by applicable privacy and electronic marketing laws.
(b)Depending on the circumstances, we may communicate with you by email, SMS, telephone, social media or other channels.
(c)You may opt out of receiving direct marketing communications from us at any time by using the unsubscribe facility provided in the communication or by contacting us using the details in this Privacy Policy.
(d)We will action opt-out requests in accordance with applicable law. Opting out of marketing communications will not prevent us from sending service, account, transactional, security or other non-marketing communications where appropriate.
5.3DISCLOSURE OF PERSONAL INFORMATION
(a)We do not sell Personal Information. We may disclose Personal Information where reasonably necessary for the purposes described in this Privacy Policy, including to:
(i)our Personnel and contractors who require access to perform their roles;
(ii)cloud hosting, software, CRM, analytics, communications, payment, AI, transcription and other technology or service providers that assist us to operate our business or provide the Services;
(iii)professional advisers, including accountants, lawyers, insurers, bankers and other advisers;
(iv)third-party platforms and providers where you or a client has authorised an integration, connection or other disclosure;
(v)partner organisations where information has been aggregated or de-identified so that individuals and client businesses cannot reasonably be identified;
(vi)another person or organisation where you have authorised or directed us to disclose the information; and
(vii)courts, regulators, law enforcement agencies, government authorities or other persons where disclosure is required or authorised by law or reasonably necessary to establish, exercise or defend legal rights.
(b)Some service providers may store or process Personal Information outside Australia. Our approach to overseas disclosures is described separately in this Privacy Policy.
5.4OVERSEAS DISCLOSURE OF PERSONAL INFORMATION
(a)Some of the service providers we use may be located outside Australia or may store or process Personal Information in overseas locations.
(b)We are likely to disclose Personal Information to overseas recipients in the United States and countries within the European Union in connection with the use of cloud, software, communications, analytics, artificial intelligence and other technology or service providers.
(c)Where we disclose Personal Information to an overseas recipient, we will take reasonable steps required by applicable privacy laws to ensure that the recipient handles the Personal Information consistently with the Australian Privacy Principles, unless an exception under applicable law applies.
(d)The countries in which our overseas service providers are located may change from time to time as our providers and their processing arrangements change.
6AUTOMATED PROCESSING AND DECISION-MAKING
(a)We use automated systems, algorithms and artificial intelligence-assisted tools in connection with our Services, including to analyse business and financial information, prepare benchmarks and insights, assist with recommendations and support the preparation of materials.
(b)These systems may use:
(i)business and financial information, including revenue, expenses, profit and loss, balance sheet information, receivables and payables;
(ii)personnel information contained in data made available to us, including staff names and remuneration information;
(iii)identity and professional information, including names, roles and business affiliations; and
(iv)technical and usage information relating to use of our portal, applications and Services.
(c)Automated systems may be involved in producing or supporting the following decisions, assessments and outputs:
(i)benchmarking assessments comparing a client business’s performance against relevant benchmarks;
(ii)analytical outputs and recommendations used by our team in providing advisory Services; and
(iii)scoring, profiling or other assessments used to identify areas of business performance or operational focus.
(d)We do not make decisions solely by automated means that significantly affect an individual’s rights or interests. Where automated outputs are used in providing advice or making assessments that may significantly affect an individual’s rights or interests, those outputs are subject to human review.
(e)You may contact us using the details in this Privacy Policy if you would like further information about our use of automated processing.
7SECURITY
(a)We take reasonable steps to protect Personal Information we hold from misuse, interference, loss and unauthorised access, modification or disclosure.
(b)Our security measures may include:
(i)access controls designed to restrict access to Personal Information to Personnel and service providers who require access for legitimate business purposes;
(ii)appropriate authentication and credential-management practices;
(iii)encryption and other technical safeguards where appropriate;
(iv)security logging, monitoring and administrative controls;
(v)reasonable measures to segregate client information within relevant systems; and
(vi)contractual privacy, confidentiality and security obligations for relevant service providers.
(c)Where a client provides or facilitates access to a third-party platform or account, the client remains responsible for managing its own account permissions and credentials and should revoke our access when it is no longer required.
(d)No method of electronic transmission or storage is completely secure, and we cannot guarantee that Personal Information will always be protected from every security threat.
(e)If we become aware of a data breach involving Personal Information, we will assess and respond to the breach in accordance with applicable privacy laws, including the Notifiable Data Breaches scheme where applicable.
8RETENTION OF PERSONAL INFORMATION
(a)We retain Personal Information only for as long as reasonably necessary for the purposes for which it was collected or as otherwise required or permitted by law.
(b)The period for which we retain Personal Information depends on the nature of the information, the purposes for which it is held, our contractual and business requirements and any applicable legal or regulatory obligations.
(c)When Personal Information is no longer required for a permitted purpose, we will take reasonable steps to destroy or de-identify it, subject to any applicable contractual deletion obligation, requirement or lawful basis to retain it and our ordinary backup and archival processes; we may retain De-identified Data and Model Improvements after deletion of the underlying Client Data only where they do not identify an individual or client business or disclose or enable reconstruction of Client Data or client-specific confidential trade secrets.
9LINKS TO THIRD-PARTY WEBSITES AND SERVICES
(a)Our website, portal, applications or communications may contain links to websites, platforms or services operated by third parties.
(b)We do not control the privacy practices, security or content of third-party websites or services merely because we provide a link to them. We encourage you to review the privacy policy and terms of the relevant third party before providing Personal Information to or through that service.
(c)Where you expressly connect or authorise a third-party platform or service to interact with our systems, any handling of Personal Information by that third party is also subject to that provider’s privacy practices and terms.
10ACCESS AND CORRECTION
(a)You may request access to the Personal Information we hold about you by contacting us using the details in this Privacy Policy.
(b)We may take reasonable steps to verify your identity before providing access to Personal Information.
(c)We will respond to access requests within a reasonable period and aim to respond within 30 days. In some circumstances permitted by law, we may refuse access to some or all of the Personal Information requested. If we refuse access, we will provide written reasons for the refusal where required by law and explain any available complaint process.
(d)You may also ask us to correct Personal Information that you believe is inaccurate, out of date, incomplete, irrelevant or misleading.
(e)If we are satisfied that Personal Information requires correction, we will take reasonable steps to correct it having regard to the purpose for which it is held. If we refuse a correction request, we will provide written reasons where required by law and explain any available complaint process.
(f)We may ask you to provide information reasonably necessary for us to identify the relevant Personal Information and assess your request.
11PRIVACY COMPLAINTS
(a)If you have a concern or complaint about how we have handled your Personal Information or complied with applicable privacy laws, please contact us using the details in this Privacy Policy.
(b)Please provide sufficient information about your concern or complaint to allow us to investigate it.
(c)We will:
(i)acknowledge your complaint within 7 days;
(ii)investigate the complaint fairly and reasonably;
(iii)contact you if we require further information; and
(iv)aim to provide our response within 30 days.
(d)If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner or exercise any other rights available to you under applicable law.
12CONTACT US
For further information about this Privacy Policy or our privacy practices, or to request access to or correction of your Personal Information, make a privacy complaint or ask a question about our handling of Personal Information, please contact us using the details below:
Name: The Trustee for Ug Lea Family Trust trading as Very Lucky Ventures
ABN: 26 847 081 003
Email: privacy@veryluckyventures.com
Postal Address: Level 5, 100 Market Street, Sydney NSW 2000
Website: www.veryluckyventures.com
This Privacy Policy was last updated on 20 August 2026.