1300 268 371
1300 268 371

Privacy Policy

PRIVACY POLICY

Business Insurance Cover Services Pty Ltd
Updated July 2026

Our Privacy Policy Statement

In this Privacy Policy, 'we', 'us', 'our' and 'BICS' means Business Insurance Cover Services Pty Ltd and, where applicable, our related entities and service providers.

We respect the privacy of your personal information. This Privacy Policy sets out how we collect, store, use and disclose your personal information (including sensitive information) in accordance with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are a participant in the Community Broker Network (CBN), and our practices are aligned with CBN's privacy protocols and regulatory framework.


What Personal Information We Collect

"Personal information" includes information or an opinion, whether true or not, and whether recorded in a material form or not, about an identified living individual or an individual who is reasonably identifiable (such as name and contact details), or data about an individual who can be identified from that data or from that data and other information to which we have or are likely to have access.

"Sensitive information" is a more sensitive subset of personal information, which includes information about an individual's bank account or payment details, criminal history, health information, religious beliefs, racial or ethnic origin, or sexual orientation.

We will not process sensitive information about you unless we have received your express consent to the processing of this information.

Types of Information We Collect

We collect certain types of information about you if you visit our website, authorise us to provide you with insurance broking services, engage us as your broker, or otherwise provide us with your personal information.

The information we collect and hold generally includes:

If you have requested that we act in a broking capacity for insurance-related services, we may also collect and hold other information required to provide such services to you, including:

Anonymous or Pseudonymous Dealings

You may be able to deal with us without identifying yourself (anonymously or by using a pseudonym) in certain circumstances, such as when making a general enquiry relating to the services we offer. If you wish to do so, please contact us to find out if this is practicable in your circumstances. However, if you do not provide us with the information that we need, we or any of our third-party service providers may not be able to provide you with the appropriate services.

How We Collect Your Personal Information

We may collect personal information in a number of ways, including:

You authorise us to contact such third parties for the purposes of providing you with the services that you have requested. We will take reasonable steps to inform you when we collect personal information from third parties.

Our Purposes for Collecting, Holding and Using Your Personal Information

We collect and hold your personal information for the purposes of providing our services to you and related purposes, including:

We will only collect, use and share your personal information where we are satisfied that we have an appropriate legal basis to do this. We only use your personal information for the purposes set out above and where we are satisfied that:

Disclosure of Your Personal Information

We will disclose your personal information to:

Other than when required or permitted by law, as specified in this Privacy Policy, or where you have provided your express or implied consent, we will not disclose your personal information.

Nothing in this Privacy Policy prevents us from using and disclosing to others de-personalised, aggregated data.

Transfer of Personal Information Overseas

We may disclose your personal information to the following parties: third-party service providers, insurers and/or related companies as they may be processing your personal information either on our behalf or otherwise for one or more of the above-stated purposes.

Some of the third-party service providers to whom we disclose personal information may be located in countries outside Australia, such as Malaysia, the Philippines, Vietnam, the United Kingdom, the European Union and the United States of America.

Where we transfer your personal information overseas, we will either:

Transfer of your personal information will only be made for one or more of the purposes specified in this Privacy Policy.

When we take reasonable steps, we will ensure that transfers of personal information are in accordance with applicable law and carefully managed to protect your privacy rights. Transfers are limited to countries which are recognised as providing an adequate level of legal protection or where we can be satisfied that alternative arrangements are in place to protect your privacy rights. To this end:

You have a right to contact us for more information about the safeguards we have put in place (including a copy of relevant contractual commitments) to ensure the adequate protection of your personal information when this is transferred as mentioned above.

Your Obligations When You Provide Personal Information of Others

You must not provide us with personal information (including any sensitive information) of any other individual (including any of your employees or customers) unless you have the express or implied consent of that individual to do so.

Before providing us with information about another individual, you must:

If you have not done this, you must tell us before you provide any third-party information.

Your Obligations When We Provide You with Personal Information

If we give you, or provide you access to, the personal information of any individual, you must only use it:

You must also ensure that your agents, advisers, employees and contractors meet the above requirements.

Accuracy, Access and Correction of Your Personal Information

We take reasonable steps to ensure that your personal information is accurate, complete and up-to-date whenever we collect, use or disclose it. However, we also rely on you to advise us of any changes to your personal information. All personal information identified as being incorrect is updated in our database.

Please contact us using the contact details below as soon as possible if there are any changes to your personal information or if you believe the personal information we hold about you is not accurate, complete or up-to-date.

Access to Your Personal Information

You can make a request to access your personal information by contacting us using the contact details below. If you make an access request, we will provide you with access to the personal information we hold about you unless otherwise required or permitted by law. We will notify you of the basis for any denial of access to your personal information.

We may charge a reasonable fee where permitted by law (for example, if your request is manifestly unfounded or excessive). We may also charge the reasonable cost of third parties who assist us in complying with the access request.

Data Retention and Destruction

We keep personal information only for as long as is reasonably necessary for the purpose for which it was collected or to comply with any applicable legal or regulatory requirement.

Standard Retention Periods

As an insurance broker, we apply the following standard retention periods for different categories of personal information:

CATEGORY
RETENTION PERIOD
BASIS
Insurance policy records and client files 7 years from policy expiry or completion Corporations Act 2001 (Cth); business need for claims and disputes
Claims files and settlement documentation 6 years from settlement Limitation periods; potential disputes
Client complaint records 6 years from resolution or closure Business need and limitation periods
Financial records and transaction documentation 7 years after completion Corporations Act 2001 (Cth) ss. 286–289; financial audit requirements
Employee records 7 years after employment termination Fair Work Act 2009 (Cth) s. 535
AML/CTF records 7 years after record creation AML/CTF Act 2006 (Cth) Part 10
Customer contact and communication records 6 years from last contact Business need and limitation periods
Marketing and consent records As required or 2 years from last engagement Consent management and legitimate business purpose
CCTV and security recordings As long as necessary for investigation or claims purposes Business security and potential disputes

Where a legal dispute or claim is ongoing, we may retain relevant information for longer than the standard retention period to preserve evidence and facilitate legal proceedings.

Destruction and De-identification

If the purpose for which your personal information is collected is no longer served by the retention of such data, or when retention is no longer necessary for any other legal or business purpose, we will ensure that hard copies of your personal information are completely destroyed and electronic personal information is de-identified or securely deleted.

If you withdraw your consent for us to use your personal information for your insurance matters, this will affect our ability to provide you with the products and services that you have asked for or have with us. However, we will retain records as required by law.

Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) Compliance

Business Insurance Cover Services Pty Ltd is an Authorised Representative of Community Broker Network Pty Ltd (ABN 60 096 916 184, AFSL 233750). We are subject to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and associated rules and regulations administered by the Australian Transaction Reports and Analysis Centre (AUSTRAC).

Compliance Framework

As an Authorised Representative of CBN, we comply with CBN's anti-money laundering and counter-terrorism financing policies and procedures. CBN, as our AFSL holder and the primary Reporting Entity with AUSTRAC, establishes and maintains our AML/CTF compliance framework. We conduct our business in accordance with that framework and CBN's AML/CTF policies.

Customer Due Diligence Information

We collect certain personal information from you for customer due diligence (CDD) and identity verification purposes, as required by the AML/CTF Act and CBN's compliance procedures. This information includes:

Before entering into a business relationship with you, we verify your identity and assess the level of risk you present in accordance with CBN's due diligence procedures. This may include obtaining and verifying identification documents, conducting searches against regulatory watchlists and sanctions lists, collecting information about your funds, and ongoing transaction monitoring.

Record Retention

In accordance with Part 10 of the AML/CTF Act and the AML/CTF Rules 2007, we retain all AML/CTF records (including customer due diligence documentation, transaction records, and supporting correspondence) for a period of seven (7) years from the date the record is created or the date a transaction is completed, whichever is later. These records are held securely in accordance with CBN's data protection and record management standards.

Your Obligations

When providing us with personal information for AML/CTF purposes, you must:

If you fail to provide information required for AML/CTF compliance, we may be unable to proceed with providing you with insurance broking services.

Further Information

For comprehensive information about CBN's AML/CTF policies and procedures, including customer due diligence requirements, suspicious activity reporting, and your privacy rights in relation to AML/CTF information, please refer to CBN's Privacy Policy at cbnet.com.au/privacy.

Security of Your Personal Information

We take reasonable steps to protect any personal information that we hold from misuse, interference and loss, and from unauthorised access, alteration and disclosure.

Our security measures include:

However, data protection measures are never completely secure and, despite the measures we have put in place, we cannot guarantee the security of your personal information. You must take care to ensure you protect your personal information (for example, by protecting any usernames and passwords). You should notify us as soon as possible if you become aware of any security breaches.

We will, where required by applicable Privacy Law, notify you as soon as reasonably possible of any material security breach concerning your personal information.

Our website may contain links to other third-party websites. We do not endorse or otherwise accept responsibility for the content or privacy practices of those websites or any products or services offered on them. We recommend that you check the privacy policies of these third-party websites to find out how these third parties may collect and deal with your personal information.

Cookies

Like many website operators, we may use standard technology called cookies on our website. Cookies are small data files that are downloaded onto your computer when you visit a particular website. Cookies help provide additional functionality to the site or to help us analyse site usage more accurately.

In all cases in which cookies are used, the cookie will not collect personal information except with your consent. You can disable cookies by turning them off in your browser; however, our website may not function properly if you do so.

If you follow a link from our website to another website, please be aware that the owner of the other website will have their own privacy and cookie policies for their site. We recommend you read their policies, as we are not responsible or liable for what happens at their website.

You can adjust the settings in your web browser to determine whether sites can set cookies on your device. To find out more about cookies, including how to see what cookies have been set and how to manage and delete them, visit www.aboutcookies.org or www.allaboutcookies.org.

You may opt out of being tracked by Google Analytics across all websites by following the guidance outlined on their website.

Direct Marketing and How to Opt Out

When we collect your personal information, we may use your personal information to send you direct marketing communications about our insurance products or our related services. We limit direct marketing to a reasonable and proportionate level, and to send you communications which we believe may be of interest to you, based on the information we have about you.

Our processing of your personal data for direct marketing purposes is based on our legitimate interests, but where opt-in consent is required by law, we may seek your consent where applicable.

If you no longer wish to receive such information, or you do not want us to disclose your personal information to any other organisation (including CBN broker network members or any other related companies), you can opt out by:

Administration of Personal Information

You may refuse or withdraw your consent for the collection, use and/or disclosure of your personal information in our possession by giving us reasonable notice so long as there are no legal or contractual restrictions preventing you from doing so.

If you withdraw your consent for us to use your personal information for your insurance matters, this will affect our ability to provide you with the products and services that you asked for or have with us.

Updates to This Privacy Policy

We reserve the right to amend our Privacy Policy from time to time to ensure we properly manage and process your personal data and to reflect changes in privacy law or our practices. Any amended Privacy Policy will be posted on our website and will take effect from the date of publication.

How to Make a Complaint

If you wish to make a complaint about a breach of this Privacy Policy or any breach of the Australian Privacy Act 1988 (Cth), you can contact us using the contact details below. You will need to provide us with sufficient details regarding your complaint together with any supporting evidence and information.

We will refer your complaint to our Privacy Officer who will investigate the issue and determine the steps that we will undertake to resolve your complaint. We will contact you if we require any additional information from you and will notify you in writing of the outcome of the investigation.

We will try to resolve any complaint within 14 working days. If this is not possible, you will be contacted within that time to let you know how long it should take us to resolve your complaint.

If you are not satisfied with our determination, you can contact us to discuss your concerns or complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or on 1300 363 992.

How to Contact Us

If you wish to gain access to your personal information, want us to correct or update it, have a complaint about a breach of your privacy or any other query relating to this Privacy Policy, please contact:

Privacy Officer
Business Insurance Cover Services Pty Ltd

Address: 5/734-738 Gympie Road, Chermside QLD 4032, Australia
Phone: 1300 268 371
Email: aaronm@bics.net.au
Website: www.bics.net.au

For further information on privacy in Australia, please visit the Office of the Australian Information Commissioner at www.oaic.gov.au.

Network Reference

We are a participant in the Community Broker Network (CBN). You can access CBN's privacy policy at cbnet.com.au/privacy.

Effective Date: July 2026
Next Review Date: July 2027

Document Notes

This Privacy Policy has been tailored for Business Insurance Cover Services Pty Ltd and aligns with:

The retention periods specified reflect current legislative requirements (Corporations Act, Fair Work Act, AML/CTF Act) and industry-standard practice for general insurance brokers in Australia.