Privacy Policy

Effective date: 29 July 2026
Last updated: 29 July 2026

BE SmartAdmin Services Pty Ltd, trading as BESAS (“BESAS”, “we”, “our” or “us”), respects the privacy of individuals and is committed to protecting the personal information entrusted to us.

This Privacy Policy explains how we collect, hold, use, disclose and protect personal information. It also explains how individuals may access or correct their personal information or make a privacy complaint.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and other applicable privacy, confidentiality and information-security obligations.

1. About BESAS

BE SmartAdmin Services Pty Ltd provides offshore staffing and business support services to Australian businesses and professional practices.

Our services may include:

  • Paraplanning;

  • Financial planning administration;

  • Bookkeeping and accounting support;

  • Administrative and executive assistance;

  • Customer service support;

  • Marketing assistance;

  • Project coordination;

  • Recruitment and staffing support; and

  • Other business process and professional support services.

As part of providing these services, BESAS may handle personal information relating to:

  • Clients and prospective clients;

  • Employees and contractors of our clients;

  • Customers and prospective customers of our clients;

  • Financial advice clients;

  • Job applicants and referees;

  • BESAS employees and contractors;

  • Suppliers and service providers;

  • Website visitors; and

  • Other individuals who communicate or interact with us.

2. Our Role When Handling Client Information

In many circumstances, BESAS receives and processes personal information on behalf of a client as part of providing contracted services.

When BESAS handles information on behalf of a client:

  • The client generally determines why the information is collected and how it is used;

  • BESAS processes the information only for authorised service-delivery purposes and in accordance with the client’s lawful instructions;

  • BESAS personnel may access the information only where reasonably necessary to perform their assigned duties; and

  • Access is subject to applicable contractual, privacy, confidentiality and information-security requirements.

If an individual’s information has been provided to BESAS by one of our clients, a request concerning that information may need to be referred to the relevant client. BESAS will provide reasonable assistance to the client in responding to the request.

3. Personal Information We May Collect

The types of personal information we collect depend on the nature of an individual’s relationship with BESAS and the services being provided.

Personal information we may collect includes:

  • Name;

  • Business or employer name;

  • Position or job title;

  • Email address;

  • Telephone number;

  • Residential, postal or business address;

  • Date of birth;

  • Identification and identity-verification information;

  • Business and company information;

  • Billing, payment and transaction information;

  • Information submitted through our website or enquiry forms;

  • Records of telephone calls, emails, meetings and other communications;

  • Service requirements, instructions and project information;

  • Recruitment and staffing requirements;

  • Employment history;

  • Resumes, qualifications, licences and professional memberships;

  • Referee details and employment references;

  • Background-screening information, where lawfully obtained;

  • Information contained in documents or systems made available by our clients;

  • Complaints, feedback and enquiry records;

  • Internet Protocol address, browser type, device information and website usage data; and

  • Other information reasonably necessary for our functions, activities or service delivery.

4. Financial and Professional Services Information

Where BESAS provides paraplanning, financial planning administration, bookkeeping or related business support services, we may access or process information including:

  • Financial circumstances;

  • Income and expenditure;

  • Assets and liabilities;

  • Superannuation and pension information;

  • Investment information;

  • Insurance information;

  • Taxation information;

  • Estate-planning information;

  • Identification documents;

  • Client fact finds and needs analyses;

  • Financial advice documents;

  • Accounting and payroll records; and

  • Information recorded in client relationship management, financial planning, accounting or product-provider systems.

BESAS generally receives this information from, and processes it on behalf of, the relevant business client. BESAS does not use this information for its own unrelated purposes.

5. Sensitive Information

Some services may involve the handling of sensitive information. Sensitive information may include health information, professional or trade association membership, criminal record information or other information classified as sensitive under applicable privacy laws.

Sensitive information may be contained in:

  • Insurance-related documents;

  • Financial advice files;

  • Employment or recruitment records;

  • Background checks;

  • Medical information provided for insurance or employment purposes; or

  • Documents supplied by a client in connection with assigned services.

BESAS will collect sensitive information only where:

  • The individual has consented and the information is reasonably necessary for our functions or activities;

  • The information is provided to us by a client for authorised service-delivery purposes;

  • Collection is required or authorised by law; or

  • Another permitted exception applies.

We do not use sensitive information for direct marketing.

6. Tax File Numbers and Government Identifiers

BESAS may encounter Tax File Numbers, Medicare numbers, Centrelink reference numbers and other government-related identifiers when providing authorised services to clients.

BESAS will only collect, access, use or disclose government identifiers where reasonably necessary for authorised services and where permitted or required by law.

We will not use a government-issued identifier as our own identifier for an individual unless permitted by law.

7. How We Collect Personal Information

We may collect personal information:

  • Directly from the individual;

  • Through our website, contact forms or booking facilities;

  • Through telephone calls, emails, meetings and consultations;

  • When an individual requests information, a proposal or quotation;

  • When an individual subscribes to communications;

  • When a business engages our services;

  • When an individual applies for employment or contract work;

  • From referees, recruiters or background-screening providers;

  • From our clients where information is required to deliver contracted services;

  • From authorised representatives, advisers or professional service providers;

  • Through technology platforms, software and systems used in providing services;

  • From publicly available sources where lawful and appropriate; or

  • Where otherwise permitted or required by law.

Where reasonably practicable, we collect personal information directly from the individual concerned. However, direct collection may not be practicable where BESAS processes information supplied by a client.

8. Dealing With Us Anonymously or Using a Pseudonym

Where lawful and practicable, individuals may deal with BESAS anonymously or by using a pseudonym.

However, this may not be possible where:

  • BESAS is required or authorised by law to identify the individual;

  • Identification is required to enter into or administer a contract;

  • Identification is necessary to provide the requested service;

  • Identity verification is required for security or fraud-prevention purposes; or

  • BESAS is processing information under a client’s instructions.

9. Why We Collect, Hold and Use Personal Information

We may collect, hold and use personal information to:

  • Respond to enquiries;

  • Prepare proposals and quotations;

  • Establish and manage client relationships;

  • Provide contracted services;

  • Perform paraplanning, financial planning administration, bookkeeping and business support activities;

  • Communicate with clients, prospective clients and other relevant parties;

  • Recruit, assess, onboard and manage employees and contractors;

  • Match personnel with client requirements;

  • Undertake appropriate reference or background checks;

  • Administer payments, payroll, invoicing and accounting;

  • Manage our business operations;

  • Provide customer and technical support;

  • Maintain and improve our systems, website and services;

  • Monitor service quality and information security;

  • Prevent or investigate suspected fraud, misuse or unlawful activity;

  • Manage complaints and disputes;

  • Maintain appropriate business and compliance records;

  • Send service information or marketing communications where permitted;

  • Protect our legal rights and the rights of others; and

  • Comply with legal, regulatory, contractual and professional obligations.

We will not use personal information for an unrelated purpose unless the individual has consented or the use is otherwise permitted or required by law.

10. Consequences of Not Providing Information

Individuals are generally not required to provide personal information to BESAS.

However, if requested information is not provided, BESAS may be unable to:

  • Respond to an enquiry;

  • Verify identity;

  • Prepare an accurate proposal or quotation;

  • Provide some or all requested services;

  • Process an employment application;

  • Complete an authorised client task; or

  • Meet legal, contractual or regulatory requirements.

11. Disclosure of Personal Information

We may disclose personal information where reasonably necessary to:

  • BESAS directors, employees and authorised contractors;

  • Offshore personnel assigned to authorised services;

  • The client on whose behalf we process the information;

  • Technology and software providers;

  • Cloud hosting and data-storage providers;

  • Customer relationship management platforms;

  • Financial planning, accounting, payroll and workflow-system providers;

  • Website hosting, analytics and communications providers;

  • Recruitment and background-screening providers;

  • Banks and payment service providers;

  • Accountants, auditors, lawyers, insurers and other professional advisers;

  • Information technology and cybersecurity providers;

  • Government bodies, regulators, courts or law-enforcement agencies where required or authorised by law;

  • A purchaser or successor as part of a genuine business sale, restructure or transfer, subject to appropriate confidentiality protections; or

  • Other parties with the individual’s consent or where otherwise permitted by law.

We do not sell or rent personal information.

12. Overseas Access, Processing and Disclosure

BESAS operates a remote-first service model and uses authorised personnel and service providers located in Australia and the Philippines.

Personal information may be accessed, processed, held or disclosed in the Philippines where:

  • Authorised offshore personnel perform services for a BESAS client;

  • Offshore personnel provide administrative, paraplanning, bookkeeping, recruitment or other business support services;

  • Overseas access is reasonably necessary for service delivery; or

  • Approved technology or support services involve access from the Philippines.

Personal information may also be processed or stored in other countries where approved cloud, technology, software or communications providers operate. The specific locations may vary depending on the provider and service used.

Before disclosing personal information to an overseas recipient, BESAS will take reasonable steps, where required, to ensure that the recipient handles the information consistently with applicable Australian privacy requirements.

Depending on the circumstances, safeguards may include:

  • Written confidentiality obligations;

  • Contractual privacy and information-security requirements;

  • Data-processing or outsourcing agreements;

  • Role-based access permissions;

  • Multifactor authentication;

  • Secure client and cloud systems;

  • Restrictions on downloading, copying or sharing information;

  • Staff privacy and security training;

  • Monitoring and access reviews;

  • Security-incident notification requirements; and

  • Requirements to return, securely delete or de-identify information.

Where BESAS processes information on behalf of a client, overseas access will also be subject to the applicable client agreement, service instructions and agreed security requirements.


13. Security of Personal Information

BESAS takes reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

Depending on the information and system involved, our security measures may include:

  • Secure cloud-based systems;

  • Individual user accounts;

  • Strong password requirements;

  • Multifactor authentication;

  • Role-based and need-to-know access controls;

  • Device and application protection measures;

  • Encryption where appropriate;

  • Secure file-sharing arrangements;

  • Access logging and monitoring;

  • Antivirus and threat-protection measures;

  • System updates and security maintenance;

  • Staff and contractor confidentiality obligations;

  • Privacy and cybersecurity training;

  • Incident-management procedures;

  • Service-provider due diligence; and

  • Periodic reviews of systems and user access.

BESAS personnel are bound by confidentiality obligations and may only access client information where necessary to perform assigned services. Access is restricted according to business need and governed by internal privacy, confidentiality and information-security procedures.

BESAS personnel must not access, use, copy or disclose client information for personal or unauthorised purposes.

No electronic transmission or information-storage method is completely secure. Accordingly, BESAS cannot guarantee absolute security. However, we will continue to review and improve our controls having regard to the nature of the information, the risks involved and available security practices.

14. Data Breaches and Security Incidents

BESAS maintains procedures for identifying, reporting, containing, investigating and responding to suspected privacy or information-security incidents.

Where an incident involves information that BESAS processes on behalf of a client, BESAS will notify and cooperate with the relevant client in accordance with applicable contractual and legal requirements.

Where BESAS has reasonable grounds to suspect that an eligible data breach may have occurred, BESAS will assess the circumstances and comply with applicable obligations under the Notifiable Data Breaches scheme.

Where notification is required, BESAS will notify the Office of the Australian Information Commissioner and affected individuals in accordance with applicable law.

We may also take steps to:

  • Contain the incident;

  • Preserve relevant evidence;

  • Remove or reduce the risk of harm;

  • Secure affected accounts or systems;

  • Require password or access-credential changes;

  • Notify relevant clients, insurers, service providers or authorities; and

  • Review security measures to reduce the risk of recurrence.

15. Data Retention

BESAS retains personal information only for as long as reasonably necessary for:

  • The purpose for which it was collected;

  • Providing or completing services;

  • Maintaining business and compliance records;

  • Satisfying client instructions;

  • Meeting contractual obligations;

  • Responding to disputes or complaints; or

  • Complying with legal, regulatory, taxation, employment, financial services or other record-keeping requirements.

Retention periods may vary depending on the nature of the information and the services provided.

Where BESAS processes information on behalf of a client, retention and deletion may also be governed by the client agreement and the client’s lawful instructions.

When personal information is no longer required, and BESAS is not legally or contractually required to retain it, we will take reasonable steps to securely destroy or permanently de-identify it.

16. Direct Marketing

BESAS may use contact information to send information about:

  • Our services;

  • Business updates;

  • Newsletters;

  • Events;

  • Educational content; or

  • Other information that may be relevant to the recipient’s business.

We will only send direct marketing communications where permitted by law.

Recipients may opt out at any time by:

  • Using the unsubscribe facility included in the communication; or

  • Contacting BESAS using the details at the end of this policy.

We will take reasonable steps to action an opt-out request promptly. Opting out of marketing communications will not prevent BESAS from sending necessary service, transactional, security or contractual communications.

17. Cookies and Website Analytics

Our website may use cookies, analytics tools and similar technologies to support website functionality and understand how the website is used.

These technologies may collect:

  • Internet Protocol address;

  • Browser type;

  • Device type;

  • Operating system;

  • Pages viewed;

  • Time and date of access;

  • Time spent on pages;

  • Referring website or source; and

  • General interaction and navigation information.

We may use this information to:

  • Operate and secure the website;

  • Understand website traffic;

  • Improve website functionality and content;

  • Diagnose technical issues; and

  • Measure the effectiveness of communications or marketing activities.

Individuals may be able to disable or manage cookies through their browser settings. Disabling cookies may affect the availability or operation of some website functions.

18. Third-Party Platforms and Websites

Our website or communications may contain links to third-party websites, platforms or services.

BESAS is not responsible for the privacy, security or content practices of independent third parties. Individuals should review the relevant third party’s privacy policy before submitting personal information.

Where BESAS uses a third-party platform to provide services, the handling of information may also be governed by that provider’s applicable terms and privacy arrangements.

19. Access to Personal Information

Individuals may request access to personal information BESAS holds about them.

To protect privacy and security, we may require suitable proof of identity before providing access.

In some circumstances, we may refuse or limit access where permitted or required by law. If we refuse an access request, we will generally provide written reasons and information about available complaint mechanisms, unless it would be unreasonable or unlawful to do so.

BESAS does not ordinarily charge for making an access request. We may charge a reasonable fee for the administrative cost of providing access where permitted, but we will notify the individual before incurring that cost.

Where information is held by BESAS solely on behalf of a client, the request may be referred to the relevant client.

20. Correction of Personal Information

BESAS takes reasonable steps to ensure that personal information is accurate, complete, relevant and up to date, having regard to the purposes for which it is used.

Individuals may ask us to correct information they believe is inaccurate, incomplete, out of date, irrelevant or misleading.

If we correct information that has previously been disclosed to another party, we will take reasonable steps to notify that party where required and reasonably practicable.

If we decline to make a requested correction, we will generally provide written reasons and information about available complaint mechanisms.

An individual may also ask us to associate a statement with the information noting that a correction was requested.

21. Recruitment and Employment Information

Where an individual applies for employment or contract work with BESAS, we may collect and use information to:

  • Assess qualifications, experience and suitability;

  • Contact referees;

  • Conduct authorised background checks;

  • Communicate about current or future opportunities;

  • Meet employment, taxation, payroll and legal obligations; and

  • Establish and manage an employment or contractor relationship.

We may retain information relating to an unsuccessful applicant for consideration for future opportunities, unless the applicant requests otherwise or retention is not otherwise appropriate.

Information about current or former employees may also be handled in accordance with applicable employment laws and any relevant employee-records provisions.

22. Children’s Information

BESAS provides services to businesses and professional organisations and does not direct its website or services to children.

We do not knowingly collect personal information directly from individuals under 18 years of age through our general website enquiry processes.

However, information relating to an individual under 18 may be contained in documents processed on behalf of a client, including financial advice, insurance, payroll, employment or accounting records. Where this occurs, BESAS will handle the information only for authorised service-delivery purposes and in accordance with applicable instructions and legal requirements.

23. Privacy Complaints

An individual who believes BESAS has mishandled personal information or breached an applicable privacy obligation may submit a complaint to our Privacy Officer.

A complaint should include:

  • The complainant’s name and contact details;

  • A description of the privacy concern;

  • Relevant dates and communications;

  • Details of any affected information; and

  • The outcome sought.

BESAS will:

  • Acknowledge the complaint promptly;

  • Review and investigate the matter;

  • Request further information where reasonably necessary;

  • Seek to resolve the complaint fairly; and

  • Aim to provide a substantive response within 30 days.

If additional time is reasonably required, we will notify the complainant and explain the reason for the delay.

If the complainant is not satisfied with our response, the complainant may lodge a complaint with the Office of the Australian Information Commissioner.

24. Changes to This Privacy Policy

We may update this Privacy Policy to reflect changes to:

  • Applicable laws or regulatory guidance;

  • Our services;

  • Our systems and technology;

  • Our business structure;

  • Our overseas operations; or

  • Our information-handling practices.

The current version will be published on our website and will display its effective date.

Material changes will apply from the date the updated Privacy Policy is published or from another date specified in the updated policy.

25. Contact Us

Questions, access requests, correction requests and privacy complaints may be directed to:

Laurie Lopez
Privacy Officer
BE SmartAdmin Services Pty Ltd

Email: hello@besas.au
Telephone: 03 8408 6765
Location: Australia – remote-first team

When contacting us, please provide sufficient information to identify the matter and enable us to respond appropriately.