Privacy Policy
Version 1.0 · September 2026
Accrue - CPD is a continuing professional development platform for Australian financial advisers and the licensees that oversee them, and for registered tax and BAS agents and the professional associations that support them. It is operated by Northern Beaches Advisory & Consulting Pty Ltd (ACN 637 335 678) trading as Accrue - CPD.
This Privacy Policy describes how we handle personal information you provide to us, or that we collect about you when you use Accrue. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. Our commitment
We are committed to protecting your privacy and to handling personal information in a way that is open, fair, and consistent with the Australian Privacy Principles. We collect only the personal information we need to operate Accrue and to help you and your licensee meet the regulatory CPD obligations that apply to financial advisers in Australia.
We do not collect or hold sensitive information about you (such as health, racial or ethnic origin, religious or philosophical beliefs, sexual orientation, or political opinions). Accrue is a CPD record-keeping product and has no operational need for any of those categories.
2. Who we are
In this policy, “Accrue”, “we”, “our” and “us” mean Northern Beaches Advisory & Consulting Pty Ltd, trading as Accrue - CPD.
Accrue is hosted in Australia. Production data is held on Australian-based cloud infrastructure in the AWS Asia Pacific (Sydney) region. Section 9 sets out the limited circumstances in which any of your personal information may be processed outside Australia.
3. What this notice covers
This notice applies to personal information we collect about you when you access or use Accrue, our websites, and any related services we provide. “Accrue” includes our web application, the marketing website, and any communications we send you in connection with the product.
4. What this notice does not cover
If you use Accrue because your licensee has subscribed to the product, your licensee determines how your CPD record is used for their own internal purposes (such as compliance oversight, audit, and reporting to ASIC). In that context your licensee is the controller of your CPD record for its own purposes, and we process the data on their behalf.
Your licensee will have its own privacy policy covering how it handles your information. If you have questions about your licensee's handling of your CPD record, please contact your licensee directly.
This policy does, however, cover everything we do with your personal information in the course of providing Accrue to you and your licensee – the platform we operate, the security we apply, the service providers we engage, and the rights you have in respect of your information.
5. Personal information we collect
The personal information we collect about you falls into the categories described in this section and elaborated in the categories table at the end of this Policy. We collect only what we need to operate Accrue.
| Category | What it covers | Where it comes from |
|---|---|---|
| Identity and contact data | Your name and work email address. | Directly from you, or from your licensee when they add you as a user. |
| Account data | Your login credentials (password stored as a one-way hash), your role (adviser, licensee admin, platform admin) and the licensee tenant you are bound to. | Directly from you, or from your licensee. |
| Adviser regulatory data | Your ASIC Financial Advisers Register (FAR) number and the validation result returned when we compare it against the public ASIC FAR. | Directly from you; validated against the public ASIC FAR at registration and periodically thereafter. |
| CPD activity data | The record of your continuing professional development activity: source, date, hours, classification across the regulated CPD areas (and, where applicable, the Tax (Financial) Advice category in addition), and evidence-of-learning notes. | Created automatically when you record activity in Accrue, or directly from you when you add or edit an activity manually. |
| Uploaded content | Certificates, articles, screenshots, and other documents you upload as evidence for a CPD activity. These may contain identifying information about you (such as your name on a certificate) and about third parties (such as the course provider). | Directly from you, when you upload. |
| Service usage data | Information about how you use Accrue: pages visited, actions taken, quizzes attempted, library entries viewed, login and logout timestamps. | Automatically, as you use the product. |
| Device data | Your IP address, browser type and operating system, device identifiers, and similar technical information. | Automatically, when you visit our websites or use the product. |
We do not collect government-issued identifiers (such as your tax file number, Medicare number, or driver's licence) other than your ASIC FAR number, which is required to operate a CPD record-keeping product for financial advisers. See section 10 for how we treat your FAR number.
6. How we collect personal information
We collect personal information about you in three ways.
-
Directly from you. When you register, when you record a CPD activity, when you upload a certificate or other supporting document, when you send us a support request, and when you respond to surveys or other communications.
-
From your licensee. When your licensee adds you to Accrue as a user, they provide your name, email, and FAR number. We may also receive from your licensee historical CPD records (such as past certificates) that they are loading into Accrue on your behalf.
-
Automatically. When you use Accrue, our systems automatically log technical and usage information about your session, such as the pages you visit, the actions you take, the IP address you connect from, and the browser and operating system you are using.
-
From the public ASIC Financial Advisers Register. We confirm the FAR number you provide by looking it up on the public ASIC FAR and comparing the registered name against the name you have provided. We do not retain additional FAR fields beyond the validation result and a timestamp of when the check was performed.
7. How we use your personal information
We use your personal information for the following purposes.
To operate Accrue
Including: authenticating your logins, recording your CPD activity, classifying activity across the regulated CPD areas (and, where applicable, the Tax (Financial) Advice category in addition), generating compliance reports for you and your licensee, running quizzes, sending service emails (such as password resets, security notifications, and product communications), and providing support.
To validate your adviser status
We use your FAR number to confirm your registration on the public ASIC FAR and to flag any change in your authorisation status (for example, if your FAR record indicates you are no longer authorised by a licensee). This is necessary so that Accrue's records remain accurate.
To share your CPD record with your licensee
Where you use Accrue because your licensee has subscribed to the product, your licensee admin and responsible managers have visibility of your CPD record for the purposes of compliance oversight, audit, and regulatory reporting. This is a core feature of Accrue and a normal part of how a licensee supervises its representatives.
To improve Accrue
We analyse usage data to understand how Accrue is being used, to fix problems, and to plan new features. Where we use service usage data for these purposes we use it in aggregate, not in a way that singles you out.
To process certificates you upload
When you upload a certificate, we run an automated optical character recognition (OCR) pass over the file to extract provider name, date, hours, and CPD area information. You can review, correct, or discard the extracted result before it is saved as a CPD activity.
For security, fraud prevention, and audit
We maintain access logs, login timestamps, and similar records so we can detect suspicious activity, investigate security incidents, and respond to lawful requests from regulators.
To comply with legal obligations
We may use your personal information to comply with applicable laws, including responding to regulatory requests from ASIC or the Office of the Australian Information Commissioner (OAIC), and to manage legal claims.
For direct marketing
We may, with your consent, send you communications about Accrue features, related products, and industry events. Marketing communications are sent only to people who hold a paid subscription with us directly, or who have actively used the Platform in the previous 24 months as a direct registered user. Advisers and other users whose access is provided through a licensee subscription do not receive direct marketing from us; communications they receive from us are limited to service-related messages (such as password resets, security notifications, and product-change notices). You can opt out of marketing at any time by following the unsubscribe link in any marketing email or by contacting our Privacy Officer. See section 17.
8. When we may disclose your personal information
We disclose personal information only where it is necessary to operate Accrue or where required by law. We may disclose your personal information to:
-
your licensee admin and responsible managers, for compliance oversight, audit, and regulatory reporting purposes, as described in sections 4 and 7;
-
service providers who help us operate Accrue, namely our cloud hosting provider (Amazon Web Services, Sydney region), our database provider (Neon, AWS Sydney), our edge network and DNS provider (Cloudflare), our transactional email provider (Resend, USA), our error-monitoring provider (Sentry, USA), our support ticketing provider (Zoho Desk, hosted in Zoho's Australian data centre), our subscription billing provider (Stripe Payments Australia Pty Ltd, with cardholder data processed under Stripe's standard arrangements which include US infrastructure), our AI-assisted classification and certificate-extraction provider (Anthropic, USA), and any provider engaged for optical character recognition (OCR) of uploaded certificates;
-
ASIC, OAIC, or other Australian regulatory bodies, where required or authorised by law;
-
law enforcement bodies and courts, where required or authorised by law;
-
a potential purchaser of Accrue in connection with a proposed sale, merger, or acquisition. Before any personal information is disclosed for this purpose, the potential purchaser will be required to execute a written confidentiality agreement on terms appropriate to the sensitivity of the information. We will limit the disclosure to anonymised or aggregated information wherever practicable, and disclose identified personal information only where strictly necessary for the purpose. Access to identified personal information for due diligence purposes will be limited in time to the period reasonably necessary for the assessment and will be revoked on conclusion of the assessment or twelve (12) months from first access, whichever is earlier. On completion of any sale, merger, or acquisition, the purchaser will be required to handle your information consistently with this policy or another policy that provides equivalent protections, and to be bound by the Australian Privacy Principles;
-
a new owner of Accrue, where ownership of the business is transferred. You will be notified before any such transfer of your information takes effect; and
-
any other person with your consent, or where disclosure is permitted or required by law.
Our employees, contractors, and service providers are required to handle your personal information confidentially and only for the purpose for which it was disclosed to them.
8.1 Platform admin access to scoped content
Where a licensee has uploaded content that is scoped to its own tenant (for example, internal training materials made available only to that licensee's advisers), our platform admin staff retain visibility of that content where reasonably necessary for debugging, support, security investigation, or removal. By using Accrue you acknowledge and accept this access policy.
Every such access is recorded in an audit log. The affected licensee may request a copy of the audit log entries relating to their scoped content at any time.
9. Data location and overseas transfers
Production data for Accrue (including your account record, your CPD activities, and uploaded certificates) is hosted on Australian-based cloud infrastructure in the AWS Asia Pacific (Sydney) region. Support requests you send to support@accrue-cpd.com.au, including any attachments, are held by our support ticketing provider, Zoho Desk, in Zoho's Australian data centre.
Some of our service providers are based outside Australia and may process limited information on our behalf. Where this happens, we take reasonable steps to ensure that the overseas recipient handles your personal information consistently with the Australian Privacy Principles. The categories of overseas processing we currently rely on are:
-
Transactional email. Our transactional email provider (Resend) processes email addresses and message contents in the United States. We use this service to send service emails, password resets, and similar notifications.
-
Error monitoring. We use Sentry (United States) for application error monitoring. Technical diagnostic data, which may include an IP address, browser metadata, and the URL path that triggered an error, is processed by Sentry on our behalf. We do not transmit personal content (such as your CPD records or uploaded certificates) through this channel. We will give reasonable notice before adding or substituting a new overseas sub-processor.
-
AI-assisted classification and certificate extraction. We use Anthropic (United States) for the AI-assisted classification of captured activities, for the generation of comprehension-check questions, and for the extraction of fields from uploaded CPD certificates. Where these features are invoked, the relevant activity content – including, for certificate extraction, the certificate file bytes (which may contain your name and other personal information) – is transmitted in real time to Anthropic's API for processing under Anthropic's standard API terms. Anthropic does not retain the content or use it to train their models under those terms. We do not transmit your name, email address, or licensee identifier to Anthropic as separate fields.
We do not store your CPD record or uploaded certificates outside Australia. Where AI-assisted classification, comprehension-question generation, or certificate extraction is invoked, the relevant activity content (including uploaded certificate file bytes, which may contain your name and other personal information, and pasted article text or URL content) is transmitted in real time to Anthropic in the United States for processing under Anthropic's standard API terms (which include no use of API data for model training and zero-retention defaults). The content is not stored by Anthropic. If our processing arrangements change in a way that affects where your personal information is processed, we will update this notice before the change takes effect.
10. Government identifiers
The only government-related identifier we collect about you is your ASIC Financial Advisers Register (FAR) number. We collect it because Accrue is a CPD record-keeping product for financial advisers, and the FAR number is the canonical identifier for an authorised representative in Australia.
We use your FAR number only for the following purposes:
-
to verify that you are a current registered financial adviser by comparing your number against the public ASIC FAR;
-
to attach your CPD record to the correct adviser identity within Accrue; and
-
to include in compliance reports generated for you or your licensee, so that the report ties back to a specific adviser.
We do not use your FAR number as an internal identifier in place of an Accrue-issued account number, and we do not disclose your FAR number except as described in section 8.
11. Sensitive information
We do not collect sensitive information about you. “Sensitive information” has the meaning given in the Privacy Act 1988 (Cth) and includes information about your race or ethnic origin, political opinions, religious or philosophical beliefs, sexual orientation, health, genetic data, biometric data, and criminal record.
Accrue is a CPD record-keeping product and has no operational need to hold any sensitive information about you. If you voluntarily upload a document that contains sensitive information (for example, a training certificate that happens to include health-related content), please consider whether it is appropriate to upload it. We will treat any sensitive information that does reach us as highly confidential.
12. Cookies and tracking
Accrue uses session cookies to keep you signed in while you use the product. These cookies are essential to the functioning of Accrue and cannot be disabled without making the product unusable.
We may also use limited analytics tooling to understand how the marketing website is used (for example, page views and referrers). This data is used in aggregate and does not identify you individually. We do not run advertising tracking, do not share data with advertising networks, and do not place behavioural advertising on Accrue.
13. How we secure your personal information
We take the security of your personal information seriously. Our measures include:
-
encryption of data in transit (HTTPS / TLS) for all connections to Accrue;
-
encryption of data at rest at our hosting and database providers;
-
password hashing using industry-standard one-way algorithms (we never store your password in a form we can read);
-
role-based access controls so that licensee admins see only their tenant's advisers, advisers see only their own record, and platform admin access is restricted to a small number of named individuals;
-
session timeouts and audit logging of administrative actions;
-
regular backups of production data, retained in the same region (AWS Sydney) as the production system; and
-
ongoing review of dependencies, security advisories, and platform configuration.
No system can be guaranteed to be secure against every possible threat. Where a security incident occurs that is likely to result in serious harm to you, we will notify you and the OAIC in accordance with the Notifiable Data Breaches scheme under the Privacy Act.
14. Data retention
We retain CPD activity records for at least seven years from the end of the CPD year in which your most recent CPD activity was completed, in accordance with the Corporations (Relevant Providers Continuing Professional Development Standard) Determination 2018. For tax and BAS agents measured under the Tax Practitioners Board's continuing professional education rules, the retention period is at least five years from the end of the relevant CPE period. For a further two years after that, records are retained pending a final review. At the end of that nine-year window, if you no longer have a continuing relationship with Accrue (no current paid subscription, no active licensee sponsorship, and no record-restoration request received in the previous twelve (12) months), your personal information will be de-identified or deleted. If you have a continuing relationship at the review point, retention continues and is reassessed annually. You may request deletion of your personal information at any time; we will action the request to the extent it is consistent with the seven-year regulatory obligation above. Other personal information not associated with a CPD activity record (for example, account-administration data) is retained for the duration of your account and for the period reasonably necessary thereafter to meet our legal, regulatory, and operational obligations.
Where deletion is given effect (either on request after the retention period has elapsed, or as part of our routine retention review), we will delete your personal information or de-identify it so that it can no longer be associated with you.
15. Your rights
You have certain rights in relation to your personal information. You can:
-
Access your personal information. Ask us to confirm what personal information we hold about you and to provide you with a copy.
-
Correct your personal information. Ask us to update or correct any personal information that is inaccurate, incomplete, or out of date.
-
Request deletion. Ask us to delete your personal information, subject to our legal obligation to retain CPD records for the period set out in section 14.
-
Withdraw consent. Withdraw any consent you have given for processing that relies on consent (for example, marketing communications). Withdrawing consent does not affect processing carried out before the withdrawal.
-
Complain. Make a complaint about our handling of your personal information. See section 20.
To exercise any of these rights, please contact our Privacy Officer using the details in section 21. We will respond to your request within 30 days. Before we provide access or make changes, we will confirm your identity.
In some circumstances we may not be able to provide you with access to your personal information, for example where doing so would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, or where providing access would be unlawful. If we refuse a request, we will explain our reasons in writing.
16. Dealing with us anonymously
Where it is lawful and practical, you may deal with us anonymously or under a pseudonym – for example, when you browse our marketing website. However, because Accrue is a CPD record-keeping product and your CPD record must be attached to an identified financial adviser to be useful, you cannot use the product itself anonymously.
17. Direct marketing
From time to time we may send you marketing communications about Accrue features, related products, and industry events. We comply with the Spam Act 2003 (Cth) in our marketing practices, which means:
-
we send marketing communications only with your consent. Consent is express where you have ticked an opt-in or otherwise affirmatively agreed; consent is inferred only where you hold a current paid subscription with us directly or have actively used the Platform in the previous 24 months as a direct registered user. We do not infer consent from a licensee-funded subscription, from a single login, or from passive registration;
-
every marketing communication identifies us as the sender; and
-
every marketing communication includes a functioning unsubscribe option.
You can opt out of marketing communications at any time by following the unsubscribe link or by contacting our Privacy Officer.
18. Terms of Use
Your access to and use of Accrue is also governed by our Terms of Use, which you accepted when you registered. The Terms of Use cover account responsibility, acceptable use, intellectual property, and other matters that are not primarily about privacy. Where the two documents address the same topic, this Privacy Policy applies in relation to the handling of your personal information.
19. Updates to this notice
We may update this Privacy Policy from time to time. Where we make a material change, we will notify you in advance – typically by email and through a notice in the product. Non-material changes (such as clarifications or corrections) may be posted without separate notice. The version number and date at the top of this document indicate the current version.
20. Complaints
If you believe we have handled your personal information in a way that is inconsistent with this policy or the Australian Privacy Principles, please contact our Privacy Officer using the details in section 21. We will acknowledge your complaint within 7 days and aim to resolve it within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC):
-
Office of the Australian Information Commissioner
-
GPO Box 5288, Sydney NSW 2001
-
enquiries@oaic.gov.au
-
1300 363 992
21. How to contact us
If you have any questions about this Privacy Policy, or you wish to exercise any of your rights under it, please contact our Privacy Officer:
-
Privacy Officer, Accrue - CPD
-
Email: privacy-team@accrue-cpd.com.au
-
Postal: PO Box 7, Collaroy Beach NSW 2097