YORKE INVESTMENT HOLDING PTY LIMITED
TERMS PRIVACY POLICY
Effective Date: 22 August 2025
1. About this Policy
YORKE INVESTMENT HOLDING PTY LIMITED (“Yorke Investment Holding”, “we”, “us” or “our”) is an Australian holding and investment company. This Privacy Policy applies to our corporate, investment, financing, banking, due-diligence, counterparty, adviser, supplier, recruitment and other business interactions.
This Policy is intended to describe our information-handling practices in a clear and transparent manner. Privacy and data-protection laws vary by jurisdiction. References in this Policy to rights or obligations under Australian privacy law, the California Consumer Privacy Act (CCPA), the GDPR, UK GDPR or other laws apply only to the extent those laws apply to the relevant entity, processing activity and individual.
Where the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) apply, we handle personal information in accordance with those requirements. This includes requirements relating to transparency, collection, notice, use and disclosure, direct marketing, overseas disclosure, information quality, security, access and correction. Where APP 2 applies, individuals may deal with us anonymously or by pseudonym where lawful and practicable.
2. Information We Collect
Depending on the interaction, we may collect:
- name, contact details, professional role, employer and organisation;
- counterparty, investor, lender, bank, adviser, supplier, contractor or service-provider information;
- corporate, transaction, financing, investment, due-diligence, governance and contractual information;
- identity-verification, compliance, tax or regulatory information where lawfully required;
- invoices, payment and accounting information;
- communications, meeting notes, call records, recordings, transcripts or summaries where applicable;
- recruitment or employment-related information where relevant;
- website, device, analytics and security information; and
- other information reasonably necessary for corporate, investment or legal purposes.
3. How We Collect Information
Information may be collected directly from you; from banks, advisers, counterparties, companies in which we invest or consider investing, service providers, professional firms, regulators, public registers and other lawful public or commercial sources; and through correspondence, meetings, telephone, video, websites, due-diligence materials and transactions.
4. Communications and Corporate Records
Communications with us may be retained as part of our ordinary business or organisational records. Where lawful, telephone, video, voice and other communications may be monitored, recorded, transcribed, summarised or otherwise documented for administration, quality assurance, training, security, accuracy, compliance, recordkeeping, evidentiary, dispute-resolution and legal purposes. Records may be associated with the relevant account, matter, client, campaign, project, transaction, case, contact or other record. Where applicable law requires additional notice, authorisation or consent before recording or processing a communication, we will take the steps required in the circumstances.
5. How We Use Information
We may use information to evaluate, structure, execute, finance, administer or monitor investments and corporate transactions; conduct due diligence; manage banking, accounting, taxation, insurance, legal, governance and compliance obligations; manage counterparties, suppliers, contractors and personnel; protect assets and systems; maintain records; prevent fraud; and manage disputes, investigations or legal matters.
6. Due Diligence and Compliance
Transactions may require us to collect or review information for identity verification, beneficial ownership, sanctions screening, anti-fraud, tax, regulatory, legal, source-of-funds or other due-diligence purposes where authorised or required. We seek to limit collection to information reasonably necessary for the relevant purpose.
7. Website and Analytics
Any corporate website or investor-facing digital service may collect ordinary technical, device, cookie, analytics and security information for functionality, performance, security and administration. Where consent or preference controls are required for non-essential technologies, we will provide them.
8. Artificial Intelligence and Automation
We may use artificial intelligence, machine-learning, transcription, analytics, automation and other technology-assisted tools to support research, drafting, classification, summarisation, administration, fraud or security detection, workflow management, reporting, customer or stakeholder support and other legitimate activities. We take reasonable steps appropriate to the circumstances to manage confidentiality, privacy and information-security risks when using third-party technology providers. Where applicable law requires information about, consent to, or rights concerning automated decision-making or profiling, we will provide those notices or controls. We do not represent that automated systems are used to make legally or similarly significant decisions unless that is actually the case.
9. Disclosures and Professional Service Providers
We may disclose information where reasonably necessary to related or portfolio entities, banks, lenders, investors, counterparties, prospective counterparties, accountants, auditors, tax advisers, lawyers, insurers, brokers, corporate advisers, technology and cloud providers, administrators, consultants, regulators, courts, tribunals and authorities. Disclosures may also occur in connection with actual or proposed investments, financings, acquisitions, disposals, restructures or other corporate transactions, subject to applicable law and confidentiality obligations.
10. International and Cross-Border Processing
Our operations, service providers, clients, partners or infrastructure may be located in more than one country. Personal information may therefore be accessed, processed, stored or disclosed outside the jurisdiction in which it was collected. Where an applicable law imposes requirements on international or cross-border transfers, we take reasonable steps or use transfer mechanisms required in the circumstances. Overseas recipients may also be subject to foreign laws requiring disclosure to governmental or regulatory authorities.
11. Security
We use reasonable administrative, organisational, physical and technical measures designed to protect personal information against loss, misuse, interference, unauthorised access, disclosure, alteration or destruction. Measures may include access controls, authentication, device and cloud security, permissions, confidentiality obligations, secure backups and incident-response processes. No transmission or storage system can be guaranteed to be completely secure.
12. Retention and Legal Holds
We retain information for as long as reasonably necessary for the purposes described in this Policy, having regard to contractual, operational, accounting, taxation, audit, insurance, regulatory, statutory limitation, security, dispute-resolution and legal requirements. Information may be preserved for longer where a complaint, investigation, threatened claim, litigation, legal hold, subpoena, discovery obligation, regulatory inquiry or other preservation requirement exists. Residual copies may remain in secure backups for a period after deletion from active systems.
13. Legal, Safety and Terms Enforcement
We may preserve, use or disclose information where reasonably necessary to enforce our Terms, contracts or policies; protect our rights, property, systems, personnel, clients, users or other persons; detect or prevent fraud, misuse, abuse or security incidents; respond to an emergency or serious safety concern; establish, exercise or defend legal rights; manage insurance matters; or comply with applicable law, regulation, court order, subpoena, warrant or lawful governmental request. Relevant records may be provided to authorised personnel, advisers, accountants, auditors, insurers, investigators, attorneys, regulators, courts, tribunals or law-enforcement authorities where permitted or required by law.
14. Access, Correction and Other Rights
Depending on the law that applies, you may have rights to request access to, correction of, deletion of, restriction of, or information about personal information we hold or process about you; to object to or opt out of certain processing; to withdraw consent where processing depends on consent; or to receive information in a portable form. These rights are not absolute and may be subject to identity verification, legal exceptions, privilege, third-party rights, security requirements and record-retention obligations. We may retain information notwithstanding a deletion request where retention is permitted or required for legal, contractual, accounting, tax, audit, insurance, security, fraud-prevention, dispute-resolution or legal-claims purposes.
15. Australian Privacy Matters
Where the Privacy Act 1988 (Cth) and APPs apply, requests for access or correction and privacy complaints will be handled in accordance with applicable requirements. Individuals may also have a right to complain to the Office of the Australian Information Commissioner after first giving us a reasonable opportunity to address the matter.
16. California Privacy Rights
If and to the extent the CCPA applies to us, California residents may have rights to know categories and sources of personal information, access specified information, request correction or deletion, opt out of certain sales or sharing, limit certain uses of sensitive personal information and exercise applicable rights without unlawful discrimination. We do not state through this Policy that the CCPA applies to every entity or activity. If we engage in processing treated as a sale or sharing under applicable California law, we will provide the notices and opt-out mechanisms required by law.
17. EEA and UK Rights
If and to the extent the GDPR or UK GDPR applies, we process personal data on one or more lawful bases available under applicable law, which may include consent, performance of a contract, steps taken before entering a contract, compliance with a legal obligation, protection of vital interests, legitimate interests or another lawful basis. Applicable rights may include access, rectification, erasure, restriction, data portability, objection, withdrawal of consent and rights relating to certain automated decision-making. Individuals may also have the right to lodge a complaint with a competent data-protection authority.
18. Third-Party Services
Our websites, applications or communications may link to third-party websites, platforms or services. We are not responsible for the independent privacy, security or content practices of unrelated third parties. Their handling of information is governed by their own terms and privacy notices.
19. Changes
We may update this Policy to reflect changes in our operations, services, technology, service providers or legal obligations. The current version will be published on the relevant website or otherwise made available, together with its effective or updated date.
20. Contact
Privacy enquiries, requests or complaints may be submitted using the contact details published on our official website or supplied in our correspondence. Please provide enough information for us to identify the relevant records and verify your identity where reasonably necessary. Where applicable, you may also have the right to complain to the privacy or data-protection regulator in your jurisdiction.
Contact via email:
[email protected]
