Privacy policy
Updated 8 October 2026
Who this policy covers
This policy explains how D’Omkara Accountants Pty Ltd, ABN 49 168 395 837, handles personal information received through this website, enquiries and client services. Our office is at Level 10, 30 Collins Street, Melbourne VIC 3000. You can contact us at team@domkara.com.au or on +61 3 9579 4450.
Our privacy and data protection commitments
We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and relevant guidance from the Office of the Australian Information Commissioner (OAIC). D’Omkara maintains comprehensive compliance and data protection measures to protect information against misuse, interference, loss and unauthorised access, modification or disclosure. Access is limited to people and service providers who need the information for their work. No method of storage or transmission can eliminate every security risk.
Website and email enquiries
Email links open your own email application. When activated, the booking assistant collects a name and email address to verify an email address and arrange a meeting. The assistant asks for consent to continue before transmitting chat text or booking fields. If you contact us, we receive your email address and any name, contact details or information you include. We use that information to respond to your enquiry and discuss the services you need. Please do not send tax file numbers, identity documents or bank details in your first email. We can explain how to provide documents when needed.
Information for client services
If you engage us, we may need business records, financial information and personal information relevant to the agreed work. We collect information from you, your authorised representatives and, where required or authorised, reliable independent sources. We explain the information needed for your engagement. If necessary information is not provided, we may be unable to start or continue the relevant service.
AUSTRAC and AML/CTF requirements
Some services are subject to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), the AML/CTF Rules and AUSTRAC requirements. Where those requirements apply, we collect and verify information to identify the client, relevant beneficial owners and people acting on the client’s behalf. Depending on the service and risk, this may include names, dates of birth, addresses, identity documents, ownership and control details, the purpose of the engagement, and information about the source of funds or wealth. We use the information for customer due diligence, ongoing monitoring, risk assessment and required reporting. We may disclose information to AUSTRAC or other authorities where required or authorised by law. Legal restrictions can limit what we may tell you about particular disclosures.
Offshore outsourcing and overseas processing
Your information may be processed by an overseas outsourcing provider to help deliver or support our services. Email, cloud and technical support providers may also process information overseas. D’Omkara remains responsible for its Australian privacy and compliance obligations; outsourcing does not transfer that responsibility to the overseas provider. We perform ongoing due diligence on third-party providers to check that D’Omkara data is handled to the required standards under Australian regulatory requirements. We take the reasonable steps required by APP 8 to ensure overseas recipients handle information consistently with the APPs, unless a lawful exception applies. Contact us if you would like to discuss the overseas processing arrangements relevant to your engagement.
Use, disclosure and record keeping
We use information to respond to enquiries, carry out agreed work, administer engagements and meet legal and professional obligations. Information may be shared with relevant staff, authorised service providers and your authorised representatives, or where required or authorised by law. Enquiry and client records are retained for as long as needed for those purposes and applicable obligations. AML/CTF customer due diligence records must generally be kept for at least seven years after the business relationship ends; other AML/CTF records have their own statutory retention periods. Where information is no longer needed and no retention requirement applies, we take reasonable steps to destroy or de-identify it.
Website hosting and analytics
The website is hosted on Microsoft Azure in Australia Southeast. Technical information, including an IP address, is processed to deliver pages and protect the service. We use Google Analytics 4 to measure page visits and interactions. The Google tag may use first-party cookies and sends page, browser and device information to Google. Google says it uses IP addresses at collection to derive location information, then discards them before data is logged. Google may process analytics information outside Australia under its own service arrangements; see How Google uses information from sites or apps that use its services and Google Analytics data safeguards. Do not put sensitive personal information in page URLs or content sent for measurement. The booking assistant uses a Secure, HttpOnly session cookie lasting up to 30 minutes when activated. Log Analytics and Application Insights are disabled. Images are served from this website rather than loaded from an external photo service.
Booking assistant — wording awaiting owner review
Online booking is awaiting activation and owner review of these disclosures. Booking requires an email code and an explicit confirmation. We send booking details to the selected staff member’s Microsoft 365 calendar with you as an attendee. Calendar and invitation records follow the firm’s Exchange retention policies; their retention period must be confirmed before activation.
Your name and email are used for verification and the calendar invitation. They are not saved in the booking Tables database or browser storage. Names, email addresses and codes are not supplied to the language model. Please do not enter tax file numbers, bank details, identity documents or confidential financial information in chat.
General chat text is processed by the approved Microsoft Azure model service. We do not persist chat transcripts or use provider conversation storage. Provider processing, abuse monitoring and retention may still apply; no promise of zero provider retention is made. The approved model processing region and provider conditions must be confirmed before activation. Cloudflare Turnstile processes technical information to check for abuse.
Booking security records include short-lived sessions, pseudonymous IP/email identifiers, holds, verification-code digests and usage limits. Sessions expire after 30 minutes; session records are removed within 24 hours after expiry. IP and daily abuse state is kept for up to 48 hours after its relevant window. Codes expire within five minutes and offers/holds within ten minutes. Minimal booking audit records are retained for 12 months, with scheduled deletion within 24 hours thereafter. Active future bookings and unresolved outcomes retain the state required to avoid duplicate bookings until reconciled. Contact team@domkara.com.au about access, corrections, retention or booking changes.
Access, correction and privacy concerns
Email team@domkara.com.au or call +61 3 9579 4450 to request access to or correction of personal information, ask a privacy question or make a complaint. Describe the issue without attaching sensitive documents. We may need to confirm your identity before providing information. We will consider your request or complaint and respond, subject to applicable legal restrictions. If a concern remains unresolved, you can contact the Office of the Australian Information Commissioner at oaic.gov.au. The policy may be updated as our services or arrangements change.