Legal

Privacy Policy

Effective date: 17 December 2025

1. Introduction

This Privacy Policy explains how Lever Impact Group collects, holds, uses, discloses, protects and manages personal information.

For the purposes of this Privacy Policy, Lever Impact Group, we, us and our means, individually and collectively as the context requires:

  1. Lever Impact Pty Ltd ABN 96 660 780 889;
  2. Lever Impact Capital Pty Ltd ABN 70 693 349 647, including in its capacity as a Corporate Authorised Representative of BMYG Capital Pty Ltd AFSL 505332 where applicable;
  3. each current or future wholly owned subsidiary of either of the above entities that uses the Lever Impact brand, operates under the Lever Impact Group, or adopts this Privacy Policy; and
  4. any related body corporate, controlled entity, business division, trading name, successor or permitted assign of the above, to the extent that entity collects or handles personal information in connection with Lever Impact Group's business.

Each Lever Impact Group entity is a separate legal entity. Unless this Privacy Policy or applicable law states otherwise, a reference to we, us or our is a reference to the specific Lever Impact Group entity that collects, holds, uses or discloses the relevant personal information.

This Privacy Policy is intended to comply with the Privacy Act 1988 (Cth), the Australian Privacy Principles, the Notifiable Data Breaches scheme, and other applicable Australian privacy, data protection, communications, corporations, financial services, professional standards and record-keeping laws.

Where a Lever Impact Group entity is not legally required to comply with all or part of the Privacy Act, that entity may nevertheless choose to handle personal information consistently with this Privacy Policy as a matter of governance and good business practice, without admitting that any statutory obligation applies beyond its legal requirements.

2. Corporate capacity and protection of directors, officers, shareholders and related persons

Personal information is collected, held, used and disclosed by the relevant Lever Impact Group entity in its corporate capacity.

To the maximum extent permitted by law:

  1. directors, officers, employees, contractors, advisers, shareholders, ultimate beneficial owners and representatives of any Lever Impact Group entity do not collect, hold, use or disclose personal information in their personal capacity merely because they perform duties for, provide services to, own shares in, advise, govern, approve decisions for, or receive reports from a Lever Impact Group entity;
  2. any privacy inquiry, access request, correction request, complaint, claim, liability, obligation or remedy arising out of or in connection with this Privacy Policy, the handling of personal information, or any applicable privacy law must be directed to the relevant Lever Impact Group entity, and not to any director, officer, employee, contractor, adviser, shareholder, ultimate beneficial owner or representative personally;
  3. no director, officer, employee, contractor, adviser, shareholder, ultimate beneficial owner or representative assumes personal responsibility for personal information handled by a Lever Impact Group entity, except to the extent that personal liability cannot lawfully be excluded; and
  4. this Privacy Policy does not create any fiduciary duty, trustee relationship, partnership, agency relationship, personal undertaking, guarantee, indemnity or duty of care by any director, officer, employee, contractor, adviser, shareholder, ultimate beneficial owner or representative in favour of any individual.

Nothing in this Privacy Policy excludes, restricts or modifies any right, remedy, liability or obligation that cannot lawfully be excluded, restricted or modified, including liability for a person's own fraud, wilful misconduct, knowing contravention of law, or any other matter for which applicable law imposes non-excludable personal liability.

3. Scope of this Privacy Policy

This Privacy Policy applies to personal information we collect or handle in connection with:

  1. corporate finance, ESG, sustainability, climate, value creation, capital advisory, financial services, dealing, investor relations, wholesale client, corporate advisory and consulting services;
  2. our websites, digital platforms, online forms, booking tools, email communications, newsletters, events, webinars, reports, surveys and social media interactions;
  3. client onboarding, identity verification, wholesale client verification, due diligence, know-your-client, anti-money laundering, counter-terrorism financing, sanctions, conflicts, independence and risk checks;
  4. dealings with clients, prospective clients, investors, lenders, financiers, counterparties, intermediaries, directors, officers, management teams, founders, shareholders, beneficial owners, employees, contractors, suppliers, referral partners, advisers and professional service providers;
  5. recruitment, employment, contractor engagement, internships and work experience;
  6. governance, corporate administration, shareholder and director administration, insurance, audit, compliance, dispute management and regulatory engagement; and
  7. any other activity connected with the operation, administration, protection, restructuring, sale, transfer, merger or financing of the Lever Impact Group or its business.

This Privacy Policy does not apply to personal information handled by a third party in its own capacity, including any external website, social media platform, payment provider, data room provider, booking provider, analytics provider, cloud provider, professional adviser, client, investor, licensee, counterparty or regulator. Those third parties may have their own privacy policies.

Where Lever Impact Capital Pty Ltd provides financial services as a Corporate Authorised Representative of BMYG Capital Pty Ltd, personal information may also be collected, held, used or disclosed by BMYG Capital Pty Ltd in its own capacity as Australian Financial Services Licensee. This Privacy Policy does not govern BMYG Capital Pty Ltd's independent handling of personal information.

4. Key definitions

Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.

Sensitive information includes information or an opinion about matters such as racial or ethnic origin, political opinions, membership of a political association, religious beliefs, philosophical beliefs, membership of a professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, biometric information and biometric templates.

Group Entity means any entity within the Lever Impact Group.

You means the individual whose personal information is collected or handled, including a client contact, investor contact, prospective client, website visitor, supplier, adviser, applicant, employee, contractor, director, officer, shareholder, beneficial owner, guarantor, referee, participant in a transaction, or other individual with whom we interact.

5. The kinds of personal information we collect

The kinds of personal information we may collect depend on the nature of our relationship with you and the services, transactions or interactions involved. This may include:

  1. name, title, salutation, signature, pronouns, employer, role, seniority, professional qualifications and business profile;
  2. business and personal contact details, including email address, telephone number, postal address and office address;
  3. date of birth, place of birth, nationality, citizenship, residency status, tax residency and other identity information;
  4. identification documents and verification information, such as passport, driver licence, Medicare card, visa, company extracts, trust deeds, beneficial ownership information and certification documents, where required or appropriate;
  5. financial, investment, banking, transaction, source of funds, source of wealth, asset, liability, income, solvency, tax, accounting, corporate structure and ownership information;
  6. information required to assess wholesale client, sophisticated investor, professional investor, institutional investor, accredited investor or similar status;
  7. information contained in due diligence materials, data rooms, board papers, financial models, information memoranda, management presentations, term sheets, cap tables, shareholder registers, investor registers, transaction documents and correspondence;
  8. ESG, sustainability, emissions, climate, workforce, governance, supply chain, risk, procurement, operational and reporting information that may identify individuals;
  9. information about directors, officers, shareholders, beneficial owners, controllers, key management personnel, employees, contractors, consultants, referees, advisers and representatives of organisations with which we deal;
  10. recruitment information, including resumes, employment history, education, qualifications, references, interview notes, right-to-work information, background checks and other application materials;
  11. sensitive information, but only where reasonably necessary and where we have consent or another lawful basis to collect it;
  12. records of communications with us, including emails, phone calls, online enquiries, meeting notes, video conference details, file notes and support requests;
  13. marketing preferences, event attendance, subscription records, survey responses and feedback;
  14. website, device and usage information, including IP address, device identifiers, browser type, operating system, pages viewed, referring pages, location data, cookie identifiers, analytics data and interaction data;
  15. payment, invoicing, billing and account administration information;
  16. complaint, dispute, investigation, insurance, incident, audit and risk management information; and
  17. any other personal information you provide to us, authorise us to collect, or that is reasonably necessary for our functions or activities.

6. Sensitive information

We will only collect sensitive information where:

  1. it is reasonably necessary for one or more of our functions or activities and you have consented;
  2. collection is required or authorised by law, a court, tribunal, regulator, professional body, financial services licensee, exchange, market operator or other competent authority;
  3. a permitted general situation or permitted health situation applies;
  4. it is necessary for a legal claim, dispute, investigation, insurance matter, safety matter, sanctions screening, background check, conflict check, fraud prevention or risk assessment; or
  5. another lawful exception applies.

Examples of circumstances in which we may collect sensitive information include criminal history checks for certain roles or transactions, sanctions and politically exposed person screening, workplace health and safety matters, accessibility requirements for meetings or events, diversity or inclusion reporting where consented to or de-identified, and due diligence materials that incidentally contain sensitive information.

We do not seek to collect sensitive information unless it is necessary or appropriate for a lawful purpose. You should not provide sensitive information to us unless we request it, it is relevant to our engagement, or you have confirmed with us that it is appropriate to provide it.

7. How we collect personal information

We may collect personal information directly from you when you:

  1. contact us, meet with us, email us, call us, submit a website form, book a meeting, attend an event or subscribe to communications;
  2. engage us, request a proposal, enter into an agreement, complete onboarding, provide due diligence materials or participate in a transaction;
  3. provide identity, verification, wholesale client, investor, financial, ESG, governance or corporate information;
  4. apply for a role, internship, contractor position or business opportunity;
  5. use our website, digital tools, data rooms, portals or online services;
  6. respond to a survey, questionnaire or information request; or
  7. otherwise provide personal information to us or authorise another person to do so.

We may also collect personal information from third parties, including:

  1. your employer, company, fund, trust, adviser, accountant, lawyer, broker, banker, financier, investor, referee, representative or intermediary;
  2. other participants in a transaction, investment, capital raising, due diligence process, advisory mandate, engagement or project;
  3. publicly available sources, including ASIC, ABR, ASX, company registries, professional registers, websites, LinkedIn, media, sanctions lists, court records and public databases;
  4. data vendors, identity verification providers, KYC providers, AML/CTF providers, sanctions screening providers, credit or risk information providers, analytics providers and research providers;
  5. BMYG Capital Pty Ltd, financial services licensees, compliance consultants, auditors, insurers, professional advisers, service providers and regulators;
  6. recruitment agencies, referees, background check providers and former employers; and
  7. our related bodies corporate, subsidiaries, contractors, employees and advisers.

Where you provide personal information about another individual to us, you must take reasonable steps to ensure that you have authority to do so and that the individual is aware of the matters in this Privacy Policy.

8. When we may not be able to deal with you anonymously

Where lawful and practicable, you may deal with us anonymously or using a pseudonym. However, in many circumstances this will not be practicable, including where we need to identify you to provide services, verify your authority, confirm wholesale client status, comply with financial services obligations, conduct due diligence, perform conflict checks, comply with law, manage risk, issue invoices, enter into contracts, communicate with you, or protect our legitimate business interests.

If you do not provide requested personal information, we may be unable to provide services, accept instructions, proceed with a transaction, verify your identity or status, respond to your request, assess your application, comply with our obligations, or continue dealing with you.

9. Purposes for which we collect, use and disclose personal information

We may collect, hold, use and disclose personal information for the following purposes:

  1. providing, managing, improving and administering our services;
  2. responding to enquiries, requests, proposals, tenders, instructions, complaints and feedback;
  3. managing client, investor, lender, counterparty, adviser, supplier, referral and stakeholder relationships;
  4. conducting corporate finance, ESG, sustainability, climate, financial modelling, valuation, transaction, deal advisory, capital advisory, investor engagement, dealing, wholesale client and strategic advisory activities;
  5. conducting due diligence, transaction readiness, data room review, information verification, market sounding, investor positioning and capital raising support;
  6. verifying identity, authority, beneficial ownership, corporate structure, source of funds, source of wealth, sanctions status, politically exposed person status, conflicts, independence, eligibility and wholesale client status;
  7. complying with laws, regulations, licence conditions, professional standards, codes, policies, regulatory notices, market rules, court orders, tribunal orders and government requests;
  8. supporting BMYG Capital Pty Ltd or any other relevant Australian Financial Services Licensee with supervision, compliance, audit, reporting, monitoring, complaints and regulatory obligations;
  9. managing financial, accounting, tax, billing, banking, payment, audit, insurance and record-keeping functions;
  10. recruiting, onboarding, managing and administering employees, contractors, interns, consultants and applicants;
  11. operating, securing, analysing and improving our websites, systems, data rooms, digital tools, communications and business processes;
  12. sending service messages, engagement updates, legal notices, risk warnings, event invitations, newsletters, thought leadership, marketing communications and other information about our services, subject to applicable consent and opt-out requirements;
  13. conducting research, analytics, benchmarking, business planning, product development, service improvement and internal reporting;
  14. protecting our rights, property, security, systems, confidential information, commercial interests and reputation;
  15. preventing, detecting, investigating and responding to fraud, misconduct, cyber incidents, data incidents, security threats, unlawful activity, conflicts and disputes;
  16. enforcing contracts, engagement terms, website terms, confidentiality obligations and legal rights;
  17. obtaining professional advice, legal advice, accounting advice, tax advice, audit advice, insurance advice and other business support;
  18. considering or implementing a merger, acquisition, sale, transfer, financing, restructuring, insolvency, reorganisation or other corporate transaction involving all or part of the Lever Impact Group or its business;
  19. de-identifying, aggregating or anonymising information and using or disclosing that de-identified, aggregated or anonymised information for any lawful purpose; and
  20. any other purpose disclosed at the time of collection, authorised by you, reasonably expected by you, or permitted or required by law.

10. Disclosure of personal information

We may disclose personal information to:

  1. other Lever Impact Group entities, including wholly owned subsidiaries and related bodies corporate;
  2. directors, officers, employees, contractors, consultants, secondees, interns and representatives of Lever Impact Group entities on a need-to-know basis;
  3. BMYG Capital Pty Ltd, its representatives, compliance consultants, auditors, advisers and service providers where relevant to financial services provided by Lever Impact Capital Pty Ltd;
  4. clients, prospective clients, investors, lenders, financiers, borrowers, issuers, counterparties, bidders, vendors, purchasers, shareholders, directors, officers, management teams, advisers, brokers, arrangers, underwriters and other transaction participants;
  5. data room providers, document management providers, cloud storage providers, email providers, CRM providers, booking platforms, analytics providers, website hosts, IT providers, cybersecurity providers and other technology vendors;
  6. identity verification providers, KYC providers, AML/CTF providers, sanctions screening providers, fraud prevention providers, background check providers and risk information providers;
  7. banks, payment providers, insurers, insurance brokers, auditors, accountants, tax advisers, lawyers, barristers, company secretaries and other professional advisers;
  8. regulators, government agencies, law enforcement bodies, courts, tribunals, external dispute resolution bodies, professional bodies, market operators and other competent authorities;
  9. prospective purchasers, investors, financiers, lenders, insurers or counterparties in connection with a proposed or actual corporate transaction involving Lever Impact Group;
  10. recruitment agencies, referees, background screening providers and former employers;
  11. marketing, communications, event, research and publishing service providers;
  12. third parties where you have consented or would reasonably expect us to disclose the information; and
  13. any other person or entity where disclosure is required or authorised by law or reasonably necessary to protect our rights, property, security, systems, commercial interests or legitimate business interests.

We may disclose de-identified, aggregated or anonymised information to any person for any lawful purpose, provided the information is not personal information under applicable law.

11. Intra-group sharing and shared services

Lever Impact Group may operate shared management, administration, technology, compliance, finance, marketing, document management, risk, governance and professional support functions.

Personal information collected by one Lever Impact Group entity may be accessed by, disclosed to, processed by or stored for another Lever Impact Group entity where reasonably necessary for:

  1. providing services;
  2. managing client, investor, supplier or stakeholder relationships;
  3. complying with legal, regulatory, financial services, professional, audit, insurance or governance obligations;
  4. operating shared systems and business processes;
  5. managing conflicts, risk, security, complaints, disputes and insurance;
  6. corporate reporting, group oversight and shareholder or board reporting; or
  7. any other purpose permitted by law.

Each Lever Impact Group entity remains responsible for personal information it handles to the extent required by law. The adoption of this Privacy Policy by a Group Entity does not make any other Group Entity, director, officer, shareholder or related person liable for that entity's acts or omissions except to the extent required by law.

12. Financial services, wholesale clients and AFSL-related disclosures

Lever Impact Capital Pty Ltd may provide certain financial services as a Corporate Authorised Representative of BMYG Capital Pty Ltd AFSL 505332. In that context, personal information may be collected, used or disclosed for financial services compliance, wholesale client verification, investor classification, dealing, transaction execution, supervision, monitoring, complaints handling, audit, licence compliance and regulatory reporting.

This may include disclosure to BMYG Capital Pty Ltd, its officers, representatives, advisers, auditors, consultants, insurers, external dispute resolution bodies, regulators and service providers.

Where BMYG Capital Pty Ltd or another Australian Financial Services Licensee collects or holds personal information in its own capacity, its own privacy policy and legal obligations may apply. Lever Impact Group is not responsible for the independent privacy practices of any third party licensee, adviser, platform, custodian, broker, fund manager, product issuer, investor, lender or other transaction participant.

13. Direct marketing

We may use personal information to send you information about our services, events, insights, reports, publications, updates, opportunities or other matters that may be relevant to you or your organisation.

We will only send marketing communications where permitted by applicable privacy, spam, telemarketing and direct marketing laws. Where required, we will obtain consent.

You may opt out of receiving marketing communications at any time by using the unsubscribe function in the relevant communication or by contacting us. We will action opt-out requests within a reasonable period and in accordance with applicable law.

Even if you opt out of marketing communications, we may still send you non-marketing communications, including service messages, legal notices, transaction updates, engagement communications, compliance requests, security alerts and administrative messages.

We do not sell personal information to third parties for their independent direct marketing purposes unless you have consented or the disclosure is otherwise permitted by law.

14. Cookies, analytics and digital technologies

We may use cookies, pixels, tags, scripts, log files, analytics tools and similar technologies on our websites and digital platforms.

These technologies may collect information such as IP address, device type, browser type, pages visited, time spent on pages, referring websites, interactions, approximate location, campaign performance and other usage information.

We use these technologies to:

  1. operate and secure our website;
  2. remember preferences;
  3. understand website traffic and usage;
  4. improve user experience and content;
  5. measure marketing and communication effectiveness;
  6. identify technical issues; and
  7. support business analytics.

You may be able to disable or manage cookies through your browser settings. If you disable cookies, some parts of our website may not function properly.

Third-party platforms, including social media platforms, analytics providers, booking providers and embedded content providers, may collect information about your interactions with our website or content. Their own privacy policies apply to their handling of information.

15. Artificial intelligence, analytics and automated decision-making

We may use software, analytics, artificial intelligence, machine learning tools, workflow automation, screening tools or decision-support tools to assist with business administration, research, document review, drafting, data analysis, due diligence, risk screening, fraud prevention, cybersecurity, marketing, service improvement, client relationship management and compliance.

Where we use these tools, we seek to do so in a way that is appropriate to the sensitivity of the information and the relevant risk.

Unless we notify you otherwise, we do not intend to use a computer program as the sole basis for a decision that could reasonably be expected to significantly affect your rights or interests.

Where we arrange for a computer program to use personal information to make, or substantially assist in making, a decision that could reasonably be expected to significantly affect an individual's rights or interests, and we are required by law to provide further information about that process, we will update this Privacy Policy or provide an appropriate notice.

16. Overseas disclosure

We may disclose personal information to recipients located outside Australia where reasonably necessary for our functions or activities, where you have consented, where required or authorised by law, or where otherwise permitted under applicable privacy laws.

Overseas recipients may include:

  1. cloud, email, CRM, analytics, cybersecurity, data room, document management, booking and IT service providers;
  2. professional advisers, auditors, consultants, data providers and compliance providers;
  3. clients, investors, lenders, financiers, funds, counterparties, transaction participants and advisers located overseas;
  4. related bodies corporate, contractors or service providers operating overseas; and
  5. regulators, courts, tribunals, government bodies or law enforcement agencies located overseas.

The countries in which overseas recipients may be located will vary depending on the services, systems, transactions and counterparties involved. They may include Australia, New Zealand, the United States, Canada, the United Kingdom, member states of the European Union or European Economic Area, Singapore, Hong Kong, India, the Philippines and other jurisdictions where our service providers, counterparties, investors, clients, advisers or transaction participants are located.

Where required by law, we will take reasonable steps before disclosing personal information overseas, which may include contractual, technical, organisational or other safeguards.

17. Security of personal information

We take reasonable steps to protect personal information we hold from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.

Depending on the nature of the information and the risk involved, these steps may include:

  1. access controls and role-based permissions;
  2. password controls and multi-factor authentication where appropriate;
  3. encryption, secure transfer protocols and secure storage where appropriate;
  4. confidentiality obligations for employees, contractors and advisers;
  5. secure document management, data room and cloud storage practices;
  6. audit logs, monitoring and incident response processes;
  7. staff training and internal policies;
  8. vendor due diligence and contractual protections;
  9. physical security measures;
  10. backup and recovery processes; and
  11. periodic review of privacy and security practices.

No method of transmission over the internet, electronic communication, cloud storage or digital processing is completely secure. To the maximum extent permitted by law, we do not guarantee that personal information will be secure from all unauthorised access, cyber incidents, malicious activity, system failure, human error or other events beyond our reasonable control.

You are responsible for maintaining the confidentiality of any passwords, access credentials or secure links provided to you.

18. Data breaches

If we become aware of, or suspect, a data breach involving personal information, we will take reasonable steps to assess, contain and remediate the incident.

Where we determine that an eligible data breach has occurred and notification is required under the Notifiable Data Breaches scheme or another applicable law, we will notify affected individuals and the Office of the Australian Information Commissioner, or any other relevant regulator, as required by law.

Where legally permitted, we may not notify an incident if remedial action prevents the likely risk of serious harm, if an exception applies, if another entity is responsible for notification, or if notification is not required by law.

19. Retention and destruction

We retain personal information for as long as reasonably necessary for the purposes for which it was collected, including for legal, regulatory, accounting, tax, audit, insurance, financial services, professional standards, dispute, record-keeping, governance and business continuity purposes.

Retention periods vary depending on the nature of the information, the relevant engagement, the applicable laws, limitation periods, regulatory requirements, professional obligations and business needs.

We may retain personal information after our relationship with you or your organisation ends, including where necessary to:

  1. comply with law;
  2. maintain business and financial records;
  3. evidence advice, services, transactions, communications or decisions;
  4. resolve disputes or complaints;
  5. respond to regulators, courts, tribunals or law enforcement bodies;
  6. manage insurance, audit or risk matters;
  7. enforce rights or defend claims; or
  8. maintain backups and archives.

Where we no longer require personal information for any lawful purpose, we will take reasonable steps to destroy it or de-identify it, subject to technical, legal, backup, archival and operational constraints.

20. De-identified and aggregated information

We may de-identify, anonymise or aggregate personal information so that it no longer identifies an individual or is not reasonably capable of identifying an individual.

We may use and disclose de-identified, anonymised or aggregated information for any lawful purpose, including research, benchmarking, ESG insights, market analysis, thought leadership, internal reporting, service improvement, product development, modelling, analytics and commercial purposes.

We will take reasonable steps to avoid re-identifying de-identified information unless permitted by law.

21. Access to personal information

You may request access to personal information we hold about you. We may require you to verify your identity and provide sufficient details to allow us to locate the relevant information.

We will respond to access requests within a reasonable period. Where required by law, we will provide access in the manner requested if reasonable and practicable.

We may refuse, limit or defer access where permitted by law, including where:

  1. giving access would pose a serious threat to life, health or safety;
  2. giving access would have an unreasonable impact on another person's privacy;
  3. the request is frivolous or vexatious;
  4. the information relates to existing or anticipated legal proceedings and would not be accessible through discovery;
  5. giving access would reveal evaluative information generated in a commercially sensitive decision-making process;
  6. giving access would prejudice enforcement, security, fraud prevention, negotiations, investigations or legal rights;
  7. the information is commercially sensitive, confidential or legally privileged;
  8. denying access is required or authorised by law; or
  9. another lawful exception applies.

We will not charge you for making an access request. We may charge a reasonable fee for giving access, where permitted by law.

22. Correction of personal information

We take reasonable steps to ensure that personal information we hold is accurate, up to date, complete, relevant and not misleading.

You may request correction of personal information we hold about you. If we are satisfied that the information is inaccurate, out of date, incomplete, irrelevant or misleading, we will take reasonable steps to correct it.

If we do not agree to correct the information, and we are required by law to do so, we will take reasonable steps to associate a statement with the information noting that you consider it to be inaccurate, out of date, incomplete, irrelevant or misleading.

You should promptly notify us if your personal information changes.

23. Government identifiers

We may collect, use or disclose government-related identifiers where required or authorised by law, where reasonably necessary for identity verification, tax, employment, financial services, AML/CTF, sanctions, corporate, regulatory or transaction purposes, or where otherwise permitted. We will not adopt a government-related identifier as our own identifier of an individual unless permitted by law.

24. Employee, contractor and applicant information

This Privacy Policy applies to personal information about job applicants, prospective contractors, referees, interns and other individuals who are not current or former employees, subject to applicable law.

For current and former employees of private sector Lever Impact Group entities, certain acts and practices directly related to employee records and the employment relationship may be exempt from the Australian Privacy Principles. However, we may still handle employee records in accordance with applicable employment, workplace, tax, superannuation, corporations, health and safety, record-keeping and confidentiality obligations.

Personal information about contractors, consultants, volunteers, interns, applicants and referees may not be covered by the employee records exemption and may be handled in accordance with this Privacy Policy and applicable law.

25. Children and minors

Our services are intended for business, corporate, professional, wholesale, institutional and adult users. We do not knowingly seek to collect personal information from children or minors.

If we become aware that we have collected personal information from a child or minor without appropriate authority or a lawful basis, we will take reasonable steps to delete or de-identify the information unless we are required or authorised to retain it.

26. Third-party websites and platforms

Our websites, emails and digital content may contain links to third-party websites, platforms, tools, widgets, social media pages, booking systems, data rooms or embedded content. We are not responsible for the privacy, security, content, accuracy, practices or policies of third parties. You should review the relevant third-party privacy policy before providing personal information to a third party.

27. Professional obligations, confidentiality and non-personal information

This Privacy Policy deals with personal information. It does not limit any separate confidentiality, professional, contractual, fiduciary, corporations, financial services, employment, intellectual property or equitable obligations that may apply to non-personal information, confidential information, commercially sensitive information, client information, transaction information or privileged material.

Where there is inconsistency between this Privacy Policy and a written engagement letter, confidentiality agreement, data processing agreement, financial services disclosure document, mandate, contract or other agreement, the specific written agreement will prevail to the extent of the inconsistency, unless applicable law requires otherwise.

28. Complaints and privacy inquiries

If you have a question, concern, access request, correction request or complaint about how we handle personal information, please contact:

Privacy Officer

Lever Impact Group

U1/85 Oakleigh Road

Carnegie VIC 3163, Australia

Email: service@leverimpact.com.au

Alternative email: accounts@leverimpact.com.au

Please include your name, contact details, the nature of your request or complaint, and any relevant supporting information. We may require proof of identity before responding.

We will aim to acknowledge privacy complaints within a reasonable period and will investigate and respond as required by law. We may need to consult with other Lever Impact Group entities, service providers, advisers, licensees or third parties to properly investigate and respond.

If you are not satisfied with our response, you may be able to complain to the Office of the Australian Information Commissioner or another relevant regulator.

29. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes in our business, corporate structure, services, systems, legal obligations, regulatory guidance, technology, data handling practices or risk management requirements.

The updated version will be published on our website or otherwise made available. The effective date will be shown at the beginning of the policy.

Your continued dealings with us after an updated Privacy Policy is published or made available will be taken as acceptance of the updated Privacy Policy, to the extent permitted by law.

30. Non-exclusion of mandatory rights

Nothing in this Privacy Policy excludes, restricts or modifies any right, remedy, guarantee, obligation, liability, regulatory power or statutory protection that cannot lawfully be excluded, restricted or modified.

To the maximum extent permitted by law, all implied warranties, conditions, guarantees, obligations and liabilities are excluded.

To the maximum extent permitted by law, Lever Impact Group, its Group Entities, directors, officers, employees, contractors, advisers, shareholders, ultimate beneficial owners and representatives are not liable for any indirect, consequential, special, incidental, punitive or exemplary loss, loss of profit, loss of revenue, loss of opportunity, loss of goodwill, loss of data, business interruption, reputational damage or similar loss arising out of or in connection with this Privacy Policy or the handling of personal information, except to the extent such exclusion is prohibited by law.

31. Governing law

This Privacy Policy is governed by the laws of Victoria, Australia and applicable Commonwealth laws of Australia.

Where privacy, data protection or communications laws of another jurisdiction apply to our handling of personal information, we will comply with those laws to the extent required. Nothing in this Privacy Policy is intended to submit any Lever Impact Group entity, director, officer, shareholder, employee, contractor, adviser or representative to the jurisdiction of any foreign law or regulator beyond the extent required by applicable law.

Effective date: 17 December 2025 · Lever Impact Group

Lever Impact Pty Ltd

Chartered Accountants and corporate advisory. Integrating corporate finance, sustainability and strategic advisory to support confident decision-making.

ABN: 96 660 780 889

Lever Impact Capital Pty Ltd

Corporate Authorised Representative (CAR No. 001319049 of BMYG Capital Pty Ltd (AFSL 505332). Financial services provided to wholesale clients only.

ABN: 70 693 349 647

Important Disclosure

Lever Impact Capital Pty Ltd provides general financial product advice only. It does not provide personal financial advice. Any advice does not take into account your objectives, financial situation or needs.

Wholesale Clients Only

Financial services under Lever Impact Capital are available to wholesale clients only, as defined in the Corporations Act 2001 (Cth).

The content provided on this website by Lever Impact Pty Ltd (ABN 96 660 780 889) is for general informational purposes only and does not constitute professional advice. While we strive to keep the information up-to-date and correct, we make no representations or warranties of any kind, express or implied, about the completeness, accuracy, reliability, suitability, or availability with respect to the website or the information, products, services, or related graphics contained on the website for any purpose. Any reliance you place on such information is therefore strictly at your own risk. Liability limited by a scheme approved under Professional Standards Legislation. Lever Impact Pty Ltd, its employees, agents, and representatives accept no liability whatsoever for any loss or damage suffered by any person as a result of the use or reliance on the information or services provided on this website.

© 2026 Lever Impact Pty Ltd. All rights reserved.