Privacy Policy
Last updated: 12 September 2026
1. About Trusted Firms Global and this policy
TFG Certification Pty Ltd (ABN: 16 695 393 429) (“Trusted Firms Global”, “we”, “us”, “our”) operates the Trusted Firms Global certification program at trustedfirms.global.
This policy explains how we collect, use, disclose, and protect personal information in connection with our certification activities, this website, and related communications. It applies across:
- – Australia – under the Privacy Act 1988 (Cth) and Australian Privacy Principles (APPs)
- – United Kingdom – under the Data Protection Act 2018 and UK GDPR
- – European Economic Area (EEA) – under the EU General Data Protection Regulation (GDPR)
Client feedback independently collected by Client Culture. Certification by Trusted Firms Global, independent of the firms it certifies. Client Culture Pty Ltd (ABN: 88 619 177 132), a member of the same corporate group, conducts service quality reviews on behalf of certified firms; Trusted Firms Global assesses the results against the published standards and awards credentials.
For how Client Culture handles personal data collected during quality reviews, please refer to the Client Culture Privacy Policy.
2. Data controller
TFG Certification Pty Ltd is the controller for personal information collected through this website (enquiries and technical data) and for what it publishes: the names and details of certified firms and advisers, the assessment results and response counts on verification pages, and consented client reviews.
For the client feedback behind a credential, the certified firm is the controller and Client Culture Pty Ltd processes it on the firm's behalf under the Client Culture Client Services Terms. Client contact details, client lists and unconsented responses stay with Client Culture and are not transferred to Trusted Firms Global.
Contact us at contact@trustedfirms.global or via our contact form.
3. What data we collect
Firm and applicant data
Firm name, the contact details of the firm's nominated contacts, and the assessment on which a credential is issued – results, response counts and the basis of the client list – provided to us by Client Culture. Client lists and invoicing records are supplied by the firm to Client Culture, which warrants their basis to us; they are not transferred to Trusted Firms Global.
Adviser credential data
Individual adviser names, associated firm, certification status and the assessment figures for the credential, issued at the firm's request and displayed on public verification pages with the adviser's knowledge.
Client reviews
Where a firm has engaged the reviews service, reviews written by its clients are published on this website only with the author's consent, obtained through the Client Culture consent workflow, exactly as written and at the level of attribution the author chose, which may include their name and organisation. We hold the consented review and its consent record. A reviewer may withdraw consent at any time through the firm, through Client Culture, or by contacting us at contact@trustedfirms.global; the review is removed from our pages on next load.
Website enquiries
Name, firm name, email, and other details you provide through the contact or application form on this website. Enquiries are emailed to a Client Culture mailbox that handles Trusted Firms Global correspondence.
Technical data
IP address, browser type, and usage data collected automatically when you visit this website. Our websites use Google Analytics to measure page views; your browser sends your IP address and page-view data to Google in that request. Where a certified firm displays a served credential mark or reviews widget on its own website, the visitor's browser requests it from trustedfirms.global and we receive that visitor's IP address in the request, as with any web request; we use it only to serve the mark and for security logging.
4. How and why we process personal data
Conducting certification assessments and audits
Legal basis (UK/EU): Contract performance / legitimate interests
Operating public verification pages
Legal basis (UK/EU): Legitimate interests (public accountability of certification)
Publishing consented client reviews
Legal basis (UK/EU): Consent
Serving credential marks and reviews widgets on certified firms’ websites
Legal basis (UK/EU): Legitimate interests
Communicating with firms about certification and renewal
Legal basis (UK/EU): Contract performance
Responding to website enquiries
Legal basis (UK/EU): Consent / pre-contractual steps
Legal and compliance obligations
Legal basis (UK/EU): Legal obligation
5. Disclosure to third parties
We only share personal data:
With Client Culture Pty Ltd, which conducts service quality reviews on behalf of certified firms. We receive from Client Culture the results, response counts and consented comments needed to assess, issue and display credentials; we do not receive client contact details or unconsented responses
With Vercel (hosting and infrastructure) and Resend (transactional email delivery) as authorised processors, and with Microsoft 365, the email service of Client Culture that receives website enquiries
With regulators, courts, or law enforcement where required by law
We do not sell personal information.
6. International transfers
This website is hosted by Vercel and served from Sydney, Australia. It holds no database of its own; the figures on verification and reviews pages are read from Client Culture's platform, which is hosted in Sydney. Vercel, a United States company, operates a global edge network, so a request may be routed through servers outside Australia. Where personal data is transferred from the UK or EEA, we rely on the European Commission Standard Contractual Clauses (2021) with the UK International Data Transfer Addendum, and on adequacy decisions or appropriate safeguards where available.
7. Data retention
Certification data is retained for the duration of the certification relationship and for a reasonable period thereafter for record-keeping and review purposes. Consented reviews are retained while the credential is active and the consent stands; a withdrawn review is removed on next load and the record of its withdrawal is kept. Service quality review data is retained in accordance with the Client Culture Privacy Policy.
8. Your privacy rights
EU / UK (GDPR)
Access, rectification, erasure, restriction of processing, data portability, right to object, right to withdraw consent, and the right to lodge a complaint with your data protection authority.
Australia (APPs)
Access to and correction of personal information held about you, and the right to make a complaint to the Office of the Australian Information Commissioner (OAIC).
To exercise any right, email contact@trustedfirms.global or get in touch via our contact form. We respond within 30 days.
9. Complaints
If you believe we have not handled your personal information appropriately, get in touch via our contact form. If we are unable to resolve your concern, you may contact:
– Australia: Office of the Australian Information Commissioner (OAIC) – oaic.gov.au
– United Kingdom: Information Commissioner's Office (ICO) – ico.org.uk
– EEA: Your local EU supervisory authority – ec.europa.eu