Chapman and Frazer Real Estate Pty Ltd, trading as Chapman and Frazer Commercial Real Estate (“we,” “us,” “our”), is committed to protecting the privacy of our clients and website visitors. This Privacy Policy outlines how we collect, use, disclose, and protect your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles, as well as relevant New South Wales State laws.
We may collect and hold the following types of personal information about you:
We collect your personal information through various methods, including:
We collect personal information to:
If we intend to use your personal information for any purpose other than those described in this policy, we will obtain your consent.
We may disclose your personal information to:
We may send you direct marketing communications regarding our or our clients’ products and services that may be of interest to you. These communications may be sent via mail, SMS, fax, or email, in compliance with the Spam Act 2003 (Cth).
You may opt out of receiving marketing communications at any time by contacting us or using the provided opt-out options.
We take reasonable steps to protect your personal information from misuse, loss, unauthorised access, modification, or disclosure. Personal information is stored in electronic and/or hard copy form and is securely destroyed or de-identified when no longer needed.
You have the right to access and correct the personal information we hold about you. To request access, updates, or corrections, please contact us using the details provided below. We will respond within a reasonable timeframe.
Our website may use cookies and tracking technologies to enhance your browsing experience and collect data on site usage. You can manage cookie preferences through your browser settings.
We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements. The most recent version will always be available on our website.
If you have any questions about this Privacy Policy or how we handle your personal information, please contact us:
Chapman and Frazer Commercial Real Estate
Level 1 / 27 Dane Drive, Gosford NSW, Australia
Phone: +61 2 4325 0208
Email: enquiries@chapmanfrazer.com.au
If you believe we have breached your privacy rights, please contact us. We will address your concerns promptly. If you are unsatisfied with our response, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC) or the New South Wales Information and Privacy Commission (IPC).
This Privacy Policy complies with:
Privacy Policy Version 2.0 23 June 2026
The purpose of this policy is to ensure that CHAPMAN & FRAZER REAL ESTATE PTY LTD T/AS CHAPMAN & FRAZER COMMERCIAL REAL ESTATE (referred to throughout this document as CFCRE) handles personal and sensitive information responsibly, transparently, and in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988. The policy outlines the processes for collecting, using, disclosing, storing and protecting personal information.
This policy applies to all personal and sensitive information collected by CFCRE, including information relating to:
CFCRE is committed to safeguarding the privacy of individuals and ensuring the confidentiality, security and integrity of personal and sensitive information. The organisation will comply with the Australian Privacy Principles and all relevant legislation while promoting trust and transparency in every interaction.
CFCRE complies with the Privacy Act 1988 (Cth) including the 13 Australian Privacy Principles (APPs) introduced under the Privacy Amendment (Enhancing Privacy Protection) Act 2012 (Cth). To provide a clear framework for our privacy practices, CFCRE, has developed and implemented this APP Privacy Policy.
CFCRE’s privacy processes are designed to ensure effective and compliant management of personal and sensitive information, in alignment with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). These processes promote responsible, transparent, and secure handling of information, helping build trust among stakeholders while meeting all regulatory obligations.
By establishing clear procedures for the collection, use, storage, and disclosure of information, CFCRE ensures its activities remain compliant with national and state-based privacy legislation. This includes maintaining strong data quality and security measures – such as password-protected computer systems, encrypted digital records, secure physical storage, and regular audits – to reduce the risk of unauthorised access, misuse, or loss of personal information.
The organisation ensures transparency by providing accessible privacy policies, offering detailed notifications at the point of data collection, and maintaining clear processes for individuals to request access to or correction of their personal information. Provisions for anonymity and informed consent further support and respect individual privacy. In addition, established procedures for managing complaints, including the option to escalate unresolved matters to external authorities, strengthen overall accountability.
Regular monitoring and review of privacy practices support continuous improvement, ensuring that processes remain effective and responsive to evolving legal requirements and organisational needs. Together, these comprehensive privacy measures protect individual rights and uphold the integrity of the organisation.
This policy is designed to maintain requirements with additional jurisdictional requirements including:
CFCRE manages personal information in an open and transparent manner. This commitment is reflected in the practices, procedures, and systems outlined in this policy, all of which support our compliance with the Australian Privacy Principles (APPs) and any binding registered APP code.
These measures also ensure that CFCRE personnel are equipped to respond appropriately to privacy-related inquiries and complaints as they arise.
The following sections of this policy explain how we handle and protect personal information.
CFCRE maintains a record of personal information for all individuals with whom we engage in the course of our activities. As part of delivering our services, we collect, hold, use, and disclose personal information from our clients, customers and other stakeholders for a range of real estate related purpose, including but not limited to:
The following types of personal information are generally collected:
CFCRE generally collects personal information directly from individuals we deal with. This may occur through the use of forms (such as commercial tenancy applications, enquiry forms, registration documents or service agreements), through web-based systems (including online enquiry forms, digital inspection registration tools, customer portals, and internal business platforms), or via interpersonal interaction, such as via phone calls or face to face meetings.
To verify your identity, we may use electronic identity verification services, including the Australian Government’s Document Verification Service (DVS).
Where you have consented, your name, date of birth and identity document details will be securely sent to the relevant Commonwealth or State authority that issued your document. This may include passport offices, driver licence authorities, the Department of Home Affairs, Births Deaths and Marriages, or other authorised holders. These authorities check whether the details you have provided match the records they hold.
We do not receive a copy of your government records. The authority returns a match result only, confirming whether your details match (yes or no).
This process may be carried out through accredited identity verification providers, including APLYiD (APLYiD Pty Ltd, ABN 36 632 866 794) and its sub-providers.
More information about the DVS is available at idmatch.gov.au.
In the course of delivering commercial real estate services, CFCRE may also receive both solicited and unsolicited personal information from third-party sources.
These may include:
CFCRE’s usual approach to holding personal information includes maintaining secure storage and security measures at all times. Upon collection, personal information is:
Access to each system is granted solely to authorised team members, with permissions limited to what is necessary for their specific role. CFCRE’s digital systems are securely hosted, across secure cloud storage, supported by strict access controls, physical security protections, encryption measures and system-level permissions. Security safeguards include virus and malware protection, routine data backups (cloud based) and continuous monitoring of access activity.
Paper based records are destroyed as soon as practicable through in office shredding and certified destruction services at CFCRE.
CFCRE retains personal information for as long as necessary to fulfil the purposes for which it was collected, to meet legal and regulatory requirements, and to support legitimate business functions related to commercial real estate activities. This includes information collected during sales, leasing, property management services, due diligence processes, financial transactions and compliance requirements.
Personal information may be retained for the following reasons:
Once information is no longer required, and there is no legal or legitimate business reason to retain the information, CFCRE securely destroys or de-identifies the information. This includes:
Destruction processes are performed in a manner that prevents:
CFCRE follows industry standard security and privacy practices to ensure information is safely managed throughout its lifecycle.
CFCRE does not rely solely on automated decision making systems to make decisions that could have a significant impact on individuals or businesses in connection with our services. All decisions related to leasing, sales, tenant selection, applications, negotiations, and property management activities involve human review and professional judgement.
CFCRE confirms all individuals have a right to request access to their personal information held. You also have the right to request the correction of any personal information which relates to you that is inaccurate, incomplete, irrelevant, misleading or out-of-date.
If you require any further information about the management of personal information or have any queries or complaints, you should contact:
A range of third parties, other than the individual concerned, may request access to personal information. These parties may include Government agencies (Commonwealth, State or local), contractors and service providers engaged at a property, legal representatives, strata agents.
Whenever such a request is made, CFCRE ensures that:
Should an individual consider that CFCRE has potentially breached an APP or a binding registered APP code, they are encouraged to consult the Privacy Complaints Procedure outlined below for guidance on the steps they may take.
Likely overseas disclosures:
In certain circumstances, CFCRE may disclose personal information to overseas recipients. Additional information regarding such disclosures is detailed in the following sections of this policy, eg assisting clients in a transaction, placing insurance, obtaining finance etc.
CFCRE makes its APP Privacy Policy available free of charge. The policy can be accessed at any time via the Privacy link on our website at www.chapmanfrazer.com.au.
In addition, the APP Privacy Policy is:
If, in the unlikely event, the APP Privacy Policy cannot be provided in the format requested, CFCRE will explain the reasons to the requesting individual and work with them to provide access through an alternative suitable method.
CFCRE reviews this APP Privacy Policy:
When this policy is updated, CFCRE, ensures changes are clearly and widely communicated. Updates are shared internally through staff communications, meetings, training and documentation and externally through publication on the CFCRE website.
CFCRE acknowledges the importance of allowing individuals to remain anonymous where practical. However, there are circumstances in which we are unable to interact with individuals who choose not to identify themselves. This is particularly the case when we are acting for a vendor or landlord in relation to the sale, rental, or lease of a property, or when we are dealing with actual or prospective tenants for any rental property under our management.
In addition, we are not able to allow people through any property inspections who do not wish to identify themselves. This requirement exists to protect the security and privacy of the property owner, as well as for other safety and operational reasons.
Where anonymity is feasible, CFCRE can provide general information, such as responding to broad telephone enquiries about a property available for sale or lease, without requiring the individual to identify themselves. However, individuals should be aware that certain modes of communication, including email or other written or electronic correspondence, may inherently disclose identifying information.
While CFCRE supports the use of anonymity and pseudonyms wherever practical, there are situations in which identification is required. Certain activities, particularly those involving property access, property transactions, tenancy matters, or the verification of an individual’s authority to act, cannot be completed without confirming a person’s identity. In these circumstances, CFCRE must request sufficient identification to meet legal, contractual, and safety obligations, and to ensure the proper delivery of our services.
CFCRE only collects personal information that is reasonably necessary for our business functions and activities.
We collect sensitive information only where the individual has provided explicit consent, unless we are legally required to collect such information, as outlined earlier in this policy.
All personal information is collected by lawful and fair means. Wherever it is reasonable and practicable to do so, CFCRE collects solicited information directly from the individual. Personal information is collected from other sources only where it would be unreasonable or impracticable to obtain it directly from the individual.
CFCRE may, from time to time, receive unsolicited personal information. When this occurs, we promptly access the information to determine whether it is the type of personal information we could have lawfully collected for the purposes of our business activities.
If the information could have been collected under APP 3 for a valid business purpose, we may retain, use and disclose it in accordance with this Privacy Policy.
If we determine that the information could not have been collected, whether due to legal restrictions or because it is not reasonably necessary for our functions, we will immediately destroy or de-identify the information, unless it would be unlawful to do so.
CFCRE takes reasonable steps to ensure individuals are made aware of important matters relating to the collection of their personal information at or before the time of collection, or as soon as practicable afterwards.
The Privacy Policy provided to individuals includes information about:
Where we know that, as part of our relationship with the individual, their personal information will be disclosed to another identifiable organisation, we will notify the individual at the time of first collection (or as soon as reasonably practicable) of:
CFCRE only uses or discloses personal information for the purpose for which it was collected (the primary purpose), unless:
CFCRE ensures that all uses and disclosures of personal information are appropriate, lawful and consistent with this Privacy Policy and the expectations of the individuals concerned.
Where personal information is disclosed to third parties, including contractors, service providers, government agencies, or related entities, we take reasonable steps to ensure those parties handle the information in accordance with the Australian Privacy Principles and maintain appropriate confidentiality and security standards.
Personal information is not used or disclosed for secondary purposes that an individual would not reasonably expect, unless consent has been obtained or the disclosure is otherwise permitted under the Privacy Act.
CFCRE will make a written record of any disclosure of personal information in accordance with an ‘enforcement related activity’, including the following details:
A written notice is not required for disclosures made for the primary purpose of collection, for a reasonably expected related purpose, or where the individual has provided consent.
CFCRE does not use or disclose the personal information it holds about an individual for the purpose of direct marking unless one of the following conditions applies:
All direct marketing communications from CFCRE clearly explains how to opt out, and we act on any opt-out requests promptly and free of charge.
On request, we will also tell an individual of the source of their personal information used for direct marketing unless it is unreasonable or impracticable to do so.
CFCRE do not disclose personal information overseas, unless specifically instructed to do so by you.
Where possible, we endeavour to use onshore Australian based cloud storage. However, we may use cloud storage services or IT servers located overseas to store personal information. Because electronic and networked storage can be accessed from various countries via the internet, it is not always possible to know the exact country in which an individual’s information may be held.
Where it is practicable, we will identify the countries in which personal information is likely to be stored or transferred.
CFCRE does not adopt, use or disclose a government related identifier of an individual unless one of the following permitted circumstances applies:
CFCRE takes reasonable steps to ensure that the personal information we collect is accurate, up-to-date and complete. We also take reasonable steps to ensure that any personal information we use or disclose is, having regard to the purpose of use or disclosure, accurate, up-to-date, complete and relevant.
These steps are particularly important:
We take reasonable steps to ensure personal information is factually correct, and where information reflects an opinion, we ensure it is based on appropriate facts, competing views are considered, and it is clearly identified as an opinion. Personal information is confirmed as up-to-date at the point in time to which it relates.
To support these requirements, we maintain the following quality measures:
CFCRE takes reasonable steps to protect the personal information we hold from misuse, interference, loss and unauthorised access, modification or disclosure.
We regularly review our security measures and use appropriate technical and organisational safeguards to maintain data security.
When personal information is no longer required for any lawful purpose, we take reasonable steps to destroy or ensure it is de-identified, unless we are legally required to retain it.
Access to our offices and work areas are restricted to authorised personnel only. Visitors must be approved by relevant staff and are accompanied at all times to protect the security of our work environment. Paper-based records are stored in secure locations accessible only to authorised individuals.
We provide regular training and updates to all personnel to ensure a strong understanding of privacy obligations and how to apply the APPS to our practices and systems. Privacy training is also included in our induction process for new personnel.
To maintain robust security standards, we conduct ongoing internal audits, at least annually and additionally as required, to assess the adequacy and effectiveness of our security and access controls.
Where CFCRE holds personal information about an individual, we provide that individual with access to their information upon request. In processing access requests, we:
These practices reflect our commitment to meeting the access requirements under APP 12, which requires organisations to give individuals access to personal information they hold, subject to limited grounds for refusal.
CFCRE takes reasonable steps to ensure that the personal information we hold is accurate, up-to-date, complete, relevant and not misleading. If we identify that information requires correction, or if an individual requests a correction, we will take appropriate steps to update the information.
If we refuse to correct personal information, we will provide the individual with a written explanation including the reasons for refusal and information about available complaint mechanisms. We will also, where requested, associate a statement with the information noting the individual’s correction request.
Where appropriate, we will take reasonable steps to notify other organisations to whom the information has previously been disclosed of any corrections. We do not charge fees for making a correction request or for correcting personal information.
If an individual believes that CFCRE has breached its obligations in the handling, use or disclosure of their personal information, they may make a complaint. We encourage individuals to first raise the matter with their CFCRE representative so we can attempt to resolve the issue promptly.
Our complaints process is as follows:
When the OAIC investigates a complaint, it will generally attempt to conciliate the matter before considering the use of other complaint-resolution powers.
Compare listings
ComparePlease enter your username or email address. You will receive a link to create a new password via email.