Legal

Privacy Policy

This policy explains how Yoda Capital collects, uses, discloses and protects personal information.

Effective 23 September 2026

Yoda Capital Pty Ltd (referred to as “Yoda Capital”, “we”, “us” or “our”) respects your privacy and handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply. This policy covers information collected through our website, forms, meetings, correspondence and advisory activities.

You can browse most of our website without identifying yourself. If you contact us, book a meeting, subscribe to updates or engage our services, we may need information that identifies you so we can respond and provide the relevant service.

Information we collect

Depending on how you interact with us, we may collect:

  • identity and contact details, including your name, email address, phone number, company, country and preferred contact method;
  • professional and business information, including your role, website, business size, revenue or transaction range, approximate EBITDA range and areas of interest;
  • transaction and enquiry information, including timing, objectives, buyer approaches, concerns, messages and information you choose to provide about a potential mandate;
  • meeting, correspondence, newsletter and relationship-management records;
  • website and attribution data, including your IP address, browser or device information, page URL and title, referring page, landing pages, campaign parameters and interactions with forms or calls to action; and
  • information received from advisers, referral partners, counterparties, publicly available sources or other people where relevant to our work.

Please do not send sensitive personal information or highly confidential transaction documents through a general website form unless we ask you to do so. If you voluntarily provide sensitive information, we will handle it only where permitted by law and, where required, with your consent.

How we collect information

We may collect personal information:

  • directly from you when you complete a form, subscribe, book a meeting, email us, speak with us or engage our services;
  • from a person or organisation that introduces or refers you to us;
  • from advisers, transaction participants and other third parties where lawful and relevant;
  • from public sources such as company websites, professional profiles and corporate records; and
  • automatically when you use our website through hosting, security, analytics and customer-relationship technologies.

If you provide personal information about another person, you should have authority to do so and, where appropriate, make them aware of this policy.

How we use information

We use personal information to:

  • respond to enquiries, arrange meetings and assess whether we can assist;
  • provide and administer advisory services and manage client, partner and professional relationships;
  • understand your interests and communicate information that may be relevant to you;
  • operate, secure, troubleshoot and improve our website, forms and communications;
  • measure website performance, marketing attribution and engagement;
  • manage conflicts, risks, records, billing and internal administration; and
  • meet legal, regulatory, insurance and professional obligations or establish, exercise or defend legal claims.

We may also use information for another purpose where you consent or where the law permits or requires it.

Who we disclose information to

We may disclose personal information where reasonably necessary to:

  • our personnel, contractors and representatives who need it to perform their work;
  • technology and business service providers, including HubSpot for forms and relationship management, Google services for tag management and analytics, Cloudflare for form security, and Vercel for website hosting;
  • professional advisers, insurers, auditors and other service providers;
  • transaction counterparties, potential buyers, investors, financiers or their advisers, but only as authorised or otherwise permitted in connection with an engagement;
  • regulators, courts, law-enforcement bodies or other parties where required or authorised by law; and
  • a purchaser or successor in connection with a proposed or completed business restructure or transfer, subject to appropriate confidentiality protections.

Yoda Capital will not contact your staff, customers, suppliers, competitors, potential buyers or external advisers about your enquiry without your approval, except where required by law. We do not sell personal information.

Overseas disclosure

Some technology providers we use operate global infrastructure or process information outside Australia, including in the United States and other countries in which those providers or their subcontractors operate. If an advisory matter involves overseas parties, we may also disclose information to authorised counterparties, advisers or service providers in the relevant countries.

Where Australian privacy law applies, we take reasonable steps to ensure overseas disclosures are handled consistently with applicable requirements. The countries involved may vary depending on the services used and the nature of an engagement.

Cookies and website data

Our website and service providers may use cookies and similar technologies to operate forms, protect the site, remember your theme preference, understand website use and attribute enquiries to campaigns. We also use session storage to remember the first page visited during a browsing session.

Website technologies may collect a HubSpot visitor identifier, IP address, browser and device information, referring page, pages viewed, campaign parameters and interaction events. Google Tag Manager helps us manage measurement tags; Cloudflare Turnstile helps detect automated or abusive form submissions; and our hosting provider may keep standard request and security logs.

You can control cookies through your browser settings. Blocking some cookies or scripts may affect forms, meeting booking, preferences or other website functions.

Security and retention

We use reasonable administrative, technical and organisational safeguards designed to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Information may be held in secure cloud systems operated by us or our service providers. No method of online transmission or storage is completely secure.

We retain personal information only for as long as reasonably necessary for the purposes described in this policy, to maintain appropriate business and transaction records, and to meet legal, accounting, insurance and dispute-resolution requirements. When information is no longer required, we take reasonable steps to delete it or de-identify it, subject to lawful retention requirements and backup cycles.

Access and correction

You may ask to access personal information we hold about you or request that inaccurate, out-of-date, incomplete, irrelevant or misleading information be corrected. Contact us using the details below and describe your request. We may need to verify your identity before acting on it.

We will respond within a reasonable period. In some circumstances, the law permits us to refuse access or correction. If that happens, we will explain the reason where we are legally able to do so and tell you about available complaint options.

Direct marketing

We may send you relevant insights, invitations or service information where you have subscribed, consented, or where otherwise permitted by law. You can opt out at any time by using the unsubscribe link in an email or contacting us. We may still send service or administrative communications that are not marketing.

Privacy complaints

If you have a privacy concern or complaint, email us with the subject line “Privacy complaint” and include enough detail for us to investigate. We will acknowledge the complaint, review the circumstances and aim to provide a response within 30 days. If we need more time, we will let you know.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner through oaic.gov.au.

Contact us

For privacy questions, access or correction requests, complaints, or a copy of this policy in another accessible form, contact:

Privacy Officer, Yoda Capital Pty Ltd
PO Box 3310
Norwood SA 5064
Australia
Email: enquiries@yoda.capital
Website: www.yoda.capital

Changes to this policy

We may update this policy when our practices, technology or legal obligations change. The current version will be published on this page with its effective date.