Risk Advice Companion

Brought to you by Risk Hub

Terms of Use & Privacy

Last updated: 21 August 2026.

Risk Advice Companion is operated by Point1 Pty Ltd trading as Risk Hub (ABN 17 645 442 262). These terms are an agreement between Point1 Pty Ltd and the practice that subscribes to Risk Advice Companion, and they apply to every user the practice authorises. By ticking to accept these terms when your practice account is set up, or by creating an account or using Risk Advice Companion, you agree to them. The version of these terms you accepted at sign-up applies to you until a change takes effect under clause 27.

In these terms, “we”, “us” and “Risk Hub” mean Point1 Pty Ltd. “You”, “your” and “the practice” mean the practice that subscribes, and include every person the practice authorises to use the platform. “RAC” means Risk Advice Companion. “Client” means an individual whose information the practice holds in RAC.

Last updated: [date of publication]. Version 2.0.

1. About Risk Advice Companion

RAC is software for Australian financial advice practices. It supports the risk advice process, including client profiles and fact finds, document management, data extraction from uploaded documents, insurance needs analysis, strategy development and the preparation of advice documentation.

Additional tools and modules may be added over time. Some may be separately priced or require a separate agreement.

RAC is a workflow tool. It sits alongside your practice management, licensee and compliance systems. It does not replace them, and if RAC is unavailable your practice can continue to operate using its existing processes.

2. Practices, accounts and users

Access to RAC is set up at practice level by agreement with us. Your practice nominates its users and each user receives an individual login. Credentials must not be shared.

You are responsible for the activity of every user you authorise, including their compliance with these terms. You must remove access promptly for anyone who leaves the practice or no longer needs it.

Each user must ensure their use of RAC is consistent with their own licensing, compliance and professional obligations, and with the requirements of their licensee.

3. Account security

You must:

  • keep login details secure and confidential, and not share them between users;
  • use multi-factor authentication where it is required by your practice settings or by your licensee, and keep secure the email accounts that receive verification codes;
  • only mark as trusted those devices that you control; and
  • notify us without delay at info@riskhub.com.au if you become aware or suspect that any login credential has been compromised, that an account has been accessed without authority, or that any client information held in RAC has been accessed, disclosed or lost without authority.

We are not responsible for loss arising from a failure to secure an account, from the sharing or compromise of credentials, from a user’s act or omission, or from a compromise originating in your own systems, devices, networks or email environment. You must cooperate with us promptly in containing and investigating any such incident.

4. Fees, setup and onboarding support

Fees are agreed between us and your practice. Where you have a written agreement or order form with us, that document sets the fees and payment terms and prevails over anything published on this page.

We may suspend access where fees remain unpaid after we have given you notice and a reasonable opportunity to pay.

Setup and onboarding. Where your practice purchases setup and onboarding, what is included is set out in your order form. Depending on the level of support agreed, onboarding may include working alongside your practice, or a paraplanner your practice engages, on an agreed number of initial advice documents, so that your people learn the process.

Assistance of that kind is training and implementation support. We do not conduct product research, we do not select products, we do not determine the strategy or the recommendation, and we do not provide financial product advice. Your adviser determines, checks and adopts the advice and the advice document, and remains responsible for it and for its compliance with their licensing obligations.

This assistance is limited to the onboarding period and to the scope stated in your order form. Further assistance after that period is agreed separately as a further scoped engagement with its own document count and end date. We do not provide open-ended ongoing document production. Clause 24 (Limitation of liability) and clause 20 (Your indemnity to us) apply to it in the same way as they apply to your use of RAC.

5. How RAC should be used

RAC outputs are indicative and preparatory only. This includes needs analysis results, data extracted from uploaded documents, generated narrative, draft advice documents, comparisons and any figures carried between parts of the platform.

Every output must be reviewed, checked and where necessary corrected by a qualified adviser before it is relied on or given to a client. RAC supports adviser judgement; it does not replace it, and it does not replace your own compliance and file-review processes.

You must not use RAC to process information you are not lawfully entitled to hold, or in a way that breaches any law, your licensee’s requirements, or a third party’s rights.

6. Not financial advice

We provide software. Nothing produced by RAC is financial product advice, a recommendation, or an offer of any financial product, and nothing in RAC should be treated as a substitute for the professional judgement of a licensed adviser.

RAC is a tool used by licensed advisers. The adviser and their licensee remain solely responsible for the advice given to a client, for the suitability of any product recommended, for the accuracy and completeness of any advice document issued, and for compliance with the Corporations Act 2001 (Cth), the adviser’s AFSL obligations and any applicable code or standard.

7. Artificial intelligence and its limits

RAC uses artificial intelligence to read and extract information from uploaded documents, and to help draft narrative text from structured client data. Where AI processing is performed by the platform, it is performed on Australian infrastructure, and the AI services we use do not use your data to train their models.

What AI can and cannot do here

AI-produced output can be incomplete, mistaken or misleading, including where a source document is unclear, non-standard, poorly scanned or ambiguous. Extraction can pick up the wrong figure, miss a figure, or attribute a figure to the wrong person, product or period.

We do not warrant that any AI-produced output is accurate or complete. Every extracted value and every drafted passage is presented for adviser review, and must be checked against the source document before it is used, relied on, or included in any document given to a client.

The AI does not make decisions, give advice, or act on its own initiative.

8. Beta and preview features

Some parts of RAC are made available as beta or preview features and are identified as such. Beta features are provided as is and without warranty of any kind. They may be incomplete, may change, and may be withdrawn at any time. Any service commitment, availability expectation or support arrangement that applies to RAC generally does not apply to beta features.

You should not rely on a beta feature in producing client-facing material without checking its output in full.

9. Fair use

Some features carry real cost to us each time they are used, in particular AI document extraction and drafting. Normal advice workflow use is never restricted. We may throttle, queue or contact you about use that is clearly excessive or automated beyond the intended workflow, such as bulk or scripted processing. Where your agreement with us specifies usage allowances, those allowances prevail.

 

10. Privacy and how we handle data

We handle personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What is collected

Practice information: practice and licensee details, adviser and staff names, contact details, authorised representative numbers, qualifications, signature images and logos, provided during onboarding and account management.

Client information entered or uploaded by the practice: names, contact details, dates of birth, employment and financial details, family information, insurance and superannuation records, health information, meeting notes and transcripts, and supporting documents.

Health information is sensitive information under Australian privacy law. You must only enter or upload client information, including health information, where you have the client’s consent to do so.

RAC is not designed to hold, and you should not upload, identity documents, banking credentials, credit card details or tax file numbers. If you upload them anyway, you do so at your own risk and remain responsible for that information.

Where it is stored

RAC runs on Australian infrastructure: application hosting in Sydney and the database in Sydney. Data is encrypted in transit using TLS 1.2 or higher and at rest using AES-256, with additional field-level encryption applied to identity and health fields. AI processing performed by the platform is performed onshore in Australia.

Overseas disclosure

Client and practice data is not transferred overseas in the ordinary course of using RAC, with these exceptions: our email delivery provider and our SMS provider process message content – such as a recipient’s email address or mobile number and the content of a notification – through overseas infrastructure when messages are sent.

Where you generate a document, transcript or other file using your own third-party tool before uploading it to RAC, any processing performed by that tool happens outside RAC and is not covered by this section. See clause 12.

11. Support access

Our personnel may access a practice’s workspace where it is reasonably necessary to provide onboarding assistance, to respond to a support request, or to maintain the operation of the service. That access is limited to what is reasonably necessary, is treated as confidential, and is not used for any other purpose.

At the database layer, sensitive fields are encrypted such that they cannot be read without the application’s key.

12. Meeting transcripts and material you upload

RAC accepts meeting transcripts, recordings, notes and documents that you produce or obtain outside the platform.

You are responsible for:

  • obtaining any consent required to record a conversation, including consent from every participant where the law of the relevant State or Territory requires it;
  • your choice of transcription, recording or note-taking tool, and for the terms on which that provider handles the recording – including where that provider processes or stores data outside Australia; and
  • ensuring you are entitled to upload the material to RAC and to have us process it on your behalf.

Note: surveillance devices and listening devices legislation differs between States and Territories, and the rules on recording a private conversation are not the same everywhere. This is worth checking with your licensee.

13. Disclosure and third parties

We use service providers to operate RAC, including an Australian application hosting provider, an Australian database provider, onshore AI services, an email delivery provider and an SMS provider. They process data on our instructions for the purpose of providing the service.

We do not sell practice or client data. We do not share it with insurers or any other party for their own purposes.

14. Third-party integrations and data

RAC may connect to third-party services for research, quoting, policy data, premium data and client data.

Data returned by those services is produced by the third party. We pass it through in good faith and we do not verify it. We are not responsible for its accuracy, completeness, currency or availability, or for any inaccuracy, omission or delay on the part of the provider. You must verify third-party data before relying on it in advice.

You hold the third-party subscription. Where an integration depends on a third-party service, you are responsible for obtaining and maintaining any subscription or licence that provider requires, and for the fees payable to them. Those fees are not part of your Risk Hub fees, and we do not collect them. If your subscription with that provider lapses, the integration stops working.

We use reasonable endeavours to keep integrations working but do not guarantee their availability or performance. A third-party provider may change, interrupt or withdraw its service at any time, and an integration may be unavailable while that is resolved. The third party’s own terms may apply to you in addition to these terms.

15. Data retention, export and deletion

We retain data while it is needed to provide the service and to meet legal and record-keeping obligations. Your practice owns and manages its client records.

You may request a copy of your practice’s data at any time. If you stop using RAC, you may request a complete copy of your practice data, and we will provide it in a structured, commonly used format within 30 days of your request. We will not withhold your data as leverage in a commercial dispute.

After a copy has been provided and any retention obligation has passed, we will delete your data on request. Backups are cycled on their normal schedule and data may persist in backups for a period after deletion.

16. If we stop providing RAC

If we decide to discontinue RAC, we will give your practice at least 60 days’ notice, and during that period we will make your data available to you in accordance with clause 15.

We maintain automated backups and a restore process that we have tested, and we hold application code in private version-controlled repositories. Nothing in this clause is a guarantee that the service will continue to be available, and it is not an escrow arrangement.

17. Access and correction

A client who wants access to, or correction of, their personal information should contact their adviser or practice, which controls that information within RAC. We will assist a practice to respond to such a request.

 

18. Data breaches and notification

If we become aware of unauthorised access to, unauthorised disclosure of, or loss of client or practice data held in RAC, we will:

  • notify the affected practice without undue delay and in any event within 72 hours of becoming aware of it;
  • provide the information reasonably available to us about what happened, what data was involved, and what we are doing about it; and
  • take reasonable steps to contain the incident and to prevent recurrence.

Because your practice holds the relationship with the client and is the entity that collected the information, your practice is responsible for assessing whether the incident is an eligible data breach under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act 1988 (Cth), and for notifying affected individuals and the Office of the Australian Information Commissioner, unless we agree otherwise in writing in relation to a particular incident. We will cooperate with you in that assessment and provide the information reasonably available to us.

Where the incident was caused by our breach of these terms or our negligence, we will bear the reasonable and documented cost of the notification we required you to make. Where the incident arose from your systems, your users or your credentials, you bear that cost.

Neither of us will make a public statement attributing responsibility for an incident to the other without first consulting the other, except where required by law.

19. Practice and adviser responsibilities

You must:

  • obtain any client consents required to collect, hold and process client information in RAC, including health information, and keep a record of them;
  • maintain your own privacy policy and privacy disclosures, and comply with your own privacy obligations;
  • review, check and verify every RAC output before relying on it or providing it to a client;
  • ensure that all advice given to your clients is your own, is appropriate, and complies with your licensing and compliance obligations;
  • keep your account and your own systems secure, and comply with clause 3; and
  • use RAC lawfully and in accordance with these terms.

20. Your indemnity to us

You indemnify us, and our directors, officers, employees and contractors, against any claim, loss, damage, liability, and reasonable costs and expenses (including reasonable legal costs) arising out of or in connection with:

  • the financial product advice or other services you provide to your clients, and any advice document you issue;
  • your failure to review, check or verify a RAC output before relying on it or giving it to a client;
  • your failure to obtain a consent or authority required under clause 19;
  • any information, document, recording or transcript you upload to RAC, including the manner in which it was obtained;
  • unauthorised access to or use of RAC through your credentials, your users or your own systems; or
  • your breach of these terms or of any law.

This indemnity is reduced to the extent that the claim or loss was caused by our own breach of these terms or our negligence. We will notify you promptly of any claim to which this indemnity may apply, and will not settle such a claim without your consent, which must not be unreasonably withheld.

21. Intellectual property

We own RAC, the underlying software and all content we supply, including any improvement or modification. Your practice retains ownership of your client data and your own materials, and you grant us only the rights necessary to operate and support the service for you.

We may use aggregated and de-identified information about how the platform is used to improve and operate the service. Aggregated and de-identified information does not identify any client, adviser or practice, and we will not seek to re-identify it.

22. Availability and support

We aim for high availability but we do not guarantee uninterrupted access. Access may be interrupted for maintenance, updates, provider outages or technical issues. Unless a separate written service level agreement applies, no service level, uptime commitment or credit applies to your use of RAC.

Support is available at info@riskhub.com.au.

23. Suspension and termination

We may suspend or terminate access where fees remain unpaid after notice, where these terms are breached and the breach is not remedied within a reasonable period after notice, or where use of the platform is unlawful or exposes us or another practice to risk. Where the risk is immediate, we may suspend first and notify promptly afterwards.

You may stop using RAC in accordance with your agreement with us. Clauses 15, 18, 20, 21, 24, 25, 26 and 28 survive termination.

 

24. Limitation of liability

(a) Australian Consumer Law. Nothing in these terms excludes, restricts or modifies any right or remedy you have under the Australian Consumer Law that cannot lawfully be excluded, restricted or modified. Where our liability under a non-excludable guarantee can be limited, it is limited, at our option, to resupplying the service or paying the cost of having it resupplied.

(b) Loss we are not liable for. Subject to paragraph (a), we are not liable for indirect or consequential loss, or for loss of profit, loss of revenue, loss of opportunity, loss of goodwill, loss of anticipated savings, business interruption, or the loss or corruption of data, however arising and whether or not it was foreseeable.

(c) Matters outside our responsibility. Subject to paragraph (a), we are not liable for loss arising from: the advice you give; your failure to review, check or verify an output; data produced by a third-party service; the unavailability, change or withdrawal of a third-party service; a beta feature; material you uploaded; a compromise of your credentials, users, devices, networks or systems; your use of RAC otherwise than in accordance with these terms; or any event beyond our reasonable control.

(d) Cap. Subject to paragraph (a), our total aggregate liability to you for all claims arising in connection with RAC and these terms – whether in contract, tort (including negligence), under statute or otherwise – is limited to the greater of the fees paid by your practice to us in the 12 months immediately before the first event giving rise to the liability, and A$5,000. This is an aggregate cap across all claims, not a cap for each claim.

(e) Time limit. Subject to paragraph (a), you must bring any claim within 12 months of the date on which you first became aware, or ought reasonably to have become aware, of the circumstances giving rise to it. After that period, the claim is barred.

(f) Your responsibility is unaffected. Nothing in these terms transfers to us any responsibility for the advice you give, and you remain responsible for verifying data and for the advice provided to your clients.

25. Dispute resolution

If a dispute arises, the party raising it must notify the other in writing setting out the issue. Both parties must then, within 14 days, have a senior representative meet – in person, by telephone or by video – and try in good faith to resolve it. If it is not resolved within 30 days of the notice, either party may commence proceedings. Nothing in this clause prevents either party from seeking urgent interlocutory relief.

26. Entire agreement and general

These terms, together with any written agreement or order form between us, are the entire agreement between us about RAC and replace any earlier representation, statement or understanding, whether written or spoken. Neither party has relied on any statement not set out in these documents. Nothing in this clause excludes liability for fraud or for misleading or deceptive conduct under the Australian Consumer Law.

If any part of these terms is unenforceable, it is severed and the rest continues to apply. A failure to enforce a right is not a waiver of it. You may not assign these terms without our written consent, which will not be unreasonably withheld. We may assign these terms to a purchaser of the business on notice to you.

27. Changes to these terms

We may update these terms. The current version is always published on this page. We will take reasonable steps to give you advance notice of any material change, and a material change takes effect no earlier than 30 days after we notify you.

28. Governing law

These terms are governed by the laws of New South Wales, Australia, and the parties submit to the non-exclusive jurisdiction of the courts of that State.

29. Contact

Point1 Pty Ltd trading as Risk Hub · ABN 17 645 442 262 · Kirrawee NSW 2232 · info@riskhub.com.au · riskhub.com.au

Scroll to Top

(If applicable) Head to the Courses area to grab your CPD certificate …