Skip to content

Privacy Policy

EasyAML Pty Ltd (“EasyAML“, “we” and “us“) is the provider of an end-to-end Customer Due Diligence (CDD) compliance solution. We act on behalf of our customers (“Clients”) to verify the identities of their customers (“Customers”) as required by AML/CTF (Anti-Money Laundering and Counter-Terrorism Financing) laws and any other relevant regulatory requirements (“Applicable Laws“).

This privacy policy (“Policy“) sets out how we collect, use, disclose and protect the Personal Information of: 

A. Customers (see Section A); and 

B. Clients, website visitors, and others (see Section B), 

(together, “you” and “your”).

In this Policy: 

EasyAML is an Australian Privacy Principle (APP) entity, as defined by the Privacy Act 1988 (Cth) (Privacy Act), and as such is committed to handling personal information in accordance with applicable privacy laws.

We may update this Policy from time to time, and any changes will be published directly to our website and will be effective from the date of publication.

Our Company Wide Commitment to Your Privacy

End-to-end AML/CTF compliance management is EasyAML’s business, handling all your Personal Information securely and in accordance with the APPs is essential to that business.

Every EasyAML employee undertakes mandatory training in the identification and handling of personal information as part of their onboarding process. Protection of personal information is discussed regularly in team and company-wide meetings, and considered when making any business decision.

Our Clients are contractually required to comply with the requirements of the Privacy Act, to comply with the security requirements of any Service Providers, and to protect all the Personal Information they receive.

Retrieval Process

EasyAML generally collects Personal Information under four scenarios:

  1. From our Clients (current and potential) and their staff, we receive information necessary to set up and manage their contracts and provide services to them.
  1. From Clients we receive contact details for a Customer to facilitate the required AML/CTF checks.
  1. From Customers we receive their Personal Information during the ‘verification of identification’ (VOI) process.
  1. From Clients and Customers we receive Customers’ Personal Information contained in documents uploaded for the ‘know your customer’ (KYC) processes.

If a Client has asked us to do your CDD check, they do so because it is a legal requirement that has to be completed prior to performing a service for you. They cannot perform that service without receiving and sharing your Personal Information with providers of VOI and KYC services. If you have any concerns or questions, you should contact the Client for further explanation of the requirements and the processes.

Section A: Customer

If you're dealing with us as a Customer, we might request and handle your Personal Information in two circumstances:

  1. For your current provider: We have received a request from, and are acting for a specific financial institution, law firm, accounting firm, real estate agent, or any other service you've hired, which are legally required to perform identity checks to complete the service  ("Current Provider").
  2. For future providers: In limited circumstances allowed by Applicable Laws, and only if you or your authorised person approves, we can also hold your personal information for future use by a service provider ("Future Provider").

When we're handling your personal information for a Current Provider, we are doing it on their behalf in accordance with their legal requirement. In these cases, this policy doesn't apply. Any questions or requests about your personal information in this circumstance you must  contact that Current Provider, and they'll instruct us if necessary.

When we're handling your personal information for potential Future Providers, we are doing it on your behalf and this policy does apply.

Note: By virtue of you visiting our website, parts of Section B (below) may also apply to you.

2. Information we collect and disclose

When we are managing your personal information during the Retrieval Process we request and collect it from you directly and your Current Providers, and then may share it, when necessary, with:

  1. Your Current Provider;
  2. Our Service Providers; and 
  3. Future Providers (subject to regulatory requirements and your authorisation) 

This includes the following types of personal information (the “Retrieved Information”):

CategoryInformation we Collect
Customer Contact  InformationFirst and last nameEmailPhone numberAddress
Biometric InformationFaceprints (and facial mapping and scans of digitised images)
Sensory InformationPhotos, videos or recordings of you and your environment
Unique IdentifiersUnique Device IDIP AddressIdentification number (such as Passport or Drivers Licence number)
Demographic InformationAge / date of birth contained on your identification documentsNationality indicated on your identification documentsSex indicated on your identification documents
Geographic InformationGeographic location

3. How long we retain information

We aim to keep your information for only as long as it is legally required for your Current Provider, or for as long as you request it for Future Providers.

Factors that may influence how long we retain your data include fulfilling our legal or regulatory obligations, responding to a question or complaint, or being unable to delete the data for technical reasons.

4. How we use and share your Personal Information

EasyAML collects, uses and holds your Personal Information so that we can conduct CDD checks on behalf of our Client who requested it. We may also use it for specific purposes that you have consented to. In general, we use your information to minimise risks and protect against fraud, misuse or loss of data, and to improve our services. We may also use it to comply with laws, obligations or provide assistance to regulatory, government and law enforcement authorities.

EasyAML shares sufficient of your Personal Information with the requesting Client to enable them to meet their legal obligations. We may share limited Personal Information to identify you or your CDD so that we may respond to a Client’s enquiry about your CDD. 

If compelled by law, we may disclose your information in response to a subpoena, court order, or a request for cooperation from a law enforcement or government agency. We may also disclose information when we believe it is appropriate to investigate illegal activity, suspected fraud, or to protect the rights, property, or safety of our company, users, and employees. In the event of a reorganisation, merger, or sale of EasyAML, we may transfer any and all Personal Information we collect to the relevant third party.

We do not disclose, use or adopt government identifiers except where the use and disclosure of the identifier is necessary to perform the CDD requested by the Client.

Agency Checks

In order to complete a CDD we may perform checks with government and other source checking agencies.

Source checking agencies verify a person's identity and background against specific databases, this may include (but is not limited to):

How long we will keep your information (Data Retention)

We aim to keep your information for only as long as we need it. Factors that may influence for how long we may keep your data include:

When we no longer have a good reason to hold onto your personal info, we'll either delete it or make it anonymous so it can't identify you. If we can't delete or anonymise it straight away (like if it's stuck in backup files), we'll keep it safe and separate it from any new processing until we can.

Security and storage

EasyAML implements a comprehensive array of physical, technical, organisational, and administrative security measures to protect the Personal Information we hold from unauthorised access, use, and disclosure.

The servers used for storing Customer data, which may include Personal Information, are operated by Amazon Web Services and are located in Sydney, Australia. These data centres are certified to SOC 1, SOC 2, and ISO 270001 standards, ensuring robust security protocols. They feature continuous, round-the-clock security, automatic fire detection and suppression systems, redundant power supply systems, and strict controls for physical access.

Data held on our servers is inaccessible to anyone who has not entered into a contract with EasyAML that includes confidentiality obligations. Data is encrypted both in transit (when being sent to and from our servers) and at rest (when stored). Specifically, 256-bit SSL/TLS encryption is employed to protect data in transit, while 256-bit AES encryption safeguards data at rest.

Furthermore, we maintain stringent policies and management oversight of security, and we conduct mandatory staff security awareness training. While we strive to protect the security of the Personal Information we hold, it is important to be aware that no method of transmitting data over the internet or storing data is completely secure.

Limited circumstances we may send personal information to overseas recipients

Generally EasyAML keeps all Personal Information on third-party encrypted and secure servers within Australia. 

There are two circumstances where Personal Information may be disclosed to or viewed by an overseas recipient:

Unsolicited personal information and de-identification

4. Accessing, correcting, erasing and your other rights

You are entitled to know and confirm the accuracy of all your Personal Information recorded by EasyAML, and all such requests will be addressed free of charge. However, Personal Information from a CDD is held on behalf of the Client who requested the CDD, and any requests in relation to this information must be directed to the Client.

Correction of Personal Information may not be possible once a CDD is completed as this information has been used to verify your identity in accordance with Applicable Laws and needs to be retained to support the CDD. During relevant parts of the CDD you will be presented with the opportunity to correct any data our system has not properly recorded.

If we cannot correct Personal Information as requested, EasyAML will respond in written form as to the reasons for denial of the correction along with the appropriate avenue for complaint. In this case should an individual request a statement be associated with that information, such a statement may be recorded and associated with the applicable data.

If you have any questions, concerns or would like to make a complaint about any of our data handling practices, please contact us.

5. Contact information

If you have any questions, concerns or would like to make a complaint about any of our data handling practices, please contact us by:

We aim to respond to your dispute within 30 days. We take all complaints seriously and are committed to a quick and fair resolution. Individuals making complaints or enquiries will be afforded the right to anonymity where it is practicable to do so, however we may require certain information to confirm your identity.

We also encourage you to seek further information about your rights from (and, where you think it necessary, complain directly to) the Australian  privacy authority the Office of the Australian Information Commissioner (OAIC): http://www.oaic.gov.au/privacy/privacy-complaints

Section B: Clients, website visitors and others

This section sets out how we process your Personal Information.

1. Personal Information we collect

When you visit our website EasyAML gathers information that doesn't directly identify you. This can include things like your job, language, postcode, area code, unique device ID, location, IP address, and the time zone. We might collect information about what Clients do on our website and with our products and services. We combine all this to help us give more useful information to our Clients and their Customers, and to see what parts of our products and services are most popular.

To offer location-based services on EasyAML products, EasyAML and our partners might collect, use, and share exact location data.

We may use non-personalized information to monitor activity that deviates from the norm using Security Information and Event Management (SIEM) tools and take appropriate action as part of our security and cyber crimes prevention processes.

1.1 Information Collected Directly

We might collect some Personal Information directly from you, and share it with our Service Providers or anyone else you authorise us to. This includes things like:

CategoryInformation we Collect
Contact  InformationFirst and last nameEmailPhone numberAddressUnique Identifiers
Professional related informationJob title
Other identifying information that you voluntarily choose to provideIdentification documentsOther identifying information in emails, letters or documents you provide to us
Audio, electronic, visual, thermal, olfactory, or similar informationFeedback and enquiries that you send to usContent from messages, emails, phone calls or phone call transcripts from communications that you provide to us. 
OtherSurvey Information

1.2  Information Collected Automatically

Also, when you visit our website or use our services, we might automatically collect some Personal Information. We might then share this with our service providers or anyone else you authorise us to. This includes:

CategoryInformation we Collect
Device / IP InformationIP addressDevice IDDomain ServerHardware and software attributes such as Type of device / operating system / browser . time zone
Web analyticsWeb page interactionsReferring webpageNon-identificable request IDsStatistics associated with the interaction between device or browser and our website 
Geolocation informationIP-address-based location informationGPS

1.3 Cookies and Other Technologies

EasyAML’s website, online services, interactive applications, email messages, and advertisements may use “cookies” and other technologies such as pixel tags and web beacons. 

These technologies help us better understand user behaviour, tell us which parts of our website people have visited, and facilitate and measure the effectiveness of advertisements and web searches. 

We treat information collected by cookies and other technologies as non-personal information. However, to the extent that Internet Protocol (IP) residential histories or similar identifiers are considered personal information by local law, we also treat these identifiers as Personal Information. Similarly, to the extent that non-personal information is combined with Personal Information, we treat the combined information as Personal Information.

We also use cookies and other technologies to remember Personal Information when you use our website, online services, and applications. Our goal in these cases is to make your experience with EasyAML more convenient and personal.

Most browsers automatically accept cookies, but you can usually modify your browser setting to disable cookies. Please note that certain features of the EasyAML website will not be available once cookies are disabled.

As is true of most websites, we gather some information automatically and store it in log files. This information includes Internet Protocol (IP) residential histories, browser type and language, Internet service provider (ISP), referring and exit pages, operating system, date/time stamp, and clickstream data.

1.4 Children

EasyAML does not knowingly collect Personal Information from children under 13. If we learn that we have collected the Personal Information of a child under 13 without first receiving verifiable parental consent we will take steps to delete the information as soon as possible.

2. How we use and share your Personal Information

2.1 How we use your Information

We only handle your Personal Information if we have a good reason under the law. The reason depends on the information itself and why we collected it. Generally, here are our main reasons:

Examples of these legitimate interests include:

We might have other legitimate interests, and if so, we'll tell you clearly at the time.

2.2 When we might share your Information

Usually, we won't share your Personal Information with anyone else but we might have to share it with a government or regulatory body, or the police, if the law says we have to. We can also share your Personal Information with anyone else you request us to. We definitely won't sell your Personal Information as defined by the privacy laws.

In the event of a reorganisation, merger, or sale of EasyAML we may transfer any and all Personal Information we collect to the relevant third party.

3. Accessing, correcting, erasing and your other rights

On top of your other rights in this policy, you can get in touch with us anytime to see your personal information and ask us to:

Before you can do any of these things, we'll need to check who you are (or who's asking on your behalf). Then we'll deal with your request as quickly as we can, following the privacy laws. We'll only ever hold back information or not fix something if we have to by law, and if that happens, we'll tell you why in writing.

If you are not satisfied with how we deal with your query or complaint, you may contact the Office of the Australian Information Commissioner (OAIC) by:

4. Complaints

To exercise your rights under this Privacy Policy, or applicable law, or if you have a dispute regarding an individual’s Personal information, you may do so by:

We aim to respond to your dispute within 30 days. We take all complaints seriously and are committed to a quick and fair resolution. 

If you are not satisfied with how we deal with your query or complaint, you may contact the Office of the Australian Information Commissioner (OAIC) by: