IDProof

Privacy Policy

IDProof is provided solely as a record-keeping and customer-identification support tool to help organisations meet their record-keeping obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). It performs no automated government identity matching, does not submit reports to AUSTRAC, and is not a substitute for the organisation’s own AML/CTF program or its obligation to make its own customer due-diligence decisions. Personal information is collected, stored, and processed only with the informed consent of the individual it concerns, and is used only for the AML/CTF record-keeping purpose for which it was provided. Information is retained for the period required by law and is handled in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

This policy explains how IDProof handles personal information on behalf of the reporting entities (tenants) who use it, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

What we collect

Identity documents and details you provide through a secure link (e.g. name, date of birth, document numbers, and your answers to risk declarations), collected only with your consent and only for AML/CTF customer-identification and record-keeping. Some of this is “sensitive information” under the APPs (for example, criminal-history or adverse-media declarations); we collect it only with your consent and handle it accordingly.

Why we collect it and how we use it

The reporting entity that sent you the link uses this information solely to identify you and to meet its customer due-diligence and record-keeping obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). We do not use it for marketing, and we do not sell it. It is not disclosed to anyone other than that reporting entity and IDProof (as its service provider), except where disclosure is required or authorised by law.

How it is stored

Sensitive information is encrypted at rest and stored in Australia. Access is restricted to the reporting entity that requested your documents.

Overseas disclosure

Your information is stored and processed in Australia (the ap-southeast-2 region). We do not disclose your personal information to overseas recipients.

Retention

Records are retained for the period required by AML/CTF law (at least 7 years after the customer relationship ends). Because this is a legal obligation, retention may override a later request to erase your information.

Access and correction

You may ask to access the personal information held about you, or to correct it if it is inaccurate, out of date, or incomplete (APP 12 and APP 13). Because this information is kept as an AML/CTF record, corrections are made by adding an updated record rather than overwriting the original. To make a request, contact the reporting entity that sent you the link, or IDProof using the details below.

Complaints

If you believe your personal information has been mishandled or that we have breached the Australian Privacy Principles, you can make a complaint. Contact the reporting entity that sent you the link in the first instance, or contact IDProof (a service by SNS Tech Services) at info@snstechservices.com.au. We will acknowledge your complaint and aim to respond within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) (phone 1300 363 992).

Contact

For privacy enquiries, contact the reporting entity that sent you the link, or IDProof (a service by SNS Tech Services) at info@snstechservices.com.au.