Privacy Policy
This policy explains how IDProof handles personal information on behalf of the reporting entities (tenants) who use it, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
What we collect
Identity documents and details you provide through a secure link (e.g. name, date of birth, document numbers, and your answers to risk declarations), collected only with your consent and only for AML/CTF customer-identification and record-keeping. Some of this is “sensitive information” under the APPs (for example, criminal-history or adverse-media declarations); we collect it only with your consent and handle it accordingly.
Why we collect it and how we use it
The reporting entity that sent you the link uses this information solely to identify you and to meet its customer due-diligence and record-keeping obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). We do not use it for marketing, and we do not sell it. It is not disclosed to anyone other than that reporting entity and IDProof (as its service provider), except where disclosure is required or authorised by law.
How it is stored
Sensitive information is encrypted at rest and stored in Australia. Access is restricted to the reporting entity that requested your documents.
Overseas disclosure
Your information is stored and processed in Australia (the ap-southeast-2 region). We do not disclose your personal information to overseas recipients.
Retention
Records are retained for the period required by AML/CTF law (at least 7 years after the customer relationship ends). Because this is a legal obligation, retention may override a later request to erase your information.
Access and correction
You may ask to access the personal information held about you, or to correct it if it is inaccurate, out of date, or incomplete (APP 12 and APP 13). Because this information is kept as an AML/CTF record, corrections are made by adding an updated record rather than overwriting the original. To make a request, contact the reporting entity that sent you the link, or IDProof using the details below.
Complaints
If you believe your personal information has been mishandled or that we have breached the Australian Privacy Principles, you can make a complaint. Contact the reporting entity that sent you the link in the first instance, or contact IDProof (a service by SNS Tech Services) at info@snstechservices.com.au. We will acknowledge your complaint and aim to respond within 30 days. If you are not satisfied with our response, you may escalate to the Office of the Australian Information Commissioner (OAIC) (phone 1300 363 992).
Contact
For privacy enquiries, contact the reporting entity that sent you the link, or IDProof (a service by SNS Tech Services) at info@snstechservices.com.au.