AML/CTF obligations for Tranche 2 businesses are now in force. Since 1 July 2026 Get compliant

Legal

Privacy Policy

AML Guard, AML/CTF Compliance Platform
Operated by AML Guard Pty Ltd

1. Introduction

AML Guard is an AML/CTF compliance platform operated by AML Guard Pty Ltd ("we", "our", "us").

This privacy policy explains how we collect, use, disclose, and protect personal information in connection with the AML Guard compliance platform. It covers information about our customers (the agencies that subscribe to AML Guard) and the individuals whose information is processed as part of compliance activities (buyers, sellers, beneficial owners, and other parties to real estate transactions).

We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also operate within the framework of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), which imposes specific obligations regarding the collection, use, and retention of personal information for compliance purposes.

For Transaction Party data (buyers, sellers, beneficial owners), the subscribing agency is the reporting entity with primary AML/CTF obligations. AML Guard operates the platform through which the agency collects and processes this information. Individuals seeking access to their personal information should contact the agency that conducted the CDD in the first instance, or AML Guard directly as described in Section 9.

2. Personal Information We Collect

2.1 Agency Users (Our Customers)

When a real estate agency subscribes to AML Guard, we collect:

2.2 Transaction Parties (Individuals Subject to CDD)

When an agency conducts Customer Due Diligence (CDD) through AML Guard, the following personal information about buyers, sellers, beneficial owners, directors, and other relevant parties may be collected:

2.3 Identity Documents

AML Guard facilitates identity verification through a third-party provider. Individuals verify their identity on their own device by scanning documents and completing a biometric face match. From 1 July 2026, in accordance with OAIC guidance on AML/CTF obligations, AML Guard stores structured verification results (name, date of birth, document type, document number, verification outcome, DVS transaction references) rather than copies of original identification documents. Raw images of identity documents are not retained by AML Guard.

3. How We Collect Personal Information (APP 3 & 5)

We collect personal information:

At the point of identity verification, individuals are informed: "Your verified identity information may be shared with other regulated professionals involved in this transaction, as required by the AML/CTF Act 2006."

4. Purpose of Collection and Use (APP 6)

We collect and use personal information for the following purposes:

The AML/CTF Act provides the primary legal basis for collection and use of personal information for compliance purposes. Under APP 6.2(b), disclosure for AML/CTF compliance is authorised by law.

5. Disclosure of Personal Information

5.1 Other Reporting Entities

Where permitted or required by law, including under valid AML/CTF reliance arrangements (sections 37A and 38 of the AML/CTF Act), structured CDD evidence may be shared with other reporting entities involved in the same transaction. Evidence shared contains structured verification results only, not copies of original identification documents.

5.2 Third-Party Service Providers

Provider CategoryPurposeData Location
Identity Verification ProviderBiometric face match, document scanning, DVS checksAustralia
Screening ProviderSanctions, PEP, adverse media screening; ASIC company extractsAustralia
Cloud Infrastructure (AWS)Platform hosting, database, encryption, storageap-southeast-2 (Sydney)
Authentication ProviderUser login and session managementUnited States (auth tokens only)
Payment Processor (Stripe)Subscription billingUnited States and other countries used by Stripe (payment data only). See stripe.com/au/privacy.
CRM IntegrationCompliance status sync (no sensitive CDD data transferred to CRM). REX at launch; additional CRMs planned.Australia

We do not sell, rent, or trade personal information to third parties.

5.3 Legal and Regulatory Disclosure

We may disclose personal information where required by law, including to AUSTRAC in connection with suspicious matter reports, threshold transaction reports, or compliance audits. We may also disclose information pursuant to court orders or lawful government requests.

6. Cross-Border Disclosure (APP 8)

AML Guard's core compliance data (including CDD records, screening results, risk assessments, and vault evidence) is hosted in Australia on AWS infrastructure in the Sydney region.

Limited operational data may be processed outside Australia in the following circumstances:

All cross-border transfers are encrypted in transit using TLS 1.2 or higher. We take reasonable steps to ensure overseas recipients comply with obligations substantially similar to the APPs.

7. Data Security (APP 11)

We have implemented technical and organisational measures to protect personal information, including:

For further detail on our security posture, see the Security page.

8. Data Retention

The AML/CTF Act requires reporting entities to retain CDD and transaction records for at least 7 years after the business relationship ends or the transaction completes. AML Guard applies a conservative 8-year retention standard for real estate transactions to accommodate settlement timelines and provide a compliance buffer. This is a precautionary, catch-all setting applied automatically by AML Guard on your behalf; you are not required to configure it, and it sits above the 7-year statutory minimum.

Data TypeRetention PeriodLegal Basis
CDD verification records8 yearsAML/CTF Act s 112 (7-yr minimum); 8-yr AML Guard standard for RE
Screening results (sanctions, PEP, adverse media)8 yearsAML/CTF Act s 112; AML Guard standard
Risk assessments8 yearsAML/CTF Act s 112; AML Guard standard
Ongoing monitoring records8 years from last activityAML/CTF Act s 112; AML Guard standard
CDD reliance share records7 years from share dateAML/CTF Act ss 37A, 38
Audit trail events8 yearsAML/CTF Act record-keeping obligations; AML Guard standard
Agency account informationDuration of subscription + 90 daysService provision
API and security logs12 monthsSecurity monitoring

Where retention is required by the AML/CTF Act, data cannot be deleted at the request of the individual during the retention period. This overrides the usual right to request deletion under the Privacy Act.

9. Access and Correction (APP 12 & 13)

Agency users can view, export, and manage compliance records through the AML Guard interface, subject to their role-based permissions.

Individuals who have been subject to CDD through AML Guard may request access to the personal information held about them by contacting the agency that conducted the CDD, or by contacting us directly at [email protected]. We will respond to access requests within 30 days.

We may refuse access in limited circumstances permitted by the Privacy Act 1988, including where providing access would prejudice the prevention, detection, investigation, or prosecution of criminal offences (including money laundering and terrorism financing), or would constitute tipping-off under section 123 of the AML/CTF Act.

10. Complaints

If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by contacting us at [email protected]. We will acknowledge your complaint within 7 days and provide a response within 30 days.

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

11. Changes to This Policy

We may update this privacy policy from time to time. Material changes will be notified via the AML Guard platform and/or by email to subscribing agencies. The effective date at the top of this policy indicates when it was last updated.

12. Contact

For privacy enquiries or to exercise your rights under the Privacy Act:

AML Guard Pty Ltd
ABN: · Email: [email protected]
Website: amlguard.com.au

See also: Security · Terms of Service · About AML Guard