Legal
Privacy Policy
AML Guard, AML/CTF Compliance Platform
Operated by AML Guard Pty Ltd
1. Introduction
AML Guard is an AML/CTF compliance platform operated by AML Guard Pty Ltd ("we", "our", "us").
This privacy policy explains how we collect, use, disclose, and protect personal information in connection with the AML Guard compliance platform. It covers information about our customers (the agencies that subscribe to AML Guard) and the individuals whose information is processed as part of compliance activities (buyers, sellers, beneficial owners, and other parties to real estate transactions).
We are bound by the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We also operate within the framework of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), which imposes specific obligations regarding the collection, use, and retention of personal information for compliance purposes.
For Transaction Party data (buyers, sellers, beneficial owners), the subscribing agency is the reporting entity with primary AML/CTF obligations. AML Guard operates the platform through which the agency collects and processes this information. Individuals seeking access to their personal information should contact the agency that conducted the CDD in the first instance, or AML Guard directly as described in Section 9.
2. Personal Information We Collect
2.1 Agency Users (Our Customers)
When a real estate agency subscribes to AML Guard, we collect:
- Name, email address, and phone number of agency staff who access the platform
- Agency business name, ABN, and office address
- Login credentials and authentication data (managed via our identity provider)
- Payment information for subscription billing (processed by Stripe; we do not store full card details)
- Usage data including actions taken within the platform for audit and support purposes
2.2 Transaction Parties (Individuals Subject to CDD)
When an agency conducts Customer Due Diligence (CDD) through AML Guard, the following personal information about buyers, sellers, beneficial owners, directors, and other relevant parties may be collected:
- Full name, date of birth, and residential address
- Identity document details (document type, document number, issuing authority); see Section 2.3
- Biometric data (facial images for identity verification, processed by our verification provider and not retained by AML Guard after verification)
- Company and trust ownership details, including ASIC-sourced shareholder and director information
- Sanctions, PEP (Politically Exposed Person), and adverse media screening results
- Risk assessment scores and outcomes
- Ongoing monitoring results and change detection records
- Contact details (email, mobile number) used to deliver identity verification requests and evidence sharing links
2.3 Identity Documents
AML Guard facilitates identity verification through a third-party provider. Individuals verify their identity on their own device by scanning documents and completing a biometric face match. From 1 July 2026, in accordance with OAIC guidance on AML/CTF obligations, AML Guard stores structured verification results (name, date of birth, document type, document number, verification outcome, DVS transaction references) rather than copies of original identification documents. Raw images of identity documents are not retained by AML Guard.
3. How We Collect Personal Information (APP 3 & 5)
We collect personal information:
- Directly from agency users when they create accounts and use the platform
- Directly from transaction parties when they complete identity verification via secure links sent by the agency
- From third-party sources as part of the compliance process, including ASIC company registers (for beneficial ownership tracing), sanctions and PEP databases, adverse media sources, and the Document Verification Service (DVS)
- From connected CRM systems (such as REX, with additional CRM integrations planned) where the agency has enabled the integration
- From other reporting entities under formal CDD reliance arrangements (sections 37A and 38 of the AML/CTF Act)
At the point of identity verification, individuals are informed: "Your verified identity information may be shared with other regulated professionals involved in this transaction, as required by the AML/CTF Act 2006."
4. Purpose of Collection and Use (APP 6)
We collect and use personal information for the following purposes:
- To provide the AML Guard compliance platform to subscribing agencies
- To conduct Customer Due Diligence as required by the AML/CTF Act, including identity verification, beneficial ownership identification, sanctions and PEP screening, and risk assessment
- To conduct ongoing monitoring of customers at risk-based intervals as required by the AML/CTF Act
- To support the preparation and lodgement workflows for Suspicious Matter Reports (SMRs) and Threshold Transaction Reports (TTRs). The subscribing agency remains responsible for actual report submission to AUSTRAC.
- To maintain compliance records in the evidence vault for the legally required retention period
- To facilitate CDD reliance arrangements between reporting entities under sections 37A and 38 of the AML/CTF Act
- To process subscription payments and manage billing
- To provide customer support and platform administration
- To improve the platform and develop new features
The AML/CTF Act provides the primary legal basis for collection and use of personal information for compliance purposes. Under APP 6.2(b), disclosure for AML/CTF compliance is authorised by law.
5. Disclosure of Personal Information
5.1 Other Reporting Entities
Where permitted or required by law, including under valid AML/CTF reliance arrangements (sections 37A and 38 of the AML/CTF Act), structured CDD evidence may be shared with other reporting entities involved in the same transaction. Evidence shared contains structured verification results only, not copies of original identification documents.
5.2 Third-Party Service Providers
| Provider Category | Purpose | Data Location |
|---|---|---|
| Identity Verification Provider | Biometric face match, document scanning, DVS checks | Australia |
| Screening Provider | Sanctions, PEP, adverse media screening; ASIC company extracts | Australia |
| Cloud Infrastructure (AWS) | Platform hosting, database, encryption, storage | ap-southeast-2 (Sydney) |
| Authentication Provider | User login and session management | United States (auth tokens only) |
| Payment Processor (Stripe) | Subscription billing | United States and other countries used by Stripe (payment data only). See stripe.com/au/privacy. |
| CRM Integration | Compliance status sync (no sensitive CDD data transferred to CRM). REX at launch; additional CRMs planned. | Australia |
We do not sell, rent, or trade personal information to third parties.
5.3 Legal and Regulatory Disclosure
We may disclose personal information where required by law, including to AUSTRAC in connection with suspicious matter reports, threshold transaction reports, or compliance audits. We may also disclose information pursuant to court orders or lawful government requests.
6. Cross-Border Disclosure (APP 8)
AML Guard's core compliance data (including CDD records, screening results, risk assessments, and vault evidence) is hosted in Australia on AWS infrastructure in the Sydney region.
Limited operational data may be processed outside Australia in the following circumstances:
- Authentication tokens processed by our identity provider (United States)
- Payment data processed by Stripe for subscription billing
All cross-border transfers are encrypted in transit using TLS 1.2 or higher. We take reasonable steps to ensure overseas recipients comply with obligations substantially similar to the APPs.
7. Data Security (APP 11)
We have implemented technical and organisational measures to protect personal information, including:
- AES-256 encryption at rest for all stored data
- TLS 1.2+ encryption in transit for all communications
- Dedicated encryption keys for compliance evidence, separate from operational data
- Multi-tenant architecture with logical data isolation at the database level
- Role-based access control with separate compliance officer permissions for sensitive actions
- Immutable audit trail for all compliance actions
- Multi-factor authentication support
- Automated session management with secure token handling
For further detail on our security posture, see the Security page.
8. Data Retention
The AML/CTF Act requires reporting entities to retain CDD and transaction records for at least 7 years after the business relationship ends or the transaction completes. AML Guard applies a conservative 8-year retention standard for real estate transactions to accommodate settlement timelines and provide a compliance buffer. This is a precautionary, catch-all setting applied automatically by AML Guard on your behalf; you are not required to configure it, and it sits above the 7-year statutory minimum.
| Data Type | Retention Period | Legal Basis |
|---|---|---|
| CDD verification records | 8 years | AML/CTF Act s 112 (7-yr minimum); 8-yr AML Guard standard for RE |
| Screening results (sanctions, PEP, adverse media) | 8 years | AML/CTF Act s 112; AML Guard standard |
| Risk assessments | 8 years | AML/CTF Act s 112; AML Guard standard |
| Ongoing monitoring records | 8 years from last activity | AML/CTF Act s 112; AML Guard standard |
| CDD reliance share records | 7 years from share date | AML/CTF Act ss 37A, 38 |
| Audit trail events | 8 years | AML/CTF Act record-keeping obligations; AML Guard standard |
| Agency account information | Duration of subscription + 90 days | Service provision |
| API and security logs | 12 months | Security monitoring |
Where retention is required by the AML/CTF Act, data cannot be deleted at the request of the individual during the retention period. This overrides the usual right to request deletion under the Privacy Act.
9. Access and Correction (APP 12 & 13)
Agency users can view, export, and manage compliance records through the AML Guard interface, subject to their role-based permissions.
Individuals who have been subject to CDD through AML Guard may request access to the personal information held about them by contacting the agency that conducted the CDD, or by contacting us directly at [email protected]. We will respond to access requests within 30 days.
We may refuse access in limited circumstances permitted by the Privacy Act 1988, including where providing access would prejudice the prevention, detection, investigation, or prosecution of criminal offences (including money laundering and terrorism financing), or would constitute tipping-off under section 123 of the AML/CTF Act.
10. Complaints
If you believe we have breached the Australian Privacy Principles, you may lodge a complaint by contacting us at [email protected]. We will acknowledge your complaint within 7 days and provide a response within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.
11. Changes to This Policy
We may update this privacy policy from time to time. Material changes will be notified via the AML Guard platform and/or by email to subscribing agencies. The effective date at the top of this policy indicates when it was last updated.
12. Contact
For privacy enquiries or to exercise your rights under the Privacy Act:
AML Guard Pty Ltd
ABN: ·
Email: [email protected]
Website: amlguard.com.au
See also: Security · Terms of Service · About AML Guard