Privacy Policy
1. About this policy
This Privacy Policy explains how Verity Ventures Pty Ltd (ABN 88 697 814 832) (“Verity Ventures”, “we”, “us”, “our”) handles personal information in connection with VerityRadar — our compliance and due-diligence platform available at verityradar.com and app.verityradar.com (the “Service”).
We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where other privacy laws apply to you, additional rights may be set out in Section 13.
By using the Service, you acknowledge the practices described in this policy.
2. Two kinds of people this policy covers
The Service involves personal information about two different groups, and your rights differ depending on which you are:
- Users — the people who hold an account and use VerityRadar (and the organisations they represent).
- Screening subjects — individuals who are the subject of a search, report or screening run by a User (for example, a director, beneficial owner or counterparty). We may handle personal information about these individuals even though they are not our Users. Section 9 explains how this works and what rights these individuals have.
3. The personal information we collect
From Users, we may collect:
- Identity and contact details — name, work email, organisation, role, and phone number if you provide it.
- Account and authentication data — login credentials and security information.
- Billing information — billing name and contact details, and a record of transactions. Card details are entered directly with our third-party payment processor; we do not store full card numbers.
- Content you submit — company names, search queries, and files you upload for screening (which may be CSV, XLSX, PDF or image files).
- Reports and history — the screening reports generated for you and your usage history.
- Technical and usage data — IP address, device and browser information, and how you interact with the Service.
About Screening subjects, the Service may compile:
- Identifying details and risk-relevant information drawn from publicly available sources and licensed third-party data providers, including sanctions, politically-exposed-person (PEP) and regulatory-status information, assembled into a risk-scored report.
We do not deliberately collect sensitive information about Users beyond what is described above. Reports about Screening subjects may, by their nature, include information that is sensitive.
4. How we collect it
We collect personal information: directly from you when you register, use or pay for the Service; automatically as you use the Service; from your organisation if it administers your account; and, for Screening subjects, from publicly available sources and licensed third-party data providers.
5. Why we use it
We use personal information to:
- provide, operate and secure the Service and generate screening reports;
- create and administer accounts, process payments and manage credits;
- provide support and respond to enquiries;
- maintain audit logs and meet our own legal and record-keeping obligations;
- monitor, troubleshoot and improve the Service; and
- send you service-related messages, and (where permitted) updates about the Service, which you can opt out of at any time.
We do not sell personal information.
6. Automated processing and AI
The Service uses artificial intelligence and automated processing to analyse data and produce risk scores and report summaries about Screening subjects.
These outputs are generated in part by automated systems and may be incomplete, out of date or incorrect. They are provided as decision-support information only. They are not a decision made by us about any individual, and they are not a substitute for independent verification and human judgement by the User. Users are responsible for the decisions they make using the Service.
7. Who we share it with
We share personal information with:
- Service providers (sub-processors) who help us run the Service, under confidentiality and data-protection obligations. We use providers located in Australia and the United States, by category:
| Purpose | Location |
|---|---|
| Application hosting and storage | Australia |
| AI / automated analysis | United States |
| Payment processing | Australia |
The vendors behind these categories are named individually in our sub-processor list.
- Your organisation — if your account is administered by an organisation, its administrators may access your account information and activity.
- Authorities and advisers — where required or authorised by law, or to establish, exercise or defend legal claims.
- A successor — if we restructure or transfer the business, under appropriate confidentiality protections.
8. Overseas disclosure
Some of our service providers are located outside Australia — currently in the United States (for AI processing). Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual protections. As at the date of this policy, no countries have been formally prescribed for the purposes of APP 8, so we rely on these reasonable steps rather than any prescribed-country exemption.
9. Information about Screening subjects
Where the Service compiles a report about an individual who is a Screening subject:
- The User who runs the screening determines the purpose, and is responsible for having a lawful basis and a permitted purpose to do so.
- We act to provide the screening tool and assemble information from publicly available sources and licensed third-party data providers. We do not independently verify the accuracy of third-party source data.
- A Screening subject who wishes to access or correct information, to object to its handling, or to ask us to erase it, can contact us at admin@verityradar.com. We aim to respond within 30 days. Where the information was provided to, or generated for, a particular User, we may need to direct the request to, or coordinate with, that User. We will respond consistently with our obligations under the Privacy Act.
- Where we act on an erasure request, we remove the individual’s identifying details and the compiled report from the record. We keep a de-identified skeleton — the fact that a screening ran, when, and its risk rating — because the 7-year AML/CTF record-keeping obligation in Section 11 applies to that fact. We cannot erase a record that is subject to a legal hold.
- Individuals are screened in isolation. A report we compile about an individual is generated fresh for the User who requested it and is never re-served to a different User. We do share compiled reports about companies between Users, because they contain no individual’s personal information.
Sensitive information
Reports about individuals can surface sensitive information as defined in s6(1) of the Privacy Act — for example criminal record, health information, religious beliefs, or membership of a political association (including politically-exposed-person status). Where a report contains any of this, we mark it in the report itself. Users must use that information only for the AML/CTF compliance purpose it was collected for, disclose it only to people who need it for that purpose, and not retain it longer than that purpose requires.
10. Security and data breaches
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. No system is completely secure, and we cannot guarantee absolute security.
If we become aware of a data breach that is likely to result in serious harm, we will assess it and notify the OAIC and affected individuals in line with the Notifiable Data Breach scheme.
Our safeguards include:
- encryption of data in transit using TLS;
- access controls and role-based access on a least-privilege basis;
- multi-factor authentication for administrative access;
- hosting with a reputable provider located in Australia;
- audit logging of activity within the Service;
- regular patching, backups and monitoring; and
- confidentiality and data-protection obligations on our staff and service providers.
11. How long we keep it
We keep personal information only as long as needed for the purposes above, or for as long as the law requires us to keep it.
| What | How long |
|---|---|
| Screening records and their audit trail (AML/CTF records) | 7 years, as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) |
| Records under a legal hold | Until the hold is lifted, however old the record is |
| API request logs | 90 days |
| Account information | While your account is active, and after it is closed. We do not currently delete closed-account records automatically; you can ask us to delete yours at any time and we will action it manually. |
The 7-year AML/CTF period is a legal minimum we cannot shorten, including at the request of a screening subject. It applies to the record of the screening. Where a screening subject asks us to erase their information and no legal hold applies, we remove their identifying details and the compiled report from the record and keep only the de-identified audit skeleton — see Section 9.
We may keep some information for longer where we are required to by law (for example, tax and financial records), or where it is needed to establish, exercise or defend a legal claim.
12. Your choices and rights (Users)
You can:
- access and correct your account information through your account settings, or by contacting us;
- request access to, or correction of, personal information we hold about you, consistent with the APPs;
- opt out of non-essential communications; and
- close your account.
To make a request, contact us at admin@verityradar.com. We may need to verify your identity first. We aim to respond within 30 days. In some cases the law allows us to refuse or limit a request — for example, where granting it would reveal another person’s information, is manifestly unfounded or repetitive, or would prejudice an investigation — and if so we will explain why.
13. Cookies and analytics
We use cookies and similar technologies. Some are strictly necessary to operate and secure the Service. Others — such as analytics cookies that help us understand how the Service is used — are non-essential.
When you first visit, a consent banner lets you accept or manage non-essential cookies, and you can change your choice at any time. Strictly necessary cookies do not require consent.
14. The Service is not offered in the EEA or UK
The Service is intended for users outside the European Economic Area (EEA) and the United Kingdom. It is not directed or offered to individuals located in those regions.
You must not access or use the Service from the EEA or the UK, or use it to screen or profile individuals located there. We do not target the Service to the EEA or UK and do not intend to bring our processing within the EU or UK GDPR. If you are located in the EEA or UK, please do not use the Service.
15. Children
The Service is intended for business users and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect personal information from children.
16. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Material changes will be notified through the Service or by email.
17. Contact us and complaints
Questions, requests or complaints about privacy can be sent to:
Verity Ventures Pty Ltd
admin@verityradar.com
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.