Privacy Policy

1. About this policy

This Privacy Policy explains how Verity Ventures Pty Ltd (ABN 88 697 814 832) (“Verity Ventures”, “we”, “us”, “our”) handles personal information in connection with VerityRadar — our compliance and due-diligence platform available at verityradar.com and app.verityradar.com (the “Service”).

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where other privacy laws apply to you, additional rights may be set out in Section 13.

By using the Service, you acknowledge the practices described in this policy.

2. Two kinds of people this policy covers

The Service involves personal information about two different groups, and your rights differ depending on which you are:

3. The personal information we collect

From Users, we may collect:

About Screening subjects, the Service may compile:

We do not deliberately collect sensitive information about Users beyond what is described above. Reports about Screening subjects may, by their nature, include information that is sensitive.

4. How we collect it

We collect personal information: directly from you when you register, use or pay for the Service; automatically as you use the Service; from your organisation if it administers your account; and, for Screening subjects, from publicly available sources and licensed third-party data providers.

5. Why we use it

We use personal information to:

We do not sell personal information.

6. Automated processing and AI

The Service uses artificial intelligence and automated processing to analyse data and produce risk scores and report summaries about Screening subjects.

These outputs are generated in part by automated systems and may be incomplete, out of date or incorrect. They are provided as decision-support information only. They are not a decision made by us about any individual, and they are not a substitute for independent verification and human judgement by the User. Users are responsible for the decisions they make using the Service.

7. Who we share it with

We share personal information with:

PurposeLocation
Application hosting and storageAustralia
AI / automated analysisUnited States
Payment processingAustralia

The vendors behind these categories are named individually in our sub-processor list.

8. Overseas disclosure

Some of our service providers are located outside Australia — currently in the United States (for AI processing). Before disclosing personal information overseas, we take reasonable steps to ensure the recipient handles it consistently with the APPs, including through contractual protections. As at the date of this policy, no countries have been formally prescribed for the purposes of APP 8, so we rely on these reasonable steps rather than any prescribed-country exemption.

9. Information about Screening subjects

Where the Service compiles a report about an individual who is a Screening subject:

Sensitive information

Reports about individuals can surface sensitive information as defined in s6(1) of the Privacy Act — for example criminal record, health information, religious beliefs, or membership of a political association (including politically-exposed-person status). Where a report contains any of this, we mark it in the report itself. Users must use that information only for the AML/CTF compliance purpose it was collected for, disclose it only to people who need it for that purpose, and not retain it longer than that purpose requires.

Users must use the Service only for legitimate, lawful purposes. See the Terms & Conditions.

10. Security and data breaches

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. No system is completely secure, and we cannot guarantee absolute security.

If we become aware of a data breach that is likely to result in serious harm, we will assess it and notify the OAIC and affected individuals in line with the Notifiable Data Breach scheme.

Our safeguards include:

11. How long we keep it

We keep personal information only as long as needed for the purposes above, or for as long as the law requires us to keep it.

WhatHow long
Screening records and their audit trail (AML/CTF records)7 years, as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
Records under a legal holdUntil the hold is lifted, however old the record is
API request logs90 days
Account informationWhile your account is active, and after it is closed. We do not currently delete closed-account records automatically; you can ask us to delete yours at any time and we will action it manually.

The 7-year AML/CTF period is a legal minimum we cannot shorten, including at the request of a screening subject. It applies to the record of the screening. Where a screening subject asks us to erase their information and no legal hold applies, we remove their identifying details and the compiled report from the record and keep only the de-identified audit skeleton — see Section 9.

We may keep some information for longer where we are required to by law (for example, tax and financial records), or where it is needed to establish, exercise or defend a legal claim.

12. Your choices and rights (Users)

You can:

To make a request, contact us at admin@verityradar.com. We may need to verify your identity first. We aim to respond within 30 days. In some cases the law allows us to refuse or limit a request — for example, where granting it would reveal another person’s information, is manifestly unfounded or repetitive, or would prejudice an investigation — and if so we will explain why.

13. Cookies and analytics

We use cookies and similar technologies. Some are strictly necessary to operate and secure the Service. Others — such as analytics cookies that help us understand how the Service is used — are non-essential.

When you first visit, a consent banner lets you accept or manage non-essential cookies, and you can change your choice at any time. Strictly necessary cookies do not require consent.

14. The Service is not offered in the EEA or UK

The Service is intended for users outside the European Economic Area (EEA) and the United Kingdom. It is not directed or offered to individuals located in those regions.

You must not access or use the Service from the EEA or the UK, or use it to screen or profile individuals located there. We do not target the Service to the EEA or UK and do not intend to bring our processing within the EU or UK GDPR. If you are located in the EEA or UK, please do not use the Service.

15. Children

The Service is intended for business users and is not directed at, or intended for use by, anyone under 18. We do not knowingly collect personal information from children.

16. Changes to this policy

We may update this policy from time to time. We will post the updated version here and change the “Last updated” date. Material changes will be notified through the Service or by email.

17. Contact us and complaints

Questions, requests or complaints about privacy can be sent to:

Verity Ventures Pty Ltd
admin@verityradar.com

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.