This policy explains how Duly Compliance Pty Ltd (“Duly Compliance”, “we”, “us”) handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
When you register or subscribe, we collect your name, business name, position, email address, phone number, business ABN, and billing details. Payment card details are collected and stored by our payment processor, not by us.
To deliver customer verification (KYC/KYB), enhanced due diligence and record-keeping, we handle information you provide about the parties to your transactions. This can include names, dates of birth, residential and contact details, identity-document details, beneficial-ownership and entity-structure information, and the results of identity, sanctions, PEP and adverse-media screening. Some of this is sensitive information within the meaning of the Privacy Act and is handled with corresponding care.
We collect log data, device and browser information, and information about how you use the portal, to operate, secure and improve the service.
We collect information directly from you through the portal, our forms and correspondence; from your authorised users; and from third-party verification and screening providers we engage to perform identity and background checks at your direction.
We disclose personal information only as needed to provide the service or as required or authorised by law, including to:
We do not sell personal information. Disclosures relating to suspicious-matter reporting are handled consistently with the tipping-off provisions of the AML/CTF Act.
Some of our service providers are located overseas. Our payment processor (Stripe) and our authentication provider (Memberstack) store and process personal information in the United States. Our identity and screening provider, NameScan, is an Australian provider. Before personal information is disclosed to an overseas recipient we take reasonable steps to ensure it is handled consistently with the APPs, including through contractual data-protection terms.
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure, including access controls, role-based permissions, encryption in transit and at rest, and audit logging.
We retain records for as long as needed to provide the service and to meet legal obligations. Records relating to AML/CTF customer due diligence are generally retained for seven years consistent with the record-keeping requirements of the AML/CTF Act, after which they are securely destroyed or de-identified.
You may request access to, or correction of, the personal information we hold about you by contacting us using the details below. We will respond within a reasonable period and may need to verify your identity first. Where we cannot give access or make a correction, we will explain why.
We may send you service-related and occasional marketing communications. You can opt out of marketing at any time using the unsubscribe link or by contacting us.
Our website uses only the minimal cookies needed to operate the site. We do not use third-party analytics or advertising trackers.
If you have a privacy concern, please contact us first at info@dulycompliance.com.au and we will investigate. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or 1300 363 992.
We may update this policy from time to time. The current version is always available on this page, with the “last updated” date shown above.
Duly Compliance Pty Ltd · ABN 76 834 095 992
Email: info@dulycompliance.com.au