⚠️ Important Notice
If CompliDesk is collecting your information on behalf of one of our clients (such as an accounting firm, law firm or real estate agency), this policy does not apply to you. In that case, CompliDesk acts as a data processor for our client. The client's own privacy policy applies and you should contact them directly with privacy questions.
1. Who We Are and Our Compliance Commitment
Kainos Consultants Australia Pty Ltd (ABN 46 678 061 535), trading as CompliDesk ("CompliDesk", "we", "us") provides a cloud-based AML/CTF compliance management software-as-a-service (SaaS) platform for Australian Tranche 2 reporting entities. We are committed to protecting your privacy and handle all personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act), the Australian Privacy Principles (APPs), and the Spam Act 2003 (Cth).
Our platform is accessible at app.complidesk.com.au. For any privacy-related enquiries, please contact our Privacy Officer at privacy@complidesk.com.au.
2. What Information We Collect
To provide our compliance services, we collect personal and business information. This includes:
- Account & Contact Information: Your name, business email address, phone number, firm name, ABN, and profession.
- Business Information: Information about your firm’s structure, compliance history, and AML/CTF compliance officers.
- Identity & KYC Verification Information: Government-issued identity documents (e.g., driver's licenses, passports), national identity numbers, dates of birth, addresses, and biometric verification data (such as facial matching data) where applicable for client verification.
- Compliance Data: Tax File Numbers (TFN) and AML/CTF compliance information where legally required to satisfy AUSTRAC reporting and record-keeping obligations.
- Payment Information: Payment details processed securely through our third-party payment processor, Stripe. We do not store or have access to your credit card numbers.
- Usage & Security Logs: IP addresses, browser types, device information, access times, and security logs of actions taken within the platform.
- Usage Analytics & Cookies: Anonymised usage metrics and cookies used for session management, authentication, and security.
3. Why We Collect Your Information
We collect, hold, and use your personal information for the following purposes:
- To provision, maintain, and secure your CompliDesk account and platform access.
- To perform identity verification and Know Your Customer (KYC) checks as requested by you.
- To assist you in meeting your AUSTRAC compliance and AML/CTF reporting obligations.
- To process payments and manage your subscription billing.
- To send critical service notifications, compliance updates, and security alerts.
- To detect, prevent, and address security incidents, fraud, or technical issues.
- To comply with our legal and regulatory obligations under the AML/CTF Act 2006 (Cth) and other applicable Australian laws.
4. How Your Information is Stored and Secured
We take data security extremely seriously. All personal information and compliance data is stored securely in Australia using Amazon Web Services (AWS ap-southeast-2 region in Sydney) and managed via Supabase. Our security measures include:
- Encryption: AES-256 encryption at rest and TLS 1.3 encryption in transit.
- Access Control: Role-based access controls (RBAC), multi-factor authentication (MFA), and strict internal access policies.
- Monitoring: Continuous security monitoring, automated vulnerability scanning, and detailed audit logging.
- Data Isolation: Logical separation of tenant data to ensure your information is kept secure and private.
4a. Automated Decision-Making and AI Use
CompliDesk uses Artificial Intelligence (AI) — specifically Anthropic's Claude models — as part of our Customer Due Diligence (CDD) screening feature, to help analyse client risk profiles and screening results.
In line with the transparency requirements for automated decision-making under the Privacy Act 1988 (Cth):
- What personal information is used: Client names, dates of birth, addresses, screening/watchlist results and risk-relevant profile data you have entered may be provided to the AI model to generate a risk analysis.
- How the output is used: AI-generated analysis is a decision-support tool only. CompliDesk does not make any compliance decision "solely" by computer — every AI output must be reviewed and either accepted, amended or rejected by you (a qualified person at your firm) before it affects a client's risk rating, onboarding outcome or any compliance record. You remain the decision-maker at all times.
- Other safeguards: AI screening is supplementary to, not a replacement for, your own due diligence obligations; we take steps to monitor and reduce algorithmic bias in AI-assisted analysis; AI outputs are not retained by Anthropic for model training under our commercial terms with them.
You remain responsible for all compliance decisions made using CompliDesk. AI screening results must be reviewed and verified by a qualified person before being relied upon.
5. Who We Share Your Information With
We do not sell, rent, or trade your personal information. We only share your information with the following third parties under strict confidentiality and privacy agreements:
- Identity Verification Providers: Third-party providers (such as Didit) to perform biometric and database-matching KYC checks.
- Payment Processors: Stripe, for secure billing and subscription payment processing.
- Cloud Infrastructure Providers: AWS and Supabase, for secure hosting and database services.
- Service Providers: Transactional email delivery services (such as Resend) to send account and system notifications.
- Regulators and Law Enforcement: Government bodies (such as AUSTRAC) or law enforcement agencies where we are legally required to do so.
6. Data Retention
We retain your account and personal information for as long as your subscription is active, and for a reasonable period thereafter to facilitate account recovery or as required by law. AML/CTF compliance records, including KYC verification logs, risk assessments, and audit trails, are retained for a minimum of 7 years in compliance with the AML/CTF Act 2006 (Cth). When information is no longer required, it is securely destroyed or de-identified.
7. Your Rights and Access
Under the Australian Privacy Principles, you have the right to:
- Request access to the personal information we hold about you.
- Request that we correct any inaccurate, out-of-date, or incomplete personal information.
- Request that we delete your personal information (subject to our 7-year legal retention obligations for compliance records).
- Opt-out of receiving any promotional or marketing communications from us at any time.
To exercise any of these rights, please contact our Privacy Officer at privacy@complidesk.com.au. We will respond to your request within 30 days.
8. Complaints
If you believe we have breached the Australian Privacy Principles or have concerns about how your privacy has been handled, please contact our Privacy Officer. We will investigate your complaint and provide a written response within 30 days. If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. We will notify you of any material changes by posting the updated policy on this page and updating the "Last updated" date at the top of the policy.
10. Contact Us
Privacy Officer
Kainos Consultants Australia Pty Ltd, trading as CompliDesk
Email: privacy@complidesk.com.au
Website: complidesk.com.au