Draft — pending independent legal review. This document is a working draft prepared for review by qualified legal counsel. It is not yet a binding agreement and does not constitute legal advice. Nothing on this page should be relied upon until it has been independently reviewed and formally adopted.
Privacy Policy
How Indium OS collects, uses, discloses, secures, and retains personal information, aligned to the Australian Privacy Act 1988 and the Australian Privacy Principles.
Draft version · Last updated July 2026
1. Scope
This policy applies to personal information handled by Indium OS in providing its compliance platform and outsourced customer due diligence (CDD) support. It is drafted with reference to the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Your agency, as the reporting entity, is the primary handler of the personal information collected through the CDD process; Indium OS processes that information to provide the service.
2. Personal information we collect
To support anti-money-laundering and counter-terrorism-financing obligations, the Platform collects and processes:
- Identity information and documents — full name, date of birth, residential address, and identity documents such as passports, driver licences, and Medicare cards;
- Verification results — outcomes of Document Verification Service (DVS) checks and related matching results;
- Beneficial ownership information — details of ultimate beneficial owners, company officers, and trust structures;
- Screening data — politically exposed person (PEP) and sanctions screening results;
- Transaction and matter data — the property matter, party roles, and risk assessment outcomes; and
- Account and usage data — user login, role, and audit-log activity.
3. Why we collect it
We collect and process this information for the primary purpose of enabling your agency to meet its obligations under the AML/CTF Act — including customer identification and verification, ongoing due diligence, risk assessment, record-keeping, and the preparation and evidencing of compliance workflows. We do not use identity documents for direct marketing.
4. Document Verification Service (DVS) consent
Identity verification may be performed against official government records via the Document Verification Service. Before a DVS check is run, the individual is asked to provide express consentto their identity documents being verified against the issuing agency's records. Verification is not performed without that consent, and consent is recorded as part of the audit trail.
5. Retention — seven years
Records and supporting evidence collected for AML/CTF purposes are retained for a minimum of seven (7) years, consistent with the record-keeping requirements of the AML/CTF Act. Retention continues for the statutory period even after an account is closed. After the retention period, records are securely deleted or de-identified unless a longer period is required by law.
6. Data residency
Personal information collected through the Platform is hosted on infrastructure located in Australia (AWS Asia Pacific (Sydney) — region ap-southeast-2). Where any processing by a sub-processor could involve access from outside Australia, we will take reasonable steps to ensure comparable protection consistent with APP 8.
7. Disclosures
We may disclose personal information to:
- Your agency (the reporting entity) — which controls and is responsible for the compliance record;
- Verification and screening providers — including the DVS gateway and PEP / sanctions screening services, to perform checks;
- Our payment provider — to process fees and, where applicable, agent cash-outs;
- Regulators and law enforcement — where required or authorised by law, including AUSTRAC; and
- Hosting and infrastructure sub-processors — bound by confidentiality and data-protection obligations.
We do not sell personal information.
8. Security
We take reasonable technical and organisational measures to protect personal information, including encryption in transit and at rest, role-gated access, audit logging, and access controls. No system is perfectly secure, and we cannot guarantee absolute security.
9. Access and correction
Under the APPs you may request access to, and correction of, the personal information we hold about you. Because your agency is the reporting entity, some requests may be directed to, or coordinated with, that agency. Access may be limited where the AML/CTF Act or other law requires (for example, "tipping off" restrictions relating to suspicious matter reporting).
10. Contact
To make a privacy enquiry, request access or correction, or make a complaint, contact us at privacy@indiumos.com. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
This policy must be read together with our Terms of Service and Legal Disclaimer.