Privacy Policy

Veriqua Pty Ltd — ABN 92 697 961 023

Effective date: 6 August 2026 | Supersedes the policy dated 29 July 2026

1. About This Policy

Veriqua Pty Ltd (Veriqua, we, us or our) operates the Veriqua Compliance OS, a cloud-based compliance management platform for Australian businesses holding an Australian Financial Services Licence or subject to anti-money laundering and counter-terrorism financing obligations. We also provide identity verification and financial crime risk screening capabilities through approved service providers.

Veriqua complies with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), the Identity Verification Services Act 2023 (Cth) where applicable, and the privacy and consent requirements governing our access to the Document Verification Service (DVS).

This policy applies to our platform, website, enquiries, self-assessment tools, customer onboarding portal, identity services and screening services. It explains how we collect, hold, use and disclose personal information. A specific collection notice and express consent request is also presented before a DVS check is initiated.

Where a business customer enters information about its own customers, staff or other individuals into the Platform, that business may also have its own privacy obligations. Veriqua remains responsible for the personal information that it holds or controls.

2. Personal Information We Collect and How We Collect It

Depending on how the Platform and our services are used, we may collect and hold:

  • Account and business contact information — name, work email address, telephone number, job title, organisation, login credentials and account permissions.
  • Enquiry and self-assessment information — contact details, sector and business information, and responses submitted through forms such as the AUSTRAC Readiness Scorecard.
  • Compliance records — register entries, risk assessments, incidents, breaches, audit findings, approvals, training records, supporting documents and workflow history entered by a customer.
  • Customer onboarding information — name, date of birth, residential address, contact details, nationality, occupation, customer risk information, source-of-funds or source-of-wealth information where required, and other information needed for customer due diligence.
  • Identity document information — document type, document number or other government-related identifier, issuing authority, issue and expiry dates, document images where enabled, and other information displayed on or derived from an identity document.
  • DVS information — the identification information included in an Information Match Request, the associated Information Match Result, consent records, transaction references and audit metadata. Veriqua does not provide the underlying DVS Information Match Result to an ID Service Client.
  • Screening information — name, date of birth, nationality, country information and potential matches against sanctions, politically exposed person, relative or close associate, watchlist and adverse-media sources.
  • Sensitive information — screening information may reveal political opinions or affiliations, alleged or established criminal conduct, religious associations or other sensitive information. We collect sensitive information only where reasonably necessary and with consent, or where another legal permission applies.
  • Technical and security information — IP address, device and browser details, timestamps, login activity, access logs, security events and actions taken within the Platform.
  • Billing information — subscription tier, invoices, payment status and tokenised payment references. Full payment card details are collected and processed by Stripe and are not stored in Veriqua systems.

We collect information directly from individuals, from our business customers and authorised users, through the Platform and website, automatically through security and usage logs, and from identity verification, official record holder and screening providers. If a customer provides personal information about another person, the customer must have a lawful basis and must provide any required notices and obtain any required consent.

3. Why We Collect, Hold, Use and Disclose Personal Information

We handle personal information only where reasonably necessary for our functions and activities, including to:

  • provide, administer, support and secure the Platform and customer accounts;
  • perform customer due diligence, identity verification and financial crime risk screening requested by an authorised customer;
  • submit identity information through authorised third-party systems to an official record holder and receive a verification response;
  • produce a client-facing identity opinion based on multiple identity checks without disclosing the underlying DVS Information Match Result;
  • support sanctions, PEP, watchlist and adverse-media review and ongoing monitoring;
  • maintain consent, access, security, compliance and audit records;
  • communicate service messages, respond to enquiries, process billing and provide support;
  • meet legal, regulatory, contractual, audit and reporting obligations; and
  • improve service reliability and usability using aggregated or de-identified information where practicable.

Identity document information, DVS information and screening information are not sold, used for advertising, used for market research, used to create behavioural profiles, or used to train general-purpose AI models.

We may send marketing communications using business contact information where consent has been given or the communication is otherwise permitted by law. Every marketing communication will provide a practical way to opt out. Identity verification and customer due diligence information is never used for marketing.

4. Identity Verification, DVS and AML Screening

Document Verification Service

Veriqua participates in the Australian DVS as an Identity Service Provider. Rapid ID Pty Ltd (RapidID) is appointed as Veriqua's Information Match Agent for DVS access. DVS requests may also pass through approved gateway and intermediary service providers and are matched by the relevant Australian government official record holder.

Before a DVS request is transmitted, the individual is shown a collection notice describing the information collected, the purpose of the check, the categories of intermediaries involved, the individual's rights, the consequences of declining and how to complain. The individual must actively give informed, voluntary, current and specific express consent.

If consent is declined or withdrawn before the check is carried out, Veriqua will not initiate that DVS check. An alternative identity verification process may be available through the relevant business customer. Declining a DVS check may delay or prevent completion of onboarding where identity verification is required by law or by the customer's risk controls.

Veriqua does not disclose the underlying DVS Information Match Result to its ID Service Clients and does not allow a client to infer that result. Any client-facing identity opinion must be based on multiple identity checks, which may include the DVS response. Government-related identifiers are used only where permitted and are not adopted as Veriqua's own identifier for an individual.

Sanctions, PEP and adverse-media screening

Where screening is requested, limited identifying information may be sent through RapidID to ComplyAdvantage and its authorised service providers to search sanctions, PEP, relative and close associate, watchlist and adverse-media data. Screening may return potential matches and associated source material. A potential match is not a finding of wrongdoing and requires human review and appropriate risk-based decision-making.

5. Data Storage and Overseas Processing

At the effective date of this policy, Veriqua's primary application environment, production database, object storage and routine database backups are configured in Australian regions. Core compliance records and uploaded customer documents are therefore primarily stored in Australia. This does not mean that every service-provider processing activity occurs solely in Australia.

Identity verification and screening services use separate provider systems. DVS information is transmitted through RapidID and authorised DVS intermediaries to the Australian Government DVS and the relevant official record holder. AML screening information may be processed or accessed in Australia or overseas, depending on RapidID's and ComplyAdvantage's contracted hosting, support and subprocessor arrangements.

The countries in which overseas recipients are currently likely to be located include Singapore, Ireland, Luxembourg, the United Kingdom, Romania, Portugal and the United States. Email delivery, analytics, payment processing, technical support and service monitoring may also involve overseas processing. Provider locations can change as services and subprocessors change; we review and update this policy when a material change occurs.

Before disclosing personal information overseas, Veriqua takes reasonable steps appropriate to the circumstances. These may include provider due diligence, contractual privacy and confidentiality obligations, data minimisation, encryption, access controls, incident notification requirements, deletion or return obligations, and review of relevant subprocessor arrangements.

6. Disclosure to Service Providers and Other Recipients

We disclose personal information only where reasonably necessary for the purposes described in this policy, including to:

  • RapidID — identity and document verification provider and Veriqua's appointed Information Match Agent for DVS access. RapidID receives information needed to perform an authorised verification or screening transaction.
  • DVS participants — the Attorney-General's Department as Framework Administrator, approved gateway or intermediary providers, and the relevant official record holder. These parties receive only the information necessary to make and respond to an authorised DVS request.
  • ComplyAdvantage — financial crime risk screening provider used through RapidID for sanctions, PEP and adverse-media screening. ComplyAdvantage's publicly identified processing and support locations include Australia and overseas jurisdictions described in section 5.
  • Replit — application hosting and object storage services used for the Veriqua Platform.
  • Neon and Amazon Web Services — production database and supporting cloud infrastructure configured for the Sydney region.
  • Microsoft Azure OpenAI — AI inference for enabled AI-assisted features, configured for the Australia East region where described in section 7.
  • Stripe — payment processing. Stripe receives payment details directly and provides Veriqua with tokenised payment and subscription status information.
  • Resend — transactional and permitted marketing email delivery. Information disclosed is limited to email addressing and message content required for delivery.
  • Google Analytics — website usage analytics. Analytics does not receive compliance records, identity documents or DVS match data from the Platform.
  • Professional advisers, regulators and authorities — lawyers, auditors, insurers, courts, regulators, law enforcement bodies or government agencies where authorised or required by law, or reasonably necessary to establish, exercise or defend legal claims.

A business customer can access the information and compliance records held within its own account, subject to permissions. Veriqua does not provide an ID Service Client with the underlying DVS Information Match Result.

7. AI-Assisted Features and Self-Assessment Tools

AI-assisted features

The Platform may include AI-assisted functions such as drafting support, compliance assistance and risk analysis. These functions support human decision-making and do not provide legal, financial or compliance advice. Customers remain responsible for decisions and regulatory obligations.

Content submitted to an enabled AI feature may be processed by Microsoft Azure OpenAI in the Australia East region. Veriqua does not use customer content to train general-purpose AI models. Query content is retained only where it is deliberately saved in the Platform or where limited technical logging is reasonably necessary for security, reliability or legal compliance. Users should not submit more personal information than is necessary for the requested function.

Self-assessment tools

A free self-assessment tool, including the AUSTRAC Readiness Scorecard, provides general information based on the answers submitted. It is not an audit, legal opinion or determination that a business is compliant or that a particular legal obligation applies.

8. Retention, Deletion and De-identification

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, to provide contracted services, to comply with law, or to establish or defend legal claims. Retention depends on the information and the customer's legal and regulatory obligations.

  • Compliance and customer due diligence records — retained during the customer relationship and, where required by the AML/CTF Act, a customer instruction or another legal obligation, for seven years or the applicable statutory period.
  • DVS Information Match Data — once the verification purpose has been fulfilled, Veriqua takes reasonable steps to permanently remove or destroy personal information contained in DVS Information Match Data, or to ensure it is no longer personal information, unless retention is required by law or court or tribunal order.
  • DVS audit and compliance records — limited records necessary to demonstrate consent, authorised use, transaction activity and compliance may be retained for at least seven years where required by the IDSP Participation Agreement, without retaining more identity document information than is necessary.
  • Screening and case records — retained for the active service period and any additional period required for customer due diligence, audit, dispute or legal obligations. Provider-held data is subject to contractual deletion or return arrangements and applicable law.
  • Enquiry and self-assessment information — retained for up to 24 months after the last interaction, or deleted earlier on request unless a legal reason requires retention.
  • Backups — encrypted routine database backups are retained on a rolling schedule and are isolated from ordinary use. Information is removed as backups expire under that schedule.

When information is no longer required, we take reasonable steps to securely delete or de-identify it. A deletion request may be refused or limited where Veriqua or its customer must retain the information by law or under a binding regulatory or contractual obligation.

9. Security and Data Breaches

Veriqua takes reasonable technical and organisational steps to protect personal information, including:

  • encryption in transit and at rest where supported by the relevant system;
  • role-based access, least-privilege permissions and authentication controls;
  • secure password hashing and controls for repeated unsuccessful login attempts;
  • security, consent and transaction logging and monitoring;
  • controlled production access and periodic access review;
  • backup, recovery, vulnerability management and incident response procedures; and
  • privacy, confidentiality and security requirements for personnel and service providers.

If an eligible data breach occurs, Veriqua will assess the incident and notify affected individuals and the Office of the Australian Information Commissioner as required by the Notifiable Data Breaches scheme. DVS-related security or privacy incidents will also be reported through the applicable DVS and RapidID processes.

10. Access, Correction, Consent and Complaints

Subject to applicable law, an individual may:

  • request access to personal information Veriqua holds about them;
  • request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading;
  • ask Veriqua to delete or de-identify information that is no longer required, subject to lawful retention obligations;
  • withdraw consent for a future DVS or other consent-based check before that check is initiated; and
  • complain about Veriqua's handling of personal information or an alleged breach of the APPs.

Where Veriqua holds information on behalf of a business customer, we may refer or coordinate the request with that customer. We will verify identity before providing access or making a correction and will respond within a reasonable period. We aim to respond to privacy complaints within 30 days.

Anonymity and pseudonymity

Where lawful and practicable, an individual may deal with Veriqua anonymously or using a pseudonym, such as for a general enquiry. This is not practicable where identity is required to provide the service, comply with law or perform an authorised identity verification.

How to complain

Contact the Privacy Officer using section 13 and provide sufficient information for us to investigate. If the response is not satisfactory, a complaint may be made to the Office of the Australian Information Commissioner.

OAIC: www.oaic.gov.au | Phone 1300 363 992 | GPO Box 5288, Sydney NSW 2001

11. Cookies and Website Analytics

We use cookies that are necessary to operate and secure the Platform, including authenticated session cookies. Our public website may use Google Analytics to understand website traffic and use. Google Analytics may process identifiers and usage information in the United States and other locations under Google's arrangements.

We do not use advertising cookies within the Platform, do not sell analytics data and do not place tracking pixels in identity verification or customer due diligence records. Browser settings can be used to restrict non-essential cookies, although some website features may be affected.

12. Changes to This Policy

We review this policy when our services, providers, data flows or legal obligations change. The effective date at the top identifies the current version. We will provide reasonable notice of a material change that affects existing customers before it takes effect where practicable.

13. Contact

For privacy enquiries, access or correction requests, deletion requests or complaints, contact:

Veriqua Pty Ltd (ABN 92 697 961 023) | Privacy Officer

Perth, Western Australia

Phone: 0425 076 750

Email: [email protected]

Appendix A — Collection Notice for the AUSTRAC Readiness Scorecard

Notice to display beneath the capture fields:

We collect your name, organisation, work email address and scorecard answers to calculate and email your results and, where permitted, to contact you about Veriqua's AML/CTF services. Email delivery is handled by a provider in the United States. Website analytics may also be processed overseas. Providing this information is voluntary. You may opt out of marketing or ask us to delete your enquiry information at any time, subject to legal retention requirements. See Veriqua's Privacy Policy at https://veriqua.com.au/privacy.

This notice is intended to appear at the point of collection. It supplements, and does not replace, the Privacy Policy.

Appendix B — DVS Collection Notice and Consent Wording

Implementation requirement: Display this notice immediately before the individual actively consents and before any identity document information is transmitted for a DVS check. The consent checkbox must be unticked by default and the consent event must be recorded.

What information is collected

Veriqua and the relevant business customer collect the identity document details needed for the selected check. Depending on the document, this may include your name, date of birth, document type, document number or other government-related identifier, issuing authority, issue or expiry date and related document details.

How the DVS is used

The information is transmitted through Veriqua, RapidID as Veriqua's Information Match Agent, and other authorised gateway or intermediary systems to the Australian Government DVS and the relevant official record holder. The details are compared with the official record and a verification response is returned. The underlying DVS Information Match Result is not disclosed to Veriqua's ID Service Client. A client-facing identity opinion must be based on multiple identity checks.

Legal and contractual obligations

The DVS is authorised and regulated by the Identity Verification Services Act 2023 (Cth). Veriqua, RapidID and the relevant business customer must comply with applicable privacy laws, DVS access requirements, security controls, record-keeping requirements and restrictions on using government-related identifiers.

Your rights

You may request access to or correction of personal information held about you, withdraw consent before the check is initiated, and make a privacy complaint. Contact Veriqua's Privacy Officer using section 13 or contact the business requesting the check.

What happens if you decline

If you do not consent, the DVS check will not be performed. An alternative identity verification method may be available from the business requesting the check. Declining may delay or prevent completion of onboarding where identity verification is legally required or forms part of that business's risk controls.

Complaints and further information

For information about Veriqua complaints, see section 10. For information about the Australian Government's operation and management of the identity verification services, see the Identity Verification Services Privacy Statement.

Express consent

Unticked checkbox: I confirm that I am authorised to provide the personal details presented and I consent to my information being checked with the document issuer or official record holder via third-party systems for the purpose of confirming my identity.

Identity document information collected for a DVS request must not be used for advertising, marketing, market research, behavioural profiling or other unrelated purposes.