Trusted AML
Privacy Policy
Last updated: 12 July 2026
1. About this Privacy Policy
Trusted AML Tech Limited, referred to in this Privacy Policy as Trusted AML, we, us or our, provides identity verification, electronic know-your-customer services, AML/CFT compliance software, customer risk assessment, screening, monitoring, case-management and related professional services.
Our services may include:
-
electronic identity verification and document verification;
-
optical character recognition and extraction of information from identity documents;
-
selfie, liveness and facial comparison checks;
-
address verification;
-
politically exposed person, sanctions, watchlist and adverse-media screening;
-
fraud and identity-risk checks;
-
customer and beneficial-owner risk assessments;
-
customer due diligence and enhanced customer due diligence;
-
source-of-funds and source-of-wealth reviews;
-
ongoing monitoring and alerts;
-
transaction-monitoring support;
-
AML/CFT case management, audit trails and regulatory-reporting support;
-
AML/CFT consulting, independent audits, training and outsourced compliance support; and
-
customer relationship management and document-storage functions.
Together, these are referred to as the Services.
This Privacy Policy explains how we collect, hold, use, disclose, protect and otherwise process personal information through our website, software platform, mobile interfaces, application programming interfaces, professional services and communications.
Trusted AML Tech Limited is located at:
Level 1, 110 Carlton Gore Road
Newmarket, Auckland 1023
New Zealand
Email: contact@trustedaml.co.nz
2. Definitions and who this Privacy Policy applies to
In this Privacy Policy:
Applicant means an individual who completes, or is asked to complete, an identity-verification, KYC, CDD, screening, monitoring or AML/CFT process using the Services.
Customer means a business, organisation, reporting entity or professional-services provider that purchases, accesses or uses the Services.
Other Data Subject means an individual whose Personal Information we process who is not an Applicant, including a Customer representative, Platform User, prospective Customer, website visitor, training attendee or professional-services contact.
Personal Information means information about an identifiable individual. Where the UK GDPR or EU GDPR applies, Personal Information also includes personal data as defined under the applicable legislation.
Platform User means an employee, officer, contractor, adviser or other authorised person who accesses the Trusted AML portal on behalf of a Customer.
Biometric Information includes photographs, video recordings, facial images, facial features, biometric templates, measurements and other information used by an automated biometric system to verify, identify or categorise a person.
This Privacy Policy applies to Personal Information relating to:
-
Applicants;
-
customers, beneficial owners, trustees, directors, shareholders, partners and authorised persons;
-
people connected with companies, trusts, partnerships, charities and other organisations;
-
Customers and Platform Users;
-
directors, officers, employees, contractors and representatives of Customers;
-
website visitors;
-
prospective Customers and business contacts;
-
people who contact us or attend our training;
-
people who receive our consulting, audit or professional services; and
-
other individuals whose information is submitted to or generated through the Services.
3. Our role and applicable privacy laws
In many cases, a Customer uses Trusted AML to process Personal Information about an Applicant for the Customer’s own identity-verification, fraud-prevention, risk-management, regulatory or AML/CFT purposes.
In these circumstances:
-
the Customer determines why the Personal Information is collected and how the verification or screening results will be used;
-
the Customer generally acts as the organisation responsible for the collection and use of the Personal Information;
-
Trusted AML generally processes the information on behalf of the Customer and in accordance with the Customer’s instructions;
-
the Customer is responsible for ensuring that it has a lawful purpose and authority to collect and use the Personal Information;
-
the Customer must provide any collection notice, consent request or other notification required by applicable law; and
-
requests relating to an Applicant’s Personal Information may need to be referred to the relevant Customer.
Where the UK GDPR or EU GDPR applies, the Customer will generally be the data controller and Trusted AML will generally act as the data processor for Applicant information.
Trusted AML separately acts as the organisation responsible for Personal Information we collect and use for our own purposes, including:
-
Customer-account administration;
-
service security;
-
billing and payment management;
-
sales and relationship management;
-
consulting, audit and training services;
-
legal and regulatory compliance;
-
service development and improvement; and
-
our own business operations.
We handle Personal Information in accordance with the New Zealand Privacy Act 2020, including the Information Privacy Principles, and any applicable privacy codes of practice.
Where we conduct biometric processing, we also comply with the Biometric Processing Privacy Code 2025 to the extent that the Code applies.
Where applicable, our handling of Personal Information may also be subject to:
-
the Australian Privacy Act 1988 and Australian Privacy Principles;
-
the Australian Identity Verification Services Act 2023;
-
the UK General Data Protection Regulation;
-
the UK Data Protection Act 2018;
-
the European Union General Data Protection Regulation; and
-
other applicable privacy and data-protection laws.
Customers may use the Services to assist with their obligations under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, associated regulations, codes of practice and regulatory guidance.
Nothing in this Privacy Policy limits the independent privacy, AML/CFT, consumer-protection or regulatory responsibilities of a Customer.
4. Overseas transfers of Personal Information
Trusted AML provides Services to Customers and Applicants in different countries. The location in which Personal Information is hosted and processed depends on the region in which the Customer or Applicant is based.
4.1 Australia and New Zealand
If you are based in Australia or New Zealand, we store and process your Personal Information using the Amazon Web Services data centre in Sydney, New South Wales, Australia.
Our service providers may also process your Personal Information in Australia or New Zealand.
Trusted AML uses MemberCheck in Australia to provide some or all of the following services:
-
electronic identity verification;
-
identity-document verification;
-
optical character recognition;
-
facial comparison;
-
biometric verification;
-
liveness detection;
-
fraud and identity-risk checks; and
-
access to the Australian Document Verification Service as our DVS gateway provider.
Information required for these checks may be transmitted to and processed by MemberCheck in Australia.
Where an Australian identity document is checked through the Document Verification Service, relevant identity information may also be transmitted through MemberCheck to the Australian Document Verification Service and the relevant Australian government document issuer.
4.2 United Kingdom and Europe
If you are based in the United Kingdom or Europe, we store and process your Personal Information using the Amazon Web Services data centre in Dublin, Ireland.
If there is a technical, security or operational issue with the Services, Personal Information stored in Ireland may be accessed by authorised Trusted AML engineers based in New Zealand where access is reasonably required to investigate and resolve that issue.
Where required, international transfers from the European Economic Area are protected using the European Commission’s Standard Contractual Clauses or another lawful transfer mechanism.
Where required, international transfers from the United Kingdom are protected using the UK International Data Transfer Addendum to the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Agreement or another lawful transfer mechanism.
If a UK or European Customer enables biometric or identity-verification services provided by MemberCheck, the information necessary to perform those services may also be transferred to and processed in Australia. Appropriate contractual and legal transfer safeguards will be applied where required.
4.3 New Zealand overseas-disclosure requirements
Where we disclose Personal Information outside New Zealand, we will take reasonable steps to comply with Information Privacy Principle 12 of the Privacy Act 2020.
Depending on the circumstances, these steps may include:
-
confirming that the recipient is subject to privacy protections comparable to those applying in New Zealand;
-
ensuring that the recipient processes the information only on our behalf;
-
entering into contractual privacy, confidentiality and security obligations;
-
limiting the information transferred to what is reasonably necessary;
-
implementing appropriate technical and organisational safeguards; or
-
obtaining informed authorisation from the individual where required.
Overseas recipients may be subject to the laws and lawful-access requirements of the countries in which they operate.
5. Personal Information we collect
The Personal Information we collect depends on the Services selected by the Customer and the type of verification, screening, review or professional service being performed.
5.1 Identity and contact information
We may collect:
-
full legal name;
-
former, previous or alternative names;
-
date and place of birth;
-
gender or sex where recorded on an identity document;
-
nationality and citizenship;
-
immigration or residency status;
-
residential, mailing and business addresses;
-
email address;
-
telephone number;
-
occupation and employer;
-
business and professional information; and
-
relationships with companies, trusts, partnerships, charities or other organisations.
5.2 Identity-document information
We may collect copies, photographs, scans or details from:
-
passports;
-
driver licences;
-
national or government-issued identity cards;
-
birth certificates;
-
marriage or name-change certificates;
-
visas and immigration documents;
-
proof-of-age cards;
-
address-verification documents;
-
utility statements;
-
bank statements;
-
company, partnership or trust records; and
-
other documents submitted to establish identity, address, authority, ownership or eligibility.
Information extracted from these documents may include:
-
document numbers;
-
issuing authorities;
-
issue and expiry dates;
-
identity-document photographs;
-
signatures;
-
machine-readable information; and
-
document-authenticity or verification results.
We will endeavour not to collect information appearing on a document that is unnecessary for the relevant verification or compliance purpose.
5.3 Biometric Information
Where facial comparison, liveness verification or another biometric function is used, we may collect or generate:
-
photographs and video recordings;
-
images of a person’s face;
-
facial measurements and features;
-
biometric templates or representations;
-
selfie-to-document comparison results;
-
liveness and spoof-detection results;
-
presentation-attack indicators;
-
quality and confidence scores; and
-
pass, fail, inconclusive or referral results.
5.4 AML/CFT, screening and risk information
Depending on the Services selected, we may collect or generate:
-
customer and beneficial-owner information;
-
director, trustee, shareholder, partner and controlling-person information;
-
politically exposed person screening results;
-
sanctions and watchlist screening results;
-
adverse-media information;
-
publicly available information;
-
fraud and identity-risk indicators;
-
customer risk ratings and risk factors;
-
information about the nature and purpose of a business relationship;
-
source-of-funds and source-of-wealth information;
-
financial, employment, business, investment and property information;
-
transaction information supplied by a Customer;
-
monitoring alerts;
-
compliance notes and review records;
-
approval, escalation and decision records;
-
regulatory-reporting information; and
-
audit trails and system activity records.
A potential name match does not necessarily mean that an individual is the person appearing on a sanctions, politically exposed person, watchlist or adverse-media record.
5.5 Customer, account and business information
For Customers and Platform Users, we may collect:
-
name, role and organisation;
-
business and professional contact details;
-
username and authentication details;
-
account permissions and access levels;
-
subscription and service information;
-
invoices and payment records;
-
account activity;
-
communications with our sales, support and professional-services teams;
-
training registrations and attendance information;
-
enquiries and complaints;
-
feedback and survey responses; and
-
information relating to consulting, audit or training engagements.
Payment-card information may be collected directly by a payment-service provider rather than stored by Trusted AML.
5.6 Technical and usage information
When a person accesses our website, portal or verification process, we may collect:
-
internet protocol address;
-
browser and device type;
-
operating system;
-
device identifiers;
-
approximate location derived from technical information;
-
login and authentication information;
-
referring and visited pages;
-
date and time of access;
-
session and activity logs;
-
error and diagnostic records;
-
security information; and
-
cookie and similar-technology information.
Precise device location will only be collected where it is reasonably required for a Service and the person has been appropriately informed.
6. How we collect Personal Information
We may collect Personal Information:
-
directly from an Applicant through an onboarding or verification process;
-
directly from a Customer or Platform User;
-
from the Customer that requested the check;
-
from an authorised representative, adviser, employer or associated person;
-
from MemberCheck;
-
from government and identity-document verification services;
-
from document issuers;
-
from public and company registers;
-
from sanctions, watchlist and politically exposed person databases;
-
from adverse-media and screening providers;
-
from address and electronic-verification providers;
-
from fraud-prevention and cybersecurity providers;
-
from publicly available websites, publications and records;
-
through our website, portal and APIs;
-
through cookies, analytics and security logs; and
-
through our consulting, audit, training or outsourced-compliance services.
Where we collect Personal Information from someone other than the person concerned, we will take reasonable steps to ensure that the individual is notified of the collection as required by Information Privacy Principle 3A, unless an applicable exception applies.
The relevant Customer may provide this notification on our behalf through its onboarding process, privacy notice or collection notice.
7. Why we collect and use Personal Information
We may collect, use and process Personal Information to:
-
establish and verify identity;
-
verify identity-document validity and authenticity;
-
extract information from identity documents;
-
compare a person’s face with an identity-document photograph;
-
perform liveness and spoof-detection checks;
-
verify address and contact information;
-
conduct KYC, CDD and enhanced CDD;
-
identify customers, beneficial owners, trustees, directors and authorised persons;
-
conduct sanctions, politically exposed person, watchlist and adverse-media screening;
-
identify and investigate possible fraud;
-
generate and support customer risk assessments;
-
review source-of-funds and source-of-wealth information;
-
provide ongoing screening and monitoring;
-
create alerts, cases, reviews and audit trails;
-
support Customers with AML/CFT and other regulatory obligations;
-
provide consulting, auditing, training and outsourced-compliance services;
-
administer Customer accounts and subscriptions;
-
process billing and payments;
-
provide customer and technical support;
-
communicate about the Services;
-
protect our systems, Customers, Applicants and Services;
-
investigate errors, complaints and suspected unlawful activity;
-
maintain system security and integrity;
-
establish, exercise or defend legal rights;
-
comply with court orders and legal or regulatory obligations;
-
improve our Services, using aggregated or de-identified information where reasonably practicable; and
-
send service updates or marketing communications in accordance with applicable law.
We do not sell Personal Information.
We will not use Biometric Information for advertising, emotion analysis or unrelated behavioural profiling.
8. Legal bases for UK and European processing
Where the UK GDPR or EU GDPR applies, we process Personal Information on one or more of the following legal bases:
-
the processing is necessary to perform a contract or take steps at an individual’s request before entering into a contract;
-
the processing is necessary for compliance with a legal obligation;
-
the processing is necessary for the legitimate interests of Trusted AML or a Customer, provided those interests are not overridden by the individual’s rights and interests;
-
the individual has provided consent;
-
the processing is necessary to establish, exercise or defend legal claims; or
-
another lawful basis permitted by applicable data-protection legislation applies.
Where special-category or sensitive information is processed, an additional lawful condition will be relied upon where required.
The relevant Customer is responsible for determining and documenting its lawful basis for collecting and using Applicant information.
9. Biometric processing
Where a Customer enables facial comparison, liveness detection or another biometric function, Trusted AML uses MemberCheck in Australia to provide some or all of the biometric-verification services.
Before Biometric Information is collected, the Applicant will be informed of:
-
the fact that Biometric Information is being collected and processed;
-
the particular purpose for which the information will be used;
-
the involvement of Trusted AML and MemberCheck;
-
the countries in which the information may be processed;
-
the likely consequences if the information is not provided;
-
whether an alternative verification method is available; and
-
where further information about the processing can be obtained.
The biometric notice will be presented clearly and separately from general terms and conditions where required.
Biometric processing will only be used where it:
-
has a lawful and specific purpose;
-
is reasonably necessary and effective for that purpose;
-
is proportionate to the likely effects on individuals; and
-
is subject to appropriate privacy safeguards.
Safeguards may include:
-
encryption;
-
access restrictions;
-
secure transmission;
-
audit logging;
-
quality and accuracy testing;
-
fraud controls;
-
human oversight;
-
limited retention; and
-
deletion or de-identification when the information is no longer required.
An Applicant who cannot or does not wish to complete a biometric check should contact the Customer that requested the verification. Whether an alternative process is available will depend on the Customer’s requirements and applicable law.
Biometric systems may produce incorrect, inconclusive or false-match results. Customers should not use a biometric result as the sole basis for a significant adverse decision without appropriate review and human oversight.
We take particular care where Biometric Information relates to a child or young person. A Customer seeking to use biometric verification for a person under 18 must ensure that the processing is lawful, necessary and proportionate and that appropriate notice, authority, consent and safeguards are in place.
10. MemberCheck and the Australian Document Verification Service
Trusted AML uses MemberCheck in Australia as its biometric and identity-verification provider and as its gateway provider for access to the Australian Document Verification Service.
Where an Applicant provides an Australian-issued identity document, relevant identity information may be transmitted:
-
from the Applicant or Customer to Trusted AML;
-
from Trusted AML to MemberCheck;
-
from MemberCheck to the Australian Document Verification Service; and
-
to the Australian government authority or document issuer responsible for the relevant identity document.
The information may include:
-
name;
-
date of birth;
-
document number;
-
issuing authority;
-
issue or expiry information; and
-
other information reasonably required to perform the match.
The Document Verification Service checks whether the submitted identity-document information corresponds with information held by the relevant Australian document issuer.
A DVS verification result is separate from any facial-comparison or liveness process performed through MemberCheck.
Before a DVS check is conducted, the Applicant will be asked to provide express consent to:
-
collection of the identity information;
-
disclosure of the information to MemberCheck;
-
disclosure through the Australian Document Verification Service;
-
matching against the relevant government record; and
-
collection and disclosure of the verification response.
If the Applicant does not provide consent, the DVS check will not be conducted. The Applicant should contact the Customer to determine whether another verification method is available.
Trusted AML and the Customer may retain the verification result, transaction reference and associated audit information where required for compliance, security, fraud-prevention, dispute-resolution and record-keeping purposes.
11. Screening and automated results
The Services may automatically compare Personal Information against databases and generate:
-
identity-verification results;
-
possible sanctions matches;
-
possible politically exposed person matches;
-
watchlist and adverse-media results;
-
document-risk indicators;
-
fraud or impersonation indicators;
-
customer-risk ratings;
-
alerts; and
-
recommendations for additional review.
These outputs assist Customers with their compliance and risk-management processes. They are not legal advice and do not necessarily represent a final conclusion about an individual.
A possible match may be caused by:
-
a similar name;
-
incomplete data;
-
outdated source information;
-
differences in spelling or transliteration; or
-
another person having similar identifying information.
The Customer is responsible for:
-
reviewing the result;
-
investigating potential false matches;
-
obtaining additional information where appropriate;
-
applying its own risk assessment;
-
meeting its legal and regulatory obligations; and
-
making the final onboarding, compliance or service decision.
Trusted AML does not make a Customer’s final decision about whether to accept, reject, suspend or terminate a relationship with an Applicant.
12. Disclosure of Personal Information
We may disclose Personal Information to:
-
the Customer that requested or manages the verification, screening or compliance process;
-
authorised Platform Users;
-
MemberCheck in Australia;
-
the Australian Document Verification Service and participating document issuers;
-
identity-document, address and electronic-verification providers;
-
sanctions, politically exposed person, watchlist and adverse-media screening providers;
-
fraud-prevention and cybersecurity providers;
-
Amazon Web Services and other hosting, storage and backup providers;
-
software, email, communications and customer-support providers;
-
payment-processing and billing providers;
-
professional advisers, auditors and insurers;
-
regulators, supervisors, courts, tribunals, law-enforcement agencies and government authorities where required or permitted by law;
-
an investor, purchaser or adviser involved in a proposed merger, acquisition, financing or sale of our business, subject to appropriate confidentiality requirements; and
-
another person authorised by the individual, Customer or applicable law.
Our service providers may only process Personal Information for agreed service purposes and must apply appropriate privacy, confidentiality and security safeguards.
Information relating to an actual or proposed suspicious activity report, prescribed transaction report or another legally protected AML/CFT matter will only be accessed or disclosed as permitted by law.
13. Storage and security
We take reasonable technical, organisational and physical measures to protect Personal Information against:
-
loss;
-
misuse;
-
interference;
-
unauthorised access;
-
unauthorised disclosure;
-
alteration; and
-
destruction.
Depending on the nature and sensitivity of the information, safeguards may include:
-
encryption during transmission and storage;
-
secure connections between Trusted AML and MemberCheck;
-
role-based access controls;
-
multi-factor authentication;
-
password and session-management controls;
-
activity and audit logging;
-
secure software-development procedures;
-
vulnerability management;
-
security monitoring;
-
backup and recovery arrangements;
-
staff confidentiality obligations;
-
access reviews;
-
privacy and security training; and
-
incident-response procedures.
Access to Personal Information is limited to authorised people who reasonably require access to perform their duties.
Customers and Platform Users are responsible for:
-
protecting their account credentials;
-
appropriately managing user permissions;
-
removing access when a user no longer requires it;
-
maintaining the security of their own devices and systems; and
-
promptly notifying us of suspected unauthorised access.
No internet-based or cloud-hosted service can be guaranteed to be completely secure. However, we regularly review our safeguards, having regard to the nature and sensitivity of the Personal Information we process.
14. Retention and deletion
The period for which Personal Information is retained depends on:
-
whether the person is an Applicant or another type of data subject;
-
the Services requested by the Customer;
-
the Customer’s instructions;
-
the purpose for which the information was collected;
-
applicable contracts; and
-
legal and regulatory requirements.
14.1 Applicants
If you are an Applicant, we will securely store your Personal Information in the Trusted AML portal on behalf of the Customer that requested your identity verification, CDD, screening or monitoring.
Different Customers have different retention requirements.
Some Customers require us to store Applicant Personal Information for fewer than seven days.
Other Customers ask us to store Applicant Personal Information for longer so that we can provide ongoing:
-
AML/CFT compliance services;
-
fraud-prevention services;
-
sanctions screening;
-
politically exposed person screening;
-
adverse-media screening;
-
customer-risk assessment;
-
identity-verification support; and
-
ongoing monitoring.
The relevant Customer determines how long Applicant Personal Information is required to be stored, subject to:
-
applicable law;
-
the Customer’s regulatory and record-keeping obligations;
-
the Customer’s relationship with the Applicant; and
-
the agreement between Trusted AML and the Customer.
Some Customers may be legally required to retain identity-verification, customer-due-diligence and related AML/CFT records for a prescribed period after a transaction or business relationship ends.
A Customer can delete Personal Information from the Trusted AML portal once it determines that the information is no longer required.
Following deletion by the Customer:
-
some information may remain temporarily in secure system backups until it is overwritten or deleted through our normal backup cycle;
-
we may retain limited audit, security or transaction records where required by law, contract or legitimate security purposes; and
-
we may retain non-identifiable, aggregated or de-identified information.
Non-identifiable information may include:
-
verification transaction references;
-
system-performance information;
-
statistical information;
-
audit information that no longer identifies the Applicant; and
-
information used to maintain security or improve the Services.
Non-identifiable information may remain archived until the Customer that requested the verification instructs us to destroy or return the relevant archived data, unless we are entitled or required to retain it for another lawful purpose.
Where archived information remains identifiable, it will continue to be protected under this Privacy Policy and will be securely deleted, destroyed, returned or otherwise handled in accordance with:
-
the Customer’s instructions;
-
our contractual obligations;
-
our backup and data-destruction procedures; and
-
applicable law.
Applicants and Other Data Subjects may ask the relevant Customer to access, correct, update or delete their Personal Information in accordance with their legal rights.
A request may also be submitted directly to Trusted AML. Where we process the information solely on behalf of a Customer, we may refer the request to that Customer or work with the Customer to respond.
Customers that use the Services are independently responsible for complying with applicable privacy and data-protection laws in relation to their collection, storage, use, disclosure and retention of Personal Information.
A deletion request may not result in immediate or complete deletion where the Customer or Trusted AML is required or permitted to retain information for:
-
AML/CFT compliance;
-
fraud prevention;
-
security;
-
accounting or tax obligations;
-
legal claims;
-
dispute resolution;
-
regulatory requirements; or
-
evidential purposes.
14.2 Other Data Subjects who are not Applicants
If you are not an Applicant, we retain your Personal Information only for as long as reasonably necessary to fulfil the purposes for which it was collected.
The applicable retention period will depend on the nature of our relationship with you.
Customer representatives and Platform Users
If you are a director, employee, contractor, officer, representative or authorised user of a Customer, we will generally retain your Personal Information for the duration of the Customer’s contract with Trusted AML.
We may retain relevant information after the contract ends until the expiry of the applicable claims or legal limitation period, or for a longer period where required by law, regulation, insurance, audit or dispute-resolution requirements.
Prospective Customers and business contacts
If you are a prospective Customer or another business contact, we will generally retain your Personal Information until:
-
it is no longer reasonably required for sales, follow-up or relationship-management purposes;
-
you ask us to stop contacting you; or
-
continued retention is no longer lawful or necessary.
We may retain limited information to record and respect an unsubscribe or no-contact request.
Training, consulting, audit and professional-service clients
We may retain Personal Information for the duration of the engagement and for any additional period required to satisfy:
-
professional obligations;
-
contractual obligations;
-
insurance requirements;
-
tax and accounting requirements;
-
evidential requirements; and
-
applicable law.
Website visitors and enquiry contacts
We retain enquiry, cookie, analytics, security and technical information only for as long as reasonably necessary for the relevant communication, operational, analytics or security purpose.
Other individuals
In all other cases, we retain Personal Information only for as long as reasonably necessary for the purpose for which it was collected, subject to any retention period required by applicable law.
When Personal Information is no longer required, we will securely delete, destroy or de-identify it unless continued retention is required or permitted by law.
15. Access, correction and other privacy rights
Under the New Zealand Privacy Act 2020, an individual may request:
-
confirmation of whether we hold Personal Information about them;
-
access to Personal Information we hold about them; and
-
correction of Personal Information they believe is inaccurate, incomplete or misleading.
Applicants should generally contact the Customer that requested the verification first, particularly where the request concerns:
-
the Customer’s compliance records;
-
the Customer’s risk assessment;
-
information entered by the Customer;
-
the purpose for which the verification was requested; or
-
a decision made by the Customer.
Requests may also be sent to contact@trustedaml.co.nz.
We may ask the requester to provide information to confirm their identity before we release or change Personal Information.
Where we do not agree to make a requested correction, the individual may ask us to attach a statement of correction to the information.
Access may be refused or limited where permitted or required by law, including where disclosure would:
-
unreasonably affect another person’s privacy;
-
prejudice security or fraud-prevention measures;
-
disclose legally privileged information;
-
breach a legal restriction;
-
prejudice law enforcement; or
-
reveal protected suspicious-activity-reporting information.
New Zealand privacy law does not provide an unrestricted right to deletion. We will consider deletion requests, but information may need to be retained for legal, regulatory, contractual, AML/CFT, security or evidential purposes.
Where the UK GDPR or EU GDPR applies, an individual may also have rights to:
-
erasure;
-
restriction of processing;
-
data portability;
-
objection to certain processing;
-
withdrawal of consent; and
-
complaint to the relevant data-protection authority.
These rights are subject to legal conditions and exceptions.
16. Withdrawal of consent
Where processing is based on consent, an individual may withdraw that consent for future processing by contacting:
-
the Customer that requested the verification; or
-
Trusted AML.
Withdrawal of consent will not invalidate processing lawfully completed before the consent was withdrawn.
Withdrawal may mean that we or the Customer cannot:
-
complete an identity-verification process;
-
provide the requested Service;
-
establish or continue a business relationship; or
-
satisfy applicable legal or regulatory requirements.
Certain information may still need to be retained or processed where required or permitted by law.
17. Accuracy of Personal Information
We take reasonable steps to ensure that Personal Information is accurate, complete, relevant and not misleading before it is used or disclosed.
However, some information is supplied by:
-
Applicants;
-
Customers;
-
document issuers;
-
public registers;
-
screening providers;
-
government sources; or
-
other third parties.
An individual who believes information is inaccurate should contact the relevant Customer or Trusted AML as soon as reasonably practicable.
Customers are responsible for reviewing screening and verification results and must not assume that every potential match or alert is accurate.
18. Privacy and security breaches
A privacy or security breach may include:
-
accidental disclosure;
-
unauthorised access;
-
loss of Personal Information;
-
unauthorised alteration;
-
cyberattack;
-
theft of credentials; or
-
destruction of information.
We maintain procedures to:
-
identify suspected incidents;
-
contain the incident;
-
investigate what occurred;
-
assess the likely impact;
-
reduce the risk of further harm;
-
notify affected Customers; and
-
meet applicable legal notification requirements.
Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the New Zealand Office of the Privacy Commissioner and affected individuals as soon as practicable, unless an exception applies.
Where the affected information is processed on behalf of a Customer, we will work with that Customer to investigate and respond to the incident.
Where Australian, UK or European breach-notification laws apply, we will also take reasonable steps to comply with those requirements.
19. Cookies, analytics and similar technologies
Our website and online Services may use:
-
cookies;
-
pixels;
-
local storage;
-
analytics tools; and
-
similar technologies.
These technologies may be used to:
-
provide essential website and login functions;
-
maintain sessions;
-
remember preferences;
-
protect account security;
-
prevent fraud;
-
understand website and platform usage;
-
diagnose errors;
-
improve performance;
-
measure communications; and
-
support marketing where permitted.
Visitors may be able to manage non-essential cookies through our cookie controls or browser settings.
Disabling cookies may affect the functionality of the website or portal.
Third-party services embedded in our website may also use cookies in accordance with their own privacy policies.
20. Electronic communications and marketing
We may use Customer and business contact information to send:
-
operational notices;
-
security notifications;
-
account and billing communications;
-
information about changes to the Services;
-
training and event information;
-
AML/CFT updates;
-
newsletters; and
-
information about related Services.
Marketing communications will include an unsubscribe option where required.
Unsubscribing from marketing will not prevent us from sending essential:
-
security notices;
-
account notices;
-
billing communications;
-
legal notices; or
-
service-related communications.
21. Third-party websites and services
Our website or Services may contain links to third-party websites, databases, applications or services.
Trusted AML is not responsible for the independent privacy practices of a third party.
Individuals should review the third party’s privacy policy before providing Personal Information directly to that third party.
22. Children and young people
The Services are generally intended for adults and organisations conducting lawful identity-verification and compliance processes.
Where Personal Information relating to a child or young person is collected, the Customer must ensure that:
-
there is a lawful and necessary purpose;
-
the collection is fair and proportionate;
-
the notice is understandable and appropriate for the child’s age;
-
parental, guardian or other authority is obtained where required;
-
no more information than necessary is collected; and
-
appropriate security and privacy safeguards are applied.
Biometric Information relating to children or young people will be processed only where the Customer has established that the processing is lawful, necessary and proportionate.
23. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to:
-
our Services;
-
our information-handling practices;
-
hosting arrangements;
-
service providers;
-
technology;
-
security requirements;
-
applicable legislation; or
-
regulatory guidance.
The updated version will be published with a revised “last updated” date.
Where a change is material, we may also notify Customers through the portal, by email or through another appropriate method.
24. Privacy Officer, enquiries and complaints
Questions, access or correction requests, and privacy complaints may be sent to:
Privacy Officer
Trusted AML Tech Limited
Level 1, 110 Carlton Gore Road
Newmarket, Auckland 1023
New Zealand
Email: contact@trustedaml.co.nz
Please provide sufficient information for us to understand and investigate the matter.
We may need to:
-
confirm your identity;
-
ask for further information;
-
consult the relevant Customer; or
-
refer your request to the Customer where we process the information solely on its behalf.
-
We will investigate privacy complaints fairly and within a reasonable period.
If you are not satisfied with our response, you may have the right to complain to:
-
the New Zealand Office of the Privacy Commissioner;
-
the Office of the Australian Information Commissioner;
-
the UK Information Commissioner’s Office; or
-
the relevant European data-protection authority,
depending on where you are located and which privacy laws apply.
