Privacy Policy

Softserve 360 Pty Ltd trading as AML SoftServe

ABN 74 691 567 665 | ACN 691 567 665 Last updated: 5 July 2026

1. About This Policy

Softserve 360 Pty Ltd (ABN 74 691 567 665, ACN 691 567 665), trading as AML SoftServe (“we”, “us”, “our”), provides a regulatory technology platform that helps small reporting entities including real estate agencies, buyers agents, property developers and accounting practices meet their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and associated Rules.

This Policy explains how we collect, use, hold and disclose personal information in connection with our platform and services. It is written to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) set out in Schedule 1 of that Act.

2. Our Role, and the Role of Our Verification Partner

We act in two capacities:

  • On our own behalf — for example, when we collect contact details from a client signing up to our platform, or information about our own staff and contractors.
  • On behalf of our clients — our reporting-entity clients (e.g. a real estate agency or accounting practice) are themselves subject to the AML/CTF Act and collect personal information about their own customers (such as vendors, buyers, and beneficial owners) to meet their own legal obligations. Where our platform stores or processes that information on a client’s behalf, the client remains responsible for their own compliance and for their own privacy notices to their customers. This Policy does not replace or override those client-facing notices.

Identity verification. Where identity documents, biometric checks (such as facial matching or liveness checks) or screening against sanctions, PEP and adverse media lists are required, this is carried out by our verification partner, Personr, not by us directly. We collect and hold limited identifying details (such as name, date of birth and email address) on the platform; Personr independently collects, verifies and holds identity documents and biometric data under its own privacy policy and security certifications. We receive verification outcomes and risk indicators from Personr — we do not capture or store raw biometric data ourselves.

3. Information We Collect

3.1 Information We Collect Directly

  • Name, business name, email address and phone number of clients, prospective clients and their authorised users.
  • Account and billing details (excluding full payment card numbers, which are handled by our payment processor, Stripe and managed by their privacy policy (https://stripe.com/au/privacy).
  • Information you provide when contacting us for support, or when using our platform (e.g. compliance program inputs, risk assessment responses, case file notes entered by your compliance officer).
  • Technical information such as IP address, browser type and platform usage logs, for security and service-improvement purposes.
  • We may use cookies and similar technologies to improve the platform experience. Details are set out in our Cookie Notice [link].

3.2 Information Collected Via Personr

Where your customer due diligence process requires identity verification, the following categories are collected and verified by Personr on our behalf, and limited verification outcomes are returned to our platform:

  • Biometric data (e.g. facial scans, liveness checks) collected and processed solely by Personr.
  • Screening results against sanctions, politically exposed person (PEP) and adverse media lists.

We do not train AI or machine learning models on client data, customer data, or any personal information processed through the platform.

4. Why We Collect, Use and Disclose Personal Information

We collect, use and disclose personal information to:

  • Provide, operate and support our platform and related compliance services.
  • Enable our clients to meet their AML/CTF Act obligations, including customer due diligence, risk assessment, transaction monitoring and reporting to AUSTRAC.
  • Verify identity and screen for sanctions, PEP and adverse media matches (via Personr).
  • Manage our relationship with clients, including billing and support.
  • Meet our own legal and regulatory obligations.
  • Improve and secure our platform.

Where practicable, individuals may deal with us without identifying themselves (for example, general website enquiries). However, we cannot provide our platform services or conduct identity verification without collecting personal information.

We do not sell personal information, and we do not use personal information for direct marketing to individuals whose information is held on behalf of a client (e.g. a vendor or buyer in a property transaction).

We will take reasonable steps to notify individuals of the matters set out in this Policy at or before the time of collection, or as soon as practicable afterwards.

If we receive personal information that we did not solicit, we will assess whether we could have collected it under APP 3. If not, we will destroy or de-identify it as soon as practicable.

5. Disclosure of Personal Information

We may disclose personal information to:

  • Personr, for identity verification, biometric checks and screening.
  • Our cloud hosting and infrastructure providers, for the purpose of operating the platform.
  • AUSTRAC and other regulators or law enforcement bodies, where required or authorised by law (including under the AML/CTF Act).
  • Professional advisers (e.g. our lawyers or accountants), bound by confidentiality.
  • A client’s own independent evaluator, where the client has enabled platform access for the purpose of an independent evaluation of their AML/CTF program.

Tipping-off restriction. Section 123 of the AML/CTF Act prohibits disclosing information from which it could reasonably be inferred that a suspicious matter report has been or may be made, where that disclosure could prejudice an investigation. Accordingly, we cannot confirm or deny, including in response to an individual’s access or correction request, whether an SMR concerning them has been prepared or filed. This restriction applies regardless of any other right of access described in this Policy.

6. Overseas Disclosure

We do not currently disclose personal information to recipients located outside Australia, other than where our cloud infrastructure provider may store data on servers located overseas as part of standard hosting arrangements. If this changes, for example, if we engage an overseas-based service provider — we will update this Policy to name the relevant countries, to the extent it is practicable to do so.

Our platform is hosted on Google Cloud Platform in Australia. Data may transit through overseas GCP infrastructure for the purposes of content delivery and redundancy.

7. Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

  • Encryption of data in transit (TLS) and at rest, using the native encryption capabilities of our cloud infrastructure provider.
  • Role-based access controls, limiting access to personal information to staff and contractors who need it to perform their role.
  • Multi-factor authentication on administrative access to the platform.
  • Confidentiality obligations in our contracts with staff, contractors and service providers.
  • In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988.

We are working towards alignment with recognised information security frameworks, including ISO 27001, as our team and processes mature. We do not currently hold ISO 27001 or SOC 2 certification ourselves; our verification partner Personr maintains its own certifications for the services it provides.

8. Data Retention and Destruction

We retain personal information for as long as necessary to provide our services and to meet legal obligations, including:

  • Customer identification and due diligence records, and risk assessment results: a minimum of 7 years from the date the record was made, or from the end of the relevant business relationship, whichever is later (in line with AML/CTF Act record-keeping requirements).
  • Other personal information: for as long as reasonably necessary for the purpose it was collected, after which it is securely destroyed or de-identified, subject to any longer retention period required by law.
  • We take reasonable steps to ensure the personal information we collect and hold is accurate, up to date, and complete. Clients can update their account information through the platform at any time.

9. Access, Correction and Complaints

Individuals may request access to, or correction of, personal information we hold about them, subject to the exceptions permitted under the Privacy Act (including the tipping-off restriction described in section 5).

Where personal information about an individual is held on behalf of one of our clients (e.g. a buyer or vendor in a property transaction), we will generally direct that request to the relevant client, as they are best placed to respond.

If you have a concern or complaint about how we have handled your personal information, please contact us using the details in section 12. We will investigate and respond within 30 days. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

10. Children’s Information

Our platform is designed for use by businesses and their authorised personnel, not by children. We do not knowingly collect personal information directly from children.

11. Changes to This Policy

We may update this Policy from time to time as our services, team and processes evolve. The current version will always be available on our website, with the “last updated” date shown at the top of this document.

12. Contact Us

If you have a question, complaint, or request relating to this Policy or how we handle personal information, please contact us: