True Comply respects your privacy and is committed to protecting the personal information we collect and hold. This Privacy Policy explains how we collect, use, disclose, store and manage personal information when you interact with us, including through our website, landing pages, enquiry and lead forms, our compliance platform, customer relationship management systems, email, phone, social media, events and related services.
1. Purpose and scope
This policy applies to True Comply Holdings Pty Ltd (ACN [ACN]) trading as True Comply, and to all personal information we handle in the course of our business. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
2. Our two roles
True Comply handles personal information in two distinct capacities, and it is important to understand the difference.
- As a business, we collect information about our own website visitors, enquirers, clients and contacts. This policy governs that information in full.
- As a platform, we process information that our clients — regulated businesses meeting their own anti-money laundering and counter-terrorism financing obligations — collect about their customers. In that context our client is responsible for the collection and for the lawful basis of it, and we handle that information on their instructions under our agreement with them. If you are the customer of a business that uses True Comply, you should contact that business in the first instance about the information it holds about you.
3. The information we collect
We may collect personal information that is reasonably necessary for our business activities, including:
- your name
- email address
- phone number
- business or organisation name
- job title or role
- industry or sector
- information you provide in enquiry forms, lead forms, booking forms, surveys, downloads or consultations
- records of communications with you
- billing and transaction information where relevant
- website, device and usage information such as IP address, browser type, pages viewed, referring pages, and interaction data collected through cookies, pixels, tags and similar technologies.
Where you use our compliance platform, we may also handle:
- identity document information, including document type, number, issuing authority and expiry
- date of birth, residential address and nationality
- facial images and biometric information used for identity verification and liveness checking
- results of sanctions, politically exposed person and adverse media screening
- beneficial ownership and company structure information
- source of funds and source of wealth information
- records of due diligence decisions and their supporting evidence.
Some of this is sensitive information under the Privacy Act, including biometric information. We collect it only where it is reasonably necessary for the AML/CTF purpose it is provided for, and where consent has been obtained or the collection is otherwise required or authorised by law.
If you provide us with personal information about another person, you should ensure you are authorised to do so.
4. How we collect personal information
We may collect personal information:
- directly from you when you complete a form, download a resource, make an enquiry, subscribe to updates, engage our services, attend an event, or communicate with us
- directly from you when you complete an identity verification or due diligence process through our platform
- from our clients, where they are using our platform to meet their own regulatory obligations
- through third-party platforms and tools that support our marketing and operations, such as Meta lead forms, LinkedIn lead forms, scheduling tools, payment platforms, analytics tools, and email and SMS communication tools
- automatically through our website and digital assets using cookies, pixels, event tracking and similar technologies
- from identity verification, screening and data providers engaged to perform checks
- from publicly available sources, government registers and trusted third parties where lawful and appropriate for business development, compliance, due diligence or service delivery.
5. Why we collect, hold, use and disclose personal information
We may collect, hold, use and disclose personal information to:
- provide our services and respond to enquiries
- deliver identity verification, screening, monitoring and compliance functions through our platform
- send requested resources, guides, proposals or other materials
- manage client and prospective client relationships
- contact you about services, updates, events or offers that may be relevant to you
- administer bookings, meetings, billing and related business operations
- improve our website, marketing, content, platform and service delivery
- maintain internal records, audit trails and reporting
- comply with legal, regulatory, contractual and risk management obligations, including under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth)
- protect our lawful interests and the integrity of our business systems.
6. Cookies, analytics and advertising technologies
Our website and landing pages may use cookies, pixels and similar technologies to:
- understand website traffic and usage
- improve performance and user experience
- measure campaign effectiveness
- build remarketing or custom audiences
- support lead generation and conversion tracking.
These technologies may be provided by us or by third-party platforms such as Google, Meta, LinkedIn and HubSpot. You can manage cookies through your browser settings. Disabling cookies may affect the functionality of parts of our website.
7. Disclosure of personal information
We may disclose personal information to third parties where reasonably necessary for our operations, including:
- IT, CRM, hosting, automation and software providers
- identity verification, screening and data providers
- advertising and analytics platforms
- email, SMS and communications providers
- payment processors and financial service providers
- contractors, consultants and professional advisers
- event, booking and scheduling providers
- regulators, law enforcement agencies, courts, tribunals or government bodies where required or authorised by law, including AUSTRAC
- any person or entity to whom you have authorised us to disclose information.
We do not sell personal information.
8. Overseas disclosure
Some of the third-party service providers we use may store or process personal information outside Australia, including in the United States and other jurisdictions in which their infrastructure or support services operate. Where this occurs, we take reasonable steps to ensure personal information is handled in a manner consistent with applicable privacy obligations.
9. Storage and security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Measures may include access controls, encryption, secure platforms, user permissions, authentication controls, monitoring, contractual safeguards with service providers, and secure disposal practices where appropriate.
No method of transmission over the internet or electronic storage is completely secure. While we take reasonable steps to protect information, we cannot guarantee absolute security.
10. Retention
We retain personal information only for as long as it is needed for the purposes described in this policy, or for as long as we are required to retain it by law.
Where information has been collected in connection with obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), records must generally be retained for seven years. This means we may be unable to delete certain information on request during that period, even where you ask us to.
11. Data breaches
We maintain procedures for identifying, containing and assessing suspected data breaches. Where a breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required under the Notifiable Data Breaches scheme.
12. Access and correction
You may request access to the personal information we hold about you, or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
To make a request, contact us using the details below. We may need to verify your identity before processing the request. In some circumstances the law may permit or require us to refuse access or correction, in which case we will explain our position.
If your information was provided to us by a business using our platform, we may need to refer your request to that business.
13. Direct marketing
We may use your personal information to send you marketing communications about our services, insights, events, resources and related offers where permitted by law or where you have consented.
These communications may be sent by email, SMS, phone, social media audience tools or other electronic means.
You can opt out at any time by using the unsubscribe link, replying STOP where available, contacting us directly, or otherwise following the opt-out instructions in the message.
We do not use information collected through identity verification or due diligence processes for marketing purposes.
14. Anonymity and pseudonymity
Where lawful and practicable, you may choose not to identify yourself or may use a pseudonym when dealing with us. However, in many cases we will need your real identity or contact details to respond to your enquiry, provide services, or comply with legal obligations. Identity verification and due diligence functions cannot be performed anonymously.
15. Third-party links and platforms
Our website, emails, landing pages or communications may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties. You should review their privacy policies separately.
16. Complaints
If you have a complaint about how we have handled your personal information, please contact us in writing using the details below. We will review your complaint and respond within a reasonable period.
If you are not satisfied with our response, you may be able to lodge a complaint with the Office of the Australian Information Commissioner at oaic.gov.au.
17. Changes to this policy
We may update this Privacy Policy from time to time. The latest version will be published on our website with the effective date shown at the top.
18. Contact us
If you have any questions, requests or complaints regarding this Privacy Policy or your personal information, please contact:
True Comply Holdings Pty Ltd trading as True Comply
ACN [ACN]
Email: info@truecomply.co
Website: truecomply.co