FreeAML

Privacy Policy

This Privacy Policy explains how the operator of FreeAML handles personal information in connection with the software platform at freeaml.com.au. Identity documents, selfies, and biometric identifiers used for verification are collected and processed by Personr, not used by FreeAML as a marketing or analytics asset.

Current as at 24 September 2026 (Melbourne, Australia)

Also see our Terms and Conditions.

1. Who we are

This Privacy Policy (the “Policy”) is issued by Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML (the “Operator”, “we”, “us”, or “our”), the platform operator behind FreeAML (freeaml.com.au) (the “Platform”). The Operator is Vaz Capital Pvt Ltd, acting as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML. Privacy enquiries may be sent to team@freeaml.com.au.

The Platform is AUSTRAC Tranche 2–oriented AML/KYC software for Australian businesses. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (“APPs”) to the extent those laws apply to us. This Policy should be read with our Terms and Conditions.

2. Scope of this Policy

This Policy describes personal information that the Operator collects and holds as operator of the Platform, including information about Users (business customers and their personnel), paying Clients, and website visitors.

It does not govern Personr’s independent collection of identity documents, biometric templates, liveness video, or government-verification payloads, except to the extent Personr returns status, outcomes, and related metadata to the Platform so that we can run the product. Personr’s handling is subject to Personr’s own terms and privacy documentation, which you and your Clients should review before completing a verification.

Third-party websites linked from the Platform (including AUSTRAC, Stripe-hosted checkout, and Personr-hosted flows) are not controlled by us.

3. Identity documents and biometrics — Personr, not FreeAML secondary use

The Operator confirms that it does not use identity-document images or biometric identity data for its own secondary purposes (including marketing, advertising profiling, or unrelated product analytics). Responsibility for identity-verification data of that kind resides with Personr, the identity-verification provider, under Personr’s terms and privacy notices.

When a verification is initiated, the individual typically interacts with Personr’s capture experience (which may include government identity documents, a selfie, and liveness or biometric matching). The Operator does not use those artefacts as a FreeAML marketing or analytics asset.

The Operator may receive, store, and display verification status, outcomes, reference identifiers (such as applicant or session IDs), and related result metadata reasonably required to operate the product (for example, to mark an order complete, generate a customer due diligence report for the User, record watchlist-screening outcome flags, or support a User’s dashboard). Where Personr’s APIs return extracted identity fields (such as name, date of birth, address, or document-type indicators) as part of a status payload, the Operator may persist those fields solely to provide the User-facing report and operational record — not to train unrelated models for advertising, and not to build a biometric matching database of our own.

4. Personal information FreeAML itself may collect

Depending on how the Platform is used, the Operator may collect and hold information such as:

  • Account and contact details — name, email address, telephone number, organisation name, role or profession, and similar details you or your organisation provide (including via cookies or a stored visitor profile used to pre-fill forms);
  • Order and workflow metadata — verification type, reference notes, short codes, timestamps, questionnaire answers you submit, entity name and registration numbers you supply, beneficial-owner contact details you enter so that a check can be sent, and parent/child order relationships for ownership chains;
  • Payment status and commercial fields — whether a session is pending, paid, failed, or refunded; amounts; client-pays flags; mark-up amounts; Stripe session or payment-intent identifiers; Connect account identifiers; and payout or earnings status. We do not collect full card PAN/CVC on our forms;
  • Verification outcomes we receive from Personr — applicant IDs, verification links, status values, review outcomes, screening result summaries, and related reference data as described in section 3;
  • Operational and security logs — approximate technical logs such as timestamps, error events, and limited request metadata used to operate, debug, and secure the Platform; and
  • Communications content — messages you send to us, and records of transactional emails or SMS we send (for example, one-time codes or verification links).

We do not invent additional categories in this Policy. If we later collect new kinds of personal information, we will update this Policy.

5. How we collect information

We collect personal information:

  • directly from you when you use forms, dashboards, or support channels;
  • from Clients when they open a link you send and complete payment or details on the Platform;
  • from Personr, Stripe, email/SMS providers, and other processors as they return status;
  • automatically via cookies, local storage, device identifiers (including a browser fingerprint identifier used to recognise returning visitors), and analytics tools; and
  • from publicly available sources only where you ask the Platform to look up information you supply (for example, an ABN you enter) through integrated services.

If you do not provide information reasonably required for a feature, we may be unable to complete a verification, payment, or account function.

6. Purposes of collection and use

We collect and use personal information to:

  • provide, operate, maintain, and improve the Platform;
  • create and manage orders, organisations, team access, and Pro features;
  • arrange identity verification through Personr and display outcomes to the User;
  • process payments and mark-up payouts through Stripe;
  • send transactional communications (links, receipts, one-time codes, status updates);
  • provide customer support and investigate incidents;
  • measure product usage via analytics (PostHog), including (where enabled) aggregated funnels and, for the Operator’s product improvement, session replay / autocapture as configured;
  • protect the Platform against fraud, abuse, and security threats; and
  • comply with law, enforce our Terms, and establish, exercise, or defend legal claims.

We do not sell personal information. We do not use identity-document or biometric verification artefacts for secondary marketing purposes.

7. Personr (identity verification)

Personr is an independent provider. When you instruct a verification, personal information necessary to commence the check (such as a Client email or phone number, and entity identifiers you enter) is transmitted to Personr so that Personr can create an applicant and verification link. Personr then collects identity evidence directly from the individual.

FreeAML does not use ID documents, selfies, or biometrics as a FreeAML marketing or analytics asset. We may receive verification status, outcomes, and reference IDs (and related result metadata) as needed to run the product. For Personr’s collection practices, retention, overseas processing, and individual rights in respect of the raw identity evidence, please refer to Personr’s published terms and privacy notices. We do not control Personr’s systems.

8. Payments via Stripe

Payments are processed by Stripe. Card details are typically entered on Stripe-hosted pages or components. Stripe handles cardholder data in accordance with Stripe’s terms and privacy policy. The Operator receives payment status, identifiers, and limited billing metadata required for fulfilment, receipts, mark-up, and accounting — not your full card number.

If you onboard to Stripe Connect for mark-up payouts, Stripe will collect identity and bank details from you as Stripe’s customer/connected account. That collection is Stripe’s.

9. Communications

We use email and SMS providers to send one-time passcodes, verification links, beneficial-owner capture requests, and similar transactional messages. Those providers process the recipient address or number and message content for delivery. You may receive operational messages that are not marketing. If we send optional marketing, we will do so in accordance with the Spam Act 2003 (Cth) and APP 7, with an unsubscribe where required.

10. Cookies, identifiers and analytics

The Platform uses cookies, local storage, and similar technologies, including:

  • Functional cookies / storage — for example, verifier contact pre-fill cookies, a session cookie associated with authenticated use, and a visitor identifier stored locally (including a fingerprint-derived identifier) to recognise returning browsers;
  • PostHog analytics — where a project key is configured, PostHog may use cookies and local storage, capture page and product events (custom events are limited to allowlisted operational properties such as order identifiers, amounts, and status), and may enable autocapture and session replay, which can record interactions in the browser interface. Custom analytics events are designed not to forward emails, phone numbers, OTPs, Personr payloads, or verification links; session replay and autocapture may still capture on-screen content. PostHog’s default ingestion host used by the Platform may be located outside Australia; and
  • Third-party cookies on Stripe or Personr domains when you use those flows.

You can control cookies through your browser settings. Blocking cookies may degrade features such as sessions or pre-fill. Analytics may be unavailable in environments where the analytics key is not configured.

11. First- and third-party processors

We use first-party systems and third-party processors to operate the Platform. They process personal information on our instructions or, in some cases (notably Personr and Stripe in respect of their own hosted collection), as independent handlers of data they collect. Processors commonly used include:

  • Stripe — payments and Connect;
  • Personr — identity verification;
  • email and SMS providers — transactional communications;
  • Vercel — hosting of the application;
  • PostHog — product analytics; and
  • Supabase — database hosting.

We do not claim particular security certifications (for example ISO or SOC reports) in this Policy. Any certifications held by a processor belong to that processor and should be verified with them if material to you.

12. Overseas disclosure

Personal information may be disclosed to, and stored or processed by, processors located outside Australia, including in the United States and other countries where those providers operate infrastructure (for example, hosting, analytics, payments, identity verification, email, or SMS). APP 8 may apply to overseas disclosure. Those jurisdictions may not have privacy laws equivalent to Australia’s.

By using the Platform, you acknowledge that overseas processing may occur as reasonably necessary to provide the service. We take reasonable steps in the circumstances to ensure that overseas recipients do not breach the APPs in relation to the information, including by contracting with reputable providers, but we cannot control every aspect of a provider’s global operations.

13. Retention

We retain personal information for as long as reasonably necessary to provide the Platform, resolve disputes, enforce agreements, meet legal and accounting obligations, and support Users’ operational access to order history. Retention periods vary by data type (for example, payment records may be kept for tax and audit purposes longer than ephemeral logs).

Users who are reporting entities remain responsible for keeping their own AML/CTF records for statutory periods, independently of our retention. We may delete or de-identify information when it is no longer reasonably required, subject to backups and legal holds.

Identity-document and biometric retention by Personr is determined by Personr, not by this Policy.

14. Security

We take reasonable steps to protect personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure, including access controls, encrypted transport (HTTPS), and limiting staff access on a need-to-know basis. No method of electronic storage or transmission is completely secure. Third-Party Services apply their own security measures.

You must protect verification links, one-time codes, and account access as described in the Terms.

15. Other disclosures

We may disclose personal information:

  • to the User organisation that initiated a check, as the customer of the Platform;
  • to processors listed above, to provide the service;
  • to professional advisers, insurers, or prospective buyers of the Operator’s business, under confidentiality arrangements;
  • if required or authorised by law, court order, or a regulator (which may include AUSTRAC or law enforcement) — without converting the Operator into your reporting agent; and
  • with your consent, or as otherwise permitted by the Privacy Act.

16. Access, correction and Australian Privacy Principles

In plain but formal terms, the APPs require (among other things) that we: manage personal information in an open and transparent way (APP 1); give you this Policy (APP 1.3–1.4); not collect information unless reasonably necessary for our functions (APP 3); collect fairly and lawfully, and usually from you where reasonable (APP 3–4); notify you of collection at or around the time of collection (APP 5); use and disclose only for the primary purpose or a related purpose you would reasonably expect, or with consent, or as required/authorised by law (APP 6); not use government identifiers as our own (APP 9); take reasonable steps to ensure quality (APP 10) and security (APP 11); give access (APP 12) and correction (APP 13) on request, subject to lawful exceptions.

You may request access to, or correction of, personal information we hold about you by emailing team@freeaml.com.au with sufficient detail for us to identify you and the information sought. We may need to verify your identity. We will respond within a reasonable period. We may refuse in the circumstances permitted by the APPs (for example, where giving access would unreasonably impact another person’s privacy, or is frivolous). If we refuse, we will provide written reasons and information about how to complain, unless it is unreasonable to do so.

If you are not satisfied with our handling of a privacy complaint, you may complain to the Office of the Australian Information Commissioner (OAIC) (oaic.gov.au). We encourage you to contact us first so that we can attempt to resolve the matter.

Requests relating solely to identity documents or biometrics held by Personr should be directed to Personr, although we will reasonably assist by pointing you to the relevant provider where we can.

17. Direct marketing

We may use contact details to send information about the Platform where permitted by APP 7 and the Spam Act, including where you would reasonably expect this in connection with your use of a business product. You may opt out using the mechanism in the message or by emailing us. Transactional messages about existing orders or security are not marketing.

18. Children’s privacy

The Platform is intended for Australian businesses and adult professional users. It is not directed at children. We do not knowingly collect personal information from children for the purpose of offering the Platform to them. Identity verification of adults may incidentally involve dates of birth. If you believe we have collected information from a child contrary to this Policy, contact us and we will take reasonable steps to delete it where appropriate. Personr’s age and identity rules apply to Personr’s capture flows.

19. Changes to this Policy

We may update this Policy from time to time by publishing a new version on the Platform and revising the “Current as at” date. Material changes may additionally be notified by email or in-product notice where reasonably practicable. The version published at freeaml.com.au/privacy is the current Policy.

20. Privacy contact

Privacy requests, questions, and complaints: team@freeaml.com.au. Please include “Privacy” in the subject line and sufficient detail for us to investigate.

Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML · FreeAML (freeaml.com.au) · Current as at 24 September 2026 (Melbourne, Australia)