top of page

WhiteLight AML | Privacy Policy

WhiteLight AML

WhiteLight AML | Privacy Policy

WhiteLight AML ("we," "our," or "us") is committed to managing the privacy of personal information in an open and transparent manner. This Privacy Policy has been developed in accordance with the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), the New Zealand Privacy Act 2020, and other applicable privacy laws and regulations.

This Privacy Policy explains how we collect, use, store and disclose personal information in the course of providing Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) compliance services. It also outlines how individuals may access or correct their personal information or raise concerns about how it is handled.​

Scope and Role in Information Handling

This Privacy Policy applies to personal information handled by WhiteLight AML in connection with our business operations and service delivery.

In the context of AML/CTF compliance services, WhiteLight AML commonly operates as a service provider handling personal information on behalf of its clients. In these circumstances, our clients retain primary responsibility for determining how personal information is used, while we process that information in accordance with contractual arrangements and applicable legal requirements.

We also collect and manage personal information in our own right in connection with our internal business operations, including client relationships and administrative functions.

Types of Personal Information We Collect

We collect and hold personal information that is reasonably necessary to perform our functions and activities.

This may include:

  • Name

  • Date of birth

  • Contact details (such as address, phone number and email)

  • Identification documents (e.g. passports or driver’s licences)

  • Financial information (such as bank account details)

  • Employment information

  • Transaction records and histories

  • Other information required for AML/CTF compliance

 

We may also collect technical information such as IP address, device information, system logs and usage data when individuals interact with our website or systems.

In certain circumstances, we may collect sensitive information where required for AML/CTF compliance purposes. This may include biometric information used for identity verification or information relating to criminal history or sanctions screening. We only collect sensitive information where permitted by law and apply additional safeguards to protect it.

 

Government-related identifiers are handled in accordance with applicable legal restrictions.

How We Collect Personal Information

WhiteLight AML collects personal information in a variety of ways, depending on the nature of the engagement. This may include:

  • Directly from clients or their customers through onboarding processes, documentation or communications

  • From third-party service providers, including identity verification platforms and data providers

  • From publicly available sources or regulatory bodies where required

  • Automatically through our website, client portals and communication systems (e.g. usage data and system logs)

 

In many cases, we do not collect personal information directly from individuals but instead receive it from our clients. In these circumstances, our clients are generally responsible for providing any required privacy notices and ensuring that the collection complies with applicable laws.

Use of Personal Information

We collect, hold, use and disclose personal information for purposes directly related to our services and business operations.

These purposes include:

  • Verifying identity and conducting due diligence

  • Assessing and monitoring risk

  • Analysing transactions and identifying potentially suspicious activity

  • Supporting AML/CTF compliance and reporting obligations

  • Maintaining records and administering client relationships

  • Improving systems and services

  • Ensuring the security and integrity of our operations

 

We may also use personal information to comply with legal or regulatory obligations, including responding to requests from government or law enforcement agencies.

We only use personal information where it is reasonably necessary to provide our services, comply with legal obligations, support legitimate business activities, or where otherwise permitted by law.

Automated Decision-Making

As part of our services, we use automated systems and technologies to assist in analysing personal information, including identity verification tools and risk assessment systems.

These systems are used to support decision-making processes and are typically subject to human oversight. We take reasonable steps to ensure that outputs from automated systems are reviewed and validated where appropriate.

Disclosure of Personal Information

WhiteLight AML may disclose personal information where necessary for the purposes outlined in this policy.

This may include disclosure to:

  • Our clients, who determine how the information is used

  • Third-party service providers and contractors (including technology, data storage and identity verification providers)

  • Professional advisers such as legal, audit and risk advisers

  • Regulatory authorities, government agencies and law enforcement bodies where required or authorised by law

 

We may also disclose personal information where an individual has provided consent or where otherwise permitted by law.

We take reasonable steps to ensure that third parties handle personal information in a manner consistent with applicable privacy laws.

We do not use personal information obtained through client service delivery for direct marketing purposes.

Cross-Border Disclosure

In providing our services, we may disclose personal information to recipients located outside Australia and New Zealand, including cloud service providers and technology vendors operating in multiple jurisdictions.

These jurisdictions may include the United States, the United Kingdom, the European Union and other countries in which our service providers operate.

Where personal information is disclosed overseas, we take reasonable steps to ensure appropriate safeguards are in place. This may include conducting due diligence on recipients and implementing contractual protections.

We ensure that cross-border disclosures comply with applicable legal requirements.

 

Data Security

WhiteLight AML is committed to protecting personal information from misuse, interference, loss and unauthorised access, modification or disclosure.

We implement a combination of technical and organisational measures, including:

  • Encryption and secure system architecture

  • Access controls and monitoring systems

  • Staff training and confidentiality obligations

  • Ongoing governance, audits and risk assessments

 

Data Breaches

In the event of a suspected or actual data breach, we will assess the nature and extent of the incident, contain any impact and implement remediation measures.

Where required, we will notify affected individuals and relevant regulators in accordance with applicable legal requirements, including Australia’s Notifiable Data Breaches scheme.

 

Access and Correction

Individuals have the right to request access to personal information held by WhiteLight AML and to request correction where information is inaccurate, incomplete or out of date.

We may take reasonable steps to verify identity before granting access. In some circumstances, access may be refused where permitted by law, and we will provide reasons if this occurs.

 

Retention of Personal Information

We retain personal information only for as long as necessary to fulfil the purposes for which it was collected and to comply with legal, regulatory and contractual obligations.

In the context of AML/CTF services, retention periods may be determined by legal requirements or our clients’ obligations.

When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it.

 

Anonymity

Where lawful and practicable, individuals may have the option to interact with us anonymously or using a pseudonym. However, due to the nature of AML/CTF services, this will generally not be possible.

 

Complaints

If you believe that we have not complied with applicable privacy laws or have mishandled personal information, you may lodge a complaint with us.

We will acknowledge and investigate complaints and aim to respond within a reasonable timeframe.

If you are not satisfied with our response, you may refer your complaint to:

 

Australia
Office of the Australian Information Commissioner
www.oaic.gov.au

 

New Zealand
Office of the Privacy Commissioner
www.privacy.org.nz

 

Cookies and Digital Technologies

We use cookies and similar technologies to operate our website and improve user experience.

These technologies may collect information such as IP address, browser type, pages visited and interaction data. Some may be provided by third-party service providers.

Users can manage or disable cookies through their browser settings, although this may affect website functionality.

 

Updates to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, legal requirements or regulatory guidance. The latest version will be published on our website.

 

Contact Us

If you have any questions, requests or complaints regarding this Privacy Policy, please contact:

WhiteLight AML
Email: info@whitelightaml.com.au
Phone: +61 2 8075 9900
Website: https://www.whitelightaml.com.au

bottom of page