Plain-English summary
We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. We collect information to verify identity, run compliance workflows and operate the Service, acting in two capacities: as the collecting organisation for client profiles and portal accounts, and as each firm's service provider for its compliance records. Data lives in Sydney, Australia by default, encrypted at rest and in transit. A small number of overseas sub-processors handle payments, email delivery and AI-assisted drafting. Biometric and DVS checks run only with express consent, captured per check. We never sell personal information. AML/CTF records are kept for seven years for the responsible firm; other firm data is deleted within 90 days of a subscription ending unless law requires longer. This summary helps you navigate the Policy but does not replace it.
1. Who we are
This Privacy Policy explains how Intentiv Pty Ltd (ABN 24 679 070 270) ("Intentiv", "we", "us", "our") collects, uses, discloses and protects personal information when you visit our websites, use the Intentiv platform or client portal (together, the "Service"), or communicate with us. By using our websites or the Service, you acknowledge that you have read and understood this Policy. Contact details for privacy matters are in section 18.
2. Our two roles
We handle personal information in two distinct capacities, and it matters which one applies.
As the collecting organisation. For Client Profiles and portal accounts, for firm user accounts, and for information about our website visitors and business contacts, we decide how the information is handled and this Policy applies in full. A Client Profile is established under a direct agreement between Intentiv and the individual or entity it describes (the Client Portal Terms), and it belongs to that person, not to any firm.
As a firm's service provider. For compliance records a firm makes or keeps through the Service ("Firm Compliance Records"), the firm is responsible for the personal information and we handle those records only on the firm's documented instructions, except where law requires otherwise. The firm is responsible for its own privacy compliance for those records, including its own notices to its clients.
The same underlying document can exist in both layers: when a firm relies on a profile document or verification outcome, a point-in-time copy is written into that firm's Firm Compliance Records. The copy is governed by the firm's instructions; the profile original remains governed by this Policy and the Client Portal Terms.
3. What we collect
3.1 Account and contact information
Name, role, firm name, email address, phone number and postal address; login credentials (passwords are stored hashed) and authentication details such as multi-factor tokens; and settings and preferences.
3.2 Billing information
Subscription plan, invoices, payment history and credit balances. Card details are processed by our PCI DSS compliant payment provider; we do not store full card numbers.
3.3 Client Profile information
For individuals and entities with a Client Profile: identity details (name, date of birth, address, citizenship, identity document details); entity details (registration numbers, directors, beneficial owners, trust structures); documents uploaded to the profile and their expiry dates; verification history and outcomes, including screening results such as sanctions, politically exposed persons and adverse information matches; consent records, including sharing grants; and biometric data (facial images and liveness recordings) collected for identity verification. Section 11 covers biometric data specifically.
3.4 Firm Compliance Records
Records firms create through the Service about their clients and matters, including risk assessments, decisions, alerts and their outcomes, reports, program documents, and point-in-time copies of profile documents relied on.
3.5 Usage and technical data
IP address, browser and device information, pages visited, features used, timestamps, and in-app activity logs such as verifications run, reviews completed and exports generated.
4. How we collect it
Directly from you, when you create an account, complete onboarding, respond to a request in the portal, or contact us. Automatically, through server logs and cookies as described in section 14. From firms, when they add client information to begin due diligence. From third parties, including government registers (such as ASIC and the ABR), screening and sanctions databases, identity verification providers, and integrated practice-management tools.
5. Why we use it
To provide and operate the Service: account management, authentication, identity verification, screening, risk workflows, document custody, expiry tracking, renewal requests and hosting.
To keep the Service secure: monitoring, fraud detection, abuse prevention and incident response.
To improve the Service: analysing usage patterns, diagnosing errors and developing features.
To communicate with you: service notices, onboarding support, billing and security notifications, and marketing where you have consented.
To comply with law: record-keeping and reporting obligations, and lawful requests from regulators and law enforcement.
To enforce our rights: detecting, investigating and resolving breaches of our terms or the law.
We do not sell personal information.
6. Our basis for handling information
Under the Privacy Act 1988 (Cth), we collect and use personal information only where reasonably necessary for our functions and activities. In practice, that means: handling necessary to provide the Service you or your firm have engaged; handling required to comply with legal obligations, including retention under AML/CTF laws and responses to lawful orders; handling in our legitimate interests, such as security monitoring, fraud prevention and service improvement, where those interests are not outweighed by your interests; and handling based on your consent, including biometric verification, DVS checks, sharing grants, marketing communications and non-essential cookies. Where consent is the basis, you can withdraw it at any time without affecting prior handling.
7. Who we share it with
7.1 Firms you authorise
Client Profile information is shared with a firm only under a current sharing grant given by the profile holder. Each grant is specific to one firm and revocable at any time. Revocation ends future access; point-in-time copies a firm has already relied on remain in that firm's compliance records because the firm is required by law to keep them.
7.2 Service providers
We engage a small number of providers to operate the Service, each bound by contract to protect personal information to a standard at least equivalent to this Policy. The categories are: cloud infrastructure and hosting; payment processing; identity verification and screening (including DVS access through an authorised gateway provider and, where credit header checks are used, an Australian credit reporting body); email delivery; and AI language model processing for draft compliance narratives (section 13). We will notify you before engaging a new provider that materially changes how personal information is processed.
7.3 Intentiv staff
Our personnel access personal information only on a need-to-know basis to resolve support requests, diagnose technical issues or comply with legal obligations. All access to production data is logged, and staff are bound by confidentiality obligations.
7.4 Within your organisation
Activity logs and audit trails within the Service are visible to administrators of your organisation as configured by your Account Owner.
7.5 Regulators and law enforcement
We may disclose personal information to regulators (including AUSTRAC and the OAIC), courts and law enforcement where required by law. Where legally permitted, we will notify the affected firm or individual before disclosing.
7.6 Business transfers
If Intentiv is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will notify you before your information becomes subject to a different privacy policy, and any acquirer of the Service must assume the Records Access Guarantee in our Terms of Service.
8. Overseas transfers
Our primary application infrastructure and databases are located in Sydney, Australia, and personal information is stored in Australia by default. Overseas processing is limited to specific categories where suitable Australian alternatives are not available: payment processing, email delivery and AI-assisted drafting, each involving sub-processors located in the United States.
When we transfer personal information overseas, we enter into agreements requiring the recipient to handle it consistently with the Australian Privacy Principles, we assess the recipient's security practices before engagement, and we remain accountable under APP 8 for how overseas recipients handle the information. Biometric data is not sent to AI sub-processors, and section 11 sets out where biometric data is processed.
Where our personnel work remotely from outside Australia, any access to production systems is controlled, logged and subject to the safeguards in section 9. Remote access does not change where your information is stored.
9. Security
We use layered technical and organisational measures to protect personal information, including AES-256 encryption at rest and TLS 1.2 or higher in transit; application-layer encryption with dedicated key management for the most sensitive credentials; role-based access control and multi-factor authentication; comprehensive, immutable audit logging of access and changes; regular vulnerability assessment and penetration testing; and documented incident response procedures. If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. Our security overview has more detail.
10. Retention
We keep personal information only for as long as it is needed for the purposes in section 5, and then delete or de-identify it. How long that is depends on which layer the information sits in (section 2) and on any law that sets a minimum period. Where a law, court order or regulator direction requires longer retention, the law prevails, and the Records Access Guarantee in our Terms of Service continues to apply to Compliance Records for as long as we hold them.
Firm Compliance Records. Retained for the responsible firm for as long as AML/CTF laws require, generally seven years, measured as those laws prescribe for each record type. When a firm's subscription ends, the firm has 90 days to export its records and may elect either a complete export followed by deletion or de-identification, or the Retention Service, under which we continue to hold the records with view and export access for the balance of the statutory period. If the firm makes no election, we retain the records only to the extent the law requires.
Client Profiles. Held while the profile remains open. A profile holder may close their profile at any time; we then delete or de-identify the profile information within 30 days, except information we must keep by law. Point-in-time copies already written into a firm's Compliance Records are governed by that firm's retention above and are not affected by profile closure.
Biometric data. Raw biometric data (facial images and liveness recordings) is not retained beyond the period needed to complete the verification and record its outcome, as described in section 11. Verification outcomes form part of the requesting firm's Compliance Records and follow that retention.
DVS document credentials. Deleted once the check completes, as described in section 12.
Account, billing and business contact information. Kept while the account or relationship is active, and afterwards as required for tax, accounting and corporate record-keeping obligations, generally seven years.
Other firm data. Firm data that is not a Compliance Record, such as settings, user accounts and support correspondence, is deleted or de-identified within 90 days of the subscription ending, unless law requires longer.
Usage and technical data. Security and system logs are retained for 12 months. Audit trails of compliance actions form part of the relevant firm's Compliance Records and follow that retention.
Backups. Deleted information leaves backup systems as backups rotate, within 35 days of deletion from production. We do not use backups to restore information deleted at your request, except where restoration is needed to recover from data loss, in which case the deletion is re-applied.
De-identified data. We may retain aggregated, de-identified information that can no longer reasonably identify anyone.
When information is deleted, it is deleted securely. Where secure deletion is not practicable, the information is put beyond use and de-identified.
11. Biometric data
Facial images and liveness recordings are sensitive information under the Privacy Act, and we treat them with the highest level of care.
Purpose. Biometric data is collected solely for digital identity verification and fraud prevention. It is never used for marketing or profiling.
Consent. Biometric verification runs only with the individual's express, informed consent, captured at the start of the verification journey and recorded with a timestamp.
Processing. Biometric data is processed by our identity verification provider under a data processing agreement requiring protection to the same or a higher standard than this Policy. We do not retain raw biometric templates beyond the period needed to complete verification and record the outcome.
Retention and deletion. Verification outcomes and supporting documents are retained in line with section 10. After the applicable retention period, biometric data is securely deleted. Individuals may request earlier deletion of specific biometric records, subject to legal retention requirements, through the portal or by contacting us.
12. Verification sources and the DVS
Where an Australian identity document is used for verification, the details provided (such as name, date of birth and document numbers) may be checked against records held by the issuing authority through the Australian Government's Document Verification Service ("DVS"), accessed via an authorised gateway provider. The DVS confirms whether details match official records; it does not disclose additional information about you.
Consent. A DVS check runs only with your express consent, requested at the start of the verification journey before any check begins. The consent statement and the time you agreed are recorded.
If you decline. You may decline. If you do, your identity cannot be verified electronically through the Service, the verification is cancelled and the firm that requested it is notified. That firm may offer an alternative method, or may be unable to act for you where verification is a legal requirement; that is a matter between you and the firm.
Retention. Document credentials collected solely for a DVS check are deleted once the check completes. The verification result is retained as part of the requesting firm's compliance records in line with section 10.
Complaints. Questions, corrections or complaints about a DVS check can be raised with the firm that requested the verification or with us under section 18, and you may also contact the OAIC.
Credit header checks. Some verifications may also check your details against credit header information held by an Australian credit reporting body. A credit header check is used for identity verification only: it is not an application for credit and does not affect your credit score, although the credit reporting body may note that a verification request was made. Where a credit header check may be used, this is disclosed in the verification flow before you give consent.
Provider analytics. Our identity verification provider may retain de-identified information, which cannot reasonably identify you, to maintain and improve its verification technology. Details of the current provider are available on request.
13. AI-assisted drafting
The Service can generate draft compliance narratives, such as a written rationale summarising a risk assessment, using large language model technology. When a draft is generated, structured and minimised data about the client profile (such as entity type, risk category and flagged indicators) is sent to our AI sub-processor. We do not include identity document details, biometric data or raw personal identifiers in AI prompts. Information submitted for drafting is not used to train AI models and is not retained by the sub-processor beyond what is needed to generate the output. Drafts must be reviewed and approved by a qualified compliance professional before use, all outputs can be completed manually, and AI actions are clearly labelled in the Service.
14. Cookies
Essential cookies only. We use cookies strictly necessary for the Service to operate, including authentication sessions, security tokens and preferences. These are placed without consent because the functionality you request depends on them.
No analytics or advertising. Our websites and the Service currently load no analytics or advertising scripts and set no non-essential cookies. We do not use advertising, retargeting or visitor-identification tools, and no marketing technology operates inside the authenticated Service. If we introduce analytics cookies in future, we will add a consent control at the same time and update this Policy.
15. Your rights
Under the Australian Privacy Principles you may: request access to the personal information we hold about you (APP 12); request correction of information that is inaccurate, out of date, incomplete or misleading (APP 13); request deletion in certain circumstances, noting we cannot delete information the law requires a firm or us to retain; object to direct marketing at any time; and withdraw any consent you have given, without affecting prior handling.
Profile holders can view, correct and manage most of their information directly in the portal, including their sharing grants. For anything else, write to support@intentiv.com.au with the subject line "Privacy request". We will acknowledge your request within 5 business days and respond substantively within 30 days. We may ask you to verify your identity first. We do not charge for access requests unless they are excessive or repetitive, and if we cannot fully comply we will explain why in writing. If your request concerns records held for a firm, we may refer it to that firm as the responsible organisation and will tell you if we do.
16. People under 18
The Service is intended for businesses, professional firms and their adult clients, and is directed at people aged 18 and over. We do not knowingly collect personal information from people under 18. If a verification journey reveals that a person is under 18, the journey ends at that point and the requesting firm is notified. If you believe we have done so inadvertently, contact us and we will promptly delete it.
17. Changes to this Policy
We may update this Policy to reflect changes in our practices, technology or legal requirements, and will update the date at the top when we do. For material changes, such as new categories of data collected or new sub-processors handling sensitive data, we will give at least 30 days notice by email or in-app notification before the change takes effect.
18. Contact and complaints
Intentiv Pty Ltd, attention: Privacy Officer. Email: support@intentiv.com.au.
If you have a complaint about how we have handled your personal information, contact us first. We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner at www.oaic.gov.au or on 1300 363 992.