AMLHQ Privacy Policy

Privacy Policy

This Privacy Policy explains how Business Advice Agency Pty Ltd trading as AMLHQ collects, uses, stores, discloses and protects personal information in connection with our AML/CTF compliance services for Australian real estate agencies and related businesses.

Last updated: 2 September 2026

Important: AMLHQ handles information connected with identity verification, customer due diligence, beneficial ownership, property transactions, compliance records and regulatory reporting. We treat this information seriously and use it only for legitimate business, compliance, legal and service-delivery purposes.

1. Who this policy applies to

This policy applies to personal information collected by Business Advice Agency Pty Ltd trading as AMLHQ, including through the AMLHQ website, enquiries, onboarding, training, compliance support, the SENTINEL platform and associated AML/CTF compliance services.

In this policy, AMLHQ, we, our and us refers to Business Advice Agency Pty Ltd trading as AMLHQ.

2. The types of information we may collect

The personal information we collect depends on how you interact with AMLHQ and the services being provided. It may include:

3. How we collect personal information

We may collect personal information directly from you, from your employer or agency, from authorised representatives, from forms completed through our website or platform, from third-party verification services, from compliance workflows and from publicly available or lawfully accessible sources where relevant to AML/CTF compliance.

Where AMLHQ is engaged by a real estate agency or reporting entity, we may collect information from that agency in order to assist with its AML/CTF compliance obligations.

4. Why we collect, use and disclose information

We collect, use and disclose personal information for purposes connected with providing AMLHQ services, including to:

5. AML/CTF compliance information

AMLHQ provides services in a regulated compliance environment. Some information collected or processed through AMLHQ may be required to support AML/CTF obligations, including identity verification, customer due diligence, enhanced due diligence, beneficial ownership assessment, source-of-funds or source-of-wealth enquiries, suspicious matter review, audit evidence and record keeping.

Where information is collected for AML/CTF compliance purposes, it may need to be retained, reviewed or disclosed in accordance with applicable law, regulatory obligations, client instructions or lawful requests from regulators or enforcement agencies.

6. Identity verification and third-party service providers

AMLHQ may use third-party service providers to assist with identity verification, customer due diligence, payments, hosting, email, analytics, security, workflow automation, document management and compliance operations.

These providers may include identity verification providers such as GreenID and related verification partners, payment providers such as Stripe, hosting and infrastructure providers, analytics providers and professional advisers. We take reasonable steps to work with providers that have appropriate privacy, security and confidentiality controls for the nature of the services they provide.

7. Overseas disclosure and cloud services

AMLHQ aims to use Australian-hosted infrastructure where practical for AML/CTF compliance records. Some service providers may store, process, back up, support or access information from locations outside Australia, depending on their systems, support arrangements and security architecture.

Where personal information is disclosed or made accessible outside Australia, AMLHQ will take reasonable steps required by applicable privacy law to protect that information, including by using appropriate contractual, technical and organisational controls.

8. Security of personal information

AMLHQ takes reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps may include access controls, encryption in transit, secure hosting, user permissions, audit logs, authentication controls, security monitoring, staff training and contractual confidentiality obligations.

No website, cloud service, email system or digital platform can be guaranteed to be completely secure. Users should take care when sending information electronically and should notify AMLHQ immediately if they suspect unauthorised access or misuse of information connected with AMLHQ services.

9. Retention of information

AMLHQ retains personal information for as long as reasonably required for the purpose for which it was collected, to deliver services, to comply with legal and regulatory obligations, to resolve disputes, to maintain business records and to support AML/CTF audit-readiness.

AML/CTF compliance records may need to be retained for statutory record-keeping periods, including for up to seven years where required. When information is no longer required, AMLHQ will take reasonable steps to securely destroy, delete or de-identify it, subject to legal and regulatory requirements.

10. Website analytics, cookies and marketing

The AMLHQ website may use cookies, pixels, analytics tools and similar technologies to understand website usage, measure campaign performance, improve content, support advertising, and provide a better user experience.

You can usually adjust your browser settings to block or delete cookies. Some website functionality may not operate as intended if cookies are disabled.

Where AMLHQ sends marketing communications, you may opt out using the unsubscribe function in the communication or by contacting us directly.

11. Automated tools, AI assistance and human oversight

AMLHQ may use automation, analytics, workflow tools or AI-assisted functionality to support risk identification, red-flag triage, document review, compliance workflows, training, reporting and operational efficiency.

AI-assisted or automated tools are used to support human review and compliance decision-making. AMLHQ does not treat AI output as a substitute for appropriate Compliance Officer oversight where human judgement is required.

Note: From 10 December 2026, Australian privacy requirements include additional privacy policy disclosure obligations for certain substantially automated decisions that could reasonably be expected to significantly affect an individual's rights or interests. AMLHQ will keep this policy under review as those requirements commence.

12. Accessing or correcting your information

You may request access to personal information AMLHQ holds about you, or ask us to correct information you believe is inaccurate, out of date, incomplete, irrelevant or misleading.

We may need to verify your identity before responding. In some circumstances, we may be unable to provide access or make a correction, including where access would affect the privacy of others, breach confidentiality, compromise security, prejudice an investigation, or conflict with legal or regulatory obligations. If we refuse a request, we will explain why where it is reasonable and lawful to do so.

13. Complaints and concerns

If you have a concern about how AMLHQ has handled your personal information, contact us first so we can review and respond to the matter.

We will aim to acknowledge privacy complaints within a reasonable timeframe and investigate the issue fairly. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.

14. Changes to this policy

AMLHQ may update this Privacy Policy from time to time to reflect changes in law, regulation, technology, services, platform functionality, provider arrangements or business operations. The latest version will be published on this page.

15. Contact AMLHQ

Privacy contact

For privacy questions, access or correction requests, complaints or concerns, contact AMLHQ using the details below.