Privacy Policy
1.1 Introduction
At Supreme AI Pty Ltd, we are bound by the Privacy Act 1988 (Cth) (‘Privacy Act’) and the thirteen Australian Privacy Principles (‘APPs’) contained in Schedule 1 to that Act. We are also subject to the Notifiable Data Breaches (‘NDB’) scheme established under Part IIIC of the Privacy Act.
1.2 Definitions
‘Personal Information’ has the meaning given in the Privacy Act; information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in material form or not.
‘Customer Data’ means personal information that you upload, input or generate on the Platform about your own clients in the course of your AML/CTF compliance activities.
‘Sensitive Information’ includes information about health, racial or ethnic origin, religious beliefs, sexual orientation, criminal record, financial information, and biometric data, it is afforded additional protections under APP 3.
1.3 Information We Collect
Account and Identity Information
- Full legal name, preferred name, and job title
- Business name, ABN, ACN, Australian Financial Services Licence number, or professional registration number
- Email address, telephone number, and postal address
- Username, password (stored in hashed, salted form), and multi-factor authentication data
Customer Data (Uploaded by client)
- Identification documents of your clients (e.g. passport copies, driver licence images, birth certificates)
- Beneficial ownership records, including names, dates of birth, addresses, and ownership percentages
- Risk assessment outputs, customer due diligence records, and transaction monitoring data
- Suspicious Matter Report (‘SMR’) drafts and Threshold Transaction Report (‘TTR’) drafts
- Records relating to politically exposed persons (‘PEPs’) and sanctions checks
Customer Data uploaded by you in connection with your AML/CTF obligations under the AML/CTF Act is subject to the same confidentiality protections as those obligations themselves. Supreme AI will never use Customer Data for any purpose other than operating the Platform for your benefit.
Technical and Usage Data
- IP address, device type, operating system, browser type and version
- Pages visited, features used, session duration, click-stream data, and error logs
- API access logs and integration audit trails
Communications Data
- Support tickets, live chat transcripts, AI chatbot conversations, and email correspondence
- Call recordings (where you are notified at the time)
- Survey responses, feedback submissions, and community posts
1.4 How We Collect Information
- Directly from the client when they register, complete onboarding, use the Platform, or contact us
- Automatically via cookies, web analytics, and server logs
- From third-party identity verification, PEP/sanctions screening, and payments providers when you engage those integrations
- From publicly available sources such as ASIC, ABR, and government registers, where relevant to platform functionality
1.5 Why We Collect and Use Your Information
We collect and use personal information for the following purposes, relying on the legal bases noted:
| Purpose | Legal Basis Under Privacy Act / Other Law |
|---|---|
| To create and manage your account and authenticate access | Contractual necessity (App 3.3) |
| To provide, maintain, and improve the Platform | Contractual necessity; legitimate interest |
| To enable AML/CTF program building, CDD, reporting, and training features | Contractual necessity; AML/CTF Act compliance |
| To detect fraud, abuse, security threats, and misuse | Legitimate interest; legal obligation |
| To meet our own obligations under Australian law (tax, corporate, AML/CTF Act) | Legal obligation (APP 3.4) |
| To communicate about your account, updates, and material changes | Contractual necessity |
| To send marketing communications (with your consent) | Consent (APP 3.3); Spam Act 2003 (Cth) |
| To conduct research and product development using de-identified data | Legitimate interest |
1.6 Disclosure of Your Information
We do not sell personal information. We may disclose personal information to:
- Cloud, infrastructure, and hosting providers under contractual data-processing agreements with AUS-equivalent protections
- Identity verification, screening, and payments partners only when you initiate the relevant function
- Professional advisers including accountants, lawyers, auditors, and insurers, under confidentiality obligations
- AUSTRAC, the OAIC, the ATO, ASIC, or other regulators where required by law or lawful request
- Courts, tribunals, or law enforcement agencies where compelled by legal process
- A successor entity in the event of a merger or acquisition, subject to equivalent privacy commitments and user notification
1.7 Cross-Border Disclosure
Production data is hosted exclusively in Australian Government certified data centres located in Queensland. Some support and infrastructure service providers may have personnel located overseas (for example, offshore-hosted help desk software) who can access metadata for support purposes. Where personal information is disclosed overseas, we take reasonable steps under APP 8 to ensure the overseas recipient handles it in a manner consistent with the APPs. By using the Platform, you consent to this limited cross-border access where contractually necessary.
1.8 Information Security
- Multi-factor authentication enforced for all accounts
- Role-based access controls and least-privilege principles
- Continuous logging, monitoring, and intrusion detection
- Regular independent penetration testing and vulnerability assessments
- Staff security vetting and annual security awareness training
1.9 Your Rights
Under the Privacy Act and the APPs, you have the right to:
- Access the personal information we hold about you (APP 12)
- Request correction of information that is inaccurate, out of date, or misleading (APP 13)
- Withdraw consent to marketing communications at any time
- Request deletion of personal information (subject to legal retention obligations pursuant to Section 5)
- Make a privacy complaint pursuant to Section 11)
To exercise any of these rights, contact our Privacy Officer at [email protected]. We will respond within 30 calendar days. We may charge a reasonable cost-recovery fee for access requests in accordance with APP 12.
1.10 Notifiable Data Breaches
If Supreme AI suffers an eligible data breach under Part IIIC of the Privacy Act, i.e, a breach that is likely to result in serious harm to any affected individual, we will notify affected individuals and the Office of the Australian Information Commissioner (‘OAIC’) as soon as practicable. We will include the nature of the breach, the type of information involved, and the steps we recommend to mitigate the risk of harm.
1.11 Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in law, our services, or data-handling practices. We will notify you of material changes by publishing an in-platform banner and, where appropriate, by email, at least 14 calendar days before the change takes effect. Continued use of the Platform after the effective date constitutes acceptance.