Privacy Policy

Version: 1.0
Effective Date: 09/03/2026
Last Updated: 09/03/2026

Introduction

Visibl Consulting Pty Ltd, ABN 37 693 869 546 (Visibl, we, us and our) is committed to ensuring that your personal information is adequately protected. It is our policy to respect the confidentiality of information and your privacy. We are a regulatory technology (RegTech) and consulting business that assists our clients to comply with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).

We are bound by the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (the Act). This Privacy Policy (Policy) explains the types of data we may collect about you and how we use your personal information. It also outlines how we keep your personal information secure and your rights in relation to the personal information we hold about you.

1. What is personal information?

Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable.

2. What personal information do we collect?

We may collect the following types of personal information reasonably required by us to carry on our RegTech and consulting services. This includes:

  1. personal details, such as name, gender, address, date of birth, telephone number, email address;
  2. copies of documents to verify identity or age (for example, government-issued ID, passport, driver's licence, birth certificate or utility bill);
  3. copies of documents provided to verify source of funds or wealth (for example, bank statements, tax returns, financial statements or payslips);
  4. information collected when you use our services or contact our team;
  5. details of transactions carried out when using our services; and
  6. in relation to our websites, your internet protocol (IP) address so it is recognised on subsequent visits.

We may update the information we hold about you during our communications. You should contact us if any personal information we hold is inaccurate or out of date. Please see the "Contact Us" information below.

3. When do we collect personal information about you?

We may collect personal information:

  1. When you visit any of our websites;
  2. When you make an enquiry about our services or use our services;
  3. When you submit or request data through our platform (such as where you make a KYC verification request to an end user);
  4. When a third party (such as a referring partner) has permission to share your personal information with us;
  5. When you report a problem, make a query or lodge a complaint; and
  6. During correspondence with Visibl employees (or persons acting on our behalf) by phone, email, online, post or in person.

We will not collect sensitive personal information unless required by law.

4. How do we use your personal information?

We may use your personal information for the following purposes, depending on how you interact with us:

  1. To provide and deliver our services;
  2. To complete onboarding processes, including providing order forms;
  3. To assist our clients in meeting their obligations, such as know your customer (KYC) obligations under the AML/CTF Act;
  4. To communicate with you about your needs and the provision of our services; and
  5. To send mandatory service-related communications (such as changes to our services, terms and conditions or this Policy). These messages are not promotional and cannot be unsubscribed from.

4.1. Responding to queries and complaints

We use personal information to respond to and manage queries or complaints and may keep records of correspondence for legal, commercial and operational purposes.

4.2. Legal and regulatory obligations

We may process personal information to assist our clients to comply with legal and regulatory requirements, including fraud prevention, AML/CTF checks, KYC and other compliance obligations.

4.3. Systems testing and security

We may use personal information to test and improve our systems, conduct risk assessments and maintain appropriate data security safeguards.

4.4. Product and service development

We may conduct market research and analysis to develop or improve services. Cookies may be used on our websites to personalise visits and analyse usage patterns.

4.5. Training and quality assurance

We review service quality to improve customer experience.

4.6. Keeping you informed

We may send marketing communications about relevant products, offers or market information unless you opt out.

4.7. Telephone, video conference and email recording

Telephone and video conference calls may be recorded and emails retained for compliance, dispute resolution, training and quality control purposes. In relation to telephone and video conference calls, we will inform you about our intention to record our meetings or correspondence.

5. Who do we share your personal information with?

We may share your personal information with:

  • Visibl's related bodies corporate and associated entities
  • Third-party service providers, including:
    • Identity verification, credit and fraud prevention agencies;
    • Data aggregators that assist us in the offer of our KYC services;
    • Auditors, lawyers, accountants and professional advisers;
    • Developers that maintain our infrastructure, website and RegTech platform;
    • Banks and payment services providers;
    • Cloud providers that host our infrastructure, website and RegTech platform;
    • IT, hosting, data storage and systems providers;
    • Compliance, finance and administrative service providers;
    • Telecommunications and marketing software providers;
    • Email archiving, security and authentication providers;
    • Our customer relationship management software;
  • Government authorities, regulators and law enforcement bodies where required by law; and
  • Referring partners, where applicable and permitted.

We may disclose your personal information to our service providers who may be located in countries outside Australia, such as Vietnam and the United States.

6. How do we protect your personal information?

We implement appropriate technical and organisational measures to store and protect your personal information from misuse, loss, unauthorised access, modification or disclosure. These measures include staff training, secure systems, encryption, access controls, multi-factor authentication and data breach response procedures.

7. How long do we keep your personal information?

We retain personal information for as long as we require it for a primary purpose, which is in order to provide our services to clients. If we have no legal or regulatory reason to hold personal information for a longer period, information may be anonymised or securely destroyed/deleted.

8. Unsolicited personal information

If you provide personal information we did not request, we will only retain it where permitted or required by law and will protect it in accordance with this Policy.

9. Your data protection rights

You have the right to:

  • Access your personal information;
  • Request correction of inaccurate or incomplete information;
  • Request erasure (subject to legal limitations);
  • Request transfer of information where practicable;
  • Withdraw consent (where applicable); and
  • Lodge a complaint with us or the Office of the Australian Information Commissioner (OAIC).

Identity verification may be required before requests are processed. We will respond to your request within 30 days. If we consider that the information does not need correcting then we will let you know the reasons why, when we respond.

10. Notifiable Data Breach

If we become aware of any data breach concerning personal information, we are required under the Act to determine whether any "eligible data breach" (as defined in the Act) has occurred. If we determine that there has been an eligible data breach, then we are required to notify the affected individuals as soon as practicable of the details of the breach and the recommended steps that the relevant individuals should take in response. We will also be required to notify the OAIC.

11. Managing your marketing preferences

We may use personal information for direct marketing purposes. You may opt out of receiving marketing communications from us in relation to our products, services or business at any time by using the unsubscribe link or contacting us directly. Please see the "Contact Us" information below. Service-related communications may still be sent.

12. Contact Us

If you have questions or complaints about this Policy or your personal information, contact:

Data Protection Officer

Visibl Consulting Pty Limited

Email: compliance@visibl.com.au

Address: Level 22, 400 George Street, Sydney NSW 2000

OAIC

You may also contact the OAIC at www.oaic.gov.au or 1300 363 992 or by mail at GPO Box 5288, Sydney NSW 2001.