Sun Card Pty Ltd (ABN 33 079 249 595), trading as Flagship AML (referred to as we, us or our), is committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This Privacy Policy explains how we collect, use, disclose, store and otherwise handle personal information in connection with the Flagship AML platform and our AML/CTF compliance services.
This Privacy Policy applies to personal information collected through the Flagship AML platform, our website and related services. It is intended to provide transparency regarding our data handling practices. This Policy does not limit or modify any obligations imposed on users under applicable AML/CTF legislation, and users remain responsible for complying with their own legal obligations in relation to customer due diligence.
“Personal information” has the meaning given in the Privacy Act 1988 (Cth) and includes information or an opinion about an identified individual or an individual who is reasonably identifiable. In the context of our platform, this may include identification details such as name, date of birth and contact information, as well as information relating to customer due diligence, beneficial ownership, control structures and risk assessments. Sensitive information may include information used for identity verification and government related identifiers. We do not collect or store biometric information or other sensitive information unless required for AML/CTF compliance purposes.
We collect personal information that is reasonably necessary to operate the platform and provide AML/CTF compliance services. This includes account and user information, client and engagement information, compliance records such as KYC data, risk assessments and monitoring records, as well as technical and usage data required for system functionality and security.
In some cases, information derived from identity documents (such as name, date of birth and document reference details) may be recorded where required for customer due diligence. Flagship AML does not store copies of identity documents, biometric data or raw government verification data.
We only collect personal information that is reasonably necessary for the performance of our functions and activities as an AML/CTF compliance service provider.
We collect personal information directly from users of the platform, from authorised representatives acting on behalf of clients, and through the operation of the platform itself, including system-generated logs and technical data. Users are responsible for ensuring that they are authorised to provide personal information to us and that they have obtained all necessary consents from individuals whose information is submitted to the platform.
We use personal information for the purpose of providing AML/CTF compliance services, including facilitating customer due diligence processes such as identity verification and risk assessment. Personal information is also used to operate, maintain and improve the platform and to comply with applicable legal and regulatory obligations.
Personal information collected through the platform, including information used for identity verification, is used solely for the purposes of providing AML/CTF compliance services, facilitating customer due diligence and risk assessment, and meeting legal and regulatory obligations. Flagship AML does not use personal information obtained through identity verification processes for profiling, marketing, advertising or market research purposes.
We may disclose personal information to third-party service providers, including identity verification providers and gateway service providers, for the purposes described in this Policy. We do not sell personal information.
Personal information collected and processed through the Flagship AML platform is stored using secure cloud infrastructure located outside Australia, including in Singapore. Core platform data is hosted in Singapore, while documents and compliance records may be stored using globally distributed storage infrastructure.
As a result, personal information may be transferred to, stored and processed in multiple jurisdictions, including Singapore, the United States, the European Union and other locations in which our service providers operate. By using the platform, users acknowledge and consent to the transfer of personal information outside Australia.
We take reasonable steps to ensure that any overseas recipient of personal information does not breach the Australian Privacy Principles in relation to that information. This includes implementing contractual, technical and organisational safeguards designed to protect personal information in accordance with Australian privacy law. Where it is not practicable to ensure such compliance, we will not disclose personal information to the overseas recipient.
Flagship AML uses third-party service providers to host, store, secure and deliver the platform. These providers include cloud infrastructure providers such as DigitalOcean and web infrastructure and security providers such as Cloudflare.
These providers may have access to personal information solely to the extent necessary to provide hosting, infrastructure, storage and security services. They do not use personal information for their own independent purposes. Flagship AML takes reasonable steps to ensure that such providers handle personal information in accordance with applicable privacy and security standards.
Flagship AML may facilitate electronic identity verification as part of customer due diligence under applicable AML/CTF legislation. Where electronic identity verification is used, personal information may be provided to a third-party identity verification provider, including gateway service providers, for the purpose of verifying an individual’s identity using reliable and independent data sources.
Electronic identity verification is conducted only after the individual has provided express consent through the provider’s verification process. Flagship AML does not receive, store or disclose raw verification responses, government data or Information Match Results. Instead, the platform records and presents a limited verification outcome or identity opinion for use as part of the customer due diligence process.
Electronic identity verification forms only one component of customer due diligence and does not replace the obligation to identify, verify and assess clients in accordance with applicable AML/CTF laws. Flagship AML does not represent that electronic identity verification constitutes confirmation of identity and users must rely on their own assessment in accordance with AML/CTF obligations.
We implement appropriate technical and organisational safeguards to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These measures include encryption of data in transit and at rest, access controls, authentication mechanisms and secure cloud infrastructure.
We retain personal information for as long as necessary to provide our services and to comply with applicable legal and regulatory obligations, including record-keeping requirements under AML/CTF legislation.
Individuals may request access to, or correction of, their personal information held by us. We will respond to such requests in accordance with applicable privacy laws.
If you have a complaint about how we handle personal information, you may contact us using the details below. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner.
By using the platform and submitting personal information, users acknowledge that personal information may be disclosed to third-party service providers and identity verification providers for the purposes described in this Policy, and that such information may be transferred to, stored and processed outside Australia.
Users are responsible for ensuring that they have obtained all necessary consents from individuals whose personal information is submitted to the platform, including any consent required for electronic identity verification.
Privacy Officer
Sun Card Pty Ltd trading as Flagship AML
Email: info@flagshipaml.com.au