1. About this Privacy Policy
OneJuly Compliance Pty Ltd (OneJuly, we, us or our) operates the OneJuly compliance platform (Platform).
The Platform assists accounting, legal, conveyancing and other professional practices and regulated organisations with client onboarding, identity verification, customer due diligence, screening, record management and related compliance activities.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information.
OneJuly has chosen to apply the Australian Privacy Principles (APPs) as the minimum privacy standard across our operations. We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) and the APPs.
This policy applies to:
- practices and organisations using the Platform
- their employees, partners, contractors and authorised users
- individuals invited to complete onboarding, identity verification or compliance activities
- directors, trustees, partners, beneficial owners and representatives associated with entities being assessed
- website visitors
- suppliers, business contacts and professional advisers
- other people who interact with OneJuly
We may provide additional collection or consent notices when particular information is collected, including before biometric information is processed.
2. Our role
2.1 Practice and organisation users
If you work for an organisation using OneJuly, we may handle your personal information to establish and administer your account, authenticate you, manage access permissions, provide support, secure the Platform, maintain audit records and manage our relationship with your organisation.
2.2 Individuals invited by a practice
If a practice or organisation invites you to provide information through OneJuly, that organisation generally determines why your information is required and how it will be used.
OneJuly provides technology and processing services to support that process.
The practice remains responsible for its own privacy, AML/CTF, professional and regulatory obligations and for decisions it makes about its clients.
If you wish to access or correct information collected about you by a practice, you should generally contact that practice first. If you contact OneJuly, we may assist the practice to respond.
3. Personal information we handle
The personal information we handle depends on how the Platform is used.
3.1 Practice and organisation users
We may handle information including:
- name and contact details
- employer, practice and role information
- business and billing information
- account and authentication information
- login and session information
- access permissions
- Platform activity
- support communications
- security and audit records
3.2 Individuals being onboarded or verified
We may process information including:
- name
- date of birth
- address
- email address and telephone number
- occupation or employment information
- identity document images and details
- passport, driver licence or other identity information
- Medicare information where lawfully used for verification
- facial images and biometric verification information
- identity verification results
- sanctions, politically exposed person, watchlist and adverse media screening results
- company, trust, partnership and other entity information
- directorship, trusteeship and beneficial ownership information
- source of funds or source of wealth information where required
- documents uploaded through the Platform
- information provided through onboarding or compliance workflows
3.3 Technical information
We may also collect technical and security information including:
- IP address
- browser and device information
- general location derived from an IP address
- login and session activity
- application events
- security events
- audit information
We minimise sensitive information in ordinary application logs and do not intentionally log passwords, authentication tokens or identity document images in ordinary application logs.
4. Mailbox, accounting and other integrations
A practice may choose to connect supported third-party systems to the Platform, including Microsoft 365, Google Workspace, approved mailbox services, Xero, MYOB, QuickBooks and other approved business systems.
Depending on the integration, information processed may include email content, attachments, customer or supplier information, transaction information, accounting records and related metadata.
The practice controls whether an integration is enabled and is responsible for ensuring that it has authority to connect the relevant system and permit the associated processing.
Integration access is restricted to authorised functions and permissions. Credentials and tokens are protected using encryption and access controls and are revoked or disabled in accordance with our procedures when access ends.
We do not use information obtained through customer integrations for unrelated advertising, direct marketing or AI model training.
5. Sensitive and biometric information
Some information processed through OneJuly may be sensitive information.
5.1 Biometric verification
The Platform may use biometric information for identity verification, including live photo click checking and, where requested by a practice, comparison of a facial image with an identity document.
We obtain express consent through the Platform before initiating biometric verification.
During a live photo click, facial information is processed to assess whether the person completing the verification appears to be physically present. OneJuly records information reasonably necessary to evidence the verification outcome and the relevant consent and verification process.
Where face matching or another external identity verification service is used, information reasonably necessary to perform the verification may be provided to an approved provider. This may include:
- a facial image
- an identity document image
- identity document information
- related verification information
We use biometric information only for identity verification and related compliance or security purposes.
We do not sell biometric information, use it for advertising or direct marketing, use it to identify individuals in unrelated contexts, or use it to train artificial intelligence or machine-learning models.
You may decline biometric verification. If you do, contact the practice that invited you to discuss an alternative verification method. Declining biometric verification may mean that verification cannot be completed using that particular method.
5.2 Screening information
Compliance screening may identify potential sanctions matches, politically exposed person status, watchlist matches, adverse media or other compliance risk information.
We process this information only for legitimate verification, risk-management and compliance purposes or where otherwise permitted or required by law.
6. Government-related identifiers
Identity verification may require us to handle government-related identifiers such as passport, driver licence or Medicare information.
We do not adopt these identifiers as OneJuly's own identifier for you.
We use and disclose them only for authorised verification, compliance or other purposes permitted or required by law.
Access to this information is restricted and auditable.
7. How we collect personal information
We may collect personal information:
directly from you;
from a practice or organisation using OneJuly;
from an authorised representative;
through information or documents uploaded to the Platform;
through customer-authorised integrations;
from identity verification and screening providers;
from government or business registers;
from information verification services;
from publicly available or lawfully accessible sources; and
automatically through use of our website or Platform.
8. How we use personal information
We use personal information for purposes including:
- providing and operating the Platform
- administering and authenticating accounts
- client onboarding
- identity verification
- processing identity documents
- biometric verification
- sanctions and compliance screening
- customer due diligence
- beneficial ownership identification
- compliance workflows and record management
- customer-authorised integrations
- technical and customer support
- troubleshooting
- billing and subscriptions
- maintaining audit trails
- detecting fraud or misuse
- protecting our systems
- investigating security or privacy incidents
- meeting legal and regulatory requirements
- maintaining and improving the security, reliability and functionality of the Platform
We do not sell personal information.
We do not use information processed on behalf of a practice about that practice's clients for OneJuly's own direct marketing.
9. AML/CTF and customer responsibilities
The Platform assists customers with activities that may form part of their obligations under Australian AML/CTF laws and other regulatory requirements.
This may include identity verification, customer due diligence, beneficial ownership identification, sanctions and PEP screening, risk assessment, compliance workflows and record management.
OneJuly provides technology to support these activities.
The customer remains responsible for:
- determining its legal and regulatory obligations
- deciding what information it is required or authorised to collect
- assessing verification and screening results
- making decisions about its clients
- meeting its regulatory obligations
- meeting its statutory record-keeping obligations
The Platform must not be treated as the customer's sole statutory record repository or business-continuity backup.
OneJuly does not provide legal or regulatory advice merely by providing the Platform.
10. Automated processing
The Platform uses automated processing to support functions including:
- document information extraction
- identity verification
- live photo click assessment
- face matching
- sanctions and PEP screening
- watchlist and adverse media screening
- fraud detection
- data-quality checks
- identification of matters requiring further review
Automated processing may use identity information, document information, facial information, entity information and screening data.
Outputs may include verification results, potential matches, exception indicators, risk indicators and requests for further review.
These outputs support the customer's compliance workflow. The customer remains responsible for material decisions concerning its clients.
11. Who we disclose personal information to
We may disclose personal information to:
the practice or organisation that invited you to use OneJuly;
identity verification and screening providers;
cloud infrastructure and storage providers;
communications and messaging providers;
payment providers;
security and fraud-prevention providers;
business information and register providers;
providers supporting customer-authorised integrations;
authorised OneJuly personnel and contractors;
professional advisers, auditors and insurers;
regulators, courts, law enforcement agencies or government authorities where required or authorised by law; and
parties involved in a genuine corporate transaction, subject to appropriate confidentiality arrangements.
We limit disclosures to information reasonably required for the relevant purpose.
12. Overseas processing and support access
OneJuly's core production environment is located in Australia.
However, personal information may be accessed or processed outside Australia in connection with authorised support activities and external service providers.
12.1 Authorised support personnel in India
OneJuly has authorised support personnel located in India.
Those personnel may access production systems and personal information where reasonably necessary for authorised:
customer support;
troubleshooting;
technical investigation;
incident response;
security investigation; or
operational support.
Production access is not unrestricted.
Access is limited to authorised personnel, provided according to role and operational need, authenticated, subject to role-based and least-privilege controls, limited to information reasonably necessary for the relevant task, subject to confidentiality and security obligations, and logged and auditable.
Where practical, troubleshooting is performed without accessing sensitive production information.
12.2 External providers
Selected verification, screening, messaging, payment, integration and other service providers may process specified categories of information outside Australia.
Personal information may therefore be processed or accessed in Australia, India and other countries in which our disclosed service providers or their subprocessors operate.
We maintain information about material subprocessors and relevant processing locations and make this information available to customers.
Where personal information is disclosed overseas, we take reasonable steps required by applicable Australian privacy law to protect that information.
13. Australian data residency
OneJuly has deliberately designed its core Platform environment around Australian data residency.
OneJuly-controlled production customer records, identity documents, database backups and security logs are stored in data centres located in Australia. OneJuly's core authenticated application processing occurs in Australia.
Identity documents upload directly to encrypted Australian storage without passing through a global content delivery network or OneJuly's application servers.
Selected external verification, screening, messaging, payment and integration providers may process specified categories of data necessary to provide their services outside OneJuly's controlled Australian environment.
Authorised OneJuly personnel in India may also access production personal information for approved support and troubleshooting purposes under the controls described in section 12.
Accordingly, we do not claim that all information associated with the Platform remains exclusively within Australia.
14. Security
We maintain security controls appropriate to the nature and sensitivity of the information we handle.
These include:
- encryption of personal information in transit and at rest
- encrypted storage for identity documents and sensitive information
- logical tenant isolation at application and database levels
- role-based and least-privilege access controls
- multi-factor authentication for privileged access
- restricted administrative access
- malware scanning of uploaded files
- security monitoring
- audit logging
- controlled and auditable production access
Access to production personal information by OneJuly personnel, including personnel located outside Australia, does not provide general or unrestricted access to customer information.
No information system can be guaranteed to be completely secure. We maintain processes for investigating, containing and responding to suspected security and privacy incidents and make notifications where required by applicable law.
15. Retention and deletion
We do not retain customer information indefinitely.
Information remains available during the customer's paid subscription period.
Following the end of the paid subscription, a 30-day retrieval period applies. During this period, access is restricted in accordance with the customer agreement, including access required to export customer information and manage relevant account functions.
At the end of the retrieval period, customer information is deleted from active production systems unless:
continued retention is required by law;
the information is subject to a legal hold;
continued retention is required by a regulatory obligation applying to OneJuly;
retention is reasonably necessary for an active fraud or security investigation; or
a different retention arrangement has been expressly agreed in writing.
An authorised customer administrator may request earlier deletion where permitted under the customer agreement.
We may take reasonable steps to verify the identity and authority of a person requesting earlier deletion.
Verification of an earlier deletion request does not extend the ordinary automatic deletion period following the 30-day retrieval period.
Following deletion from active production systems, residual encrypted copies may temporarily remain in access-controlled backups or non-current storage versions.
Those residual encrypted copies are deleted or overwritten no later than 35 days after active deletion, except where longer retention is required by law, legal hold or a regulatory obligation applying to OneJuly.
Residual backup copies are not used for ordinary business purposes.
OneJuly does not impose a universal seven-year retention period on customer information merely because the Platform supports AML/CTF compliance.
Customers remain responsible for their own statutory record-retention obligations.
Different retention periods may apply to OneJuly's own billing, security, incident, consent, complaint and legal records.
16. Artificial intelligence and model training
OneJuly may use artificial intelligence, machine learning or automated technologies as components of authorised Platform functionality, including document processing, information extraction, matching and compliance-support workflows.
We do not use customer content, identity documents or biometric information to train artificial intelligence or machine-learning models.
OneJuly maintains the organisation-level opt-out from service improvement and model training for its production cloud environment.
We do not authorise our cloud or technology providers to use customer content, identity documents or biometric information for unrelated model training or service improvement.
If we propose to use identifiable customer information for a materially different AI or machine-learning training purpose in the future, we will first assess the privacy implications and obtain any consent or other authority required.
17. Access and correction
You may request access to personal information that OneJuly holds about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
We may take reasonable steps to verify your identity and authority before responding.
Where information is held primarily on behalf of a practice, we may refer the request to that practice and assist it to respond.
We will respond within a reasonable period and may refuse or limit access where permitted or required by law.
18. Privacy complaints
If you believe OneJuly has mishandled your personal information or failed to meet an applicable privacy obligation, you may make a complaint to our Privacy Officer at privacy@onejuly.com.au.
Please provide sufficient information for us to understand what occurred, the information or activity concerned and the outcome you are seeking.
We will acknowledge a privacy complaint within 5 business days and aim to provide a substantive response within 30 days.
If additional time is reasonably required because of the complexity of the matter, we will let you know.
Where a complaint primarily concerns information handled on behalf of a practice using the Platform, we may work with that practice to investigate and respond.
If you are not satisfied with our response, you may be entitled to complain to the Office of the Australian Information Commissioner.
19. Cookies and direct marketing
Our website and Platform use cookies and similar technologies required to operate and secure our services, including for authentication, security, session management and essential functionality.
If we introduce non-essential analytics, advertising or tracking technologies, we will provide appropriate notice and controls where required.
We may send marketing communications to customers, prospective customers and business contacts where permitted by law. You may opt out of marketing communications at any time.
We do not use client identity information, identity documents, biometric information or compliance-screening information for direct marketing.
20. Children and authorised representatives
The Platform is primarily designed for professional practices and adult users.
Where information relates to a minor or a person acting through a guardian, attorney, administrator or other authorised representative, the relevant practice is responsible for determining whether it has appropriate authority to initiate the process.
OneJuly may require evidence of authority or restrict particular verification methods where appropriate.
21. Changes to this Privacy Policy
We may update this Privacy Policy to reflect changes to our services, technology, suppliers, processing arrangements, legal requirements or privacy and security controls.
The current version will be published on our website with its effective date.
Where a change materially affects how we handle personal information, we will take reasonable steps to provide appropriate notice.
22. Contact us
For privacy enquiries, access or correction requests, or privacy complaints, contact:
Privacy Officer
OneJuly Compliance Pty Ltd
ACN 698 932 663
Unit 207, 111 Overton Road
Williams Landing VIC 3027
Australia
Email: privacy@onejuly.com.au