Syntrico Pty Ltd · ACN 692 777 245

Website Privacy Policy

Effective upon publication · 81–83 Campbell Street, Surry Hills NSW 2010

This Privacy Policy applies to all personal information collected by Syntrico Pty Ltd (we, us or our) via the website located at www.syntrico.com.au (Website).

1.What information do we collect?

The kind of Personal Information that we collect from you will depend on how you use the website. The Personal Information which we collect and hold about you may include:

We collect the following personal information from website users: full name, email address, phone number, company name, job title, IP address, browser type and version, device information, cookies and tracking data, usage data and analytics, billing and payment information for customers, correspondence and support enquiry records, and any other information voluntarily provided through contact forms, service requests, or account registration processes.

2.Types of information

The Privacy Act 1988 (Cth) (Privacy Act) defines types of information, including Personal Information and Sensitive Information.

Personal Information means information or an opinion about an identified individual or an individual who is reasonably identifiable:

2.1
whether the information or opinion is true or not; and
2.2
whether the information or opinion is recorded in a material form or not.

If the information does not disclose your identity or enable your identity to be ascertained, it will in most cases not be classified as “Personal Information” and will not be subject to this privacy policy.

Sensitive Information is defined in the Privacy Act as including information or opinion about such things as an individual's racial or ethnic origin, political opinions, membership of a political association, religious or philosophical beliefs, membership of a trade union or other professional body, criminal record or health information.

Sensitive Information will be used by us only:

2.3
for the primary purpose for which it was obtained;
2.4
for a secondary purpose that is directly related to the primary purpose; and
2.5
with your consent or where required or authorised by law.

3.How we collect your Personal Information

3.1
We may collect Personal Information from you whenever you input such information into the Website, related app or provide it to Us in any other way.
3.2
We may also collect cookies from your computer which enable us to tell when you use the Website and also to help customise your Website experience. As a general rule, however, it is not possible to identify you personally from our use of cookies.
3.3
We will only place non-essential cookies (including analytics, marketing, and performance cookies) on your device with your prior explicit consent. You may accept, reject, or customise cookie preferences through our cookie banner, and withdraw consent at any time through your browser settings or our Website controls.
3.4
We generally don't collect Sensitive Information, but when we do, we will comply with the preceding paragraph.
3.5
Where reasonable and practicable we collect your Personal Information from you only. However, sometimes we may be given information from a third party, in cases like this we will take steps to make you aware of the information that was provided by a third party.

4.Purpose of collection

4.1
We collect Personal Information to provide you with the best service experience possible on the Website and keep in touch with you about developments in our business.
4.2
We customarily only disclose Personal Information to our service providers who assist us in operating the Website. Your Personal Information may also be exposed from time to time to maintenance and support personnel acting in the normal course of their duties.
4.3
All service providers who receive Personal Information must execute data processing agreements requiring compliance with the Australian Privacy Principles, implementation of security measures equivalent to our own standards, and notification to us of any data breaches within 24 hours. Service providers must limit use of Personal Information to purposes specified in their engagement and return or securely destroy such information upon contract termination.
4.4
By using our Website, you consent to the receipt of direct marketing material. We will only use your Personal Information for this purpose if we have collected such information direct from you, and if it is material of a type which you would reasonably expect to receive from use. We do not use sensitive Personal Information in direct marketing activity. Our direct marketing material will include a simple means by which you can request not to receive further communications of this nature, such as an unsubscribe button link.

5.Security, Access and correction

5.1
We store your Personal Information in a way that reasonably protects it from unauthorised access, misuse, modification or disclosure. When we no longer require your Personal Information for the purpose for which we obtained in, we will take reasonable steps to destroy and anonymise or de-identify it. Most of the Personal Information that is stored in our client files and records will be kept for a maximum of 7 years to fulfill our record keeping obligations.
5.2
The Australian Privacy Principles:
5.2.1
permit you to obtain access to the Personal Information we hold about you in certain circumstances (Australian Privacy Principle 12); and
5.2.2
allow you to correct inaccurate Personal Information subject to certain exceptions (Australian Privacy Principle 13).
5.3
Where you would like to obtain such access, please contact us in writing on the contact details set out at the bottom of this privacy policy.
5.4
We maintain specific retention schedules for different categories of Personal Information: client contact and project information is retained for 7 years following engagement completion to fulfill tax and business record obligations; website analytics and usage data is retained for 12 months; and marketing preferences are retained until consent is withdrawn. Upon expiration of the applicable retention period, Personal Information is securely destroyed through irreversible deletion methods with documented verification, unless legal hold or regulatory requirements mandate continued retention.

6.Complaint procedure

If you have a complaint concerning the manner in which we maintain the privacy of your Personal Information, please contact us as on the contact details set out at the bottom of this policy. All complaints will be considered by Managing Director and we may seek further information from you to clarify your concerns. If we agree that your complaint is well founded, we will, in consultation with you, take appropriate steps to rectify the problem. If you remain dissatisfied with the outcome, you may refer the matter to the Office of the Australian Information Commissioner.

7.Overseas transfer

Your Personal Information will not be disclosed to recipients outside Australia unless you expressly request us to do so. If you request us to transfer your Personal Information to an overseas recipient, the overseas recipient will not be required to comply with the Australian Privacy Principles and we will not be liable for any mishandling of your information in such circumstances.

8.How to contact us about privacy

If you have any queries, or if you seek access to your Personal Information, or if you have a complaint about our privacy practices, you can contact us through: [email protected].

9.Contractual safeguards for overseas transfers

Where Personal Information is transferred to overseas recipients in jurisdictions without substantially similar data protection laws to Australia, we will implement contractual safeguards including Standard Contractual Clauses or equivalent mechanisms to ensure your information receives adequate protection. You may request details of these safeguards by contacting us using the details provided in this policy.

10.Complaint handling timeframes

We will acknowledge your complaint within 3 business days of receipt and provide a substantive response within 7 days of acknowledgment. During the investigation period, we will provide interim updates on progress and may implement temporary remedies to address your concerns. If you remain dissatisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au or by calling 1300 363 992 within 30 days of receiving our final response.

11.Information Security Policy

11.1 Intent and Scope

11.1(a)
This information security policy (policy) provides the basis of information security management within Syntrico Pty Ltd (Company).
11.1(b)
Effective protection of business information creates a competitive advantage, both in the ability to preserve the reputation of the Company and in reducing the risk of the occurrence of negative events and incidents.
11.1(c)
This policy aims to balance the following priorities:
11.1(c)(i)
Meeting the Company's legislative requirements.
11.1(c)(ii)
Keeping data and documents confidential as required by the Company and its stakeholders.
11.1(c)(iii)
Ensuring the integrity of the Company's data and IT systems.
11.1(c)(iv)
Upholding the Company's reputation as a trusted recipient of data.
11.1(c)(v)
Maintaining storage and back-up systems that meet the needs of the Company and its employees, contractors, volunteers, vendors and anyone else who may have any type of access to the Company's systems, software, hardware, data and/or documents (collectively referred to as the Participants).

11.2 Responsibilities

11.2(a)
This policy applies to all Participants who are given access to the Company’s systems, software, hardware, data and/or documents.
11.2(b)
All Participants are responsible for protecting business information and systems. Where there is any doubt about the security of any action, the Participants should take a cautious approach and avoid any potential risks.
11.2(c)
The Information Security Officer is responsible for implementing this policy.

11.3 Authorisation and Access

Managers should exercise caution when:

  • Sharing information and documents with the Participants.
  • Authorising the Participants to enter and control information systems.
  • Giving the Participants access to information systems.

As a general rule, managers should follow a need-to-know basis. If there is any uncertainty regarding how information and documents should be shared, contact the Information Security Officer at [email protected].

11.4 Device and Password Security

Participants must follow guidelines to protect electronic devices:

11.4(a)
When using and securing devices:
11.4(a)(i)
Keep all electronic devices' passwords secure and protected.
11.4(a)(ii)
Logging into accounts should only be performed through safe networks.
11.4(a)(iii)
Install security updates on a regular basis.
11.4(a)(iv)
Upgrade antivirus software on a regular basis.
11.4(a)(v)
Never leave devices unprotected and exposed, particularly in public spaces.
11.4(a)(vi)
Lock computers when leaving the desk.
11.4(a)(vii)
When accessing trusted external systems, all applicable guidelines must be complied with.
11.4(b)
It is recommended that any Internet of Things (IoT) devices are kept segregated from Company systems unless they have been approved by an IT specialist for use.
11.4(c)
The Participants must not use unauthorised devices on their workstations, unless they have received specific authorisation from the Information Security Officer.
11.4(d)
Any devices deemed no longer suitable for use must be disposed of in a secure way to ensure all information is permanently removed.

11.5 Transferring Data

Data transfer is a common cause of cybercrime. The Participants should follow these best practices when transferring data:

11.5(a)
Avoid transferring personal information such as customer data and employee information (this includes anything that can or may identify an individual including first name, last name, age, address and email address).
11.5(b)
Adhere to the relevant personal information legislation including the Australian Privacy Principles.
11.5(c)
Data should only be shared over authorised networks.
11.5(d)
If applicable, destroy any sensitive data when it is no longer needed.

11.6 Working Remotely

When working remotely, all the information security policies and procedures must be followed.

11.7 Company Systems

11.7(a)
When accessing the internet from any system set up by the Company:
11.7(a)(i)
Participants must use the standard process and not bypass any security measure.
11.7(a)(ii)
Reasonable care must be taken in relation when downloading documents and transmitting data over the internet. Access only trusted websites.
11.7(b)
When accessing accounts on Company systems:
11.7(b)(i)
User accounts on work systems are only to be used for the business purposes of the Company and not to be used for personal activities.
11.7(b)(ii)
Participants are responsible for protecting all confidential information used and/or stored on their accounts. This includes their user logins and passwords. Participants are prohibited from making unauthorised copies of such confidential information and/or distributing it to unauthorised persons outside of the Company.
11.7(b)(iii)
Participants must not purposely engage in any activity with the intent to: harass other users; degrade the performance of the system; divert system resources to their own use; or gain access to Company systems for which they do not have authorisation.

11.8 General Security Requirements

11.8(a)
Participants must not install unauthorised software. The Company may at any time introduce a whitelist of approved/trusted programs. If this occurs then only these programs may be used by the Participants.
11.8(b)
Participants should stay up-to-date with any other Company-wide recommendations, such as recommended browser settings.
11.8(c)
Participants should perform daily backups of important new/changed data, software and configuration settings.
11.8(d)
Participants must not attempt to turn off or circumvent any security measures.
11.8(e)
Participants must report any security breaches, suspicious activities or issues that may cause a cyber security breach to the Information Security Officer immediately, and await their instructions regarding the appropriate response to the breach.

11.9 Other Company Policies

This Policy must be followed in conjunction with the Company's Privacy Policy, Data Breach Response Policy, Acceptable Use Policy, Access Control Policy, and Client Data Handling Policy. These policies are accessible via the company intranet at intranet.syntrico.com.au/policies or by contacting the Information Security Officer directly.

11.10 Training

All Participants must maintain working knowledge of basic information security protocols. All new Participants will be given training on information security.

11.11 Disciplinary Action

If this policy is breached, one or more of the following disciplinary actions will take place:

11.11(a)
Incidents will be assessed on a case-by-case basis.
11.11(b)
In case of breaches that are intentional or repeated or cases that cause direct harm to the Company, Participants may face serious disciplinary action, including termination of your employment, engagement or services.

12.Data Security & Customer Data Handling Policy

12.1 Purpose

12.1(a)
This Data Security and Customer Data Handling Policy sets out how Syntrico Pty Ltd, trading as Syntrico AML Guardian, handles, stores, protects, accesses, and manages customer data processed through its cloud-based software-as-a-service platform.
12.1(b)
Syntrico AML Guardian is an AML/CTF compliance software platform designed to assist businesses with compliance workflows, customer due diligence, identity verification, risk assessment, screening, monitoring, reporting, training, audit readiness, and related compliance activities.
12.1(c)
Syntrico recognises that customer data, including personal information and personally identifiable information, is sensitive and must be handled with appropriate security, confidentiality, and governance controls. This policy is intended to explain the security and data handling practices applied to the Syntrico AML Guardian platform.

12.2 Application of this Policy

12.2(a)
This policy applies to all customer data collected, uploaded, submitted, generated, stored, processed, accessed, or otherwise handled through the Syntrico AML Guardian platform.
12.2(b)
This policy applies to Syntrico, its employees, officers, contractors, developers, support personnel, authorised administrators, and approved third-party service providers who may be involved in the operation, maintenance, support, security, or improvement of the platform.

12.3 Customer Data

12.3(a)
For the purposes of this policy, “Customer Data” means all data, information, records, documents, files, content, and materials submitted to, generated within, or processed by the Syntrico AML Guardian platform by or on behalf of a customer.
12.3(b)
Customer Data may include, but is not limited to:
12.3(b)(i)
customer business information;
12.3(b)(ii)
user account information;
12.3(b)(iii)
client or end-customer information;
12.3(b)(iv)
personal information;
12.3(b)(v)
personally identifiable information;
12.3(b)(vi)
identity verification information;
12.3(b)(vii)
AML/CTF compliance information;
12.3(b)(viii)
customer due diligence records;
12.3(b)(ix)
beneficial ownership information;
12.3(b)(x)
risk assessment data;
12.3(b)(xi)
screening, monitoring, and reporting records;
12.3(b)(xii)
audit logs and system activity records; and
12.3(b)(xiii)
documents, notes, forms, checklists, declarations, and compliance records.

12.4 SaaS Platform Security

12.4(a)
Syntrico AML Guardian is delivered as a cloud-based SaaS application. Syntrico takes reasonable technical, operational, and organisational measures to protect the confidentiality, integrity, and availability of Customer Data processed through the platform.
12.4(b)
These measures are designed to reduce the risk of unauthorised access, misuse, interference, loss, disclosure, alteration, destruction, or compromise of Customer Data.
12.4(c)
Syntrico's security approach includes:
12.4(c)(i)
secure cloud hosting;
12.4(c)(ii)
encryption of data at rest;
12.4(c)(iii)
encryption of data in transit;
12.4(c)(iv)
authenticated user access;
12.4(c)(v)
restricted administrative access;
12.4(c)(vi)
role-based access controls where applicable;
12.4(c)(vii)
secure database storage;
12.4(c)(viii)
system monitoring and audit logging;
12.4(c)(ix)
controlled access to production environments;
12.4(c)(x)
use of reputable infrastructure and service providers; and
12.4(c)(xi)
internal access controls for employees and contractors.

12.5 Data Hosting and Location

12.5(a)
Customer Data is hosted on secure Amazon Web Services infrastructure located in Sydney, Australia.
12.5(b)
Syntrico uses AWS infrastructure to support the availability, scalability, security, and performance of the AML Guardian platform.
12.5(c)
Customer Data is stored in secure cloud environments and databases with appropriate technical and administrative safeguards.

12.6 Encryption

12.6(a)
Syntrico applies encryption controls to protect Customer Data.
12.6(b)
Personal information and personally identifiable information stored in the platform database is encrypted at rest.
12.6(c)
Data transmitted between users, browsers, systems, APIs, and the Syntrico AML Guardian platform is encrypted in transit using secure communication protocols.
12.6(d)
These encryption controls are intended to protect Customer Data from unauthorised interception, access, disclosure, or modification.

12.7 Access to Customer Data

12.7(a)
Access to Customer Data within Syntrico AML Guardian is controlled and restricted. Customer users must authenticate using valid login credentials before accessing the platform. Customer information cannot be accessed through the platform without valid authentication and authorised access.
12.7(b)
Customer Data is not made generally available to all Syntrico personnel.
12.7(c)
Only authorised Syntrico personnel with elevated access privileges may access Customer Data, including personal information or personally identifiable information, and only where such access is reasonably necessary for a legitimate business, technical, operational, security, support, or product improvement purpose.
12.7(d)
Such purposes may include:
12.7(d)(i)
providing technical or customer support;
12.7(d)(ii)
investigating or resolving platform issues;
12.7(d)(iii)
maintaining, securing, or improving the platform;
12.7(d)(iv)
troubleshooting errors or performance issues;
12.7(d)(v)
improving software functionality and user experience;
12.7(d)(vi)
testing, validating, or enhancing system features;
12.7(d)(vii)
monitoring platform security and integrity;
12.7(d)(viii)
responding to customer requests; and
12.7(d)(ix)
complying with legal, contractual, regulatory, or security obligations.
12.7(e)
Syntrico personnel are not permitted to access Customer Data for personal, unauthorised, unrelated, or improper purposes.

12.8 Elevated Access and Internal Controls

12.8(a)
Syntrico may assign elevated access privileges to certain employees, contractors, system administrators, developers, or support personnel where such access is required for their role.
12.8(b)
Elevated access is limited to personnel who require access to perform authorised duties in relation to the platform.
12.8(c)
Where Customer Data, including personal information or personally identifiable information, is accessed by authorised personnel, such access must be solely for legitimate business purposes connected with operating, supporting, securing, maintaining, building, improving, or enhancing the Syntrico AML Guardian platform or the customer experience.
12.8(d)
Syntrico may maintain access logs, system records, and audit trails to assist with monitoring access, investigating issues, and maintaining platform security.

12.9 Use of Data for Platform Improvement

12.9(a)
Syntrico may use Customer Data, system usage data, technical logs, customer feedback, support requests, workflow information, and platform analytics to improve the Syntrico AML Guardian platform.
12.9(b)
This may include using information to:
12.9(b)(i)
improve software functionality;
12.9(b)(ii)
enhance user experience;
12.9(b)(iii)
identify and resolve bugs;
12.9(b)(iv)
improve workflows and system performance;
12.9(b)(v)
develop new features;
12.9(b)(vi)
enhance compliance tools and automation;
12.9(b)(vii)
improve customer onboarding and support; and
12.9(b)(viii)
maintain security and platform reliability.
12.9(c)
Where practical, Syntrico will use aggregated, anonymised, masked, or de-identified data for analytics, testing, reporting, software development, and product improvement activities.
12.9(d)
Where access to identifiable Customer Data is required, such access is restricted to authorised personnel with elevated access and must be limited to the purpose for which access is required.

12.10 Confidentiality

12.10(a)
Syntrico treats Customer Data as confidential information.
12.10(b)
Syntrico personnel, contractors, and authorised service providers who may access Customer Data are expected to handle that information confidentially and in accordance with applicable internal policies, contractual obligations, and security requirements.
12.10(c)
Customer Data must not be disclosed, copied, exported, modified, shared, or used except as authorised by Syntrico, required to provide the platform, requested by the customer, or required by law.

12.11 Customer Responsibilities

12.11(a)
Customers are responsible for managing access to their own Syntrico AML Guardian account.
12.11(b)
Customers must ensure that:
12.11(b)(i)
only authorised users are invited to access their account;
12.11(b)(ii)
user access permissions are reviewed and maintained;
12.11(b)(iii)
login credentials are kept secure and confidential;
12.11(b)(iv)
passwords are not shared;
12.11(b)(v)
users promptly notify Syntrico of any suspected unauthorised access;
12.11(b)(vi)
information entered into the platform is accurate, lawful, and authorised; and
12.11(b)(vii)
their use of the platform complies with applicable laws, regulations, and internal policies.
12.11(c)
Syntrico is not responsible for unauthorised access caused by customer-side credential sharing, weak passwords, compromised user accounts, or failure to manage user permissions appropriately.

12.12 Third-Party Service Providers

12.12(a)
Syntrico may use third-party service providers to assist in delivering, hosting, maintaining, supporting, securing, or improving the Syntrico AML Guardian platform. These providers may include cloud hosting providers, verification providers, infrastructure providers, security tools, communication tools, analytics tools, and other technology service providers.
12.12(b)
Syntrico will take reasonable steps to ensure that third-party providers used in connection with the platform are reputable and apply appropriate security, confidentiality, and data handling controls.
12.12(c)
Customer Data will only be shared with third-party providers where reasonably required to provide the platform, deliver requested functionality, support customers, maintain security, or comply with legal or regulatory obligations.

12.13 Security Monitoring and Audit Logging

12.13(a)
Syntrico may collect and retain system logs, access logs, audit records, event data, and technical information to support platform security, performance, support, compliance, and reliability.
12.13(b)
These records may be used to:
12.13(b)(i)
monitor system activity;
12.13(b)(ii)
detect suspicious or unauthorised activity;
12.13(b)(iii)
investigate technical issues;
12.13(b)(iv)
troubleshoot user issues;
12.13(b)(v)
maintain platform integrity;
12.13(b)(vi)
support audit and compliance requirements;
12.13(b)(vii)
improve security controls; and
12.13(b)(viii)
verify system performance.

12.14 Data Retention

12.14(a)
Syntrico retains Customer Data for as long as reasonably required to provide the platform, support customer accounts, comply with legal or regulatory obligations, maintain audit records, resolve disputes, enforce agreements, and meet operational or security requirements.
12.14(b)
Where Customer Data is no longer required, Syntrico may securely delete, archive, anonymise, or de-identify the information, subject to applicable legal, regulatory, contractual, technical, backup, and audit requirements.

12.15 Data Backup and Availability

12.15(a)
Syntrico may maintain backups of Customer Data and system information to support business continuity, disaster recovery, security, and platform availability.
12.15(b)
Backup data may be retained for a limited period in accordance with Syntrico's operational and technical requirements.
12.15(c)
Backup systems are intended to assist Syntrico in restoring platform availability and data integrity in the event of accidental loss, technical failure, security incident, or other disruption.

12.16 Data Security Incidents

12.16(a)
If Syntrico becomes aware of an actual or suspected data security incident involving Customer Data, Syntrico will take reasonable steps to assess, contain, investigate, and remediate the incident.
12.16(b)
Where required by applicable law, regulation, contract, or privacy obligation, Syntrico will notify affected customers, regulators, or other relevant parties.
12.16(c)
Syntrico may also take steps to suspend access, reset credentials, apply security patches, update systems, or implement other remedial measures where necessary to protect Customer Data and platform integrity.

12.17 No Sale of Customer Data

12.17(a)
Syntrico does not sell Customer Data or customer personal information.
12.17(b)
Customer Data is used only for purposes connected with providing, operating, securing, maintaining, supporting, improving, or enhancing the Syntrico AML Guardian platform, or as otherwise authorised by the customer or required by law.

12.18 Privacy and Legal Compliance

12.18(a)
Syntrico will take reasonable steps to handle personal information in accordance with applicable privacy, data protection, contractual, and regulatory obligations.
12.18(b)
This policy should be read together with Syntrico's Privacy Policy, Terms of Use, customer agreements, and any other applicable contractual documents.
12.18(c)
In the event of inconsistency between this policy and a signed customer agreement, the terms of the signed customer agreement will prevail to the extent of the inconsistency.

12.19 Changes to this Policy

12.19(a)
Syntrico may update this policy from time to time to reflect changes to its platform, security controls, business operations, legal requirements, technology providers, or data handling practices.
12.19(b)
The updated version will apply from the date it is published or otherwise notified to customers.

12.20 Summary Statement

Syntrico AML Guardian is a secure cloud-based SaaS platform hosted on AWS infrastructure in Sydney, Australia. Customer personal information and personally identifiable information is encrypted at rest and encrypted in transit. Access to Customer Data is protected through authentication controls and is not generally available to all Syntrico personnel. Only authorised employees or contractors with elevated access may access Customer Data, and only where required for legitimate business, technical, security, support, product development, software improvement, customer experience, legal, or compliance purposes. Syntrico takes reasonable steps to protect Customer Data from unauthorised access, misuse, interference, loss, disclosure, alteration, or destruction.

SYNTRICO PTY LTD · ACN 692 777 245

81–83 Campbell Street, Surry Hills NSW 2010

[email protected]