Privacy Policy

Privacy Policy

Last Updated: 9 September 2026
© 2026 VeriEzi, a product of Dingo Devs Pty Ltd. All rights reserved.

This Privacy Policy explains how Dingo Devs Pty Ltd (ABN 87 691 872 214), trading as VeriEzi (VeriEzi, we, us or our), collects, uses, discloses, stores and protects personal information. VeriEzi provides software and related services that support identity verification, verification of identity (VOI), electronic identity checks, company and business searches, ASIC-related searches, customer due diligence, sanctions and politically exposed person screening, adverse media screening and related workflow/reporting services for our business customers. We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), any other Australian laws that apply to our services, and the privacy and data-handling obligations in our supplier agreements. Where applicable to the relevant Document Verification Service (DVS) access arrangement, this includes the Identity Verification Services Act 2023 (Cth), the Identity Verification Services Rules 2024, the DVS Access Policy and applicable participation or gateway terms. This policy should be read together with any collection notice, consent screen, customer notice or product-specific terms that apply to a particular VeriEzi workflow. Those materials may give more specific information about a particular verification, DVS request, biometric check, ASIC/company search, screening report or support process. Where a workflow-specific notice is more specific, it applies to that workflow.
  1. Scope

    This policy applies to personal information we collect and handle through the VeriEzi platform, our website, customer onboarding and support, supplier-integrated verification services, APIs and related communications.

    It applies to personal information about:

    • individuals whose identity is verified, screened or searched through VeriEzi;
    • representatives, directors, officers, beneficial owners, shareholders, trustees, partners or authorised contacts of businesses or other entities searched through VeriEzi;
    • users of the VeriEzi platform, including our customers' staff and authorised users;
    • people whose personal information is provided to us by a customer or authorised user for a lawful VeriEzi workflow;
    • people who contact us, submit enquiries or make complaints; and
    • service providers, suppliers, professional advisers and business contacts.

    VeriEzi is designed for business use. It is not intended for children. We do not knowingly collect personal information from children through the platform unless this is required for a lawful customer workflow and appropriate authority, notice and consent have been obtained.

  2. What Personal Information We Collect

    The kinds of personal information we collect depend on the VeriEzi product or workflow used. We may collect:

    • identity and contact details, such as name, previous names, date of birth, address, email address, phone number and occupation or role;
    • identity document details, such as driver licence, passport, Medicare card, birth certificate, citizenship certificate, visa, ImmiCard or other government-issued document details;
    • copies or images of identity documents, selfies, liveness images, video or audio recordings, facial comparison outputs, biometric templates or biometric-derived information, where the relevant service requires them;
    • government related identifiers, such as passport numbers, driver licence numbers, Medicare numbers or tax file numbers, where lawful and necessary for the relevant verification or check;
    • business and company information, including ABN, ACN, ARBN, entity names, trading names, officeholder details, shareholding or beneficial ownership information, ASIC extracts and company search results;
    • customer due diligence and screening information, including sanctions, politically exposed person, relative/close associate and adverse media screening results;
    • verification responses, match scores, reference numbers, report metadata, audit logs and transaction histories;
    • platform user information, including login details, role/access permissions, organisation details, support records and usage records;
    • technical information, such as IP address, device/browser information, cookie identifiers, session logs, security logs and analytics information; and
    • payment, billing and account administration information.

    Some of this information may be sensitive information under the Privacy Act, including biometric information used for automated biometric verification, biometric templates, health-related information that appears on a document, racial or ethnic information that may be inferred from an image or document, criminal history or screening-related information, and tax file numbers. We only collect sensitive information where we have consent or another lawful basis to do so.

  3. How We Collect Personal Information

    We collect personal information:

    • directly from individuals, including through forms, identity verification workflows, consent screens, uploads, camera capture, support requests and correspondence;
    • from our business customers and their authorised users, including lawyers, conveyancers, accountants, financial services providers, businesses and other organisations using VeriEzi;
    • from identity verification, document verification, biometric, DVS, bank verification, sanctions, PEP, adverse media, ASIC, company search and commercial data suppliers integrated into VeriEzi;
    • from government agencies, registries or authorised data sources where the relevant service involves a permitted verification or search;
    • from integration partners, connected platforms and third-party systems used to request or deliver a VeriEzi service;
    • from publicly available sources and commercial databases where lawful and relevant to the requested service; and
    • automatically through our website, platform, security systems, logs, cookies and analytics tools.

    We will generally collect personal information directly from the individual where it is reasonable and practicable to do so. In some workflows, it is necessary for a customer or supplier to provide personal information to us so that we can deliver the requested verification, search, screening or reporting service.

    If a customer or authorised user provides us with personal information about another person, they must ensure they have the authority to do so, have given any required privacy notice, have obtained any required consent or authorisation, and have taken reasonable steps to ensure the information is accurate, complete and up to date.

    When a customer initiates a verification, search, screening or reporting workflow, VeriEzi generally handles the information to deliver that service on the customer's instructions. The customer determines the purpose of the workflow and remains responsible for ensuring that its request is lawful and that required notices, consents and authorities have been provided or obtained.

    VeriEzi determines how and why personal information is handled for its own platform administration, account management, billing, support, security, fraud prevention, service improvement, legal compliance, audit and dispute-resolution activities. This distinction does not limit an individual's rights under the Privacy Act.

  4. Unsolicited Personal Information

    If we receive personal information that we did not request, we will decide within a reasonable period whether we could have collected it under the APPs. If we could not have collected it, and it is lawful and reasonable to do so, we will destroy or de-identify it.

  5. Why We Collect, Use and Disclose Personal Information

    We collect, use and disclose personal information for purposes reasonably necessary for VeriEzi's functions and activities, including to:

    • provide, operate, support and improve the VeriEzi platform and related services;
    • verify identity, conduct VOI checks, perform document checks, biometric/liveness checks, DVS checks, e-passport checks, bank account matching, TFN verification and other permitted verification services;
    • perform company, business, ASIC-related, beneficial ownership and individual verification searches;
    • support AML/CTF, sanctions, PEP, relative/close associate and adverse media screening workflows;
    • generate and deliver verification reports, search results, match results, audit logs and transaction records to our customers;
    • administer customer accounts, billing, support, training, security, service availability, troubleshooting and compliance;
    • detect, investigate and prevent fraud, misuse, unauthorised access, security incidents and unlawful activity;
    • meet legal, regulatory, contractual, audit, record-keeping and dispute-resolution obligations;
    • communicate with customers, users and affected individuals about services, support, policy updates and privacy matters; and
    • send marketing communications where permitted by law and subject to opt-out rights.

    Australian privacy law does not use a separate overseas-style 'legal basis' framework. For Australian privacy purposes, we rely on the Privacy Act and APPs, including collection where reasonably necessary for our functions or activities, consent where required, and other permissions or requirements under Australian law.

  6. Notices, Consent and Consequences of Not Providing Information

    Before using a verification, biometric, DVS, e-passport, TFN, screening or similar service, the individual may be asked to read a collection notice and give consent or authorisation. Depending on the service, this may include consent to:

    • capture and use identity document images, selfies, liveness data, facial images or biometric information for identity verification;
    • submit document details or government related identifiers to authorised verification services, including DVS or other approved sources;
    • disclose information to our data suppliers, gateway providers, issuing authorities and their data sources so they can perform the requested check;
    • receive and use match results, reference numbers, screening results and verification reports; and
    • retain evidence, reports and audit records for legal, contractual, audit and customer-service purposes.

    Where express consent is required, it must be voluntary, informed, current, specific and unambiguous. We do not infer express consent from silence, a failure to opt out or a pre-selected choice. Before a DVS request, the individual will be told what identification information is proposed to be collected, why it is required, how it will be used and disclosed, how any facial image will be used, retained and disposed of, the consequences of declining, the relevant legal obligations and rights, and how to make a privacy complaint.

    If required information or consent is not provided, or if a verification service returns a non-match, inconclusive or adverse result, we may not be able to complete the verification, search, screening, report, customer onboarding or support activity. A customer may need to use an alternative verification or review process.

    Where consent is withdrawn, the withdrawal will not affect handling that occurred before withdrawal, but it may affect our ability or a customer's ability to continue the relevant service or workflow.

  7. Identity Verification, VOI, DVS and Biometrics

    VeriEzi may use third-party verification services to compare identity information against independent data sources. This may include document verification, DVS checks, e-passport checks, liveness detection, facial comparison, bank account matching, TFN verification and other identity-related checks.

    Where the Australian Government's DVS or a similar official-document check is used, selected identity document fields are transmitted through an authorised gateway or service provider to the DVS Hub or other relevant official record holder. The issuing authority normally returns a match or non-match response. VeriEzi does not receive a copy of the underlying government record from the issuing authority.

    Where a facial image, selfie, liveness recording or biometric information is captured or generated, the relevant collection notice or consent process will explain how it is used, retained and disposed of. We use that information only for the relevant verification, fraud-prevention or security purpose, unless another use is permitted by law and any required consent has been obtained. We retain it only for the minimum period reasonably necessary for the permitted purpose, subject to any applicable legal, contractual or customer-configured requirement.

    We do not use or disclose identification information collected for DVS, identity verification or biometric verification to create a behavioural or marketing profile, track behaviour, offer or promote unrelated goods or services, conduct market research, enable online behavioural advertising or direct marketing, or for any other purpose prohibited by law, a collection notice, a consent process, a participation or gateway arrangement, or a supplier agreement.

    Some verification outputs, including match scores, bank match results, sanctions/PEP/adverse media results and automated screening results, are probabilistic or indicative. They are not legal, compliance, financial or credit advice. Our customers are responsible for making their own decisions using appropriate human review, risk assessment and legal/regulatory processes.

    Automated processing and human review. VeriEzi may use automated tools to perform document checks, biometric comparison, liveness checks, matching and screening. Automated results are indicators and are not intended to be the sole basis for a decision that produces legal or similarly significant effects for an individual. The customer that requested the service is responsible for appropriate human review, validation and lawful decision-making.

    Where a supplier agreement restricts storage of document images, selfies or biometric information unless expressly agreed, we will configure the relevant service and retention settings consistently with that restriction.

  8. Government Related Identifiers

    We may collect, use or disclose government related identifiers, including passport numbers, driver licence numbers, Medicare numbers or other identifiers, where this is reasonably necessary and permitted for identity verification, DVS, e-passport, TFN or other lawful checks.

    We do not adopt a government related identifier as our own identifier for an individual. We use and disclose government related identifiers only where permitted by law, required by a verification service, consented to where required, or otherwise authorised.

    Tax file numbers and other specially regulated identifiers are handled only for the limited purposes permitted by applicable law and the relevant service terms.

  9. ASIC, Experian and Company Search Information

    VeriEzi may provide or facilitate company, business and ASIC-related searches, including searches supplied through Experian, Simple KYC or other commercial data providers.

    We use this information only for the authorised purpose of providing VeriEzi services to our customers and supporting lawful due diligence, identity verification, business verification, onboarding, compliance, audit and reporting workflows.

    We do not resell, repackage, bulk extract or make Experian, ASIC-related or supplier-provided data available as a separate database or product except as expressly permitted by the relevant supplier agreement and applicable law.

    ASIC, company, commercial and supplier search information may contain personal information about individuals associated with an entity. We handle that personal information under this policy, the APPs and applicable supplier restrictions.

  10. Sanctions, PEP and Adverse Media Screening

    VeriEzi may facilitate sanctions, politically exposed person, relative/close associate and adverse media screening through ComplyAdvantage or other screening providers. These results may include personal information obtained from watchlists, public sources, media sources, commercial databases and supplier data.

    Screening results are provided for authorised compliance and risk assessment purposes. They are not conclusions, recommendations or determinations about a person. Customers should not make automatic decisions or adverse decisions based solely on a screening result without appropriate review, validation and lawful decision-making processes.

    Supplier data must not be used for unauthorised purposes such as pre-employment screening, consumer credit reporting, marketing, unlawful profiling, bulk extraction or public disclosure unless expressly permitted by the supplier agreement and law.

  11. Credit Reporting Information

    VeriEzi is not intended to be used to obtain consumer credit reports or consumer credit eligibility information unless a separate lawful product, authority, customer agreement and privacy notice apply.

    If we handle credit reporting information or credit eligibility information, we will do so in accordance with the Privacy Act, the Credit Reporting Code and any additional notices required at the time.

  12. Cookies, Analytics and Website Data

    Our website and platform may use cookies, analytics tools, log files and similar technologies to operate the site, keep sessions secure, remember preferences, analyse traffic, improve usability, detect fraud or misuse, and support customer service.

    Cookies may collect technical information such as IP address, device identifiers, browser type, pages visited, time spent on pages and referring links. If this information identifies or reasonably identifies a person, we handle it as personal information.

    You can usually control cookies through your browser settings. Some browsers or devices allow you to use privacy controls such as disabling cookies or sending tracking-preference signals. Some cookies are necessary for security, authentication or platform functionality and disabling them may affect the service.

    Where we use a third-party analytics, cookie or similar technology provider, technical and usage information may be disclosed to that provider for the purposes described above and will be handled under this policy and applicable supplier arrangements.

  13. Who We Disclose Personal Information To

    We may disclose personal information to:

    • our business customers and their authorised users, including the organisation that requested the relevant verification, search, screening or report;
    • identity verification, DVS, biometric, document verification, bank verification, TFN verification, sanctions/PEP/adverse media, ASIC, company search, commercial data and other supplier services;
    • gateway providers, document issuers, official record holders, government agencies, registries or public authorities where required for the requested service;
    • government agencies, regulators, law enforcement bodies, courts, tribunals and dispute-resolution bodies where required or authorised by law;
    • technology, cloud hosting, security, support, payment, analytics, communication and professional service providers who help us operate VeriEzi;
    • integration partners and connected platforms where a customer uses those integrations to request or receive VeriEzi services;
    • related bodies corporate, contractors and personnel who need the information for authorised business purposes and are subject to confidentiality obligations;
    • professional advisers, insurers, auditors and prospective purchasers or investors in connection with business, corporate or financing transactions; and
    • other persons where the individual has consented or where disclosure is otherwise required or permitted by law.

    Where we use service providers, suppliers, contractors or integration partners to help provide VeriEzi, we take reasonable steps to require them to handle personal information only for authorised purposes and to protect it consistently with the Privacy Act, our contracts and any applicable supplier terms.

    Information about material service providers, sub-processors and processing locations used to deliver VeriEzi is available on request from our Privacy Officer. Where required by law or contract, we will take reasonable steps to notify affected customers of a material change to those providers or locations.

    We do not sell personal information. We do not disclose supplier data, Experian data, ComplyAdvantage data, ASIC-related data or verification results for unrelated marketing or unauthorised third-party use.

  14. Overseas Disclosures

    Some VeriEzi services may involve disclosure of personal information to overseas recipients, including suppliers, cloud service providers, related bodies corporate or third-party data sources. The countries may include Singapore, the United Kingdom, countries in the European Economic Area, New Zealand, the United States and any other country notified in a workflow-specific notice or required for a particular third-party service.

    Where we disclose personal information overseas, we will take reasonable steps required by APP 8 to ensure the overseas recipient handles the information consistently with the APPs, unless an exception applies.

    Some services or customer arrangements may require particular categories of information to be stored and processed only in Australia. Where such a restriction applies, we will configure the relevant service accordingly.

  15. Storage, Security and Privacy Governance

    We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These steps may include:

    • role-based access controls and authorised-user restrictions;
    • secure authentication and credential management;
    • encryption or secure transfer mechanisms where appropriate;
    • logging, monitoring and audit trails;
    • staff training and confidentiality obligations;
    • supplier, sub-processor and contractor controls;
    • security incident response processes;
    • access reviews and removal of access when no longer required; and
    • secure deletion or de-identification processes where information is no longer needed.

    We do not make any public claim in this policy that VeriEzi is certified to a particular security standard unless that claim is separately verified and approved for publication.

  16. Data Breaches

    If we become aware of a suspected or actual data breach, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme, the Privacy Act, our customer contracts and supplier agreements.

    Where required, we will notify affected individuals and the Office of the Australian Information Commissioner. We may also be required to notify customers, suppliers, regulators or other parties within timeframes set by contract or law, including the Attorney-General's Department or a DVS gateway provider where the applicable DVS access arrangement requires notification.

  17. Retention and Deletion

    We retain personal information for as long as reasonably necessary for the purposes for which it was collected, including to provide VeriEzi services, maintain reports and audit trails, comply with legal and contractual obligations, resolve disputes, support security and fraud prevention, and meet customer or regulator requirements.

    We distinguish between full copies or images of identity documents, selfies, liveness/video/audio recordings and biometric material, and verification records such as relevant document fields, reports, outcomes, risk records, transaction records and audit logs. Full copies and biometric material are retained only for the minimum period reasonably necessary for verification, fraud and security controls, a customer-configured lawful purpose, dispute resolution, or another legal or contractual obligation, after which we take reasonable steps to destroy or de-identify them.

    Where VeriEzi holds information for a customer subject to the reformed AML/CTF framework, the AML/CTF Act does not itself require a scanned or photocopied identity document collected under the new framework to be retained merely as an AML/CTF record. Different requirements may apply to documents collected before the relevant commencement date, or where another law or permitted purpose requires retention.

    Verification metadata, reports, outcomes, records of the identification and verification steps taken, risk assessments and audit trails may be retained for the period required by applicable AML/CTF, VOI, conveyancing, professional, contractual or dispute-resolution obligations. Where a seven-year period applies, it applies to the records and evidence required by the relevant obligation and does not automatically require every source document image, selfie, recording or biometric record to be retained for seven years.

    Where a supplier agreement restricts storage of document images, selfies, biometric information or supplier data, we will retain that information only as permitted by the supplier agreement and law.

    When personal information is no longer needed for any purpose permitted under the APPs, and we are not required by law or court/tribunal order to retain it, we will take reasonable steps to destroy or deidentify it.

    If personal information cannot immediately be removed from a backup or archive for technical reasons, we will take reasonable steps to place it beyond use, restrict access and prevent further active processing, and delete or overwrite it in accordance with the applicable backup cycle, unless restoration or continued retention is required or permitted by law.

  18. Accuracy, Access and Correction

    We take reasonable steps to ensure personal information we collect, use and disclose is accurate, up to date, complete and relevant, having regard to the purpose of use or disclosure.

    Individuals may request access to personal information we hold about them or ask us to correct it. We may need to verify identity before responding. We will respond within a reasonable period and in accordance with the Privacy Act.

    We do not charge a fee to make an access or correction request. We may charge a reasonable fee for giving access where the Privacy Act allows. If we refuse access or correction, we will explain why where reasonable and lawful. If we refuse to correct information, you may ask us to associate a statement noting that you consider it inaccurate, out of date, incomplete, irrelevant or misleading.

    In some cases, we may need to refer a request to the VeriEzi customer that requested the relevant verification, search, screening or report, or to a supplier that provided the information. We will explain where this applies.

    We cannot amend records held by a government agency, document issuer, ASIC, a registry, Experian, ComplyAdvantage or another independent data source. If an official record or third-party source record appears incorrect, the individual may need to contact that record holder directly. We can, where appropriate, correct information we hold, rerun a check using corrected input data, or help identify the likely source of a mismatch.

  19. Marketing Communications

    We may use business contact information to send information about VeriEzi products, services, updates, events or offers where permitted by law. Individuals can opt out of marketing communications at any time by using the unsubscribe function or contacting us.

    We do not use sensitive verification information, biometric information, identity documents, DVS information, supplier search results or screening results for unrelated direct marketing, behavioural advertising or profiling.

  20. Anonymity and Pseudonymity

    Individuals may deal with us anonymously or using a pseudonym where this is lawful and practicable. However, anonymity or pseudonymity will usually not be practicable for identity verification, VOI, DVS, ASIC/company search, customer due diligence, screening, account administration, support, dispute handling or legal compliance purposes.

  21. Changes to This Policy

    We may update this Privacy Policy from time to time. The updated version will be published on our website or otherwise made available. If changes are material, we will take reasonable steps to bring them to the attention of affected customers or users.

  22. Complaints

    If you have a privacy concern or complaint, please contact us using the details below. Please provide your contact details, enough information for us to understand the issue, and the outcome you are seeking.

    We aim to acknowledge privacy complaints within 5 business days and provide a substantive response within 30 calendar days. If we need more time, we will let you know. If you are not satisfied with our response, you may ask for the matter to be escalated for further internal review.

    If you remain dissatisfied, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au. If your complaint relates to the operation or management of the DVS Hub, you may also contact ID Match or the Attorney-General's Department through www.idmatch.gov.au or www.ag.gov.au. If it relates to another registry, issuing authority or supplier service, we may direct you to that organisation's complaint pathway.

  23. Product Analytics

    We use PostHog (PostHog, Inc.), a third-party analytics service, to understand how signed-in users use the VeriEzi platform so we can maintain and improve it. PostHog receives limited usage information only: pages visited and actions taken within the platform, time of use, device and browser type, IP address, and a pseudonymous user identifier with the user's role and organisation identifier. We do not send PostHog any names, email addresses, identity documents, photographs, questionnaire answers, screening results or other client file content, and analytics is not active on the pages our customers' clients use to complete identity verification or questionnaires. This usage information is stored on PostHog's servers in the United States. We take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. See Privacy policy, PostHog style for PostHog's privacy policy.

  24. Contact Us

    Email: support@veriezi.com.au

    Website: https://veriezi.com.au