Last Updated: 9 September 2026
© 2026 VeriEzi, a product of Dingo Devs Pty Ltd. All rights reserved.
This policy applies to personal information we collect and handle through the VeriEzi platform, our website, customer onboarding and support, supplier-integrated verification services, APIs and related communications.
It applies to personal information about:
VeriEzi is designed for business use. It is not intended for children. We do not knowingly collect personal information from children through the platform unless this is required for a lawful customer workflow and appropriate authority, notice and consent have been obtained.
The kinds of personal information we collect depend on the VeriEzi product or workflow used. We may collect:
Some of this information may be sensitive information under the Privacy Act, including biometric information used for automated biometric verification, biometric templates, health-related information that appears on a document, racial or ethnic information that may be inferred from an image or document, criminal history or screening-related information, and tax file numbers. We only collect sensitive information where we have consent or another lawful basis to do so.
We collect personal information:
We will generally collect personal information directly from the individual where it is reasonable and practicable to do so. In some workflows, it is necessary for a customer or supplier to provide personal information to us so that we can deliver the requested verification, search, screening or reporting service.
If a customer or authorised user provides us with personal information about another person, they must ensure they have the authority to do so, have given any required privacy notice, have obtained any required consent or authorisation, and have taken reasonable steps to ensure the information is accurate, complete and up to date.
When a customer initiates a verification, search, screening or reporting workflow, VeriEzi generally handles the information to deliver that service on the customer's instructions. The customer determines the purpose of the workflow and remains responsible for ensuring that its request is lawful and that required notices, consents and authorities have been provided or obtained.
VeriEzi determines how and why personal information is handled for its own platform administration, account management, billing, support, security, fraud prevention, service improvement, legal compliance, audit and dispute-resolution activities. This distinction does not limit an individual's rights under the Privacy Act.
If we receive personal information that we did not request, we will decide within a reasonable period whether we could have collected it under the APPs. If we could not have collected it, and it is lawful and reasonable to do so, we will destroy or de-identify it.
We collect, use and disclose personal information for purposes reasonably necessary for VeriEzi's functions and activities, including to:
Australian privacy law does not use a separate overseas-style 'legal basis' framework. For Australian privacy purposes, we rely on the Privacy Act and APPs, including collection where reasonably necessary for our functions or activities, consent where required, and other permissions or requirements under Australian law.
Before using a verification, biometric, DVS, e-passport, TFN, screening or similar service, the individual may be asked to read a collection notice and give consent or authorisation. Depending on the service, this may include consent to:
Where express consent is required, it must be voluntary, informed, current, specific and unambiguous. We do not infer express consent from silence, a failure to opt out or a pre-selected choice. Before a DVS request, the individual will be told what identification information is proposed to be collected, why it is required, how it will be used and disclosed, how any facial image will be used, retained and disposed of, the consequences of declining, the relevant legal obligations and rights, and how to make a privacy complaint.
If required information or consent is not provided, or if a verification service returns a non-match, inconclusive or adverse result, we may not be able to complete the verification, search, screening, report, customer onboarding or support activity. A customer may need to use an alternative verification or review process.
Where consent is withdrawn, the withdrawal will not affect handling that occurred before withdrawal, but it may affect our ability or a customer's ability to continue the relevant service or workflow.
VeriEzi may use third-party verification services to compare identity information against independent data sources. This may include document verification, DVS checks, e-passport checks, liveness detection, facial comparison, bank account matching, TFN verification and other identity-related checks.
Where the Australian Government's DVS or a similar official-document check is used, selected identity document fields are transmitted through an authorised gateway or service provider to the DVS Hub or other relevant official record holder. The issuing authority normally returns a match or non-match response. VeriEzi does not receive a copy of the underlying government record from the issuing authority.
Where a facial image, selfie, liveness recording or biometric information is captured or generated, the relevant collection notice or consent process will explain how it is used, retained and disposed of. We use that information only for the relevant verification, fraud-prevention or security purpose, unless another use is permitted by law and any required consent has been obtained. We retain it only for the minimum period reasonably necessary for the permitted purpose, subject to any applicable legal, contractual or customer-configured requirement.
We do not use or disclose identification information collected for DVS, identity verification or biometric verification to create a behavioural or marketing profile, track behaviour, offer or promote unrelated goods or services, conduct market research, enable online behavioural advertising or direct marketing, or for any other purpose prohibited by law, a collection notice, a consent process, a participation or gateway arrangement, or a supplier agreement.
Some verification outputs, including match scores, bank match results, sanctions/PEP/adverse media results and automated screening results, are probabilistic or indicative. They are not legal, compliance, financial or credit advice. Our customers are responsible for making their own decisions using appropriate human review, risk assessment and legal/regulatory processes.
Automated processing and human review. VeriEzi may use automated tools to perform document checks, biometric comparison, liveness checks, matching and screening. Automated results are indicators and are not intended to be the sole basis for a decision that produces legal or similarly significant effects for an individual. The customer that requested the service is responsible for appropriate human review, validation and lawful decision-making.
Where a supplier agreement restricts storage of document images, selfies or biometric information unless expressly agreed, we will configure the relevant service and retention settings consistently with that restriction.
We may collect, use or disclose government related identifiers, including passport numbers, driver licence numbers, Medicare numbers or other identifiers, where this is reasonably necessary and permitted for identity verification, DVS, e-passport, TFN or other lawful checks.
We do not adopt a government related identifier as our own identifier for an individual. We use and disclose government related identifiers only where permitted by law, required by a verification service, consented to where required, or otherwise authorised.
Tax file numbers and other specially regulated identifiers are handled only for the limited purposes permitted by applicable law and the relevant service terms.
VeriEzi may provide or facilitate company, business and ASIC-related searches, including searches supplied through Experian, Simple KYC or other commercial data providers.
We use this information only for the authorised purpose of providing VeriEzi services to our customers and supporting lawful due diligence, identity verification, business verification, onboarding, compliance, audit and reporting workflows.
We do not resell, repackage, bulk extract or make Experian, ASIC-related or supplier-provided data available as a separate database or product except as expressly permitted by the relevant supplier agreement and applicable law.
ASIC, company, commercial and supplier search information may contain personal information about individuals associated with an entity. We handle that personal information under this policy, the APPs and applicable supplier restrictions.
VeriEzi may facilitate sanctions, politically exposed person, relative/close associate and adverse media screening through ComplyAdvantage or other screening providers. These results may include personal information obtained from watchlists, public sources, media sources, commercial databases and supplier data.
Screening results are provided for authorised compliance and risk assessment purposes. They are not conclusions, recommendations or determinations about a person. Customers should not make automatic decisions or adverse decisions based solely on a screening result without appropriate review, validation and lawful decision-making processes.
Supplier data must not be used for unauthorised purposes such as pre-employment screening, consumer credit reporting, marketing, unlawful profiling, bulk extraction or public disclosure unless expressly permitted by the supplier agreement and law.
VeriEzi is not intended to be used to obtain consumer credit reports or consumer credit eligibility information unless a separate lawful product, authority, customer agreement and privacy notice apply.
If we handle credit reporting information or credit eligibility information, we will do so in accordance with the Privacy Act, the Credit Reporting Code and any additional notices required at the time.
Our website and platform may use cookies, analytics tools, log files and similar technologies to operate the site, keep sessions secure, remember preferences, analyse traffic, improve usability, detect fraud or misuse, and support customer service.
Cookies may collect technical information such as IP address, device identifiers, browser type, pages visited, time spent on pages and referring links. If this information identifies or reasonably identifies a person, we handle it as personal information.
You can usually control cookies through your browser settings. Some browsers or devices allow you to use privacy controls such as disabling cookies or sending tracking-preference signals. Some cookies are necessary for security, authentication or platform functionality and disabling them may affect the service.
Where we use a third-party analytics, cookie or similar technology provider, technical and usage information may be disclosed to that provider for the purposes described above and will be handled under this policy and applicable supplier arrangements.
We may disclose personal information to:
Where we use service providers, suppliers, contractors or integration partners to help provide VeriEzi, we take reasonable steps to require them to handle personal information only for authorised purposes and to protect it consistently with the Privacy Act, our contracts and any applicable supplier terms.
Information about material service providers, sub-processors and processing locations used to deliver VeriEzi is available on request from our Privacy Officer. Where required by law or contract, we will take reasonable steps to notify affected customers of a material change to those providers or locations.
We do not sell personal information. We do not disclose supplier data, Experian data, ComplyAdvantage data, ASIC-related data or verification results for unrelated marketing or unauthorised third-party use.
Some VeriEzi services may involve disclosure of personal information to overseas recipients, including suppliers, cloud service providers, related bodies corporate or third-party data sources. The countries may include Singapore, the United Kingdom, countries in the European Economic Area, New Zealand, the United States and any other country notified in a workflow-specific notice or required for a particular third-party service.
Where we disclose personal information overseas, we will take reasonable steps required by APP 8 to ensure the overseas recipient handles the information consistently with the APPs, unless an exception applies.
Some services or customer arrangements may require particular categories of information to be stored and processed only in Australia. Where such a restriction applies, we will configure the relevant service accordingly.
We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. These steps may include:
We do not make any public claim in this policy that VeriEzi is certified to a particular security standard unless that claim is separately verified and approved for publication.
If we become aware of a suspected or actual data breach, we will assess and respond to it in accordance with the Notifiable Data Breaches scheme, the Privacy Act, our customer contracts and supplier agreements.
Where required, we will notify affected individuals and the Office of the Australian Information Commissioner. We may also be required to notify customers, suppliers, regulators or other parties within timeframes set by contract or law, including the Attorney-General's Department or a DVS gateway provider where the applicable DVS access arrangement requires notification.
We retain personal information for as long as reasonably necessary for the purposes for which it was collected, including to provide VeriEzi services, maintain reports and audit trails, comply with legal and contractual obligations, resolve disputes, support security and fraud prevention, and meet customer or regulator requirements.
We distinguish between full copies or images of identity documents, selfies, liveness/video/audio recordings and biometric material, and verification records such as relevant document fields, reports, outcomes, risk records, transaction records and audit logs. Full copies and biometric material are retained only for the minimum period reasonably necessary for verification, fraud and security controls, a customer-configured lawful purpose, dispute resolution, or another legal or contractual obligation, after which we take reasonable steps to destroy or de-identify them.
Where VeriEzi holds information for a customer subject to the reformed AML/CTF framework, the AML/CTF Act does not itself require a scanned or photocopied identity document collected under the new framework to be retained merely as an AML/CTF record. Different requirements may apply to documents collected before the relevant commencement date, or where another law or permitted purpose requires retention.
Verification metadata, reports, outcomes, records of the identification and verification steps taken, risk assessments and audit trails may be retained for the period required by applicable AML/CTF, VOI, conveyancing, professional, contractual or dispute-resolution obligations. Where a seven-year period applies, it applies to the records and evidence required by the relevant obligation and does not automatically require every source document image, selfie, recording or biometric record to be retained for seven years.
Where a supplier agreement restricts storage of document images, selfies, biometric information or supplier data, we will retain that information only as permitted by the supplier agreement and law.
When personal information is no longer needed for any purpose permitted under the APPs, and we are not required by law or court/tribunal order to retain it, we will take reasonable steps to destroy or deidentify it.
If personal information cannot immediately be removed from a backup or archive for technical reasons, we will take reasonable steps to place it beyond use, restrict access and prevent further active processing, and delete or overwrite it in accordance with the applicable backup cycle, unless restoration or continued retention is required or permitted by law.
We take reasonable steps to ensure personal information we collect, use and disclose is accurate, up to date, complete and relevant, having regard to the purpose of use or disclosure.
Individuals may request access to personal information we hold about them or ask us to correct it. We may need to verify identity before responding. We will respond within a reasonable period and in accordance with the Privacy Act.
We do not charge a fee to make an access or correction request. We may charge a reasonable fee for giving access where the Privacy Act allows. If we refuse access or correction, we will explain why where reasonable and lawful. If we refuse to correct information, you may ask us to associate a statement noting that you consider it inaccurate, out of date, incomplete, irrelevant or misleading.
In some cases, we may need to refer a request to the VeriEzi customer that requested the relevant verification, search, screening or report, or to a supplier that provided the information. We will explain where this applies.
We cannot amend records held by a government agency, document issuer, ASIC, a registry, Experian, ComplyAdvantage or another independent data source. If an official record or third-party source record appears incorrect, the individual may need to contact that record holder directly. We can, where appropriate, correct information we hold, rerun a check using corrected input data, or help identify the likely source of a mismatch.
We may use business contact information to send information about VeriEzi products, services, updates, events or offers where permitted by law. Individuals can opt out of marketing communications at any time by using the unsubscribe function or contacting us.
We do not use sensitive verification information, biometric information, identity documents, DVS information, supplier search results or screening results for unrelated direct marketing, behavioural advertising or profiling.
Individuals may deal with us anonymously or using a pseudonym where this is lawful and practicable. However, anonymity or pseudonymity will usually not be practicable for identity verification, VOI, DVS, ASIC/company search, customer due diligence, screening, account administration, support, dispute handling or legal compliance purposes.
We may update this Privacy Policy from time to time. The updated version will be published on our website or otherwise made available. If changes are material, we will take reasonable steps to bring them to the attention of affected customers or users.
If you have a privacy concern or complaint, please contact us using the details below. Please provide your contact details, enough information for us to understand the issue, and the outcome you are seeking.
We aim to acknowledge privacy complaints within 5 business days and provide a substantive response within 30 calendar days. If we need more time, we will let you know. If you are not satisfied with our response, you may ask for the matter to be escalated for further internal review.
If you remain dissatisfied, you may contact the Office of the Australian Information Commissioner at www.oaic.gov.au. If your complaint relates to the operation or management of the DVS Hub, you may also contact ID Match or the Attorney-General's Department through www.idmatch.gov.au or www.ag.gov.au. If it relates to another registry, issuing authority or supplier service, we may direct you to that organisation's complaint pathway.
We use PostHog (PostHog, Inc.), a third-party analytics service, to understand how signed-in users use the VeriEzi platform so we can maintain and improve it. PostHog receives limited usage information only: pages visited and actions taken within the platform, time of use, device and browser type, IP address, and a pseudonymous user identifier with the user's role and organisation identifier. We do not send PostHog any names, email addresses, identity documents, photographs, questionnaire answers, screening results or other client file content, and analytics is not active on the pages our customers' clients use to complete identity verification or questionnaires. This usage information is stored on PostHog's servers in the United States. We take reasonable steps to ensure it is handled consistently with the Australian Privacy Principles. See Privacy policy, PostHog style for PostHog's privacy policy.
Email: support@veriezi.com.au
Website: https://veriezi.com.au