Skip to content
View all servicesIndependent AML/CTF evaluationML/TF risk assessment + AML/CTF programRemediation and advisory
ResourcesMeet the team
AustraliaAUNew ZealandNZ
Request a quote
Australia

Services

00View all services01Independent AML/CTF evaluation02ML/TF risk assessment + AML/CTF program03Remediation and advisory
ResourcesMeet the team
Switch to NZRequest a quote

Privacy • Australia

Privacy Statement

How personal information is collected, protected and used across Seamless AML’s Australian and New Zealand consulting work.

Applies from29 July 2026
MarketAustralia

At a glance

  • One statement covers the separate AU and NZ consulting businesses
  • Raw CDD samples are normally deleted 90 days after the final report
  • Identifiable client data is not authorised for consumer AI accounts
  • Privacy requests are handled through casey@seamlessaml.com

On this page

  1. 01Who this statement covers
  2. 02Information we collect
  3. 03How information is collected
  4. 04Why information is used
  5. 05Website, forms and cookies
  6. 06Client files and AML evidence
  7. 07Use of artificial intelligence
  8. 08Who information may be shared with
  9. 09Overseas storage and processing
  10. 10How information is protected
  11. 11How long information is kept
  12. 12Access and correction
  13. 13Privacy and security incidents
  14. 14Questions and complaints
  15. 15Changes to this statement
On this page
  1. 01Who this statement covers
  2. 02Information we collect
  3. 03How information is collected
  4. 04Why information is used
  5. 05Website, forms and cookies
  6. 06Client files and AML evidence
  7. 07Use of artificial intelligence
  8. 08Who information may be shared with
  9. 09Overseas storage and processing
  10. 10How information is protected
  11. 11How long information is kept
  12. 12Access and correction
  13. 13Privacy and security incidents
  14. 14Questions and complaints
  15. 15Changes to this statement
01

Who this statement covers

This statement explains how the businesses trading as Seamless AML collect, use, disclose, store and dispose of personal information. The Australian and New Zealand businesses are separate companies under common ownership. The company responsible for an engagement will be named in the proposal, invoice or engagement letter.

In this statement, Seamless AML, we, us and our refer to the relevant Seamless AML company and, where the context requires, both companies. Each company is responsible for the information it holds.

This statement covers this website, enquiries and Seamless AML consulting work, including independent AML reviews, audits and evaluations, risk assessments, programmes or programs, remediation and advisory work. AskAML is a separate product and is governed by its own published terms and privacy information.

Australian privacy position

The Australian company is currently a small business that may be exempt from the Privacy Act 1988. It has chosen to follow controls based on the Australian Privacy Principles where practical. If that Act or another privacy law applies, its legal requirements will prevail.

02

Information we collect

The information collected depends on how you deal with us. Only information that is reasonably needed for a lawful business purpose should be collected.

Enquiries
Your name, work email, phone number, organisation, sector, service needs, timing, entity and record counts, and any context you choose to provide.
Client administration
Contact details, proposals, signed terms, instructions, meeting notes, correspondence, invoices, payment status and conflict-check information.
AML engagement material
Risk assessments, programmes or programs, policies, procedures, registers, training records, governance records, working papers and selected customer due diligence material supplied for review or testing.
People in client records
Names, contact details, dates of birth, roles, ownership information, identity and verification evidence, risk information and transaction information where this is included in material lawfully provided by a client.
Technical information
IP address, device and browser details, request times, security logs, referring pages and an approximate country derived by the website host.
Business relationships
Information about suppliers, contractors, professional advisers, prospective team members and other business contacts.
Do not use enquiry forms for sensitive records

Customer records, identity documents, CDD samples and SAR or SMR information must not be pasted into a public website form. Secure transfer instructions will be given after an engagement is accepted.

03

How information is collected

Information may be collected from you through the website, email, phone or video calls, proposals, meetings, shared folders and work completed during an engagement. It may also be received from your organisation, its staff, professional advisers, related companies or public records.

Much of the personal information reviewed during AML work is supplied by the client rather than by the person it concerns. The client must have lawful authority to provide it and must give any notice required by law. We may ask for evidence that this has been done.

New Zealand indirect collection

From 1 May 2026, Information Privacy Principle 3A may require reasonable steps to be taken after personal information has been collected from someone other than the individual. Unless an exception applies, the individual must be told about the collection, its purpose, intended recipients, the collecting and holding agency, any law authorising or requiring the collection, and their access and correction rights.

Where practical, the client will be asked to give this notice on behalf of Seamless AML before records are supplied. Seamless AML may give notice itself where that is more suitable. A legal exception may be relied on where notice would prejudice the purpose of the work, the person has already been told, or another exception applies.

04

Why information is used

Personal information may be used to:

  • respond to enquiries and decide whether work can be accepted
  • prepare a proposal, check conflicts and manage the client relationship
  • plan, perform, document and review the agreed AML work
  • test selected records and controls, record evidence and support findings
  • prepare reports, risk assessments, programmes, programs, advice and other deliverables
  • communicate with the client, its advisers and a regulator where authorised
  • issue invoices, keep accounting records and recover unpaid amounts
  • protect the website, shared folders, email and other systems
  • meet legal, regulatory, insurance and professional obligations
  • manage complaints, claims, legal holds and disputes
  • improve internal methods using information that has been de-identified where practical

Information will not be sold. It will not be used for unrelated direct marketing. A follow-up may be sent about an enquiry or existing client service, and you may ask for that contact to stop.

05

Website, forms and cookies

Website enquiry forms send the details entered to a secured website database so that the request can be reviewed. Hosting and security providers may also keep request and security logs. Website data should be limited to the fields requested.

The site uses an approximate country signal supplied by Cloudflare to show the New Zealand version to visitors in New Zealand and the Australian version elsewhere. If you choose a market, a necessary cookie named seamless_market remembers that choice for up to 180 days. It is not used to advertise to you.

Website analytics

We use PostHog Cloud EU in cookieless mode to understand website usage, including pages visited, general traffic source, selected service or resource pages, and whether an enquiry was started or successfully submitted. Session replay is disabled. Broad form and element autocapture, surveys and exception capture are also disabled. We do not send enquiry form contents, names, email addresses, telephone numbers, business names or customer information to PostHog. Analytics data is processed in the European Union.

When an eligible Google ad leads to a saved enquiry, we may use a first-party advertising click reference for conversion measurement. Only the click reference, conversion time, enquiry type, market and an enquiry order number are sent through PostHog to Google; enquiry contents and contact details are not sent to Google. The advertising click reference and conversion information may be processed overseas by Google. The Disable analytics control in the website footer stops both cookieless website analytics and future advertising attribution on that browser.

06

Client files and AML evidence

A separate Dropbox folder may be used for each client. Casey Marsh has direct access to the main client-data Dropbox. Access to a client folder is shared only with the client users nominated for that engagement. If a specialist needs to assist, only the minimum information needed will be shared and it will be de-identified where practical. Confidentiality duties will apply.

Clients should supply only the material requested and should remove information that is not needed. Original statutory records must remain under the client's control. Seamless AML does not become the client's statutory archive merely because a copy is reviewed.

SAR and SMR information

Full New Zealand SAR registers and information that discloses the existence or content of an SAR must not be supplied. Restricted Australian SMR information must not be supplied unless its disclosure has been assessed as lawful and the transfer has been agreed in writing. SAR and SMR information must never be entered into an AI tool.

07

Use of artificial intelligence

Approved AI tools may be used to assist with source research, drafting, structure, reference and consistency checks, comparison of working papers with source documents, and suggestions for possible ratings or findings. AI may also help design a sample-selection method. Sample selection from an identifiable client list must be completed locally using coded or anonymised identifiers.

AI output is treated as working material. It is checked against the source evidence and relevant law by a person with suitable experience. A finding, rating or professional conclusion will not be issued on the sole decision of an AI system.

  • Personal or sensitive client information is not authorised for use in consumer AI accounts.
  • Approved business or API services must be assessed for data use, retention, security, subprocessors, location and contractual protection.
  • Information must be reduced, coded or de-identified before AI use where practical.
  • Client information must not be used to train a general AI model for other customers.
  • Identity documents, authentication data, full CDD files, SARs and SMRs must not be entered into AI.
  • A record will be kept where AI materially assists an engagement, including its purpose and the human checks completed.

A client may ask for no AI to be used by telling us before the engagement begins. The scope, timing or fee may need to be changed. A later request will be treated as a change to the engagement.

08

Who information may be shared with

Information may be disclosed only where it is reasonably needed for the purposes described in this statement, where you have authorised it, or where disclosure is required or permitted by law. Recipients may include:

  • the relevant Seamless AML company and authorised personnel
  • the client and client users nominated for a shared folder
  • Dropbox for secure file storage and exchange
  • Google Workspace and Gmail for business email and documents
  • Xero for contacts, invoices and accounting records
  • approved video meeting, website hosting, security and IT providers
  • approved AI providers where the controls in this statement and the Client Data and AI Schedule have been met
  • lawyers, accountants, insurers and other professional advisers
  • regulators, courts, law enforcement bodies or public authorities where disclosure is authorised or required

Service providers are expected to handle information only for the agreed service and under suitable confidentiality, privacy and security terms. Providers may change as systems are reviewed. You may ask for the current list relevant to an engagement.

09

Overseas storage and processing

Cloud and technology providers may store or process information in Australia, New Zealand, the United States and other countries where they or their subprocessors operate. The location may depend on the service plan and configuration in use.

Before personal information is disclosed overseas, reasonable steps will be taken to assess the recipient and put suitable contractual or other safeguards in place. Where a provider acts only as an agent storing or processing information under our control, responsibility for that information is retained by Seamless AML as required by law.

New Zealand disclosures will be assessed against Information Privacy Principle 12. Australian disclosures will be assessed against controls based on Australian Privacy Principle 8 where practical and against that principle where it applies.

10

How information is protected

Safeguards are selected in light of the sensitivity and amount of information held. Measures may include multi-factor authentication, restricted folders, least-privilege access, device security, encrypted services, confidential transfer instructions, access review, secure disposal and incident response.

No internet or storage system can be promised to be risk-free. Clients must protect their own accounts, use approved sharing links, check recipients and tell us at once if access should be removed or if a security concern is found.

11

How long information is kept

Information is kept only for as long as it is reasonably needed for the engagement, legal obligations, professional accountability, insurance, disputes or another lawful purpose.

Raw audit and CDD samples
Normally deleted within 90 days after the final report or final deliverable is issued.
Core engagement file
Normally kept for seven years after the engagement ends. This may include the proposal, terms, key correspondence, methodology, material working papers, results, findings, final deliverables, invoices and evidence of review.
Enquiries not accepted
Normally kept for no more than 24 months after the last contact.
Website preference cookies
The market and analytics opt-out preferences are kept on the device for up to 180 days unless removed sooner. Eligible advertising click references are kept for no more than 90 days.

A legal hold, complaint, claim, regulator request or insurer requirement may require information to be kept for longer. Backups may retain deleted data for a limited period until they are overwritten. The client's own five-year New Zealand or seven-year Australian AML record duties are not reduced by our deletion timetable.

12

Access and correction

You may ask whether personal information about you is held and may request access to or correction of it. A request should be sent to the Privacy Officer at casey@seamlessaml.com. Enough detail should be provided to identify you and the information concerned.

Identity may need to be checked before information is released. A request may be refused or limited where the law allows, including where disclosure would affect another person, reveal confidential or legally privileged material, prejudice an investigation or reveal protected SAR or SMR information. Reasons will be given where required.

New Zealand requests will be handled within the time required by the Privacy Act 2020. Australian requests will normally be answered within 30 calendar days where practical.

13

Privacy and security incidents

Suspected loss, unauthorised access, disclosure, alteration or destruction of personal information will be contained, assessed and documented. Affected clients will be told where the incident concerns their information and notification is required or is needed to reduce harm.

In New Zealand, a breach that has caused or is likely to cause serious harm will be notified to the Privacy Commissioner and affected people as soon as practicable, unless an exception applies. In Australia, the Notifiable Data Breaches scheme will be followed where it applies. Similar steps may be taken voluntarily where the Australian company is exempt.

14

Questions and complaints

Questions, access requests and privacy complaints should be sent to the Privacy Officer at casey@seamlessaml.com. The concern, the information involved and the outcome sought should be described. The complaint will be acknowledged and reviewed.

If a New Zealand complaint is not resolved, it may be taken to the Office of the Privacy Commissioner. If the Australian Privacy Act applies, a complaint may be taken to the Office of the Australian Information Commissioner. These rights are not limited by this statement.

15

Changes to this statement

This statement may be updated when our services, providers, practices or legal duties change. The current version and its effective date will be published on this website. A material change affecting an active engagement will also be raised with the client where required.

Related documents

Website termsEngagement termsClient data
casey@seamlessaml.com+61 423 472 666

Services

View all servicesIndependent AML/CTF evaluationML/TF risk assessment + AML/CTF programRemediation and advisory

Company

ResourcesGuidance and legislationMeet the team

Legal

Privacy statementWebsite termsEngagement termsClient data

© 2026 Seamless AML

Switch to
AustraliaAUNew ZealandNZ