On this page
- 01Who this statement covers
- 02Information we collect
- 03How information is collected
- 04Why information is used
- 05Website, forms and cookies
- 06Client files and AML evidence
- 07Use of artificial intelligence
- 08Who information may be shared with
- 09Overseas storage and processing
- 10How information is protected
- 11How long information is kept
- 12Access and correction
- 13Privacy and security incidents
- 14Questions and complaints
- 15Changes to this statement
Who this statement covers
This statement explains how the businesses trading as Seamless AML collect, use, disclose, store and dispose of personal information. The Australian and New Zealand businesses are separate companies under common ownership. The company responsible for an engagement will be named in the proposal, invoice or engagement letter.
In this statement, Seamless AML, we, us and our refer to the relevant Seamless AML company and, where the context requires, both companies. Each company is responsible for the information it holds.
This statement covers this website, enquiries and Seamless AML consulting work, including independent AML reviews, audits and evaluations, risk assessments, programmes or programs, remediation and advisory work. AskAML is a separate product and is governed by its own published terms and privacy information.
Information we collect
The information collected depends on how you deal with us. Only information that is reasonably needed for a lawful business purpose should be collected.
- Enquiries
- Your name, work email, phone number, organisation, sector, service needs, timing, entity and record counts, and any context you choose to provide.
- Client administration
- Contact details, proposals, signed terms, instructions, meeting notes, correspondence, invoices, payment status and conflict-check information.
- AML engagement material
- Risk assessments, programmes or programs, policies, procedures, registers, training records, governance records, working papers and selected customer due diligence material supplied for review or testing.
- People in client records
- Names, contact details, dates of birth, roles, ownership information, identity and verification evidence, risk information and transaction information where this is included in material lawfully provided by a client.
- Technical information
- IP address, device and browser details, request times, security logs, referring pages and an approximate country derived by the website host.
- Business relationships
- Information about suppliers, contractors, professional advisers, prospective team members and other business contacts.
How information is collected
Information may be collected from you through the website, email, phone or video calls, proposals, meetings, shared folders and work completed during an engagement. It may also be received from your organisation, its staff, professional advisers, related companies or public records.
Much of the personal information reviewed during AML work is supplied by the client rather than by the person it concerns. The client must have lawful authority to provide it and must give any notice required by law. We may ask for evidence that this has been done.
New Zealand indirect collection
From 1 May 2026, Information Privacy Principle 3A may require reasonable steps to be taken after personal information has been collected from someone other than the individual. Unless an exception applies, the individual must be told about the collection, its purpose, intended recipients, the collecting and holding agency, any law authorising or requiring the collection, and their access and correction rights.
Where practical, the client will be asked to give this notice on behalf of Seamless AML before records are supplied. Seamless AML may give notice itself where that is more suitable. A legal exception may be relied on where notice would prejudice the purpose of the work, the person has already been told, or another exception applies.
Why information is used
Personal information may be used to:
- respond to enquiries and decide whether work can be accepted
- prepare a proposal, check conflicts and manage the client relationship
- plan, perform, document and review the agreed AML work
- test selected records and controls, record evidence and support findings
- prepare reports, risk assessments, programmes, programs, advice and other deliverables
- communicate with the client, its advisers and a regulator where authorised
- issue invoices, keep accounting records and recover unpaid amounts
- protect the website, shared folders, email and other systems
- meet legal, regulatory, insurance and professional obligations
- manage complaints, claims, legal holds and disputes
- improve internal methods using information that has been de-identified where practical
Information will not be sold. It will not be used for unrelated direct marketing. A follow-up may be sent about an enquiry or existing client service, and you may ask for that contact to stop.
Client files and AML evidence
A separate Dropbox folder may be used for each client. Casey Marsh has direct access to the main client-data Dropbox. Access to a client folder is shared only with the client users nominated for that engagement. If a specialist needs to assist, only the minimum information needed will be shared and it will be de-identified where practical. Confidentiality duties will apply.
Clients should supply only the material requested and should remove information that is not needed. Original statutory records must remain under the client's control. Seamless AML does not become the client's statutory archive merely because a copy is reviewed.
Use of artificial intelligence
Approved AI tools may be used to assist with source research, drafting, structure, reference and consistency checks, comparison of working papers with source documents, and suggestions for possible ratings or findings. AI may also help design a sample-selection method. Sample selection from an identifiable client list must be completed locally using coded or anonymised identifiers.
AI output is treated as working material. It is checked against the source evidence and relevant law by a person with suitable experience. A finding, rating or professional conclusion will not be issued on the sole decision of an AI system.
- Personal or sensitive client information is not authorised for use in consumer AI accounts.
- Approved business or API services must be assessed for data use, retention, security, subprocessors, location and contractual protection.
- Information must be reduced, coded or de-identified before AI use where practical.
- Client information must not be used to train a general AI model for other customers.
- Identity documents, authentication data, full CDD files, SARs and SMRs must not be entered into AI.
- A record will be kept where AI materially assists an engagement, including its purpose and the human checks completed.
A client may ask for no AI to be used by telling us before the engagement begins. The scope, timing or fee may need to be changed. A later request will be treated as a change to the engagement.
Who information may be shared with
Information may be disclosed only where it is reasonably needed for the purposes described in this statement, where you have authorised it, or where disclosure is required or permitted by law. Recipients may include:
- the relevant Seamless AML company and authorised personnel
- the client and client users nominated for a shared folder
- Dropbox for secure file storage and exchange
- Google Workspace and Gmail for business email and documents
- Xero for contacts, invoices and accounting records
- approved video meeting, website hosting, security and IT providers
- approved AI providers where the controls in this statement and the Client Data and AI Schedule have been met
- lawyers, accountants, insurers and other professional advisers
- regulators, courts, law enforcement bodies or public authorities where disclosure is authorised or required
Service providers are expected to handle information only for the agreed service and under suitable confidentiality, privacy and security terms. Providers may change as systems are reviewed. You may ask for the current list relevant to an engagement.
Overseas storage and processing
Cloud and technology providers may store or process information in Australia, New Zealand, the United States and other countries where they or their subprocessors operate. The location may depend on the service plan and configuration in use.
Before personal information is disclosed overseas, reasonable steps will be taken to assess the recipient and put suitable contractual or other safeguards in place. Where a provider acts only as an agent storing or processing information under our control, responsibility for that information is retained by Seamless AML as required by law.
New Zealand disclosures will be assessed against Information Privacy Principle 12. Australian disclosures will be assessed against controls based on Australian Privacy Principle 8 where practical and against that principle where it applies.
How information is protected
Safeguards are selected in light of the sensitivity and amount of information held. Measures may include multi-factor authentication, restricted folders, least-privilege access, device security, encrypted services, confidential transfer instructions, access review, secure disposal and incident response.
No internet or storage system can be promised to be risk-free. Clients must protect their own accounts, use approved sharing links, check recipients and tell us at once if access should be removed or if a security concern is found.
How long information is kept
Information is kept only for as long as it is reasonably needed for the engagement, legal obligations, professional accountability, insurance, disputes or another lawful purpose.
- Raw audit and CDD samples
- Normally deleted within 90 days after the final report or final deliverable is issued.
- Core engagement file
- Normally kept for seven years after the engagement ends. This may include the proposal, terms, key correspondence, methodology, material working papers, results, findings, final deliverables, invoices and evidence of review.
- Enquiries not accepted
- Normally kept for no more than 24 months after the last contact.
- Website preference cookies
- The market and analytics opt-out preferences are kept on the device for up to 180 days unless removed sooner. Eligible advertising click references are kept for no more than 90 days.
A legal hold, complaint, claim, regulator request or insurer requirement may require information to be kept for longer. Backups may retain deleted data for a limited period until they are overwritten. The client's own five-year New Zealand or seven-year Australian AML record duties are not reduced by our deletion timetable.
Access and correction
You may ask whether personal information about you is held and may request access to or correction of it. A request should be sent to the Privacy Officer at casey@seamlessaml.com. Enough detail should be provided to identify you and the information concerned.
Identity may need to be checked before information is released. A request may be refused or limited where the law allows, including where disclosure would affect another person, reveal confidential or legally privileged material, prejudice an investigation or reveal protected SAR or SMR information. Reasons will be given where required.
New Zealand requests will be handled within the time required by the Privacy Act 2020. Australian requests will normally be answered within 30 calendar days where practical.
Privacy and security incidents
Suspected loss, unauthorised access, disclosure, alteration or destruction of personal information will be contained, assessed and documented. Affected clients will be told where the incident concerns their information and notification is required or is needed to reduce harm.
In New Zealand, a breach that has caused or is likely to cause serious harm will be notified to the Privacy Commissioner and affected people as soon as practicable, unless an exception applies. In Australia, the Notifiable Data Breaches scheme will be followed where it applies. Similar steps may be taken voluntarily where the Australian company is exempt.
Questions and complaints
Questions, access requests and privacy complaints should be sent to the Privacy Officer at casey@seamlessaml.com. The concern, the information involved and the outcome sought should be described. The complaint will be acknowledged and reviewed.
If a New Zealand complaint is not resolved, it may be taken to the Office of the Privacy Commissioner. If the Australian Privacy Act applies, a complaint may be taken to the Office of the Australian Information Commissioner. These rights are not limited by this statement.
Changes to this statement
This statement may be updated when our services, providers, practices or legal duties change. The current version and its effective date will be published on this website. A material change affecting an active engagement will also be raised with the client where required.
Related documents