Legal & Compliance

Privacy Policy

Four Foxes Consulting  ·  Effective date: 8 May 2026

01

Introduction

Four Foxes Consulting ("we", "us", "our") is committed to protecting personal information in accordance with the Privacy Act 1988.

This Privacy Policy explains how we collect, use, disclose and store personal information in connection with our services, including:

02

What Information We Collect

We may collect personal information including:

Identity & Verification Data

Contact Information

AML Screening Data

Technical & Usage Data

Sensitive Information

Some personal information we collect is classified as sensitive information under the Privacy Act 1988. This includes biometric information and biometric templates collected as part of identity verification, including facial images used for liveness detection and face matching.

We will only collect sensitive information where you have expressly consented to that collection, or where otherwise permitted by law. Sensitive information is handled with a higher standard of care and is used only for the purpose for which it was collected, unless you consent to another use or we are required or authorised by law to use it for another purpose.
03

How We Collect Information

We collect personal information:

Collection Notices

In addition to this Privacy Policy, we take reasonable steps to notify individuals about the collection of their personal information at or before the time of collection, in accordance with Australian Privacy Principle 5.

Where individuals are invited to complete an identity verification process via a link provided by one of our clients, a collection notice will be presented to that individual prior to or at the point of collection. That notice will describe:

This Privacy Policy should be read alongside any collection notice provided to you.

04

Purpose of Collection

We collect and use personal information to:

We provide information and tools to assist Clients, but we do not make compliance determinations on their behalf.

05

Disclosure of Personal Information

We may disclose personal information to:

Some of these providers may be located outside Australia.

06

Overseas Disclosure

Some of our third-party service providers are located outside Australia. As a result, personal information we hold may be disclosed to, processed by, or stored with recipients in overseas jurisdictions.

Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles that information in a manner consistent with the Australian Privacy Principles. These steps may include:

Where an overseas recipient is subject to a foreign law that requires or permits disclosure of personal information in circumstances that would not be permitted under the Privacy Act 1988, we will take reasonable steps to mitigate that risk.

We will update this section if our use of overseas providers changes materially.

07

Data Quality and Reliance

We rely on:

We do not guarantee that personal information or screening results are accurate, complete, or up to date. Our services provide information to support decision-making and must be independently assessed by the Client.
08

Data Security

We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access. This includes:

Notifiable Data Breaches

We are subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988.

If we become aware of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:

We maintain internal procedures for identifying, assessing and responding to data breaches. These procedures are reviewed periodically and align with our broader information security practices.

09

Data Retention

We retain personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, or as required by law. Retention periods vary depending on the nature of the information:

When personal information is no longer required and retention is not mandated by law, we take reasonable steps to destroy or de-identify it securely.

10

Access and Correction

Individuals may request access to or correction of their personal information by contacting us at:

Four Foxes Consulting
Email: aml@fourfoxes.com.au

We will respond within a reasonable time.

11

Complaints

If you have a concern or complaint about how we have handled your personal information, we encourage you to contact us in the first instance so we can attempt to resolve the matter.

We will acknowledge your complaint within five business days and aim to provide a substantive response within 30 days. Where a complaint is complex or requires further investigation, we will keep you informed of progress.

If you are not satisfied with our response, or if you have not received a response within a reasonable time, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner (OAIC)
Website: www.oaic.gov.au
Phone: 1300 363 992

12

Changes to this Policy

We may update this Privacy Policy from time to time. The latest version will be available on our website.

13

Contact

Four Foxes Consulting
Email: aml@fourfoxes.com.au
Website: www.fourfoxes.com.au