AMLyticsAI — Anti Money Laundering Software
  • Features
  • Regulators
  • Platform
  • Guide
  • FAQ
Back to site →
Legal

Privacy Policy

Last updated  1 July 2026 Operated by  Smart Resources QLD Jurisdiction  Australia

This Privacy Policy explains how Smart Resources QLD [Pty Ltd] (48659972273) (“Smart Resources QLD”, “we”, “us”, “our”), the operator of the AMLyticsAI platform (“AMLyticsAI”, the “Platform”), collects, holds, uses and discloses personal information, and how you can access, correct, or raise concerns about that information.

We are committed to handling personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs). Because AMLyticsAI is used by our business customers (“Customers”, “you” where referring to a Customer) to meet their own obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), this policy also explains how information is handled in that specific regulatory context.

On this page

  1. Scope of this Policy
  2. What Personal Information We Collect
  3. How We Collect Personal Information
  4. Why We Collect, Hold, Use and Disclose Personal Information
  5. Automated Decision-Making and AI-Driven Risk Scoring
  6. Direct Marketing
  7. Disclosure of Personal Information
  8. Data Quality and Security
  9. How Long We Retain Personal Information
  10. Access and Correction
  11. Children’s Privacy
  12. Cookies and Website Analytics
  13. How to Make a Complaint
  14. Changes to this Policy
  15. Contact Us

1Scope of this Policy

This Policy applies to:

  • personal information of individuals who work for, or represent, our Customers (e.g. account administrators, compliance officers, authorised users of the Platform);
  • personal information that our Customers input into, or that the Platform collects on their behalf, about their own customers and prospective customers (i.e. the individuals our Customers are conducting KYC/CDD, screening, and monitoring on) (“End Customers”); and
  • personal information of visitors to our website and prospective customers.

Where Smart Resources QLD processes End Customer information on behalf of a Customer for the purposes of that Customer’s AML/CTF Act obligations, we generally act as a service provider to the Customer. The Customer remains the entity responsible under the AML/CTF Act and the Privacy Act for the collection and primary handling of its End Customers’ personal information, including for providing its own privacy notices to End Customers. This Policy describes our own handling practices as the platform provider and processor.

2What Personal Information We Collect

Depending on how AMLyticsAI is used, we may collect:

Account and user information

Name, job title, business email address, phone number, employer/organisation details, login credentials, and role-based permissions for individuals who use the Platform on behalf of a Customer.

End Customer compliance information

Input by Customers or collected through integrated verification and screening services, which may include:

  • full name, date of birth, residential address, contact details;
  • identity document details (e.g. passport, driver’s licence, or other government-issued ID numbers and images);
  • occupation, source of funds/wealth, and business or beneficial ownership information;
  • politically exposed person (PEP) status and sanctions screening results;
  • transaction data and account activity relevant to AML/CTF monitoring;
  • risk ratings, alerts, case notes, and Suspicious Matter Report (SMR) workflow records generated through use of the Platform.

This category may include sensitive information as defined under the Privacy Act (for example, information revealing criminal record checks, or in some cases information that touches on health or other special categories where relevant to enhanced due diligence). We only collect sensitive information where it is reasonably necessary for our Customers’ AML/CTF compliance functions, or with consent, and we apply additional protections to it as described in Section 8.

Technical and usage information

IP address, device and browser information, log data, cookies, and analytics data collected when you use our website or Platform.

Billing and contact information

For Customer accounts, billing contacts, and prospective customers who contact us.

We do not knowingly collect more personal information than is reasonably necessary for the purposes described in this Policy, and we do not collect personal information from End Customers directly via marketing channels.

3How We Collect Personal Information

We collect personal information:

  • directly from Customers and their authorised users when they register for, configure, or use the Platform;
  • from Customers on behalf of their End Customers, as part of KYC/CDD onboarding and ongoing monitoring workflows configured by the Customer;
  • from third-party identity verification, document verification, PEP, and sanctions/watchlist screening providers integrated with the Platform, used to validate or enrich information already provided by the Customer;
  • automatically, through use of the website and Platform (cookies, log files, analytics tools); and
  • from publicly available sources, where relevant to sanctions, PEP, or adverse media screening functions.

Where it is unreasonable or impracticable to collect personal information about an End Customer directly from that individual (which is typically the case, as our direct relationship is with the Customer), we rely on the Customer to have provided appropriate notice and, where required, obtained consent from their End Customers in line with the Customer’s own privacy obligations.

4Why We Collect, Hold, Use and Disclose Personal Information

We collect, hold, use, and disclose personal information to:

  • provide, operate, maintain, and support the AMLyticsAI platform for Customers;
  • enable Customers to perform risk assessments, KYC/CDD onboarding, ongoing customer monitoring, transaction analysis, PEP and sanctions screening, and SMR reporting workflows in connection with their AML/CTF Act obligations;
  • generate AI-driven risk scores, alerts, and analytics to support (not replace) Customer compliance decision-making;
  • verify identity and screen against sanctions, PEP, and other relevant watchlists via integrated third-party data providers;
  • manage Customer accounts, provide customer support, and communicate with Customers about the Platform;
  • bill and process payments;
  • maintain records as required under the AML/CTF Act and other applicable law (see Section 9 on retention);
  • investigate and respond to actual or suspected fraud, misuse of the Platform, or security incidents;
  • improve, test, and develop the Platform, including its risk-scoring models, using de-identified or aggregated data wherever practicable; and
  • comply with our own legal and regulatory obligations, including responding to lawful requests from AUSTRAC, law enforcement, or other regulators.

We do not sell personal information to third parties, and we do not use End Customer personal information for our own direct marketing purposes.

5Automated Decision-Making and AI-Driven Risk Scoring

AMLyticsAI uses automated processes, including AI-driven models, to generate risk scores, flag transactions, and surface alerts for review by our Customers’ compliance staff. In line with recent amendments to the Privacy Act requiring transparency about substantially automated decision-making, we confirm:

  • Risk scores and alerts generated by the Platform are decision-support outputs, intended to inform — not replace — a human compliance decision made by the Customer (e.g. whether to onboard a customer, escalate a case, or file an SMR).
  • The factors that may inform automated risk scoring include, where applicable, transaction patterns, customer risk attributes, geographic and industry risk indicators, sanctions/PEP screening results, and behavioural indicators relevant to AML/CTF typologies.
  • Customers retain ultimate responsibility for any compliance decision made using Platform outputs, including final risk classifications and SMR determinations.
  • Individuals who believe an automated output significantly affecting them is inaccurate should raise this with the Customer (the reporting entity) in the first instance, who can in turn contact us for further information about how a particular score or alert was generated.

6Direct Marketing

We may use business contact information (e.g. of prospective Customers or existing Customer administrators) to send information about AMLyticsAI, updates, and relevant regulatory content. You can opt out of marketing communications at any time using the unsubscribe link in our emails, or by contacting us at reachus@smartresourcesqld.com.au. We do not use End Customer personal information for direct marketing.

7Disclosure of Personal Information

We may disclose personal information to:

  • AUSTRAC and other regulators, where a Customer uses the Platform to submit reports (such as SMRs), or where we are otherwise required or authorised by law to disclose information;
  • Third-party identity verification, document verification, and sanctions/PEP screening providers engaged to deliver core Platform functionality (these providers act under contractual obligations consistent with this Policy);
  • Cloud hosting and infrastructure providers who store and process data on our behalf, under appropriate contractual security and confidentiality obligations;
  • Professional advisers (legal, audit, insurance) where reasonably necessary for our business operations;
  • Law enforcement or government bodies, where required or authorised by law; and
  • A purchaser, in the event of a sale, merger, or restructure of our business, subject to that party agreeing to handle personal information consistently with this Policy.

8Data Quality and Security

We take reasonable steps to ensure personal information we hold is accurate, complete, and up to date, including by allowing Customers to correct information within the Platform.

We protect personal information using a combination of technical and organisational measures appropriate to the sensitivity of the information involved, including encryption in transit and at rest, access controls and role-based permissions, staff confidentiality obligations and training, and regular security review of our systems. Given the sensitive nature of AML/CTF compliance data processed through the Platform, we apply enhanced security controls to this category of information, consistent with our obligations under APP 11.

No system can guarantee absolute security. If we become aware of a data breach that is likely to result in serious harm to affected individuals, we will comply with our obligations under the Notifiable Data Breaches scheme in Part IIIC of the Privacy Act, including notifying the Office of the Australian Information Commissioner (OAIC) and affected individuals (via the relevant Customer, where appropriate) as required.

9How Long We Retain Personal Information

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, and as required by law. Importantly, the AML/CTF Act imposes its own statutory retention requirements — generally requiring reporting entities (our Customers) to retain certain KYC, transaction, and reporting records for a minimum of seven (7) years. Where the Platform is used to generate or store such records on a Customer’s behalf, we retain that data for the period directed by the Customer’s obligations, which may exceed standard data minimisation timeframes that would otherwise apply.

Where information is no longer required for any purpose, including legal retention requirements, we will take reasonable steps to securely destroy or de-identify it.

10Access and Correction

Individuals may request access to, or correction of, personal information we hold about them, subject to the exceptions in APPs 12 and 13.

  • Customer users (e.g. compliance officers, administrators) can typically access and update their own account information directly within the Platform.
  • End Customers of our Customers should generally direct access and correction requests to the relevant Customer (reporting entity) in the first instance, as they hold the primary relationship and underlying records. We will support our Customers in responding to such requests where we hold relevant data as a service provider.

You can also contact us directly at reachus@smartresourcesqld.com.au, and we will respond within a reasonable period (generally 30 days), or explain if we are unable to provide access (e.g. where doing so would compromise an ongoing AML/CTF investigation or breach “tipping-off” prohibitions under the AML/CTF Act).

11Children’s Privacy

AMLyticsAI is a business-to-business compliance platform and is not intended for use by, or directed at, children. We do not knowingly collect personal information from individuals under the age of 18 through our website or Platform other than where it forms part of End Customer KYC information collected by a Customer in the ordinary course of identifying their own customers.

12Cookies and Website Analytics

Our website may use cookies and similar technologies to support functionality and analyse usage. You can manage or disable cookies through your browser settings; doing so may affect the functionality of our website.

13How to Make a Complaint

If you have a concern about how we have handled personal information, please contact us first at reachus@smartresourcesqld.com.au. We will investigate and respond to your complaint within a reasonable timeframe (generally 30 days).

If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner:

  • Office of the Australian Information Commissioner (OAIC)
  • Website: www.oaic.gov.au
  • Phone: 1300 363 992

14Changes to this Policy

We may update this Policy from time to time to reflect changes in our practices or legal obligations, including as further tranches of Australian privacy law reform take effect. The most current version will always be available on our website, with the “Last updated” date shown at the top.

15Contact Us

For any questions about this Policy or your personal information, please contact us:

Smart Resources QLD
ABN 48659972273

Email: reachus@smartresourcesqld.com.au

↑ Back to top
© 2026 AMLyticsAI. All rights reserved.
Terms of Service Contact
A product developed in-house Smart Resources QLD www.smartresourcesqld.com.au

Demo Booked Successfully

Your request has been submitted successfully.Our team will contact you within one business day to confirm your preferred demo date and answer any questions you may have.

Enterprise Enquiry

Fill in your details and we'll get back to you with a custom quote.