ComplyReady Privacy Policy
Last updated: 23 June 2026
ComplyReady is operated by Sandlabs Pty Ltd (ABN 26 678 968 753) ("ComplyReady", "we", "us", "our"). We provide software that helps Australian reporting entities meet their obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (the "AML/CTF Act").
We are committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) (the "Privacy Act") and the Australian Privacy Principles (APPs). This policy explains what personal information we collect, how we use and disclose it, how we keep it secure, and how you can access or correct it or make a complaint.
Your data and your customers' data
ComplyReady is a tool used by businesses (our "customers") to run their own AML/CTF compliance. Where you are our customer, you remain responsible for the personal information you collect about your clients and enter into the platform (for example, customer due diligence records and identity documents). We process that information on your behalf and in accordance with our agreement with you and this policy. If you are an individual whose information has been entered into ComplyReady by one of our customers, please contact that business in the first instance about how they handle your information.
The information we collect
Information you provide to us
- Account & business details: your name, email, phone, role, business name, ABN, entity type, state, and compliance officer details.
- Compliance content: risk assessments, AML/CTF programs, training records, and reports (SMRs, TTRs) you create.
- Customer due diligence (CDD) records: information you enter about your own clients to meet your AML/CTF obligations, which may include identity details and uploaded identification documents. Some of this may be "sensitive information" under the Privacy Act; we handle it only to provide the service to you.
- Billing details: subscription and payment information (card payments are processed by Stripe; we do not store full card numbers).
- Support & correspondence: messages you send us and records of your enquiries.
Information collected automatically
- Usage and device information (IP address, browser/device type, pages viewed, actions taken) and diagnostic/error logs used to keep the service secure and reliable.
- Cookies and similar technologies used for authentication, preferences, and analytics (see "Cookies" below).
How we use your information
- To provide, maintain, and improve the ComplyReady platform.
- To enable your AML/CTF compliance activities (risk assessments, programs, training, CDD records, and reporting).
- To perform ABN look-ups via the Australian Business Register.
- To process payments, manage subscriptions, and provide support.
- To send service and account communications, and (where permitted) product updates you can opt out of.
- To protect the security and integrity of the service, prevent misuse, and comply with our legal obligations.
Automated processing and AI
Some features use artificial intelligence (provided by Anthropic) to help generate or summarise compliance content. AI is used to assist you; it does not make legally binding decisions on your behalf, and you remain responsible for reviewing and approving any output. We do not permit our AI provider to use your data to train its models.
How we disclose your information
We do not sell your personal information. We share it only as needed to run the service or as required by law, including with the following categories of service providers (sub-processors):
- Supabase — database, authentication, and document storage.
- Vercel — application hosting and delivery.
- Anthropic — AI features.
- Resend — transactional and notification emails.
- Stripe — payment processing.
- Australian Business Register (ABR) — ABN verification look-ups.
- Sentry — error monitoring and diagnostics.
We may also disclose information to government, regulatory, or law enforcement bodies where required or authorised by law (for example, to AUSTRAC), to professional advisers, or in connection with a business sale or restructure (subject to confidentiality).
Overseas disclosure
We host the core ComplyReady application database in Australia (Amazon Web Services, Sydney region). However, some of our service providers process or store certain data outside Australia, including in the United States and other countries where they operate. Where we disclose information overseas, we take reasonable steps to ensure it is handled consistently with the APPs.
Data security
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These include encryption of data in transit and at rest, role-based access controls, authentication, and audit logging. No method of transmission or storage is completely secure, but we work to protect your information and to respond appropriately to any data breach in line with the Notifiable Data Breaches scheme.
How long we keep it
We retain personal information for as long as needed to provide the service and to meet legal and regulatory requirements. Note that the AML/CTF Act generally requires reporting entities to keep certain records (including your AML/CTF program, CDD records, transaction records, and training records) for 7 years. When information is no longer required, we delete or de-identify it, other than copies retained securely in backups until they are overwritten.
Accessing and correcting your information
You may request access to the personal information we hold about you and ask us to correct it if it is inaccurate, out of date, or incomplete. To make a request, contact us using the details below. We will respond within a reasonable period (generally 30 days). There is no charge to make a request, though we may charge a reasonable cost for providing access in some cases.
Cookies
We use cookies and similar technologies for sign-in, security, remembering your preferences, and understanding how the service is used. You can control cookies through your browser settings, but disabling them may affect how the platform works.
Children
ComplyReady is a business tool and is not directed at children. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us so we can delete it.
Complaints
If you have a concern or complaint about how we have handled your personal information, please contact us using the details below and we will investigate and respond. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC):
Phone: 1300 363 992
Website: www.oaic.gov.au
Changes to this policy
We may update this policy from time to time. The current version will always be available on our website, and we will indicate the date it was last updated above.
Contact us
For privacy questions, access or correction requests, or complaints, contact:
ComplyReady (Sandlabs Pty Ltd) — Privacy
Email: hello@sandlabs.com.au