Skip to main content
Create Free Account

Legal

Privacy Policy.

How ComplyFlow collects, uses, shares, and protects personal information across the website and the web application, and what you can ask of us. The summary is a reading aid; the policy below it is what applies.

  • Effective 19 May 2021. Last updated 6 Aug 2026
  • Privacy contact: Mitchell Bourne, support@complyflow.com.au
  • Applies to complyflow.com and the web application at app.complyflow.com.au

In Plain English

What the Privacy Policy Says, in Six Cards.

This summary is a reading aid, not the policy. The full text below is what applies, and it takes precedence wherever the two differ.

  • What we collect.

    Name, email, date of birth, phone, address, certificates, licences, and business details such as ABN, position, and organisation, plus the usual log data from your browser: IP address, pages visited, and errors.

    See Clauses 1.1, 1.2, and 1.2.1

  • Why we collect it.

    To provide the platform’s core features, to contact you, for record keeping, and to meet legal obligations. Only what is reasonably necessary to provide the service.

    See Clauses 1.3 and 1.4

  • Who sees it.

    Information collected on behalf of a Client or employer is disclosed only to the Clients or employers you work for. Service providers such as hosting, analytics, and advertising platforms, and courts or regulators where the law requires. Not sold.

    See Intro, and clauses 1.6 and 1.8

  • Where it lives.

    Stored and processed in Australia on Australian servers, including AI processing. The policy states that personal information is not disclosed to overseas recipients. Anything you connect through the API or MCP server is a transfer you initiate and control.

    See Clauses 1.9.2, 1.10, 1.16.2, and 1.16.4

  • How AI is used.

    For document verification, compliance monitoring, and data analysis. Outputs are reviewed by authorised people where appropriate, and customer data is not used to train third-party AI systems.

    See Clauses 1.9 and 1.9.1

  • Your rights.

    Ask what we hold, have it corrected, withhold information, unsubscribe from email, and complain to us or to a regulator. A notifiable data breach is reported under the Privacy Act’s scheme.

    See Clauses 1.7.2, 1.7.4, and 1.11

Your privacy is important to us. It is ComplyFlow's policy to respect your privacy and comply with any applicable law and regulation regarding any personal information we may collect about you, including across our website, https://complyflow.com and our web application https://app.complyflow.com.au where our cloud services are hosted.

Personal information is any information about you that can be used to identify you. This includes information about you as a person (such as name, address, and date of birth), your devices, payment details, and even information about how you use a website or online service.

Personal records are not revealed, sold, distributed, rented, licensed, shared or passed on to any third party unless ComplyFlow is legally required to do so, or as part of our core product offering — refer to 1.4 Collection and Use of Information.

In the event our site contains links to third-party sites and services, please be aware that those sites and services have their own privacy policies. After following a link to any third-party content, you should read their posted privacy policy information about how they collect and use personal information. This Privacy Policy does not apply to any of your activities after you leave our site.

1.1 Information We Collect

Information we collect includes both information you knowingly and actively provide us when using or participating in any of our services and promotions, and any information automatically sent by your devices in the course of accessing our products and services.

1.2 Log Data

When you visit our website or web application, our servers may automatically log the standard data provided by your web browser. It may include your device's Internet Protocol (IP) address, your browser type and version, the pages you visit, the time and date of your visit, the time spent on each page, and other details about your visit.

Additionally, if you encounter certain errors while using our services, we may automatically collect data about the error and the circumstances surrounding its occurrence. This data may include technical details about your device, what you were trying to do when the error happened, and other technical information relating to the problem. You may or may not receive notice of such errors, even in the moment they occur, that they have occurred, or what the nature of the error is.

1.2.1 Personal Information

We may ask for personal information which may include one or more of the following:

  • Name
  • Email
  • Date of birth
  • Phone/mobile number
  • Home/mailing address
  • Certificates
  • Licences
  • Information in regards to a person's business or professional capacities such as ABN/ACN, position and organisation.
  • Other personal information

1.2.2 User-Generated Content

We consider "user-generated content" to be materials voluntarily supplied to us by our users through our public-facing website or forum/s (i.e. not the ComplyFlow Application) for the purpose of publication on our website and/or social media channels. All user-generated content is associated with the account or email address used to submit the materials.

Please be aware that any comments, feedback or questions you submit for the purpose of publication on our company websites (i.e. www.complyflow.com or forums and/or public-facing web properties) will be public after posting (and subsequent review or vetting process). Once published, it may be accessible to third parties not covered under this privacy policy.

1.3 Legitimate Reasons for Processing Your Personal Information

We only collect and use your personal information when we have a legitimate reason for doing so. In which instance, we only collect personal information that is reasonably necessary to provide our services to you.

1.4 Collection and Use of Information

We may collect personal information from you when you do any of the following on our website:

  • Register for an account
  • Use a mobile device or web browser to access our content
  • Contact us via email, social media, or on any similar technologies
  • When you mention us on social media

We may collect, hold, use, and disclose information for the following purposes, and personal information will not be further processed in a manner that is incompatible with these purposes:

  • to provide you with our platform's core features and services
  • to enable you to customize or personalise your experience of our website
  • to contact and communicate with you
  • to enable you to access and use our website, associated applications, and associated social media platforms
  • for internal record keeping and administrative purposes
  • to comply with our legal obligations and resolve any disputes that we may have

Please be aware that we may combine information we collect about you with general information or research data we receive from other trusted sources.

1.5 Security of Your Personal Information

When we collect and process personal information, and while we retain this information, we will protect it within commercially acceptable means to prevent loss and theft, as well as unauthorised access, disclosure, copying, use, or modification. We will comply with laws applicable to us in respect of any data breach.

You are responsible for selecting any password and its overall security strength, ensuring the security of your own information within the bounds of our services.

1.6 Sharing information with Clients & Employers

ComplyFlow is committed to providing a confidential service to its users, we are bound by the National Privacy Principles of the Privacy Act 1988 and individual state legislation.

Information collected by ComplyFlow on behalf of each Client or Employer is only disclosed to Client/s and/or Employers that you work for. It is important to refer to their respective Privacy Policies for information on how they handle your data, for example, they may retain your personal information for their compliance with legal, accounting, or reporting obligations.

For the purpose of this policy, confidentiality relates to the transmission of personal, sensitive or identifiable information about individuals or organisations (confidential information), which comes into the possession of the organisation through its work.

ComplyFlow holds personal data about its users on behalf of your Client or Employer which will only be used for the purposes for which it was gathered and will not be disclosed to anyone outside of the parties mentioned above where a warrant or subpoena has not been provided.

All personal data will be dealt with sensitively and in the strictest confidence internally and externally.

1.7 The Privacy Act 1988 (Privacy Act)

All personal paper-based and electronic data must be stored in accordance with The Privacy Act 1988 (Privacy Act) and must be secured against unauthorised access, accidental disclosure, loss or destruction.

All personal paper-based and electronic data are only accessible to those individuals authorised to have access.

1.7.1 Records

We consider protecting personal information a high priority and have strict measures when it comes to securing data on our Australian based servers.

The data is not viewed or accessed by personnel unless management, your Client or Employer require us to do so. Our personnel do not access accounts or export records unless it is intentionally granted by the Managing Director or disclosed by your Clients or your Employer.

ComplyFlow is committed to the use of personal information in accordance with the Australian Privacy Principles.

1.7.2 Accessing the information we hold about you.

You can access and correct the personal information we hold about you.

Contact us via: E-mail: Support@complyflow.com.au Physical mail: Suite 3, 12-16 Sydney Road MANLY NSW 2095

1.7.3 Breaches of the Privacy Policy

Confidential or sensitive information relating to an individual may be divulged where it is against the law to withhold it. In these circumstances, information may be divulged to external agencies e.g. police or social services on a need to know basis, provided that they present a subpoena or a warrant. If the breach is caused by any other than the above-listed reasons, the disciplinary measure is immediate termination.

1.7.4 Data Breaches

In the event of a data breach, ComplyFlow will inform all involved as per The Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Privacy Act)

1.7.5 Legislative Framework

ComplyFlow will monitor this policy to ensure it meets statutory and legal requirements including the:

  • Privacy Act 1988
  • Information Privacy Act 2014 (ACT)
  • Privacy and Personal Information Protection Act 1998 (NSW)
  • Information Act (NT)
  • Information Privacy Act 2009 (Qld)
  • Information and Protection Act 2004 (Tas)
  • Privacy and Data Protection Act 2014 (Vic)
  • General Data Protection Regulation (GDPR) (EU) 2016/679

Ensuring the effectiveness of the policy:

  • All employees will receive a copy of the Privacy Policy.
  • New workers and/or subcontractors will be introduced to the Privacy Policy via induction and training.
  • The policy will be reviewed annually and amendments will be proposed and agreed upon by the Directors.
  • The disciplinary sanction for any breaches of this policy is immediate termination.

1.7.6 Children's Privacy

We do not aim any of our products or services directly at children under the age of 13, and we do not knowingly collect personal information about children under 13.

1.8 Disclosure of Personal Information to Third Parties

We may disclose personal information to:

  • a parent, subsidiary, or authorised integration partner of our company
  • third party service providers for the purpose of enabling them to provide their services, for example, IT service providers, data storage, hosting and server providers, advertisers, or analytics platforms
  • our employees, contractors, and/or related entities (refer to Sharing information with Clients & Employers)
  • courts, tribunals, regulatory authorities, and law enforcement officers, as required by law, in connection with any actual or prospective legal proceedings, or in order to establish, exercise, or defend our legal rights
  • third parties, including sub-contractors, who assist us in providing information, products, services, or email communication and product updates to you
  • Hosting services used to collect and process data.

1.9 Use of Artificial Intelligence (AI)

ComplyFlow uses Artificial Intelligence (AI) within certain modules of our platform to enhance automation, data accuracy, and user experience. The use of AI is governed by our commitment to transparency, fairness, and compliance with applicable Australian privacy and data protection laws.

AI tools are used to support processes such as document verification, compliance monitoring, and data analysis. These tools assist in improving efficiency and reliability but do not replace human judgement. All AI-assisted outputs are reviewed and validated by authorised personnel where appropriate.

1.9.1 Data Handling and Protection

All personal information processed by AI is handled in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). AI models only use data necessary to perform their intended functions, and ComplyFlow does not sell, share, or use customer data to train third-party AI systems.

1.9.2 Data Residency

AI data is processed and stored in Australia.

1.9.3 Transparency and Human Oversight

ComplyFlow ensures clear disclosure of where and how AI is used within the system. AI outputs are subject to human oversight to ensure accuracy, fairness, and compliance with ethical and legal standards.

1.9.4 Monitoring and Continuous Improvement

AI systems are periodically reviewed to ensure they remain effective, unbiased, and compliant with evolving Australian regulatory requirements and ethical AI principles.

1.10 International Transfers of Personal Information

The personal information you provide to ComplyFlow, and the compliance records held in our web application, are stored and processed in Australia on Australian based servers.

The third-party service providers described in Section 4 of this policy hold the personal information they process on our behalf in Australia. Matomo, our website analytics platform, does not hold personal information at all: IP addresses are anonymised before storage, as described in Section 4.5.

We do not disclose personal information to overseas recipients. If this position changes, we will take steps that are reasonable in the circumstances to ensure that an overseas recipient does not handle that information in a way that breaches the Australian Privacy Principles, as required by APP 8, and we will update this policy accordingly.

Where you choose to connect an external platform to your ComplyFlow data through our API or our MCP server, any resulting transfer is initiated and controlled by you. Refer to Section 1.16.4.

1.11 Your Rights and Controlling Your Personal Information

You always retain the right to withhold personal information from us, with the understanding that your experience of our website may be affected. We will not discriminate against you for exercising any of your rights over your personal information. If you do provide us with personal information you understand that we will collect, hold, use and disclose it in accordance with this privacy policy. You retain the right to request details of any personal information we hold about you.

If we receive personal information about you from a third party, we will protect it as set out in this privacy policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such a person's consent to provide the personal information to us.

If you have previously agreed to us using your personal information for email communication and product updates, you may change your mind at any time. We will provide you with the ability to unsubscribe from our email database or opt-out of communications. Please be aware we may need to request specific information from you to help us confirm your identity.

If you believe that any information we hold about you is inaccurate, out of date, incomplete, irrelevant, or misleading, please contact us using the details provided in this privacy policy. We will take reasonable steps to correct any information found to be inaccurate, incomplete, misleading, or out of date.

If you believe that we have breached a relevant data protection law and wish to make a complaint, please contact us using the details below and provide us with full details of the alleged breach. We will promptly investigate your complaint and respond to you, in writing, setting out the outcome of our investigation and the steps we will take to deal with your complaint. You also have the right to contact a regulatory body or data protection authority in relation to your complaint.

1.12 Use of Cookies

We use "cookies" to collect information about you and your activity across our site. A cookie is a small piece of data that our website stores on your computer, and accesses each time you visit, so we can understand how you use our site. This helps us serve you content based on the preferences you have specified.

Please refer to our Cookie Policy for more information.

1.13 Limits of Our Policy

Our website may link to external sites that are not operated by us. Please be aware that we have no control over the content and policies of those sites, and cannot accept responsibility or liability for their respective privacy practices.

1.14 Changes to This Policy

At our discretion, we may change our privacy policy to reflect updates to our business processes, current acceptable practices, or legislative or regulatory changes. If we decide to change this privacy policy, we will post the changes here at the same link by which you are accessing this privacy policy.

If the changes are significant, or if required by applicable law, we will contact you (based on your selected preferences for communications from us) and all our registered users with the new details and links to the updated or changed policy.

If required by law, we will get your permission or give you the opportunity to opt in to or opt-out of, as applicable, any new uses of your personal information.

1.15 Contact Us

For any questions or concerns regarding your privacy, you may contact us using the following details:

  • Mitchell Bourne
  • support@complyflow.com.au

1.16 Model Context Protocol (MCP) Server and Third-Party Platform Access

ComplyFlow provides a Model Context Protocol (MCP) server that allows customers to connect approved third-party applications, AI assistants, and analytics tools to their ComplyFlow data. The MCP server operates as an access and integration mechanism — functionally similar to our API — enabling authorised external clients to query and surface data held in ComplyFlow within those external platforms.

1.16.1 Data Residency Remains Unchanged

Data accessed via the MCP server continues to be hosted, stored, and processed by ComplyFlow within Australia, in the same manner described elsewhere in this Privacy Policy. The MCP server does not relocate, copy, or migrate your data to any new ComplyFlow storage location.

1.16.2 Customer-Initiated Access

Access through the MCP server is initiated and controlled by you. You decide which external applications, AI clients, or platforms to connect, what credentials and permission scopes to grant, and what data those tools may retrieve. This is no different in principle to using our API to surface ComplyFlow data in an external system such as a business intelligence or reporting platform (for example, Power BI).

1.16.3 Data in External Platforms is Your Responsibility

Once ComplyFlow data is retrieved by, or surfaced within, a third-party platform, that data leaves the ComplyFlow environment and its handling is governed by the terms, privacy policy, and security controls of that third party — not by ComplyFlow. We do not control, and are not responsible for, how connected platforms store, process, retain, secure, transmit, or further disclose your data, including whether they process or store it outside Australia or use it to train AI models.

You are responsible for:

  • selecting and connecting only trustworthy applications and platforms
  • reviewing the terms and privacy policies of any platform you connect
  • managing the credentials, permissions, and data scopes you grant
  • monitoring and revoking access where appropriate
  • ensuring your use of connected platforms complies with your own legal and privacy obligations, including any obligations you owe to the workers, contractors, or clients whose information is held in ComplyFlow.

1.16.4 International Transfers via Connected Platforms

Where you connect an external platform that processes or stores data outside Australia, the resulting transfer of personal information offshore is one that you initiate and control. You should satisfy yourself that any such transfer is permitted under, and complies with, the Privacy Act 1988 (Cth), the Australian Privacy Principles (including APP 8), and any other laws applicable to you. Refer to Section 1.10 (International Transfers of Personal Information).

1.16.5 ComplyFlow's Role and Security

ComplyFlow applies authentication and access controls to the MCP server consistent with the security measures described in this Privacy Policy, and access requires valid authorisation. Our responsibility extends to securing data within the ComplyFlow environment and to providing the access mechanism; it does not extend to the security or conduct of the external platforms you choose to connect. Use of the MCP server is also subject to our Fair Usage Policy for API Usage (Section 3).

The Other Documents

The Rest of the Legal Set.

Four documents, each on its own page, all part of the one controlled policy.

  • Section 2

    Terms of Service.

    The terms that govern use of the ComplyFlow website and related services: what you may not do, content you post, liability, and governing law.

  • Section 3

    Fair Usage Policy for API Usage.

    How ComplyFlow keeps its API and MCP server fair for everyone: usage limits, acceptable use, monitoring, and what happens when limits are exceeded.

  • Section 4

    Website Cookie Policy.

    Which cookies the ComplyFlow website and web application use, what each kind does, the third-party services involved, and how to refuse them.