AML Sorted.

Beta privacy policy · Version 2026-07-15 · Independent confirmation pending

Your information should stay controlled.

AML Sorted is operated by Advery Pty Ltd. This policy explains how AML Sorted collects, holds, uses and discloses personal information when providing the beta service. The business or practice using AML Sorted remains responsible for deciding what customer information it needs for its AML/CTF obligations.

Information we handle

Depending on how the service is used, this may include:

How information is collected

Information may be provided by a workspace user, by a customer using a secure document request, by an authentication provider, or created when the service records workflow and security activity. We ask users to collect only information reasonably necessary for the stated AML/CTF or service purpose.

Why we use it

We use information to provide secure AML/CTF workflows, evidence and audit records, administer accounts, protect the service, respond to support and privacy requests, meet legal obligations and improve the beta without using customer identity documents for advertising or AI model training. If required information is not provided, the relevant customer check, evidence request or workspace function may not be available.

Who information may be disclosed to

Information is available to authorised users of the relevant workspace according to their role. We may also disclose the minimum necessary information to infrastructure, authentication, email, security and support providers, or where required by law. Support access to a customer workspace requires a recorded purpose, customer approval and expiry. We do not sell personal information.

Storage and overseas processing

Primary production customer and evidence data is stored in Sydney, Australia. Malware scanning runs in Sydney. Some service metadata, email delivery, security telemetry and encrypted backup data may be processed by providers in the United States or other countries in which those providers operate. The current providers include Supabase, Vercel, Google Cloud, Cloudflare, Resend and Sentry. We assess access controls, contractual protections and data minimisation before enabling a provider for production data.

Security, retention and deletion

Production evidence is encrypted in transit, kept in private storage, quarantined and malware scanned before access. Workspace access is role restricted, privileged functions require multi-factor authentication, document access is audited and downloads use short-lived links. AML/CTF records may need to be retained for seven years or longer depending on the record and its legal basis. Legal holds and statutory obligations can prevent early deletion. Records that are no longer required are scheduled for controlled destruction or de-identification.

Access, correction and complaints

Contact support@aml-sorted.app to request access or correction, make a privacy complaint or report a suspected data incident. Include enough information for us to verify your identity without sending an identity document by email. We aim to acknowledge requests promptly and respond to privacy complaints within 30 days. If you are not satisfied, you may contact the Office of the Australian Information Commissioner.

Collection notices and updates

More specific notices may apply when information is collected. See the customer collection notice for secure document requests. We will publish a new version and effective date when this policy materially changes.