Overview
While primarily operating in Australia, we recognize that some users may be subject to the European Union General Data Protection Regulation. This document outlines how we handle data for individuals covered by GDPR provisions.
Legal Basis for Processing
We process personal data under the following legal bases:
- Contract Performance: Processing necessary to deliver fraud monitoring services you have subscribed to
- Legitimate Interest: Analyzing transaction patterns to detect fraud and protect financial assets
- Legal Obligation: Retaining records as required by financial regulations and responding to lawful requests
- Consent: Marketing communications and optional service features you explicitly agree to
Your GDPR Rights
If you are subject to GDPR, you have the following rights regarding your personal data:
Right to Access
You can request confirmation of what personal data we hold about you and receive a copy in a structured, commonly used format.
Right to Rectification
You can request correction of inaccurate or incomplete personal data we maintain.
Right to Erasure
You can request deletion of your personal data when it is no longer necessary for the purposes collected, subject to legal retention obligations.
Right to Restrict Processing
You can request that we limit how we use your data in certain circumstances, such as while accuracy is being verified.
Right to Data Portability
You can receive your personal data in a machine-readable format and transmit it to another service provider.
Right to Object
You can object to processing based on legitimate interests or for direct marketing purposes.
Rights Related to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing that significantly affect you. Our fraud detection uses automated analysis, but human review is available upon request for any flagged transactions.
Data Processing Activities
We process personal data for these specific purposes:
- Fraud detection through transaction pattern analysis
- Alert delivery regarding suspicious activity
- Customer support and inquiry response
- Service improvement and security enhancement
- Regulatory compliance and legal obligations
Data Retention
Personal data is retained only as long as necessary for the purposes collected:
- Active service data: Duration of subscription plus seven years for financial compliance
- Transaction metadata: Seven years from transaction date
- Marketing consent records: Until consent is withdrawn
- Support correspondence: Three years from last contact
International Data Transfers
Our primary data processing occurs within Australia. If data transfers to other jurisdictions become necessary, we implement appropriate safeguards such as standard contractual clauses approved by the European Commission.
Data Protection Officer
For GDPR-related inquiries, you can contact our data protection representative at [email protected]. Please include "GDPR Request" in the subject line for priority handling.
Exercising Your Rights
To exercise any GDPR rights, submit a request to [email protected] with:
- Clear identification of which right you wish to exercise
- Sufficient information to verify your identity
- Specific details about the data or processing concerned
We will respond within one month of receiving a valid request. Complex requests may require up to three months, with notification of any extension.
Right to Lodge a Complaint
If you believe our data processing violates GDPR, you have the right to lodge a complaint with your local supervisory authority in the EU member state where you reside or work.
Data Security Measures
We implement technical and organizational measures to ensure data security appropriate to the risk:
- Encryption of data in transit and at rest
- Regular security assessments and penetration testing
- Access controls limiting who can view personal data
- Staff training on data protection principles
- Incident response procedures for data breaches
Updates to This Statement
We may update this GDPR compliance statement to reflect changes in regulations or our practices. Significant changes will be communicated to affected users via email.