Customer Data Protection & Data Residency Policy
Our Data Protection Commitment
At ARM Financial Services Pty Ltd ("ARMF", "we", "us" or "our"), protecting customer information is a fundamental part of how we operate our remittance services.
Customer data entrusted to ARMF is stored in Australia. Our core customer databases, identity and KYC records, transaction records and operational backups are maintained using data-centre infrastructure located in Australia and operated by ARMF and/or third-party infrastructure providers engaged by ARMF. ARMF does not represent that it owns the physical data-centre premises or all underlying infrastructure used to provide these services.
We do not use overseas data centres to host or replicate our core customer databases.
This Policy explains how ARMF protects customer data, where it is stored, who may access it, how long it is retained, and the limited circumstances in which information may need to be transmitted to another country to complete an international money transfer or comply with law.
Purpose of This Policy
This Policy is designed to provide customers with clear information about ARMF's approach to:
- customer data protection;
- Australian data residency;
- data security;
- access controls;
- data retention;
- international remittance information;
- regulatory disclosures;
- security incidents and data breaches; and
- customer privacy rights.
This Policy should be read together with ARMF's Privacy Policy, Terms and Conditions, Complaints Policy and other applicable customer notices.
ARMF handles personal information in accordance with applicable Australian privacy and data-protection requirements, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Australian Data Residency
Customer data stays in Australia
ARMF's core customer information is hosted and stored within Australia.
Our Australian data-residency model applies to information including:
- customer names and contact details;
- residential addresses;
- dates of birth;
- customer identification and KYC information;
- identity-verification records;
- account information;
- transaction histories;
- source-of-funds and source-of-wealth information;
- compliance and risk-assessment records;
- customer communications and support records;
- account-security information;
- audit and access logs; and
- backups containing customer information.
ARMF and service-provider managed infrastructure
Customer data is maintained within data-centre infrastructure located in Australia.
ARMF maintains administrative, technical and contractual controls over its core customer-data environment. Depending on the hosting model, underlying infrastructure may be operated by third-party providers, while ARMF manages or oversees controls relevant to its systems and customer data, including:
- servers and storage systems;
- database infrastructure;
- access permissions;
- authentication controls;
- encryption controls;
- monitoring and audit logs;
- backup systems;
- security configuration;
- incident-response processes; and
- data-retention and deletion processes.
ARMF does not intentionally host or replicate its master customer database or customer-data backups in overseas data centres.
Information We Protect
ARMF applies this Policy to personal information and other customer information that we collect or hold in connection with our services.
Depending on the service you use, this may include:
- identity information;
- identification documents or verification results;
- contact information;
- account information;
- banking and payment information;
- transaction and beneficiary information;
- device and security information;
- customer due-diligence information;
- sanctions and screening information;
- fraud and scam-prevention information;
- source-of-funds and source-of-wealth information;
- correspondence with ARMF;
- complaints and customer-support records; and
- information required to meet legal or regulatory obligations.
We seek to collect only information that is reasonably necessary for providing our services, protecting customers, preventing financial crime and complying with applicable law.
How We Protect Customer Data
ARMF maintains technical, physical and organisational security measures designed to protect customer information from:
- misuse;
- interference;
- loss;
- unauthorised access;
- unauthorised disclosure;
- alteration;
- destruction; and
- cyber-security threats.
Depending on the relevant system and risk, these measures may include:
Encryption
Customer information is protected through appropriate encryption and cryptographic controls both while stored and while being transmitted through our systems.
Access control
Access to customer information is restricted according to role and business need.
Employees and authorised personnel should only have access to information necessary to perform their authorised responsibilities.
Multi-factor authentication
Administrative and sensitive system access is protected through appropriate authentication controls, including multi-factor authentication where applicable.
Monitoring and audit logs
ARMF maintains monitoring and logging capabilities designed to identify unusual, unauthorised or suspicious access to customer information.
Access to sensitive systems and customer information may be recorded for security, compliance and audit purposes.
Security testing
ARMF maintains security-management processes that may include:
- vulnerability assessment;
- security testing;
- patch management;
- system monitoring;
- access reviews;
- penetration testing;
- incident-response exercises; and
- periodic security reviews.
Physical security
Physical security for data-centre facilities is managed by ARMF and/or the relevant infrastructure provider, depending on the hosting arrangement. ARMF seeks to ensure that physical access to systems or facilities hosting ARMF customer data is restricted to authorised personnel and subject to appropriate physical security and access-control requirements.
Who Can Access Customer Data
Access to customer information is provided on a need-to-know and least-privilege basis.
Authorised access may be provided to appropriately authorised ARMF personnel where necessary for:
- processing customer transactions;
- customer identification and verification;
- customer support;
- fraud and scam prevention;
- sanctions screening;
- AML/CTF compliance;
- transaction monitoring;
- regulatory reporting;
- security administration;
- system maintenance;
- complaints management; or
- another legitimate and lawful ARMF business purpose.
Personnel with access to customer information are subject to confidentiality, privacy, security and access-control requirements.
ARMF regularly reviews access permissions and may remove or restrict access where it is no longer required.
Overseas Access and International Transfers
Storage is different from transaction transmission
ARMF provides international money-remittance services. This means that although ARMF's core customer data remains stored in Australia, certain limited information may need to be transmitted outside Australia to complete a transaction.
For example, when you ask ARMF to send money to a recipient in another country, information such as:
- recipient name;
- recipient account or wallet details;
- transaction amount;
- transaction reference;
- payment instructions; and
- other information reasonably required by the receiving institution
may need to be provided to an overseas bank, payment network, payout partner, mobile-wallet provider or other recipient institution.
This limited transmission is necessary to provide the international remittance service requested by you.
It does not mean that ARMF moves or hosts its master customer database outside Australia.
Overseas disclosures
Where ARMF discloses personal information to an overseas recipient, we will do so only where reasonably necessary, permitted or required by law, and we will handle the disclosure in accordance with applicable Australian privacy requirements.
ARMF seeks to limit overseas disclosures to the minimum information reasonably required for the relevant purpose.
No routine overseas hosting
ARMF does not use overseas data centres for the routine hosting or backup of its core Australian customer information.
If ARMF proposes a material change to this data-residency model in the future, we will review the privacy and security implications and update our customer disclosures where required.
Third-Party Service Providers
Where ARMF uses a technology, security, verification, professional or other service provider that may have access to customer information, we take reasonable steps appropriate to the circumstances to assess and manage privacy and security risks.
Depending on the arrangement, these controls may include:
- due diligence before onboarding;
- contractual confidentiality requirements;
- restrictions on use of customer information;
- security requirements;
- access limitations;
- incident-notification obligations;
- audit or assurance requirements;
- restrictions on subcontracting; and
- requirements concerning return, deletion or destruction of information.
Where practicable and appropriate for services involving the storage of core customer information, ARMF's architecture is designed so that the relevant information remains within Australia.
Regulatory and Legal Disclosure
As a regulated remittance business, ARMF may be required or authorised to disclose information to government agencies, regulators, law-enforcement bodies, courts or other competent authorities.
This may include disclosures to:
- AUSTRAC;
- the Australian Federal Police;
- the Australian Taxation Office;
- sanctions and law-enforcement authorities;
- courts and tribunals; and
- other Australian authorities where disclosure is required or authorised by law.
ARMF will disclose only information reasonably required or authorised for the relevant legal or regulatory purpose.
Nothing in this Policy prevents ARMF from complying with an applicable Australian law, court order, regulatory requirement or lawful government request.
Data Retention
ARMF retains customer information only for as long as reasonably necessary for the purpose for which it is held or for as long as required by applicable law.
Because ARMF provides regulated remittance services, certain AML/CTF and transaction records must be retained for extended periods.
In particular, applicable Australian AML/CTF requirements may require relevant customer due-diligence, transaction and compliance records to be retained for at least seven years, depending on the type of record and the relevant legal requirement.
Information that is no longer required to be retained will be securely destroyed, deleted or de-identified where appropriate and subject to applicable law.
Deletion processes apply to relevant active systems and backups in accordance with ARMF's data-retention and secure-destruction procedures.
Data Breaches and Security Incidents
ARMF maintains processes designed to identify, contain, investigate and respond to suspected cyber-security incidents and data breaches.
Where an incident occurs, ARMF may take steps including:
- containing affected systems;
- restricting or disabling compromised access;
- securing customer accounts;
- investigating the cause and scope of the incident;
- assessing whether personal information has been affected;
- taking remedial action;
- preserving appropriate evidence;
- reviewing security controls; and
- notifying relevant authorities or affected individuals where required.
Where an incident constitutes an eligible data breach under Australia's Notifiable Data Breaches scheme, ARMF will notify the Office of the Australian Information Commissioner and affected individuals as required by law.
Customer Rights
Subject to applicable law, customers may request:
- access to personal information ARMF holds about them;
- correction of inaccurate, incomplete or out-of-date information; and
- information about how their personal information is handled.
Customers may also make a complaint if they believe their personal information has not been handled appropriately.
We may need to verify your identity before processing a privacy request.
Certain information may need to continue to be retained even after an account has been closed where retention is required under AML/CTF, taxation, regulatory, legal or dispute-management requirements.
Our Employees and Contractors
Personnel who are permitted to access ARMF customer information must comply with applicable:
- privacy requirements;
- confidentiality obligations;
- information-security policies;
- access-control requirements;
- AML/CTF obligations; and
- internal data-handling procedures.
Customer information must not be copied, downloaded, exported or transferred from ARMF systems except where authorised and reasonably necessary for a legitimate business, customer, security, compliance or legal purpose.
Unauthorised access, use or disclosure of customer information may result in access being revoked and appropriate disciplinary, contractual or legal action.
No Sale of Customer Data
ARMF does not sell customer personal information.
ARMF does not provide customer personal information to third parties for their independent marketing purposes without an appropriate lawful basis and, where required, customer consent.
Customer information is used primarily for providing and securing ARMF services, complying with regulatory obligations and operating our business lawfully.
Security Responsibilities of Customers
Customers also play an important role in protecting their information.
You should:
- keep your password, PIN and authentication credentials confidential;
- never provide a one-time password to another person;
- use secure devices and networks when accessing ARMF;
- review transaction information carefully before confirming a payment; and
- contact ARMF immediately if you suspect unauthorised access or activity.
No internet-connected system can be guaranteed to be completely free from security risk. ARMF therefore maintains security measures designed to manage and reduce risk but does not represent that cyber-security incidents can never occur.
Governance and Review
ARMF periodically reviews its data-protection arrangements having regard to:
- changes in Australian privacy law;
- AML/CTF requirements;
- cyber-security risks;
- technology changes;
- regulatory guidance;
- changes to ARMF systems or services; and
- findings from security reviews, audits and incidents.
Material changes to this Policy will be published with an updated version or effective date.
Contact ARMF
If you have a question about this Policy, the security of your personal information or how ARMF handles customer information, please contact:
ARM Financial Services Pty Ltd
ABN 35 659 595 570 | ACN 659 595 570
Suite 110, Level 1, 530 Little Collins Street, Melbourne VIC 3000, Australia
Privacy: privacy@armf.com | Security: security@armf.com.au | Phone: +61 3 8679 2233 | Website: armf.com
Dispute Resolution
Complaints and Initial Resolution
If a dispute, complaint or claim arises between you and ARMF in connection with your ARMF account, a transaction, our Services, our Website, our Platforms or these Terms (a Dispute), we encourage you to contact us first so that we have an opportunity to investigate and resolve the matter.
You may submit a complaint in accordance with our Complaints Policy.
Nothing in this section prevents you from exercising any right that you may have under applicable Australian law.
External Dispute Resolution and Regulatory Rights
Nothing in these Terms prevents or restricts you from making a complaint or application to any regulator, external dispute-resolution body, ombudsman, tribunal or other authority where you are entitled to do so under applicable law.
This includes the Australian Financial Complaints Authority (AFCA) where ARMF is a member of AFCA and the complaint falls within AFCA's jurisdiction.
Privacy complaints may also be made to the Office of the Australian Information Commissioner (OAIC) where applicable.
Nothing in these Terms requires you to waive a statutory right or remedy that cannot lawfully be excluded or restricted.
Good-Faith Resolution
Before commencing court proceedings, where reasonably practicable, you and ARMF should attempt in good faith to resolve the Dispute directly.
Either party may provide the other with a written notice describing:
- the nature of the Dispute;
- the relevant facts;
- the outcome or remedy sought; and
- any information reasonably necessary to understand the Dispute.
The parties should then use reasonable efforts to resolve the matter through discussion or another appropriate dispute-resolution process.
This requirement does not prevent either party from seeking urgent or interim relief or taking action where a limitation period, regulatory requirement or other legal consideration requires immediate action.
Arbitration by Agreement
After a Dispute has arisen, you and ARMF may agree in writing to resolve that Dispute by arbitration instead of court proceedings.
Arbitration will only apply where both parties agree to arbitration in relation to the particular Dispute.
Unless otherwise agreed in writing:
- the arbitration will be conducted by a single independent arbitrator;
- the place and legal seat of the arbitration will be Melbourne, Victoria, Australia;
- the arbitration will be conducted in English;
- Victorian law will apply to the arbitration to the extent applicable; and
- the arbitration will be conducted in accordance with the applicable Australian arbitration legislation.
If the parties agree to arbitrate but cannot agree on the appointment of the arbitrator, the arbitrator may be appointed in accordance with the applicable arbitration legislation.
The arbitrator must be independent and impartial.
Powers of the Arbitrator
Subject to applicable law and the parties' arbitration agreement, the arbitrator may determine the Dispute and grant any remedy that a court could lawfully grant in relation to the individual Dispute.
The arbitrator must apply these Terms together with all applicable Australian laws and any non-excludable statutory rights or remedies.
Costs of Arbitration
Unless the parties otherwise agree or applicable law requires otherwise, each party will initially bear its own legal costs and its share of any applicable arbitration costs.
The arbitrator may make an appropriate order concerning the costs of the arbitration having regard to applicable law, the circumstances of the Dispute and the conduct of the parties.
Nothing in this section requires a customer to reimburse ARMF merely because the customer unsuccessfully brings a genuine complaint or claim.
Court and Tribunal Proceedings
Where a Dispute is not resolved through ARMF's complaints process, an applicable external dispute-resolution process or arbitration agreed between the parties, either party may commence proceedings before a court or tribunal having jurisdiction.
Nothing in these Terms restricts any right you may have under applicable Australian law concerning the court, tribunal or jurisdiction in which a claim may be brought.
Representative Proceedings
To the maximum extent permitted by law, ARMF and a customer may seek to resolve a dispute on an individual basis. However, nothing in these Terms requires a customer to waive, discharge or release a right to commence, participate in or benefit from a representative, group or class proceeding where such a waiver would be prohibited, unfair or otherwise unenforceable under applicable Australian law.
Urgent and Protective Relief
Nothing in this section prevents either party from applying to a court of competent jurisdiction for urgent, interlocutory or protective relief where reasonably necessary, including relief relating to:
- fraud or suspected fraud;
- unauthorised account access;
- misuse of confidential information;
- infringement or misuse of intellectual property rights;
- preservation of evidence or assets; or
- another matter requiring urgent judicial intervention.
Existing Statutory Rights
Nothing in this Dispute Resolution section excludes, restricts or modifies:
- any consumer guarantee, statutory right or remedy that cannot lawfully be excluded, restricted or modified;
- any right available under the Australian Consumer Law;
- any right to make a complaint to a regulator, law-enforcement authority, ombudsman or external dispute-resolution body;
- any jurisdiction conferred on a court or tribunal that cannot lawfully be excluded by agreement; or
- any other mandatory protection provided by Australian law.
Changes to this Section
ARMF may amend this Dispute Resolution section where reasonably necessary because of changes to law, regulation, regulatory guidance, ARMF's dispute-resolution arrangements or its Services.
Where a change is materially adverse to customers, ARMF will provide reasonable advance notice unless an earlier change is required by law or regulation.
A change to this section will not retrospectively alter the dispute-resolution arrangements applicable to a Dispute of which ARMF had already received written notice before the change became effective, unless the parties expressly agree otherwise.