Merchant & Business Contact Privacy Notice — Australia
About this Notice
This Notice supplements ARMF's Privacy Policy and applies when ARMF collects personal information about an individual in connection with a business customer, prospective business customer, merchant, commercial partner, supplier or other organisation. This may include directors, beneficial owners, controllers, partners, trustees, employees, contractors and authorised representatives.
The use of the word "merchant" in this Notice is a privacy description only. It does not by itself represent that merchant acquiring, payment acceptance or any product other than ARMF's currently available Australian remittance services is offered or available in Australia.
Personal information we may collect
Depending on your role and the relationship with ARMF, we may collect:
- identity and contact information, such as name, date of birth, address, email, telephone number and identification-document information;
- business-role information, including title, authority, employer, directorship, ownership, control, beneficial ownership and authorised-signatory status;
- business contact and account-administration information, including login, access, permissions and communications;
- KYC, KYB and customer-due-diligence information, including source-of-funds or source-of-wealth information where reasonably required;
- sanctions, politically exposed person, adverse-media, fraud, financial-crime and risk-screening information;
- transaction, beneficiary, settlement, bank or payment information associated with an authorised business remittance;
- device, IP, authentication, security, access-log and technical information when you use ARMF systems; and
- support, complaint, audit, contractual and other correspondence relating to the business relationship.
How we collect information
We may collect information directly from you, from the organisation you represent, from another authorised representative, and from third parties such as identity-verification, fraud-prevention, sanctions/PEP screening, banking, payment and professional service providers, public registers, regulators, government bodies and lawfully available public sources.
Why ARMF collects, uses and discloses this information
ARMF may handle business-contact personal information where reasonably necessary to:
- identify and verify individuals and organisations and establish authority to act;
- onboard, administer and support a business relationship or authorised remittance account;
- process, settle, reconcile, investigate, return or recover transactions;
- conduct AML/CTF customer due diligence, sanctions/PEP screening, transaction monitoring, fraud prevention and risk assessment;
- protect ARMF, customers and third parties from fraud, scams, unauthorised activity and security incidents;
- communicate about accounts, transactions, service changes, support, complaints, contracts and compliance requirements;
- meet legal, regulatory, audit, record-keeping, reporting and law-enforcement obligations;
- manage ARMF's operations, service providers, information security and legitimate commercial relationships; and
- send business marketing communications where permitted by law and subject to available opt-out choices.
If information is not provided
Where information is reasonably required for identity verification, AML/CTF compliance, authority checks, risk management or transaction processing, ARMF may be unable to onboard or continue the relevant business relationship, grant access, accept an instruction or process a transaction if that information is not provided.
Who we may disclose information to
ARMF may disclose relevant personal information to banks, correspondent institutions, payment partners, identity-verification providers, fraud and financial-crime screening providers, technology and cloud providers, cybersecurity providers, customer-support platforms, auditors, insurers, professional advisers, contractors, regulators, government authorities, courts and law-enforcement bodies where reasonably necessary, authorised or required.
Overseas disclosures
International remittance necessarily involves cross-border activity. Consistent with ARMF's Privacy Policy, personal information may be disclosed to overseas recipients including payment and compliance providers and the institution responsible for delivering a payment. Depending on the service and supplier arrangements, recipients may be located in Pakistan, the United Kingdom, the United States, Singapore, countries within the European Economic Area and the destination country of a beneficiary. ARMF handles overseas disclosures in accordance with applicable Australian privacy requirements.
Security and retention
ARMF uses technical and organisational measures designed to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Personal information is retained for as long as reasonably necessary for the relevant business, legal, regulatory, security, audit and dispute-resolution purposes, including any retention period required by AML/CTF law.
Access, correction and privacy complaints
You may request access to or correction of personal information ARMF holds about you, subject to applicable law. Privacy complaints may be made to ARMF's Privacy Officer. If you are not satisfied with ARMF's response and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner.
Relationship with the Privacy Policy
This Notice should be read together with ARMF's Privacy Policy, which contains further information about sensitive information, automated systems, data breaches, retention, overseas disclosures, marketing choices, access, correction and privacy complaints. Nothing in this Notice reduces a privacy right provided by applicable law.
Contact ARMF
ARM Financial Services Pty Ltd | ABN 35 659 595 570 | ACN 659 595 570
Suite 110, Level 1, 530 Little Collins Street, Melbourne VIC 3000, Australia
Email: privacy@armf.com | Phone: +61 3 8679 2233 | Website: armf.com