ARMF Privacy Policy (Australia)
Who We Are
ARM Financial Services Pty Ltd is an Australian company with ABN 35 659 595 570 and ACN 659 595 570. Address: Suite 110, Level 1, 530 Little Collins Street, Melbourne VIC 3000, Australia.
For privacy enquiries, access or correction requests or privacy complaints, contact the Privacy Officer at privacy@armf.com or +61 3 8679 2233.
Scope of This Policy
This Policy applies to personal information handled by ARMF through:
- our website;
- our mobile or web applications;
- customer onboarding and identity verification;
- international remittance transactions;
- customer support and complaints;
- fraud, scam and financial-crime monitoring;
- marketing and communications; and
- other interactions between you and ARMF.
Additional privacy notices may apply to particular features, technologies or jurisdictions.
Personal Information We May Collect
The personal information we collect depends on how you interact with ARMF and the services you use.
- Identity information: full name, date of birth, nationality, residential address and other information used to establish and verify your identity.
- Identity documents: information from passports, driver's licences, identity cards or other documents (document numbers, issuing authorities, issue and expiry dates and document images).
- Contact information: email address, mobile telephone number, residential address and other contact details.
- Biometric and verification information: where used for identity verification, a facial image, selfie, liveness-check information or other biometric information, treated as sensitive information and collected only where permitted by law.
- Transaction and financial information: amounts sent, currencies, beneficiaries and recipients, funding sources, bank or payment details, transaction dates and status, transaction history, the purpose of a payment and, where reasonably required for AML/CTF purposes, source-of-funds or source-of-wealth information.
- Beneficiary information: where you instruct us to send money to another person, their name, country, account or wallet details and other information necessary to complete the transaction.
- Business information: where business customers are permitted, information about the business and its directors, beneficial owners, controllers, employees and authorised representatives.
- Compliance and risk information: customer risk assessments and information associated with sanctions, politically exposed person, adverse-media, fraud and other financial-crime screening.
- Device and technical information: IP address, device type, browser and operating system, device identifiers, login and authentication information, security events, network information, application and website usage and, where enabled, location information.
- Communications: emails, customer-support interactions, complaints, call records where lawful, survey responses and information submitted through online forms.
- Cookies and analytics: our website and applications may use cookies, analytics tools and similar technologies (see Cookie Preferences).
How We Collect Personal Information
We generally collect information directly from you when you visit our website, create or maintain an account, complete identity verification, submit a transfer, contact customer support, make a complaint, participate in a survey or promotion, or otherwise communicate with us.
We may also collect information from third parties where reasonably necessary, including identity-verification providers; fraud-prevention providers; sanctions, PEP and financial-crime screening services; banks and payment partners; publicly available registers and information sources; government bodies and regulators; business representatives and beneficial owners; and other parties where collection is authorised or required by law.
Why We Collect, Use and Disclose Personal Information
We collect, use and disclose personal information where reasonably necessary for our functions and activities, including to open, maintain and administer your ARMF account; verify your identity; provide international remittance services; process, settle, reconcile, return or investigate transactions; calculate and display exchange rates and fees; communicate with you; provide customer support; manage complaints; detect, investigate and prevent fraud, scams, unauthorised activity and security incidents; conduct sanctions, PEP, adverse-media and other financial-crime screening; undertake customer and transaction risk assessments; comply with Australia's AML/CTF legislation and other legal and regulatory obligations; respond to lawful requests from regulators, courts and law-enforcement bodies; maintain and improve our services; and send marketing communications where permitted by law and subject to your marketing choices.
We will not use personal information for an unrelated purpose unless you consent or the use is otherwise permitted or required by law.
Identity Verification and Sensitive Information
Financial-services and remittance businesses are required to undertake customer identification and due-diligence activities. ARMF may use specialised service providers and electronic data sources to verify the information you provide. Where biometric information such as a facial image or liveness result is used, we will handle it in accordance with applicable privacy law and any additional consent or notice requirements. We use biometric information primarily for identity verification, fraud prevention and account security. If you do not provide information required to meet our legal or regulatory obligations, we may be unable to open your account, continue providing services or process a transaction.
Disclosure of Personal Information
We do not sell your personal information to third parties for their independent marketing purposes. We may disclose personal information to organisations that assist us in operating ARMF and providing the services, including banks, correspondent institutions and payment partners; identity-verification providers; fraud, sanctions, PEP and financial-crime screening providers; transaction-monitoring providers; cloud hosting and technology providers; cybersecurity providers; customer-support and communications platforms; professional advisers, auditors and insurers; contractors and service providers; regulators and government authorities; law-enforcement agencies and courts; and a purchaser, investor or successor entity in connection with a corporate transaction. We seek to limit disclosures to information reasonably necessary for the relevant purpose.
Regulators and Legal Disclosures
As a remittance provider, ARMF may be required to provide information to AUSTRAC and other competent authorities, including information required for transaction reporting, suspicious-matter reporting and other AML/CTF obligations. We may also provide personal information to law-enforcement bodies, courts, regulators, tax authorities or other government bodies where required or authorised by Australian law. Legal restrictions may prevent us from telling you that particular information has been provided to an authority.
Overseas Disclosure of Personal Information
International remittance necessarily involves cross-border activity. Personal information may therefore be disclosed to recipients outside Australia, including overseas banks, payment partners, identity or compliance providers, technology providers and the institution responsible for delivering money to your beneficiary.
Depending on the service and supplier arrangements in use, overseas recipients may be located in countries or regions including Pakistan, the United Kingdom, the United States, Singapore, countries within the European Economic Area, and the country in which the payment beneficiary is located.
Where APP 8 applies, ARMF will take such steps as are reasonable in the circumstances to ensure an overseas recipient handles personal information consistently with applicable Australian privacy requirements. Your general use of ARMF is not treated, by itself, as consent to waive protections provided by APP 8.
Security of Personal Information
ARMF uses technical and organisational measures designed to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure. Depending on the relevant system, these measures may include encryption; access controls; multi-factor authentication; monitoring and audit logging; secure software and infrastructure practices; staff access restrictions; employee training; vendor risk management; vulnerability management; incident-response procedures; and security testing.
No internet-based system is completely secure, and we cannot guarantee absolute security. You should keep your account credentials and authentication information confidential and contact us immediately if you believe your account or personal information has been compromised.
Data Breaches
ARMF maintains processes to identify, assess and respond to suspected data breaches. Where a breach is an eligible data breach under Australia's Notifiable Data Breaches scheme, we will notify the Office of the Australian Information Commissioner and affected individuals as required by law.
How Long We Keep Personal Information
We retain personal information for as long as reasonably necessary for the purposes for which it was collected and to meet our legal, regulatory, operational and dispute-resolution obligations. In general:
- customer due-diligence records may need to be retained for at least seven years after the relevant business relationship ends or as otherwise required by law;
- transaction records may need to be retained for at least seven years from the relevant transaction or record date;
- compliance and regulatory records are retained for the periods required by law; and
- other account, security, complaint, support and business records are retained only for as long as reasonably necessary.
When personal information is no longer required to be retained, we take reasonable steps to destroy it securely or de-identify it, subject to any legal requirement to retain the information.
Direct Marketing
Where permitted by law, we may send you information about ARMF products, services, promotions or updates. You can opt out of electronic marketing at any time by using an unsubscribe link, changing available communication preferences, or contacting us at privacy@armf.com. Opting out of marketing does not prevent us from sending communications necessary to operate your account, process transactions, maintain security or meet legal obligations. We do not sell personal information to third parties for their independent direct-marketing activities.
Cookies and Similar Technologies
Our website and applications may use cookies and similar technologies to operate services, remember preferences, maintain security, understand service performance and, where applicable and permitted, provide analytics or marketing functionality. Where consent is required for non-essential cookies, we will provide appropriate choices. You may review or change available cookie choices through our Cookie Preferences page.
Automated Systems and Decision-Making
ARMF may use automated systems to support activities such as identity verification; fraud and scam detection; sanctions and PEP screening; transaction monitoring; customer and transaction risk assessment; security monitoring; and identifying transactions or accounts that require additional review.
Automated systems may contribute to decisions including whether additional information or verification is required; a transaction requires further review; a transaction should be delayed or declined; a transaction or account presents an elevated fraud or financial-crime risk; or an account should be temporarily restricted while further checks are undertaken.
Where the Privacy Act requires additional transparency concerning decisions made or substantially assisted by computer programs, including requirements taking effect from 10 December 2026, ARMF will maintain this Policy so that it provides the information required by law. You may contact us if you have questions about how personal information has been used in connection with an account or transaction decision.
Access to Your Personal Information
You may request access to personal information that ARMF holds about you by contacting privacy@armf.com. We may need to verify your identity before providing access. In certain circumstances permitted by law, we may refuse access or provide only limited access, and we will generally explain our reasons unless we are legally prevented from doing so.
Correction of Personal Information
We take reasonable steps to ensure that personal information we use is accurate, up to date, complete and relevant. If you believe information we hold about you is inaccurate, incomplete, out of date, irrelevant or misleading, you may request correction by contacting privacy@armf.com. We will deal with access and correction requests within a reasonable period as required by applicable privacy law.
Anonymity and Pseudonyms
Where practicable, you may interact with ARMF anonymously or using a pseudonym for general enquiries. However, Australian AML/CTF requirements mean that we generally cannot provide remittance services anonymously or under a false identity. We must verify customers before or in connection with providing regulated remittance services as required by law.
Children
ARMF's Australian remittance services are intended for persons aged 18 or older. We do not knowingly open remittance accounts for children. If you believe a child has provided personal information to us in circumstances where it should not have been collected, please contact privacy@armf.com.
Third-Party Websites
Our website or applications may contain links to websites or services operated by third parties. Their collection and handling of personal information is governed by their own privacy practices, and ARMF is not responsible for those practices. We recommend reviewing the privacy information of any third-party service you use.
Privacy Complaints
If you believe ARMF has not handled your personal information appropriately, please contact our Privacy Officer first at privacy@armf.com or +61 3 8679 2233. We will acknowledge your complaint promptly, investigate it fairly and aim to respond within a reasonable period.
If you are not satisfied with our response, you may be able to lodge a complaint with the Office of the Australian Information Commissioner (OAIC). Phone: 1300 363 992, Post: Office of the Australian Information Commissioner, GPO Box 5218, Sydney NSW 2001.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes to our services, systems, operating arrangements, technology, privacy practices or legal requirements. The latest version will be published on our website with an updated effective or "last updated" date. Where a change materially affects how we handle personal information, we will take reasonable steps to provide additional notice where appropriate.
Contact Us
- Entity: ARM Financial Services Pty Ltd (trading as ARM Financial / ARMF)
- ABN / ACN: 35 659 595 570 / 659 595 570
- Address: Suite 110, Level 1, 530 Little Collins Street, Melbourne VIC 3000, Australia
- Privacy: privacy@armf.com
- General support: support@armf.com
- Phone: +61 3 8679 2233