Skip to content

Privacy Policy

Last Updated: 19 August 2026 | Version 2.1

Duely is a registered business name of Ilixir Technologies Pty Ltd (ABN 11 680 039 392, ACN 680 039 392) ("Duely", "we", "us", "our"). We are committed to protecting your privacy. This Privacy Policy outlines how we collect, use, disclose, and safeguard your personal information when you use our platform and website. This policy is prepared to comply with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth). Duely has applied to be listed on the Office of the Australian Information Commissioner's Privacy Opt-in Register and handles all personal information in accordance with the Australian Privacy Principles.

This policy explains how we handle personal information. Where the Privacy Act requires consent (for example, before an identity check that uses your personal information), we obtain it separately, as described in sections 2 and 7.

1. Role as a Data Processor versus Data Controller

For the AML/CTF compliance tools provided through our platform:

  • the Reporting Entity (Firm / Subscriber) using our platform is the Data Controller of its clients' personal data; and
  • Duely acts as the Data Processor, acting on the instructions of the Firm.

Where Duely obtains identity information from a verification provider or a government registry in the course of an identity check, Duely also has its own obligations under the Privacy Act and its agreements with those providers. Those obligations apply in addition to any instruction from a Firm and, where inconsistent, prevail over it.

If you are an individual whose data has been submitted to Duely by a participating Firm, your primary point of contact for privacy inquiries is the Firm itself. You may also contact us directly (section 10).

2. Information We Collect

We collect personal information to operate and improve our services.

2.0 How We Collect Information

We collect personal information through the following channels:

  • Directly from you: when you register an account, subscribe to a plan, submit a support request, or interact with our platform.
  • From Firms on behalf of their clients: when a Firm uploads customer identity documents, enters customer details, or initiates verification workflows through the platform.
  • From third-party providers: identity verification results from Didit (identity document checks, biometric liveness and face-match results); sanctions, politically exposed person and adverse-media screening results from dilisense; Australian Business Register (ABR) records for ABN and business-name lookups; and payment confirmations from Stripe.
  • Automatically: through cookies, server logs, and analytics tools (PostHog, Google Analytics) when you visit our website or use the platform. See our Cookie and Tracking Policy for details.

2.1 Information Collected from Subscribers (Firms)

When creating an account or subscribing to our services, we collect:

  • contact details (name, email address, phone number);
  • business details (company name, ABN/ACN, role/title), which we verify against the Australian Business Register;
  • billing and payment information; and
  • account credentials and platform usage data.

2.2 Sensitive Data Processed on Behalf of Firms

In operating our AML/CTF compliance platform, we process sensitive customer data on behalf of Firms, which may include:

  • Identity information: names, dates of birth, residential addresses.
  • Government-issued IDs: drivers' licences, passports, Medicare cards, and the document numbers on them. Document numbers are government related identifiers under APP 9. We use and disclose them only to verify the identity of the individual for the Firm's obligations under the AML/CTF Act 2006 (Cth), and we do not adopt them as our own identifier for any person.
  • Biometric data: a live image (selfie), liveness and face-match data processed via our verification partner, Didit. Didit performs this processing outside Australia, in the European Union, and does not retain the data: it is purged once the verification result is returned. Duely stores the resulting verification record in Australia. Retention of the live image is described in section 6.
  • Screening data: Politically Exposed Persons (PEP) status, sanctions list matches, and adverse media findings, obtained by sending the individual's name (and, for individuals, date of birth) to our screening provider, dilisense.

3. How We Use Information

We use the collected information to:

  • operate and maintain the Duely platform;
  • facilitate Identity Verification (KYC/KYB) and screening processes as instructed by the Firm;
  • process payments and manage subscriptions;
  • provide customer support and respond to inquiries;
  • monitor platform security and prevent fraudulent activity; and
  • analyse platform usage and improve our services.

Marketing to Firms: we may use the contact details of Subscribers and their account holders to send product updates, feature announcements and offers about Duely services. You can opt out at any time using the link in the message or by contacting us, and we honour opt-outs promptly (APP 7).

No marketing or profiling of verified individuals: we do not use the personal information of individuals whose identity a Firm asks us to check (their identity information, identity documents, biometric data or screening results) to build profiles of them, to offer, advertise or promote goods or services to them, to enable anyone else to do so, or for market research.

AI features: where a Firm enables AI-assisted document reading, we use a large language model provider (currently Anthropic; we may also use OpenAI, section 4.1) to extract data from documents the Firm uploads, for example to pre-fill identity or entity details for the Firm to check. AI features process data only to provide the service to the Firm. We do not use customer data to train our own or any third party's AI models, and our AI providers do not use the data we send them to train their models under our agreements with them. If we add an AI feature that uses a new provider or processes data for a new purpose, we will update this Policy and, where required, the sub-processor list in the Data Processing Agreement before it takes effect.

4. How We Share and Disclose Information

We do not sell your personal information. We share information only in the following circumstances.

4.1 Third-Party Sub-Processors

We engage trusted third-party providers to assist in operating our platform. These include:

  • Didit: identity document verification, biometric liveness and face-match. Processed outside Australia, in the European Union.
  • dilisense (Zurich, Switzerland): sanctions, politically exposed person, watchlist and adverse-media screening. Processed outside Australia, in Switzerland.
  • Australian Business Register (ABR): ABN and business-name lookups. The ABR is a public government register, not a sub-processor; we send it only the ABN or business name being looked up.
  • AI model providers (Anthropic and/or OpenAI): AI-assisted document reading, only for Firms that enable it. Documents are sent to the provider in the United States for extraction; under our agreements the providers do not use this data to train their models.
  • Stripe: payment processing.
  • Keycloak: authentication and identity management (self-hosted by Duely).
  • BinaryLane (Sydney) and Microsoft Azure (Australia East): cloud infrastructure and storage in Australia.
  • PostHog / Google: platform and website analytics.

4.2 Legal and Regulatory Requirements

We may disclose information where required by law, subpoena, or other legal process, or to protect the rights, property, or safety of Duely, our users, or others. We may also disclose information to a verification provider or the government agency administering a verification service where our agreements with them require it, including for audit of our use of that service. Where permitted by law, we will notify the Firm of such requests in accordance with our Law Enforcement Request Policy.

5. Data Storage and Security

Data Localisation: Application hosting and the primary storage of matter, document, and evidence data are located in Australia (BinaryLane, Sydney, and Microsoft Azure, Australia East). Certain specialist processing is performed outside Australia by our sub-processors Didit (identity document and biometric verification, European Union) and dilisense (screening, Switzerland). Didit operates on a process-and-purge basis: the data is not retained offshore, and the resulting verification record is stored in Australia.

Cross-Border Transfers: Some of our third-party processors operate internationally. This means the relevant data is disclosed to and processed by those providers outside Australia:

  • Didit (identity document verification, biometric liveness / face-match): European Union (AWS). Government-issued identity documents and facial-biometric data are processed by Didit outside Australia. Duely operates Didit on a process-and-purge basis: the identity and biometric data is deleted once the verification result is returned and is not retained by Didit. Didit is GDPR-compliant and holds ISO 27001 and SOC 2 (Type I) certification.
  • dilisense (sanctions, PEP, watchlist and adverse-media screening): Switzerland. Only the name and, for individuals, date of birth of the person being screened are sent.
  • Anthropic / OpenAI (AI-assisted document reading, where enabled by the Firm): United States. Uploaded documents are processed to extract data; not used to train the providers' models.
  • Stripe (payment processing): United States.
  • PostHog (product analytics): United States and European Union.
  • Google Analytics (website analytics): United States.

We put appropriate safeguards in place for cross-border transfers, including reviewing each processor's security certifications, data processing agreements, and compliance with applicable privacy frameworks.

Security Measures: We use security practices including AES-256 encryption at rest, TLS 1.3 in transit, role-based access control (RBAC), and append-only audit logging.

6. Data Retention

We retain data for the periods below. Where a Firm's own legal obligations require longer retention, the Firm is responsible for exporting and keeping its records.

DataRetained by Duely forNotes
Firm account, billing and support recordsLife of the subscription plus 7 yearsTax and corporate record-keeping.
Customer identity records, screening results, risk assessments, audit logs and evidence packsLife of the subscription, then a 90-day export window, then secure deletion (primary systems within 30 days, encrypted backups within 180 days)These are the Firm's AML/CTF records. The Firm must export and keep them for the 7 years required by Part 11 of the AML/CTF Act 2006 (Cth).
Identity document images (front and back)With the customer identity record, as abovePart of the record of the document verified.
Live image (selfie) captured for a face matchWith the verification record, as aboveDuely is introducing automatic destruction of the live image shortly after the face match has been reviewed, keeping only the face-match and liveness result, the provider reference and a hash of the image. This policy will state the period when that takes effect.
Biometric processing by DiditNot retained: processed and purged once the result is returned
Consent records (who consented, when, and to which wording)With the customer identity record; consent records relating to identity checks are kept for at least 7 yearsProducible to the Firm or, where our agreements require, to a verification provider or the government agency administering a verification service.

After deletion we may keep anonymised, aggregated statistics that cannot identify anyone, and anything the law, a court order or our agreements with government verification services require us to keep.

7. Your Privacy Rights

Under the Australian Privacy Principles, individuals have the right to request access to and correction of their personal information.

  • Account holders / Subscribers: you may access and update your profile directly within the platform or by contacting us.
  • Clients of Subscribers (Data Subjects): if you are an individual whose data was submitted by a Firm, please direct your access, correction, or deletion requests to that Firm. We will assist the Firm in fulfilling its obligations.
  • Consent to identity checks: before an identity check that uses your personal information, you are shown a collection notice and asked for your express consent. You may decline, in which case the Firm will need to verify your identity another way, and you may withdraw consent before a check is run by telling the Firm or us.

Note on Deletion Requests: Deletion of certain AML/CTF verification records may be restricted where statutory record-keeping obligations (for example, section 107 of the AML/CTF Act 2006) require the Firm to retain that evidence, overriding general privacy deletion rules.

Children's Privacy: The Duely platform is a business-to-business service for professional services firms, and only individuals aged 18 or over may hold an account. Where a Firm asks us to verify the identity of a person under 18 as part of its customer due diligence, the Firm must obtain consent from a parent or guardian if that person is under 15 or otherwise lacks capacity to consent.

8. Cookies and Tracking

We use cookies for platform functionality, session management, and usage analytics. You can manage your cookie preferences through your browser settings or our website's consent banner. See our Cookie and Tracking Policy for details.

9. Complaints Process

If you believe we have breached the Australian Privacy Principles, or you have a complaint about the collection, use or disclosure of your information for an identity check, please contact us with your concerns. We will acknowledge your request within 7 business days and aim to resolve it within 30 days.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

10. Contact Us

For any questions about this Privacy Policy or our data practices, please contact our Privacy Officer at:

Email: [email protected]
Entity: Ilixir Technologies Pty Ltd (ABN 11 680 039 392), trading as Duely
Address: Bellbird Park, Queensland 4300, Australia