Skip to content

Privacy

Last updated 15 September 2026

Clarifyd holds identity documents and financial records about people who are usually not our customers, but are dealing with one. This page says what we hold, why, where it lives and when it is destroyed.

Who we are

KYCK GRC Services Pty Ltd (ABN 71 676 098 650), trading as Clarifyd, is an Australian company. We are the entity responsible for the personal information described here, and we are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Two kinds of person

The distinction runs through everything below.

  • Users — people who hold a Clarifyd account. Staff at a business, or people checking someone they’re dealing with.
  • Subjects — the people being assessed or verified. They usually have no account and no direct relationship with us. Their information reaches us because our customer uploaded or entered it, or because they completed an identity check we sent them.

If you are a subject and want to know what we hold about you, contact us.

What we collect

From users, to run the account:

  • Name, email address and optionally a phone number.
  • Business details: entity name, ABN or ACN, sector, AUSTRAC enrolment number where given.
  • Sign-in records: when you signed in, and from which IP address and browser.
  • If you sign in with Google, the name, email address and profile picture Google gives us.

From or about subjects, because an assessment cannot be done without it:

  • Documents uploaded by our customer — identity documents, financial records, corporate records, and anything else they consider relevant.
  • Name and date of birth, which we send to our verification provider for AML screening (PEP and sanctions) when our customer pays for an assessment or asks for the check.
  • For a standard check, the identity document number and address our customer enters. These go to our verification provider for the check. We don't store the document number.
  • Identity verification results, where ClariID is used: a scan of the front and back of an identity document, a facial image, and a liveness video.
  • Identity details extracted from those documents and checked against government and credit records.
  • Signals collected during the check by our verification provider, including whether a VPN was in use and whether the stated location matched the device.
  • The assessment itself: the risk rating, the reasoning, and the indicators relied on.

Biometric information

A facial image and a liveness video are sensitive information under the Privacy Act, and they are the most sensitive things we hold. They are collected only when a customer uses ClariID. The person completes the check themselves, on their own device, through our verification provider, APLYid.

They are destroyed 30 days after we receive them, along with the scans of the identity document and our verification provider’s report of the check.

We keep the result of the check. The customer who asked for it keeps their own records. APLYid keeps its own record of the check under its own privacy policy.

How long we keep things

  • Uploaded documents — destroyed 30 days after the assessment closes.
  • Identity check files — facial image, liveness video, identity document scans, the details read off the document, and the provider’s report of a biometric check, destroyed 30 days after we receive them.
  • The record of the work — issued assessments and reports, check results, PEP and sanctions match reports (which name who on a list a person may match), audit records, company register reports (which name a business’s officeholders), and our record of each person a customer adds: name, date of birth, address, phone, email and PEP status.

We keep the record of the work while it is needed to show what was done, what was decided and why. Both we and our customers may need to produce it years later. We have not set a fixed period for it.

When a file is destroyed we keep the record that it existed: what it was called, a cryptographic hash of its contents, and the time it was destroyed. We keep that on purpose. It is how we can answer “you held my bank statement, what happened to it” — a deleted record could not.

Where it is held

Our database and files are hosted in Sydney, Australia: files with Amazon Web Services (ap-southeast-2), and the database with Neon. Uploaded files are encrypted at rest and are never publicly readable; they are reachable only through short-lived links issued to someone already signed in and entitled to see them.

Some of the providers below are based overseas, mainly in the United States, and personal information may be accessed or processed there. Each is named below with what it receives.

Who we share it with

We do not sell personal information, and we do not disclose it for anyone else’s marketing. We use these providers to deliver the service:

  • APLYid — biometric checks (document scan, facial match and liveness), standard identity checks, AML screening (PEP and sanctions), and company register reports. It checks details against government and credit records.
  • Amazon Web Services — hosting, file storage and email delivery, in Australia.
  • Neon (a United States company) — our database, hosted in Sydney.
  • Stripe (United States) — payments. It receives your email address. Card details are handled by Stripe and never reach us.
  • Google (United States) — sign-in if you choose Google, and address lookup when you enter your business address. Google also serves the portal’s fonts, so it sees your IP address when a page loads.
  • Microsoft 365 — our email inbox, including anything you send to hello@clarifyd.com.au.
  • Anthropic (United States) — document text extraction. Switched off at present. See below.

We may also disclose information where the law requires it, including to AUSTRAC, law enforcement or a court. Where we can lawfully tell you that we have, we will.

Automated processing

Assessments are read and rated by a person. We do not make an automated decision about anyone’s risk rating.

We may use machine assistance to extract text from an uploaded document and to suggest which indicators an analyst should consider. Where that is in use, the analyst sees the suggestion alongside the passage it came from, and the rating remains theirs.

That processing would be carried out by Anthropic, in the United States. It is switched off at present, and we will update this page before we turn it on. Anthropic acts on our instruction and does not use the content to train its models. Neither do we — nothing you or your clients give us trains any model of ours.

Access, correction and complaints

You can ask us what we hold about you, ask us to correct it, or ask us to delete it. Some records we must keep — an assessment we have already issued, or a record required by law — and where that applies we will say so and explain why.

If you are unhappy with how we have handled your information, tell us first and we will investigate. If you are still unsatisfied you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Cookies

The portal sets a cookie to keep you signed in, and stores your light-or-dark preference in your browser. There is no advertising or tracking. Google sees your IP address when it serves our fonts and address lookup.

Contact

Write to us at hello@clarifyd.com.au and we will respond within a reasonable time, and in any case within 30 days.