FreeAML customer agreement
This document is the customer-facing Data Processing Agreement for FreeAML. It is published for review at freeaml.com.au/dpa. Your firm accepts it by using the Platform, as section 16 describes. There is no separate countersignature screen and no downloadable signature pack. Personr’s data-processing terms sit upstream, between Personr and FreeAML. Your firm does not sign Personr’s DPA by using FreeAML.
1. Parties and status
This Data Processing Agreement (the “DPA”) is between the business that uses FreeAML (the “Customer”, “firm”, or “you”) and Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML (the “Operator”, “FreeAML”, “we”, “us”, or “our”).
The Operator is Vaz Capital Pvt Ltd, acting as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML. Notices under this DPA may be sent to team@freeaml.com.au.
This DPA forms part of the Terms and Conditions (the “Terms”) and should be read with the Privacy Policy and the Trust & Safety page. If this DPA and the Terms conflict about the processing of personal information described here, this DPA prevails to the extent of the conflict. If they conflict about liability, indemnity, fees, or the liability cap, the Terms prevail.
Nothing in this DPA makes the Operator an AUSTRAC agent, a reporting entity for your designated services, or your AML/CTF compliance officer.
2. Definitions
In this DPA, unless the context otherwise requires:
- “AML/CTF Laws” has the meaning given in the Terms.
- “Client” means an individual or entity in respect of whom you initiate, or who completes, a verification or related workflow on the Platform, including a beneficial owner you ask us to contact.
- “Personal information” has the meaning given in the Privacy Act 1988 (Cth), and includes information about an individual who is reasonably identifiable.
- “Platform” means the FreeAML software, website at freeaml.com.au, dashboards, and related communications described in the Terms.
- “Process” means to collect, hold, use, or disclose personal information, as those ideas are used in the Australian Privacy Principles.
- “Sub-processor” means a third party we engage to process personal information so that we can provide the Platform. The current list is Annex B.
Words defined in the Terms have the same meaning here unless this DPA gives them another meaning.
3. Roles
You remain the APP entity for personal information about your clients that you collect for your business, including customer due diligence. In processing terms, you are the controller: you decide why that client information is collected and what the check is for.
FreeAML is a processor and service provider. We process personal information on your instructions to provide the Platform. We are also an APP entity for personal information we hold in our own right, such as firm user accounts and our own business records. That does not move your client relationship, your privacy notice, or your AML/CTF duties onto us.
Personr is FreeAML’s upstream identity-verification provider. We engage Personr as a sub-processor for identity verification, as Annex B describes. Personr also collects identity documents, selfies, and liveness or biometric checks directly from the individual in Personr’s own flow, under Personr’s privacy notice. Personr’s data processing agreement is between Personr and FreeAML. Customers do not sign it.
An individual who completes a check is not a party to this DPA. You are responsible for your own collection notice to that person.
4. Nature and purpose of processing
We process personal information so that you can run AML/CTF workflow on the Platform: create and manage orders, invite colleagues, send a verification, take payment, receive the outcome, and produce a customer due diligence report for your file. The categories of people, the categories of information, and the purposes are set out in Annex A. They follow the Privacy Policy, including verification artefacts the Platform stores when Personr returns them.
We do not sell personal information. We do not use identity-document images or biometric identity data as a FreeAML marketing or advertising asset, and we do not build our own biometric matching database.
The Platform does not enrol you with AUSTRAC, does not act as your agent for suspicious matter or threshold transaction reports, and does not decide that your firm has complied with the AML/CTF Laws. A completed or verified status is an operational result of the workflow and of Personr. It is not a compliance finding.
5. Customer instructions
Your instructions are this DPA, the Terms, the Privacy Policy, and the actions your users take in the product. Creating an order, entering a client’s details, sending a verification link, and asking for a report are instructions to process the personal information needed for that step.
You must have a lawful basis for the collection you ask us to support, and you must give your clients the notice the Privacy Act and your own AML/CTF programme require. You must not instruct us to process personal information for a purpose this DPA and the Privacy Policy do not describe.
If you send an additional written instruction to team@freeaml.com.au, we will follow it where the Platform can already do so and where it would not break the law or another customer’s privacy. If the product cannot carry out the instruction, we will tell you. We are not obliged to build a new feature to meet it.
We may refuse or suspend an instruction that we reasonably believe is unlawful, harmful, or outside the Platform. The suspension rights in the Terms still apply.
6. FreeAML obligations
We will:
- process Customer personal information for the purposes in Annex A and the Privacy Policy, and on the instructions in section 5;
- not process identity-document images or biometric data for our own secondary marketing;
- apply the security measures in section 7;
- use the sub-processors in Annex B, and tell you about changes by updating this DPA, the Privacy Policy, and the Trust & Safety page;
- assist you, to a reasonable extent and using the information we actually hold, with access and correction requests under the Australian Privacy Principles that relate to personal information we hold for you;
- notify you of a suspected eligible data breach as section 11 describes; and
- answer reasonable information requests as section 12 describes.
Where a request is really about identity evidence held only by Personr, we will point you to Personr. We do not control Personr’s systems.
Our staff and contractors may handle personal information only where they need it to operate or support the Platform, and they are required to keep it confidential.
7. Security
We take reasonable steps, in the sense of Australian Privacy Principle 11, to protect personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. The steps we actually run are:
- HTTPS. The site and application are served over encrypted transport (HTTPS).
- Sign-in. The firm area at /my uses a one-time passcode by email or SMS. Send and check attempts are rate-limited. We do not offer single sign-on, and we do not offer an authenticator-app second factor.
- Access controls. Firm roles limit who can create checks, read matters, change settings, or export audit material. Platform administration is a separate operator allowlist. A customer cannot grant it.
- Secrets. API keys are held as hosting environment variables, not in the public site.
- Staff access. Need-to-know, for operations and support.
Card numbers are entered with Stripe. We store payment status and identifiers, not the full card number. Database hosting is Supabase. We do not claim a named application-layer encryption scheme of our own for that database.
FreeAML does not hold ISO 27001, SOC 2, or PCI DSS certification, and we do not publish a penetration-test report. Identity verification is powered by Personr. Personr states that its platform is ISO 27001:2022 certified, with encryption in transit and at rest (RDS AES-256), and that it uses multiple data centres. Those statements are Personr’s. A Personr certificate is not a FreeAML certificate.
No method of electronic storage or transmission is completely secure.
8. Sub-processors
You authorise us to use the sub-processors in Annex B. The list matches the Privacy Policy, in the same order: Stripe, Personr (identity verification), email and SMS providers, Vercel, PostHog, and Supabase. Email is sent through Resend and SMS through Twilio. That email and SMS work sits in one row. We do not list a separate authentication vendor.
Personr may itself use sub-processors. Those are listed by Personr, not by us.
If we add or replace a sub-processor, we will update Annex B, the Privacy Policy, and the Trust & Safety page before or as we start using them for Customer personal information. We do not run a separate sub-processor mailing list. Continued use of the Platform after the updated list is published is acceptance of that list, on the same basis as changes to the Terms. If you do not agree, you must stop using the Platform.
We remain responsible for the sub-processors’ processing under this DPA to the extent the Terms and section 13 allow. Certifications published by a sub-processor belong to that sub-processor.
9. International transfers
Personal information may be disclosed to, and stored or processed by, sub-processors located outside Australia, including in the United States and other countries where those providers operate. Hosting, payments, identity verification, email, SMS, and analytics can all involve overseas processing. Australian Privacy Principle 8 may apply.
We do not offer an Australia-only hosting guarantee. Other countries may not have privacy laws equivalent to Australia’s. By using the Platform, you acknowledge that overseas processing may occur as reasonably necessary to provide the service, as the Privacy Policy already states.
We take reasonable steps in the circumstances so that overseas recipients do not breach the Australian Privacy Principles in relation to the information, including by using established providers. We do not control every part of their global operations, including Personr’s sub-processors. We do not claim that a particular transfer tool, such as a standard contractual clause pack, is in place unless we have said so in writing for that provider.
10. Retention, export and deletion
You are responsible for statutory AML/CTF record-keeping. If you are a reporting entity, you must keep the records the law requires, for the period and in the form the law requires. FreeAML is not your system of record for AUSTRAC retention. This DPA does not warrant a seven-year archive, and leaving an order in the product is not, by itself, that statutory file. Export or download what you need while you still have access. Where the product offers an audit or evidence export for your role, use it. There is no separate “download my entire statutory file” product beyond the exports and reports the Platform already shows.
We keep personal information we hold for as long as we reasonably need it to provide the Platform, resolve disputes, enforce agreements, meet legal and accounting duties, and let you open order history, as the Privacy Policy describes. Periods differ by record. Payment records kept for tax can outlast short technical logs. We may delete or de-identify information when it is no longer reasonably required, subject to backups and legal holds.
After you stop using the Platform, you may email team@freeaml.com.au and ask us to delete or de-identify personal information we hold for your firm. We will do so within a reasonable period, except where we need to keep it for law, tax, accounting, dispute, or security reasons, or it remains in backups until those backups cycle. There is no self-service “delete the firm” control in the product today.
Personr captures identity documents, selfies, and liveness or biometric checks in Personr’s flow. Where Personr returns document images or other verification artefacts, we may store those copies so you can review the result and produce a customer due diligence report. Deleting information from FreeAML does not, by itself, delete copies Personr holds. Personr’s retention follows Personr’s privacy policy, your instructions to the extent Personr accepts them, and applicable law. We do not restate a timetable Personr has not fixed in those documents.
11. Breach notification
If we become aware of a suspected eligible data breach under the Notifiable Data Breaches scheme (Privacy Act, Part IIIC) affecting personal information we hold for your firm, we will notify you without undue delay after we have a reasonable understanding of what happened, using the contact details we hold. We do not publish a fixed number of hours for that notice.
We will assess a suspected eligible data breach as soon as practicable. The scheme expects that assessment within 30 days. If we believe an eligible data breach has occurred, we notify the Office of the Australian Information Commissioner and the individuals at risk as soon as practicable, as the Privacy Act requires. See the OAIC’s guidance.
Notice to you does not move your AML/CTF duties or your own APP duties onto us. You remain responsible for notices you must give your clients or AUSTRAC.
There is no separate vulnerability portal. Email team@freeaml.com.au with “Security vulnerability” or “Privacy” in the subject. Evidence held only by Personr can also be raised with Personr at privacy@personr.co. We will point you there when we can.
12. Information requests
On a reasonable written request to team@freeaml.com.au, we will provide information reasonably required for you to assess our handling of personal information under this DPA. That information is this DPA, the Privacy Policy, the Trust & Safety page, and written answers to reasonable follow-up questions about them.
We do not publish a penetration-test report, a SOC report, an ISO certificate of our own, or a standing security-questionnaire pack. We do not offer on-site audits. We may refuse or narrow a request that would compromise the security of the Platform or reveal another customer’s information, or that is repetitive or unreasonable in scope. We may answer from the published documents rather than completing a third-party spreadsheet line by line.
13. Liability and indemnity
This DPA does not increase the Operator’s liability beyond the Terms, and it does not add a separate uncapped indemnity.
To the maximum extent permitted by law, the limitation of liability, the Australian Consumer Law clause, and the indemnity in the Terms apply to claims arising out of or in connection with this DPA. That includes the exclusion of indirect and consequential loss, regulatory fines imposed on you, and the cap: the greater of the fees you paid to the Operator for the specific paid check or subscription period giving rise to the claim, and AUD 100.
Nothing in this DPA limits liability for fraud, fraudulent misrepresentation, or any liability that cannot be limited under applicable law, including non-excludable rights under the Australian Consumer Law.
If this DPA and the Terms conflict about liability, indemnity, or that cap, the Terms prevail.
14. Term and termination
This DPA starts when you accept it under section 16 and continues while you use the Platform. It also continues for as long as we hold personal information processed under it, and clauses that should survive (including confidentiality, retention and deletion, liability, and governing law) survive.
You may stop using the Platform at any time. We may suspend or terminate access as the Terms allow. On termination we may disable access. You should export records you are required to keep before access ends. We have no obligation to retain data after termination except as required by law or as the Privacy Policy and section 10 describe.
15. Governing law
This DPA is governed by the laws of the State of Victoria, Australia. The parties submit to the exclusive jurisdiction of the courts of Victoria, Australia, and courts of appeal from them, except that the Operator may seek injunctive or urgent relief in any jurisdiction.
Before commencing proceedings (other than for urgent relief), each party must attempt in good faith to resolve the dispute by written notice and a reasonable period of negotiation, as the Terms require.
16. Acceptance
There is no electronic-signature product and no countersigned PDF in FreeAML. You accept this DPA in the same way you accept the Terms: by accessing or browsing the Platform, creating an account, sending or completing a verification, initiating a payment, clicking to accept where a screen says that continuing means you agree, or otherwise using the Platform.
If you use the Platform for a business, partnership, company, trust, or other organisation, you confirm that you have authority to bind it, and “you” includes that organisation.
Where a signup screen refers to the Terms and the Privacy Policy, this DPA is incorporated into those Terms for personal information we process for the firm. You may print or save this page for your file. A wet-ink copy is not required.
We may update this DPA by publishing a new version at freeaml.com.au/dpa and revising the “Current as at” date. Material changes may also be notified by email or in-product notice where reasonably practicable. Continued use after the updated version is published is acceptance. If you do not agree, you must stop using the Platform.
Questions about this DPA: team@freeaml.com.au, with “Data processing agreement” in the subject line.
Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML · FreeAML (freeaml.com.au) · Current as at 25 September 2026 (Melbourne, Australia)
17. Annex A — Details of processing
Subject matter. Hosting and operating the Platform so the Customer can run customer due diligence workflow, including identity and entity checks arranged through Personr, payments through Stripe, and the reports and audit material the product generates.
Duration. The term in section 14, and afterwards only as section 10 and the Privacy Policy allow. Not a fixed seven-year statutory archive.
Nature and purpose. Collection, storage, display, transmission to the sub-processors in Annex B, and deletion or de-identification, for the purposes in section 4 and the Privacy Policy.
Data subjects.
- Firm users — your personnel who use the Platform, including owners, compliance officers, staff, viewers, and auditors;
- Clients and other subject individuals undergoing customer due diligence, including beneficial owners you nominate;
- People who pay for a check, where that is someone other than a firm user; and
- Website visitors, to the limited extent of cookies, local storage, and analytics described in the Privacy Policy.
Categories of personal information. These are the categories the Privacy Policy describes, plus verification artefacts the application stores when Personr returns them. We do not add categories the product does not handle.
| Category | Examples the product handles |
|---|---|
| Account and contact details | Name, email address, telephone number, organisation name, and role. Used for the firm account, one-time passcodes, and team access. |
| Order and workflow details | Verification type, reference notes, short codes, timestamps, questionnaire answers, entity name and registration numbers you supply, beneficial-owner contact details you enter so a check can be sent, and parent/child order links for ownership chains. |
| Verification outcomes | Applicant or session identifiers, verification links, status, review outcomes, screening summaries, and extracted identity fields Personr returns (such as name, date of birth, address, or document type), so you can see the result and produce a customer due diligence report. |
| Verification artefacts | Document images and related document metadata (such as document type, document number, and expiry) that Personr returns. Personr captures the identity document, selfie, and liveness or biometric check. FreeAML may store the artefacts Personr returns. We do not claim that identity-document images are stored only by Personr. We do not use those images as a marketing or analytics asset. |
| Payment metadata | Whether a payment is pending, paid, failed, or refunded; amounts; client-pays and mark-up flags; Stripe session or payment-intent identifiers; Connect account identifiers; and payout or earnings status. Not the full card number or CVC. Stripe collects card data, and Stripe collects bank details if you onboard to Connect. |
| Communications | Messages you send us, and records of transactional email or SMS we send, including one-time passcodes and verification links. |
| Logs, cookies and analytics | Technical logs (timestamps, errors, limited request metadata), functional cookies and local storage, a visitor identifier, and, where a project key is configured, PostHog product analytics, which may include autocapture and session replay as the Privacy Policy describes. |
Sensitive identity evidence that Personr collects in its own capture flow, and that Personr does not return to us, is held by Personr under Personr’s privacy policy. This Annex describes what FreeAML processes. It is not a warranty that every image Personr captures is copied into FreeAML.
18. Annex B — Sub-processors
Six categories, in the same order as the Privacy Policy and the Trust & Safety page. Resend and Twilio are named inside the email and SMS row because the application calls those services. There is no separate authentication-vendor row.
| Provider | Category | Role |
|---|---|---|
| Stripe | Payments | Card payments and, where a firm uses it, Stripe Connect for mark-up payouts. Card numbers are entered with Stripe. FreeAML stores payment status and identifiers, not the full card number. |
| Personr | Identity verification | The verification layer. Personr captures identity documents, selfies, and biometric or liveness checks, and runs screening. FreeAML receives the status, outcomes, and related result material so the firm can see the result and produce a CDD report. Personr’s own certifications and retention rules are on Personr’s site, not ours. |
| Email and SMS providers | Transactional communications | One-time passcodes, verification links, and other transactional email and SMS. The application sends email through Resend and SMS through Twilio. |
| Vercel | Hosting | Hosts the FreeAML application. Production secrets are environment variables on that platform. |
| PostHog | Analytics | Product analytics where a project key is configured. The Privacy Policy describes autocapture and session replay. Ingestion may be outside Australia. |
| Supabase | Database | Hosts the database for orders, firm memberships, and the verification outcomes FreeAML stores. |
The named providers are listed in this Annex B. The Trust & Safety page lists categories only and points here for the current named list.