FreeAML

Trust & Safety

FreeAML is the AML workflow. Personr is the identity check. This page says which company holds what, in plain language for Australian firms.

Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML. Current as at 24 September 2026 (Melbourne, Australia).

01

Who we are

FreeAML is AML/KYC software for Australian businesses preparing for AUSTRAC Tranche 2: real estate agents, accountants, lawyers, conveyancers, jewellers, and similar firms. The operator is Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML.

The product helps a firm run orders, send a client to be identified, take payment (including a client-pays flow), keep the result with the matter, and produce a customer due diligence report. Sign-in to My is a one-time passcode. Firms can add members with roles.

FreeAML

The workflow: orders, firm access, payments through Stripe, and the CDD record your team works from.

Personr

The verification layer. Identity documents, selfies, liveness, and screening are captured by Personr. Personr Trust Center · Legal Centre

Your firm

The reporting entity, if the AML/CTF Act applies. Your programme, your decision, your statutory file, and your own privacy notice to the client.

02

What FreeAML is and is not

FreeAML is

  • Software for customer due diligence workflows aimed at Tranche 2.
  • The place your team starts a check and reads the outcome.
  • A payer of record through Stripe, including Connect where a firm uses mark-up payouts.

FreeAML is not

  • Your AML/CTF compliance officer or independent reviewer.
  • An AUSTRAC reporting agent. We do not enrol you, and we do not lodge reports for you.
  • Legal advice, or a finding that a client or a file is compliant.
  • The company that captures the passport photo and the liveness check. That is Personr.

The Terms and Conditions set this out as the contract. This page does not narrow them.

03

Privacy Act and the APPs

We handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles, to the extent they apply to us. The Privacy Policy is the notice: what we collect, why, who receives it, overseas disclosure, retention, and how to ask for access or correction (APP 12 and APP 13).

Your firm has its own privacy duties to its clients. Sending someone a verification link does not move those duties onto FreeAML. You need a lawful basis and a clear notice before you send them. Personr shows its own collection notice in the verification flow. Read Personr’s privacy policy for that collection.

We do not sell personal information. We do not use identity documents or biometric data for marketing or unrelated analytics.

If you are not satisfied with how we handle a privacy complaint, you can go to the Office of the Australian Information Commissioner. Write to us first, at team@freeaml.com.au, so we can try to fix it.

04

How a verification works

Identity verification is powered by Personr.

  1. Someone at your firm starts an order in FreeAML, or sends the client a link.
  2. FreeAML asks Personr to open a verification for that person or entity.
  3. The individual completes the check in Personr’s flow: government identity document, selfie, and liveness or biometric matching, as the check type requires. Screening (sanctions, watchlists, and related results) is also Personr’s.
  4. Personr returns status, outcomes, reference identifiers, and related result material. That material can include extracted identity fields and document images.
  5. FreeAML shows the result on the order and can produce a CDD report for your file.
  6. Your firm decides whether the result is enough, whether to ask for more, and whether to proceed. FreeAML does not make that decision.

What Personr says about its own security

Personr states that its platform is ISO 27001:2022 certified, with encryption in transit and at rest (RDS AES-256), and that it is built to run across multiple data centres. Personr also states that it follows the Privacy Act and the Australian Privacy Principles, and the EU/UK GDPR and the CCPA. Those are Personr’s statements, published on the Personr Trust Center and the Personr Legal Centre. FreeAML does not hold ISO 27001, SOC 2, or PCI DSS certification.

05

What FreeAML stores and what Personr stores

The split matters. A firm asking “where is the passport photo?” should get a direct answer.

What FreeAML stores compared with Personr
InformationFreeAMLPersonr
Identity document, selfie, livenessCaptured by Personr. FreeAML may keep document images Personr returns, so the firm can review the result and produce the CDD report.Captured and held in Personr’s systems, under Personr’s privacy policy and data-disposal policy.
Outcome, status, reference IDs, extracted fieldsStored with the order, for the workflow and the report.Produced by Personr and returned to FreeAML.
Screening (sanctions, PEP, watchlists)We store the result summary Personr returns.Run by Personr.
Orders, firm members, rolesStored by FreeAML.Not a Personr firm login.
Card numbersNot collected on our forms. We keep payment status and Stripe identifiers.Not Personr’s role. Stripe collects the card.
Marketing use of ID or biometricsWe do not use them as a marketing or analytics asset.Governed by Personr’s policy, not by a FreeAML advertising programme.

Personr’s subprocessors (including its cloud hosts) are listed by Personr, not invented here: Sub-processors and third-party providers.

06

Who can see a check

People in your firm see what their role allows. The roles shipped today:

Firm roles
RoleWhat they can do
OwnerFirm settings, members, billing, creating and sending checks, all matters, and audit export.
Compliance officerInvites and non-owner role changes, checks, all matters, and audit export. Not billing or ownership transfer.
StaffCreate and send checks, and read matters they can access.
ViewerRead matters. Cannot create or send checks.
AuditorRead all matters and export audit material. Cannot create, send, or change settings.

Selected firm actions — membership changes, order creation, a CDD export, payout steps — are written to an operational log. That log is Phase 1. It does not record every time someone opens a file, and a missed log line does not undo the action. It is not a certified audit archive, and it is not a substitute for the records the AML/CTF Act requires you to keep.

FreeAML staff access is need-to-know: operate the service, answer a support question, investigate abuse. Platform administration is a separate operator allowlist. A customer cannot grant it. We do not publish an independent access-review report.

A verification link lets the holder start or continue that client’s workflow. Send it only to the person you mean to send it to. The Terms put that on you.

07

Subprocessors

The list matches the Privacy Policy: Stripe, Personr (identity verification), email and SMS providers, Vercel, PostHog, and Supabase. Email is sent through Resend and SMS through Twilio.

Subprocessors used to operate FreeAML
ProviderCategoryRoleTheir pages
StripePaymentsCard payments and, where a firm uses it, Stripe Connect for mark-up payouts. Card numbers are entered with Stripe. FreeAML stores payment status and identifiers, not the full card number.
PersonrIdentity verificationThe verification layer. Personr captures identity documents, selfies, and biometric or liveness checks, and runs screening. FreeAML receives the status, outcomes, and related result material so the firm can see the result and produce a CDD report. Personr’s own certifications and retention rules are on Personr’s site, not ours.
Email and SMS providersTransactional communicationsOne-time passcodes, verification links, and other transactional email and SMS. The application sends email through Resend and SMS through Twilio.
VercelHostingHosts the FreeAML application. Production secrets are environment variables on that platform.
PostHogAnalyticsProduct analytics where a project key is configured. The Privacy Policy describes autocapture and session replay. Ingestion may be outside Australia.
SupabaseDatabaseHosts the database for orders, firm memberships, and the verification outcomes FreeAML stores.

Certificates published by those companies belong to them. If we add or replace a processor, we will update the Privacy Policy and this page.

08

Security on the FreeAML side

Reasonable steps, in the sense of APP 11, for the information we hold. The list is what we actually run.

  • HTTPS. The site and app are served over HTTPS, on Vercel. We do not publish a separate TLS white paper.
  • Sign-in. My (/my) uses a one-time passcode by email or SMS. Send and check attempts are rate-limited. We do not offer single sign-on or an authenticator-app second factor.
  • Firm roles. Sensitive actions are checked against the member’s role.
  • Secrets. API keys live in hosting environment variables, not in the public site.
  • Staff access. Need-to-know, for operations and support.

Encryption of identity data inside Personr’s platform is Personr’s control, including the RDS AES-256 at-rest encryption Personr describes. FreeAML does not implement its own application-layer encryption scheme, and we do not claim a named AES mode for our database. Database hosting is Supabase; read Supabase’s security page for that layer. Card data is Stripe’s.

We do not publish a penetration-test report, a public status page, or an uptime percentage. No transmission or storage method is completely secure.

09

Retention and your records

We keep personal information for as long as we reasonably need it to provide the platform, resolve disputes, meet legal and accounting duties, and let you open order history. Payment records kept for tax can outlast short technical logs. We may delete or de-identify information when it is no longer required, subject to backups and legal holds. That is the rule in the Privacy Policy. It is not a promise of a fixed seven-year archive inside FreeAML.

The statutory file is still yours

Reporting entities have to keep AML/CTF records for the period and in the form the law requires. Export them. Leaving a check in the product is not, by itself, that record. Some Australian AML platforms describe a short hold for raw identity images and a long hold for the outcome. FreeAML does not publish that split. Personr’s privacy policy says retention follows the client’s instructions, applicable law, and Personr’s data-disposal policy. Read those documents rather than assuming a timetable we have not stated.

10

Incidents and privacy contact

Privacy requests, corrections, complaints, and suspected security issues go to team@freeaml.com.au. Put “Privacy” or “Security vulnerability” in the subject. Tell us what you saw, when, and which account or order if you know.

  1. We acknowledge the report. We do not publish an hour-count for that reply.
  2. We contain what we can and work out what information was involved.
  3. If we suspect an eligible data breach under the Notifiable Data Breaches scheme (Privacy Act, Part IIIC), we assess it as soon as practicable. The scheme expects that assessment within 30 days. If we believe an eligible data breach has occurred, we notify the OAIC and the individuals at risk as soon as practicable. See the OAIC’s guidance.
  4. If your firm’s workspace is affected and we should tell you, we use the contact details we hold. That notice does not move your AML/CTF duties onto us.

There is no separate vulnerability portal. Evidence held only by Personr can be raised with Personr at privacy@personr.co as well as with us.

11

Documents

Privacy Policy

Available now

Collection, Personr, Stripe, overseas disclosure, retention, and APP rights.

Terms and Conditions

Available now

The software contract, including your AML/CTF responsibility.

Personr Legal Centre

Personr’s site

Personr’s privacy policy, subprocessors, data disposal, and Trust Center. Verification-layer documents live there.

Data processing addendum

Planned

Coming soon. There is no DPA PDF to download or sign. Email us if a pilot needs the current position in writing. A standing security questionnaire pack is not published either. We will answer from this page, the Privacy Policy, and the Terms.

12

FAQ

Whose privacy policy applies?

Three layers. FreeAML’s Privacy Policy covers the platform operated by Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML. Your firm still needs its own privacy notice for the client relationship: why you are asking for identity information, and what you will do with it. Personr’s privacy policy covers the identity documents, selfies, and biometric checks Personr collects in its own flow. FreeAML’s policy does not replace either of the other two.

Who sees identity documents?

The individual completes document and liveness checks with Personr. Personr’s staff and subprocessors see what Personr’s own access rules allow. FreeAML may store the outcome, reference identifiers, extracted fields, and document images Personr returns, so your firm can review the result and produce a customer due diligence report. Inside your firm, visibility follows the role on the membership. FreeAML staff see personal information only where they need it to operate or support the platform. We do not use identity documents or biometric data as a marketing asset, and we do not run our own biometric matching database.

What does FreeAML store, and what does Personr store?

Personr stores the capture: identity documents, selfies, biometric or liveness checks, and the screening it performs. FreeAML stores the workflow around that check: the order, payment status, the outcome and reference identifiers, extracted fields, and document images returned with the result, plus firm and account details. For how long Personr keeps the capture, read Personr’s privacy policy and data-disposal policy. We do not restate a timetable Personr has not fixed in those documents.

Does FreeAML have ISO 27001 or SOC 2? Does Personr?

FreeAML does not hold ISO 27001, SOC 2, or PCI DSS certification, and we do not publish a penetration-test report. Identity verification is powered by Personr. Personr states that its platform is ISO 27001:2022 certified, with encryption in transit and at rest (RDS AES-256), and that it uses multiple data centres. Personr also states that it follows the Privacy Act and the Australian Privacy Principles, and the EU/UK GDPR and the CCPA. Those statements are Personr’s. Read them on the Personr Trust Center. A Personr certificate is not a FreeAML certificate.

Is our data stored only in Australia?

No. We do not offer an Australia-only hosting guarantee. The FreeAML application is on Vercel and the database is on Supabase. Payments are on Stripe. Transactional email and SMS use the providers named in the Privacy Policy: email through Resend, SMS through Twilio. Analytics, where configured, use PostHog. Personr uses its own infrastructure and subprocessors, which include cloud providers that can sit outside Australia. Our Privacy Policy says personal information may be processed overseas, including in the United States. Other countries may not have privacy laws equivalent to Australia’s.

How long are records kept? Is it seven years?

If you are a reporting entity, you must keep the AML/CTF records the law requires, for the period the law requires. FreeAML does not warrant that leaving an order in the product meets that duty. Export what you need. We keep personal information we hold for as long as we reasonably need it to run the platform, meet legal and accounting duties, and let you open order history. Periods differ by record. Personr’s retention of the evidence it holds follows Personr’s privacy policy: client instructions, applicable law, and its data-disposal policy. We do not publish a rule that raw images are deleted after a few days and outcomes are kept for seven years.

Will FreeAML report to AUSTRAC for our firm?

No. You remain the reporting entity if the Act applies to you. FreeAML does not enrol you with AUSTRAC, does not act as your AML/CTF compliance officer, and is not your agent for suspicious matter or threshold transaction reports. A completed or verified status is an operational result of the workflow and of Personr. It is not a finding that your firm has complied with the AML/CTF Act.

Can personal information be disclosed overseas?

Yes. Hosting, payments, identity verification, email, SMS, and analytics can involve processing outside Australia. APP 8 can apply. The Privacy Policy is the notice. We use established providers. We do not control every part of their global operations, including Personr’s subprocessors.

Can we sign a data processing addendum?

Not yet. A DPA is planned. There is no PDF on this site to download or countersign. Email team@freeaml.com.au with the subject “Data processing addendum” and we will tell you where that stands. This page is not a contract.

How do we raise a privacy or security issue?

Email team@freeaml.com.au. Use “Privacy” or “Security vulnerability” in the subject, and include enough detail for us to find the account or order. We will acknowledge and look into it. There is no separate disclosure portal. If we believe there has been an eligible data breach under the Notifiable Data Breaches scheme, we notify the OAIC and the people at risk as the Privacy Act requires. Issues that are only about evidence held by Personr can also go to privacy@personr.co. We will point you there when we can.

Vaz Capital Pvt Ltd as trustee for the Vaz Capital Trust (ABN 28 247 067 155), trading as FreeAML · FreeAML (freeaml.com.au) · Current as at 24 September 2026 (Melbourne, Australia)