Legal

Privacy & Security Policy

Last updated: 25 August 2026

1. Who we are

Comply.LM ("Comply.LM", "we", "us") provides a compliance workspace that helps Australian legal, conveyancing, accounting, and other Tranche 2 reporting entities run firm enrolment, staff onboarding and personal due diligence (PDD), client onboarding, KYC/KYB, AML/CTF risk assessments, secure document storage, matters, consultations, AUSTRAC transactional and annual compliance reporting, staff training, and record keeping. This policy explains what personal information and firm data we handle and how we protect it.

Comply.LM is currently in Beta. We are actively iterating on the product and may update this policy as features and controls evolve.

2. Information we collect

  • Firm and account data: firm name, ABN, trading name, profession, jurisdiction, address, key representative details, staff member name, email, phone, role, and authentication credentials (including Google OAuth identifiers where staff sign in with Google).
  • Staff PDD data: personal due diligence records your firm maintains about its own staff, and training and course completion history.
  • Client data your firm uploads: client identification details (name, date of birth, address, ID documents), beneficial ownership and KYB records, risk assessment inputs, matter records, and supporting documents stored in the secure document store. Clients may submit information directly through the token-based client portal.
  • Consultation and matter data: consultation requests, messages, scheduling and meeting-link details, and any attachments shared by individuals or businesses.
  • Public eligibility-check data: when a member of the public runs the eligibility-check flow we collect the name, contact details, verification OTP, questionnaire answers, payment reference, and generated result PDF needed to deliver the check and receipt.
  • AUSTRAC reporting data: transactional reports, SAR/SMR records, and Annual Compliance Report (ACR) inputs generated within the workspace.
  • Reference and compliance data: country risk, FATF ratings, and sanctions list lookups used to score assessments.
  • Operational data: log events, audit trails, IP address, browser and device metadata, notification preferences, unsubscribe state, and timestamps for approvals and decisions.
  • Payment data: we do not store full card numbers. Consultation and eligibility-check payments are processed by Stripe or PayPal — under your firm's connected accounts for consultations, and under the Comply.LM merchant account for platform eligibility checks and subscriptions. We retain only the references needed for receipts, invoicing, and reconciliation.
  • Support and helpdesk data: messages you send to the in-app AI helpdesk and IT support requests you raise.
  • AI Query Space data: your chat threads and messages, documents and images you upload to a chat, the derived text embeddings used to retrieve relevant passages, the model you selected, and per-call token usage and cost metering against your AI credit allowance.
  • Demo booking data: when you book a demo we collect your name, email, firm, and preferred time, and create a Google Calendar event and invitation on the Comply.LM calendar.
  • Promo and affiliate data: promo code redemptions, affiliate referral links and their encrypted keys, referral status (account created / paid subscription and amount), and points accrual and redemption requests.
  • Demo account data: demo instances use test payment keys and synthetic working data, which may be wiped or reset at any time.

3. How we use information

  • Provide and operate the Comply.LM workspace and public flows (eligibility check, consultation requests, blog).
  • Run automated KYC, KYB, sanctions, and country risk checks.
  • Generate audit-ready records, receipts, invoices, ACR drafts, and reports.
  • Deliver staff training and record course completion.
  • Answer product questions through the in-app AI helpdesk assistant.
  • Operate the AI Query Space: generate answers to your prompts, retrieve relevant passages from documents you upload, enforce your AI usage allowance, and process top-up payments.
  • Schedule demo bookings and send calendar invitations and confirmations.
  • Send transactional emails such as account verification, staff invites, password resets, magic links, consultation and eligibility-check notifications, and unsubscribe confirmations.
  • Improve product quality, reliability, and security.
  • Comply with legal and regulatory obligations including AUSTRAC requirements.

We do not sell personal information. We do not use client data uploaded by your firm to train third-party AI models.

4. Legal basis and data ownership

Your firm is the controller of the client data and staff PDD records you upload. Comply.LM acts as the processor and handles that data on your instructions and under your firm's policies. For the public eligibility-check flow, Comply.LM is the controller of the personal information submitted by the individual, and shares the result with the firm the individual is engaging (where applicable). We process personal information in line with the Australian Privacy Principles under the Privacy Act 1988 (Cth).

5. Sharing and sub-processors

We share data only as needed to operate the service:

  • Hosting and database: our managed backend provider for Postgres, authentication, object storage, and serverless functions; and our edge hosting provider (Netlify) for the production web front-end.
  • Authentication: Google is offered as an optional single sign-on provider for staff. Google receives only the information required to complete the sign-in.
  • AI helpdesk: Lovable AI Gateway powers the in-app helpdesk assistant. Prompts are scoped to product documentation and reference data and do not include client records.
  • AI Query Space: Alibaba Cloud Model Studio (DashScope, Singapore / ap-southeast-1) provides the chat, vision, and embedding models. Prompts, uploaded documents, and generated outputs are processed there to produce answers. Per the provider's service terms, this content is not used to train or improve models, and we contractually and technically rely on that commitment as a guardrail. Only usage metadata (tokens, cost, model) is retained by us for metering.
  • Spam protection and analytics: Google reCAPTCHA v3 scores public form submissions (contact, demo booking) to block abuse, and Google Analytics 4 measures aggregated site usage. Both receive device and browser metadata under Google's own privacy terms.
  • Calendar: Google Calendar hosts the demo booking calendar and sends invitations to the email address you provide.
  • Payments: Stripe and PayPal — under your firm's connected accounts for consultations, and under the Comply.LM merchant account for eligibility-check fees and platform subscriptions. Card data is handled directly by these processors.
  • Email delivery: our transactional email provider for authentication, invite, notification, and receipt emails. Firms on paid plans may connect their own custom sending domain.
  • Reference data: publicly available country risk, FATF, and sanctions sources used to enrich assessments.

We do not disclose your data except as described in this policy or as required by law.

6. Security controls

  • Transport encryption (TLS) for all traffic.
  • Encryption at rest for the database and document storage.
  • Row Level Security on every tenant-scoped table so a firm can only read and write its own records.
  • Role-based access control with distinct Tenant Admin and Platform Admin scopes; Platform Admin never views Tenant data without an explicit support request.
  • Server-side authentication on all protected server functions, with signed sessions and token rotation.
  • Webhook endpoints verify signatures before processing any external payload.
  • Immutable audit trails for approvals, document uploads, and compliance decisions.
  • Strict transport and content security headers, including a conservative Permissions-Policy and X-Content-Type-Options.
  • Least-privilege service roles; the service role key is never exposed to the browser.

7. Data location and retention

Data is stored in regions provided by our backend host. We retain firm and client records for as long as your firm maintains its account and for any additional period required by AUSTRAC or other applicable law. You can request export or deletion of your firm's data at any time.

AI Query Space threads and uploaded documents are kept until you delete the thread or your account is closed; usage metering records (tokens, cost, model — not content) may be retained for accounting. Demo account working data may be wiped or reset without notice.

8. Your rights

Individuals whose data is held in Comply.LM may request access, correction, or deletion of their personal information by contacting the firm that uploaded it. If you cannot reach the firm, contact us and we will route the request appropriately.

9. Cookies and analytics

We use strictly necessary cookies for authentication and session management. We do not use advertising cookies. Google Analytics 4 measures aggregated site usage and Google reCAPTCHA v3 protects public forms from abuse; both set their own cookies under Google's terms. Product analytics is aggregated and used only to improve the service.

10. Children

Comply.LM is a B2B product. It is not directed to children and we do not knowingly collect personal information from children.

11. Changes to this policy

We will post any material changes here and update the "Last updated" date above. Significant changes affecting your firm's data will also be communicated in-app.

12. Contact

Privacy or security questions, including suspected incidents, should be sent to your firm's Tenant Admin or to the Comply.LM support channel inside the app. We aim to acknowledge security reports within one business day.