Privacy Policy
Effective Date: September 2026
Governing Framework: Privacy Act 1988 (Cth) & Australian Privacy Principles (APPs)
1. Commitment and Legislative Framework
Annapurna Express Remit Pty Ltd ("AERemit", "we", "us", "our") is committed to protecting your privacy and handling your personal information with transparency and integrity. AERemit is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As a reporting entity registered with the Australian Transaction Reports and Analysis Centre (AUSTRAC), we also collect, verify, and retain personal information to comply with our statutory obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and associated AML/CTF Rules.
2. Information We Collect
We collect personal information necessary to deliver our remittance and payment services, verify your identity, mitigate fraud, and satisfy Australian regulatory obligations.
* Personal Identifiers: Full legal name, residential address, date of birth, nationality, email address, and phone number.
* Government-Issued Verification Documents: Passports, Australian driver licences, Medicare cards, national identity cards, or foreign equivalent identification documents.
* Financial & Payment Data: Bank account details (BSB and Account Number), source of funds/wealth declarations, and electronic payment records.
* Transaction Details: Beneficiary names, destination accounts, remittance amounts, transfer references, currency exchange parameters, and transaction timestamps.
* Technical & Device Information: IP addresses, browser types, mobile device identifiers, geolocation data, login session logs, and tracking technologies (cookies) used to detect anomalous access.
3. How We Collect Your Information
We collect personal information primarily through direct and automated digital channels:
* Directly From You: When you register for an AERemit account, submit identity documents, initiate transactions, or contact customer support.
* Identity Verification Vendors: Through automated verification providers (such as Plaid or Document Verification Service [DVS] partners) using facial biometric matching and electronic database cross-referencing.
* Payment Partners & Financial Institutions: Through payment collection rails and partners, including Zai Australia Pty Ltd and domestic clearing rails, when processing collections and account settlements.
* Public & Watchlist Databases: From official company registries (ASIC), Politically Exposed Persons (PEP) lists, and Australian Department of Foreign Affairs and Trade (DFAT) / United Nations sanctions databases.
4. How We Use Your Information
Your information is processed for primary operational, security, and statutory purposes:
* Remittance Execution: Processing inbound collections, foreign exchange conversions, and outbound settlements to intended beneficiaries.
* Regulatory Compliance: Satisfying Know Your Customer (KYC) / Customer Due Diligence (CDD) mandates, sanctions screening, and statutory transaction reporting (e.g., IFTIs, TTRs, SMRs) to AUSTRAC.
* Fraud Prevention & Platform Security: Monitoring transaction velocity, preventing unauthorized account takeovers, and screening against illicit or restricted business activities.
* Partner & Platform Operations: Coordinating technical integrations, reconciliation workflows, and settlement routines with upstream payment processors including Zai.
* Customer Support & Service Improvement: Resolving account inquiries, disputes, and optimizing user workflows.
5. Data Sharing and Disclosures
AERemit does not sell or rent personal information to third parties. We disclose data strictly on a need-to-know basis to:
* Payment Infrastructure Partners: Regulated payment gateways, collection institutions, and technology providers—notably Zai Australia Pty Ltd—for payment initiation, fraud analysis, and acquiring services.
* Regulatory Authorities & Law Enforcement: AUSTRAC, the Australian Federal Police (AFP), the Australian Taxation Office (ATO), ASIC, or other statutory authorities when required by Australian law or court order.
* Identity Verification & Risk Vendors: Independent screening and verification services (such as Plaid) for document authenticity and sanctions monitoring.
* Payout & Banking Partners: Local and international correspondent banks, liquidity providers, and destination payout operators (e.g., partner banking networks in South Asia) strictly to complete cross-border disbursements.
6. Cross-Border Data Disclosures (APP 8)
Due to the international nature of remittance services, your information may be disclosed to overseas recipients, including our operational hubs, technology maintenance teams, and licensed payout partners in jurisdictions such as Nepal, India, and Canada.
Before disclosing personal information overseas, AERemit takes reasonable steps to ensure that the overseas recipient handles your information in accordance with standards comparable to the Australian Privacy Principles, or where disclosure is necessary to execute your requested international funds transfer instruction.
7. Data Security and Retention
We maintain robust administrative, technical, and physical safeguards:
* Security Controls: Industry-standard TLS/SSL encryption for data in transit, AES-256 encryption for data at rest, role-based access restrictions, and multi-factor authentication.
* Statutory Retention Period: Under Section 106 of the AML/CTF Act, AERemit is legally required to retain customer identification data, transaction logs, and compliance records for a minimum of seven (7) years following the date a transaction is executed or after the business relationship ceases. Data is securely destroyed or de-identified once statutory retention periods expire.
8. Your Rights (Access and Correction)
Under APPs 12 and 13, you have the right to:
* Access: Request a copy of the personal information AERemit holds about you.
* Correction: Request correction of any inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information.
Requests may be made by contacting our Privacy Officer. We will respond within 30 days. Please note that legal exemptions (such as statutory tipping-off provisions or ongoing AUSTRAC reporting obligations) may restrict our ability to alter or delete certain transaction histories.
9. Complaints and Dispute Resolution
If you believe AERemit has breached the Australian Privacy Principles, submit your complaint to our Privacy Officer using the details below. We will investigate and provide a written response within 30 business days.
If you are unsatisfied with our resolution, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
* Website: https://www.oaic.gov.au
* Phone:** 1300 363 992
* Post: GPO Box 5218, Sydney NSW 2001
10. Contact Us
For all inquiries, access requests, or privacy concerns, contact:
Privacy & Compliance Officer
Annapurna Express Remit Pty Ltd (AERemit)
* Email: privacy@aeremit.com / aeremit14@gmail.com
* Phone: +61 490 137 779
Governing Framework: Privacy Act 1988 (Cth) & Australian Privacy Principles (APPs)
1. Commitment and Legislative Framework
Annapurna Express Remit Pty Ltd ("AERemit", "we", "us", "our") is committed to protecting your privacy and handling your personal information with transparency and integrity. AERemit is bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). As a reporting entity registered with the Australian Transaction Reports and Analysis Centre (AUSTRAC), we also collect, verify, and retain personal information to comply with our statutory obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and associated AML/CTF Rules.
2. Information We Collect
We collect personal information necessary to deliver our remittance and payment services, verify your identity, mitigate fraud, and satisfy Australian regulatory obligations.
* Personal Identifiers: Full legal name, residential address, date of birth, nationality, email address, and phone number.
* Government-Issued Verification Documents: Passports, Australian driver licences, Medicare cards, national identity cards, or foreign equivalent identification documents.
* Financial & Payment Data: Bank account details (BSB and Account Number), source of funds/wealth declarations, and electronic payment records.
* Transaction Details: Beneficiary names, destination accounts, remittance amounts, transfer references, currency exchange parameters, and transaction timestamps.
* Technical & Device Information: IP addresses, browser types, mobile device identifiers, geolocation data, login session logs, and tracking technologies (cookies) used to detect anomalous access.
3. How We Collect Your Information
We collect personal information primarily through direct and automated digital channels:
* Directly From You: When you register for an AERemit account, submit identity documents, initiate transactions, or contact customer support.
* Identity Verification Vendors: Through automated verification providers (such as Plaid or Document Verification Service [DVS] partners) using facial biometric matching and electronic database cross-referencing.
* Payment Partners & Financial Institutions: Through payment collection rails and partners, including Zai Australia Pty Ltd and domestic clearing rails, when processing collections and account settlements.
* Public & Watchlist Databases: From official company registries (ASIC), Politically Exposed Persons (PEP) lists, and Australian Department of Foreign Affairs and Trade (DFAT) / United Nations sanctions databases.
4. How We Use Your Information
Your information is processed for primary operational, security, and statutory purposes:
* Remittance Execution: Processing inbound collections, foreign exchange conversions, and outbound settlements to intended beneficiaries.
* Regulatory Compliance: Satisfying Know Your Customer (KYC) / Customer Due Diligence (CDD) mandates, sanctions screening, and statutory transaction reporting (e.g., IFTIs, TTRs, SMRs) to AUSTRAC.
* Fraud Prevention & Platform Security: Monitoring transaction velocity, preventing unauthorized account takeovers, and screening against illicit or restricted business activities.
* Partner & Platform Operations: Coordinating technical integrations, reconciliation workflows, and settlement routines with upstream payment processors including Zai.
* Customer Support & Service Improvement: Resolving account inquiries, disputes, and optimizing user workflows.
5. Data Sharing and Disclosures
AERemit does not sell or rent personal information to third parties. We disclose data strictly on a need-to-know basis to:
* Payment Infrastructure Partners: Regulated payment gateways, collection institutions, and technology providers—notably Zai Australia Pty Ltd—for payment initiation, fraud analysis, and acquiring services.
* Regulatory Authorities & Law Enforcement: AUSTRAC, the Australian Federal Police (AFP), the Australian Taxation Office (ATO), ASIC, or other statutory authorities when required by Australian law or court order.
* Identity Verification & Risk Vendors: Independent screening and verification services (such as Plaid) for document authenticity and sanctions monitoring.
* Payout & Banking Partners: Local and international correspondent banks, liquidity providers, and destination payout operators (e.g., partner banking networks in South Asia) strictly to complete cross-border disbursements.
6. Cross-Border Data Disclosures (APP 8)
Due to the international nature of remittance services, your information may be disclosed to overseas recipients, including our operational hubs, technology maintenance teams, and licensed payout partners in jurisdictions such as Nepal, India, and Canada.
Before disclosing personal information overseas, AERemit takes reasonable steps to ensure that the overseas recipient handles your information in accordance with standards comparable to the Australian Privacy Principles, or where disclosure is necessary to execute your requested international funds transfer instruction.
7. Data Security and Retention
We maintain robust administrative, technical, and physical safeguards:
* Security Controls: Industry-standard TLS/SSL encryption for data in transit, AES-256 encryption for data at rest, role-based access restrictions, and multi-factor authentication.
* Statutory Retention Period: Under Section 106 of the AML/CTF Act, AERemit is legally required to retain customer identification data, transaction logs, and compliance records for a minimum of seven (7) years following the date a transaction is executed or after the business relationship ceases. Data is securely destroyed or de-identified once statutory retention periods expire.
8. Your Rights (Access and Correction)
Under APPs 12 and 13, you have the right to:
* Access: Request a copy of the personal information AERemit holds about you.
* Correction: Request correction of any inaccurate, out-of-date, incomplete, irrelevant, or misleading personal information.
Requests may be made by contacting our Privacy Officer. We will respond within 30 days. Please note that legal exemptions (such as statutory tipping-off provisions or ongoing AUSTRAC reporting obligations) may restrict our ability to alter or delete certain transaction histories.
9. Complaints and Dispute Resolution
If you believe AERemit has breached the Australian Privacy Principles, submit your complaint to our Privacy Officer using the details below. We will investigate and provide a written response within 30 business days.
If you are unsatisfied with our resolution, you may escalate your complaint to the Office of the Australian Information Commissioner (OAIC):
* Website: https://www.oaic.gov.au
* Phone:** 1300 363 992
* Post: GPO Box 5218, Sydney NSW 2001
10. Contact Us
For all inquiries, access requests, or privacy concerns, contact:
Privacy & Compliance Officer
Annapurna Express Remit Pty Ltd (AERemit)
* Email: privacy@aeremit.com / aeremit14@gmail.com
* Phone: +61 490 137 779