Privacy Policy (Version 4.4 as of 19 June 2026)
1 INTRODUCTION
1.1 Definitions:
“we”, “us” and “our” refer to “Data Zoo” [Data Zoo Pty Ltd (ACN 146 612 553); Data Zoo Limited (CN3287828); Data Zoo Pte Ltd (UEN201718678C); Data Zoo US LLC]. “you” or “user” means you and includes everyone who visits and interacts with Data Zoo including existing and prospective, customers, data subjects, employees, contractors, and interns etc. “Personal information” refers to information or data (linked or unlinked) that identifies an individual (directly or indirectly).
1.2 Privacy at Data Zoo
We are a private sector identity verification (“IDV”) service provider and a Gateway Service Provider (GSP) for the Australia Document Verification Service (DVS). We understand the importance of protecting your privacy, which we demonstrate through our commitment to compliance with privacy and data protection legislation and standards, wherever we operate. From our established APAC presence in Australia, New Zealand, and Singapore; our US Operations and EU presence, we cross multiple jurisdictions around the globe, each with different protection measures that collectively aim to protect your privacy, whenever and wherever you or your personal information interacts with us.
At Data Zoo, we take a global approach to privacy, strongly emphasising compliance with global and regional data protection and privacy, standards, laws, and regulations. This includes compliance with the Australian Privacy Principles (The Privacy Act 1988 and related legislation), the New Zealand Privacy Principles (The Privacy Act 2020 and related legislation), the Singaporean Personal Data Protection Act 2012, TheEuropean Economic Area (EEA) General Data Protection Regulation (EU) 2016/679 (General Data Protection Regulation) (“GDPR”); Chinese Personal Information Protection Law 2021 (PIPL); US data protection and privacy compliance against the Californian Consumer Protection Act (“CCPA”) and the Californian Privacy Rights Act of 2020 (“CPRA”), while keeping up-to-date with evolving privacy regimes across the globe.
This Privacy Policy sets out how we collect, use, share, store and safeguard your information when you interact with us by visiting our website, visit us in person, for marketing and sales purposes, or through our Products and Services. Our Policy extends to include your right to control your privacy, which includes having access, making corrections, or deletions or objecting to the processing of your personal information. As an ethical and responsible Identity Verification Service provider, it is important for you to appreciate that once we receive your personal information, we apply the principle of data minimisation in our collection, storage, and use (see Retention, Disposal or Destruction of Personal Information) and maintain control and responsibility of what we hold for you. We do not sell the personal information of Californian data subjects to anyone. Where we sell or share personal information, it will be in the facilitation of services to you the data subject, and we will do so based on your consent or other lawful basis as outlined in this policy.
1.3 The Privacy and Data Protection Officer
If you have any queries regarding the content and subject matter of this policy; wish to request access, correction or deletion of your personal information; wish to withdraw your consent; wish to object to us processing your personal information, or require further assurance of how we securely use your personal information, please submit a Data Access Request with our Privacy and Data Protection Officer through our webform here, or by using the relevant details below depending on the personal data in question. We will do our best to deal with your request or query as soon as possible.
If you have questions or concerns regarding your personal data, please contact the relevant officer or representative for your jurisdiction:
The Privacy and Data Protection Officer
Data Zoo Pty Ltd
Suite 1803, 99 Mount Street
North Sydney, NSW 2060
AUSTRALIA
Email: privacy@datazoo.com
UK GDPR Representative
Euverify Ltd (UK)
3rd Floor, 86-90 Paul Street
London, EC2A 4NE
United Kingdom
Email: gdpr@euverify.com
EU GDPR Representative
Euverify Ltd (Ireland)
Unit 3D North Point House
North Point Business Park
New Mallow Road, Cork
T23 AT2P, Ireland
Email: gdpr@euverify.com
1.4 Accessibility
Hyperlinks are provided to allow you to quickly move around this Privacy Policy and access external resources. You may also download a PDF copy of our Privacy Policy if you wish. If you require a printed copy of this Privacy Policy (at no charge) or require it to be available in another language or alternative format for accessibility (including users with disabilities), please contact our Privacy and Data Protection Officer, or the representative using the details above or by submitting an online request via the privacy request webform (https://datazoo.com/policy/privacy-policy) on our website. If you are visually impaired, and reading this notice on our website, you may access this notice through your browser’s text-to-speech voice reader.
2 VISITORS
You are a Visitor if you visit our websites or otherwise contact us.
2.1 Personal information we collect:
We collect personal information from Visitors:
a) when you visit our website: through the use of Website analysis and Cookies; and when the visitor uses the “contact us”, “book a demo”, or online query form; or
b) when you contact us through a marketing campaign, register and/or attend any of our events (e.g. podcasts, and webinars), at conferences or marketing events, or connect/contact us via professional networking platforms such as LinkedIn; or
c) when you email, telephone, or meet us in person.
We collect and securely store the Visitor’s Name, the Name of their Organisation, Email Address, any Email Correspondence, Telephone Number and IP Address. We may also collect Other Personal Information that the Visitor voluntarily submits to us (see 11.1 Unsolicited Personal Information).
2.1.1 Website Analysis and Cookies
Our web server collects information on the usage patterns of people visiting our website for the legitimate purpose to assess, develop and improve your usability of our services. The information is collected each time a user visits our website and consists of the date and time of visits; the number of users who visit the website; and the traffic patterns and pages viewed. We do not seek to identify your browsing activities. Our websites in the most part use only session-based cookies that collect and process the personal information of Customers and demonstration users for the functional purpose to keep them logged in during a session. We may also use cookies from third parties. We self-manage all our Cookies (including preferences, and consents). To find out what cookies we currently collect, how and why, see our Cookie Policy. Our website and services are not directed at children, and we do not knowingly collect or solicit data from anyone under the age of 18. If you have any concerns or believe such information has been collected, please contact our Privacy and Data Protection Officer or reach out through the webform here.
2.2 Why we collect personal information from Visitors
We will only ever use your personal information in accordance with the consent and purpose you have provided (Consent Management Policy available upon request) and in conformance with relevant and applicable Privacy Laws. We collect and process your information predominantly to respond to or facilitate your queries or requests. We may also collect your personal information and process it within our clients’ specific legitimate interests [1], which may include the operation of our/their business, internal analytics, and to improve our website. Subject to your consent we may also provide you (via email or other medium) with updates on our services and marketing content. We do not share any Visitor personal information with third-party providers except where that Visitor is a Customer.
[1] Article 6(f), GDPR allows us to process people’s personal data for the data controllers' specific legitimate purpose unless their interests, rights and freedoms override that purpose.
2.4 Right to Anonymity |
|---|
Where possible, our systems will allow you to communicate with us on an anonymous basis or by using a pseudonym. We do not seek to identify you when you access our websites or otherwise contact us. The provision of personal information through the website or other means of communication is, therefore, entirely voluntary. Please note, however, that it may be difficult for us to fully respond to your query or enquiry without certain contact details. Communication with Customers requiring assistance in relation to specific accounts or the information which they have provided us for the purposes of establishing or using the account, may not be practically possible without further details being first provided by the Customer. |
3 CUSTOMERS
Customers are organisations (through their authorised representatives) to whom we provide identity verification and / or Fraud detection services under contract (to enable Customers to verify Individual Verification/Data Subjects) against a selection of data sources. Our Customers range from SME’s (Small to medium sized enterprises) to big global organisations. These include, amongst others, reputable payment gateway providers, heavily regulated Financial Institutions and providers of Age Restricted products and services.
3.1 Why we collect personal information from Customers
We collect information about you, from the initial pre-contracting introduction of prospects to onboarding you as a Customer. This includes Identifiers and Customer Record Information [2], your Company Name; Company Registration Details, the Name of your Representative(s), Contact Telephone Number(s), Email Address(es) and Correspondence, and IP Addresses. We may conduct additional enquiries and collect further information depending on the services which you request to acquire. This includes information obtained for due diligence purposes from publicly available sources such as, a Company Registry, Privacy Registry, Taxation Number Registry, your LinkedIn presence, and your website. IP addresses are collected as part of our security and authentication measures when providing you access to our services (see also Information Security Policy).
[2] As per CCPA 1798.140 (o)(1) within the definition and categories of personal information.
3.2 The lawful basis for processing your personal information
With the exception of marketing purposes (for which we would seek consent), we collect and process your personal information on the lawful basis of ‘legitimate interest’, in that it is necessary in order to successfully enter into and perform a contract with you while complying with the relevant legal obligations. This legal basis extends to: communicating with you; conducting due diligence checks on you, which includes Know Your Customer (“KYC”) and Know Your Business (“KYB”) searches; securely providing identity verification services to you; providing information to specific organisations with whom you have authorised us to communicate; managing the Customer relationship and providing support to you.
3.3 Sharing or disclosing of your personal information
We do not share any of your personal information to any third-party service providers unless it is in the provision of services to you (via those providers) as our Customer. We share Customer personal information with our third-party service providers, which includes the Customer Records Management Software (CRM), SMTP delivery services, our contracted marketing, and External Legal Counsel. All information shared is strictly limited to the legitimate purpose for which it is required (e.g. successful performance and management of the contract we have with you) and is subject to our information security controls (set out in our Information Security Policy), data processing agreements, and relevant privacy laws. A full list of the categories of our third-party service providers is available upon request.
We will otherwise only disclose your personal information in the following circumstances:
where you have given your consent (within the scope of the specified purpose);
where we are required to do so by law or enforceable request by a regulatory body;
where it is necessary for the purpose of, or in connection with legal proceedings or in order to exercise or defend legal rights; and
if we sell our company, merge with another company, or go into administration (we will treat all personal information in conformance with the relevant Privacy laws and obligations).
4 Verification Subjects and their Privacy rights
4.1 Verification Subjects
Verification or Data Subject is an individual who our Customers request to identify using our identity verification services.
A Verification or Data Subject is an individual who our Customers request to identify using our identity verification and/ or fraud detection products and services. We act as a Personal Data Processer to process the personal information of Verification Subjects, on behalf of and in accordance with the instructions provided by our Customers who act as Data Controllers. We do not claim any ownership or rights over the personal information of Verification Subjects processed on behalf of our Customers and act only on our Customers’ instructions. We de-identify any personal information of a Verification subject 24hours after the completion of processing for a Customer. Any personal information of a Verification Subject that is still to be fully processed or where reprocessing is considered ‘work-in-progress’, we hold on behalf of the Customer. If you require further information on how your information is used, please contact the Customer organisation.
4.2 Verification Subject Personal Information Processing
Verification Subject personal information is processed against personal information either held and processed by Matching services provided by our suppliers, OR collected, compiled, maintained, and held by us in processes separate to those used by our Customers. The categories of personal information we handle in the course of the verification process and used strictly for Identity Verification and Fraud detection may include: Identifiers (Name, Address, Date of Birth, Government Identifiers such as Passport Numbers, and State Identification Numbers); Customer Records Information (Name, Address, Telephone Number, Email address),; and Biometric Information (Face Matching).[3]
[3] CCPA 1798.140 (o)(1) defines personal information and outlines categories of personal information.
4.2.1 Suppliers of Matching Services
Our suppliers of personal information matching services undergo a rigorous due diligence process to ensure that their information has been lawfully, collected, compiled, and made available for the purpose of identity verification. The actual data matching process is undertaken by the supplier using a secure Application Programming Interface ("API") where we, on behalf of our Customer, will submit a Verification Subject’s personal information to a supplier to receive a <Matched>, <Not Matched> or other response that we will return to the Customer. The Customer will interpret and incorporate responses according to their own matching rules and advise a result to the Verification Subject.
We do not extract, retain, make a record of, nor modify any personal information held by any supplier. Suppliers are subject to Privacy laws, regulations, and standards, in addition to compliance with their contractual obligations and our Supplier Code of Conduct, which we regularly audit to ensure the integrity of our data sources. Suppliers have a responsibility to protect personal data from improper disclosure, theft, or misuse at all times. Suppliers are additionally required to ensure that they do not store any transactional Personal Identifiable Information except where required to do so to satisfy legal or regulatory compliance obligations. The Supplier must maintain a Data Breach Notification Policy that conforms with the relevant legislation and reporting obligations, and must immediately report to Data Zoo any incident that involves our personal data including Data Zoo Client Data and verification subject data provided for processing.
4.2.2 Data Zoo Data (collected, compiled, maintained, and held by us)
We also collect, compile and hold personal information sourced from either, or a combination of:
1) the public domain such as published directories, lists and other publicly available sources, and/or
2) consented personal information sourced directly from individuals or via Third Party Data Providers (“TPDP’s”) under a license to be collected and compiled by us in the provision of our identity verification services. In accordance with the License and compliance with relevant Privacy Laws and Obligations, these datasets can be prepared and licensed for our clients in a “flat file” format (e.g. CSV, TSV or Plain Text files) or accessed directly from the source via API. Access and use of the Licensed data is contingent on consent being obtained as the legal basis. In compliance with the relevant laws and obligations, we regularly update and re-compile flat file data to maintain and optimise accuracy and reliability. The relevant consents are secured and applicable data controller obligations security measures in compliance with legislative and regulatory obligations are revisited each time data is refreshed or updated. Data subjects can exercise their privacy rights outlined in this policy in relation to their personal data (including the licensed data) at any time using our webform. Where consent is withdrawn or modified by the data subject, we will promptly update our records, including licensed datasets prepared and licensed to clients.
4.2.2.1 Third-Party Data Providers.
Where we source Personal Data from TPDP’s in order to supplement our existing services, we enter into written agreements that impose information security and privacy obligations on the collection of personal data no less onerous than the data controller obligations we are required to comply with in the collection of Data Zoo Data. Compliance with these obligations is confirmed through our annual audit programs. Additionally, our agreements with TPDP’s and suppliers are independently audited to confirm our legitimate access to the personal information we receive from each of the TPDP’s.
Our TPDP’s include Credit Reporting Bodies or Agencies, who are subject to additional privacy obligations that apply to the protection of credit reporting information. We use their services to verify your identity, specifically your Name, Address, and Date of Birth. We do not receive, handle, process, or store any other credit reporting information for any other purpose. Should we receive any additional credit reporting information we will immediately delete or deidentify this information. Please contact our Privacy and Data Protection Officer to exercise your data rights set out in this Policy including details of relevant credit reporting agencies.
Services accessed via TPDP’s are tested prior to integration. Where your personal information is utilised in the testing or analysis of new services, your consent will have been collected to cover this specified purpose (either by our clients or directly by us). See our Consent Management Policy for further details (available upon request).
Enriched Data: While in the provision of our identity verification and fraud detection services, we may provide enriched personal data or information additional to the simple verification to our clients (e.g. providing flat files under license). We do not sell or share your personal information for any other purpose, nor provide any financial incentives tied to the collection or deletion of personal information. However, subject to the consent attached to the data in question, our clients may use the data or the results from the data to enrich ancillary lists such as marketing or mailing lists, newsletters etc.
We conduct supply chain due diligence on our TPDP’s and Data Sources to ensure compliance with all applicable legislation. With the exception of the Credit Reporting Bodies and Agencies, the identity of our Data Sources are protected trade secrets that are not included in our Sub-processer list. Balancing our need to protect our trade secrets while maintaining transparency and confirming to legal obligation, these TPDP’s may only be disclosed strictly upon request, where there is a clear, unambiguous legislative requirement. Where required, we will support end-users in satisfying their compliance obligations and in facilitating data subjects in exercising their legal rights (Privacy Request).
4.2.3 Batch Processing, Testing and Data analysis/evaluation
In the provision of our services to our customers, our customers may send us securely via SFTP, a batch of records. These records may be for a one -off verification or to test our various IDV services for match rates and accuracy. These records will be handled securely and with care by our data analysts and Solutions Engineers in compliance with our Information Classification and Handling Policy. The records are then manually processed and presented to our Customers. Depending on the Customers needs and instructions, subject to the specific contractual obligations in place, we may securely retain the data for further analysis and testing in conformance with their Privacy Policies and Notices and in line with our Data retention and deletion policy (see Data Handling, Retention, Disposal or Destruction of Personal Information).
5 Recruitment and Employment Activities
As part of our recruitment and employment process, we act as data controllers where we collect and maintain personal information of prospective, current, and former employees used for customary human resources purposes. This may include: Identification data and contact details – including your name, address, email address, phone number and other contact information, gender, date of birth, nationality/ies, national identifiers (such as national ID/passport, social security number(s)). Employment history – such as previous employers and job titles/positions. Background information – such as academic/professional qualifications, job qualifications, education, details included in your CV/résumé (which might include details of any memberships or interests constituting sensitive personal information), transcripts, employment references. Details of your Emergency contact(s)/ Next of Kin (including their name and contact details). Details of your nominated referees (including their name, contact details, employer, and job role). Details of your immigration/visa status. Details and result of Criminal background checks. Previous applications/roles (information relating to previous applications you have made to us and/or any previous employment history with Data Zoo). Other information you voluntarily provide throughout the recruitment process or during your employment, including but not limited to assessments, exercises, interviews, background screening and management discussions.
Sensitive Personal Information: For legitimate recruitment or employment related purposes, we may need to collect, or request on a voluntary disclosure basis, some Sensitive Personal Information that includes for example, information about your racial/ethnic origin, gender and disabilities for the purposes of equal opportunities monitoring, to comply with anti-discrimination laws and for government reporting obligations; or information about your physical or mental condition to consider accommodations for the recruitment process and/or subsequent job role.
Employee data will remain confidential and will only be accessible to individuals within the business on a “least privilege” and “need to know” basis. This includes Human Resources and Payroll access for processing. This data is retained for the minimal period in compliance with relevant employment laws and regulations.
6 Our Products and Services
6.1 API
We offer services to suit the Identity Verification and Fraud Detection needs of our wide customer base. Our Identity verification solution is accessible via API integration and provides access to an array of global services, allowing tailored customisable verification flows for those in need of a flexible solution.
6.2 Open Banking and Consumer Data Right (CDR) Data
Where Financial data, in the context of Open Banking and CDR Data services is being accessed by our Customers via our Open Banking Licence, this will be provided in accordance with the data subjects consent and in line with the relevant CDR rules as outlined in our CDR Data Policy. We will process the CDR data for the business purposes of digital Identity verification, bank account verification, and personal finance management using the legal basis of consent.
7. International Data transfers
We are an Australian Company with a global presence. As such we have our servers securely and strategically located in Australia, New Zealand, Singapore, Belgium, Canada, and the USA. Applying the principle of Data Sovereignty, insofar as is possible and where applicable, we will store and process data locally. EU and UK data will generally be processed in the EU, and US data will generally be processed in the USA. We principally source and store APAC personal information in Australia, New Zealand, Indonesia, or Singapore in compliance with the relevant and applicable data protection and privacy laws. EU and UK personal data is treated in compliance with the relevant GDPR, received and processed within the EU and in conformance with the Standard Contractual Clauses. Where EU/UK personal data needs to be rerouted, (for example, as a fail-safe), that data will remain (for processing or storage) within the EU or a country or Framework (such as the EU-US Data Privacy Framework that applies to certain certified organisations) recognised by the EC by virtue of and in compliance with an EU adequacy decision as having the equivalent or recognised legislative protection of personal data.
Where EU or UK Personal Data is transferred from the EEA (or an adequacy decision country with EC recognised legislative protection) to a non-EEA third-country that does not have a recognised adequacy decision or equivalent legislative protection, we will conduct a risk assessment to ensure that equivalent technical and organisational measures are in place to protect the personal data being transferred in addition to completing the requisite Standard Contractual Clauses for International transfers. Our Information Security Policy and standards together with the stringent level of due diligence conducted when contracting, allows us to confidently satisfy the GDPR requirements to transfer personal data to Third countries whose privacy laws may not have fully matured or have otherwise not considered to hold an EC adequacy protection decision. However, where our Customers or Suppliers have strictly forbidden or limited personal data transfers to “Third Countries”, we will restrict our services to prevent such transfers or access. For further information on how we protect your personal information around the world please contact our Privacy and Data Protection Officer.
8 Access to personal information
8.1 Process for accessing personal information
Verifiable Requests When contacting us for access/disclosure, correction, or deletion requests to personal information you may need to first verify your identity. To do this, we may ask you for additional information, which may include asking you to confirm other Personal Information you have provided to us. We reserve the right to deny any requests for which identity cannot be reasonably verified. If you have authorised another person to make a request on your behalf, that person must also provide verification of their identity, in addition to your written authorisation accompanying a copy of your power of attorney allowing that person to make such a request on your behalf. We reserve the right to deny any request by an authorised agent if we are not reasonably able to confirm proper authorisation or verification of that agent. |
|---|
If you would like to request access to your personal information which we hold about you (or a person whom you are authorised to represent), to exercise your rights to access, correct/amend, delete, to object to the processing of, or to withdraw your consent to the use of or disclosure/sharing of your personal information outlined in this Privacy Policy, please submit a verifiable request to the Privacy and Data Protection Officer or complete a Data Access Request to initiate the request. We do not sell your personal information, nor provide any financial incentives tied to the collection or deletion of your personal information.
Your request should specify the format in which you wish to be provided the personal information (for example, in person, by email, or printed copy) and details of the context in which your personal information has been provided to us. This application is free of charge. However, we may make a reasonable charge for providing access to you. If we wish to charge you to access the personal information, we will notify you of this charge prior to giving you access to the personal information.
When a decision is made, access will be provided either free of charge or subject to a charge as follows:
No charge for access – we will notify you of the decision and (where you have requested that the information be provided to you by email or printed copy delivered or sent to you), we will also provide the personal information to you at the same time (except as set out below)
Access charge – we will notify you of its decision and the proposed charge for giving you access and the payment terms and method of payment. If you wish to discuss the proposed charge with us, you should contact our representative nominated in the notice. Once you have paid the access charge, we will provide the personal information to you (except as set out below).
Where the format of access is different from the format requested – If we conclude, acting reasonably, that it is not possible or practicable for us to provide your personal information in the format you have requested (for example because of the volume or nature of the personal information or your needs), we will contact you to agree a format in which we can give you access to the personal information. If you have requested access by in person or by telephone, we will contact you to arrange the time and place at which you may access the personal information.
8.2 Refusal of a request for access to personal information
Please Note: For your protection, to ensure that your personal data is not released to a third party without your authority, we will only address verifiable, legitimate, and complete personal data requests. Where we are unable to verify your identity or the authenticity of the request, we will not process that request. |
In limited circumstances, where an exemption applies, access to some or all of your personal information may be refused depending on the circumstances. This includes circumstances covered by the relevant privacy legislation and principles or where the request is manifestly unfounded or excessive. Where permitted we will promptly notify you of the reasons and consult with you to identify any alternative means of providing you access to your personal information (e.g. reducing the scope of request, or giving you access through an agreed intermediary). In those circumstances, you will not be charged for making a request to access your personal information, but you may be charged for the reasonable time and expense incurred in compiling information in response to your request.
8.3 Quality, accuracy, and right to correction or deletion of personal information
We make reasonable effort to ensure that the personal information that we collect is accurate, up-to-date, complete, and relevant, both at the time of initial collection, and throughout the period that we store or handle it. In the provision of our services, we use reputable and reliable sources (including Government Sources and TPDP’s) to optimise the quality and accuracy of the personal information we verify. We implement a data quality and accuracy program utilising these services to manage our data, which can be updated as frequently as daily in some cases (usually monthly). Our sources are thoroughly vetted and monitored via our Vendor Risk Management program as well as third party audits.
If you consider that any personal information that we or our TPDP’s hold about you is inaccurate, out-of-date, incomplete, irrelevant, or misleading and you wish to have the information corrected or deleted, please submit a verifiable request to the Privacy and Data Protection Officer. This application is free of charge. Please note, we do not provide any financial incentives tied to the collection or deletion of your personal information.
If we accept your request: we will take such steps as are reasonable in the circumstances to ensure that we correct or delete the information, having regard to the reasons for which the information is held.
If we decline your request: we will send you a written notice explaining the reasons for the refusal (except where it is unreasonable to provide an explanation), the complaint mechanism which you may follow, and other matters which we are required to include. Additionally, you may request that we add or associate a statement to the personal information stating that it is inaccurate, out-of-date, incomplete, irrelevant, or misleading. We will take reasonable steps (given the circumstances) to associate the statement in such a way to make it apparent to users of the information.
8.4 Timeframes and record keeping of your requests
We acknowledge and confirm receipt of all requests by you to exercise your right to know/access, correct/rectify or erase/delete your personal information within ten (10) business days of receiving the request and will provide information as to how we will process the requests. We aim to then provide a full response to these requests within 45 calendar days of the date your request was received. If we cannot respond within this period, we will promptly notify you of the delay, the reasons for the delay, and the date by which we will provide a response (no later than 90 calendar days from the date your request was received). We will keep all records pertaining to the requests for a period of at least 24 months. [4]
[4] CCPA 999.317 timeframes and record keeping and CPRA 1798.130
Retention of records exception |
|---|
Within your rights, you may access all your personal information held by us to request correction/amendment or deletion except where we or an organisation to which we have provided your personal information as part of our verification services is required to retain that information as part of their legislative or compliance obligations. This includes for the legitimate purpose of records retention for compliance with Anti-Money Laundering, Anti-Corruption legislation or other laws or regulations. |
9 Specific rights under the EEA/UK GDPR
Our obligations to you in the provision of our services are largely as a Personal Data Processor. However, as specified throughout this policy, we are also subject to data controller obligations, including the personal data we control in relation to Data Zoo Data and data collected in the course of Recruiting and Hiring Activities. Under the GDPR, you have the following rights in relation to how your personal data is controlled and processed:
a) Right to request access – by contacting us and submitting a Data Access Request via our website or our Privacy and Data Protection Officer (or for the UK, our UK data representative (GDPRRep)) with a verifiable request you may obtain confirmation from us as to whether or not your personal data is being processed or controlled by us, and where that is the case, request access to personal information we hold about you following our process for accessing personal information (see above).
b) Right to rectification – you have the right to obtain rectification of inaccurate personal data we hold concerning you.
c) Right to erasure – you have the right to obtain the erasure of personal information we hold about you without undue delay in certain circumstances.
d) Right to restriction of processing or to object to processing – you may require us to restrict the processing we carry out on personal information we hold about you in certain circumstances or to object to us or the processer processing your personal data.
e) Right to data portability – you have the right to receive a copy of personal information we hold about you in a structured, commonly used, and machine-readable format.
f) Right to withdraw consent – where you have provided your consent to us to process personal information we hold about you in a certain way, you have the right to withdraw your consent at any time. To learn more see our Consent Management Policy (available upon request) or contact our Privacy and Data Protection Officer.
g) Right to lodge a complaint – you may lodge a complaint through our Dispute Resolution channels, by contacting our Privacy and Data Protection Officer; the Information Commissioner's Office (ICO) in the UK, and the relevant data protection or supervisory authority in the EU. A list of the EU data protection authorities can be found at Data Protection Authorities - European Commission (europa.eu).
We will not charge you a fee if you wish to exercise any of your rights, except where we are permitted to do so by the EEA/UK GDPR. To exercise the above rights or to learn more about your rights under the EEA/UK GDPR, please complete our Data Access Request webform on our website or contact our Privacy and Data Protection Officer.
10 Specific rights under Californian Privacy Law (CCPA/CPRA) [5]
Where you are a Californian Resident, you may also have certain specific privacy rights against us afforded to you by Californian Privacy legislation, which includes:
a) Right to Know/ Access [6]: which entails your right to disclosure of what / how we collect, use, disclose, sell [7] or share your Personal Data (to the extent permitted by applicable law).
b) Right to Opt-out of the Sale [8] or Sharing of your Personal Information to Third Parties[9], where the business sells or shares personal data with contractors, service providers and other third parties. This will specifically relate to your Right to Opt-out of behavioural advertising.[10]
c) Right to Know and Opt-out of Automated Decision-Making Technology (ADMT) [11]: Specifically, this right includes the Right to Know/Access knowledge about automated decision making, how the automated decision technologies work and what their probable outcomes are in relation to your Personal Information, allowing you to exercise your Right to Opt-out of Automated Inferences (e.g. in profiling for targeted, behavioural advertisement online).
d) Right to Limit Use and Disclosure of Sensitive Personal Information [12]: allowing you to restrict our use and disclosure of any sensitive personal information[13] we may hold about you. This includes consumer’s account log-in details; financial account, debit card, or credit card number in combination with a security or access code, password, or credentials; social security number, driver’s license, state ID card, or passport number; precise geo-location; racial or ethnic origin, religious or philosophical beliefs, or union membership; the contents of a consumer’s email and text messages unless the business is the intended recipient of the communications; genetic data and biometric data; health, sex life or sexual orientation. The restriction applies to certain secondary purposes to third-parties for cross-context behavioural advertising [14].
e) Right to Correction/ Rectification [15]: If you find that we hold inaccurate personal data about you, you have the right to have it corrected/ rectified.
f) Right to Request Deletion [16] of your personal information collected or maintained by us, which extends to notifying any service providers, contractors third parties to delete as well.
g) Right to not receive discriminatory treatment [17] by the business for the exercise of your privacy rights conferred by the Californian Privacy legislation.
h) Right to designate an authorised agent to make a verifiable request under the CCPA on your behalf to us with a copy of your power-of-attorney document granting that right.
To exercise the above rights, please complete our Data Access Request webform or contact our Privacy and Data Protection Officer. To learn more about your rights under the CCPA and CPRA contact us, the Office of the Attorney General (OAG), or the California Privacy Protection Agency (CPPA).
[5] California Consumer Privacy Act 2018 (CCPA) and California Privacy Rights Act 2020 (CPRA)
[6] CPRA 1798.110: Consumers’ Right to Know What Personal Information is Being Collected. Right to Access Personal Information
[7] Note: We do not sell the personal information of Californian citizens/data subjects- nb. 1798.115. Consumers’ Right to Know What Personal Information is Sold or Shared and to Whom
[8] CPRA 1798.120
[9] CPRA Position does not apply to non-personalised advertising that is defined as a business purpose.
[10] CPRA 1798.130/ 2026 CPPA regulations; Note: Our IDV solution and services are distinguishable from ADMT, as they only return verification results for our Customers to interpret and decide upon.
[11] CPRA 1798.121: Consumers’ Right to Limit Use and Disclosure of Sensitive Personal Information
[12] CPRA 1798.140 Definitions: (L) Sensitive Personal Information
[13] Cross-context behavioural advertising means the targeting of advertising to a consumer based on the consumer’s personal Information obtained from the consumer’s activity across businesses, distinctly branded websites, applications, or services, other than the business, distinctly-branded website, application, or service with which the consumer intentionally Interacts. California Privacy Rights Act, §13(k).
[14] CPRA 1798.106.
[15] CPRA 1798.105
[16] CPRA 1798.125: Consumers’ Right of No Retaliation Following Opt Out or Exercise of Other Rights
11 Additional Notes
11.1 Unsolicited Personal Information
We sometimes receive unsolicited personal information. This occurs where personal information is received by us where we have not taken any active steps to collect that information. In such cases, we will, review the unsolicited personal information within a reasonable amount of time to determine if it is reasonably necessary for our legitimate business purpose, including our contractual obligations with you and our obligations under law. If it is, we will handle the information in the same way as we handle the information we would actively collect from a person. If we do not need the information, we will destroy the information or de-identify it in line with our ongoing application of the principle of data minimisation (see Data Handling, Retention, Disposal or Destruction of Personal Information for further detail).
11.2 Data Handling, Retention, Disposal or Destruction of Personal Information
We strongly adhere to the principle of data minimization in the collection, use, storage, and disposal/destruction of data. Personal data must be adequate, relevant, and limited to what is necessary to the purposes for which it is processed. We delete all personal information on conclusion of the Visitors or Customer’s arrangements with us, except where we are legally required to keep the personal information for a longer period. We then delete that information as soon as that period has expired/lapsed. In the provision of our services, we retain data only for the duration of processing the transaction/ verification. As a Processor, this period is set within our active systems, for the duration of the verification, and the brief period after (determined by the Customer) to enable the Customer to retrieve the verification report (after which, the verification is destroyed/ permanently de-identified, as applicable). While residual data exists within restricted system-level recovery environments, this is not in our active systems, it is limited to 48 hours, and may only be accessed or restored in the event of a system incident or recovery scenario. Beyond this, we do not store any client PII unless advised otherwise. Our Customers can request to deactivate the retention period at any time. As a data controller, we will retain the personal data within the period permitted by legislation, consent, and/or to perform contractual obligations, in the course of delivering our identity verification and fraud detection services.
11.3 Special Category or Sensitive Personal data
Where we collect and process Special Category[18] or Sensitive Personal Data[19] it will follow a legitimate basis for the purposes permitted by the relevant legislation and in compliance with the requisite technical and organisational measures summarised in our Information Security Policy. Such categories of personal data include financial or biometric data, government issued identifiers processed in the provision of our services, and the sensitive data processed in the course of our Recruitment and Employment Activities. Within each context, the data is processed in accordance with the relevant legislation either with the data subjects’ consent or one of the other permitted exceptions[20], via reputable and reliable TPDP’s and/or Government Sources, for the business and commercial purpose of providing identity verification and fraud prevention services or otherwise for the permissible purpose of recruitment and employment.
[17] Article 9 GDPR
[18] CPRA 1798.140 Definitions: (L) Sensitive Personal Information
[19] Permitted exceptions at Article 9 (2) and (3) of the GDPR
11.4 Disclosure of Personal information
We will not disclose information that identifies an individual, or enables an individual to be identified except as:
specified in this Privacy Policy;
authorised by the individual;
as required under applicable laws; or
as directed by courts, tribunals or other bodies having authority over us.
We will only disclose government issued document identifiers (such as National ID, Passport, or Driver Licence numbers) or identifiers issued by another entity or person, as part of an identification verification request on behalf of an individual who has provided their consent (Consent Management Policy available upon request).
11.5 Data Recipients
In the provision of our identity verification and fraud detection services, both as data controller or data processer, we will only provide your data to the relevant Customer Organisation, TPDP, or Third-Party Service Provider (including subprocessers). Often the verification request containing your personal data will originate from our Customers (or End User of our Services). The verification request will be processed against the TPDP or other data source(s) that the Customer has selected, before being returned with the result to be received by that Customer (and/or any permitted third-party as instructed by the Customer) upon completion of the verification process. The original data together with the verification result is deleted/ deidentified upon completion of the transaction in line with the retention rules set by the Customer. Where we transfer personal data, the categories of data recipients include the data subject (upon request); and Customer Organisations, including financial institutions. Where we supply and maintain Data Zoo Data) for our Customers, we act as Data Controllers and will ensure we discharge the relevant Data Controller obligations.
11.6 Data Controller Obligations
Where we handle your personal data as a Data Controller, we ensure all authorities and consents are obtained, and the data is protected (including technical and organisational security measures) in accordance with applicable laws and our Information Security Policy. These obligations apply whilst your data is in our control and extended to processing, internally (including analytical purposes in the provision of our services), or externally by our Customers or third parties. For certain Customers, which include financial institutions, we may acquire or compile datasets from TPDPs for the strict purpose of Identity Verification and Fraud Detection (Data Zoo Data) and supply these datasets under license. We ensure the personal data is acquired lawfully and in compliance with the relevant Privacy Laws and in line with our data controller obligations.
11.7 Children
Our websites and activities are not directed at children. We do not knowingly collect, use, share, or sell Personal Information from children under the age of 18, in the course of our business practices. We recognise and respect personal data of children as sensitive. Any consent change requests or concerns that personal data belonging to anyone under the age of 18 may have been collected should be directed to the Privacy and Data Protection Officer. In the event that we learn that we have gathered such personal information from anyone under the age of 18 without the consent of a parent or guardian, we will delete that information as soon as possible.
11.8 Privacy Complaints
Our Dispute Resolution Policy details our general Complaints process. Within the context of a Privacy Complaint or dispute, and depending on the relevant jurisdiction, you may lodge a complaint directly with the Data Zoo Privacy and Data Protection Officer; and/or the local privacy regulator relevant to you. This may include Australian privacy complaints being directed to the Australian Privacy regulator- Office of the Australian Information Commissioner (OAIC), New Zealand Complaints to the Office of the Privacy Commissioner; UK Complaints to the Information Commissioner's Office (ICO), and the relevant data protection or supervisory authority in the EU. A list of the EU data protection authorities can be found at Data Protection Authorities - European Commission (europa.eu).
12 Changes to this Privacy Policy
In general, changes will be made to this Privacy Policy to address new or modified applicable laws and/or new or modified business procedures and/or technologies. However, we may update this Privacy Policy at any time, with or without advance notice, so please review it periodically. We may provide additional forms of notice of modifications and/or updates as appropriate under the circumstances. Your continued use of the Website and solutions after any modification to this Privacy Policy will constitute your acceptance of such modifications and/or updates. You can determine when this Privacy Policy was last revised by referring to the date it was last “Updated” above. If we consider it necessary, we may consult with the Office of the Australian Information Commissioner (OAIC), the New Zealand Privacy Commissioner, the Singaporean Personal Data Protection Commission, the California Privacy Protection Agency (CPPA), the Information Commissioner's Office (ICO) or other appropriate government representatives and/ or representative groups or stakeholders before implementing any change or review to this Privacy Policy.
When this Privacy Policy is updated, the updated policy will be published on our website at: www.datazoo.com. The most current version of our Privacy Policy will always be the version published on our website and any previously downloaded or printed versions should not be relied upon. We will identify each version, include a publication date, and ensure that superseded versions continue to be available upon request to our Privacy and Data Protection Officer.
13 Breach of Policy
We will take all necessary measures to remedy any breach of this policy including the use of our disciplinary or contractual processes where appropriate.