Product: VettiGuard Product owner and provider: Ikemba Tech (ABN 82 565 415 510) Effective date: 25 September 2026 Version: 1.3
1. Purpose and scope
This Policy explains how VettiGuard collects, uses, holds, processes, discloses, protects, corrects and deletes personal information. It applies to the public website, account and workspace services, APIs, SDKs, verification widgets, hosted verification experiences, facial liveness, biometric enrolment and matching, documentary identity verification, device and application trust, risk and trust decisions, support channels and related VettiGuard services.
VettiGuard commits to handling personal information consistently with the Australian Privacy Principles (APPs) as a baseline privacy standard and complies with the Privacy Act 1988 (Cth) where that Act applies. Additional Commonwealth, State, Territory, industry or customer-specific requirements may apply to particular deployments.
2. Roles and customer responsibility
VettiGuard may collect information directly from account holders and website visitors. It may also process information on behalf of a customer that has integrated VettiGuard into its own application or business process.
Where a customer determines why a person must complete a verification, that customer is responsible for having a lawful and appropriate basis for the verification, providing any notices required for its own purpose, obtaining required consent or authority, and deciding what business consequence follows from the VettiGuard result.
VettiGuard is responsible for the personal information it handles for its own business purposes and for operating its services consistently with this Policy and applicable law.
3. Categories of information
Depending on the feature used, VettiGuard may process:
- account and contact information such as name, email address, telephone number, organisation, role and workspace membership;
- authentication and account-security information such as MFA status, passkey information, session records and recovery events;
- application and integration information such as domains, mobile application identifiers, API credential metadata, policies, webhooks and configuration;
- technical and security information such as IP address, browser and device information, operating system, network information, request timing, failed attempts, rate-limit events, integrity signals and audit logs;
- customer-supplied opaque subject, account, device, transaction or resource references;
- verification results, assurance levels, challenge outcomes, trust decisions and review outcomes;
- support and inquiry information; and
- where identity verification is enabled, identity-document and biometric information described below.
4. Identity-document information
For an authorised documentary identity journey, VettiGuard may process a document image and information derived from it, such as name, date of birth, document type, document number, issuing country or authority, expiry information, machine-readable-zone data, supported barcode data, document portrait, capture-quality information, field-consistency information and bounded tamper or recapture signals.
Customers should request documentary evidence only where it is reasonably necessary and proportionate to the protected purpose.
5. Facial and biometric information
Some VettiGuard services process facial images, facial characteristics, biometric templates, liveness evidence, enrolment references, matching results and verification confidence information.
Biometric information used for automated biometric verification or identification, and biometric templates, are sensitive information under the Privacy Act when the Act applies. VettiGuard therefore treats biometric information as high-sensitivity information and applies enhanced restrictions to access, purpose, retention and disclosure.
VettiGuard does not use biometric information for behavioural advertising. It does not sell biometric information or identity-document information. VettiGuard does not intentionally use facial verification to infer ethnicity, religion, health status, emotions or unrelated demographic characteristics.
6. Consent and collection notices
Where consent is required for biometric or other sensitive-information processing, the relevant journey should obtain consent that is informed, voluntary, current and sufficiently specific before collection begins. Consent should not be bundled into unrelated terms.
A hosted VettiGuard identity or biometric journey may record privacy-safe evidence of consent such as a consent status, timestamp, notice version and session or consent reference.
Where reasonably practicable and appropriate to the risk, customers should provide an assisted or alternative verification path for a person who cannot use the configured biometric method.
7. Liveness and facial matching
Liveness verification is used to assess whether a real person appears to be present during a verification session. Liveness may use movement prompts, capture continuity, image quality, replay indicators and presentation-attack signals. Liveness alone does not establish identity.
Facial matching may compare a live capture with an authorised enrolled identity or an authorised document portrait. Browser-supplied fields or scores are not treated as authoritative verification results. Sensitive verification decisions are generated or confirmed through trusted backend systems and governed policy.
8. Native document screening boundary
VettiGuard may perform capture-quality checks, OCR, ICAO-compatible machine-readable-zone checks where supported, supported barcode checks, field consistency, document geometry, expiry checks and bounded tamper indicators.
Unless VettiGuard expressly states otherwise for a particular transaction, native document screening is not a government or issuing-authority confirmation. VettiGuard does not represent native screening as the Australian Government Document Verification Service (DVS) or Face Verification Service (FVS). If an authorised government or issuer service is separately integrated, its separate eligibility, contractual, privacy and consent requirements apply.
9. Government-related identifiers
Identity documents may contain government-related identifiers. VettiGuard does not adopt a government-related identifier as its general account identifier except where permitted by law. Such identifiers are processed only where reasonably required for an authorised verification function or otherwise permitted.
10. Purposes of processing
VettiGuard may process information to operate and secure accounts; provide human verification; perform liveness and authorised facial matching; screen identity documents; provide device, application and session trust; protect APIs and high-risk actions; prevent replay, abuse and fraud; administer workspaces; operate review queues; maintain auditability; provide support; send service communications; monitor reliability; investigate incidents; administer contractual arrangements; comply with law; and establish, exercise or defend legal rights.
VettiGuard applies data-minimisation principles and customers should provide only information necessary for the configured purpose.
11. Automated decision-making and human review
VettiGuard uses automated systems to analyse verification, device, application, security, transaction and behavioural signals. Outcomes may include allow, verify, recapture, step-up, rate-limit, review, reject or block.
Inputs may include identity and biometric information, liveness results, document information, device and application integrity, verification history, failed attempts, request velocity, customer-supplied risk context and transaction context.
VettiGuard's result addresses the configured trust or verification question. It is not a general assessment of a person's character, honesty, health, competence or eligibility. Customers remain responsible for the underlying business decision and should apply human review where the decision may significantly affect a person's rights or interests.
This disclosure is included ahead of the additional APP 1 privacy-policy requirements for certain substantially automated decisions commencing on 10 December 2026.
12. Hosting, communications and overseas processing
VettiGuard uses service providers to operate its production environment. Personal information may be stored or processed in the United States. Current material providers are identified in the Data Hosting & Subprocessor Notice.
VettiGuard uses a communications provider for transactional and service messages. Processing may include recipient details, message content or template variables, delivery identifiers, bounce or delivery information and related metadata. Raw biometric templates and unrestricted identity-document images are not placed in ordinary email messages.
Communications may use infrastructure in Australia and the United States. Recipient email systems and networks may involve additional countries. Current material providers and processing locations are identified in the Data Hosting & Subprocessor Notice.
Where APP 8 applies to an overseas disclosure, VettiGuard will take reasonable steps appropriate to the circumstances to address the handling of personal information by overseas recipients, subject to applicable exceptions.
13. Service providers and subprocessors
VettiGuard may use providers for hosting, communications, monitoring, support, security and customer-selected verification services. VettiGuard is currently provided without charge, so no payment processor is currently used to collect VettiGuard service fees. If VettiGuard introduces paid services in the future, any material payment provider and related processing location will be added to the Data Hosting & Subprocessor Notice before or when that processing begins. Material providers and location information are maintained in that Notice.
Providers receive only information reasonably required to perform their function and are subject to appropriate confidentiality, security or contractual controls where practicable.
14. Cookies and browser storage
VettiGuard may use cookies, local storage or similar technologies for authentication, session continuity, security, user preferences, abuse prevention and service operation. Any non-essential analytics or similar technologies introduced later will be documented in the Cookies & Similar Technologies Policy and handled in accordance with applicable requirements.
15. Retention and deletion
Information is retained only for as long as reasonably required for the purpose for which it was collected, security and fraud prevention, configured customer requirements, contractual obligations, dispute management or applicable law.
Transient portrait material used only for a document-to-face comparison should be removed after comparison or finality when no longer required. Biometric enrolment information may remain while an authorised enrolment is active and may be revoked or replaced. Verification outcomes, consent evidence and audit events may be retained longer where necessary for governance and security.
Where personal information is no longer required, VettiGuard will take reasonable steps to destroy it or de-identify it, subject to lawful retention and authorised legal holds.
16. Security
VettiGuard uses layered technical and organisational safeguards appropriate to the sensitivity of the information processed. These may include encryption, access controls, role-based permissions, workspace isolation, secret management, short-lived capabilities, server-side verification, replay prevention, rate limiting, logging, monitoring, backup controls, security reviews and incident-response procedures.
No internet-connected service can guarantee absolute security. Customers remain responsible for the security of their own applications, accounts, devices, credentials and integrations.
17. Data breaches
VettiGuard maintains processes to identify, contain, assess and respond to suspected data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, VettiGuard will take the steps required by law, including relevant notifications to affected individuals and the Office of the Australian Information Commissioner (OAIC).
18. Access, correction and privacy requests
A person may request access to personal information VettiGuard holds about them or correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading, subject to applicable exceptions.
Where VettiGuard processes the information only on behalf of a customer, VettiGuard may refer the request to that customer or work with the customer to respond. Identity verification may be required before sensitive information is released.
Eligible deletion or biometric-revocation requests can also be made. Some information may need to be retained for security, legal, backup or dispute reasons.
19. Marketing and service communications
VettiGuard may send operational communications relating to verification, account administration, security, support and material service changes. Marketing communications are treated separately. Where VettiGuard sends commercial electronic messages, it will seek to comply with the Spam Act 2003 (Cth), including applicable consent, sender-identification and unsubscribe requirements.
20. Children and young people
VettiGuard is primarily a business and developer platform. Where a customer proposes to use identity or biometric verification involving a child or young person, that customer must assess lawfulness, necessity and proportionality and obtain any required parental, guardian or other authority. VettiGuard may impose additional restrictions for high-risk or inappropriate uses.
21. High-impact and regulated uses
Customers using VettiGuard in healthcare, NDIS, employment, finance, education, government or other regulated settings remain responsible for sector-specific obligations and appropriate human oversight. VettiGuard must not be used as an undisclosed surveillance tool or as the sole basis for a prohibited discriminatory decision.
22. Complaints
Privacy complaints can be sent to support@vettiguard.com. Provide enough information for investigation, but do not include unnecessary identity documents, biometric images, passwords, API secrets or authentication codes in the initial complaint.
Where the Privacy Act applies, unresolved complaints may be taken to the OAIC after the person has first given VettiGuard a reasonable opportunity to respond.
23. Changes to this Policy
VettiGuard may update this Policy when services, infrastructure, subprocessors or legal requirements change. Material changes will be identified by a new version or effective date and, where appropriate, an account or website notice. A policy update alone does not authorise a materially different use of sensitive information where additional consent or authority is required.
24. Contact
Privacy Officer, Ikemba Tech (VettiGuard) Victoria, Australia Privacy and support: support@vettiguard.com General enquiries: info@vettiguard.com