Custarra is in closed beta testing and currently closed to new sign-ups — email info@custarra.com.au for more information.

Privacy Policy

Current as of 27 July 2026.

1. Who we are

Custarra is an Australian regulatory-compliance platform built for real estate agencies, accounting firms, and other property and professional-services businesses to meet their Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF) obligations. Custarra is operated by Custarra Pty Ltd (ABN 66 698 484 614) (“Custarra”, “we”, “us”, “our”).

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), where they apply to us. We also aim to handle personal information consistently with the APPs as a matter of good privacy practice. This policy explains how we collect, hold, use and disclose personal information. You can contact us about privacy at privacy@custarra.com.au.

2. Our two roles — information we handle for ourselves and information we handle for business customers

Custarra handles personal information in two very different capacities. Keeping them separate is important, because your rights and who you contact depend on which one applies.

(a) Information we handle for our own purposes. For some information, we decide how it is collected, used and disclosed. This includes information about people who use or interact with Custarra itself, such as staff at a business who hold a Custarra login, billing contacts, people who contact our support team, and visitors to our website. This policy governs that information.

(b) Information we handle for a business customer. When a business — such as a real estate agency, accounting firm, law firm or other property or professional-services business — uses Custarra to run its AML/CTF program, the business may load records about its own customers, including identity details, due-diligence records, screening results and related compliance information. Some of this information is entered by the business’s staff; some may be provided directly by the customer through a self-service onboarding link that we host on the business’s behalf. In this situation, the business decides what information is collected and how it is used for its AML/CTF compliance. We hold and process that information on the business’s instructions, as the system provider. We do not use that information for our own purposes unless this is permitted by our agreement with the business customer, this policy, or law.

If you are a customer of one of these businesses and you want to access, correct, or complain about information the business holds about you, you should usually contact that business first. The business is generally responsible for responding to those requests. If you contact us, we may redirect your request to the relevant business or assist the business to respond, where appropriate. The business’s own privacy policy should explain how it handles your information.

3. What personal information we collect

The personal information we handle for our own purposes falls into these categories:

  • Account holders (staff at the business). Name, work email address, position title, the AML/CTF role(s) assigned to the person, and account-security information (such as whether multi-factor authentication is enabled). Login credentials and multi-factor authentication factors are held by our authentication provider (see Section 8), not by us directly.
  • Billing contacts. Business name, ABN, billing contact details, subscription and plan information, and payment records. Card details, where payments are taken, are handled by our payment provider — we do not store full card numbers.
  • Support correspondence. Anything you tell us when you contact support — your message, contact details, and related account context.
  • Marketing-site visitors. Information you submit through contact or demo-request forms, and limited technical information collected automatically when you browse our site (see Sections 4 and 14).

We separately handle, on a business customer’s behalf, personal information that the business collects about its own customers in order to meet its AML/CTF obligations. This information may be entered by the business’s staff or provided directly by the customer through a self-service onboarding link. The business is generally responsible for deciding what information is collected and how it is used. We hold and process it on the business’s instructions, and access, correction and complaint requests about that information should usually be directed to the business. The categories the platform may hold in this capacity include:

CategoryExamples
Contact & identity detailsFull name, other or former names, date of birth, residential address, country of residence, occupation
Identity documentsDocument type, document details and, where uploaded or required, copies of identity documents or other verification documents
Biometric informationBiometric information used for identity verification, such as facial images, facial matching information or liveness check information, where these checks are enabled
Screening resultsSanctions, politically exposed person, adverse media, fraud and other screening results, alerts or matches
Payment & source-of-funds detailsDeclared payment methods, amounts, and related details
Beneficial ownership & representativesFor non-individual customers: names, roles, ownership percentages, and identity details of beneficial owners and people acting for the customer
Transaction & service detailsDesignated-service and transaction records, including property and service details
Supporting documentsSupporting documents uploaded by the business customer or its customers, such as authority documents, registry extracts, trust documents or other due diligence materials

We handle this information as the business customer instructs, and for the purposes of providing, securing, supporting and improving the Custarra service, supporting AML/CTF compliance workflows, maintaining audit records, calibrating screening rulesets, diagnosing issues raised by customers, and complying with law. We do not sell this information. Where we use information to improve the service, we aim to use aggregated or de-identified information where practicable.

We collect only what is reasonably necessary for the purposes set out in this policy (APP 3).

4. How we collect personal information

  • Directly from you — when you create or are added to an account, set up billing, contact support, or submit a form on our website.
  • From the business you work for — when it adds you as a staff member, it provides your name, email, and role so we can create your account.
  • Automatically — when you use the service or browse our website, we collect limited technical information such as log data and, on the marketing site, basic analytics (see Section 14).

5. Why we collect and use it

We use the personal information we control to:

  • provide, operate, and maintain the Custarra service;
  • authenticate users and keep accounts secure (including offering multi-factor authentication);
  • manage billing and subscriptions;
  • respond to support requests and communicate with you about the service;
  • improve, maintain and develop the Custarra service, including through account information, support information, usage information and aggregated or de-identified information where appropriate;
  • send transactional and service emails (account, security, and notification emails); and
  • meet our own legal and regulatory obligations.

We do not sell personal information. We may send service-related emails, product updates and other communications about Custarra. Where required, we will only send marketing communications with consent or where otherwise permitted by law, and each marketing communication will include an unsubscribe option.

6. Sensitive information and identity verification

We do not usually collect sensitive information, such as biometric or health information, about account holders or website visitors.

Identity documents and biometric information used to verify a business customer’s own customers are compliance information handled on the business customer’s behalf. A business customer may record identity-document details, upload and store copies of identity documents, or use an electronic identity-verification provider through the Custarra platform.

Identity verification may involve third-party identity verification, document verification, biometric verification, fraud screening, sanctions screening, politically exposed person screening and adverse media screening providers. These providers may check information against government, public, private, commercial or international data sources. Where a hosted verification flow is used, identity documents, facial images and liveness check information may be provided directly to the relevant verification provider and may not pass through Custarra’s systems. Custarra may receive and store verification outcomes, screening results, response records and related audit information.

7. Where your information is stored, and how we protect it

We primarily store account data and compliance data using cloud infrastructure and service providers selected by us. We aim to use Australian hosting for core account and compliance records where practicable. Some operational information, such as logs, support information, billing information, email delivery information and analytics information, may be handled by other providers, including as described in Sections 8 and 9.

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. These steps may include technical, organisational and contractual measures, such as access controls, encryption, authentication controls, audit logging, staff access restrictions, vendor due diligence and security monitoring.

8. Third-party providers (sub-processors)

We use third-party providers to help us operate, secure, support and improve the Custarra service. These providers may handle personal information only as needed to provide services to us or to our business customers.

The types of providers we use may include:

Type of providerWhat they doPersonal information involved
Cloud hosting, database, authentication and file storage providersHost the platform, store records, manage authentication and support platform securityAccount information, compliance records, login information, files and audit information
Website and application hosting providersHost our website, application front end and related infrastructureTechnical information such as IP addresses, device information, browser information and request logs
Email and communication providersSend account, security, notification, support and marketing emailsNames, email addresses and message content
Payment providersProcess subscriptions, invoices and paymentsBilling contact details, payment records and payment information
Identity verification, screening and data source providersVerify identity information, check documents, conduct biometric checks where used, and screen against sanctions, politically exposed person, fraud and adverse media sourcesIdentity information, document information, biometric information where used, screening information and verification results
Business registry, government data and compliance data providersValidate business names, ABNs, registry information or other compliance informationBusiness identifiers and related information
Analytics, diagnostics and error-monitoring providersHelp us understand usage, diagnose technical faults and improve service reliabilityTechnical information, usage information, error logs and account identifiers where relevant
Professional advisers and compliance providersProvide legal, accounting, insurance, audit, compliance, security or other professional servicesInformation relevant to the advice or services provided

Some providers may use information in accordance with their own terms, privacy policies or data processing terms, including to operate, secure, maintain, analyse and improve their services, where permitted by law and applicable agreements.

We may add, replace or remove providers from time to time. We will update this policy where a change is material to how we handle personal information.

9. Overseas disclosure

Personal information may be handled by providers or data sources located outside Australia, such as the United States, the United Kingdom and countries in the European Union, and other countries depending on the provider, data source or check requested. This may include providers that support hosting, email delivery, payment processing, identity verification, document verification, biometric verification, fraud screening, sanctions screening, politically exposed person screening, adverse media screening, analytics, diagnostics and customer support.

The countries involved may vary depending on the provider used, the customer’s location, the documents submitted, the checks requested and the relevant data sources. For example, identity verification and screening may involve overseas data sources where an overseas document, international watch-list, international sanctions list or overseas registry is checked.

Where personal information is disclosed overseas, we take reasonable steps to ensure that overseas recipients handle the information consistently with the APPs, where required by Australian privacy law. These steps may include contractual protections, data-processing terms, security requirements, due diligence or reliance on providers that operate under comparable privacy obligations.

Because business customers are generally responsible for collecting information from their own customers, business customers should ensure that their own privacy notices and collection notices explain any relevant overseas disclosures. Our onboarding collection notice may also provide information about overseas disclosure at the point of collection.

10. How long we keep your information

We keep account, billing, and support information for as long as your account is active, and for a reasonable period afterwards to meet our legal, tax, and operational obligations.

For compliance records we handle on a business customer’s behalf, the relevant business customer may be required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) to keep certain records for seven years, or another period required by law. We retain those records for the period instructed by the business customer, required by law, or reasonably needed for legal, security, audit, backup, operational or service delivery purposes. After the relevant retention period ends, we will take reasonable steps to destroy or de-identify the information, unless we are required or permitted to retain it by law.

11. Your rights — access and correction

You can ask us for a copy of the personal information we control about you, and ask us to correct it if it is wrong or out of date (APPs 12 and 13). Contact us at privacy@custarra.com.au. We may need to verify your identity first, and we will respond within a reasonable time. In the limited cases where we cannot provide access, we will explain why.

For information we hold on behalf of a business customer about that business customer’s own customers, the relevant business customer is generally responsible for responding to access and correction requests. If you contact us about that information, we may redirect your request to the relevant business customer or assist the business customer to respond, where appropriate.

12. Data breaches

We comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), where it applies to us. If a data breach involving personal information we handle is likely to result in serious harm, we will assess the incident and notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where required.

Where a data breach involves records we handle on behalf of a business customer, we will take reasonable steps to notify and assist the relevant business customer so that the business customer can assess and respond to the incident, including by making any required notifications.

13. Automated decision-making

Custarra provides features that help business customers with AML/CTF compliance workflows, such as risk indicators, risk ratings, screening results, alerts, flags and workflow recommendations. These features are designed to support human review and decision-making by the business customer.

Custarra does not make final decisions about whether a business customer accepts, rejects, onboards, offboards, reports, escalates or otherwise deals with its own customers. Business customers remain responsible for reviewing outputs, clearing false positives, making final decisions and complying with their own AML/CTF obligations.

Australian privacy law may require additional transparency for certain automated decisions in the future. We will update this policy if those requirements apply to Custarra.

14. Cookies and tracking

Our website and platform use cookies and similar technologies that are necessary to operate the service, manage authentication and sessions, keep accounts secure, and maintain service reliability.

We may also use cookies or similar technologies to remember user preferences, understand how the website and platform are used, measure performance, and improve our services. If we introduce non-essential analytics, advertising or tracking technologies, we will update our practices where required by law.

A cookie is a small file placed on your browser or device. You can usually configure your browser to refuse or disable cookies. If you do so, some parts of the website or platform may not work properly.

Our hosting and infrastructure providers may collect standard technical information, such as IP addresses, device information, browser information and request metadata, as part of operating and securing the service.

15. Complaints

If you think we have mishandled your personal information, please contact us first at privacy@custarra.com.au. We take complaints seriously and will acknowledge and respond within 30 days.

We may ask you for further information to verify your identity or understand your complaint. We will take reasonable steps to investigate and, where appropriate, remedy any failure to comply with our privacy obligations.

If you are not satisfied with our response, you can escalate to the Office of the Australian Information Commissioner (OAIC), which can investigate privacy complaints under section 36 of the Privacy Act 1988:

16. Availability of this policy

This policy is published free of charge at www.custarra.com.au/privacy. If you need it in an alternative format (for example, large print or a plain-text or printed copy), email info@custarra.com.au and we will provide one within a reasonable period.

17. General privacy inquiries

For general questions about how we handle personal information — short of a formal access, correction, or complaint request — you can email info@custarra.com.au and we will respond within a reasonable period.

18. Legislative framework

This policy reflects the Australian privacy laws that apply to how we handle personal information, including the Privacy Act 1988 (Cth), the Australian Privacy Principles and the Notifiable Data Breaches scheme. It also reflects the AML/CTF compliance context in which our business customers use the Custarra platform.

Our business customers remain responsible for complying with their own AML/CTF obligations, including any applicable record-keeping, customer due diligence, reporting and ongoing monitoring obligations. Custarra provides technology to assist with those compliance workflows but does not replace the business customer’s own legal and regulatory responsibilities.

19. Changes to this policy

We may update this policy from time to time, including where our services, data handling practices, providers or legal obligations change. The “current as of” date at the top shows when this policy was last updated. If we make material changes to this policy, we will take reasonable steps to notify users, such as through the service, our website or direct communications.

20. Contact us

Custarra Pty Ltd (ACN 698 484 614) trading as Custarra