top of page

ClearMarc Privacy Policy

CLEARMARC PTY. LTD. ACN 694 351 543
Effective date: 11 June 2026

ClearMarc ("we", "us", "our") is committed to protecting your privacy and handling personal information in a transparent and responsible manner.
This Privacy Policy explains how we collect, use, disclose, store, and protect personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). By accessing our website or engaging our services, you acknowledge the practices described in this Policy.
Who this Policy applies to
This Policy applies to personal information we handle about:

  • Clients and their representatives — the businesses and people who purchase or request our services;

  • Website visitors; and

  • Subjects — the individuals whose personal information may appear in a verification report or investigation (for example, company directors, officers, or other individuals connected to an entity being verified), who are usually not our direct clients.

"Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, as defined in the Privacy Act.

1. What information we collect
We may collect personal information including (but not limited to):
a) Client and business information

  • Names, job titles, and contact details

  • Business names, ABNs, and business addresses

  • Declared purpose for a verification or investigation request

  • Account credentials for client portals and dashboards (if applicable)

  • Billing and payment-related information (processed via our payment providers)

b) Subject and individual information (where lawful)

  • Names, and where relevant identifying information such as role or directorship

  • Directorships, business associations, and professional background

  • Publicly available information, including company registers, regulatory records, and court records

  • Information reasonably necessary to perform verification, due diligence, or investigative services

c) Technical and usage information

  • IP address, browser and device information

  • Website usage data, cookies, and analytics
     

2. How we collect information
We collect personal information through:

  • Direct interactions (website forms, onboarding, emails, contracts)

  • Client-uploaded data and project instructions

  • Public records and open-source information (OSINT)

  • Third-party data providers, where legally permitted (including providers located overseas)

  • Automated systems used in connection with our services

We only collect personal information that is reasonably necessary for our functions and activities. Where it is reasonable and practicable, we collect personal information directly from the individual concerned.

3. Information about individuals who are not our clients (Subjects)
Some of our services involve verification, due diligence, and investigations. This means we may collect and handle personal information about individuals who are not our clients and who have not provided that information to us directly.
Where this occurs:

  • information is collected lawfully, ethically, and proportionately;

  • only information relevant to a legitimate, lawful business purpose is collected and used;

  • sensitive information (as defined in the Privacy Act, such as information about a person's criminal record) is handled with additional care and is only collected where permitted by law, reasonably necessary, and proportionate to the purpose; and

  • we do not engage in unlawful surveillance or improper investigative practices.

Where we collect personal information about an individual from a third party or a public source, we take reasonable steps to make the individual aware of the matters set out in APP 5, except where doing so would be impracticable, unlawful, or would prejudice the purpose of a lawful verification or investigation. In those cases, the steps that are reasonable may be limited or none, consistent with the APPs.

4. Why we collect personal information
We collect and use personal information to:

  • provide verification, investigative, and risk-related services;

  • conduct due diligence, background checks, and compliance reviews;

  • manage client accounts and deliver our services;

  • communicate with clients and authorised stakeholders;

  • meet legal, regulatory, and contractual obligations; and

  • maintain, improve, and secure our services, systems, and website.
     

5. Disclosure of personal information
We may disclose personal information to:

  • clients, where disclosure forms part of agreed deliverables;

  • third-party service providers (including data providers, payment processors, and IT and hosting services);

  • professional advisers, such as legal, accounting, or compliance advisers; and

  • regulators, courts, or law enforcement agencies, where required or authorised by law.

We do not sell personal information, and we do not disclose personal information for unrelated direct marketing by third parties.

6. Overseas disclosure
Some of our service providers and data sources are located outside Australia. In particular, because we provide verification reports on entities in countries including India and China, we may obtain information from, or relating to entities in, those and other countries, and some data providers and hosting or technology services may be located overseas.
Where personal information is disclosed to an overseas recipient, we take reasonable steps (consistent with APP 8) to ensure that either the recipient handles the information in a manner consistent with the APPs, or the disclosure is otherwise permitted under the Privacy Act.

7. Data security
We take reasonable technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. These measures include access controls, secure systems, and confidentiality obligations on our personnel and contractors. However, no method of transmission or storage is completely secure.

8. Data retention
We retain personal information only for as long as necessary for the purposes set out in this Policy, and then securely destroy or de-identify it.
Third-party reports and source data. The underlying reports and raw data we obtain from third-party data providers in order to prepare a verification report are retained for no longer than 60 days from the date the relevant deliverable is provided to the client, after which they are securely deleted or de-identified. This reflects both good privacy practice and our data providers' requirements regarding the storage of their data.
Our deliverables and records. Our own verification reports, investigation findings, client account information, and project records may be retained for a longer period where reasonably necessary to comply with legal and regulatory requirements, maintain an audit trail, and resolve or defend disputes. These are then securely destroyed or de-identified when no longer required.

9. Access and correction
You may request access to the personal information we hold about you, and request corrections where it is inaccurate, incomplete, or out of date. Requests can be made using the contact details below. We may require verification of your identity before processing a request, and in limited circumstances we may decline access as permitted under the Privacy Act (in which case we will explain why).

10. Cookies and analytics
Our website may use cookies and analytics tools to improve user experience, monitor website performance, and analyse traffic and usage trends. You can manage or disable cookies through your browser settings, though some features of the website may not function as intended if you do.

11. Direct marketing
Where we send commercial electronic messages, we do so in accordance with the Spam Act 2003 (Cth) and will include an unsubscribe option. You can opt out of marketing communications at any time.

12. Complaints
If you believe we have breached your privacy rights or the Australian Privacy Principles, please contact us first using the details below, with details of your complaint. We will acknowledge and investigate, and respond within a reasonable timeframe.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

13. Changes to this Policy
We may update this Privacy Policy from time to time. The current version will always be available on our website, with the "last updated" date shown above.

14. Contact us
For privacy enquiries, access requests, or complaints, contact:
CLEARMARC PTY. LTD. (ACN 694 351 543) Email: support@clearmarc.com.au Within Australia: 02 8323 7184 International: +61 408 511 908

bottom of page