How TrancheMate collects, uses, and protects your personal information
Last updated: 10 June 2026 · Effective: 10 June 2026
This Privacy Policy is issued by TrancheMate (ABN 74 421 798 989) and governs the handling of personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs). By using TrancheMate, you agree to the collection and use of information as described in this policy.
TrancheMate ("TrancheMate", "we", "us", "our") operates the TrancheMate compliance platform at tranchemate.com.au. We provide AUSTRAC Tranche 2 AML/CTF compliance tools to Australian accounting firms, law firms, and real estate agencies.
Our platform enables subscriber firms ("Firms") to build AML/CTF compliance programs, manage client due diligence (CDD) records, and maintain audit-ready compliance documentation as required under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
TrancheMate operates in two capacities:
When a Firm registers and uses TrancheMate, we collect:
Answers provided in the AML/CTF Program Builder wizard, including firm structure, designated services, client risk profile, and governance arrangements. This information is used to generate compliance documentation.
Firms use TrancheMate to collect identity and KYC information from their own clients. This data, stored on behalf of the Firm, may include:
TrancheMate stores this data as a processor on behalf of the Firm. Firms bear responsibility for their own compliance obligations to their clients under the Privacy Act and the AML/CTF Act.
SMR and TTR records logged by Firm staff, including event descriptions, transaction amounts, and AUSTRAC reference numbers. These records are immutable once created (required for audit integrity under the AML/CTF Act).
Dates, event types, and reminder preferences for compliance obligations. No sensitive personal information is contained in these records.
We collect personal information:
We collect personal information only by lawful and fair means, and not in an unreasonably intrusive way.
We collect and use personal information for the following purposes:
We will not use or disclose personal information for a secondary purpose unless: (a) the individual would reasonably expect us to; (b) we have consent; or (c) we are required or authorised by law.
We do not sell, rent, or trade personal information. We may disclose personal information to:
We may disclose personal information where required or authorised by Australian law, including:
If TrancheMate is acquired, merged, or its assets transferred, personal information may form part of the transferred assets. We will notify affected users of any such transfer and the new entity's privacy policy before any change in data handling occurs.
We do not disclose personal information to overseas recipients as a matter of ordinary practice. All infrastructure and data storage is located in Australia (see section 6). In the unlikely event an overseas disclosure becomes necessary (for example, in response to an international regulatory request), we will comply with APP 8 and take reasonable steps to ensure the recipient handles the information consistently with the Australian Privacy Principles.
All data stored in TrancheMate — including CDD records, identity documents, AML/CTF program content, and account information — is stored exclusively on infrastructure located in Sydney, Australia (Akamai ap-southeast-2). No data is transferred to or stored in overseas systems.
Australian data residency is a material requirement for professional services firms subject to the Privacy Act and the AML/CTF Act. We treat it as a non-negotiable architectural constraint.
Akamai's Sydney infrastructure holds ISO 27001:2022 and SOC 2 Type II certifications at the infrastructure layer. TrancheMate's application layer operates to an ISO 27001-aligned security posture.
We take reasonable steps to protect personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:
Despite these measures, no transmission over the internet is completely secure. If you suspect a security breach affecting your account, contact us immediately at [email protected].
We retain personal information for as long as necessary to provide the platform and comply with our legal obligations. Specific retention practices:
When a subscription is cancelled, Firms may export all their compliance records in a full archive download before account closure. We provide a 30-day post-cancellation window to complete this export.
We will take reasonable steps to destroy or de-identify personal information that is no longer required for any purpose permitted under this policy.
We send transactional email that is necessary to operate the platform and your account. This includes:
Transactional email is sent as part of the service you have contracted with us. You cannot opt out of essential transactional messages while your account remains active.
Any marketing or promotional email we send complies with the Spam Act 2003 (Cth). This means:
We do not send unsolicited commercial electronic messages. We do not purchase email lists or send cold email.
To unsubscribe from marketing communications, click the unsubscribe link in any marketing email, or contact us at [email protected] with "Unsubscribe" in the subject line.
Under APP 12 and APP 13, you have the right to:
To request access to or correction of your personal information, contact us at [email protected]. We will respond within 30 days.
We may refuse access in certain circumstances as permitted by the Privacy Act. If we refuse, we will give you written reasons and advise of the available complaint mechanisms.
Note on CDD records and immutability: CDD, SMR, and TTR records stored on behalf of Firms are immutable once created — this is an audit-integrity requirement under the AML/CTF Act. Corrections to underlying personal information held in these records must be handled directly by the Firm that collected them, in accordance with the Firm's own privacy obligations to their clients.
If you have a complaint about how we have handled your personal information, please contact us first:
We will acknowledge your complaint within 5 business days and endeavour to resolve it within 30 days. If we cannot resolve the complaint to your satisfaction, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance.
When we make material changes, we will:
Your continued use of TrancheMate after the effective date of a revised policy constitutes acceptance of the updated policy.
For any privacy-related enquiries, access requests, or complaints, please contact us:
TrancheMate
ABN 74 421 798 989
Email: [email protected]
This policy is governed by the laws of New South Wales, Australia and the Privacy Act 1988 (Cth).