Privacy Policy
Last updated: 28 July 2026
1. Who we are
Senly ID is operated by SenlyAI, a trading name of Uinspo Pty Ltd (ABN 47 664 833 872) (“Senly”, “we”, “us”), registered in Victoria, Australia. We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we handle personal information in an open and transparent way (APP 1).
Senly ID is an identity and business-verification platform. A consumer verifies their identity once and holds the result in a personal vault; a business runs verification checks on its own customers or people and receives a tamper-proof, re-verifiable result it can file as evidence. Different data-handling rules apply to each, and we explain them below.
2. The personal information we collect and hold
We collect only what a verification requires. Depending on how you use Senly ID:
- Identity information: your name, date of birth, and details from a government identity document (for example a driver licence, passport or Medicare card), plus a live selfie / liveness capture used to confirm the document belongs to you.
- Verification results: a result summary (verified / not verified, the assurance level, and whether any sanctions or politically-exposed-person match was found), and a cryptographically-signed record of the check.
- Account information: your email address and authentication details (one-time codes or passkeys) used to sign in.
- Business information: for business users, your organisation’s legal name, ABN/ACN, and the details of the people who own or control the business (its beneficial owners and directors) where a business check requires them.
- Billing information: for business users, billing contact and ABN. Card payments are processed by our payment provider (Stripe) on their hosted page. We never see or store your card number.
- Technical information: limited device, browser and network signals used for security and fraud prevention when a verification is performed.
Your liveness / biometric capture is sensitive information under the Privacy Act, which we collect only with your consent. A government-related identifier (for example a driver licence, passport or Medicare number) is personal information that we use and disclose only where it is reasonably necessary to verify your identity (APP 9); we never adopt it as our own identifier for you.
3. How we collect it
We collect personal information directly from you when you complete a verification, and from a business when it asks us to verify one of its customers (in which case that business is responsible for having a lawful basis and telling you it is using Senly). Where a business check requires it, company and registry information is collected from official Australian registers (such as the Australian Business Register and ASIC).
4. Why we collect, use and disclose it (purpose)
- To verify your identity and produce a verification result.
- To let a business you are dealing with confirm your verification, sharing only what you consent to disclose (see selective disclosure below).
- To let you re-use your verified identity and control what you share.
- To meet legal and regulatory obligations (including AML/CTF record-keeping).
- To secure the service, prevent fraud, and provide support and billing.
Selective disclosure & consent. Senly ID is built so that you share only the specific attribute a business needs, for example confirming you are over 18 without revealing your date of birth. A business receives your personal details only when you expressly consent to disclose them.
4a. Ongoing monitoring (included with an AML check)
Every AML check includes ongoing monitoring for a certain period. While monitoring is active, we periodically re-check the person, and any business entity involved, against public sanctions, politically-exposed-person and adverse-media sources, and we re-check them when those lists change. This helps the business keep its customer due diligence up to date, as expected under the AML/CTF regime. Monitoring is based only on the identity details already collected for the check; we do not collect new document images to monitor you. Monitoring runs for the period covered by the check and then stops.
5. Automated verification steps
Identity verification uses automated steps to reach a “verified” or “not verified” outcome. These steps are checks and comparisons, not a decision made about you by artificial intelligence: reading the details on your document, matching those details against the issuing authority’s records, comparing your selfie to the photo on your document to confirm it is you and that you are physically present, and screening your name against public sanctions and politically-exposed-person lists.
This automated outcome can affect whether a business proceeds with you. A verification result is evidence for the business, not a final decision by us about you, and the business makes its own decision. Where a check is declined and you are eligible, we offer a review/appeal path with human involvement, and you can contact us about any result that concerns you.
6. How we protect it (security)
We take the security of personal information seriously (APP 11). Our safeguards include:
- Encryption at rest of sensitive vault data using AES-256-GCM, with keys managed in a hardware-backed key-management service; encryption in transit using TLS.
- Process-and-purge. After a verification result is captured and signed, the raw verification session (including document images) is deleted at the verification processor. We store the outcome and the attributes you choose to keep. We do not retain raw identity documents.
- Strict access controls, tenant isolation, and audit logging.
- Our identity-verification processing is performed by a specialist provider that is independently certified to recognised standards, including SOC 2 (Type 1), ISO/IEC 27001:2022, and iBeta Level 1 presentation-attack detection (ISO/IEC 30107-3) , with AES-256 encryption at rest, TLS 1.3 in transit, a 99.99% availability target, and no material data breaches to date.
- Australian government-document checks are performed against the official Document Verification Service (DVS) through a trusted gateway provider authorised on the Australian Government’s approved list of gateway service providers. A DVS check confirms that a document’s details match the issuing authority’s records; it is a yes/no match and does not retain your document.
7. Overseas disclosure
Our identity-verification processing provider hosts data in the European Union (on AWS infrastructure) by default. This means that when you complete a verification, the relevant personal information may be processed by that provider overseas (APP 8). We take reasonable steps to ensure any overseas recipient handles your information consistently with the APPs, including through a data-processing agreement with GDPR-standard technical and organisational measures. Our payment provider may also process limited billing information overseas. Where a business has enrolled ongoing monitoring, this overseas processing continues for the monitoring period, not just at the moment of the original check.
8. How long we keep it (retention)
Retention depends on who the record is for:
- Business compliance records. When a business runs a check on you, the resulting evidence is the business’s record and is retained for the period the law requires for that business’s purpose. For anti-money-laundering (AML/CTF) checks this is seven (7) years; for other sectors we keep the record for a shorter, minimised period appropriate to the purpose (for example around a year for a utility or telco account, or only while a rental application is assessed), after which it is securely disposed of. You cannot shorten or delete a record the business is legally required to keep. Where ongoing monitoring is active, the monitoring result and any alerts form part of that business record and are kept on the same basis.
- Your personal vault copy. Any copy you save to your own free Senly vault is controlled by you: you can view it, choose what to share, and delete it at any time. Deleting your copy never affects a business’s separate compliance record.
Where we are not required by law to keep information, we destroy or de-identify it when it is no longer needed (APP 11.2).
Disclosure records. When a business downloads a record containing your verified identity, we keep an access log of that disclosure — who downloaded it, when, and the consent they gave — as a security and accountability measure. This log itself is protected personal information and is kept only as long as needed for that purpose.
9. Accessing and correcting your information (APP 12 & 13)
You may ask us to access the personal information we hold about you, and to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us at privacy@senly.ai. We will respond within a reasonable time and may need to verify your identity first. If we cannot give access or make a correction, we will tell you why in writing.
10. Children and young people
Senly ID consumer accounts and the personal vault are intended for people aged 15 and over. A business may ask us to verify a person’s age (for example, to confirm they are over 16 or over 18) or otherwise verify a minor. Where a person is under 15, we require the consent of a parent or guardian, consistent with guidance from the Office of the Australian Information Commissioner, which as a general rule treats a young person aged 15 or over as able to consent for themselves, and otherwise looks to a parent or guardian.
When we perform an age check, we follow data-minimisation and disclose only the age result required (for example “over 18”). We do not reveal a date of birth unless it is necessary and you consent. We handle any minor’s information with the same protections and process-and-purge rules set out in this policy, and we will align with Australia’s Children’s Online Privacy Code when it takes effect.
11. Cookies and analytics
We use a small number of strictly-necessary cookies to keep you signed in and to keep the service secure. We do not sell your personal information. If we introduce optional analytics or preference cookies, we will seek your consent and update this policy.
12. A note for businesses using Senly ID
When a business verifies a customer through Senly ID, the business is the entity responsible for that customer relationship and its own compliance obligations. Senly provides evidence of verification. It does not replace your own customer due diligence (CDD) or AML obligations. The business must have a lawful basis to collect and use the individual’s information and must comply with its own privacy obligations.
13. Complaints
If you believe we have breached the Australian Privacy Principles, contact us first at privacy@senly.ai and we will investigate and respond. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
14. Changes to this policy
We may update this policy from time to time. The “last updated” date above shows when it last changed. Material changes will be notified through the service.