Privacy Policy
Last updated: 11 July 2026. This notice explains how Veri5me handles candidate, business, payment, provider, and platform-security data across web, API, and mobile workflows.
Information We Handle
Purpose-Limited Collection
Veri5me collects personal information only where it is reasonably needed to create an account, request or complete a verification workflow, process payment, issue reports, support candidate rights, secure the platform, or meet legal and operational obligations.
Business customers must choose checks that are relevant to the stated role, engagement, tenancy, property, or compliance purpose. Candidates can see the purpose and requested categories before providing consent.
Consent, Access, Correction, Dispute, And Withdrawal
Candidates can request access to their records, correction of inaccurate information, dispute review of an outcome, or withdrawal of consent from the portal or mobile app.
Some requests may pause report release, apply a compliance hold, or limit deletion while Veri5me investigates, preserves evidence, or meets legal, audit, provider, or regulatory obligations.
Australian Storage And Processing
Sensitive verification documents and records are designed to be stored in Australian-region Firestore and Cloud Storage resources before production candidate document handling.
Operational controls include private object storage, signed download URLs, direct-write blocking for sensitive collections, retention policies, audit events, and legal holds.
Overseas Processors And Providers
Stripe, Resend, monitoring tools, cloud infrastructure services, and selected verification providers may process limited operational or payment data outside Australia.
Outbound emails and push notifications are designed to be notification-only. Veri5me does not attach raw verification evidence or sensitive report results to transactional messages.
Retention, Deletion, And De-Identification
Raw evidence, reports, audit events, billing records, and candidate profile data are governed by retention policies based on data type, workflow state, legal hold status, dispute status, and operational need.
Deletion sweeps are audit logged. Legal holds, open disputes, provider obligations, tax/accounting records, fraud prevention, or regulatory requirements may extend retention.
Security, Breaches, And Audit
Veri5me uses role-based access, privileged MFA challenges, server-side workflow enforcement, private storage, signed URLs, webhook signature verification, redacted logs, and audit trails for sensitive actions.
Suspected privacy or security incidents are triaged through the incident register. Where a notifiable data breach threshold is met, the response workflow supports affected-user and regulator notification preparation.
Marketing Consent
Transactional messages for security, consent, evidence, workflow, referee, billing, and report milestones are separate from marketing messages and may be required to deliver the service.
Marketing is optional and preference-based. Opting out of marketing does not disable required transactional or security notifications.
Candidate Requests
Candidates can submit access, correction, dispute, or withdrawal requests from My Checks. Verified support requests may also be directed to privacy@veri5me.com.au.
Production Approval
Police, official identity, tenancy, property/title, and other regulated workflows require approved provider access, privacy impact review, security review, and final Australian legal approval.