Privacy Statement
This statement explains how BNDRY handles personal information. It is written to be read in full by our business customers, their compliance and procurement teams, and by individuals whose information we handle, including patrons whose identity is verified at a venue. It is a plain-language summary of our full privacy policy and links to that policy where you need more detail.
Last Updated: 5th August 2026
Who we are
BNDRY Pty Ltd (ABN 49 678 808 449) is a wholly owned subsidiary of Identitii Limited (ACN 603 107 044). We handle personal information in accordance with the Privacy Act 1988 (Cth) (the Privacy Act) and the Australian Privacy Principles (APPs) in Schedule 1 to that Act. Our full privacy policy is published at identitii.com/legal/governance and governs both companies. This statement summarises it and does not replace it. Where the two differ, the full policy prevails.
Which document applies to you
Several documents work together. This statement is the entry point. The full privacy policy at identitii.com/legal/governance carries the complete detail. Our terms and conditions and, for identity verification, our end user terms at bndry.net/legals/end-user-terms set out the functional detail of specific services. Where we handle personal information on behalf of a business customer, the customer collects that information under its own privacy policy and we handle it under a data processing agreement with that customer, which sets our obligations as processor.
Where your data is held
This is the question we are asked most often, so we answer it plainly and by category.
Information we process on behalf of customers. Personal information that we process for a customer through our platform, including membership and venue records, is stored and processed in Australia. Where a service provider accesses this information from outside Australia under a standing arrangement, that provider, its location and the purpose of the access are identified at trust.bndry.net/subprocessors.
Identification information handled through identity verification. Identification information and verification results are stored and accessed only within Australia. The systems that deliver the service are located in Australia, operated in a dedicated environment that BNDRY controls, and management and control of the service is conducted in Australia. This information is not held or processed in the United States, the Philippines or the European Union. Overseas access occurs only where it has been authorised in writing under our participation agreements, and any overseas personnel involved must comply with the APPs for all personal information they receive.
General corporate information. Information we hold for corporate functions, meaning marketing, recruitment, customer support and website analytics, may be disclosed to or accessed by service providers in the United States, the Philippines and the European Union. Those countries appear for a specific reason. Our customer support includes staff based in the Philippines who answer support tickets, and our corporate email and productivity tools run on Google Workspace, whose tenancy involves the United States and the European Union. Customer data and identity verification data are not stored in those countries.
Before we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs, usually through enforceable contractual terms. We remain accountable for the acts and practices of overseas recipients under APP 8.1 and Privacy Act s 16C unless an exception in APP 8.2 applies. No country has been prescribed by regulation for the purposes of the prescribed country exception in APP 8.3, so we place no reliance on any Australian Government country list.
Information we collect
The kinds of personal information we collect depend on your relationship with us as a website visitor, business contact, job applicant, customer or individual undergoing identity verification. They include contact and identity details such as name, address, email, phone and job title; employment history and professional qualifications; government identification documents such as a driver licence, passport, visa, birth certificate or Medicare card; device and technical information such as IP address, browser and operating system; cookie data; customer support records; marketing preferences; financial and billing details; social media interactions; and feedback, complaints and survey responses. For customers in the venue sector we also handle membership and venue records at the customer's direction.
Some of this is sensitive information under the Privacy Act, including government identification and any biometric information used for identity verification. We collect sensitive information only with consent, unless an exception in APP 3.4 applies, such as where collection is required or authorised by an Australian law.
How we collect it
We collect personal information directly from you where we can, for example when you complete a form, sign a contract, contact support or verify your identity. We also receive it indirectly, for example from a customer using our services, from business partners and service providers, and from public sources. Where you may be unaware of an indirect collection, we take reasonable steps to make you aware of the matters in APP 5.
Why we collect and use it
We use personal information for the purpose for which it was collected and for related purposes you would reasonably expect. Our main purposes and their basis under the APPs are:
- providing our services, including onboarding, due diligence, risk management and identity verification, as the primary purpose of collection (APP 6.1)
- meeting legal and regulatory obligations, including under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), where required or authorised by an Australian law (APP 6.2(b))
- customer support and service notices, as a related purpose you would reasonably expect (APP 6.2(a))
- billing and payments, as a primary purpose (APP 6.1)
- recruitment, as reasonably necessary for our functions (APP 3.2)
- website analytics and marketing, with your consent (APP 7)
Identity verification
Where a customer uses us to verify an individual's identity, we check the details of a document the individual provides, such as a driver licence or passport, against official records held by the document issuer or the relevant government body, and return only whether the details match. Where a check involves a biometric step, any facial image is used only to complete that check and is kept no longer than needed. Verification is always optional and requires the individual's express consent before any check is initiated. If an individual does not consent, the customer offers another way to verify identity. The functional detail, including the consent statement, is at bndry.net/legals/end-user-terms.
Anonymity and pseudonymity
Where it is lawful and practicable, you can deal with us anonymously or under a pseudonym (APP 2), for example for a general enquiry. This is usually impracticable where we verify identity or meet AML/CTF obligations, because those functions depend on knowing who you are.
Automated decision making
We use automated processing in some areas, including fraud detection, security lockouts and identity checks, where an automated outcome can affect an individual, for example by delaying onboarding. We keep meaningful human involvement in decisions that may significantly affect you, and you can ask us to review a decision and explain how it was made. This describes our use of computer programs to make, or to do things substantially and directly related to making, decisions that could reasonably be expected to significantly affect your rights or interests, consistent with APP 1.7, which commences 10 December 2026.
Government-related identifiers
We do not adopt a government-related identifier, such as a Medicare number or Tax File Number, as our own identifier of you (APP 9). We use or disclose such identifiers only where the APPs permit, for example where reasonably necessary to verify your identity or where required by an Australian law. Identity documents contain government-related identifiers, and we apply the same restrictions to the identifiers they contain.
Cookies
Our website uses cookies. On your first visit you can give or decline consent by category through our cookie banner, and no cookies other than those needed to record your choice load before you consent. You can change your preferences at any time.
Direct marketing
We use personal information for direct marketing only with your consent or where you would reasonably expect it, and every marketing message includes a simple way to opt out (APP 7). We do not use sensitive information for direct marketing without your express consent.
Security
We take reasonable steps to protect personal information (APP 11.1). These include encryption in transit and at rest, access limited to authorised personnel on a least-privilege basis with multi-factor authentication, network and endpoint protection, secure development practices, and due diligence on service providers.
Retention and destruction
We keep personal information only for as long as it is needed for the purpose for which it was collected, or as required by law. When it is no longer needed and we are not required to retain it, we take reasonable steps to destroy it or de-identify it (APP 11.2).
Data breaches
If we suspect a data breach, we contain it and assess it. Where we suspect an eligible data breach, we complete an assessment within a maximum of 30 days (Privacy Act s 26WH). If we have reasonable grounds to believe an eligible data breach has occurred, we notify the Office of the Australian Information Commissioner (OAIC) and affected individuals as soon as practicable (Privacy Act ss 26WK and 26WL), and where it is not practicable to notify individuals directly we publish a statement. Where we process personal information for a customer, we also notify that customer under the data processing agreement. A 72 hour notification deadline applies only where the EU or UK GDPR applies.
Your rights, access and correction
You can ask us for access to the personal information we hold about you (APP 12) and ask us to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). We respond within a reasonable period, generally within 30 days, and we do not charge for making a request. You can also withdraw a consent you have given, and opt out of direct marketing, at any time. If we refuse access or correction, we give written reasons and tell you how to complain. Where your information is held by a customer on whose behalf we process it, contact that customer directly.
Complaints
If you think we have mishandled your personal information, contact us at [email protected]. We acknowledge complaints promptly and aim to respond in writing within 30 days. If you are not satisfied with our response, you can complain to the OAIC at oaic.gov.au.
Individuals in the EU or UK
Where the EU or UK GDPR applies to how we handle your personal data, additional rights and transfer safeguards apply, including access, rectification, erasure, restriction, portability and objection. These are set out in the full privacy policy at identitii.com/legal/governance.
Contact us
Email [email protected], call +61 2 8806 0438, or write to C/- Boardroom Pty Limited, Level 8, 210 George Street, Sydney NSW 2000. Our subprocessor list is at trust.bndry.net/subprocessors.
Changes to this statement
We update this statement when our practices change or for legal or operational reasons. Material changes are communicated through our website.