Privacy Policy
Last updated 6/05/2022
About this Policy
Novatti Group Limited (ACN 606 556 183) and its subsidiaries, including Novatti Acquiring Services (AUS) Pty Ltd (ACN 647 567 084) (together, Novatti, we, us, our), are committed to protecting the privacy of individuals whose personal information we handle.
This Privacy Policy (Policy) sets out how we collect, hold, use, disclose, and manage personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), as amended by the Privacy and Other Legislation Amendment Act 2024.
This Policy applies to:
- our website at novatti.com and all associated Novatti digital properties;
- our payment processing, acquiring, card issuing, and related financial services;
- our interactions with customers, merchants, business partners, and job applicants; and
- all personal information we collect, whether online, in writing, or in person.
By using our website or services, or by providing us with your personal information, you acknowledge that you have read and understood this Policy. You are not required to provide personal information to us, but if you do not, we may be unable to provide you with certain services.
Who We Are and How to Contact Us
Novatti Group Limited is an APP (Australian Privacy Principles) entity for the Privacy Act, and is the entity accountable for the personal information described in this Policy. Our Privacy Officer is responsible for ensuring our compliance with this Policy and the APPs.
Privacy Officer: Novatti Group Limited
Address: Level 3, 461 Bourke Street, Melbourne VIC 3000, Australia
Telephone: +61 3 9011 8490
Email: privacy.officer@novatti.com
Website: novatti.com/privacy
If you have questions about this Policy, wish to access or correct your personal information, make a privacy complaint, or opt out of direct marketing, please contact our Privacy Officer using the details above. We will respond within a reasonable time and no later than 30 days of receiving your request.
What Personal Information We Collect
Personal information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not true and whether or not recorded in material form.
Information You Provide to Us
We collect personal information that you voluntarily provide, including:
- Identity information: name, date of birth, gender, and government-issued identification details collected for verification and KYC/AML compliance purposes;
- Contact details: postal address, email address, telephone, and fax numbers;
- Financial information: bank account details, payment card information, and transaction data required to process payments;
- Business information: ABN, ACN, business name, and the contact details of authorised representatives;
- Account credentials: usernames and passwords for any Novatti online portal or application;
- Correspondence: information you include in emails, enquiries, or other communications with us; and
- Employment information: résumés, CVs, qualifications, and references submitted for job applications.
Information Collected Automatically
When you visit our website, we may automatically collect:
- Technical data: your IP address, browser type and version, operating system, device identifiers, and time zone;
- Usage data: pages visited, links clicked, time on page, referring URLs, and session information;
- Cookie data: information stored by cookies and similar tracking technologies (see Section 7 below).
This data is primarily statistical and non-identifying. Where it can be linked to an individual, it is treated as personal information under this Policy.
Sensitive Information
Sensitive information is a subset of personal information that warrants higher protection. It includes racial or ethnic origin, health information, biometric data, criminal record information, and similar categories defined under the Privacy Act.
We do not actively seek to collect sensitive information through our website or general customer interactions. However, sensitive information may be collected in the following limited circumstances:
- With your explicit consent, where it is necessary to provide a service or comply with a legal obligation (for example, health information provided in the context of an employment application);
- Where collection is required or authorised by law (for example, under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006).
We will handle sensitive information in accordance with the heightened protections required by APP 3.3 and will not use or disclose it except as permitted by the APPs or required by law.
How We Collect Personal Information
We collect personal information by lawful and fair means. We collect it directly from you wherever reasonably practicable. Collection occurs:
- when you visit or interact with our website;
- when you contact us by telephone, email, post, or in person;
- when you apply for, use, or enquire about our products or services;
- when you complete account registration or onboarding processes;
- when you submit a job application or participate in a recruitment process;
- through cookies and analytics tools (see Section 7); and
- through identity verification and KYC processes required by law.
We may also collect personal information from third parties, including credit reporting bodies, identity verification services, government agencies, and publicly available sources, where permitted by law and where it is unreasonable or impracticable to collect the information directly from you. Where we do so, we will take reasonable steps to notify you as soon as practicable.
How We Use Your Personal Information
We use personal information only for the purposes for which it was collected, for directly related purposes, or as otherwise permitted or required by law. These purposes include:
Providing Our Services
- Processing and settling payment transactions;
- Operating and managing merchant acquiring and payment facilitation services;
- Creating and managing customer accounts and profiles;
- Responding to enquiries, requests, and complaints;
- Communicating with you about your account or our services.
Legal and Regulatory Compliance
- Verifying your identity and conducting customer due diligence (KYC/CDD) as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006;
- Monitoring transactions and reporting to AUSTRAC as required by law;
- Meeting our obligations as an Australian Financial Services Licensee;
- Complying with court orders, regulatory directions, and other legal requirements
Business Operations
- Improving and developing our products, services, and website;
- Conducting internal analytics, risk management, and fraud prevention;
- Managing supplier, partner, and contractor relationships;
- Processing job applications and managing our workforce.
Direct Marketing
We may use your contact information to send you marketing communications about our products and services, but only where:
- you have provided your consent, or we reasonably believe you would expect to receive such communications based on our existing relationship; and
- we provide a clear and easy opt-out mechanism in every marketing communication.
You may opt out of direct marketing at any time by:
- using the unsubscribe link in any marketing email;
- contacting our Privacy Officer at privacy.officer@novatti.com; or
- updating your communication preferences in your account settings.
We will action opt-out requests promptly and no later than 5 business days after receipt. We will not use or disclose personal information for direct marketing if you have opted out.
Automated Decision-Making
From December 2026, amendments to the Privacy Act introduced by POLA 2024 require APP entities to notify individuals when their personal information is used in substantially automated decisions that significantly affect them. Where we use automated processes to make or inform such decisions — including in the areas of fraud detection, transaction risk scoring, or onboarding assessments — we will take reasonable steps to inform you of this use at or before the time of collection, or as otherwise required by law. You may contact our Privacy Officer if you have questions about whether an automated decision has been made using your personal information.
Disclosure of Personal Information
We do not sell personal information. We may disclose personal information to third parties and overseas recipients in the limited circumstances set out below.
Disclosure to Third Parties
We may disclose personal information to the following categories of third parties:
- Service providers: third-party vendors and contractors who assist us in operating our business (including technology providers, payment processors, identity verification services, cloud storage providers, and professional advisers), who are bound by confidentiality obligations and must handle personal information in accordance with the APPs;
- Related entities: other Novatti Group entities where necessary to deliver services or for internal business purposes;
- Regulatory authorities: AUSTRAC, ASIC, APRA, and other regulatory bodies as required by law;
- Law enforcement: when required by law, court order, or government authority;
- Business transfers: in connection with a merger, acquisition, corporate restructure, or asset sale, where equivalent privacy obligations bind the recipient.
Cross-Border Disclosure
Novatti operates internationally, and your personal information may be transferred to, stored, or processed by personnel or systems located outside Australia, including in the following countries or regions:
- India — technology development and operations support;
- United States — cloud infrastructure and third-party service providers;
- United Kingdom and European Union — international payment network partners;
- Singapore and other Asia-Pacific jurisdictions — regional operations.
Before disclosing personal information to overseas recipients, we take reasonable steps to ensure that the overseas recipient does not breach the APPs in relation to the information. This may include entering into data processing agreements, standard contractual clauses, or other contractual protections.
Where we are unable to ensure that an overseas recipient will handle personal information in accordance with the APPs, we will seek your consent to the disclosure. By consenting, you acknowledge that we may not be able to take reasonable steps to ensure the overseas participant complies with the APPs, and that you may not be able to seek redress under the Privacy Act in relation to the recipient’s handling of your personal information.
Cookies and Online Tracking
What Are Cookies?
Cookies are small data files placed on your device when you visit a website. We use cookies and similar technologies (including pixels, web beacons, and local storage) to operate and improve our website, personalize your experience, and support our marketing activities.
Types of Cookies We Use
- Essential cookies: required for the website to function and cannot be disabled;
- Analytics cookies: help us understand how visitors interact with our website (we use Google Analytics for this purpose);
- Marketing and remarketing cookies: used to deliver advertisements relevant to your interests across third-party platforms, including through Google Ads.
Google Ads Remarketing
Our website uses Google Ads to show advertisements to previous visitors on third-party websites and in Google search results. This service uses cookies to identify visitors who have previously interacted with our site. Any personal information collected through these activities is used in accordance with this Policy and Google’s Privacy Policy.
You can opt out of Google’s use of cookies for advertising purposes by visiting Google’s Ad Settings page at adssettings.google.com.au.
Managing Cookies
Most browsers allow you to control cookies through their settings. You can choose to block or delete cookies; however, doing so may affect the functionality of our website. For more information about managing cookies, visit allaboutcookies.org.
Data Security
We take the security of your personal information seriously and implement reasonable technical and organisational safeguards to protect it from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:
- Encryption of personal information in transit (TLS/SSL) and at rest for sensitive data;
- Multi-factor authentication and role-based access controls on systems storing personal information;
- Regular security assessments, penetration testing, and vulnerability management;
- Staff training on privacy and information security obligations;
- Physical security controls at our premises and data centres;
- Contractual requirements on third-party service providers to maintain appropriate security measures.
While we take all reasonable precautions, no method of electronic transmission or storage is entirely secure, and we cannot guarantee the absolute security of information transmitted over the internet.
Data Retention
We retain personal information only for as long as it is necessary to fulfil the purposes for which it was collected, or as required or permitted by law. Specific retention obligations include:
- AML/CTF records: minimum 7 years from the date of the relevant transaction or customer relationship, as required by the Anti-Money Laundering and Counter-Terrorism Financing Act 2006;
- Financial records: as required by applicable tax and corporations legislation;
- Customer account data: retained for the duration of the customer relationship and for a period thereafter as required by law and legitimate business purposes;
- Job applicant data: for unsuccessful applicants, retained for up to 12 months after the completion of the recruitment process, unless you consent to retention for future opportunities;
- Website analytics data: typically retained in aggregate or anonymised form after 26 months.
When personal information is no longer required, we take reasonable steps to securely destroy it or de-identify it in accordance with APP 11.2.
Please refer to the Record Keeping Policy for further information.
Notifiable Data Breaches
Novatti is subject to the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. If we become aware of a data breach that is likely to result in serious harm to one or more individuals, we are required to:
- assess whether the breach is an eligible data breach;
- notify the Office of the Australian Information Commissioner (OAIC); and
- notify affected individuals as soon as practicable.
We maintain an internal data breach response plan and incident register. All staff are required to report suspected data breaches to the Privacy Officer immediately upon becoming aware of them.
If you believe that a data breach involving your personal information has occurred, please contact our Privacy Officer as soon as possible using the contact details in Section 2.
Your Rights
Access
You have the right to request access to personal information that we hold about you. To make an access request, please contact our Privacy Officer. We will respond within 30 days and provide access in a format that is reasonable and appropriate. We may charge a reasonable fee to cover the cost of providing access.
We may refuse access in limited circumstances permitted by the Privacy Act, such as where access would unreasonably impact the privacy of other individuals, or where required by law. We will provide written reasons for any refusal.
Correction
If you believe that personal information we hold about you is inaccurate, incomplete, out of date, irrelevant, or misleading, you may request that we correct it. We will take reasonable steps to correct the information and will respond to your request within 30 days.
Anonymity and Pseudonymity
Where lawful and practicable, you may interact with us anonymously or using a pseudonym. We will inform you if it is not practicable to deal with you on this basis.
Opt Out of Direct Marketing
You may opt out of receiving direct marketing communications from us at any time. See Section 5.4 for opt-out methods.
Children
Our services are not directed at children under the age of 18. We do not knowingly collect personal information from individuals under 18 without verifiable parental or guardian consent. If you believe we have inadvertently collected such information, please contact our Privacy Officer, and we will take steps to delete it promptly.
We are committed to compliance with any Children’s Online Privacy Code made under the Privacy Act as that framework develops.
Statutory Tort for Serious Invasions of Privacy
From 10 June 2025, individuals have a direct right to take legal action against organisations — including Novatti — for serious invasions of privacy under the statutory tort introduced by POLA 2024. This right exists independently of any complaint made to the OAIC.[C1]
A serious invasion of privacy may include unauthorised surveillance or monitoring, improper disclosure of sensitive personal information, or misuse of personal data in a way that would be highly offensive to a reasonable person. If you believe Novatti has seriously invaded your privacy, you may:
- contact our Privacy Officer to raise a complaint (see Section 11); or
- seek independent legal advice about your rights under the statutory tort.
Making a Privacy Complaint
If you have a complaint about how we have handled your personal information, or believe we have breached the APPs or this Policy, please contact our Privacy Officer using the details in Section 2. Please provide as much detail as possible about the nature of your complaint.
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. Where a complaint is complex, we will keep you informed of our progress.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):
Australian Information Commissioner (OAIC): Office of the Australian Information Commissioner GPO Box 5218, Sydney NSW 2001 Telephone: 1300 363 992
Website: oaic.gov.au
Online complaint form: oaic.gov.au/privacy/privacy-complaints
Government Identifiers
Novatti will not adopt, use, or disclose a government-related identifier (such as a tax file number or Medicare number) as its own identifier of an individual, except where required or permitted by law, including for identity verification and AML/CTF compliance.
Updates to This Policy
We may update this Policy from time to time to reflect changes in our practices, technology, or legal obligations. We will publish the updated Policy on our website and, where the changes are material, we will notify you by email or through a prominent notice on our website.
The current version and effective date of this Policy are shown on the cover page. We encourage you to review this Policy periodically.
This Policy will be reviewed at least annually, or earlier upon:
- material changes to the Privacy Act, APPs, or OAIC guidance (including POLA 2024 implementation);
- significant changes to the Novatti Group’s business model, services, or data handling practices;
- identification of a material compliance deficiency or privacy incident; or
- direction from the OAIC or another regulatory authority.
Definitions
APP: Australian Privacy Principle, as set outin Schedule 1 ofthe PrivacyAct.
APP entity: An organisation or agency bound by the APPs underthe Privacy Act.
Eligible data breach: A data breach thatis likely to resultin serious harm to any oftheindividuals to whom the information relates.
KYC / CDD: Know Your Customer/ Customer Due Diligence — identityverification and risk assessment processes required by AML/CTF law.
NDB scheme: The Notifiable Data Breaches scheme under PartIIIC ofthe PrivacyAct.
OAIC: Office ofthe Australian Information Commissioner.
Personal information: Information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive information: A subset of personal information, including racial or ethnic origin,health information, biometric data, and other categories defined inthe Privacy Act