AML/CTF Privacy Policy

Rosie Projects Pty Ltd trading as Shaddock Real Estate

Our commitment

Rosie Projects Pty Ltd trading as Shaddock Real Estate (we, us, our) is committed to protecting the privacy and security of personal information collected and handled in connection with our real estate services and our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).

We collect, use, disclose, store and manage personal information only as reasonably necessary for carrying out our functions and activities, including providing real estate services and complying with our legal and regulatory obligations.

Where we are required to collect personal information to comply with our obligations under the AML/CTF Framework, we will handle that information in an open and transparent manner and in accordance with applicable privacy laws.

This AML/CTF Privacy Policy explains how we collect, use, disclose and protect personal information obtained for the purpose of complying with our AML/CTF obligations.

This policy operates alongside our existing Privacy Policy, which applies generally to personal information collected in connection with our real estate, property management and strata management services.

What does this AML/CTF Privacy Policy cover?

This policy applies specifically to personal information collected, used, disclosed and retained by us in connection with our obligations under the AML/CTF Framework.

These obligations may apply when we provide regulated real estate services, including:

  • assisting with the sale, purchase or transfer of real property
  • acting as a real estate agent in connection with property transactions
  • carrying out customer identification and verification requirements
  • undertaking ongoing customer due diligence
  • assessing and managing risks associated with money laundering and terrorism financing
  • complying with reporting and record keeping obligations.

Our general Privacy Policy continues to apply to other personal information handling activities associated with our business, including property management, leasing, strata management and general customer enquiries.

Meaning of words used in this Privacy Policy

In this Privacy Policy:

AML/CTF Act means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).

AML/CTF Framework means the AML/CTF Act, AML/CTF Rules and relevant guidance issued by the Australian Transaction Reports and Analysis Centre (AUSTRAC).

AML/CTF Rules means the rules made under the AML/CTF Act.

APPs means the Australian Privacy Principles contained in Schedule 1 of the Privacy Act 1988 (Cth).

AUSTRAC means the Australian Transaction Reports and Analysis Centre.

Personal Information has the meaning given under the Privacy Act 1988 (Cth) and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.

Sensitive Information includes information such as health information, racial or ethnic origin, political opinions, religious beliefs, membership of professional or trade associations, criminal records, biometric information and other categories of information defined as sensitive information under the Privacy Act.

KYC Information means information required to verify the identity of a customer and comply with our AML/CTF obligations, including information relating to identity, beneficial ownership, authority to act, transaction purpose and other matters required under the AML/CTF Framework.

We, us, our means Rosie Projects Pty Ltd trading as Shaddock Real Estate.

What privacy laws apply to our relationship?

Rosie Projects Pty Ltd trading as Shaddock Real Estate is required to comply with privacy obligations relating to personal information collected, used, disclosed and retained in connection with our AML/CTF obligations.

The Privacy Act 1988 (Cth), including the Australian Privacy Principles, applies to personal information handled by us for the purposes of complying with the AML/CTF Framework.

These obligations operate alongside our existing privacy obligations relating to our real estate, property management and strata management services.

In some circumstances, we may not be able to provide services or proceed with a transaction unless we are able to collect and verify certain information required under the AML/CTF Framework.

Where lawful and practicable, individuals may choose to interact with us anonymously or using a pseudonym. However, this will generally not be possible where we are required by law to identify and verify an individual.

How do we collect Personal Information?

We collect personal information only by lawful and fair means.

We generally collect personal information directly from the individual concerned.

We may collect personal information when you:

  • engage us as a vendor, purchaser, landlord, tenant, strata owner, owners corporation representative or other customer
  • provide information in connection with the sale, purchase, leasing or management of property
  • provide identification documents or information required for identity verification
  • communicate with us in person, by telephone, email, website enquiry, online platform or other communication methods
  • complete forms, applications or documents associated with our services; or
  • provide information through an authorised representative.

We may also collect personal information from third parties where permitted by law, including:

  • authorised representatives
  • government agencies
  • identity verification service providers
  • professional advisers
  • other parties involved in a property transaction; or
  • publicly available sources.

Where we use a third-party identity verification provider, we will take reasonable steps to ensure personal information is handled securely and in accordance with applicable privacy obligations.

What Personal Information do we collect?

We are required under the AML/CTF Framework to collect and verify certain personal information to assist us in meeting our legal obligations.

The type of personal information we collect may include:

  • full name
  • residential address
  • postal address
  • date of birth
  • contact details, including telephone number and email address
  • identification information and documents required to verify identity
  • information relating to occupation, business activities or source of funds where required
  • information relating to the nature and purpose of the business relationship or transaction
  • information relating to beneficial ownership or control where applicable
  • information relating to persons acting on behalf of another individual or entity
  • information required to determine whether an individual is a politically exposed person (PEP) or subject to targeted financial sanctions
  • any other information required under the AML/CTF Framework.

We may also collect information about interactions, transactions and services provided by us where required to comply with our AML/CTF obligations.

We will only collect Sensitive Information where it is necessary, permitted by law, and reasonably required for the purpose for which it is collected.

What happens if you do not provide requested Personal Information?

Where we are required by law to collect and verify personal information, you may not be able to proceed with certain services or transactions if you do not provide the requested information.

If we are unable to complete required customer identification or verification procedures, we may be unable to:

  • provide certain real estate services
  • proceed with a transaction
  • establish or continue a business relationship; or
  • comply with our legal obligations.

Purposes of collection of Personal Information

We collect and use personal information obtained under the AML/CTF Framework for purposes including:

  • verifying the identity of customers and relevant individuals
  • complying with our obligations under the AML/CTF Act and related legislation
  • conducting customer due diligence and ongoing monitoring where required
  • assessing and managing risks associated with money laundering and terrorism financing
  • maintaining records required under the AML/CTF Framework
  • determining whether additional information or verification is required
  • reporting matters to AUSTRAC or other government authorities where required by law
  • complying with applicable legal, regulatory and professional obligations
  • protecting our business, customers and the integrity of the services we provide.

We will generally only use personal information for the purpose for which it was collected, or for another related purpose that an individual would reasonably expect, or where otherwise permitted or required by law.

Disclosure of Personal Information

We may disclose personal information collected for AML/CTF purposes where reasonably necessary or permitted by law.

This may include disclosure to:

  • AUSTRAC
  • government agencies, regulators or law enforcement authorities where required or authorised by law
  • identity verification providers
  • technology and service providers assisting us with compliance, record keeping, security or administration
  • professional advisers, including legal, accounting or compliance advisers
  • parties involved in a property transaction where disclosure is necessary to provide our services
  • other persons or organisations where an individual has provided consent or where disclosure is permitted or required by law.

We take reasonable steps to ensure third-party service providers that handle personal information on our behalf have appropriate privacy, confidentiality and security obligations in place.

Disclosure to AUSTRAC and other authorities

As part of our AML/CTF obligations, we may be required to provide information to AUSTRAC or other government authorities.

There may be circumstances where we are prohibited by law from informing an individual that information has been provided to AUSTRAC or another authority.

This includes circumstances relating to suspicious matter reporting or other disclosures required under the AML/CTF Framework.

Nothing in this Privacy Policy limits our obligations to comply with lawful reporting requirements.

Business transactions

If we enter into, or propose to enter into, a transaction involving the sale, transfer, restructure or acquisition of our business, personal information may be disclosed to prospective purchasers, advisers or other relevant parties as part of that process.

Any disclosure will be undertaken in accordance with applicable privacy obligations and appropriate confidentiality arrangements.

How do we protect your information?

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.

We hold personal information in both electronic and physical formats and maintain appropriate administrative, technical and physical security measures.

These measures include:

  • restricting access to personal information to authorised employees and service providers who require access
  • maintaining password protection and access controls for business systems
  • using appropriate cybersecurity measures, including antivirus protection, firewalls and security updates
  • providing staff with training regarding privacy obligations and the secure handling of personal information
  • maintaining secure office procedures for physical records
  • reviewing our security practices periodically.

Where a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner where required.

How long do we retain AML/CTF information?

We retain personal information collected for AML/CTF purposes for the period required by law.

AML/CTF records and relevant customer identification information are generally required to be retained for seven (7) years after the end of the relevant business relationship or completion of the relevant transaction.

Where personal information is no longer required and we are not required by law to retain it, we will take reasonable steps to securely destroy or de-identify that information.

Can your Personal Information be accessed overseas?

We may use third-party technology providers, cloud-based systems and software platforms that may store or process information in Australia or overseas.

Where personal information may be accessed or stored overseas, we take reasonable steps to ensure appropriate privacy, confidentiality and security protections are in place.

We require relevant service providers to maintain appropriate safeguards and only use personal information for authorised purposes.

How you can access your Personal Information

Individuals may request access to personal information we hold about them.

Before providing access, we may take reasonable steps to verify the identity of the person making the request.

We will respond to requests for access within a reasonable timeframe.

We may refuse access where permitted under the Privacy Act 1988 (Cth), including where providing access would:

  • pose a serious threat to the life, health or safety of an individual or public health or safety
  • unreasonably impact the privacy of another individual
  • be unlawful
  • prejudice an investigation or enforcement activity
  • reveal commercially sensitive information; or
  • be otherwise permitted by law.

If we refuse access, we will provide written reasons unless prohibited by law.

Correction of Personal Information

We take reasonable steps to ensure personal information we hold is accurate, complete, relevant and up to date.

If you believe personal information, we hold about you is incorrect, you may request that we correct it.

We will consider correction requests and take reasonable steps to update information where appropriate.

We may ask you to verify your identity before making corrections.

We will not charge a fee for correcting personal information.

How you can complain about our information handling practices

If you have concerns about how we collect, use, disclose or manage your personal information under our AML/CTF obligations, you may contact our Privacy Officer.

Privacy Officer

Rosie Projects Pty Ltd trading as Shaddock Real Estate

We will:

  • acknowledge your complaint within a reasonable timeframe
  • review the circumstances of your complaint
  • investigate whether our privacy obligations have been met
  • provide a written response outlining the outcome of our review.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).

Contact Us

If you have any questions regarding this AML/CTF Privacy Policy, please contact:

Rosie Projects Pty Ltd trading as Shaddock Real Estate
ABN: 52 647 391 722
Privacy Officer
Email: danielle@shaddockrealestate.com.au

Date reviewed: 3 August 2026

Link to Office of The Australian Privacy Commissioner

https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us