Rosie Projects Pty Ltd trading as Shaddock Real Estate
Rosie Projects Pty Ltd trading as Shaddock Real Estate (we, us, our) is committed to protecting the privacy and security of personal information collected and handled in connection with our real estate services and our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
We collect, use, disclose, store and manage personal information only as reasonably necessary for carrying out our functions and activities, including providing real estate services and complying with our legal and regulatory obligations.
Where we are required to collect personal information to comply with our obligations under the AML/CTF Framework, we will handle that information in an open and transparent manner and in accordance with applicable privacy laws.
This AML/CTF Privacy Policy explains how we collect, use, disclose and protect personal information obtained for the purpose of complying with our AML/CTF obligations.
This policy operates alongside our existing Privacy Policy, which applies generally to personal information collected in connection with our real estate, property management and strata management services.
This policy applies specifically to personal information collected, used, disclosed and retained by us in connection with our obligations under the AML/CTF Framework.
These obligations may apply when we provide regulated real estate services, including:
Our general Privacy Policy continues to apply to other personal information handling activities associated with our business, including property management, leasing, strata management and general customer enquiries.
In this Privacy Policy:
AML/CTF Act means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
AML/CTF Framework means the AML/CTF Act, AML/CTF Rules and relevant guidance issued by the Australian Transaction Reports and Analysis Centre (AUSTRAC).
AML/CTF Rules means the rules made under the AML/CTF Act.
APPs means the Australian Privacy Principles contained in Schedule 1 of the Privacy Act 1988 (Cth).
AUSTRAC means the Australian Transaction Reports and Analysis Centre.
Personal Information has the meaning given under the Privacy Act 1988 (Cth) and includes information or an opinion about an identified individual, or an individual who is reasonably identifiable.
Sensitive Information includes information such as health information, racial or ethnic origin, political opinions, religious beliefs, membership of professional or trade associations, criminal records, biometric information and other categories of information defined as sensitive information under the Privacy Act.
KYC Information means information required to verify the identity of a customer and comply with our AML/CTF obligations, including information relating to identity, beneficial ownership, authority to act, transaction purpose and other matters required under the AML/CTF Framework.
We, us, our means Rosie Projects Pty Ltd trading as Shaddock Real Estate.
Rosie Projects Pty Ltd trading as Shaddock Real Estate is required to comply with privacy obligations relating to personal information collected, used, disclosed and retained in connection with our AML/CTF obligations.
The Privacy Act 1988 (Cth), including the Australian Privacy Principles, applies to personal information handled by us for the purposes of complying with the AML/CTF Framework.
These obligations operate alongside our existing privacy obligations relating to our real estate, property management and strata management services.
In some circumstances, we may not be able to provide services or proceed with a transaction unless we are able to collect and verify certain information required under the AML/CTF Framework.
Where lawful and practicable, individuals may choose to interact with us anonymously or using a pseudonym. However, this will generally not be possible where we are required by law to identify and verify an individual.
We collect personal information only by lawful and fair means.
We generally collect personal information directly from the individual concerned.
We may collect personal information when you:
We may also collect personal information from third parties where permitted by law, including:
Where we use a third-party identity verification provider, we will take reasonable steps to ensure personal information is handled securely and in accordance with applicable privacy obligations.
We are required under the AML/CTF Framework to collect and verify certain personal information to assist us in meeting our legal obligations.
The type of personal information we collect may include:
We may also collect information about interactions, transactions and services provided by us where required to comply with our AML/CTF obligations.
We will only collect Sensitive Information where it is necessary, permitted by law, and reasonably required for the purpose for which it is collected.
Where we are required by law to collect and verify personal information, you may not be able to proceed with certain services or transactions if you do not provide the requested information.
If we are unable to complete required customer identification or verification procedures, we may be unable to:
We collect and use personal information obtained under the AML/CTF Framework for purposes including:
We will generally only use personal information for the purpose for which it was collected, or for another related purpose that an individual would reasonably expect, or where otherwise permitted or required by law.
We may disclose personal information collected for AML/CTF purposes where reasonably necessary or permitted by law.
This may include disclosure to:
We take reasonable steps to ensure third-party service providers that handle personal information on our behalf have appropriate privacy, confidentiality and security obligations in place.
As part of our AML/CTF obligations, we may be required to provide information to AUSTRAC or other government authorities.
There may be circumstances where we are prohibited by law from informing an individual that information has been provided to AUSTRAC or another authority.
This includes circumstances relating to suspicious matter reporting or other disclosures required under the AML/CTF Framework.
Nothing in this Privacy Policy limits our obligations to comply with lawful reporting requirements.
If we enter into, or propose to enter into, a transaction involving the sale, transfer, restructure or acquisition of our business, personal information may be disclosed to prospective purchasers, advisers or other relevant parties as part of that process.
Any disclosure will be undertaken in accordance with applicable privacy obligations and appropriate confidentiality arrangements.
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure.
We hold personal information in both electronic and physical formats and maintain appropriate administrative, technical and physical security measures.
These measures include:
Where a data breach is likely to result in serious harm, we will comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner where required.
We retain personal information collected for AML/CTF purposes for the period required by law.
AML/CTF records and relevant customer identification information are generally required to be retained for seven (7) years after the end of the relevant business relationship or completion of the relevant transaction.
Where personal information is no longer required and we are not required by law to retain it, we will take reasonable steps to securely destroy or de-identify that information.
We may use third-party technology providers, cloud-based systems and software platforms that may store or process information in Australia or overseas.
Where personal information may be accessed or stored overseas, we take reasonable steps to ensure appropriate privacy, confidentiality and security protections are in place.
We require relevant service providers to maintain appropriate safeguards and only use personal information for authorised purposes.
Individuals may request access to personal information we hold about them.
Before providing access, we may take reasonable steps to verify the identity of the person making the request.
We will respond to requests for access within a reasonable timeframe.
We may refuse access where permitted under the Privacy Act 1988 (Cth), including where providing access would:
If we refuse access, we will provide written reasons unless prohibited by law.
We take reasonable steps to ensure personal information we hold is accurate, complete, relevant and up to date.
If you believe personal information, we hold about you is incorrect, you may request that we correct it.
We will consider correction requests and take reasonable steps to update information where appropriate.
We may ask you to verify your identity before making corrections.
We will not charge a fee for correcting personal information.
If you have concerns about how we collect, use, disclose or manage your personal information under our AML/CTF obligations, you may contact our Privacy Officer.
Rosie Projects Pty Ltd trading as Shaddock Real Estate
We will:
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC).
If you have any questions regarding this AML/CTF Privacy Policy, please contact:
Rosie Projects Pty Ltd trading as Shaddock Real Estate
ABN: 52 647 391 722
Privacy Officer
Email: danielle@shaddockrealestate.com.au
Date reviewed: 3 August 2026
https://www.oaic.gov.au/privacy/privacy-complaints/lodge-a-privacy-complaint-with-us