Privacy Policy
Last updated August 2026
BA ICON is a customer relationship management and workflow platform for buyer’s agents, operated by Rose Technology Group Pty. Ltd. As Trustee For Rose Technology Unit. This Privacy Policy explains how personal information is collected, used, stored and disclosed when people use the BA ICON website, platform and related services, including identity verification and anti-money laundering services delivered through our third-party provider, Personr.
By using BA ICON, customers agree to the handling of personal information in accordance with this Privacy Policy and applicable Australian privacy laws, including the Privacy Act 1988 (Cth) and, where relevant, the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
Information collected
BA ICON may collect personal information such as names, email addresses, phone numbers, business details, login details, property preferences, transaction notes, uploaded documents, and other information entered into the platform by customers and authorised users.
Where customers use BA ICON’s AML/CTF compliance features, additional personal information may be collected for the purpose of identity verification and customer due diligence, including dates of birth, residential addresses, government-issued identity documents (such as passports and driver licences), document numbers, biometric information (such as facial images used for identity matching), and the results of verification, sanctions, politically exposed person (PEP) and adverse media checks. This information is collected directly from individuals or via our identity verification partner, Personr.
BA ICON may also collect technical and usage information, including browser type, IP address, device information, access times and activity within the platform, to help operate, maintain and secure the service.
How information is used
Personal information is used to provide and support the BA ICON platform, manage accounts and subscriptions, deliver customer support, facilitate platform communications, improve system performance and functionality, and comply with legal and regulatory obligations.
Information collected through BA ICON’s AML/CTF features is used to enable customers to conduct identity verification, customer due diligence (including enhanced due diligence where required), ongoing customer monitoring, and sanctions, PEP and adverse media screening, in order to meet their obligations under the AML/CTF Act and AUSTRAC requirements.
Personal information is only used as reasonably necessary to fulfil these purposes or as otherwise required by law.
Identity verification and AML/CTF checks (Personr)
BA ICON integrates with Personr, a third-party identity verification and AML/CTF compliance provider, to perform all identity verification, customer due diligence, sanctions and PEP screening, and ongoing monitoring checks conducted through the platform.
When a verification or screening check is initiated, relevant personal information (including identity documents and biometric data where applicable) is transmitted securely to Personr, which processes the information to verify identity and conduct the required checks against official and third-party data sources, including government document verification services and global sanctions and watchlists.
Personr handles personal information in accordance with its own privacy policy, which is available on Personr’s website. By submitting to an identity verification or AML/CTF check through BA ICON, individuals acknowledge that their information will be disclosed to and processed by Personr for these purposes.
Verification results and associated records are retained within BA ICON and by Personr as required to meet record-keeping obligations under the AML/CTF Act, including the requirement to retain customer due diligence records for at least seven years.
Disclosure of information
Personal information may be disclosed to employees, contractors, service providers and technology partners who require access to assist in delivering the services, provided they are subject to appropriate confidentiality and privacy obligations. This includes disclosure to Personr for the purpose of performing identity verification and AML/CTF checks as described above.
Information may also be disclosed where required by law, regulation, legal process or regulatory authority, including to the Australian Transaction Reports and Analysis Centre (AUSTRAC) or other government agencies where required under the AML/CTF Act, or where a customer has authorised a third-party integration or connected service.
Customers should be aware that the AML/CTF Act contains tipping-off provisions that may restrict BA ICON and its customers from disclosing certain information relating to suspicious matter reporting.
Data security
BA ICON takes reasonable technical and organisational steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
These measures include access controls, internal security processes, ongoing system maintenance and security practices aligned with SOC 2 style requirements. Information transmitted to Personr for verification purposes is transferred using secure, encrypted channels.
Data retention and access
Personal information is retained only for as long as reasonably necessary to provide the services, comply with legal obligations, resolve disputes and enforce agreements.
Records relating to identity verification and customer due diligence conducted through the platform are subject to mandatory retention periods under the AML/CTF Act and must be retained for at least seven years after the relevant record was made or the customer relationship ended, whichever is later. These records cannot be deleted during the mandatory retention period, even on request, except where permitted by law.
Following termination, customers may be provided with a limited period to export their data before deletion or secure archival, subject to legal and operational requirements, including AML/CTF record-keeping obligations.
Customer responsibilities
Customers are responsible for ensuring they have the lawful right to collect, enter, store and use personal information in BA ICON, including obtaining any required consents from their own clients, contacts and third parties. Where customers initiate identity verification or AML/CTF checks, they are responsible for ensuring the relevant individuals are appropriately notified that their information will be processed by BA ICON and Personr for these purposes.
Customers must also ensure that their use of BA ICON complies with applicable privacy, spam, real estate and AML/CTF laws, including their own obligations as reporting entities under the AML/CTF Act where applicable.
Access, correction and complaints
A person may request access to or correction of personal information held by BA ICON by contacting Rose Technology Group Pty. Ltd. As Trustee For Rose Technology Unit using the contact details published on the website. Requests relating to information held by Personr may be directed to Personr in accordance with its privacy policy, and BA ICON will provide reasonable assistance where appropriate.
Access and correction rights may be limited where records are subject to mandatory retention or non-disclosure requirements under the AML/CTF Act.
Privacy complaints will be handled in accordance with applicable law and, where necessary, may be referred to the Office of the Australian Information Commissioner.
Changes to this policy
This Privacy Policy may be updated from time to time to reflect changes in legal requirements, technology, services or business practices. The latest version published on the website will apply from the date of publication.