1. Overview
Zai Australia Pty Ltd (ABN 96 637 632 645) ("Zai", "we", "us", "our") is committed to protecting the privacy of personal information provided to us, or that we otherwise collect, hold, use and disclose, whether offline or online, including through hellozai.com and our related applications ("Site"). This policy explains what personal information we collect, why, who we share it with, how we keep it secure, and how you can access, correct or complain about our handling of it.
This policy is written to comply with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles ("APPs"), and, to the extent applicable, the Identity Verification Services Act 2023 (Cth), and the European Union General Data Protection Regulation (EU) 2016/679 ("GDPR").
By providing personal information to us, you consent to us collecting, holding, using and disclosing your personal information in accordance with this Privacy Policy. If you are a third party providing personal information about somebody else, you represent and warrant that you have such person's consent to provide the personal information to us.
2. Definitions
"Personal information" Information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information or opinion is true and whether or not it is recorded in a material form. The terms Personal Data and Personally Identifiable Information are used interchangeably with Personal Information in this Policy. This includes information that may not identify you on its own but does when combined with other information we hold.
"Sensitive information" is a subset of personal information given a higher level of protection under the APPs. It includes information or an opinion about an individual's racial or ethnic origin, political opinions, religious or philosophical beliefs, membership of political, professional or trade association, membership of a trade union, sexual orientation or practices, criminal record, health information, genetic information, and biometric information that is used for the purpose of automated biometric verification or biometric identification, or a biometric template.
"Identification information" means the personal information collected as part of the identity verification process described in section 6, including the information contained on an identity document.
3. Personal information we collect
We collect the following categories of personal information:
any other personal information we reasonably need for a function or activity described in section 4, provided by you or a third party.
We collect personal information both:
We take reasonable steps to keep the personal information we hold accurate, up to date and complete. This matters more than usual for our identity verification process. Please contact us if anything we hold about you needs correcting (see section 21).
4. Purpose and use of personal information
We may collect, hold, use and disclose personal information for any of the following purposes:
Failure to provide required personal information may limit or prevent your access to our services. We will inform you at the time of collection if providing certain information is mandatory.
5. How we notify you at the point of collection
This policy sets out the matters required by APP 5.2 in relation to our collection of your personal information — including, for example, as part of our customer due diligence obligations under the AML/CTF Act — such as the law that requires or authorises a collection, the consequences if you don't provide it, and how to access, correct or complain about our handling of it. We take reasonable steps to ensure this policy, or a link to it, is presented to you at or before the time we collect your personal information. Where notifying a matter would be inconsistent with our obligations not to "tip off" a customer under the AML/CTF Act, we limit our notice accordingly.
6. Separate consent for identity verification
As part of onboarding and account administration, we may ask you to verify your identity electronically. Where we do, we check the details on your identity document against official government records through secure third-party systems, for the purpose of confirming your identity. You can find general information about how Australia's identity verification services are securely operated and managed, at idmatch.gov.au.
We only submit your details for this check once you have given express, separate consent. This consent is not bundled with our general terms of service, account-opening terms, or the general consent to this policy. Where a third party collects your identity information on our behalf, the same consent is captured in their flow before any check is submitted.
We only perform verification for individuals who have consented, we do not retain identification information for longer than is strictly necessary for the check or is required under our legal and regulatory obligations (see section 10). If you decline to consent, or an electronic check cannot be completed for your identity verification under section 6, an alternative verification method might be available upon request.
If our verification process also involves capturing and matching a facial image against the photo on your document, that is a separate collection of sensitive information, addressed in section 7.
Identification information collected for a verification request is only ever used to confirm your identity. We do not use it to build a profile of you or track your behaviour online or offline, to offer or advertise goods or services to you, to let a third party market or advertise to you, or for market research — even though we may use other personal information we independently and lawfully hold about you for those purposes as addressed in section 14.
7. Biometric information
Where our identity verification process includes capturing a facial image and matching it against the photograph on your identity document, that image, and any biometric template generated from it, is sensitive information under the Privacy Act.
How we use biometric information is the same as for identity verification. The same use restrictions and separate consent requirements that apply to identification information under section 6 apply here.
Retention and destruction of biometric information is covered in section 10.
8. Sensitive information generally
We only collect sensitive information (see the definition in section 2) with your consent, and where it is reasonably necessary for one of our functions or activities. Aside from biometric information collected as part of identity verification (section 7), we do not otherwise seek to collect sensitive information from you. Provided you consent or volunteer, your sensitive information may only be used and disclosed for purposes relating to the primary purpose for which the sensitive information was collected.
9. Government-related identifiers and tax file numbers
Where a government-related identifier — such as a driver licence number, passport number or Medicare number — forms part of the identification information we collect for identity verification (see section 6), we only use or disclose it where reasonably necessary to verify your identity or where required or authorised by law. We do not adopt a government-related identifier as our own identifier for you.
In the exceptional circumstance that we collect your tax file number, we handle it in accordance with the Privacy (Tax File Number) Rule 2015 and only use or disclose it for the purposes permitted under that Rule and taxation law.
10. How long we keep your information
We keep personal information only for as long as it is needed for the purpose we collected it for, or as required by law, and take reasonable steps to destroy or de-identify it once that purpose no longer applies. In particular:
11. Disclosure of personal information to third parties
We may disclose personal information to the following categories of third parties:
We may disclose personal information to recipients located overseas, including our service providers, for example other financial institutions, payment processors, customer support and CRM platforms, fraud detection providers, and cloud hosting providers. Before we do, we take reasonable steps to ensure the overseas recipient does not breach the APPs in relation to that information, consistent with APP 8.1, and we remain accountable under the Privacy Act where an overseas recipient handles your personal information in a way that would breach the APPs if we had done it. Where identification information is to be accessed by personnel located overseas, we give prior written notice as required and require those personnel to comply with the APPs.
The current countries and service providers to whom we disclose personal information are set out in Schedule A. We keep this list current as our provider footprint changes.
12. Notifiable data breaches
If we suspect an eligible data breach has occurred — one likely to result in serious harm to individuals whose personal information is involved — we assess it within 30 days, as required by Part IIIC of the Privacy Act. Where we confirm an eligible data breach, we notify affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
13. Security
We take reasonable steps to protect the personal information we hold from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include pseudonymisation and encryption of personal information where appropriate, TLS technology, restricted access, staff training and confidentiality obligations, and electronic security measures including firewalls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If you have a question about how we store and secure your personal information, see section 21 to contact us.
14. Direct marketing, analytics and cookies
We may use personal information — other than identification information and biometric information (see sections 6-9) — for analytics, market research and business development, and to send you promotional information about our products and services, including information about third parties we consider may be of interest to you. You can opt out of direct marketing at any time, free of charge, using the unsubscribe function in our communications, or by contacting us (see section 21).
We and our service providers use cookies and similar technologies, including Google Analytics and retargeting through platforms such as Google and Facebook, to understand how the Site is used and to tailor advertising. Cookies are small text files stored in your browser. Where you voluntarily provide personal information to us, we may link it to information collected through cookies for these purposes. This does not extend to identification information or biometric information collected under sections 6 and 7.
To find out how Google uses data when you use third party websites or applications, please see www.google.com/policies/privacy/partners/ or any other URL Google may use from time to time.
If you have a question about our use of cookies, web beacons, Google Analytics or other marketing use of your personal information, see section 21 to contact us.
15. Your rights and controlling your personal information
You can ask us for access to the personal information we hold about you (APP 12), and ask us to correct it if it's inaccurate, out of date, incomplete, irrelevant or misleading (APP 13). To do so, contact us using the details in section 21.
When you make a request:
Separately, and as discretionary services rather than obligations under Australian law, we can also:
16. Automated decision-making
From 10 December 2026, where we use a computer program to make a decision, or to do something substantially and directly related to making a decision, that could reasonably be expected to significantly affect your rights or interests, and personal information is used in the operation of that program, we will disclose in this policy the kinds of personal information used and the kinds of decisions made. This applies to decisions made on or after that date, regardless of the start date of the system.
17. Anonymity and pseudonymity
Because of our legal obligations, including under AML/CTF law, we are generally not able to provide our services to you anonymously or under a pseudonym. Where an interaction with us does not involve those obligations — for example, general browsing of our Site — you may be able to deal with us anonymously or under a pseudonym.
18. Complaints
If you have a complaint about how we have handled your personal information, please contact us using the details in section 21. We will investigate your complaint and aim to respond within 30 calendar days.
If you are not satisfied with our response, you can escalate your complaint to:
Office of the Australian Information Commissioner (OAIC)
Phone: 1300 363 992 Web: oaic.gov.au Post: GPO Box 5288, Sydney NSW 2001
OR
Australian Financial Complaints Authority (AFCA)
Phone: 1800 931 678 Web: afca.org.au Post: GPO Box 3, Melbourne VIC 3001
19. Children
We don't apply a fixed age threshold to using our Site or services. Instead, consistent with Australian privacy guidance, we consider whether a young person has the maturity and understanding to consent to our collection of their personal information — a capacity test, generally presumed from age 15. Where we are not satisfied a young person has that capacity, we seek consent from a parent or guardian instead. We are monitoring the development of the Children's Online Privacy Code and will update this policy as it takes effect.
20. Our obligations as a data processor under the GDPR
Where the GDPR applies to us and we are a processor, we have contracts containing certain prescribed terms in our contracts with controllers. Depending on circumstances, we can be a controller or processor, or controller and processor. In addition to:
21. Contact us
If you have a question, request or complaint about this policy or about how we handle your personal information, you can contact our Risk and Compliance team at:
Phone: 1300 047 883
Post: Level 6/55 Collins St, Melbourne VIC 3000
Email: risk@hellozai.com
22. Changes to this policy
We review this policy at least annually, and whenever our practices, the services we offer, or the law change materially. We publish the current version on the Site, note the version number and effective date at the top, and keep it publicly available at all times, including while it is being updated.
Schedule A — Overseas recipients
As at the date of our last review, our service providers included Google WorkSpace, Employment Hero, Freshdesk, Atlassian/Confluence and Amazon. These and other service providers may process or receive personal information in overseas locations, including: