Terms & Policies
Data Protection Policy
1. Our Commitment to Data Protection
1.1 FUNDiMO is committed to protecting the personal data of every user on our platform. Data protection is fundamental to our operations and underpins the trust our customers and business partners place in us.
1.2 This Data Protection Policy outlines the measures we take to safeguard your personal data, your rights as a data subject, and how we comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1.3 This policy should be read in conjunction with our Privacy Policy, which provides further detail on the types of information we collect and how we use it.
2. Data Controller
2.1 FUNDiMO Pty Ltd is the data controller responsible for your personal data processed through the FUNDiMO platform.
2.2 Our Privacy Officer oversees data protection compliance across the organisation.
2.3 For all data protection enquiries, contact us at:
Privacy Officer: privacy@fundimo.com.au
3. Personal Data We Process
3.1 Account Information
3.1.1 Name, email address, phone number, authentication credentials (passkeys), and identity documents provided for verification.
3.2 Transaction Data
3.2.1 Payment amounts, timestamps, merchant details, and transaction reference identifiers.
3.3 Device and Usage Information
3.3.1 Browser type, device identifiers, IP addresses, pages visited, and feature usage patterns.
3.4 Business Account Data
3.4.1 Business name, ABN, trading address, bank account details for settlement, and authorised representative information.
3.5 For a comprehensive description of the personal data we collect, please refer to our Privacy Policy.
4. Legal Basis for Processing
4.1 We process your personal data on the following lawful bases:
4.2 Consent
4.2.1 Where you have given explicit consent for specific processing activities, such as marketing communications and optional analytics.
4.2.2 You may withdraw consent at any time by contacting us or updating your account preferences.
4.3 Contract Performance
4.3.1 Processing necessary to provide our payment and marketplace services as outlined in our Terms of Use.
4.3.2 This includes account management, transaction processing, and customer support.
4.4 Legal Obligation
4.4.1 Processing required to comply with Australian law, including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act), tax reporting obligations, and regulatory requirements.
4.5 Legitimate Interests
4.5.1 Processing necessary for our legitimate business interests, including fraud detection, platform security, service improvement, and analytics.
4.5.2 We conduct balancing tests to ensure our legitimate interests do not override your rights and freedoms.
5. Data Security Measures
5.1 We implement robust technical and organisational measures to protect your personal data:
5.2 Encryption
5.2.1 All data in transit is encrypted using current industry-standard transport security (TLS).
5.2.2 All data at rest is encrypted using AES-256.
5.2.3 Sensitive personal data is protected with envelope encryption, where individual encryption keys are maintained per customer.
5.2.4 Identity documents are stored in secure cloud storage with server-side encryption at rest and strict access controls.
5.3 Access Controls
5.3.1 Role-based access controls (RBAC) restrict data access to authorised personnel only.
5.3.2 Multi-factor authentication is required for all administrative access.
5.3.3 Comprehensive audit logging tracks all access to personal data.
5.4 Authentication
5.4.1 Passwordless authentication via passkeys (WebAuthn) eliminates risks associated with password-based attacks.
5.4.2 PayTo authentication is handled through secure banking infrastructure.
5.5 Pseudonymisation
5.5.1 FUN IDs provide pseudonymisation by default. Businesses interact with your FUN ID, never your personal details.
5.5.2 Blind indexes enable secure lookups without exposing plaintext personal data.
5.6 Auditing and Testing
5.6.1 Regular security audits and penetration testing are conducted to identify and remediate vulnerabilities.
5.6.2 Immutable audit trails maintain a complete record of all data processing activities.
6. Data Breach Notification
6.1 In the event of a data breach that is likely to result in serious harm, we will:
6.1.1 Where we are required to do so under the Notifiable Data Breaches (NDB) scheme, carry out a reasonable and expeditious assessment within 30 days of suspecting an eligible data breach and, where the breach is established, notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
6.1.2 Notify affected individuals as soon as practicable with details of the breach, the types of data involved, and recommended steps to mitigate potential harm.
6.2 We maintain an incident response plan that is regularly tested and updated to ensure timely and effective breach management.
6.3 Our breach assessment process evaluates the severity, scope, and likely impact of any suspected breach to determine notification obligations.
7. Cross-Border Data Transfers
7.1 Your personal data is primarily stored and processed in Australia.
7.2 Where we transfer personal data to overseas recipients, we ensure:
7.2.1 Contractual arrangements are in place that require the recipient to handle personal data in accordance with the APPs.
7.2.2 We take reasonable steps to ensure overseas recipients do not breach the APPs in relation to your data.
7.3 We comply with APP 8 (cross-border disclosure of personal information) for all international data transfers.
8. Data Subject Rights
8.1 Under Australian privacy law, you have the following rights in relation to your personal data:
8.2 Right of Access
8.2.1 You may request access to the personal data we hold about you. We will respond within 30 days.
8.3 Right of Rectification
8.3.1 You may request correction of inaccurate or incomplete personal data.
8.4 Right of Erasure
8.4.1 You may request deletion of your personal data, subject to legal retention requirements (such as tax records retained for 7 years).
8.4.2 Where erasure is not possible due to legal obligations, we will restrict processing to the minimum required.
8.5 Right of Restriction
8.5.1 You may request that we restrict the processing of your personal data in certain circumstances, such as while we verify its accuracy.
8.6 Right of Data Portability
8.6.1 You may request a copy of your personal data in a structured, commonly used, and machine-readable format.
8.7 Right to Object
8.7.1 You may object to processing based on legitimate interests. We will cease processing unless we demonstrate compelling legitimate grounds.
8.7.2 You may object to direct marketing at any time, and we will cease such processing without exception.
8.8 To exercise any of these rights, contact us at privacy@fundimo.com.au. We will respond within 30 days.
9. Automated Decision-Making
9.1 We use automated processing in the following areas:
9.2 Fraud Detection
9.2.1 Automated systems monitor transactions for patterns indicative of fraudulent activity.
9.2.2 Flagged transactions are reviewed by authorised personnel before any action is taken against an account.
9.3 Compliance Screening
9.3.1 Automated screening against sanctions lists (including DFAT consolidated list) and Politically Exposed Persons (PEP) reference data.
9.3.2 Matches are subject to human review before any compliance action is taken.
9.4 No decisions with significant legal or similarly significant effects are made solely by automated means without human oversight.
9.5 You have the right to request human review of any automated decision that affects you.
10. Data Protection Impact Assessments
10.1 We conduct Data Protection Impact Assessments (DPIAs) for processing activities that are likely to result in a high risk to individuals, including:
10.1.1 Introduction of new technologies or processing methods.
10.1.2 Large-scale processing of sensitive personal data.
10.1.3 Systematic monitoring of publicly accessible areas.
10.1.4 Automated decision-making with legal or significant effects.
10.2 DPIAs are reviewed and approved by our Privacy Officer before processing commences.
10.3 Where a DPIA identifies high residual risk, we consult with the OAIC before proceeding.
11. Children's Data
11.1 FUNDiMO is not intended for use by individuals under the age of 18.
11.2 We do not knowingly collect or process personal data from children.
11.3 If we become aware that we have collected personal data from a child, we will take steps to delete that data as soon as practicable.
11.4 If you believe a child has provided us with personal data, please contact us immediately at privacy@fundimo.com.au.
12. Updates and Contact
12.1 We may update this Data Protection Policy from time to time to reflect changes in our practices, technology, or legal requirements.
12.2 We will notify you of material changes by email or through the FUNDiMO platform.
12.3 The "Last updated" date at the top of this page indicates when the policy was last revised.
12.4 For questions about this policy or our data protection practices, contact us at:
Privacy Officer: privacy@fundimo.com.au
General Support: support@fundimo.com.au
13. Australian Privacy Principles
13.1 FUNDiMO's data protection practices comply with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth).
13.2 For more information about privacy and data protection in Australia, visit the Office of the Australian Information Commissioner at www.oaic.gov.au.
13.3 If you are not satisfied with our response to a data protection concern, you may lodge a complaint with the OAIC.