Last updated: 21 August 2026
⚡ Quick Summary – Privacy at a Glance
- Your data is never shared with third parties.
- Reports are deleted immediately after you download them.
- We keep de-identified intelligence only – never your name or findings.
- If we find illegal activity, we are legally required to report it – even if you are our client.
- All data is hosted on air-gapped Australian servers – never offshore.
1. Our Commitment to Privacy
Sentinel Due Diligence is committed to protecting your privacy. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains how we collect, use, disclose, and protect your personal information when you engage our services, visit our website, or interact with us.
🔐 Personal sign‑off: Every report produced by Sentinel Due Diligence is personally reviewed, verified, and signed off by a licensed financial investigator. You receive a decision‑ready report you can trust.
2. Information We Collect
We collect personal information that is necessary to provide our due diligence and investigation services. This may include:
- Contact & Identity Information: Name, email address, phone number, company name, ABN, and pre-agreed security codes/trigger words used for identity verification.
- Enquiry details: Information you provide when contacting us about a potential investigation.
- Investigation data: Information gathered during due diligence, including ASIC records, ATO data, liquidator reports, and publicly available information.
- Website usage: Anonymous data collected via cookies for analytical purposes (see Section 13).
ABN Collection Note: If you are a sole trader, your ABN is treated as personal information under this policy and is handled with the same level of protection as any other personal data.
3. How We Collect Information
We collect personal information in the following ways:
- Directly from you: When you submit a contact form, email us, or engage our services (including the exchange of security codes for identity verification).
- From public registers: ASIC, ABN Lookup, PPSR, court records, and other publicly available sources.
- From third parties: Commercial intelligence providers, liquidators, and credit bureaus (where permitted by law).
4. How We Use Your Information
We use your personal information for the following purposes:
- To provide investigation services: Conducting due diligence, preparing reports, and delivering findings.
- To verify identity & communicate securely: Using pre-collected mobile numbers and security codes to ensure your report reaches only you.
- To comply with legal obligations: Reporting illegal activity where required by law.
- To improve our proprietary intelligence: Adding de-identified phoenix and sham entity patterns to our private database to protect future clients.
🤖 AI-Assisted Pre-Search: We utilise AI-assisted tools to conduct preliminary public-record searches based on the ABN or business name you provide. These initial risk flags are always reviewed, verified, and signed off by a licensed human investigator before any report is finalised. You never receive an automated decision – only a human‑verified conclusion.
5. Confidentiality & Non‑Disclosure
We treat all client information as strictly confidential.
- Your interest, findings, and any information you share with us are never shared with the investigated party.
- Reports are provided exclusively to you as the client.
- We do not take on two firms that are investigating each other – your loyalty is our priority.
🔒 Confidentiality commitment: Reports or concerns are never shared with third parties. Your information is used solely for the purpose of your investigation.
6. Legal Reporting Obligations – Our Non-Negotiable Ethical Duty
By law, we are required to report certain illegal activities.
If during an investigation we uncover evidence of illegal phoenix activity, tax evasion, fraud, or other criminal conduct, we are legally obligated to report this to the relevant authorities – including the Australian Taxation Office (ATO), ASIC, or the Australian Federal Police (AFP).
This obligation applies even if the illegal activity is uncovered during work for a client. Our duty to the law overrides any confidentiality agreement.
🚨 Mandatory Reporting – No Exceptions
If we find connections to illegal phoenix activity, tax evasion, or other criminal conduct, we are legally required to report it – even if you are our client. We will always inform you before making a referral, where legally permitted.
Clarification: We do not report mere suspicions or unverified allegations – only evidence that meets the threshold of reasonable belief that a criminal offence or serious regulatory breach has occurred. This protects you from unfounded speculation while ensuring we meet our legal obligations.
7. Your Rights
You have the following rights regarding your personal information:
- Right to access: You can request a copy of the personal information we hold about you.
- Right to correction: You can ask us to correct inaccurate or incomplete information.
- Right to withdraw consent: You can withdraw your consent for us to use your information (subject to legal obligations that may require us to retain certain records).
- Right to complain: You can lodge a complaint with us or directly with the Office of the Australian Information Commissioner (OAIC).
To exercise any of these rights, please contact us using the details in Section 16 below.
8. Data Security
We take data security seriously. Your information is stored in a secure, encrypted database with access restricted to authorised personnel only.
- Encryption: All data is stored using industry‑standard encryption.
- Access control: Only the licensed investigator has access to client data.
- Backups: Regular backups are performed to prevent data loss.
- Secure transmission: All communications are transmitted via HTTPS/SSL.
- Air‑gapped AI system: Our AI and proprietary database systems are hosted on an air‑gapped, locally hosted network in Australia with no inbound internet access. They are only accessible via localhost and the local subnet, ensuring your data never leaves our secure environment.
- Segmented architecture: Report numbers and client names are stored in separate, isolated databases. A breach of one system reveals nothing useful without access to the others.
📱 Ephemeral Delivery Protocol:
Your report is delivered via a secure, time-bound portal. The file is only accessible during the download session – the timer does not start on login, but only when you click to download. This gives you time to review the portal without pressure, while ensuring the file is not left exposed.
Access requires a pre‑registered mobile number collected before engagement. You have three verification attempts – after which the link locks permanently. If digital access is lost, we verify your identity using a pre‑agreed Security Code/Trigger Word.
Once the report is downloaded, it is immediately and permanently deleted from our servers. We retain no copy. It is your responsibility to store and protect your report – this is by design, to ensure no unauthorised party can ever access it after delivery.
9. Data Retention & Deletion (Our "Clean Slate" Policy)
We believe in storing only what we are legally required to keep. Your sensitive investigative data does not linger on our systems. We operate a strict one‑time fee model – no retainers, no long‑term data hoarding.
-
Case‑Specific Investigative Files (Wiped on Delivery):
Once we deliver your report and you confirm receipt (via download or physical dispatch), all case‑specific investigative data – including your detailed findings, personal information gathered for the investigation, and internal working notes – are permanently and securely deleted from our active systems. We do not retain the substance of your investigation after the job is complete.
-
Proprietary Intelligence Database (Retained Permanently):
To protect future clients from repeat offenders, we permanently retain de‑identified intelligence – including ABNs, business names, and verified patterns of illegal phoenix or sham activity. This database does not contain your personal name, your specific findings, or any information that links the intelligence back to your engagement.
-
Financial Invoices (Retained 7.5 Years, Then Wiped):
We keep a financial invoice record only – for tax and audit compliance under the Corporations Act 2001 (Cth) and ATO requirements. We retain these invoices for the statutory minimum of 7 years, with an additional 6‑month buffer (7.5 years total) before secure deletion. No investigative data is attached to this invoice – only the transaction amount, date, and invoice number.
10. Overseas Data Disclosure
We do not transfer your personal information overseas. Our systems – including our AI, proprietary database, and all client data – are hosted exclusively on air‑gapped, locally hosted servers in Australia. These systems have no inbound internet access and are only accessible via localhost and the local subnet.
(For completeness: If we ever use cloud-based or third-party tools that may process data offshore, we will update this policy and obtain your explicit consent before any transfer occurs.)
11. Disclosure of Information
We do not sell, rent, or trade your personal information. We may disclose your information in the following limited circumstances:
- To comply with the law: Where we are legally required to disclose information to a government agency or law enforcement.
- To protect rights and safety: Where necessary to protect the rights, property, or safety of Sentinel Due Diligence, our clients, or others.
- With your consent: Where you have explicitly consented to the disclosure.
12. Access & Correction
You have the right to access and correct the personal information we hold about you. If you wish to request access, update your information, or withdraw consent, please contact us using the details in Section 16 below.
We will respond to your request within a reasonable timeframe and in accordance with the Privacy Act 1988 (Cth).
13. Cookies
Our website uses minimal cookies to enhance functionality and gather anonymous analytics. We do not use tracking cookies for advertising purposes.
- Essential cookies: Required for basic site functionality (e.g., session management).
- Analytics cookies: We use anonymised data to understand how visitors interact with our site. This data does not identify you personally.
You can manage your cookie preferences in your browser settings. Disabling cookies may affect some website features.
14. Complaints
If you believe we have breached your privacy rights, you may lodge a complaint with us. We will investigate and respond to your complaint within 30 days.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at:
https://www.oaic.gov.au
15. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or legal obligations. The latest version will always be available on our website.
16. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact our dedicated Privacy Officer:
Privacy Officer
Sentinel Due Diligence
Email: privacy@sentinelduediligence.com.au
Website: sentinelduediligence.com.au
📱 For identity verification, we use a pre‑agreed Security Code / Trigger Word – established before engagement.
Disclaimer: This Privacy Policy does not constitute legal advice. For legal advice, you should consult a qualified Australian legal practitioner.