Privacy Policy
Effective Date: 17 July 2026
1. Introduction
OceanXZ AU Pty Ltd (ACN 694 833 924) (“OceanXZ AU”) is committed to maintaining the highest levels of professional integrity and ethical conduct. This Privacy Policy outlines how we manage your Personal Information in an open and transparent manner, in compliance with the Privacy Act 1988 and the Australian Privacy Principles.
2. When Does This Policy Apply?
This Policy applies to all representatives, employees, and operations of OceanXZ AU to ensure your Personal Information is protected at all times.
3. Information We Collect
To provide you with our services, we collect Personal Information, which may include:
- Identity Details: Name, address, date of birth, and gender.
- Contact Details: Telephone, email, and facsimile.
- Financial Data: Bank account details, transactional history, and trading records.
- Digital asset wallet addresses and associated transaction details.
- Originator and beneficiary information for digital currency transfers (to comply with the ‘Travel Rule’).
- Information required for Customer Due Diligence (CDD) and Know Your Customer (KYC) processes, including source of wealth and source of funds declarations.
- Records of communications and activities to monitor for Prohibited Activities or Financial Crimes.
- Other Information: Any other data necessary to provide our services.
Note: Sensitive Information (e.g., biometric data) is only collected with your explicit consent or where required by law.
4. How We Collect Information
We collect information lawfully and fairly, primarily directly from you when you:
- Complete our Application Form.
- Communicate with our representatives via telephone or email.
- Interact with our website, payment platform, or social media accounts.
5. Purpose of Collection
We hold your information to:
- Determine your eligibility for our services.
- Manage and administer our products.
- Process payments and protect against fraud/crime.
- Respond to your complaints or queries.
- Comply with legal and regulatory requirements.
- AML/CTF Compliance: Complying with obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and associated Rules, including CDD, KYC checks, and ongoing transaction monitoring.
- The Travel Rule:Complying with domestic and international ‘Travel Rule’ requirements for digital asset transfers — obtaining, holding, and transmitting required originator and beneficiary information to counterparty institutions.
- Preventing Prohibited Activities: Monitoring, investigating, and preventing Prohibited Activities, Financial Crimes, money laundering, terrorist financing, and other unlawful activities as outlined in our Terms of Service.
6. Disclosure of Information
We may share your information with trusted third parties, including:
- Service providers (e.g., technology and business systems suppliers).
- Financial institutions and payment organisations.
- Professional advisers (legal, financial, or auditing).
- Regulatory bodies and law enforcement as required by law.
- Counterparty Institutions (Travel Rule): domestic and international VASPs, digital currency exchanges, or financial institutions counterparty to a transaction.
- Regulatory Authorities: bodies, government agencies, and law enforcement (such as AUSTRAC) in any jurisdiction for AML/CTF reporting, transaction monitoring, and legal compliance.
7. Cross-Border Disclosure
We may disclose information to recipients in countries including, but not limited to, the United Kingdom, United Arab Emirates, Germany, and the United States of America. We ensure these recipients comply with the Australian Privacy Principles.
8. Direct Marketing
We do not use your information for direct marketing without your consent. You may opt-out of receiving marketing communications at any time by following the instructions provided in our communications.
9. Security and Integrity
We implement robust security measures to protect your data from misuse or unauthorized access, storing it in secure data centres both in Australia and abroad.
10. Your Rights: Access and Correction
You have the right to access your Personal Information and request corrections if it is inaccurate or out of date. We will process these requests within a reasonable timeframe, free of charge.
11. Complaints and Data Breaches
If you have concerns about your privacy, please contact dpo@oceanxz.com. If not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992. In the event of a data breach, we will notify you and the OAIC if there is a risk of serious harm.