Overview
This disclosure explains how Canvas Digital Pty Ltd (ACN 648 707 706; ABN 77 648 707 706) (Canvas Digital, we, us, our) collects, holds, uses and discloses your personal information when you use our website and services.
Canvas Digital is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act) and is registered with AUSTRAC as a virtual asset service provider. We are subject to the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs), including in connection with our AML/CTF obligations.
This disclosure is prepared in accordance with APP 1 and has regard to the OAIC's Privacy guidance for reporting entities under the AML/CTF Act (February 2026) and the Australian Privacy Principles guidelines.
1. Our Services
Canvas Digital provides digital asset exchange, payment, foreign exchange, stablecoin, wallet and merchant services. Our services include:
- Stablecoin digital exchange
- On/off ramps, including fiat to digital currency and digital currency to fiat
- Domestic and international payments
- Foreign exchange, including spot and forward
- Fiat and stablecoin wallets
- Merchant payment acceptance
- Debit cards
- Business credit facilities
2. What Personal Information We Collect
The kinds of personal information we collect and hold depend on how you interact with us.
When you create an account or use our services
- Your name, date of birth, residential address, email address, phone number and other contact details
- Identity verification documents, such as passport, driver's licence or proof of age card
- Financial information, including bank account details, transaction history and source of funds information
- Digital asset wallet addresses
- Digital asset transfer information, including originator and beneficiary details, counterparty institution details, transaction hashes and Travel Rule information required for digital asset deposits and withdrawals
- Self-hosted wallet information, including whether you control a wallet address and information needed to validate that control
- Tax file numbers or tax residency information, where required by law
- Employment and occupation details
- Beneficial ownership information for corporate and trust accounts
When you visit our website
- IP address, browser type and version, device information and operating system
- Pages visited, time spent on pages and navigation patterns
- Referral source and search terms
- Information collected via cookies and similar tracking technologies
When you send a website enquiry
When you submit the website contact form, we collect the name, work email address, company, enquiry type, message and source that you provide. We use this information to respond to your enquiry and route it to the appropriate Canvas Digital team.
Cloudflare processes the form request, checks the anti-bot challenge, stores the enquiry and sends the notification email. We do not store your IP address, geolocation, anti-bot token or raw provider errors with the enquiry record.
Information we receive from third parties
- Identity verification results from verification service providers
- Sanctions, politically exposed persons (PEP) and adverse media screening data
- Blockchain analytics data
- Information from banking and payment partners relevant to your transactions
- Information from counterparty virtual asset service providers, Travel Rule compliance providers, transaction monitoring providers and other institutions involved in processing or validating digital asset transfers
- Credit reporting information, where applicable
Sensitive information
We may collect sensitive information where required to comply with the AML/CTF Act, including biometric information, such as facial recognition data for identity verification, and membership of a professional or trade association.
We only collect sensitive information with your consent or where required or authorised by law, including under the AML/CTF Act and AML/CTF Rules.
3. How We Collect Personal Information
We collect personal information directly from you, from third parties, and through automated means.
Where practicable, we collect personal information directly from you. We may collect personal information from third parties where it is unreasonable or impracticable to collect it from you directly, or where the collection is required or authorised by law, including under the AML/CTF Act.
- Directly from you when you create an account, complete identity verification, submit a transaction, contact us or use our website
- From third parties including identity verification providers, banking partners, blockchain analytics providers, sanctions screening services, regulators and publicly available sources
- Through automated means including cookies, web analytics tools and transaction monitoring systems
4. Why We Collect, Hold, Use and Disclose Personal Information
We collect, hold, use and disclose your personal information for the purposes below. We limit our collection of personal information to what is reasonably necessary for these purposes, in accordance with APP 3.
To provide our services
- Opening, operating and managing your account
- Processing your transactions and payments
- Providing customer support
To comply with our legal and regulatory obligations
- Verifying your identity as required by the AML/CTF Act, including customer due diligence
- Ongoing customer due diligence and monitoring
- Reporting to AUSTRAC, including suspicious matter reports, threshold transaction reports and international funds transfer instructions
- Complying with Travel Rule obligations for digital asset transfers, including collecting, verifying and sharing required originator, beneficiary, wallet address, counterparty institution and transaction information
- Complying with sanctions obligations
- Responding to requests from law enforcement and regulatory authorities, including AUSTRAC, ASIC, the ATO and the OAIC
- Record-keeping as required under the AML/CTF Act and other applicable laws
To manage risk and protect our business
- Fraud prevention and detection
- Transaction monitoring for suspicious activity
- Validating digital asset transfers, including whether a transfer involves another virtual asset service provider, a custodial wallet or a self-hosted wallet
- Risk assessment and management
- Sanctions and PEP screening
To improve our services
- Analysing how our website and services are used
- Developing and improving our products and services
- Internal training and quality assurance
To communicate with you
- Providing account notifications and service updates
- Sending marketing communications with your consent. You can opt out at any time by contacting us or using the unsubscribe link in our communications.
5. What Happens If You Do Not Provide Personal Information
Some personal information is required by law. Under the AML/CTF Act, we must verify your identity before providing designated services.
If you do not provide the required information, we may be unable to open or maintain your account, process your transactions, or provide you with our products and services.
Provision of personal information for marketing purposes is voluntary and will not affect your access to our services.
6. Who We Disclose Personal Information To
We may disclose your personal information to the following categories of recipients. We do not sell your personal information and we do not disclose your personal information for direct marketing by third parties without your consent.
- Canvas group companies: Canvas Capital Pty Ltd, Canvas Connect Pty Ltd, Canvas Management Pty Ltd and Canvas IP Pty Ltd, for business operations and compliance purposes
- Service providers including identity verification providers, payment processors, cloud hosting providers, IT support, legal and professional advisers, and auditors
- Regulatory authorities including AUSTRAC, ASIC, the ATO and the OAIC, as required or authorised by law
- Financial institutions, banks and payment networks involved in processing your transactions, including Banking Circle, NAB and Fiserv
- Counterparty virtual asset service providers, Travel Rule compliance providers, transaction monitoring providers and other institutions involved in processing, validating or screening digital asset transfers
- Law enforcement agencies where required or authorised by law or in connection with a suspicious matter report
- External dispute resolution bodies where relevant to a complaint
7. Overseas Disclosure of Personal Information
Some of our service providers and partners operate global infrastructure or are located overseas. Your personal information may be processed or disclosed outside Australia, including in Luxembourg, the United States, the United Kingdom, Singapore and Denmark. We do not promise Australia-only processing or storage.
Before disclosing personal information to an overseas recipient, we take reasonable steps to ensure that the recipient handles the information in accordance with the APPs, as required by APP 8 and section 16C of the Privacy Act.
Where the disclosure is required or authorised by law, including under the AML/CTF Act, the exceptions under APP 8.2 may apply.
- Contractual obligations requiring compliance with privacy standards comparable to the APPs
- Assessing the privacy laws and practices of the recipient's country
- Ongoing monitoring of the recipient's compliance
8. Automated Decision-Making
We use automated systems to assist with certain decisions. These automated processes use your identity, transaction, screening and verification information.
We maintain human oversight of automated decision-making processes that may significantly affect you. If you have concerns about an automated decision that has affected you, you may contact our Privacy Officer.
- Sanctions and PEP screening: automated checks against sanctions lists and PEP databases at onboarding and on an ongoing basis. Matches are flagged for human review before any action is taken, except where a confirmed sanctions match requires immediate blocking under applicable law.
- Transaction monitoring: automated rules-based systems monitor transactions for indicators of money laundering, terrorism financing or fraud. Transactions flagged by the system are reviewed by our compliance team before a suspicious matter report is made.
- Digital asset transfer validation: automated and rules-based systems may assist us to identify counterparty institutions, screen wallet addresses, assess whether a transfer involves a self-hosted wallet and determine whether additional information is required before a transfer can be processed or credited.
- Customer risk assessment: automated scoring based on customer type, jurisdiction, products used and transaction patterns. Risk ratings inform the level of due diligence applied to your account and are subject to periodic human review.
- Identity verification: automated document verification and biometric matching to confirm your identity at onboarding. Where automated verification is unable to confirm your identity, the matter is escalated for manual review.
9. Data Quality
We take reasonable steps to ensure the personal information we collect, use and disclose is accurate, up-to-date, complete and relevant, as required by APP 10.
- Verifying information against authoritative sources during onboarding
- Periodic reviews of customer information as part of ongoing due diligence under the AML/CTF Act
- Providing you with the ability to update your information through your account or by contacting us
10. Data Security and Retention
Security
We take reasonable steps to protect your personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, as required by APP 11.
- Encryption of data in transit and at rest
- Access controls and authentication requirements
- Regular security assessments and penetration testing
- Staff training on information security and privacy obligations
- Incident detection and response capabilities
Retention
We retain your personal information for as long as it is needed for the purposes for which it was collected, or as required by law.
When personal information is no longer needed for any purpose for which it may be used or disclosed under the APPs, including AML/CTF purposes, we take reasonable steps to destroy or de-identify it, unless we are required by law to retain it.
- AML/CTF records: 7 years after the end of the relevant relationship or transaction, as required by the AML/CTF Act
- Travel Rule and digital asset transfer records: as required under the AML/CTF Act, including originator and beneficiary details, wallet addresses, counterparty institution details, transaction hashes, screening outcomes and the basis for transfer validation decisions
- Transaction records: as required by applicable financial services and taxation laws
- Account information: for the duration of our relationship with you and for the period required by law after your account is closed
- Website contact enquiries: live records are retained for 90 days. After deletion, Cloudflare's D1 recovery history may retain a recoverable copy for up to a further 30 days before it expires automatically.
Notifiable Data Breaches
In the event of a data breach that is likely to result in serious harm to you, we will notify you and the OAIC in accordance with Part IIIC of the Privacy Act.
12. Your Rights
Under the Privacy Act, you have the right to access the personal information we hold about you, correct any personal information that is inaccurate, out of date, incomplete, irrelevant or misleading, opt out of receiving marketing communications at any time, and complain if you believe we have breached the APPs.
We will respond to access requests within 30 days. In some circumstances, we may refuse access, for example where providing access would be unlawful, would prejudice enforcement-related activities, or where the request is frivolous or vexatious. If we refuse access, we will give you written reasons.
If we correct information that we have previously disclosed to a third party, we will take reasonable steps to notify the third party of the correction.
To make an access or correction request, or to exercise any of your privacy rights, contact our Privacy Officer.
- Email: privacy@canvas.co
- Mail: Privacy Officer, Canvas Digital Pty Ltd, C/- Presidio Partners Pty Limited, Level 2, 222 Pitt Street, Sydney NSW 2000
13. Complaints
If you believe we have breached the APPs or mishandled your personal information, you may make a complaint to us.
We will acknowledge your complaint within 5 business days and aim to resolve it within 30 days. We will investigate your complaint and provide you with a written response, including the outcome and the reasons for our decision.
If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner.
- Privacy complaint email: privacy@canvas.co
- Privacy complaint mail: Privacy Officer, Canvas Digital Pty Ltd, C/- Presidio Partners Pty Limited, Level 2, 222 Pitt Street, Sydney NSW 2000
- OAIC website: www.oaic.gov.au
- OAIC phone: 1300 363 992
- OAIC email: enquiries@oaic.gov.au
- OAIC mail: GPO Box 5218, Sydney NSW 2001
14. Updates to This Disclosure
We may update this disclosure from time to time to reflect changes to our personal information handling practices, our services, or changes in applicable law. The current version will always be available on our website. Where we make material changes, we will take reasonable steps to notify you.
15. Contact Us
If you have any questions about this disclosure, our privacy practices, or how we handle your personal information, please contact our Privacy Officer.
- Email: privacy@canvas.co
- Mail: Privacy Officer, Canvas Digital Pty Ltd, C/- Presidio Partners Pty Limited, Level 2, 222 Pitt Street, Sydney NSW 2000
This disclosure is issued by Canvas Digital Pty Ltd (ACN 648 707 706; ABN 77 648 707 706), a reporting entity registered with AUSTRAC. Canvas Digital is committed to handling your personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles and the OAIC's guidance for reporting entities under the AML/CTF Act.