- Legal Documents
- Comms.ID Privacy Policy
Comms.ID Privacy Policy
Last Updated: 14 July 2026 Version: 1.0.13
Welcome to Comms.ID. Our mission is to build a more trustworthy digital world by combating fraud and misinformation. We do this by providing a secure, high-assurance digital identity platform that replaces insecure, anonymous interactions with a verified and consent-driven ecosystem.
Your privacy is not an afterthought; it is fundamental to our design and our mission. This Privacy Policy outlines our core privacy commitments and explains how we handle your personal information.
Our Legal Framework
The Australian Government Digital ID System (AGDIS) is a voluntary accreditation scheme. While Comms.ID is on the journey to achieve formal accreditation, we have built our platform from the ground up to adopt and conform to all relevant aspects of this framework and its governing legislation. We are bound by and committed to upholding our responsibilities under the:
- Privacy Act 1988 (Cth);
- Digital ID Act 2024 (Cth); and
- Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act).
At all times, we aim to meet and exceed the best practices and legal requirements of this framework.
1A. What Personal Information We Collect
To provide, operate, secure, personalise and improve our identity verification, authentication and related services; detect, investigate and prevent fraud; and meet our legal obligations, we collect the following types of personal information:
- Identity document information: Images or copies of government-issued identity documents and information from them, including your name, date of birth, address and document numbers.
- Biometric information: Facial images, liveness recordings and biometric templates used for identity verification and authentication; security and fraud detection; and developing, training, testing, validating, monitoring, improving and quality-assuring Comms.ID's biometric authentication, liveness-detection and fraud-detection systems. See our Identity Services Privacy Notice for detailed information on biometric handling.
- Profile information: Your display name and chosen avatar or profile image, used to personalise Comms.ID and participating Relying Party applications.
- Device, network and service-usage information: Technical information about your devices and network connections, and how you interact with our websites and applications.
- Verification, review and transaction records: Records of identity verifications, manual reviews, authentications, consent decisions and information-sharing transactions performed using your Comms.ID.
We collect identity document and biometric information directly from you through our mobile and web applications. We automatically collect device, network and service-usage information and create verification and transaction records when you use our services. We verify identity documents through the Australian Government's Document Verification Service and receive the resulting verification outcome. We may also receive personal information from Relying Parties in connection with verification and review activities.
1B. Face Data Disclosure
We collect and process facial images, liveness recordings and biometric templates for identity verification and authentication; security and fraud detection; and model development, training, testing, validation, monitoring, improvement and quality assurance. Here is how we handle this sensitive data:
- Liveness recordings: Retained for authentication, security and fraud detection, and for developing, training, testing, validating, monitoring, improving and quality-assuring Comms.ID's biometric authentication, liveness-detection and fraud-detection systems. We periodically document whether continued retention remains reasonably necessary for these purposes and destroy recordings when it no longer is.
- Biometric templates: We may create and retain biometric templates derived from facial images for authentication, security, fraud detection, model training and quality purposes. This processing is required to use Comms.ID and cannot be opted out of while maintaining an account. Templates are retained while your account is active and for up to 7 years after closure for compliance purposes.
- Authentication images: Retained with your consent on a rolling 24-month window; images older than 24 months are automatically destroyed.
- Relying Party disclosure: Relying Parties receive Comms.ID's verification or authentication outcome and the minimum requested attributes you consent to share. They do not receive or access the underlying DVS transaction request or result. "Access and Duplicate" is limited to information needed to personalise the Relying Party's application—commonly your name and avatar or profile image—not Comms.ID identity-system records. If your chosen avatar or profile image depicts your face, that image will be disclosed to and may be retained by the Relying Party. Comms.ID does not disclose liveness recordings, biometric templates or facial images collected specifically for identity verification or authentication to Relying Parties for their own purposes.
- Law-enforcement disclosure: Face data may be disclosed where required or authorised by or under Australian law or a court or tribunal order; where we reasonably believe disclosure is reasonably necessary for an enforcement-related activity conducted by, or on behalf of, an enforcement body; or with your express consent for identity-verification or offence-investigation purposes. We disclose only the information reasonably necessary and make a written record where required. See our Identity Services Privacy Notice for full details.
- Processing: Real-time liveness verification and facial matching use secure cloud infrastructure located within Australia. Cloud processors do not retain liveness session data after processing; Comms.ID separately retains liveness recordings as described above.
Because biometric processing is required to provide Comms.ID, withdrawing consent will close your account. After closure, each category of face data remains subject to its stated retention period: biometric templates may be retained for up to 7 years for compliance purposes; authentication images remain subject to the rolling 24-month period; and liveness recordings are retained only while reasonably necessary for authentication, security, fraud detection, model training and quality purposes, subject to periodic documented review. For complete details, see our Identity Services Privacy Notice.
2. Our Roles Explained: An Interoperable System
Comms.ID performs several distinct roles within the AGDIS framework. This separation of roles is a fundamental requirement of the system's design to enhance your privacy and security. It also ensures our services are interoperable, meaning in the future they can work with other accredited providers in the digital identity network.
Our roles include:
- Identity Service Provider (ISP): Verifying your identity against official documents to create your secure Digital ID.
- Attribute Service Provider (ASP): Verifying specific claims about you, such as your authority to act for a business.
- Identity Exchange (IXP): Acting as the secure, consent-driven "switchboard" that manages information flow between you and the services you access ("Relying Parties").
You can find detailed information on how we handle data in these specific roles in our dedicated notices:
3. Our Legal Obligations and Data Minimisation
We are subject to strict legal obligations that govern how we operate. The AML/CTF Act, in particular, requires both us and many of the Relying Parties that use our services (e.g., banks) to verify your identity to a high standard and keep records of those verifications. This may require us to collect specific information and retain verification records for a minimum of 7 years, even after you close your account. These are mandatory legal duties designed to prevent serious crime.
At the same time, we are deeply committed to data minimisation. We believe your data should not be duplicated unnecessarily across the internet. Our consent model requires each Relying Party to request only the permissions it needs to provide its service, including whether it needs to access information or receive and retain a copy. You may accept or deny the Relying Party's request as a whole. If you deny it, authentication for that Relying Party will not proceed and the Relying Party may be unable to provide its service. See our Identity Exchange Privacy Notice for details.
4. Your Privacy Rights
You are in control of your personal information. You have the right to:
- Access: Review your personal information at any time through the Comms.ID mobile or web applications.
- Correction: Request to have incorrect information corrected.
- Deletion: Close your Comms.ID account at any time. Upon your request, we will delete your personal information, subject to any legal obligations to retain it (such as under the AML/CTF Act).
- Withdraw Consent: View and revoke your consent for sharing information with a specific Relying Party at any time.
After authenticating through a native Comms.ID application for iOS or Android, or at https://auth.comms.id, select the relevant profile—such as Individual, Sole Trader, Company Director or another profile—to access and update its information. You may also request access to or correction of your personal information through any chat interface at https://comms.id or https://auth.comms.id.
5. Automated Decisions
We use computer programs to analyse identity-document information, biometric information, device, network and service-usage information, and verification, authentication and transaction records. These programs perform identity-document checks, facial matching, liveness detection, and security and fraud analysis.
Results and signals produced by these programs are directly involved in deciding whether an identity verification or authentication succeeds, is rejected or is paused, and whether access is restricted for security or fraud reasons. These decisions may be made solely by computer programs.
If you believe an automated decision was mistaken, you can seek assistance through live chat at https://comms.id, https://auth.comms.id, or through chat in the native Comms.ID applications for iOS and Android.
6. Data Security and Storage
Protecting your information is our highest priority. We store and process personal information within Australia and will not store personal information overseas. We use cloud-hosting and processing providers to process personal information on our behalf using services located within Australia. They are contractually restricted to processing that information on our instructions and may not use it for their own purposes. We use industry-leading security measures, including end-to-end encryption, and undergo regular independent security assessments to ensure our systems are robust.
7. Information for Minors
The Comms.ID service is available to individuals aged 15 years and older. We do not knowingly collect personal information from individuals under the age of 15.
8. How to Contact Us and Make a Complaint
To protect you from fraud, we will never use standard email, SMS, or unsecure phone calls for authentication or to request sensitive personal information.
To get support from a real person at Comms.ID, please use our secure, end-to-end encrypted channels:
- Use the secure chat widget on our public website at https://comms.id/.
- Use the in-app communication features (chat messages, voice or video calls) at https://auth.comms.id/, https://companion.comms.id/, or within our iOS and Android apps.
Privacy complaints may be lodged at https://complaints.comms.id. We will acknowledge your complaint, investigate it and provide our response within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC).
9. Governing Law
This Privacy Policy and our handling of your personal information are governed by the laws of Queensland, Australia.
Document integrity hash:
9ff9a964f28f58fdb97aee38cd2428400e8b790d5fe69e312d5246330f0dd3d5