Personal information

Privacy policy

This policy explains the information Corvenhall Trust collects, why it is used, who may receive it, how long it is kept and the choices available to Australian users.

1. Controller and definitions

The data controller is [LEGAL ENTITY NAME], trading as Corvenhall Trust, contactable at [email protected]. The legal entity remains a placeholder until verified corporate details are provided.

“Personal information” means information or an opinion about an identified or reasonably identifiable person. “Processing” covers collection, use, storage, disclosure and deletion.

2. Information you provide

We may collect first and last name, phone number, email address, residential details, the content of a request and account or complaint references. Where applicable, identity, address and source-of-funds evidence is collected through an approved verification process.

Do not submit credentials, private keys, recovery phrases or complete card details through general contact fields.

3. Usage and device information

Systems may record IP address, browser and device information, timestamps, requested pages, referring address, approximate location, language, session events and security signals. These records support delivery, troubleshooting, abuse prevention and analysis.

Approximate technical data can be inaccurate and is not treated as proof of a person's precise location.

4. Cookies and local storage

Essential cookies or browser storage may maintain a session, security state, language or functional preference. Non-essential analytics is inactive unless a valid measurement identifier is configured and applicable consent requirements are met.

You can control cookies through the browser, but blocking essential storage may prevent login or other functions from working.

5. Controller and processors

Corvenhall Trust determines purposes for information collected through this site. Specialist providers may process data on documented instructions for hosting, security, communications, verification, customer support or analytics.

A separate account, execution or custody provider may act as an independent controller for its own legal service and must provide its own privacy information.

6. Purposes of use

Information is used to respond to requests, assess registration, provide and secure services, perform identity and financial-crime checks, process payments, support users, investigate incidents, handle complaints, keep required records and improve functionality.

Contact details may be used for marketing only where an appropriate basis and required consent exist. You can opt out without stopping necessary account or security messages.

7. Legal bases and Australian requirements

Depending on the context, processing is necessary to take requested steps or perform a contract, comply with law, protect legitimate security and operational interests, or act on consent. The Australian Privacy Principles apply where the entity and activity fall within the Privacy Act 1988.

Consent is not relied on where information must be retained or disclosed under a legal obligation.

8. Retention

Registration enquiries that do not proceed are retained only as long as needed for follow-up, consent records, fraud prevention and legal claims. Account, transaction, KYC, AML/CTF, complaint and security records can be retained for statutory periods and while a claim or investigation is reasonably possible.

Exact periods depend on the record category and responsible provider. At expiry, information is deleted, de-identified or securely isolated unless a lawful hold applies.

9. International transfers

Technology or verification providers may operate outside Australia. Before a transfer, the responsible entity should consider contractual, security and legal safeguards appropriate to the information and destination.

Ask support for current categories of overseas recipients relevant to your service; this site does not invent locations that were not supplied.

10. Disclosure

Information may be disclosed to the executing or account provider, related entities performing an approved function, identity and screening providers, IT and communications providers, payment services, professional advisers, insurers, regulators, AUSTRAC, courts or law-enforcement where authorised or required.

We do not sell personal information as a data-broker product. A provider receives only information reasonably connected with its function.

11. Security

Controls include encryption in transit, access restriction, logging, authentication, monitoring, backups and incident procedures. Controls are reviewed according to the service and sensitivity of the information.

No internet service can guarantee absolute security. Users should protect their devices, email and authentication factors and report suspicious access promptly.

12. Your rights

You may request access to personal information and correction of inaccurate or incomplete information. Depending on applicable law and context, you may also request deletion, restriction, objection, withdrawal of consent or a copy in a usable form.

A request can be limited where identity cannot be established or legal retention, fraud prevention, another person's privacy or legal privilege applies. We will explain a refusal where permitted.

13. Service providers

Providers are selected based on function, security, reliability and legal considerations. Contracts address confidentiality, permitted use, safeguards, incident communication and deletion or return where appropriate.

Provider use can change as services evolve. Material changes are reflected in this policy or related notices.

14. Analytics and advertising

The site includes an inactive Google Analytics configuration slot; no measurement request is sent while the identifier is empty. If analytics is enabled later, the responsible team must address notice, consent and settings as applicable.

Corvenhall Trust does not currently describe behavioural advertising or retargeting as active. Such activity must not begin without an updated notice and required choices.

15. External sites

External sites have their own privacy and security practices. Check the destination before submitting information, especially where a page handles an account or payment.

16. Children

The services are intended for adults aged 18 or over. We do not knowingly seek registration from children. Contact support if you believe a child has submitted personal information.

17. Changes

This policy may be updated for changes in law, services, providers or data practices. The current version applies when published, and a prominent notice may be used for a material change.

18. Contact and complaints

Send privacy requests or concerns to [email protected]. We may verify identity before disclosing or changing information.

If a privacy concern is not resolved, you may be able to contact the Office of the Australian Information Commissioner. The complaint pathway does not remove other rights.