1. About this Privacy Policy
Hummingbird Intercoms Pty Ltd (ABN 75 651 091 057; ACN 651 091 057) operates Humi and uses the Humi Networks brand. In this policy, “Humi”, “we”, “us” and “our” refer to Hummingbird Intercoms Pty Ltd.
This Privacy Policy explains how we collect, hold, use and disclose personal information when you visit humi.au, use a Humi website or business portal, use the Humi mobile application, communicate with us, submit a support or complaint ticket, or apply for or use a Humi payment, collection, remittance or Spot FX service. It also explains how to ask for access or correction, request account deletion, make a privacy complaint and exercise other privacy choices.
This policy is intended to satisfy the transparency requirements of the Australian Privacy Principles. It does not reduce any right or remedy you have under applicable law. Product-specific terms and collection notices may give more detail about a particular interaction. For identity verification in the Humi App, please also read our Identity Verification Collection Notice.
Privacy questions, access and correction requests, and privacy complaints: compliance@humi.au. Account and deletion requests: account@humi.au. General support: support@humi.au. Postal address: 25 Lime Street, Sydney NSW 2000, Australia.
2. What “personal information” means
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form. Some information, including certain biometric information used for automated identification, may be sensitive information and receive additional protection. Government identifiers, financial information and identity-document images also require careful handling even where they do not fall within every legal definition of sensitive information.
Information that has been irreversibly de-identified so that no individual is reasonably identifiable is not personal information. We may use aggregated or de-identified information for service planning, security analysis, reporting and improvement.
3. Personal information we collect
The information we collect depends on how you interact with Humi and which service you request. We seek to collect only information reasonably necessary for our functions, legal obligations and the service concerned.
3.1 Account and contact information
- name, display name, email address, telephone number and residential or business address;
- date of birth, nationality, country of residence and age or eligibility confirmations;
- customer, account and user identifiers, account status, preferences and communication history;
- password hashes, transaction-PIN hashes, email-verification status, session and security information; and
- information about an authorised representative, director, beneficial owner or other person connected with a business customer where relevant.
We do not store your account password or transaction PIN in readable form. You should never disclose a password, one-time code or transaction PIN in a support form or email.
3.2 Identity and compliance information
- legal name, date of birth, nationality, residential address and occupation or source-of-funds information where required;
- identity-document type, number, issuing country, issue and expiry dates, and images of passports, driver licences or other government-issued documents;
- verification status, manual-review notes, requests for further information, risk indicators and the outcome and reasons recorded by authorised reviewers;
- information needed for sanctions, politically exposed person, fraud, financial-crime or other legally required screening; and
- communications and supporting evidence you provide in response to a compliance request.
Do not send identity-document images through our ordinary support form or by unrequested email. If additional evidence is needed, we will tell you how to provide it through an approved channel.
3.3 Payment, recipient and transaction information
- AUD funding instructions, bank account information, payment references and evidence of funding;
- quote amounts, fees, exchange rates, transfer instructions, transaction dates, statuses and settlement or return information;
- recipient name, telephone number, identity number where required, bank, bank-account details, country and currency;
- the purpose of a payment or transfer, relationship to a recipient and supporting transaction information where required; and
- records received from banks, payment and payout partners, screening providers, counterparties and other participants in a transaction.
If you give us personal information about a recipient or another person, you must have a lawful reason to provide it, take reasonable steps to ensure it is accurate and, where appropriate, tell that person that Humi will use it to provide and administer the requested service.
3.4 App, device and security information
- Humi user and device identifiers, device type, operating-system and App version, IP address, login times and session records;
- network, request, error, audit, fraud-prevention and security-event information;
- camera or photo-library content that you actively choose for an identity-document upload; and
- information needed to detect repeated requests, protect accounts, investigate faults and maintain service integrity.
The current Humi App does not use your data for cross-app tracking or targeted advertising and does not request access to your contacts, microphone or precise location for the AUD to CNY service. If this changes, we will update the relevant notice and platform privacy disclosure before the new collection begins.
3.5 Website, support and complaint information
- the pages requested, IP address, browser or user-agent information, timestamps, referrer and security logs ordinarily generated when a website is used;
- a limited session cookie needed to protect and operate the Humi support form;
- your name, contact email, account email, request category, reference, subject, message, selected language, and the privacy-notice version and presentation time when you submit a support ticket;
- complaint allegations, requested outcomes, investigation records, correspondence and resolution information; and
- records of privacy, access, correction and account-deletion requests.
Our current public website and App do not use third-party advertising trackers. We may use essential operational logs and privacy-protective service measurements to secure and improve our services. If we introduce a non-essential cookie or analytics technology that requires a choice, we will provide the required information and controls.
4. How we collect personal information
We usually collect personal information directly from you when you create or use an account, enter information in the App or portal, take or select an identity-document image, request a quote, nominate a recipient, fund a transfer, contact us, or submit a complaint or data request.
We may also collect information from:
- banks, payment processors, payout providers, recipient banks and other transaction participants;
- identity, screening, fraud-prevention, communications, hosting and support service providers;
- authorised representatives, business customers or another person who lawfully provides your information;
- government bodies, regulators, courts, law-enforcement agencies and legally available public records; and
- our systems when they generate account, transaction, security and audit records.
Where it is reasonable and practicable, you may interact with us anonymously or using a pseudonym for a general website enquiry. We cannot provide an account, identity verification, payment, remittance, complaint outcome or most account-specific support anonymously because we must identify the relevant person, transaction or legal obligation.
5. Why we collect, use and disclose information
We may handle personal information for the purpose for which it was collected and for related purposes that you would reasonably expect, where you consent, or where the law otherwise permits or requires. These purposes include:
- creating, verifying, securing and administering accounts;
- assessing eligibility and carrying out customer due diligence, identity checks, sanctions and other financial-crime controls;
- providing quotes and carrying out, monitoring, reconciling, returning or recovering payments and AUD to CNY transfers;
- validating recipients and communicating instructions to banks, payout providers and other transaction participants;
- detecting and responding to fraud, scams, unauthorised access, abuse, cyber incidents and operational risk;
- meeting record-keeping, reporting, tax, anti-money laundering and counter-terrorism financing, court, regulator and law-enforcement requirements;
- answering questions, handling support, investigating complaints, correcting records and processing account-deletion or privacy requests;
- maintaining, testing, auditing, troubleshooting and improving our services and business controls;
- communicating service, security, legal, transaction and account information; and
- establishing, exercising or defending legal rights and managing a corporate transaction subject to appropriate confidentiality and legal safeguards.
We may send marketing only where permitted. You can unsubscribe from optional marketing at any time. Security alerts, transaction notices, legal notices and other communications needed to administer an account or service are not marketing and may continue while the account or relevant obligation remains active.
6. Identity review, OCR and device biometrics
6.1 Current Humi identity process
The current Humi App implementation collects identity details and an identity-document image for Humi review. The current review approach is human review. Automatic optical character recognition (OCR) is disabled by default. If Humi enables OCR, it is used only to suggest document fields for you to review and to assist the process; it does not replace the customer’s confirmation or Humi’s review.
Humi does not currently integrate a third-party face-recognition SDK into the App, does not conduct automated facial matching in the current flow and does not collect or create a facial-recognition template through that flow. A normal photograph on an identity document is still personal information and is protected as part of the identity record.
6.2 Apple and Android device authentication
When Humi asks you to unlock an existing App session using Apple Face ID, Touch ID or the device passcode, or an Android system biometric (such as fingerprint or face recognition) or device credential (such as PIN, pattern or password), the device operating system performs the authentication locally on your device. Humi receives only the success or failure result needed to allow or refuse local access. Humi does not receive, collect, store or upload the biometric image, mathematical representation or biometric template used by Apple, Android or the device operating system.
6.3 Future changes
If we later propose biometric identification, liveness detection, a third-party face SDK or a materially different automated identity service, we will complete the required legal, privacy, security and vendor review first. We will give a specific collection notice and seek any consent required before collecting sensitive biometric information. We will not describe an experimental or unapproved tool as part of the current service.
7. When we disclose personal information
We do not sell or rent personal information. We disclose only what is reasonably necessary for the service, a permitted purpose or a legal requirement. Recipients may include:
- banks, payment networks, payment processors, payout providers, recipient banks and other parties needed to execute or investigate a transaction;
- identity, sanctions, fraud and compliance information providers where approved and required for the service;
- cloud, data, security, website, email, support, document-storage and communications providers acting for us;
- professional advisers, auditors, insurers and contractors subject to confidentiality and access controls;
- government bodies, regulators, courts, law-enforcement agencies and other persons where disclosure is authorised or required by law; and
- a prospective or actual purchaser or successor in connection with a corporate transaction, subject to appropriate confidentiality and legal safeguards.
We may also disclose information with your consent or at your direction. When Humi discloses personal information to a service provider, we take reasonable steps to require the provider to handle it only for the agreed purpose, protect it appropriately and return or delete it in accordance with applicable requirements and our instructions.
8. Overseas handling and disclosures
Humi is based in Australia. The current Humi App application service and its identity submissions are processed on Humi application systems in Australia. Providing an international payment and operating the public website, email and support service nevertheless requires some information to be handled outside Australia. As at the effective date of this policy, the countries in which recipients are likely to handle or access personal information include at least:
| Country | Why information may be handled there | Typical information |
|---|---|---|
| United States | Providers involved in public website, email and support-service hosting or related technical operations. | Website and support contact information, service logs, ticket content and associated operational metadata. |
| China | CNY recipient validation, payout, banking, transaction processing, compliance enquiries and transfer support. | Recipient and transaction details, payment instructions, status information and information required by the relevant bank, payout provider or law. |
A provider or transaction participant may use personnel or infrastructure in another country. Where a new country becomes a likely location for a material category of personal information, we will update this policy or give a more specific notice. We take reasonable steps appropriate to the circumstances before an overseas disclosure, which may include due diligence, contractual privacy and security requirements, data minimisation, access controls and review of retention and incident-response arrangements. However, overseas recipients may be subject to different laws, and courts or authorities in those countries may lawfully require access.
9. Security
We use administrative, technical and physical safeguards designed to protect personal information against misuse, interference, loss, unauthorised access, modification and disclosure. Depending on the information and system, measures may include encrypted network connections, credential hashing, restricted role-based access, session revocation, audit logging, environment separation, backups, monitoring, staff confidentiality and incident procedures.
No internet or storage system is completely secure. You can help by using a unique password, protecting your device and email account, keeping the App and operating system updated, checking transfer details carefully and contacting support@humi.au immediately if you suspect compromise. Humi will never ask you to provide your password, one-time code or transaction PIN in an email or support ticket.
If an eligible data breach occurs, we will investigate and make notifications required by the Privacy Act 1988 (Cth) and other applicable law.
10. Retention and deletion
We keep personal information only for as long as it is needed for the purpose for which it was collected, to provide and secure the service, and to meet legal, accounting, dispute, fraud-prevention and audit obligations. Retention is applied by record type; it is not one undifferentiated period for every item.
| Record category | General approach |
|---|---|
| Identity, customer-due-diligence and AML/CTF records | Generally retained for seven years from the relevant event required by law, which may be when a record is made, a transaction occurs or the customer relationship ends. The correct trigger depends on the record and applicable law. |
| Transaction, recipient, funding, reconciliation and compliance records | Generally retained for seven years from the applicable transaction, record or relationship event, or longer where another legal obligation, investigation, dispute or legal hold requires it. |
| Account and authentication records | Kept while an account is active and afterwards for the period reasonably needed to close it, protect customers, evidence instructions and meet security, audit and legal requirements. Tokens and active access are revoked when appropriate. |
| Support, complaint and privacy-request records | Kept while the matter is handled and for an appropriate accountability and dispute period afterwards. A record linked to a transaction, compliance obligation or legal dispute may need to be kept with that matter. |
| Website sessions and operational security logs | Usually retained for shorter operational periods unless the information is needed for security investigation, fraud prevention, audit or a legal requirement. |
When information is no longer required, we take reasonable steps to destroy it securely or irreversibly de-identify it. Deleting an account does not require us to erase records that the law requires or permits us to retain. Retained information is restricted to the permitted purpose and is not kept active merely so the account can continue to be used. See Account and Data Deletion for the request process and what happens next.
11. Access, correction and privacy choices
You may ask for access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also ask us to delete information that is no longer needed, withdraw an optional consent, stop optional marketing, or explain how a particular category of information is handled.
Submit a request through our Support Centre privacy form or email compliance@humi.au. We may need to verify your identity and authority before giving access or changing a record. We will not ask for more verification information than is reasonably needed, and we will provide an approved method if identity documents are required.
We respond within a reasonable period and generally aim to complete an ordinary verified request within 30 calendar days. Complex, high-volume or legally restricted requests may take longer; if so, we will explain the reason and expected next step. We ordinarily do not charge for making a request. If the law permits a reasonable charge for providing access, we will explain it before proceeding.
There may be lawful reasons to refuse access, correction or deletion in whole or part, including the privacy of another person, legal privilege, security, fraud prevention, litigation, regulatory restrictions and mandatory record retention. If we refuse a request, we will give written reasons and available complaint options unless the law prevents us from doing so. More detail is available at Privacy Choices and Data Requests.
12. Account deletion
You can initiate account deletion from within the Humi App by opening the Account area, entering your login password in the Account closure section and confirming the deletion request. You can also request deletion without reinstalling the App by using the public account-deletion support form or emailing account@humi.au.
We verify requests to prevent an unauthorised person deleting your account. An in-App request changes the account to a deletion-requested state and revokes mobile sessions. We then review open transfers, complaints, refunds, security concerns and mandatory retention before completing closure. We delete or de-identify information that is no longer needed and preserve only records that must or may lawfully be retained. Full details are set out on the Account and Data Deletion page.
13. Privacy complaints
If you believe Humi has mishandled personal information, email compliance@humi.au, submit a privacy request, or write to Hummingbird Intercoms Pty Ltd, 25 Lime Street, Sydney NSW 2000, Australia. Please describe what happened, the information involved and the outcome you seek. The process is free.
We aim to acknowledge a complaint within one business day, investigate it fairly, keep you informed where more time is needed and provide a reasoned response. See our Complaints and Disputes page for the current process.
If you are not satisfied with our response to a privacy complaint, you may contact the Office of the Australian Information Commissioner (OAIC). Current contact and complaint information is available at oaic.gov.au/privacy/privacy-complaints. We do not state that another external dispute-resolution scheme applies unless that has been verified for the relevant service and legal entity.
14. Adults and information about children
The Humi consumer App is intended for eligible individuals aged 18 years or older. We do not knowingly offer an App account to a child. If you believe a child has provided personal information without appropriate authority, contact compliance@humi.au so we can investigate and take appropriate action, subject to any mandatory record-keeping obligation.
15. Changes to this policy
We may update this policy when our services, providers, technology or legal obligations change. The page heading shows the effective and last-updated date. If a change materially affects how we handle information already collected, we will take reasonable steps to notify affected users and seek consent where required. An archived copy can be requested from compliance@humi.au.
16. Contact details
Hummingbird Intercoms Pty Ltd
ABN 75 651 091 057; ACN 651 091 057
Operator of Humi; Humi Networks brand
25 Lime Street, Sydney NSW 2000, Australia
- Privacy, compliance and complaints: compliance@humi.au
- Account and deletion requests: account@humi.au
- General support: support@humi.au
- Online request form: humi.au/support