Legal Entity: Chu Pay Pty Ltd
Version: 1.0
Effective Date: 23 August 2026
Last Reviewed: 21 August 2026
This Policy forms an integral part of the Chu Pay Terms of Service and must be read and applied together with those Terms. In the event of any inconsistency between the Terms of Service and this Policy in relation to the processing of personal information, this Policy shall prevail.
1.1. Chu Pay Pty Ltd (“Chu Pay”, “Company”) provides international electronic money transfer services between Australia and Mongolia through the Chu Pay mobile application (the “Application”).
1.2. This Policy explains how the Company collects, uses, discloses, transfers, stores, protects, and deletes personal information relating to users of its products, as well as the measures taken to protect such information.
1.3. This Policy applies to:
1.4. This Policy does not apply to the employment records of the Company's employees or to third-party websites and services linked from the Application.
2.1. The Company processes personal information in accordance with the following laws and regulations:
2.2. Where a customer is located in a jurisdiction that requires additional rights or protections (for example, the EU/UK under the GDPR), the provisions set out in Part E will also apply.
2.3. Conflicting obligations. Certain obligations imposed under Australian and Mongolian anti-money laundering laws may take precedence over a customer's privacy requests, including requests made by the customer. Where the law requires the Company to collect, retain, or disclose information, the Company will comply with those requirements and will explain why a customer's request cannot be fulfilled, unless prohibited by law from doing so (including under Section 22).
Personal Information: Information or an opinion about an identified individual or an individual who is reasonably identifiable, whether the information or opinion is true or recorded in material form.
Sensitive Information: A category of personal information requiring a higher level of protection under APP 3. This includes biometric information and biometric templates used for automated verification and identification, health information, and racial or ethnic information.
KYC: “Know Your Customer” — customer identification and verification procedures required under the AML/CTF Act and applicable Mongolian laws.
IFTI: International Funds Transfer Instruction. Reportable to AUSTRAC.
TTR: Threshold Transaction Report — a report submitted to AUSTRAC regarding cash transactions of AUD 10,000 or more (or the equivalent amount in a foreign currency).
SMR: Suspicious Matter Report. Submitted to AUSTRAC and the FIU.
PEP: Politically Exposed Person.
Recipient: The individual or legal entity designated by the Customer to receive a transfer.
Processor / Service Provider: A third party that processes personal information on behalf of the Company and in accordance with the Company's instructions.
4.1. Personal identification information
Full name, former or other names, date of birth, place of birth, gender (where stated on an identity document), citizenship, residential address and previous addresses, and occupation.
4.2. Identity document information
Passport number and expiry date, Australian driver's licence number, card number, issuing state, visa type, visa subclass, residency status, Mongolian national registration number, national identity card information, and photographs or scanned copies of these documents.
4.3. Biometric information (Sensitive Information)
A selfie photograph or short liveness video captured during registration, together with biometric templates derived from it. This information is used to verify that the person presenting the identity document is the same person shown in the document.
The Company will collect such information only with the customer's explicit consent provided at the time of capture. If the customer does not provide consent, the Company will offer an alternative manual verification process, which may take longer.
4.4. Contact information
Mobile telephone number, email address, postal address, and contact information provided by the customer regarding a recipient.
4.5. Financial and transaction information
Bank account name, BSB and account number, Mongolian bank and account information, card information (where card payments are supported), transfer amount, currency, exchange rate applied, fees, transaction date and time, transaction reference number, purpose of the transfer, source of funds, source of wealth where required, and the relationship between the sender and recipient.
4.6. Recipient information
For the purpose of processing a transfer, the Company may collect the recipient's name, account information, contact information and, where required under AML/CTF “Travel Rule” requirements or applicable Mongolian laws, address, date of birth, and registration number.
The customer is responsible for confirming that they are authorized to provide such information to the Company and, where reasonably practicable, must inform the recipient that their information has been provided to the Company and may be processed in accordance with this Policy.
4.7. Screening and monitoring information
Results of sanctions, terrorism financing, PEP, and adverse media screening; risk assessments determined by the Company; enhanced due diligence records; and information provided by the customer in response to requests under Section 3.8 of the Terms of Service (for example, where the total amount of transfers made within 24 hours exceeds MNT 20 million or exceeds a threshold prescribed under Australian law).
4.8. Device, technical, and usage information
Device model, operating system, unique device identifier, mobile network, carrier, IP address, approximate location derived from the IP address, Application version, language settings, login and logout times, failed login attempts, screens viewed, actions taken, error reports, and diagnostic data.
4.9. Fraud and security signals
Device fingerprint, behavioural signals used for fraud detection, including typing and navigation patterns, security event logs associated with the customer's account, and indicators showing whether the customer's device has been rooted/jailbroken, is operating within an emulator, or is under the control of remote-access or screen-sharing software.
4.10. Communications
Correspondence with the Company, in-app chat messages, complaint and dispute records, and recordings of telephone conversations with the Company's support team where notice was provided at the beginning of the call.
4.11. Marketing information
The customer's marketing preferences and information regarding whether messages sent by the Company were opened or clicked.
4.12. The Company does not intentionally collect health information, political opinions, religious beliefs, sexual orientation, or criminal records. This does not apply where such information is inadvertently included in documents provided by a customer or where criminal record information is identified through mandatory sanctions or adverse media screening.
5.1. Directly from the customer — when the customer registers, completes identity verification, creates a transfer request, contacts customer support, responds to monitoring requests, or participates in surveys or promotions.
5.2. Automatically from the customer's device — through the Application and website as described in Section 4.8 and Part D.
5.3. From third parties, including:
5.4. Anonymity and pseudonymity (APP 2).
The Company is required to identify and verify customers under the AML/CTF Act and applicable Mongolian laws. Accordingly, the Company does not permit customers to remain anonymous or use a pseudonym when obtaining transfer services. General research surveys may be accepted anonymously.
5.5. Failure to provide information.
If a customer does not provide information requested by the Company, the Company may be unable to open or verify the customer's account, process a transfer, or continue providing the service, and may have a legal obligation to reject, delay, suspend, or reverse a transaction.
6.1. The Company uses personal information for the following purposes:
6.2. Secondary use (APP 6).
The Company will only use personal information for a purpose other than the purpose for which it was originally collected where the customer would reasonably expect such use, the customer has provided consent, or the use is required or authorized by law.
6.3. The Company will not sell customers' personal information or disclose it to third parties for their own marketing purposes.
7.1. The Company uses automated systems for sanctions screening, PEP screening, transaction monitoring, risk assessment, and fraud detection. These systems may automatically suspend, delay, reject, or flag a transaction for human review.
7.2. Where a decision made by an automated system has a significant impact on the customer — for example, where a transfer is rejected or an account is suspended — the customer may contact the Company and request a review by an employee.
However, this right will not apply where providing the reason or reviewing the decision would breach the AML/CTF Act or applicable Mongolian laws prohibiting disclosure of information (see Section 22).
8.1. The Company will disclose personal information only to the extent necessary for the purposes set out in Section 6 and only to the following parties:
Under written agreements, subject to confidentiality obligations, and authorized to use the information only for the Company's purposes:
Partner banks, correspondent banks, partner banks in Mongolia, payment institutions, and settlement networks in Australia, to the extent necessary to process the customer's transfer.
Payment messages may include payer and recipient information as required by AML/CTF “Travel Rule” requirements and applicable Mongolian laws.
Where required or authorized by law:
Lawyers, auditors, accountants, and insurers who are subject to confidentiality obligations.
Potential or actual purchasers or investors in connection with the sale, merger, or restructuring of the business.
In such circumstances, confidentiality undertakings will be obtained, and the purchaser will be required to continue processing the information under a policy providing a level of protection no less protective than this Policy.
Any other person designated or authorized by the customer.
8.2. Amendment to the Terms of Service.
Section 4.2 of the Company's Terms of Service states that the Company will not disclose personal information to third parties. That provision must be interpreted consistently with this Part C: disclosures required by law, as well as disclosures to service providers and payment institutions acting on behalf of the Company to process transfers, are permitted and necessary.
9.1. As the Company provides cross-border transfer services, customers' personal information may be transferred overseas. The countries to which information may be transferred include:
9.2. Before disclosing personal information to an overseas recipient, the Company will take reasonable steps to ensure that the recipient does not breach the APPs. These steps may include:
9.3. Liability.
Except where APP 8.2 applies, the Company remains responsible under Section 16C of the Privacy Act for acts or practices of an overseas recipient that breach the APPs.
9.4. Limitations of overseas protection.
An overseas recipient will be subject to the laws of its own country. Those laws may not provide protection equivalent to Australian or Mongolian law, and in some circumstances the customer may be unable to enforce their rights or seek compensation in that jurisdiction.
There is also a risk that the Company and the customer may not be notified in advance where information is disclosed pursuant to a compulsory request from an overseas authority.
9.5. Where information is disclosed to a recipient in Mongolia in order to execute a transfer instruction provided by the customer, the Company relies on APP 8.2(b), meaning that the disclosure is necessary to perform the agreement with the customer.
10.1. The Company may send customer service notifications, including transaction confirmations, security alerts, monitoring requests, maintenance notifications, and changes to this Policy.
While an account remains active, customers cannot opt out of service notifications, as they are necessary for the reliable provision of the service.
10.2. Where the customer has provided consent, the Company may send marketing communications by email, SMS, or push notification. Under the Spam Act 2003, all marketing messages will contain a functional unsubscribe mechanism.
10.3. Customers may opt out at any time through Settings → Notifications in the Application or through the unsubscribe mechanism. Such requests will be processed within 5 business days.
10.4. The Company will not use Sensitive Information, including biometric information, for direct marketing purposes.
11.1. As required by APP 11.1, the Company will take reasonable steps to protect personal information from misuse, interference, and loss, as well as unauthorized access, modification, or disclosure.
The Company's control framework is aligned with the ISO/IEC 27001 family of standards and the Australian Cyber Security Centre's Essential Eight.
11.2. The Company does not assume that any system is completely secure (zero trust). The Company does not guarantee that its systems will never be subject to an attack.
Nothing in this provision limits rights provided to customers under the Australian Consumer Law or any other non-excludable law.
12.1. Transmission Encryption.
All traffic between the Application and the Company's servers, as well as between the Company's servers and its partners, will be encrypted using TLS 1.2 or higher and modern cipher suites.
HSTS will be implemented, and certificate pinning will be used in the mobile Application.
12.2. Encryption at Rest.
Personal information, identity documents, and biometric templates will be stored using AES-256 encryption or an equivalent method.
Encryption keys will be stored in a dedicated key management system, access will be restricted, keys will be rotated regularly, and keys will be stored separately from encrypted data.
12.3. Authentication.
Access to an account requires a username, password, and one-time code.
Passwords will be stored only as salted hashes using a memory-hard algorithm. The Company does not store passwords in a recoverable form, and no employee can view them.
Device biometric authentication (Face ID / fingerprint) may be enabled and is processed only on the customer's device.
12.4. Session Management.
Sessions will expire after a specified period of inactivity. Sessions will also be invalidated when the customer logs out, changes their password, or when a new or high-risk device is detected.
12.5. Card and Account Information.
Where card payments are supported, card information will be tokenized and processed by a payment service provider compliant with PCI DSS.
The Company will not store full card numbers or CVV codes in its own systems.
12.6. Network and Infrastructure.
Production systems are segregated from corporate systems and protected by firewalls and web application firewalls, DDoS protection, access controls, and intrusion detection systems.
Administrator access is permitted only through authenticated and logged channels.
12.7. Mobile Application Security.
The Application includes certificate pinning, code obfuscation, tamper-detection controls, and root/jailbreak and emulator detection.
Screenshots will be restricted on sensitive screens, and customers will be warned if screen-sharing or remote-control software is detected, as these are common methods used in transfer fraud.
12.8. Logging and Monitoring.
Security-related events, including logins, privileged access, and data exports, will be recorded in tamper-evident storage and retained for at least [12] months, with abnormal activity monitored.
12.9. Backup and Business Continuity.
Data will be backed up in encrypted form [daily], and restoration will be tested at least [annually].
The Company maintains written business continuity and disaster recovery plans, with a recovery time objective of 2 hours.
13.1. Least Privilege.
Employee access will be granted based on role and limited to what is necessary, reviewed at least [quarterly], and revoked when an employee changes responsibilities or leaves the Company.
13.2. Human Resources.
All employees and contractors will undergo reference and criminal history checks before commencing employment, provide confidentiality undertakings, and receive privacy, security, and anti-money laundering training upon commencement and at least annually thereafter.
13.3. Supplier Management.
Third parties will be assessed for security and privacy before engagement.
Written agreements will include confidentiality and security standards, sub-processing requirements, breach notification timeframes, and data return or deletion requirements.
Suppliers will be reassessed periodically.
13.4. Secure Development.
Code changes will be reviewed and tested and introduced through controlled processes that segregate development, testing, and production environments.
Production personal information will not be used in testing environments unless it has been de-identified.
13.5. Assurance Testing.
The Company will conduct an independent penetration test at least [annually] and following significant changes to the Application.
Automated vulnerability scanning and dependency monitoring will also be performed continuously.
Identified issues will be remediated according to written timeframes based on severity.
13.6. Physical Security.
The Company's offices are subject to access controls.
Paper documents containing personal information will be stored in locked safes and securely destroyed.
13.7. Governance.
The Board of Directors or its appointed delegate will review this Policy and the Company's security posture at least annually.
The anti-money laundering program, appointed Compliance Officer, and independent assurance reviews will operate alongside these controls.
14.1. Consistent with Sections 3.1, 3.2, and 3.4 of the Terms of Service, customers must:
14.2. Delaying notification may increase the customer's loss.
Unless otherwise required by law, the Company will not be liable for losses arising solely from the customer's failure to comply with the obligations set out in Section 14.1.
15.1. The Company maintains a Data Breach Response Plan, which will be tested at least [annually].
The plan covers steps for containing, assessing, notifying, and reviewing data breaches.
15.2. Australia — Notifiable Data Breach Scheme.
Where the Company suspects that an eligible data breach may have occurred, it will conduct a reasonable and prompt assessment and complete it within 30 days.
If there are reasonable grounds to believe that an eligible data breach has occurred — meaning that personal information has been accessed, disclosed, or lost without authorization and is likely to result in serious harm — the Company will notify the OAIC using the approved form as soon as practicable and notify affected individuals.
15.3. Notification Content.
The notification will include a description of the breach, the types of information involved, the actions taken by the Company, and steps recommended by the Company.
15.4. Mongolia.
Where a data breach involves information subject to Mongolian law, the Company will notify the competent authority and affected individuals within the timeframe prescribed by the Law on the Protection of Personal Information.
15.5. Partners and Regulators.
The Company will notify affected partner banks in accordance with contractual and regulatory requirements and will notify AUSTRAC where the breach affects anti-money laundering obligations.
15.6. Vulnerability Reporting.
If a customer identifies a security vulnerability in the Application, please report it to [security@domain].
The Company will not take action against researchers who act in good faith, respect confidentiality, do not delete data, and comply with this provision.
16.1. Personal information will be stored in encrypted form in cloud data centres located in Australia and operated by GoDaddy.
Certain information may be replicated and stored in Mongolia for backup and disaster recovery purposes.
16.2. Records relating to Mongolian transactions may be stored in the systems of the Company's partners in Mongolia in accordance with their own confidentiality obligations.
17.1. Anti-Money Laundering Records — 7 Years.
Under the AML/CTF Act, the Company is required to retain customer identification records for 7 years after the end of the customer relationship and transaction records for 7 years after the transaction occurs.
Even if a customer requests deletion, the Company cannot delete these records before the applicable retention period expires.
Applicable Mongolian laws impose similar minimum retention periods.
17.2. Other Retention Periods:
InformationRetention PeriodIdentity documents and verification results7 years after account closureBiometric templatesWithin [90] days after successful verification; immediately if verification is unsuccessful, except where an investigation is ongoingTransaction records7 years after the transactionSMR / TTR / IFTI records7 yearsCustomer correspondence and complaints7 years after resolutionCall recordings[12] months, except where related to a dispute or investigationSecurity and access logs[12] monthsMarketing preferencesUntil withdrawal; withdrawn preferences will be retained indefinitelyDevice and analytics data[26] months, or a shorter period where aggregated
17.3. Deletion (APP 11.2).
Where information is no longer required for any lawful purpose for which it may be used and is not required to be retained by law or court order, the Company will securely delete or de-identify it.
17.4. Legal Hold.
Where information relates to actual or reasonably anticipated litigation, regulatory investigation, or dispute, it will be retained until the matter is resolved, regardless of the retention periods stated above.
18.1. The Company's website uses cookies and similar technologies for the following purposes:
18.2. The Application uses SDKs for crash reporting, analytics, push notification delivery, and fraud/device intelligence.
These may collect device and usage information described in Sections 4.8 and 4.9.
18.3. Customers may manage cookies through their browser settings and manage analytics collection through Settings → Privacy in the Application.
Disabling essential cookies may cause the website to function improperly.
18.4. The Company does not use third-party advertising cookies or cross-site advertising tracking technologies.
19.1. In accordance with Section 6.1 of the Terms of Service, customers can directly view their profile information, service history, active requests, and their status through the Application.
19.2. For information that is not available through the Application, customers may submit a request to [email protected].
The Company will:
19.3. No fee will be charged for submitting a request.
A reasonable and non-excessive fee may be charged to cover the cost of providing information, for example, where a very large volume of historical records is requested.
The Company will notify the customer of any fee in advance.
19.4. Circumstances in Which Access May Be Refused.
The Company may refuse access under the circumstances set out in APP 12.3.
These circumstances include where access would unreasonably affect another person's privacy (for example, information concerning a recipient or third party), be unlawful, prejudice an investigation into unlawful activity, reveal fraud detection or transaction monitoring methodologies, or relate to existing or anticipated legal proceedings.
Where access is refused, the Company will provide the customer with written reasons and information about the complaints process.
20.1. Customers can update most of their information directly through the Application.
Certain fields, including full name and date of birth, may only be changed upon provision of supporting identity documents because these details are relevant to KYC verification.
20.2. If a customer believes information held by the Company is inaccurate, out of date, incomplete, irrelevant, or misleading, they may contact [email protected].
The Company will correct the information within 30 days, or provide written reasons why the information will not be corrected together with information about the complaints process.
20.3. A customer may request that a statement noting their belief that a particular record is inaccurate be attached to that record, and the Company will take reasonable steps to ensure that the statement is visible to users of the information.
20.4. Where information that has already been disclosed to a third party is corrected, the Company will notify that third party upon request, except where this is impracticable or unlawful.
21.1. There is no general right to erasure under the Australian Privacy Act.
Where a customer requests deletion of their information, the Company will:
21.2. Customers may object to processing based on legitimate interests, and the Company will consider the objection, except where processing is required by law.
21.3. If the customer is subject to the GDPR, for example, because the customer was located in the EU or United Kingdom when using the service, the customer may additionally have rights to erasure, restriction of processing, data portability, and to lodge a complaint with the relevant local supervisory authority.
These rights remain subject to lawful retention obligations under Section 17.1.
22.1. Under the AML/CTF Act, it is a criminal offence to disclose to a customer or unauthorized person that a suspicious matter report has been made or that certain information has been provided to AUSTRAC.
Mongolian law similarly prohibits “tipping off” in applicable circumstances.
22.2. Accordingly, where a transaction has been suspended, delayed, rejected, reported, or a customer's account has been restricted for anti-money laundering reasons, the Company may not be legally permitted to explain the reason, confirm or deny whether a report has been made, or provide access to relevant records.
In some circumstances, the Company may not even be permitted to state that AML/CTF requirements are the reason.
This does not constitute arbitrary refusal by the Company.
Please submit your complaint to the Privacy Officer of the Company:
Privacy Officer, Chu Pay Pty Ltd
Email: [email protected]
The Company will acknowledge receipt within 5 business days and provide a response within 30 days, including its findings and any actions to be taken.
If you are dissatisfied with the response or do not receive a response within the applicable timeframe, you may lodge a complaint with the Office of the Australian Information Commissioner:
Online: oaic.gov.au/privacy/privacy-complaints
Telephone: 1300 363 992
Postal: GPO Box 5218, Sydney NSW 2001
The OAIC generally requires complainants to first lodge a complaint with the Company and allow 30 days for a response.
23.3. Section 8.3 of the Terms of Service (negotiation followed by resolution under the law of the customer's country of residence) will continue to apply to disputes.
Nothing in this Policy or the Terms of Service prevents a customer from lodging a complaint with a regulatory authority at any time.
24.1. The service is available only to individuals who are 18 years of age or older.
The Company will not knowingly collect personal information from persons under 18.
If such a case is identified, the account will be closed and the information deleted, except where the Company is legally required to retain it.
25.1. Users of money transfer services are frequently targeted by fraudsters.
The Company will never:
25.2. If you believe you have been targeted by such an attempt, stop the transfer and contact [email protected].
You may also report the incident to Scamwatch (scamwatch.gov.au) and your bank.
26.1. This Policy may be amended from time to time.
The latest version will be available in the Application under Profile → Privacy Policy and at http://www.chupay.com.au.
26.2. If a change is material — for example, the addition of a new type of information, a new purpose, or a new category of recipient — customers will be notified through the Application and by email at least [14] days before the change takes effect.
26.3. Continued use of the service after the changes take effect constitutes acceptance of the updated Policy.
Where the law requires customer consent for a change, consent will be obtained separately.
27.1. This Policy will be published in both English and Mongolian.
In the event of any inconsistency between the two versions, the [English] version shall prevail.
28.1. Privacy inquiries, access, correction, and complaints:
[email protected]
28.2. Security incidents and vulnerability reports:
[email protected]
28.3. General support:
[email protected]
Chu Pay Pty Ltd is registered with AUSTRAC as a remittance service provider. Registration does not mean that AUSTRAC endorses or guarantees the business.