Privacy Policy
How Averis Solutions collects, uses, shares and protects personal information.
Document Information
1. About this Policy
1.1 This Privacy Policy explains how AVERIS SOLUTIONS PTY. LTD. (ABN 60 695 090 665, ACN 695 090 665), trading as Averis Solutions (Averis, we, us or our), handles personal information through https://www.averissolution.com, our dashboards, APIs, onboarding workflows, integrations, support channels and related services.
1.2 We are based in Australia and aim to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) where they apply. Additional privacy laws may apply depending on where an individual lives or where a service is provided.
1.3 This Policy should be read with our Terms and Conditions, Cookie Policy, any collection notice presented when information is collected, and any data processing addendum that applies to a customer relationship.
2. Our role and the role of merchants and Payment Providers
2.1 Averis acts as a privacy controller or APP entity when we decide why and how to process information for website operations, account administration, merchant onboarding support, platform security, risk management, billing, support, analytics and our own legal obligations.
2.2 When we process an end customer's information only on a merchant's documented instructions, we generally act as that merchant's processor or service provider. The merchant remains responsible for its customer relationship, privacy notice, lawful basis, consents, responses to privacy requests and instructions to Averis.
2.3 Payment Providers such as Stripe and Adyen may process information as independent controllers for payment processing, verification, fraud prevention, security, regulatory compliance, settlement and their own services. Their privacy notices apply to that processing.
2.4 Averis is a software, integration and payment-orchestration provider. Unless an approved written arrangement says otherwise, we do not independently provide regulated payment processing or settlement and do not hold customer or merchant funds.
3. Personal information we collect
- Identity and contact information. Name, date of birth where required, work title, employer, address, email, telephone number, signature and account contact preferences.
- Business and verification information. Business name, registration and tax identifiers, industry, websites, licences, ownership and control, directors, authorised signatories, beneficial owners, bank-account verification, expected transaction activity and supporting documents. Some verification information may be sensitive and is collected only when reasonably required.
- Account and commercial information. User identifiers, roles, permissions, subscriptions, Order Forms, pricing, invoices, payment status, account settings, service selections and Provider Account references.
- Transaction and reconciliation information. Order and transaction references, amount, currency, time, status, merchant and customer references, payment-method type, token or masked details, last four digits where supplied, refund, dispute, chargeback, payout, settlement and reconciliation data. Averis is designed not to store complete card numbers or CVV/CVC codes.
- End-customer information. Name, contact details, billing and shipping details, customer and order identifiers, purchase or subscription context, device and network data, support information and other information a merchant submits through an approved integration.
- Device, usage and cookie information. IP address, device and browser type, operating system, language, time zone, pages viewed, referring links, session identifiers, cookie identifiers, logs, API requests and approximate location derived from IP.
- Risk, fraud and security information. Authentication events, device identifiers, behavioural and velocity indicators, geolocation inconsistencies, proxy or VPN signals, rule matches, risk scores, fraud or dispute history, sanctions or adverse-media results where lawfully obtained, and incident records.
- Communications and support information. Enquiries, support tickets, call or meeting notes, feedback, complaint material, survey responses, attachments and records of our communications.
- Marketing information. Business interests, campaign engagement, event attendance, preferences and records of consent or opt-out choices.
4. How we collect information
4.1 We collect information directly when an individual visits the Website, completes a form, creates or uses an account, submits onboarding information, uses an API or checkout, contacts support, signs an agreement, attends a meeting or otherwise communicates with us.
4.2 We may receive information from a business customer, its personnel, end customers, Payment Providers, banks, fraud and identity vendors, commerce platforms, implementation partners, service providers, public registers, regulators, sanctions lists, professional advisers and other lawful sources.
4.3 We collect technical information automatically through cookies, server logs, security tools, pixels and similar technologies. More detail appears in our Cookie Policy and any cookie preference tool presented on the Website.
4.4 If you provide information about another person, you must be authorised to do so and give that person any privacy notice required by law.
5. Why we use personal information
5.1 To provide and administer the Website and Services, create and secure accounts, authenticate users, enable integrations, route authorised instructions, display transaction status, generate reports, reconcile activity and provide support.
5.2 To support merchant onboarding and continuing review, validate business information, transmit information to Payment Providers, manage requests for further information and assess service or payment-method eligibility.
5.3 To prevent, detect and investigate fraud, prohibited activity, account compromise, transaction laundering, security threats, disputes, misuse and violations of Provider requirements or our Terms.
5.4 To manage subscriptions, fees, invoicing, tax, finance, audit, complaints, legal claims, corporate transactions, record keeping and compliance with law, court orders, regulatory requests and Payment Provider obligations.
5.5 To operate, monitor, troubleshoot, analyse and improve the Website, APIs, risk tools, customer experience, product performance and security, including using aggregated or de-identified information where appropriate.
5.6 To communicate about services, incidents, account actions, policy changes, events and relevant business offerings. We send direct marketing only as permitted by law and provide an unsubscribe method.
6. Legal bases where European or UK law applies
6.1 Where the GDPR or UK GDPR applies, we rely on one or more of the following bases: performance of a contract or steps requested before a contract; compliance with legal obligations; our legitimate interests or those of a merchant, Provider or other party; protection of vital interests; and consent where required.
6.2 Legitimate interests may include providing and improving business services, securing systems, preventing fraud, managing commercial relationships, enforcing agreements, maintaining audit records and communicating with business contacts. We balance those interests against the individual's rights and expectations.
6.3 Where processing relies on consent, consent may be withdrawn at any time without affecting prior lawful processing. Refusing or withdrawing consent may make an optional feature unavailable.
7. How we disclose personal information
- Payment Providers and financial partners. We disclose information to Stripe, Adyen and other enabled Providers, banks, payment methods, card networks and settlement partners for account onboarding, verification, processing, risk, refunds, disputes, settlement, payout and compliance.
- Merchants and platform customers. We disclose relevant end-customer, transaction, account, risk and support information to the merchant or organisation responsible for the account or transaction.
- Technology and operational service providers. We use vendors for cloud hosting, communications, analytics, identity, fraud prevention, customer support, document management, security, logging, software development, professional services and business continuity. They are permitted to process information only for agreed purposes and subject to appropriate obligations.
- Authorities and professional advisers. We may disclose information to regulators, courts, law enforcement, tax authorities, card schemes, auditors, insurers, lawyers and other advisers where reasonably necessary or legally required.
- Corporate events. Information may be disclosed in connection with a financing, restructuring, merger, acquisition, sale or insolvency, subject to confidentiality and lawful-use restrictions.
- With direction or consent. We disclose information where an individual or authorised business customer directs us or provides valid consent.
7.1 We do not sell personal information for money. We do not use or disclose sensitive personal information for unrelated advertising. If a jurisdiction treats certain advertising-cookie activity as a sale or sharing, we will provide the choices required by applicable law.
8. Stripe, Adyen and other Payment Providers
8.1 For Stripe Connect, Averis may share connected-account, representative, end-customer, transaction, activity and risk information with Stripe and may receive corresponding data from Stripe as authorised by the connected account and the applicable Stripe agreements.
8.2 For Adyen for Platforms, Averis may create or manage legal-entity, account-holder, balance-account, store, merchant-account and transfer-instrument records and transmit verification, transaction, split, payout, risk and support information to Adyen. Adyen may return verification, capability, risk, transaction and account-status results.
8.3 A Payment Provider may use information for its independent regulatory, risk, fraud, security, service-improvement and legal purposes. Individuals should read the Provider's privacy notice linked at the end of this Policy.
8.4 If you are an end customer of a merchant, the merchant's privacy policy and the applicable Provider's privacy notice also apply. Contact the merchant first about the underlying order, goods, services, refund or customer account.
9. International handling and overseas disclosure
9.1 Averis is located in Australia and uses global Payment Providers and technology vendors. Personal information may be accessed, hosted or disclosed outside the individual's country, including in Australia, the United States, the United Kingdom, Singapore, countries in the European Economic Area and countries where the relevant merchant, Provider, bank, payment method or service provider operates.
9.2 Where practicable, we identify likely countries in this Policy, a collection notice, Provider documentation or an up-to-date service-provider list. The locations may change as services, merchants and Providers change.
9.3 Before an overseas disclosure, we take reasonable steps appropriate to the circumstances, such as due diligence, contractual privacy and security commitments, data minimisation, access restrictions and recognised transfer mechanisms. Where European or UK transfer rules apply, we may use adequacy decisions, standard contractual clauses or another lawful mechanism.
9.4 No security or transfer mechanism eliminates all risk. By using global payment services, information may be subject to lawful access by authorities in relevant jurisdictions.
10. Data retention
10.1 We keep personal information only for as long as reasonably needed for the purpose collected, the Services, transaction and dispute lifecycles, security, audit, legal claims, Provider obligations and applicable law. We then delete, destroy or de-identify it where reasonably practicable.
- Account, contract and billing records. Generally for the relationship and up to 7 years afterwards, reflecting tax, accounting, audit and claim requirements.
- Merchant onboarding and verification records. For the account lifecycle and up to 7 years after closure where required by law, Provider obligations or legitimate fraud and compliance needs; shorter where the information is no longer necessary.
- Transaction, refund, dispute and reconciliation records. Generally up to 7 years after the relevant transaction or longer if a dispute, investigation, legal hold or Provider requirement remains open.
- Security and technical logs. Generally 12 to 24 months, unless a longer period is reasonably needed to investigate an incident, prevent fraud or meet a legal obligation.
- Support and complaint records. Generally 3 years after closure, or longer where linked to a transaction, legal claim or regulatory requirement.
- Marketing records. Until opt-out or the relationship is no longer active, with a minimal suppression record retained to honour the opt-out.
10.2 Backup copies may remain for a limited rotation period and are protected from ordinary use. Retention periods may be shorter or longer where required by law, a Provider, a legal hold, security needs or the context of the information.
11. Security and payment-card information
11.1 We use reasonable administrative, technical and physical safeguards, including role-based access, multi-factor authentication where available, encryption in transit, logging, monitoring, secure development, vulnerability management, vendor review, backup and incident-response procedures.
11.2 We design payment integrations to use Provider-hosted fields, tokenisation or equivalent controls so that Averis does not need to store complete payment-card numbers or CVV/CVC codes. Masked card details, tokens and Provider references may be stored for transaction and support purposes.
11.3 Do not send full card numbers, CVV/CVC codes, passwords, API keys, signing secrets or identity documents through an unapproved form, ordinary email or support message. If we receive such information unexpectedly, we may delete or redact it and ask for secure resubmission.
11.4 No system is completely secure. Individuals and customers must protect credentials, use strong authentication and notify us promptly of suspected compromise.
12. Data breaches
12.1 We maintain procedures to identify, contain, investigate, assess and remediate suspected personal-information breaches. We coordinate with affected customers, Providers and service providers where appropriate.
12.2 Where required, we will notify affected individuals and the Office of the Australian Information Commissioner or another regulator in accordance with applicable data-breach law. Notifications may be made by the party best placed or legally responsible to do so.
13. Cookies, analytics and marketing
13.1 We use essential cookies and similar technologies for security, sessions, form operation and preferences. With consent where required, we may use analytics or performance technologies to understand Website and platform use.
13.2 Individuals can use browser controls and any cookie preference tool we provide. Blocking essential technologies may prevent parts of the Services from working. See our Cookie Policy for more information.
13.3 Business marketing communications include an unsubscribe method. An individual can also opt out by contacting us. Service, security, legal and account messages are not marketing and may still be sent when necessary.
14. Risk tools and automated processing
14.1 Averis and Payment Providers may use automated tools, rules and risk models to detect fraud, card testing, account takeover, sanctions concerns, unusual activity, security threats and prohibited use. Inputs may include transaction, device, location, account, behavioural and third-party risk data.
14.2 These tools may approve an action, request additional authentication, refer activity for review, restrict a capability or block an instruction. A Payment Provider remains responsible for its own decisions. Where applicable law gives a right regarding a solely automated decision with significant effect, an individual may request information, express a view and seek human review by contacting us or the responsible Provider.
15. Access, correction and other privacy rights
15.1 An individual may ask to access or correct personal information held by Averis by contacting info@averissoulution.com. We will take reasonable steps to verify identity and authority before responding.
15.2 Depending on applicable law, an individual may also have rights to deletion, restriction, portability, objection, withdrawal of consent, opt-out of direct marketing and review of certain automated decisions. These rights may be subject to exceptions for legal obligations, fraud prevention, security, transaction records, claims and the rights of others.
15.3 If Averis holds information only for a merchant or Payment Provider, we may refer the request to that party or assist it to respond. For an underlying purchase, contact the merchant. For information controlled independently by a Provider, use the Provider's privacy channel.
15.4 We do not charge for making a request. Where permitted, a reasonable fee may apply to provide access if the request is manifestly unfounded, excessive or requires substantial retrieval, and we will explain any fee first.
16. Privacy complaints
16.1 Send a privacy complaint to info@averissoulution.com or the postal address in section 19. Describe the concern, the relevant account or interaction, any supporting details and the outcome requested.
16.2 We will acknowledge the complaint within a reasonable time, investigate fairly and aim to respond within 30 days. If more time is reasonably needed, we will provide an update where permitted.
16.3 If you are not satisfied after giving us a reasonable opportunity to respond, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au/privacy/privacy-complaints. Other local regulators may also be available depending on your location.
17. Children
17.1 The Website and Services are intended for businesses and adults. They are not directed to children under 16, and we do not knowingly create platform accounts for children. If we learn that we collected a child's information without appropriate authority, we will take reasonable steps to delete it.
18. Changes to this Policy
18.1 We may update this Policy to reflect changes to law, Providers, technology or our practices. We will post the updated version and effective date. For material changes affecting account users, we will provide additional notice where reasonably practicable or legally required.
19. Contact us
For privacy questions, requests or complaints, contact our Privacy Contact using the details below. Please do not include full payment-card data, passwords, API secrets or unnecessary identity documents in an initial message.
Contact information
Privacy and legal contact: info@averissoulution.com
Postal address: 15 Kent Ave, Croydon VIC 3136, Australia
Phone: +61 476 366 666
Website: https://www.averissolution.com
ABN: 60 695 090 665
ACN: 695 090 665
Provider and regulator privacy resources
- Averis Cookie Policy
- Stripe Privacy Policy
- Stripe Connected Account Agreement (Australia)
- Adyen Privacy Statement
- Adyen for Platforms documentation
- OAIC - Australian Privacy Principles
- OAIC - Privacy complaints