Artificial Intelligence Terms of Use
Last updated: 25 August, 2026
Preamble
These Artificial Intelligence Terms of Use govern your use of artificial intelligence features within the Personr platform. They supplement the Personr Terms and Conditions, Service Provider Agreement, and the Personr Privacy Policy (together, the "Master Services Agreement"). Where these Terms are inconsistent with the Master Services Agreement in relation to AI Features, these Terms prevail.
By using any AI Feature, you agree to these Terms on behalf of yourself and the organisation you represent.
Current AI Features:
Feature
Purpose
Annex
Compass
An AI Compliance model assisting with AML/CTF obligations, your own compliance documents, and cases in your account.
1
Trust Reader
Automated extraction and analysis of trust, and self-managed superfund details from an uploaded trust or self-managed superfund deed.
2
Definitions and Interpretations
1.1. In these Terms, unless the context otherwise requires:
AI Features means the artificial intelligence features available within the Personr platform, currently comprising Compass and Trust Reader, as further described in the Annexes to these Terms.
AI Output means any text, analysis, extraction, reasoning, or other content generated by an AI Feature.
Compass means the AI compliance model described in Annex 1.
Trust Reader means the trust and self-managed superfund deed analysis feature described in Annex 2.
Personal Compliance Context or PCC means documents uploaded by the Customer for use with Compass, such as the Customer's AML/CTF program, risk assessment methodology, policies and procedures.
Master Services Agreement means the Personr Terms and Conditions, and Privacy Policy available at https://personr.co/legal-centre, or your Service Provider Agreement entered into with us, whichever is relevant to you.
Privacy Policy means the Personr Privacy Policy available at https://personr.co/legal/privacy-policy, as updated from time to time.
Service Provider means Personr Pty Ltd (ACN 697 453 400).
1.2. References to clauses and Annexes are to the clauses of, and Annexes to, these Terms respectively.
1.3. A reference to a statute includes any subordinate legislation made under it and any modification or re-enactment of it.
1.4. The headings in these Terms are for ease of reference only and shall not affect their interpretation.
1.5. Where the expressions "includes(s)", "including", or "in particular" are used, the list following them is not exhaustive unless explicitly indicated otherwise.
1.6. The singular includes the plural and vice versa.
2. Nature and Limitations
2.1. AI Features are built on large language models. Their output is generated not retrieved from a verified record. It may be inaccurate, incomplete, outdated, internally inconsistent, or confidently wrong. An incorrect output will read exactly as fluently and authoritatively as a correct one.
2.2. No AI Feature provides legal advice, and no AI Output creates a lawyer-client relationship or substitutes for advice from a qualified legal or compliance professional. How your organisation responds to any verification result, screening flag, extracted trust detail or regulatory obligation is a business decision that must align with your own AML.CTF program and risk appetite.
For formal AML/CTF legal advice, the Service Provider can refer you to its partner network, available at https://personr.co/partner-directory.
2.3. You must review AI Output before acting on it. This is a condition of use, not a recommendation. You remain solely responsible for every compliance decision your organisation makes.
AI Output must not be the sole basis for:
deciding whether to onboard, decline, or off board a customer;
determining whether a screening match is a true or false positive;
identifying a beneficial owner, trustee, settlor, or appointor;
deciding whether to lodge a Suspicious Matter Report, Threshold Transaction Report, or any other regulatory report;
assessing or assigning a customer risk rating; or
concluding that your AML/CTF program complies with any law.
A qualified individual within your organisation must review and take responsibility for each such decision.
2.4. Where an AI Feature refers to AML/CTF law, that reflects the Service Provider's understanding at a point in time and may not account for subsequent amendments, regulatory guidance, or judicial interpretation. Always verify statutory references against the authoritative text published by regulators and their respective governments.
3. Liability
3.1. To the maximum extent permitted by law, AI Features are provided "as is" and "as available". The Service Provider makes no warranty that AI Output will be accurate, complete, current, fit for any particular purpose, or compliant with any law applicable to you.
3.2. The Service Provider is not liable for any loss, damage, penalty, regulatory sanction, enforcement action, remediation cost, or reputational harm arising from your reliance on AI Output, including where that output is inaccurate incomplete or misleading.
3.3. The Service Provider is not liable for any decision made by you or on your behalf in reliance on AI Output.
3.4. Nothing in these Terms excludes, restricts, or modifies any guarantee, right or remedy under the Australian Consumer Law or any other law that cannot lawfully be excluded. Where liability may be limited but not excluded, refer to the Master Services Agreement.
3.5. The Service Provider's aggregate liability is capped in accordance with the Master Services Agreement.
4. Processing Location and Infrastructure
4.1. AI Features process data within the Service Provider's infrastructure in the Asia Pacific (Sydney) region, unless stated otherwise in a feature-specific Annex.
4.2. Models are hosted and run within the Service Provider's own infrastructure. Your content is not transmitted to any third-party, or external AI service.
5. Data Use and Training
5.1. The Service Provider does not use your queries, documents, case data, or AI Output to train, fine-tune, or improve any artificial intelligence model.
5.2. Data processed through AI Features is used only to:
generate the requested output;
store results within your account;
record usage for billing, rate limiting, and capacity management;
maintain security, operational and diagnostic logs; and
meet the Service Provider's own legal and regulatory obligations.
5.3. The Service Provider may use aggregated, de-identified operational metrics (such as volumes, response times, and error rates) for service improvement and capacity planning. Such metrics do not identify you, your organisation or any individual, and are not derived from the content or your submissions.
6. Tenant Isolation and Security
6.1. Data submitted to AI Features is tagged with your organisation's account identifier and access is filtered to that identifier at the retrieval and application layers. One customer's data cannot be surfaced to another.
6.2. The Service Provider maintains encryption in transit and at rest, least-privilege access controls, network isolation, logging and monitoring, and periodic review, consistent with its ISO 27001:2022 certified information security management system.
7. Your Responsibilities
7.1. You must only submit documents and data your organisation is lawfully entitled to submit and to have processed as described in these Terms.
7.2. You must ensure you have any consent, notice, or other lawful basis required for personal information you submit, including in respect of individuals who are not your customer (see Annex 2, clause A2.4).
7.3. You must not submit material beyond what the feature requires. Submitting unrelated material degrades output quality and needlessly expands the personal information being processed.
7.4. You must not use AU Features to profile or make automated decisions about individuals or entities in a manner prohibited by applicable law.
7.5. You must not attempt to circumvent tenant isolation, extract system instructions, or induce an AI Feature to operate outside its intended purpose.
7.6. You must ensure your personnel understand that AI Output requires human verification.
8. International Data Transfers
8.1. AI Features process data within Australia. Where personal information originates from elsewhere:
8.1.1. From the EEA or UK, transfer relies on Standard Contractual Clauses (SCCs) with a transfer impact assessment.
8.1.2. Under APP 8, where the Service Provider discloses personal information overseas, it takes reasonable steps to ensure the recipient does not breach the APPs, or relies on a permitted exception.
8.2. Sub-processors are listed at https://personr.co/legal/sub-processors-and-third-party-providers
9. Privacy Law Compliance
Australian Privacy Act 1988 (Cth) and the APPs
9.1. The service Provider handles personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
9.1.1. In relation to APP 1, these Terms and the Privacy Policy describe how personal information is handled in AI Features.
9.1.2. In relation to APP 3 and APP 5, AI Features do not independently collect personal information from individuals. They process information submitted by you, for which you are responsible for collection notices.
9.1.3. In relation to APP 6, personal information is used only for the purposes in clause 5.2, within the primary purpose of collection.
9.1.4. In relation to APP 8, see clause 8.
9.1.5. In relation to APP 11, see clause 6.2.
9.1.6. In relation to APP 12 and 13, access and correction requests can be submitted by emailing privacy@personr.co.
9.2. Where you are a reporting entity, you remain responsible for your own APP obligations in respect of your customers' information. The Service Provider acts as a data processor.
GDPR (EU) and UK GDPR
9.3. You are the controller; the Service Provider is processor. Processing is governed by the Data Processing Agreement.
9.4. The Service Provider processes personal data only on your documented instructions, which include your use of AI Features as described in these Terms.
9.5. No AI Feature makes automated decisions producing legal or similarly significant effects. All are decision-support tools and require human review under clause 2.3. You must ensure meaningful human involvement in any decision affecting an individual.
9.6. The Service Provider will assist you with access, rectification, erasure, restriction, portability and objection requests, insofar as the data resides within our infrastructure.
9.7. Confidentiality, security, sub-processor engagement, assistance, deletion or return on termination and audit rights are addressed in the Data Processing Agreement.
California (CCPA, CPRA)
9.8. The Service Provider acts as a service provider. It does not sell or share personal information as defined in the CCPA, and does not retain, use or disclose it other than to perform the service. It does not combine your personal information with information from other sources except as permitted for a service provider. Consumer requests should be directed to you as the business; the Service Provider will provide reasonable assistance.
Biometric Information (BIPA and Comparable Laws)
9.9. AI Features do not collect, capture, receive, purchase or otherwise obtain biometric identifiers or biometric information. They process text and documents. They do not perform facial recognition, liveness detection, fingerprint or voiceprint analysis, and do not access biometric templates.
9.9.1. An AI Feature may reference the outcome of a biometric check performed elsewhere int he platform, for example a rejection label. Such an outcome is a verification result, not a biometric identifier.
9.9.2. Where the Personr platform performs biometric verification, that processing is governed by the relevant policy, which addresses notice, consent, retention and destruction under the Illinois Biometric Information Privacy Act and comparable laws including those of Texas and Washington.
10. Intellectual Property
10.1. You retain all rights in the documents and data you submit.
10.2. As between you and the Service Provider, you may use AI Output for your internal compliance purposes. Given the nature of generative output, the Service Provider makes no representation that any output is original or that its use will not infringe a third party's rights.
10.3. The Service Provider retains all rights in its AI Features, including prompts, knowledge bases, underlying data, and systems.
11. Availability and Changes
11.1. AI Features may be unavailable, and no availability commitment applies unless expressly stated in your Service Level Agreement.
11.2. Usage may be subject to limits. Customers on Pay as you go plans are not eligible to access certain AI Features.
11.3. The Service Provider may modify, suspend or discontinue any AI Feature, or change the underlying model, at any time.
12. Contact
12.1. For privacy enquiries and data requests, please email privacy@personr.co.
12.2. For general support, please email help@personr.co.
Annex 1 - Compass
A1.1. Compass is an AI model that helps compliance personnel navigate AML/CTF obligations and the Personr platform. It answers questions by reasoning over sources including, but not limited to:
a general knowledge base of Australian AML/CTF law maintained by the Service Provider;
your Personal Compliance Context (PCC), comprising documents your organisation has uploaded, such as your AML/CTF program, risk assessment methodology, policies, and procedures; and
case data already in your account, such as verification statuses, rejection labels, risk ratings, AML screening results, and audit history.
Compass is a decision-support tool. It does not make compliance decisions, take regulatory action, or perform verification.
A1.2. Compass processes the following categories of data, with your instruction:
query content, such as the questions you type, and prior messages in the conversation;
PCC documents, such as your AML/CTF program, policies, procedures, methodologies, and documents attached to an applicant or entity (excluding identity documents).
case context, such as applicant or entity names, their verification status, reject labels, risk rating, AML screening results (including match scores and determinations), and audit history;
account identifiers, such as your account identifier and the identifier of the applicant or entity in view; and
operational metadata, such as token counts, timestamps, and retrieval diagnostics.
Personal information may be present in the categories. Case context routinely includes an identified individual's name, verification outcome, and screening results.
A1.3. PCC documents are tagged with your account identifier at ingestion, and every retrieval is filtered to that identifier. Compass cannot retrieve another customer's documents.
Within your account, a document uploaded against a specific applicant or entity is available in that profile's conversation and in your account-wide conversations. Documents uploaded at the account-level (such as your program, policies, and procedures) are available in all conversations within your account.
A1.4. Compass may display its intermediate reasoning. This is a working process, not a conclusion, and may contain speculation or errors that do not appear in the final answer. It is provided for transparency and should not be relied on independently.
A.1.5. Conversation history, PCC documents, and operational logs are retained in your account until you delete them, or terminate your relationship with Personr.
Your own AML/CTF record-keeping obligations may require retention for a minimum of seven years. Deleting material from Compass does not discharge those obligations, and you should satisfy yourself that you hold records independently.
Annex 2 - Trust Reader
A2.1. Where a customer operates through a trust or self-managed superfund, Trust Reader analyses an uploaded trust or self-managed superfund deed and extracts structural details for your review. It accepts PDF and DOCX files up to 20MB.
It extracts, for your review:
trust name and type;
trustee;
appointor;
settlor;
beneficiaries;
ultimate beneficial owners;
key risks; and
other analysed information.
It may also suggest follow-up steps, such as verifying a corporate trustee.
A2.2. Trust Reader produces a proposed reading of a legal document. It is not a legal interpretation of that document and it is not a determination of beneficial ownership.
You must verify every extracted field against the original deed before confirming it. Trust deeds vary enormously in drafting; discretionary trusts frequently describe beneficiaries by class rather than name, may include unborn or unascertained beneficiaries, and may confer powers whose effect on control is not apparent from the text alone.
An extraction error may cause you to identify the wrong beneficial owner and consequently fail your customer due diligence obligations.
A2.3. A trust deed may be uploaded by you, or by an authorised representative of the customer during an onboarding flow. Where a representative uploads it, you remain responsible under clauses 7.1 and 7.2 for the lawfulness of that submission, and for ensuring the representative is authorised to provide it.
A2.4. A trust deed commonly contains personal information about individuals who have no relationship with you or with the Service Provider, and who have not been through any verification flow (such as settlors, appointors, named beneficiaries, and members of beneficiary classes including, in some deeds, minors.)
Accordingly, you warrant that:
A2.4.1. You are lawfully entitled to disclose the deed and its contents to the Service Provider for processing.
A2.4.2. You have complied with any notification or consent obligation owed to individuals named in the deed, including under APP 5 where personal information about them is collected from someone other than the individual.
A2.4.3. You have considered whether the deed contains sensitive information as defined in the Privacy Act, such as health information, and have any consent required for its collection.
A2.4.4. Where an individual named in a deed is in the EEA or UK, you have identified a lawful basis under the GDPR and can satisfy the transparency obligations in Articles 13 and 14.
A2.5. Uploaded deeds will be retained against an entity profile until you request to delete, or delete them. Extracted fields will be retained as part of the entity record and follow the entity's retention period.
Deleting a deed does not delete extracted fields already confirmed into the entity's record, nor does it discharge your own record-keeping obligations.

