Privacy Policy
Crawford Doran Real Estate
Last updated: 15/06/2026
1. Introduction
Crawford Doran Real Estate (we, us, our) is committed to protecting your personal information and handling it in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
This Privacy Policy explains how we collect, use, store, disclose and protect personal information, including information used to verify your identity.
A current version of this Policy is always available on our website at https://www.crawfordoran.com.au/
2. What Personal Information We Collect
We may collect the following personal information about you:
- Full name
- Date and place of birth
- Residential or business address
- Email address and phone number
- Government-issued identification details, such as driver licence, passport, Medicare card or other ID document numbers
- Biometric information, such as a facial image or short video used to verify your identity
- Information about the services we provide to you and any related transactions
- Any other information you choose to provide to us
We only collect personal information that is reasonably necessary to carry out our business activities.
3. Why We Collect Your Personal Information
We collect, use and disclose your personal information to:
- Verify your identity
- Provide and manage our services to you
- Communicate with you about your account with us
- Meet our legal and regulatory obligations, including anti-money laundering and counter-terrorism financing (AML/CTF) requirements
- Detect and prevent fraud, and keep our systems secure
- Improve our services
4. Identity Verification and Government Data Matching (DVS)
To verify your identity, we may use electronic identity verification services, including the Australian Government’s Document Verification Service (DVS).
Where you have consented, your name, date of birth and identity document details will be securely sent to the relevant Commonwealth or State authority that issued your document. This may include passport offices, driver licence authorities, the Department of Home Affairs, Births Deaths and Marriages, or other authorised record holders.
These authorities check whether the details you have provided match the records they hold.
We do not receive a copy of your government records. The authority returns a match result only, confirming whether your details match (yes or no).
This process may be carried out through accredited identity verification providers, including APLYiD (APLYiD Pty Ltd, ABN 36 632 866 794) and its sub-providers.
More information about the DVS is available at idmatch.gov.au.
5. Biometric Information
As part of identity verification, we may collect biometric information, such as a facial image or a short video of you holding your ID.
Biometric information may be used to:
- Confirm that you are a real person and physically present
- Match your image to the photograph on your identification document
- Reduce the risk of fraud and identity theft
Biometric information is treated as sensitive information under the Privacy Act. We only use it for identity verification and related compliance purposes, and only with your consent.
6. Consent to Collection and Identity Verification
By providing your personal information and completing the identity verification process, you consent to:
- The collection, use and disclosure of your personal information for identity verification, AML/CTF and related compliance purposes
- The collection and use of biometric information, such as a facial image or video, for identity verification
- Your information being checked against records held by Commonwealth and State authorities through the DVS
- Your information being shared with our authorised identity verification providers, including APLYiD
Your consent is voluntary. You can withdraw your consent at any time by contacting us using the details in section 13.
If you do not consent, or do not provide the information we need, we may not be able to verify your identity electronically. In that case, we may need to verify your identity in another way, or we may not be able to provide our services to you.
7. Disclosure of Personal Information
We may disclose your personal information to:
- Identity verification providers, including APLYiD and its authorised sub-providers
- Commonwealth and State authorities and official record holders, through the DVS
- Our employees and authorised representatives, on a need-to-know basis
- Our professional advisers, such as lawyers, accountants and auditors
- Trusted technology and service providers that help us operate our business
- Regulators, law enforcement or other third parties where required or authorised by law
We do not sell your personal information.
8. Overseas Disclosure
Some of our service providers may store or process personal information outside Australia.
Where this happens, we take reasonable steps to ensure that your personal information is handled in line with the Australian Privacy Principles, including through contractual protections with our providers.
9. Data Security and Storage
We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification or disclosure.
These steps include secure systems, access controls, and encryption in transit and at rest where appropriate.
We retain personal information only for as long as we need it for the purposes set out in this Policy, or as required by law. When we no longer need your information, we securely delete or de-identify it.
10. Access and Correction
You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, incomplete or out of date.
To make a request, please contact us using the details in section 13. We will respond within a reasonable time.
11. Direct Marketing
From time to time, we may use your contact details to send you information about our services that we think may be of interest to you.
You can opt out of marketing communications at any time by using the unsubscribe link in our messages, or by contacting us using the details in section 13.
12. Privacy Complaints
If you have a complaint about how we have handled your personal information, please contact us first using the details in section 13.
We will acknowledge your complaint, investigate it, and respond to you within a reasonable time.
If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
13. Contact Details
If you have any questions about this Policy, or want to exercise any of your privacy rights, please contact us:
- Business name: Crawford Doran Real Estate
- Privacy contact: Gemma Niscioli
- Email: gemma@crawfordoran.com.au
- Phone: 08 8124 8930
- Address: 77 Palmer Place, North Adelaide SA 5006
14. Updates to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or in the law.
The latest version will always be available on our website. Where changes are significant, we will let you know.
We are committed to protecting the privacy and security of our clients, customers, and users of our website. This Privacy Policy sets out the types of personal information we collect, how we use that information, and the steps we take to ensure its protection. By using our website and our services, you agree to the terms of this Privacy Policy.
- Collection of Personal Information
We may collect and process the following types of personal information:
a) Contact information, such as name, address, email address, and telephone number.
b) Demographic information, such as age, gender, and occupation.
c) Financial information, such as income, assets, and credit history.
d) Property-related information, such as property address, property type, and property value.
e) Information related to your preferences, interests, and requirements in relation to real estate.
f) Technical data, such as IP address, browser type, and operating system.
We collect this information directly from you when you provide it to us, such as through our website, email, telephone, or in person, or indirectly from third parties, such as credit reporting agencies or publicly available sources.
- Use of Personal Information
We may use your personal information for the following purposes:
a) To provide and improve our services, such as property sales, property management, and property appraisals.
b) To communicate with you, such as responding to your inquiries, sending you updates on properties, and informing you about our services and promotions.
c) To personalize your experience on our website, such as displaying relevant content and advertisements.
d) To conduct market research, analysis, and reporting.
e) To comply with legal and regulatory requirements.
- Disclosure of Personal Information
We may share your personal information with:
a) Our employees, agents, and contractors, who are bound by confidentiality obligations.
b) Third-party service providers, such as property inspectors, conveyancers, and financial institutions, who assist us in providing our services.
c) Government agencies, regulators, and law enforcement authorities, when required by law or to protect our rights and property.
We will not sell, rent, or trade your personal information to any third party without your consent.
- Security of Personal Information
We take appropriate technical and organizational measures to protect your personal information against unauthorized access, disclosure, alteration, or destruction. These measures may include secure data storage, access controls, encryption, and regular security assessments.
- Retention of Personal Information
We will retain your personal information for as long as necessary to fulfill the purposes for which it was collected, comply with legal and regulatory requirements, or resolve disputes. Once your information is no longer required, we will securely destroy or anonymize it.
- Access, Correction, and Deletion of Personal Information
You have the right to request access to, correction of, or deletion of your personal information held by us. To exercise these rights, please contact us using the contact details provided below.
- Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or applicable laws. We will notify you of any material changes by posting the updated policy on our website.
- Contact Us
If you have any questions or concerns about this Privacy Policy or our handling of your personal information, please contact us using the details below.
We are committed to resolving any privacy issues promptly and fairly.
9. Overseas Disclosure of Personal Information
In some circumstances, we may disclose personal information to team members or service providers located overseas who assist us in delivering our services (for example, administrative or support functions).
Where we do so, we take reasonable steps to ensure that the overseas recipient handles personal information in accordance with Australian privacy laws and this Privacy Policy, including entering into confidentiality and data protection agreements where appropriate.
By providing us with your personal information, you acknowledge that your information may be disclosed to recipients located in the Philippines for these purposes.
10. Data Breaches and Notifiable Data Breach Scheme
We take data security seriously and have procedures in place to detect, investigate, and respond to suspected data breaches.
In the event of a suspected data breach, we will promptly assess whether the breach is likely to result in serious harm to any individuals whose personal information is involved.
Where we determine that an eligible data breach has occurred under the Privacy Act 1988 (Cth), we will:
- take immediate steps to contain and remediate the breach where possible;
- notify affected individuals as soon as practicable, including providing information about the nature of the breach and recommended steps they can take to protect themselves; and
- notify the Office of the Australian Information Commissioner (OAIC) in accordance with our legal obligations.
We maintain internal data breach response procedures to ensure compliance with the Notifiable Data Breaches scheme and to minimise the risk of harm arising from any unauthorised access, disclosure, or loss of personal information.
