Welcome to the new dacs.io: same team, same address, new look. Spotted something off? Tell us

Legal

Privacy policy

How DACS collects, uses and protects personal information.

Last updated: 5 October 2026

Who we are

Digital Asset Compliance Solutions Pty Ltd (ABN 80 625 017 110) ("DACS", "we", "us") provides independent verification of digital asset holdings, mainly for self-managed superannuation funds and their auditors and accountants. This policy explains how we handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

What we collect

We only collect what we need to quote, verify and report. Depending on how you deal with us, that can include:

  • Contact details — name, email address, phone number, and the name of your fund, trustee company, accountant or auditor.
  • Identity information — documents we ask for to confirm who controls the fund and its assets (for example, a driver licence or passport, and company or trust details).
  • Asset information — public wallet addresses, exchange account details, holdings and balances, and the records you provide so we can verify them.
  • Read-only exchange access keys — keys that let us read balances. We do not accept keys that allow trading or withdrawals.
  • Payment and billing details — invoices and payment records. Card payments are processed by Stripe; we do not see or store your full card number.
  • Conversations — emails, portal messages, and chats with Metis, our AI concierge.
  • Website usage — on dacs.io, basic analytics (Google Analytics) about pages visited and the device used.

We do not ask for private keys, seed phrases or passwords, and you should never send them to us.

How we collect it

Mostly directly from you — through our website forms, the DACS portal, Metis, email and payment. We also collect information from your accountant or auditor when they refer you to us, from public blockchains, and from exchanges using the read-only access you give us.

Why we use it

  • To quote, onboard you and confirm identity and control of the fund.
  • To verify and value holdings and prepare your report.
  • To share your report with the auditor or accountant you authorise.
  • To bill you and keep financial records.
  • To answer questions and provide support, including through Metis.
  • To improve our services and website.
  • To send you updates you have asked for. You can unsubscribe from marketing email at any time.
  • To meet our legal, professional and insurance obligations.

Metis and automated tools

Metis is an AI assistant, not a person. It answers questions and gathers the details we need to prepare a quote. Prices for standard engagements are calculated automatically from the information you give; complex engagements are reviewed by our team. A person at DACS reviews every verification report before it is issued. Metis runs on our own systems in Australia, and its instructions, knowledge and conversation records are held there. To generate each reply, the text of the conversation is sent to an AI model provider — currently Anthropic or OpenAI, both based in the United States — through their business API, which does not permit them to use it to train their models. Metis conversations are kept for the same period as our other records.

Who we share it with

We do not sell personal information. We share it only where needed to deliver our service or where the law requires, including with:

  • The auditor, accountant or adviser you authorise to receive your report.
  • Service providers who run parts of our business for us — hosting and security (Amazon Web Services, Cloudflare), email and documents (Google Workspace), payments (Stripe), accounting (Xero), email updates (Mailchimp) and AI services used by Metis (Anthropic and OpenAI).
  • Our professional advisers and insurers, under confidentiality.
  • Regulators, courts or law enforcement where we are legally required to.

Overseas disclosure

Our portal and verification systems are hosted with Amazon Web Services in Sydney, Australia. Some of our other service providers store or process information outside Australia, mainly in the United States — including Anthropic and OpenAI (which process the text of Metis conversations to generate replies), Google, Cloudflare, Stripe and Mailchimp. Where that happens we choose providers with recognised security practices and contractual protections.

Security

We protect information with access controls, encryption in transit, restricted staff access and logging. Exchange access keys are stored encrypted and are read-only. Reports are sealed so any later change can be detected. No system is perfectly secure; if a data breach is likely to cause you serious harm, we will notify you and the Office of the Australian Information Commissioner as the Notifiable Data Breaches scheme requires.

How long we keep it

We keep verification records and supporting evidence for as long as they may be needed to support an audit, and generally for seven years after an engagement ends, to meet record-keeping and professional obligations. After that we delete or de-identify it.

Access and correction

You can ask to see the personal information we hold about you, or ask us to correct it. We will respond within 30 days. We may need to confirm your identity first, and in limited cases the law allows us to refuse access; if so, we will tell you why.

Contact and complaints

For privacy questions or complaints, email [email protected] with "Privacy" in the subject line, or write to us at Level 9, 360 Collins Street, Melbourne VIC 3000. We will acknowledge your complaint promptly and aim to resolve it within 30 days. If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at oaic.gov.au.

Changes to this policy

We may update this policy from time to time. The current version is always on this page.