Home/Compliance & security
Compliance & security

What happens to a loan file when it reaches our team

Offshore support only helps you if you can still answer for it. This page sets out where your data sits, who we let near it, what they are trained on, and what we do when something goes wrong. It names the limits as well as the controls.

Data handling

Your files stay in your systems. We work inside them, and we do not take copies.

  • Staff work inside your CRM, aggregator platform or lending software over remote access. No loan file is copied onto EXTEND systems.
  • Sending us documents by email is not permitted. System access is the only route to a client file.
  • Every workstation is issued by EXTEND and centrally managed. Staff cannot use personal equipment for client work.
  • Full-disk encryption is enforced on every device rather than left to the user.
  • USB storage, printing and local downloads are blocked.
  • Screens are recorded and activity is monitored for the whole of every shift.
  • Home-based staff work under a written policy requiring a private workspace that the rest of the household cannot access.
  • A clean-desk and no-paper rule applies, so nothing from a client file is printed or written down.

Where this stops: Access to your systems is created and revoked by you, not by us. We cannot revoke it ourselves. We tell you the moment someone leaves or changes role, but the final control, and its timing, stays with you.

NCCP alignment

We work under your licence, and we train our people to the obligations that come with it.

  • All work is performed under your Australian credit licence or credit representative authorisation.
  • EXTEND holds no credit licence and provides no credit assistance in its own right. Your obligations remain yours; our job is to support them, not to assume them.
  • Staff complete a responsible lending module covering NCCP obligations before they are given access to any loan file.
  • Staff complete a separate module on the Privacy Act and the Australian Privacy Principles.
  • Staff complete an AML/CTF module. It is deliberately general awareness: our staff perform no designated service under the AML/CTF Act, and we do not present them as doing so.
  • All three modules are recorded on completion, and refreshed every year.
Australian data residency

Your data stays in Australia. Our people reach it from the Philippines, and you should hear that from us rather than find it out.

  • Client data remains in your Australian systems throughout. EXTEND operates no data store that holds client loan files.
  • Our staff are located in the Philippines and access your systems remotely from there.
  • Because that access is from overseas, APP 8 still applies to you. Giving an overseas recipient access to personal information is a disclosure under the Privacy Act, even where nothing is copied or stored offshore.
  • Our client agreement addresses overseas handling and the safeguards that apply to it. Your compliance team can have a copy on request.
Breach response

A written plan, and a clock we hold ourselves to.

  • We maintain a written incident response plan.
  • Where we become aware of an incident affecting your data, we notify you within 24 hours of becoming aware of it.
  • Because your data stays in your systems, an incident on our side is a compromise of access rather than of a stored file. Revoking that access is immediate, and it is in your hands.
Staff vetting

Who we let near your files, and what happens on the day they leave.

  • Every hire completes an NBI clearance, the Philippine national police check.
  • We verify identity and right to work against government identification.
  • We contact previous employers directly for references.
  • We verify claimed qualifications with the institution that issued them.
  • Every staff member signs a confidentiality agreement, on top of the confidentiality clause in their employment contract. We will also sign your own NDA where you want one.
  • On exit we notify you straight away so you can revoke system access, we remotely wipe or lock the issued device, and we require its physical return.
  • Confidentiality obligations continue after employment ends.

Last reviewed August 2026. If your compliance team needs something this page does not answer, ask us: a question we cannot answer is one we would rather know about.

Let's extend together

Ready to extend what your business can do?

Tell us where you need capacity. We'll match you with the talent and the model that fit, and handle the rest.