Legal Consolidated Privacy, Confidentiality and Data Handling Policy
See also:
- Legal Consolidated's Online Terms
- Legal Consolidated's Security
See also:
Legal Consolidated Barristers & Solicitors is an Australian law firm. In this policy, 'Legal Consolidated', 'we', 'us' and 'our' mean Legal Consolidated Barristers & Solicitors and, where the context permits, our principals, lawyers, employees, contractors and authorised representatives.
This policy explains how we collect, hold, use and disclose personal information when you use our website, create an account, build a legal document, communicate with us, deal with us through a lawyer, accountant, financial planner or other adviser, or otherwise interact with Legal Consolidated.
This policy should be read with our Online Terms. The Online Terms deal with the legal document-building service. This policy deals with privacy, confidentiality, legal professional privilege and data handling.
We respect privacy and handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, our professional obligations as an Australian law firm, and other laws that apply to our online legal document service.
Privacy law is one part of a larger professional framework. Because we are a law firm, confidentiality, legal professional privilege, duties to the court, conflict obligations, AML/CTF obligations, sanctions obligations, court orders and other professional obligations may also affect how information is handled.
Where privacy law permits exceptions or where another law requires or permits collection, use, retention or disclosure, we may rely on those exceptions or comply with those other obligations.
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not and whether it is recorded in a material form or not.
The kinds of personal information we collect depend on how you deal with us and which document you build.
Some documents may involve sensitive information. This may include health information, family information, religious or cultural information, criminal record information, biometric or identity information, membership of professional or trade associations, financial information, tax information, estate planning information and information about vulnerable people.
We collect sensitive information only where it is reasonably necessary for our functions or activities, where you consent, where the information is provided to us for the document build, where the law permits or requires it, or where it is necessary for legal, regulatory, professional, AML/CTF, sanctions, identity, authority, risk, complaint, insurance or dispute purposes.
We usually collect personal information directly from you through our website, online forms, account system, document-building questions, email, telephone, document portals and other communications.
We may also collect personal information from other sources where appropriate.
If you provide us with personal information about another person, you must have authority to do so and, where reasonable, tell that person about this policy.
We collect, hold, use and disclose personal information for the purposes of operating Legal Consolidated and providing our online legal document service.
If requested information is not provided, or if we cannot verify information to our satisfaction, we may be unable to create an account, build a document, release a document, provide a refund, communicate with an adviser, complete an AML/CTF or sanctions check, respond to a request, or continue to provide the online service.
We may disclose personal information where reasonably necessary for the purposes described in this policy, where you consent, where disclosure is required or authorised by law, or where disclosure is consistent with our professional obligations.
Recipients may include:
We do not sell personal information.
We use online systems and service providers. Personal information may be stored, accessed, processed or backed up using cloud services or technology providers located in Australia or overseas.
Where it is practicable to identify likely countries, overseas recipients or systems may be located in countries such as the United States, the United Kingdom, the European Union, New Zealand, Singapore, Canada or other countries where our service providers or their infrastructure operate.
Where privacy law requires it, we take reasonable steps in the circumstances to address cross-border disclosure of personal information.
We may use cookies, pixels, local storage, server logs, analytics tools and similar technologies to operate, secure, measure and improve our website and online document-building system.
These technologies may help us remember preferences, maintain sessions, protect accounts, detect errors, prevent misuse, understand website traffic, improve content and measure the performance of pages, hints, videos and document-building workflows.
You can usually control cookies through your browser settings. If cookies or similar technologies are disabled, parts of the website or document-building system may not work properly.
Credit card payments are handled by our merchant facility through its secure payment gateway. Your card number, expiry date and CVV are entered into and processed by the merchant facility, not by Legal Consolidated, and cannot be viewed by us.
Your full credit card details do not pass through, and are not stored on, Legal Consolidated's website, servers, database, email system or document-building system. This is standard merchant facility practice.
For administration, reconciliation, refunds, fraud prevention and record keeping, the merchant facility may provide us with limited payment information, such as the cardholder's name, payment amount, payment date, transaction reference, approval status and the last four digits of the card.
As an Australian law firm, we owe professional duties of confidentiality. We keep confidential information confidential in accordance with our professional obligations.
Confidentiality is not absolute. We may use or disclose information where required or authorised by law, where necessary for legal professional obligations, where permitted by the client, where necessary to defend or enforce our rights, where required for AML/CTF, sanctions, suspicious matter reporting, identity checks, professional indemnity, complaints, audits, cyber security, court orders, regulatory enquiries or other lawful purposes.
Because Legal Consolidated is a law firm, some communications may attract legal professional privilege or client legal privilege. Privilege belongs to the client and may be lost or waived by conduct.
Not every communication with us is privileged. Privilege may not protect information that we are required or permitted by law to collect, retain, use or disclose.
Legal professional privilege is different from privacy and confidentiality. Privacy concerns personal information. Confidentiality concerns information we must keep confidential. Privilege concerns protection from compulsory disclosure in particular legal settings.
We may use technology, automation, document assembly systems, expert systems, artificial intelligence and other tools to build, test, improve, review, validate and deliver online legal documents and website content.
We do not use public artificial intelligence systems in a way that intentionally discloses confidential client information contrary to our professional obligations.
Where we use AI or automated tools, we apply confidentiality controls that we consider appropriate for the nature of the information and the work. We do not treat the use of approved internal or controlled tools as permission for public disclosure of confidential information or waiver of privilege.
Our online document-building system uses questions, answers and logic to build documents. The user remains responsible for selecting the document, entering data, checking data and confirming that answers are accurate and complete.
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, unauthorised modification and unauthorised disclosure.
Security measures may include secure website connections, password controls, access controls, logging, backups, cyber security tools, staff confidentiality obligations, service provider controls, document version control and other administrative, technical and physical safeguards.
No online service is risk-free. You are responsible for keeping your account credentials secure, logging out of shared devices, checking suspicious emails or payment requests by telephone, and telling us promptly if you suspect unauthorised access or misuse.
If we become aware of a data breach, we assess it and respond in accordance with our legal and professional obligations.
Where the Notifiable Data Breaches scheme applies and a data breach is likely to result in serious harm, we notify affected individuals and the Office of the Australian Information Commissioner as required by law.
We retain personal information for as long as reasonably necessary for the purposes for which it was collected, for our legal and professional obligations, for record keeping, for insurance and risk management, for complaints and disputes, for cyber security, and where required or permitted by law.
Different records may be kept for different periods. AML/CTF, tax, legal profession, limitation period, insurance, audit, complaint or dispute requirements may require or justify longer retention.
When information is no longer required, we may delete, de-identify, archive or securely destroy it, subject to our legal and professional obligations.
You may ask us to give you access to personal information we hold about you or to correct personal information that is inaccurate, out of date, incomplete, irrelevant or misleading.
We may need to verify your identity before responding. We may refuse access or correction where the law permits, including where access would affect another person's privacy, breach confidentiality, prejudice legal proceedings, reveal commercially sensitive information, undermine security, interfere with AML/CTF or sanctions obligations, or otherwise be unlawful or inappropriate.
If we refuse a request, we will explain the reason where it is reasonable and lawful to do so.
We may send legal updates, educational material, service messages, website information or marketing communications where permitted by law.
You may opt out of marketing communications by using the unsubscribe function or contacting us. We may still send service, account, document, compliance, security or legal notices that are not marketing.
If you have a privacy complaint, contact Legal Consolidated first using the contact details below and mark the communication 'Privacy Complaint'. Please provide enough detail for us to understand and investigate the issue.
We will consider the complaint and respond within a reasonable time.
If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
We may update this policy from time to time by publishing an updated version on our website or otherwise making it available.
The current version published or made available by Legal Consolidated applies from the time it is published or made available, unless we state otherwise.
Legal Consolidated Barristers & Solicitors ABN 94 936 003 432
Website: www.legalconsolidated.com.au
Email: [email protected]
Email: [email protected]
Postal: Post Office Box 5169, Dalkeith, WA, 6009
Head office: 18 Stirling Highway, Nedlands, WA, 6009