This policy explains how Southbank Legal Pty Ltd (Southbank Legal, we, us, our) collects, holds, uses, discloses and protects personal information. It applies when you visit our website, make an enquiry, engage us, are involved in a matter on which we act, work with us as a service provider or otherwise interact with the practice.
We manage personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to us. Our privacy obligations operate alongside our professional duties as a law practice, including duties concerning confidentiality and legal professional privilege.
1. The information we collect
The information we collect depends on our relationship with you and the work involved. It may include:
- Identity and contact information: your name, date of birth, address, email address, telephone number, occupation, signature and copies or details of identity documents.
- Conflict and relationship information: the names of related, opposing and interested parties, your role in a building or transaction, corporate positions and relevant personal or business relationships.
- Matter information: instructions, facts, correspondence, contracts, plans of subdivision, owners corporation records, expert reports, photographs, witness material, court or tribunal documents and other evidence.
- Financial information: billing details, account information, fee and levy records, transaction details, trust-account information and information relevant to financial hardship or recovery.
- AML/CTF information: customer and beneficial ownership information, authority to act, ownership and control structures, politically exposed person and sanctions information, and, where relevant, source-of-funds and source-of-wealth information.
- Sensitive information: information about health, disability, racial or ethnic origin, political or religious associations, criminal history or other sensitive matters where relevant to an enquiry, legal matter, employment or our legal obligations.
- Website and security information: IP address, browser and device information, request logs, security signals, form-submission data and similar technical information used to deliver and protect the website.
- Business and recruitment information: information about suppliers, professional contacts, job applicants, personnel and referees.
2. How we collect information
We usually collect information directly from you through conversations, email, forms, documents and the work we perform. We may also collect information from:
- your authorised representatives, owners corporation, committee, manager, insurer, broker, accountant or other adviser;
- other parties, their lawyers, witnesses, experts, barristers and service providers;
- courts, tribunals, regulators, government agencies and law-enforcement bodies;
- public and subscription registers, title and property records, company and business searches, sanctions and politically exposed person databases, and other lawful information sources; and
- our website, email, hosting and cybersecurity systems.
If you give us personal information about another person, you should have an appropriate basis for doing so and, where practicable, make them aware of this policy.
3. Why we collect, use and disclose information
We may use personal information to:
- receive, assess and respond to enquiries and referrals;
- conduct conflict checks and decide whether we can accept or continue an engagement;
- verify identity, authority and beneficial ownership and comply with AML/CTF and sanctions obligations;
- provide legal advice and representation, communicate with you and progress a matter;
- open, administer and close files, issue invoices, receive payments and manage trust money where applicable;
- engage counsel, experts, consultants and other providers required for a matter;
- meet professional, court, tribunal, regulatory, insurance, audit, reporting and record-keeping obligations;
- manage complaints, disputes, risk, quality assurance and professional indemnity matters;
- operate, secure, maintain and improve our website, systems and business;
- recruit, engage and manage personnel and suppliers; and
- send service updates or insights where you have requested them or where otherwise permitted, with an opportunity to opt out.
If required information is not provided, we may be unable to complete a conflict or identity check, accept instructions, provide a designated service, progress a matter or meet a legal obligation.
4. Initial enquiries, confidentiality and privilege
Sending an enquiry does not create a lawyer-client relationship and does not mean we can act. Keep an initial enquiry brief and non-confidential. Do not send identity documents, privileged material, sensitive records or a detailed account of allegations until we have completed an appropriate conflict check and provided a suitable way to send information.
We take care with information received from prospective clients, but you should not assume that an unsolicited communication is legally privileged or that it prevents us from acting for another person. If we accept an engagement, our professional duties of confidentiality apply independently of this policy. Legal professional privilege is a separate doctrine and does not attach to every confidential communication or document.
5. Who we may disclose information to
Where appropriate for the purpose collected, authorised by you, or permitted or required by law, we may disclose personal information to:
- our directors, lawyers, employees, contractors and related service personnel;
- barristers, experts, investigators, consultants, mediators, process servers, search providers and other professionals involved in a matter;
- courts, tribunals, registries, dispute-resolution bodies, government agencies, regulators, law-enforcement bodies and AUSTRAC;
- other parties to a transaction or dispute and their advisers where necessary to act on instructions or progress the matter;
- banks, payment providers, auditors, accountants, insurers, brokers and professional advisers;
- providers of practice management, document storage, identity verification, AML/CTF screening, email, communications, cybersecurity, website hosting and support services; and
- another person where you consent, or where disclosure is otherwise authorised or required.
We do not sell personal information.
6. Technology providers and overseas processing
Our website enquiry system uses Cloudflare for hosting and security, Resend for email transmission and Microsoft 365 for business email and information systems. We may use other carefully selected providers for legal practice management, document storage, verification, screening and professional support.
These providers may store, process, support or back up information in Australia and in other jurisdictions in which they or their subcontractors operate, potentially including the United States. The location can depend on the service configuration and may change. Where the Australian Privacy Principles apply to an overseas disclosure, we take the steps required by law and consider privacy, confidentiality and security in selecting and managing providers.
7. Security, retention and data breaches
We use administrative, physical and technical safeguards designed to protect information from misuse, interference, loss and unauthorised access, modification or disclosure. Safeguards may include access controls, authentication, secure cloud systems, staff procedures, backups and provider due diligence. No internet transmission or storage system can be guaranteed to be completely secure.
We retain information for as long as reasonably required for the relevant enquiry or engagement and to meet professional, legal, insurance, tax, AML/CTF, dispute and record-keeping obligations. When information is no longer required, we take reasonable steps to destroy or de-identify it where lawful and practicable. Some information may remain for a period in secure backups or where destruction is prevented by law, legal hold or professional obligation.
We assess suspected data breaches and, where the Notifiable Data Breaches scheme applies, notify affected individuals and the Office of the Australian Information Commissioner when required.
8. Website data, cookies and external links
The site may use essential cookies or similar technologies required for hosting, security and anti-spam controls. If Cloudflare Turnstile is enabled, Cloudflare will process technical signals to assess whether a submission is legitimate. We do not currently use advertising cookies or behavioural advertising.
Our website may link to courts, regulators and other third parties. Their privacy practices are governed by their own policies, not this policy.
9. Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details below and describe the information concerned. We may need to verify your identity.
Access or correction may be limited where an exception applies, for example, to protect another person's privacy, preserve privilege, comply with legal process or avoid prejudice to a matter. Where required, we will explain a refusal and the available complaint process. We do not charge for making a request, although the law may permit a reasonable charge for giving access in some circumstances.
10. Privacy questions and complaints
Send privacy questions, access requests, correction requests or complaints to:
Privacy Officer
Southbank Legal Pty Ltd
contact@southbanklegal.com.au
Southbank, Melbourne, Victoria
Please provide enough detail for us to understand the issue. We will assess the matter, may request further information and will respond after a reasonable investigation. If the Privacy Act applies and you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
11. Changes to this policy
We may update this policy when our practice, providers, technology or legal obligations change. The effective date above identifies the current version. A materially revised policy will be published on this page.
This policy should be read with our website terms of use and, for clients, the applicable engagement letter and costs agreement. If those documents address a specific matter differently, the engagement documents govern the legal services while this policy continues to describe our general information-handling practices.
