Privacy
Privacy Policy
How Carter Green Lawyers (Mind Law Group Pty Ltd trading as Carter Green Law Practice) collects, holds, uses and discloses your personal information.
1. Introduction
- Mind Law Group Pty Ltd trading as Carter Green Law Practice ABN 74 577 489 512, also trading as Carter Green Lawyers, is referred to in this Privacy Policy as Carter Green Lawyers, we, us or our.
- This Privacy Policy explains how we collect, hold, use and disclose personal information. It also explains how you may request access to or correction of personal information we hold about you, and how you may make a privacy complaint.
- This Privacy Policy operates in addition to our professional obligations as solicitors, including our duties of confidentiality, legal professional privilege, duties to the court, undertakings, and obligations under applicable professional conduct rules.
2. Application of this Privacy Policy
- This Privacy Policy applies to personal information we collect, hold, use or disclose to the extent that the Privacy Act 1988 (Cth) applies to that information or to our handling of that information.
- To the extent that we are a small business operator under the Privacy Act, this Privacy Policy is intended to apply to personal information we collect, hold, use or disclose for the purposes of, or in connection with, our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and related rules.
- We may manage other personal information in a manner consistent with this Privacy Policy as a matter of good practice, professional confidentiality and risk management. However, unless the Privacy Act otherwise applies, this Privacy Policy is not intended to constitute a voluntary opt-in to Privacy Act regulation for information or activities that are not otherwise regulated.
- Nothing in this Privacy Policy limits or reduces our professional obligations as solicitors.
3. Personal information we collect
- The types of personal information we collect depend on the matter, the services requested, and any legal, professional or regulatory obligations that apply.
- Personal information we may collect includes:
- identity information, including names, dates of birth, signatures, photographic identification, citizenship or residency information, directorships, offices held and authority to act;
- contact information, including residential addresses, postal addresses, email addresses and telephone numbers;
- professional and business information, including occupation, employer, position, company details, trust details, business interests, shareholding information, beneficial ownership information and control information;
- financial information, including bank account details, payment information, billing details, source of funds information, source of wealth information, transaction information and tax information;
- matter-related information, including information relevant to legal advice, conveyancing, leasing, property transactions, commercial transactions, business sales, estate planning, estate administration, disputes and other legal matters;
- communications, including emails, letters, file notes, telephone notes, meeting notes, messages and records of instructions;
- website and technical information, including IP address, browser type, device information, pages visited and information collected through cookies or similar technologies; and
- sensitive information, where relevant and lawful, including health information, criminal history information, family information, financial vulnerability information, political exposure information and other information relevant to our legal services or regulatory obligations.
- We collect personal information where it is reasonably necessary for our functions and activities, including providing legal services, complying with professional obligations, complying with AML/CTF obligations, managing risk and operating our legal practice.
4. Identity verification and AML/CTF obligations
- We may be required to collect and verify identity information when providing services that are regulated under the AML/CTF regime.
- This may include collecting information about:
- clients and prospective clients;
- directors, shareholders, trustees, beneficiaries, appointors, attorneys, agents and authorised representatives;
- beneficial owners and persons who ultimately own or control a company, trust or other entity;
- the nature, purpose and circumstances of a transaction or matter;
- source of funds and source of wealth; and
- other information required for customer due diligence, ongoing customer due diligence, risk assessment, record keeping and reporting obligations.
- We may use identity verification providers, electronic conveyancing systems, government registers, public registers and other reliable sources to verify information.
- If you do not provide information we reasonably require for identity verification, AML/CTF compliance or professional obligations, we may be unable to act for you, continue acting for you, complete a transaction, or provide the requested service.
5. How we collect personal information
- Where reasonable and practicable, we collect personal information directly from the individual concerned.
- We may collect personal information when you:
- contact us by telephone, email, website form, post or in person;
- engage us or enquire about engaging us;
- provide instructions, documents or information to us;
- complete a form, client information sheet, verification process or questionnaire;
- participate in a legal transaction, proceeding or matter in which we are involved;
- visit our website or interact with our online services; or
- apply for employment with us.
- We may also collect personal information from third parties, including:
- our clients;
- other lawyers, conveyancers and professional advisers;
- real estate agents, accountants, financial advisers, brokers and consultants;
- courts, tribunals, government agencies and regulators;
- public registers, including titles, ASIC, PPSR, court and insolvency registers;
- identity verification providers, electronic conveyancing platforms and search providers;
- witnesses, experts, counterparties and other persons involved in a matter;
- referrers and lead sources; and
- recruitment agencies, referees and previous employers.
6. Anonymity and pseudonymity
- You may access general information on our website without identifying yourself.
- You may also make a general enquiry without providing full identity information. However, before we provide legal services, open a file, give advice specific to your circumstances, act in a transaction or proceeding, receive or deal with money, or perform work requiring identity verification or client due diligence, we must identify the client and any person giving instructions on the client’s behalf.
- It is not lawful or practicable for us to act for an unidentified person, or for a person using a pseudonym, in a legal matter. This is because we must know who we are dealing with, who we are acting for, whether a person has authority to give instructions, whether there is a conflict of interest, and whether we can comply with our professional, legal, regulatory and AML/CTF obligations.
- If you do not provide information we reasonably require, we may be unable to respond to your enquiry, act for you, continue acting for you, or complete a transaction.
7. Why we collect, hold, use and disclose personal information
- We collect, hold, use and disclose personal information for the primary purpose of providing legal services and operating our legal practice.
- This includes:
- taking instructions and communicating with clients and others;
- providing legal advice and representation;
- preparing, reviewing and negotiating legal documents;
- conducting conveyancing, leasing, property, commercial, estate, succession and business matters;
- conducting searches, due diligence and investigations;
- verifying identity and authority to act;
- complying with AML/CTF obligations;
- managing client files and legal matters;
- billing, collecting fees and enforcing our rights under a costs agreement, retainer or other arrangement;
- managing trust money or controlled money where applicable;
- complying with legal, professional, regulatory and insurance obligations;
- managing conflicts, complaints, claims and professional indemnity matters;
- operating, maintaining and improving our systems, website and business processes;
- managing cybersecurity, document storage, archiving and record keeping; and
- maintaining records.
- We may also use personal information for related secondary purposes, including internal training, quality assurance, auditing, cybersecurity, system improvement, risk management, relationship management and sending legal updates or information about our services. You may opt out of marketing communications at any time.
8. Disclosure of personal information
- We may disclose personal information where reasonably necessary for the purposes described in this Privacy Policy, where authorised by you, or where required or permitted by law.
- Recipients may include:
- courts, tribunals, regulators and government agencies;
- other parties to transactions or proceedings and their lawyers or advisers;
- barristers, mediators, experts, investigators, accountants, financial advisers, agents and consultants;
- identity verification providers, electronic conveyancing platforms and search providers;
- banks, financial institutions, payment processors and trust account service providers;
- insurers, professional indemnity insurers, brokers and claims managers;
- IT, cloud, document management, practice management, archiving, cybersecurity and other service providers;
- debt recovery providers, costs assessors and enforcement agencies;
- contractors and external service providers who assist us to operate our practice; and
- any person you authorise us to disclose information to.
- We do not sell personal information.
- Nothing in this Privacy Policy reduces our professional duties of confidentiality. Where information is confidential, we will only disclose it where permitted by law, professional rules, court rules, your instructions or another applicable basis.
9. Service providers and data storage
- We use third-party service providers to assist us to operate our legal practice, including legal practice management systems, document management systems, search providers, identity verification providers, electronic conveyancing platforms, cloud storage, email, cybersecurity, archiving, accounting, payment and IT support services.
- Our current principal technology systems are selected and configured with the objective of storing core client and matter information in Australia where reasonably available.
- However, some services may involve technical support, security monitoring, diagnostics, metadata, backups, integrations or other processing in accordance with the provider’s applicable terms and security arrangements.
- We take reasonable steps to use reputable service providers and to ensure that personal information is handled consistently with our legal, professional and confidentiality obligations.
10. Overseas disclosure
- Having regard to our current principal technology systems and ordinary practice, we do not use overseas disclosure of personal information as a routine feature of our legal practice.
- However, we may disclose personal information to overseas recipients where reasonably necessary for a matter, where authorised by you, or where required or permitted by law. This may include disclosure:
- to overseas clients, counterparties, beneficiaries, executors, attorneys, directors, shareholders, trustees, advisers or other persons involved in a matter;
- to overseas lawyers, accountants, financial advisers, experts, agents, regulators, courts, tribunals or government authorities;
- where a transaction, estate, company, trust, asset, bank account, party or document has an overseas connection;
- where you instruct or authorise us to communicate with an overseas recipient; or
- where a service provider’s support, security, storage, processing or backup arrangements involve access from outside Australia.
- The countries in which overseas recipients may be located will depend on the particular matter.
- Where the Privacy Act applies and we disclose personal information to an overseas recipient, we will take reasonable steps required by law in relation to that disclosure.
11. Website, cookies and online enquiries
- When you visit our website, we may collect technical information such as IP address, browser type, device information, pages visited and the time and date of your visit.
- Our website may use cookies, analytics tools or similar technologies to improve website functionality, understand usage and improve our services.
- Our website may contain links to third-party websites. We are not responsible for the privacy practices of those websites.
- Submitting an enquiry through our website does not, by itself, create a solicitor-client relationship. Information submitted through the website will be handled in accordance with this Privacy Policy and our professional obligations.
12. Artificial intelligence and automated tools
- We use technology, including automation and AI-assisted tools, to support administrative, research, drafting, review, summarisation or practice management tasks. These tools are included within Leap practice management software.
- We will do so having regard to our duties of confidentiality, legal professional privilege, professional conduct, supervision, cybersecurity and information security.
- We do not currently use automated decision-making systems to make decisions that have a legal or similarly significant effect on clients or other individuals without human review.
13. Security of personal information
- We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
- These steps may include secure legal practice management systems, access controls, password protection, multi-factor authentication where available, secure document storage, staff confidentiality obligations, physical office security, cybersecurity support, backup processes and secure destruction or archiving practices.
- No electronic system is completely secure. We cannot guarantee that unauthorised access, cyber incidents or data loss will never occur, but we take reasonable steps to reduce those risks.
14. Retention and destruction
- We retain personal information for as long as reasonably necessary for the purpose for which it was collected, for legal and professional obligations, for AML/CTF record keeping obligations, for limitation periods, for insurance purposes and for legitimate business purposes.
- When information is no longer required, we may securely destroy, delete, de-identify or archive it, subject to our legal and professional obligations.
- Secure destruction may include secure deletion of electronic records, secure destruction of physical documents, or use of a secure destruction provider.
15. Access and correction
- You may request access to personal information we hold about you.
- You may also request that we correct personal information if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading.
- Requests should be made to our Privacy Officer using the contact details below.
- We will respond within a reasonable period. We may need to verify your identity before responding.
- We may refuse access or correction where permitted by law, including where access would breach confidentiality, legal professional privilege, court obligations, legal professional obligations, the privacy of another person, or another applicable exemption.
- If we refuse access or correction, we will provide reasons where reasonable and lawful to do so.
- We may charge a reasonable fee for access requests where permitted, including for locating, retrieving, reviewing and providing information.
16. Privacy complaints
- If you have a question or complaint about how we have handled personal information, please contact our Privacy Officer.
- We ask that complaints be made in writing and include enough detail for us to understand and investigate the issue.
- We will aim to acknowledge a complaint within 5 business days and respond within a reasonable period, usually within 30 days. If we require more time, we will let you know.
- If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner or the relevant legal services regulator.
17. Changes to this Privacy Policy
- We may update this Privacy Policy from time to time to reflect changes in our practices, technology, service providers or legal obligations.
- The current version will be available on our website.
18. Contact details
Privacy Officer
- PracticeCarter Green Lawyers
- PostPO Box 505, Robina QLD 4226
- Emailinfo@cartergreen.com.au
- Phone(07) 5575 9555
19. Office of the Australian Information Commissioner
If you are not satisfied with our response to your privacy complaint, or if we are unable to resolve your concerns, you may contact the Office of the Australian Information Commissioner.
Office of the Australian Information Commissioner
- PostGPO Box 5288, Sydney NSW 2001
- Phone1300 363 992
- WebsiteOAIC website
You may also contact the relevant legal services regulator if your concern relates to our professional obligations as solicitors.
