North Star Lawyers Pty Limited (ACN 692 036 070) trading as Roser Lawyers (“Roser Lawyers”,
“we”, “us” or “our”) is committed to protecting the privacy of personal information we hold. This
Privacy Policy explains how we collect, hold, use and disclose personal information, in accordance
with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
This Privacy Policy applies to personal information we collect through our website at
www.roserlawyers.com.au, in the course of providing legal services, and otherwise in the ordinary
course of our business. It does not apply to our treatment of employee records, which is dealt with
separately and is generally exempt from the APPs under the Privacy Act.
What Personal Information We Collect
The personal information we collect depends on the nature of our dealings with you. It may include:
- your name, date of birth, residential and postal address, telephone number and email
address; - information relevant to the legal matter for which you engage us, including financial,
property, business and (where relevant) health information; - if you are a company, trust or other entity, information about your directors, shareholders,
trustees, partners, settlors, beneficiaries and beneficial owners; - identification and verification documents (such as your driver’s licence, passport, or
company extract) and information about the source of funds or source of wealth relevant to
your matter, which we collect in order to meet our obligations under the Anti-Money
Laundering and Counter-Terrorism Financing Act 2006 (Cth) (“AML/CTF Act”); - information you provide when you contact us, request a consultation, or otherwise
communicate with us through our website; and - technical information collected automatically when you visit our website, such as your IP
address, browser type, device information and browsing activity on our site.
Where reasonably practicable, we only collect sensitive information (such as health information)
with your consent, or where otherwise permitted or required by law.
How We Collect Personal Information
We collect personal information:
- directly from you, including when you instruct us, complete a form on our website, or
otherwise communicate with us; - from third parties, including other parties to your matter, opposing parties, courts and
tribunals, government agencies, other solicitors and barristers, and (where relevant)
adverse parties; - from identity verification and credit reporting providers we engage to assist with our
obligations under the AML/CTF Act, currently InfoTrack; and - from publicly available sources, such as public registers, where relevant to your matter.
Why We Collect, Hold, Use and Disclose Personal Information
We collect, hold, use and disclose personal information for the following purposes:
- to provide legal advice and services to you and to manage your matter;
- to comply with our obligations under the Legal Profession Uniform Law (NSW) and the
Legal Profession Uniform General Rules, including client identification (Rule 93) and trust
account record-keeping (Rule 47); - to comply with our obligations under the AML/CTF Act, including client due diligence,
ongoing monitoring, and reporting obligations to the Australian Transaction Reports and
Analysis Centre (AUSTRAC) (see clause 5 below); - to comply with our duties to the courts and other regulatory bodies;
- to manage billing, trust account transactions, and the general administration of our practice;
and - to respond to enquiries or consultation requests made through our website.
Disclosure of Personal Information
Depending on the nature of your matter, we may disclose your personal information to:
- courts, tribunals and their registries;
- the other party or parties to your matter, and their legal representatives;
- barristers, experts and other professional advisers engaged in relation to your matter;
- the Office of State Revenue, PEXA Limited, and Land Registry, where relevant to property
transactions; - AUSTRAC, and other government, regulatory or law enforcement agencies, where we are
required or authorised by law to do so; - identity verification and credit reporting providers we engage for the purposes of client due
diligence, currently InfoTrack; and - our service providers, including our practice management, IT and document storage
providers, who assist us to deliver our services.
We do not disclose personal information to overseas recipients unless your instructions involve
dealing with parties located overseas, in which case we may disclose limited personal information
to overseas recipients associated with that matter, to the extent necessary to carry out your
instructions.
Anti-Money Laundering and Counter-Terrorism Financing (AML/CTF)
As a legal practice that provides certain services regulated under the AML/CTF Act (“designated
services”), we are required to collect and verify personal information about our clients and, where
relevant, associated persons such as beneficial owners, directors and trustees, before and during
the course of acting for you (“Client Due Diligence”).
Our AML/CTF obligations mean that we may also:
- ask you to provide updated information where your circumstances change, including
changes in beneficial ownership or control of an entity; - screen you, and any associated persons, against politically exposed persons (PEP) and
sanctions lists; - decline to act, or delay the provision of services, until Client Due Diligence has been
completed to our satisfaction; and - report certain transactions or suspicious matters to AUSTRAC.
Where we make, or are considering making, a report to AUSTRAC, we are prohibited by law from
disclosing this to you or any other person in the limited circumstances set out in section 123 of the
AML/CTF Act. Further detail about our AML/CTF obligations is set out in our Costs Agreement and
General Terms of Business, provided to you at the commencement of any engagement.
Cookies and Website Analytics
Our website may use cookies and similar technologies to improve your browsing experience,
understand how visitors use our site, and inform our marketing. This may include the use of
analytics tools such as Google analytics. Most cookies used on our website do not identify you
personally.
You can control or disable cookies through your browser settings; however, this may affect the
functionality of our website. We do not use your website browsing information to make any
automated decision that has a legal or similarly significant effect on you.
Data Quality and Security
We take reasonable steps to ensure the personal information we collect, use and disclose is
accurate, complete and up to date. We store personal information electronically, including in our
practice management system, and in hard copy at our offices. We take reasonable technical and
organisational measures to protect personal information from misuse, interference, loss, and
unauthorised access, modification or disclosure, including restricting access to authorised
personnel.
How Long We Retain Personal Information
We generally retain client files and personal information for 7 years from the completion or
termination of your matter, after which they may be securely destroyed, unless we are otherwise
required to retain them (for example, documents held in safe custody are retained indefinitely in
accordance with your instructions).
Personal information collected for the purposes of Client Due Diligence and our AML/CTF
obligations is retained for a minimum of 7 years in accordance with the AML/CTF Act, which may
be longer than the general retention period referred to above.
Access to, and Correction of, Your Personal Information
You may request access to, or correction of, the personal information we hold about you by
contacting our Privacy Officer using the details set out below. We will respond to your request
within a reasonable period. We may charge a reasonable fee to cover the cost of retrieving and
providing access to your information, but will not charge for making the request itself. There may be
circumstances in which we are not required to provide access, in accordance with the Privacy Act,
in which case we will explain our reasons.
How to Make a Complaint
If you have a concern about how we have handled your personal information, please contact our Privacy Officer, Raymond Roser, Director, using the contact details below. We will investigate and respond to your complaint within a reasonable period.
If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.
Changes to This Policy
We may update this Privacy Policy from time to time. The most current version will be available on
our website. This Privacy Policy was last updated in [INSERT MONTH AND YEAR].
Contact Us
If you have any questions about this Privacy Policy, or wish to access or correct your personal
information, please contact us:
- Post: Suite 404, Level 4, 74 Pitt Street, Sydney NSW 2000, or Suite 710, Level 7, 288
Forest Road, Hurstville NSW 2220 - Phone: (02) 9232 3792
- Email: info@roserlawyers.com