Privacy Policy
Flint Lawyers Pty Ltd (ABN 75 624 650 611)
1. Introduction
- In this Privacy Policy, the terms “Flint”, “we”, “us” or “our” refer to Flint Lawyers Pty Ltd (ABN 75 624 650 611).
- We are committed to protecting personal information we collect from you in accordance with all legal requirements, including but not limited to the Australian Privacy Principles (APPs) and the Privacy Act 1988 (Cth)(Privacy Act). The purpose of this Policy is to inform you about the information we may collect from you, how we will use it or disclose it and how you can contact us.
- This Policy applies to personal information you provide to us in whatever manner you deal with us, whether by visiting our website, through engaging us to act as your lawyers, or in any other dealings you have with us. We may specify additional terms to apply to information you disclose in relation to our performance of legal services for you, and those additional terms supersede anything in this Policy. For employees, any personal information we collect is handled in accordance with their employment agreement and this Policy.
2. The information we collect
- We collect the personal information we need to perform and provide our services as lawyers to our clients, to develop and promote our services and to assist us with complying with our legal and regulatory obligations. The particular information we collect will depend upon the services we provide, though typically this includes your name, address, date of birth, driver’s licence details, birth certificate details, passport details (government identifiers), relationship status, your facial image, employment details and contact details, including social media addresses, and your expertise and interests.
- We may supplement the personal information that you provide with other information that we obtain from our dealings with you or from third parties.
- We are a Registered Entity and are regulated under the AML/CTF Act,as our service portfolio includes designated services. Pursuant to that Act, we are required to collect and verify additional identification information before providing you with designated services, and on an ongoing basis. Depending on your circumstances, this may include government identifiers, the beneficial owners of an organisation, details of directors and controlling persons of organisations and trusts, information about your source of funds or source of wealth, and information about whether you or persons connected with you are politically exposed persons. We collect this information because it is required or authorised by the AML/CTF Act. We will limit what we collect to what is reasonably necessary to meet those obligations.
- To verify identity, we may use electronic verification services provided by third parties. Where identity verification involves the collection of biometric information (for example, comparing a facial image with photo identification), we will seek your consent to use such electronic verification services.
- The nature of the work we carry out for our clients means that there is no effective way for us to deal with clients who wish to remain anonymous or to use a pseudonym when dealing with us. In addition, where the AML/CTF Act applies to the services we provide, we are required by law to identify our clients and cannot act for clients who wish to remain anonymous. If you do not consent to our collection of personal information, we may not be able to provide services to you.
- We may collect information about how you access, use and interact with our website. We do this by using a range of tools, including Google Analytics and Microsoft Clarity. This information may include:
- the location from which you have come to the site and the pages you have visited; and
- technical data, which may include IP address, the types of devices you are using to access the website, device attributes, browser type, language and operating system.
- We use cookies on our website. A cookie is a small text file that the website may place on your device to store information. We may use persistent cookies (which remain on your computer even after you close your browser) to store information that may speed up your experience on future visits to our website. We may also use session cookies (which are removed when you end your browsing session) to help manage the display and presentation of information on the website. You may refuse to use cookies by selecting the appropriate settings on your browser. However, please note that doing so may prevent you from using the full functionality of the website.
3. How we use your personal information
- Personal information that we obtain will be stored, used, disclosed and protected by us in accordance with this Policy. We primarily use or disclose (or both) your personal information:
- to provide our services;
- to communicate with you;
- for administrative purposes;
- to comply with our legal and regulatory obligations — including our customer due diligence, record-keeping and reporting obligations under the AML/CTF Act — and to assist government and law enforcement agencies or regulators;
- to improve the quality of our services;
- for the marketing of our services to you; or
- for job applicants, to consider making offers of employment.
- When we collect personal information from you, this will be for the primary purpose of providing legal services. By providing personal information, you consent to the collection, use and disclosure of personal information (including any sensitive personal information) for that purpose.
- You may provide us with someone else’s personal information. Where you do, we will accept that information on the basis that you have their authority or consent to provide it to us. If you provide us with personal information about other people in connection with customer due diligence (for example, beneficial owners, directors, or signatories), please ensure those people are aware of this Policy.
4. Disclosure of your information
- We may disclose your personal information to third parties we engage with while providing services to you. These third parties may include barristers, other law firms, law enforcement, insurance companies and their agents, regulators, government departments and agencies, experts, delivery organisations, third party suppliers, agents and other service providers.
- These third parties will have access to the information needed to perform their function. By giving your personal information to us, you consent to us disclosing this personal information to third parties for any purpose related to the purposes set out in this Policy.
- We may also disclose personal information where we are required or authorised to do so by law, including to AUSTRAC under the AML/CTF Act. In some circumstances, the law prohibits us from telling you that information has been, or is required to be, disclosed (for example, where the ‘tipping off’ prohibition in the AML/CTF Act applies).
5. Anti-money laundering and counter-terrorism financing
- From 1 July 2026, the AML/CTF Act applies to law firms that provide designated services. Flint Lawyers provides designated services.
- The AML/CTF Act requires Flint Lawyers to collect and verify identification information of the kind described in clause 2.3, keep that information up to date, and assess money laundering and terrorism financing risk prior to and while providing a designated service. Due to the nature of our services, Flint Lawyers has decided to comply with the requirements of the AML/CTF Act in respect of all Flint Lawyers clients from 1 July 2026.
- Records demonstrating our compliance with customer due diligence obligations must be kept for at least seven years after the end of our relationship with you. We aim not to retain copies of full identification documents (such as passports or driver licences) for longer than they are needed: where practicable, we keep a record of the verification we performed rather than copies of the documents themselves, and we take reasonable steps to destroy or de-identify copies once they are no longer required.
- We may be required to report certain matters to AUSTRAC (including suspicious matter reports and reports of certain transactions) without your knowledge or consent. Where the law prohibits us from disclosing that a report has been made or is required, your rights to access personal information and to be notified of disclosures may be limited to that extent.
- We will only collect, use and disclose personal information for AML/CTF purposes to the extent reasonably necessary to comply with our obligations, and we handle that information in accordance with the Privacy Act and this Policy.
6. Direct marketing
- We may use your relevant personal information to tell you about our services and about legal developments that may be of interest to you. If you do not want to receive marketing material from us, please contact us on the details set out at the end of this Policy or use the opt-out facility included in our marketing communications.
7. Disclosure of your information outside Australia
- Where possible, we store your personal information on servers located in Australia. We may also store, process, or back up your personal information on servers located overseas (including through third-party service providers). Given the nature of how data is stored, either in the “cloud” or on third-party servers located at multiple sites, it is not possible for us to advise you of the countries where your personal information may be stored.
- If your matter requires this, and after obtaining your consent, we may disclose your personal information to entities overseas (for example, other law firms, experts or advisers) to provide legal services to you and as allowed by this Policy. These countries will have laws relating to the protection, use, and disclosure of personal information that differ from those that apply in Australia.
8. Security and retention of information
- All reasonable steps are taken to ensure that all personal information is treated confidentially, kept secure, protected against unauthorised use and is only used or disclosed for the purpose for which it was collected. Please be aware that the internet is not a secure environment, and when you provide us with information over the internet you do so at your own risk.
- We keep personal information only for as long as it is needed for the purposes described in this Policy or as required by law. For example, the AML/CTF Act requires us to keep customer due diligence records for at least seven years after the end of our relationship with you, and legal practice rules require us to retain client files for minimum periods. When personal information is no longer required, we take reasonable steps to destroy or de-identify it.
- We maintain processes for responding to data breaches. If a data breach involving your personal information occurs that is likely to result in serious harm, we will notify you and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme under the Privacy Act, subject to any restrictions imposed by law.
9. Access, correction and review of personal information
- In some cases, you have the right to access and review your personal information held by us, subject to exceptions provided by law, including our obligations to provide legal services and to preserve information. Please direct all requests to the Directors in writing at the contact details below. We may charge a small fee towards the cost of administering any request you make.
- In some circumstances, we may be unable to grant access to your personal information — for example, where giving access would be unlawful, would prejudice legal professional privilege or our duties to other clients, or where a secrecy or ‘tipping off’ prohibition under the AML/CTF Act applies. If we refuse a request, we will tell you why, to the extent permitted by law.
- All reasonable steps are taken to update the personal information we hold if the information is not accurate and complete. You may update your personal information by emailing us at info@flint-lawyers.com.au. Please include your name, address and/or email address when you contact us.
10. Use of Artificial Intelligence tools
- From time to time, and where appropriate, we may use enterprise-grade Artificial Intelligence (AI) tools to assist with legal research, drafting, and contract analysis. To protect your personal information, data and confidentiality, we use secure environments within Australia that do not train on client data, and where necessary, we redact sensitive and personal information. All AI-assisted work remains subject to the supervision and professional judgment of our legal team, and our fees reflect the expert review and verification provided. Where AI tools are used in the course of providing legal services to you, we will inform you of this.
- We do not use your personal information in computer programs to make decisions, without human involvement, that could reasonably be expected to significantly affect your rights or interests. If this changes, we will update this Policy to describe the kinds of decisions involved and the kinds of personal information used, as the Privacy Act requires.
11. Complaints and contact details
- Should you wish to contact us regarding this Privacy Policy, or complaints about the use of your personal information, please contact us by email at info@flint-lawyers.com.au. Alternatively, you can contact us at: Flint Lawyers Pty Ltd, Level 4, 501 La Trobe Street, Melbourne, VIC 3000, Attention: The Directors.
- We will acknowledge your complaint within 7 days and aim to provide you with a substantive response within 30 days. If we need more time, we will tell you why and give you an expected timeframe.
- If you are not satisfied with the outcome of your complaint, you can contact the Office of the Australian Information Commissioner on 1300 363 992, via email at enquiries@oaic.gov.au, or at www.oaic.gov.au.
12. Changes to this Policy
- This Policy may change from time to time. Accordingly, we recommend that you check this page from time to time on our website in order to review the current policy.
13. Definitions
Term | Meaning |
AML/CTF Act | Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), as amended (including by the Anti-Money Laundering and Counter-Terrorism Financing Amendment Act 2024 (Cth)), and the rules and instruments made under it. |
APPs | The Australian Privacy Principles set out in Schedule 1 to the Privacy Act. |
AUSTRAC | The Australian Transaction Reports and Analysis Centre, Australia’s AML/CTF regulator and financial intelligence unit. |
Customer due diligence | The customer identification, verification and ongoing monitoring procedures required by the AML/CTF Act before and while providing designated services. |
Designated services | Services listed in section 6 of the AML/CTF Act, which from 1 July 2026 include certain professional services provided by law firms. |
Personal information / sensitive information | Have the meanings given in section 6(1) of the Privacy Act. |
Privacy Act | Privacy Act 1988 (Cth). |
Policy owner | Directors of Flint Lawyers Pty Ltd |
Approved by | Directors of Flint Lawyers Pty Ltd |
Approval date | 30/07/2026 |
Next review | 30/07/2027 |
Version | 1.0 |