YOU LEGAL PTY LTD PRIVACY POLICY
Updated as of 1 July 2026
DEFINITIONS
AML/CTF Act means the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
AML/CTF Framework means the AML/CTF Act, the AML/CTF Rules and AUSTRAC issued guidance.
AML/CTF Rules means the Anti-Money Laundering and Counter-Terrorism Financing Rules 2025 (Cth), made under the AML/CTF Act.
APPs means the Australian Privacy Principles in Schedule 1 of the Privacy Act.
AUSTRAC means the Australian Transaction Reports and Analysis Centre.
Designated Services means the services listed in Table 6 of Section 6 of the AML/CTF Act that are provided by a legal practitioner, law practice or other relevant professional.
KYC Information means information sufficient to establish initial customer due diligence matters on reasonable grounds, or to fulfil ongoing customer due diligence obligations, under the AML/CTF Framework.
OAIC means the Office of the Australian Information Commissioner.
Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not. The Scope section below explains the personal information to which this Privacy Policy applies.
Privacy Act means the Privacy Act 1988 (Cth).
Sensitive Information means personal information that includes information or an opinion about an individual’s racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, criminal record, or health, genetic or biometric information.
Services means our legal services and related client onboarding, verification, administrative and compliance activities we provide, including any AML/CTF checks we are required to complete.
We, us and our means You Legal Pty Ltd ACN 166 501 873.
Website means our website, www.youlegal.com.au
INTRODUCTION AND PURPOSE
Protecting your privacy and treating your Personal Information in accordance with Australian privacy laws is of paramount importance to us.
This Privacy Policy explains what Personal Information we collect, why we collect Personal Information and how we collect, use, disclose, store and protect your Personal Information when you visit our Website, use our corporate and commercial legal services and resources, interact with us on social media, attend our webinars or continue to use our Services. This Privacy Policy also applies to Services delivered by our independent contractors under our systems and by our third-party IT providers, who manage our email and security infrastructure.
As a law firm, we may collect and handle Personal Information in connection with the conduct of your matter, our professional obligations and our obligations under the AML/CTF Rules and the Act. We will take reasonable steps to ensure that Personal Information collected for AML/CTF purposes is handled responsibly, transparently and securely. This includes ensuring that individuals are given information about how their Personal Information may be collected, held, used and disclosed for AML/CTF purposes, and how they may request access to, or correction of, Personal Information we hold about them.
We will keep Personal Information confidential, except where disclosure is authorised by you, necessary for the conduct of your matter, required or authorised by law, or otherwise permitted under our professional or legal obligations.
We are committed to maintaining the highest standards of privacy protection for sensitive information.
This Privacy Policy also explains how to contact us to request access to, correct, update or delete any Personal Information provided to us, or make a complaint if you have concerns about how your Personal Information has been handled.
We comply with the Privacy Act, the APPs and any other relevant law, including the AML/CTF Act and the AML/CTF Rules.
We maintain secure records of all user consents and withdrawals to ensure compliance with data protection regulations and to respect your privacy choices. These records are kept for the duration of our relationship with you and for a reasonable period thereafter as required by applicable laws.
Unless otherwise indicated by the context, words importing the singular include the plural and vice versa.
CHANGES THAT WE MAKE TO OUR PRIVACY POLICY
We may change this Privacy Policy from time to time. Any updated versions of this Privacy Policy will be posted on our Website. We recommend that you check our Website periodically to review our current Privacy Policy. If we make any changes to this Privacy Policy that materially affect our practices with regard to the Personal Information we have previously collected from you, we will endeavour to provide you with notice in advance of such change by highlighting the change on the Website or, where practical, by emailing you.
COLLECTION OF YOUR PERSONAL INFORMATION BY THIRD PARTIES
This Privacy Policy does not apply to any third-party service, application or website which we connect to, and which may also collect and use information about you. We are not responsible for the privacy practices of any third party, including but not limited to payment processors, or other service providers who may be involved in your matter. We encourage you to review the privacy policies of all third-party services you interact with through our Website and in the provision of our Services.
WHICH ENTITIES DOES THIS PRIVACY POLICY COVER?
This Privacy Policy applies to us with respect to content on our Website, our Services, and information you provide to us about yourself through any of our service delivery channels.
WHAT IS PERSONAL INFORMATION?
For the purposes of this Privacy Policy, Personal Information means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not and whether recorded in a material form or not.
This includes both general Personal Information such as your name, date of birth, address, bank account details, occupation and contact details, as well as sensitive Personal Information and any other information we may need to identify you or provide our services.
SOLICITOR-CLIENT PRIVILEGE
Information protected by solicitor-client privilege is subject to the highest level of confidentiality and is handled in accordance with our professional legal obligations. This Privacy Policy does not override any applicable legal professional privilege.
AML/CTF FRAMEWORK
You Legal respects the privacy of Personal Information collected and handled in connection with our Services. We will take reasonable steps to ensure that:
- Personal Information collected for AML/CTF Act and Rules purposes is handled responsibly, transparently and securely;
- individuals are given information about how their Personal Information may be collected, held, used and disclosed in accordance with the AML/CTF Act and Rules; and
- individuals are informed about how they may request access to, or correction of, Personal Information we hold about them.
We will keep Personal Information confidential, except if disclosure is authorised by you, necessary for the conduct of your matter, required or authorised by law, or otherwise permitted under our professional obligations.
DESIGNATED SERVICES
We are a South Australian legal practice that provides Services to clients across Australia.
We provide Designated Services under the AML/CTF Act. If we provide, prepare to provide, or reasonably anticipate providing a designated service, we will be required to collect and verify information about clients and in some instances, other relevant persons.
The Designated Services we provide may include:
- assisting in the planning or execution of a transaction to buy, sell or transfer a body corporate or legal arrangement. This includes acting on a client’s behalf in a transaction. This only applies where the sale, purchase or transfer relates to a controlling interest in the body corporate or legal arrangement;
- selling or transferring a shelf company; and
- assisting in planning or executing in the creation or restructuring of a body corporate or legal arrangement. This includes acting on a client’s behalf.
WHEN AND HOW DO WE COLLECT YOUR PERSONAL INFORMATION?
We collect Personal Information only by lawful and fair means, and directly from you wherever it is reasonable and practicable to do so.
We automatically collect, through our Website and Services, information that is often not personally identifiable, such as the website from which visitors came to our Website, IP address, browser type and other information relating to the device through which they access the Website. We may also collect Personal Information from third parties including courts, counterparties, government bodies, referrers, professional advisers, service providers, and publicly available sources where necessary to provide our legal services.
We collect Personal Information for the purposes of providing the Services you have requested and managing our relationship with you. This occurs when you engage us to provide Services, attend a webinar and sign up to receive information from us.
We also collect information to comply with our obligations under the AML/CTF Act and AML/CTF Rules, including for client due diligence and personnel due diligence. If you, your organisation, or someone acting on your or its behalf:
- engages us to provide Designated Services;
- provides information or documents to us for AML/CTF purposes;
- communicates with us by post, email, telephone, text message, video conference or other means; or
- completes forms or provides documents to us;
We may collect Personal Information from third parties if you have consented, if it is unreasonable or impracticable to collect it from you directly, or if we are required or authorised by law to do so.
Third party sources may include:
- our clients;
- persons acting on behalf of a client;
- other parties to a matter and their representatives;
- courts, tribunals, regulators, law enforcement bodies and government agencies;
- publicly available sources, including public registers; and
- identity verification, screening, information technology and other service providers.
We also collect Personal Information through our Website and through online third-party identity verification platforms, including InfoTrack, for example when you complete an enquiry or intake form or upload identification documents, when you provide information to them the terms of their Privacy Policy apply.
We will provide a collection notice at or before the time we collect Personal Information for AML/CTF purposes, or as soon as practicable afterwards.
When we collect your Personal Information, we will take reasonable steps to notify you (or ensure you are aware) of the purposes for which we are collecting it, who we may disclose it to, and how you may access or correct it.
WHAT PERSONAL INFORMATION DO WE COLLECT?
Personal Information and Sensitive Information
We may collect and process various types of Personal Information, including Sensitive Information. When we collect Sensitive Information, we implement additional safeguards to protect this information, including enhanced security measures, stricter access controls, and specialised handling procedures in compliance with applicable laws and regulations. We will only collect Sensitive Information where you have provided your consent and where it is necessary for us to provide our legal services or as otherwise permitted by law, such as when required by the AML/CTF Framework.
We will not ask you to disclose Sensitive Information unless it is necessary to provide our Services to you, or unless it is required to comply with our obligations under the AML/CTF Act. Where we collect Sensitive Information, we may do so without your consent where the collection is required or authorised by Australian law, including the AML/CTF Act or the AML/CTF Rules.
Where we or a third-party agent collect or use biometric information for identification or verification for client due diligence purposes, we will generally seek your consent before doing so and will provide you with sufficient information about the process in our collection notice.
We collect Personal Information necessary for providing our Services. This includes:
Demographic and contact information
Your contact details, including your full legal name, email address and contact phone number; your birth date; your business or company name; your payment and billing information, details regarding conversations we have had with you; information relevant to matters we conduct on behalf of our clients; and other information relevant to you that relates to the Company.
KYC Information
We are required by the AML/CTF Framework to collect and verify certain information, including Sensetive Information. We may be prohibited from providing Designated Services if we cannot collect or verify that information.
The Personal Information we collect for AML/CTF purposes may include:
- your full legal name;
- date of birth;
- residential address;
- contact details;
- photographic identification;
- occupation;
- business holdings and structures;
- information about beneficial ownership and control;
- information about persons acting on behalf of a client;
- information about source of funds and source of wealth;
- information about the nature and purpose of the business relationship or transaction; and
- details of the legal services or transactions sought or provided.
We will only collect Sensitive Information if required under the AML/CTF Framework, with your consent if required, or if an exception under the Privacy Act applies.
We may collect government related identifiers, such as passport, driver licence or Medicare details, if required for identity verification or other AML/CTF purposes.
We will not adopt a government related identifier as our own identifier. We will only use or disclose a government related identifier if required or authorised by law, or if otherwise permitted by the Privacy Act.
If you do not provide requested Personal Information, we may be unable to provide Designated Services and/or comply with our legal obligations.
Personnel due diligence
We collect Personal Information about employees and prospective employees if required for personnel due diligence under the AML/CTF Framework. This may include identity information, employment history, and information about criminal history or regulatory action, collected with the individual’s consent or as otherwise permitted by law.
We use this information to assess whether a person is suitable for a role that could be used to facilitate money laundering, terrorism financing or proliferation financing, and to comply with our AML/CTF program. We handle it in accordance with this Privacy Policy and our professional obligations.
Anonymity and pseudonymity
Where lawful and practicable, you may deal with us anonymously or using a pseudonym. However, due to the nature of legal services we generally require identification and Personal Information in order to provide our services, comply with legal obligations including under the AML/CTF Framework and conduct conflict checks. Our professional obligations also ordinarily require us to know who we are acting for and who is giving instructions.
We may be able to provide general information on an anonymous basis. We will usually be unable to act in a legal matter anonymously or pseudonymously.
WHY DO WE COLLECT YOUR PERSONAL INFORMATION?
We may collect your Personal Information when required by law but generally we collect Personal Information from you (or about you) to allow us to provide you with our services. Personal information collected by us will generally only be used or disclosed for the purpose it was collected.
We may also use your Personal Information for secondary purposes, including:
- to efficiently and effectively maintain your account and contact details;
- to provide Services to you, including to generate aggregate reports about Service usage;
- to respond to requests or inquiries from you and to communicate with you about our Services, accounts or orders, and for similar customer-service-related purposes;
- to process your payments and to assess charges for our Services;
- to effectuate or enforce a transaction or agreement with you;
- to tailor the information we send or display to you, including to market our Services or opportunities to attend events or seminars;
- to analyse our Services or internal operations;
- to provide you with information about our company or Services that we believe may be of interest, including to send marketing and promotional e-mails;
- to improve our Website, offerings or Services and to better understand how you access and use our Website and Services on an aggregated and individualised basis;
- where disclosure or its use is required or authorised by law;
- to administer our Website and keep it safe and secure;
- in the process of procuring advice from legal and accounting firms, auditors, contractors, consultants and other advisors;
- to provide you with notices required under legislation, including but not limited to the Corporations Act 2001 (Cth); and
- to conduct conflict of interest checks;
- any other purpose for which you have consented.
We may use and disclose Personal Information for AML/CTF purposes, including to:
- identify and verify clients and other relevant persons;
- identify beneficial owners;
- confirm the authority of persons acting on behalf of clients;
- assess money laundering, terrorism financing and proliferation financing risks;
- conduct sanctions, politically exposed person and other screening checks;
- conduct ongoing customer due diligence;
- monitor transactions and matter activity where required;
- comply with record keeping obligations;
- comply with reporting obligations; and
- comply with directions, notices, requests or requirements from AUSTRAC or another lawful authority.
UNSOLICITED PERSONAL INFORMATION
If we receive Personal Information that we did not request, we will determine whether we could have collected that information under the Privacy Act.
If we could not have collected the information and it is lawful and reasonable to do so, we will take reasonable steps to destroy or de-identify it as soon as practicable and in accordance with APP 4.
MARKETING AND COMMUNICATIONS
We will only send you marketing and promotional materials with your explicit, opt-in consent. You may withdraw your consent at any time by contacting us or using the unsubscribe link in our emails.
We will not use Personal Information collected for AML/CTF purposes for direct marketing unless permitted by an exception under APP 6.
WHEN DO WE DISCLOSE YOUR PERSONAL INFORMATION?
Subject to our duties of confidentiality, privilege and any applicable court rules or undertakings, we may disclose Personal Information we collect or receive through our Website and Services as follows:
- our employees and related corporate bodies;
- to our contractors or third-party service providers who provide services or perform functions on our behalf;
- our professional advisors and agents;
- payment systems operators such as merchants or third-party payment providers; in response to a subpoena or other legal process by a governmental entity or third party, or if otherwise required by law;
- to regulatory bodies and government agencies, including AUSTRAC, where required or authorised by the AML/CTF Act or AML/CTF Rules;
- to protect or enforce our rights or property;
- in the event of the sale or dissolution (bankruptcy) of assets; and
- to our affiliates and subsidiaries for purposes consistent with this Privacy Policy;
- to other parties to proceedings or transactions and their representatives;
- to contracted service providers who assist us to operate our practice, including information technology, document management, data storage, archiving, identity verification and screening providers; and
- related entities, where applicable.
We will not disclose, sell, share or trade your Personal Information to any third parties for a benefit, service, or advantage.
We may share your information with third-party service providers including cloud storage providers, practice management software providers, IT service providers and communication platforms.
We take reasonable steps to ensure that contracted service providers handle Personal Information appropriately and do not use or disclose it for unauthorised purposes.
We may use technology tools (including artificial intelligence tools) to assist in processing information. We take reasonable steps to ensure such tools are used in a manner consistent with our privacy and confidentiality obligations.
Legal requirements and AUSTRAC reporting
There may be circumstances where we are required or authorised by law to use or disclose Personal Information without your consent.
This may include where:
- disclosure is required by warrant, subpoena, court order, statutory notice or other lawful requirement;
- disclosure is required or authorised under the AML/CTF Framework;
- we form a suspicion about a matter or transaction that must be reported to AUSTRAC;
- disclosure is necessary to lessen or prevent a serious threat to life, health or safety;
- disclosure is necessary for us to take appropriate action in relation to suspected unlawful activity or serious misconduct; or
- disclosure is otherwise permitted by the Privacy Act.
In some cases, it is an offence for us to disclose that we have made a report to AUSTRAC.
We do not retain copies of full identification documents (such as driver’s licences or passports) for AML/CTF record keeping purposes. Instead, we record the relevant Personal Information from identification documents that is reasonably necessary to demonstrate compliance with our client due diligence obligations (such as names, date of birth, passport or licence number). We may retain copies of identification documents where another professional or legal obligations requires us to do so.
We may link Personal Information collected for AML/CTF purposes with other information we hold about you in connection with your matter, for example, in our client and matter records.
Nothing in this Privacy Policy limits our obligations of confidentiality or client legal privilege. However, there may be circumstances where we are compelled to disclose confidential information to AUSTRAC under the AML/CTF Framework. In some circumstances, we may be prohibited from notifying you that a disclosure has been made.
DATA QUALITY
We take reasonable steps to ensure that Personal Information we collect, use and disclose for AML/CTF purposes is accurate, current, complete and relevant.
We rely on you to provide accurate information and to tell us if your information changes during the course of your matter or business relationship with us.
Records held after our work has concluded will not usually be monitored or updated unless further instructions are received or we are required to do so by law.
YOUR RIGHTS ABOUT YOUR PERSONAL INFORMATION
You may exercise certain rights regarding your Personal Information held by us. In particular, you have the right to withdraw consent where you have previously given your consent, learn if your Personal Information is being processed by us, obtain a copy of the Personal Information we hold about you, verify the accuracy of your Personal Information and ask for it to be updated or corrected, restrict access to your Personal Information under certain circumstances and seek the erasure of your Personal Information from us under certain circumstances.
Access to your information
You can access and/or correct the Personal Information we hold about you at any time by contacting us at info@youlegal.com.au. We will provide you with access to your Personal Information within a reasonable period, unless there are exceptional circumstances that require additional time for processing.
We may refuse access or correction where permitted by law. This may include where giving access would have an unreasonable impact on the privacy of others, would be unlawful, would prejudice enforcement activities or anticipated legal proceedings, would reveal commercially sensitive evaluative information, or would be inconsistent with our duties to another client.
Correction of your information
You have the right to request correction of Personal Information we hold about you if you believe it is inaccurate, out of date, incomplete, irrelevant, or misleading. We will update your Personal Information within a reasonable time and may need to charge an appropriate fee to cover the costs of responding to your request.
If we refuse access or correction, we will provide written reasons unless it would be unreasonable or unlawful to do so.
Deletion of your information
You may request deletion of your Personal Information. However, we may be required by law to retain certain information, including legal files and records, for specified periods. Where we are not legally required to retain the information, we will take reasonable steps to destroy or de-identify it. You can request deletion of your Personal Information by contacting us at info@youlegal.com.au. If we no longer require the use of your Personal Information, we will take reasonable steps to destroy or permanently de-identify it.
HOW LONG DO WE KEEP YOUR PERSONAL INFORMATION
We are required to hold all legal files for a minimum of seven years. In some cases, this statutory period may be longer. We also hold employee information for a period of seven years. Information collected for AML/CTF purposes including KYC Information and transaction records will be kept for at least seven years after the business relationship ends or the transaction is completed, as required by the AML/CTF Framework.
Notwithstanding the above, any documents relating to a person under the age of 18 will be retained until that person turns 25.
Once the retention period expires, Personal Information is securely deleted from our information management systems. After the retention period expires, the information is securely destroyed or de-identified (where lawful and practicable).
SECURITY OF YOUR PERSONAL INFORMATION
We are committed to ensuring that the Personal Information we collect is secure. We take reasonable steps to protect your Personal Information from misuse, interference and loss, as well as unauthorised access, modification or disclosure. Our staff and contractors are required to comply with confidentiality and privacy obligations and receive training in privacy and information security practices appropriate to their role. We use a number of physical, administrative, personnel and technical measures to protect your Personal Information. These measures include:
Access controls
Access to client information is limited to our employees and related corporate bodies; to our contractors or third-party service providers who provide services or perform functions on our behalf; our professional advisors and agents; payment systems operators such as merchants or third-party payment providers.
Physical security
Information is stored both electronically and in paper files in secured locations.
Our electronic systems include practice management, document management and storage systems operated by third party providers.
Vendor management
We require all third-party service providers and vendors who handle Personal Information on our behalf to adhere to strict confidentiality and data protection standards. We conduct due diligence on our vendors to ensure they have appropriate security measures in place.
DATA BREACH NOTIFICATION
In the event of a data breach that is likely to result in serious harm, we will notify the OAIC and affected individuals as required by the Notifiable Data Breaches (NDB) scheme. Our notification will include a description of the breach, the kinds of information involved, and our recommendations for steps individuals should take in response to the breach.
DISCLOSURE OF PERSONAL INFORMATION OUTSIDE OF AUSTRALIA
- We may disclose your Personal Information to organisations in other countries. Recipients may include:anyone that you have consented for us to disclose Personal Information to;
- our related entities, employees or officers;
- external service providers that may assist us in our business by providing administration, information technology or other services;
- external service providers, if necessary, for us to provide you with requests for products or services;
- cloud providers and storage, data processors, and any other person or entity required by law.
We take all steps reasonably necessary to ensure that your data is treated securely and in accordance with this privacy policy. It should be noted, however, that international recipients may not have data protection laws that provide the same level of protection that exists under the Australian Privacy Principles. We will not be responsible for the acts or practices of the overseas recipient where the disclosure is required by AML/CTF Act or the AML/CTF Rules.
WEBSITE AND DIGITAL PLATFORM PRIVACY
When you interact with our Website, we strive to make your experience easy and meaningful. We, or our third-party service providers, may use cookies, web beacons (clear GIFs, web bugs) and similar technologies to track site visitor activity and collect site data. We may also engage third parties, including Google Analytics, to track and analyse Website activity on our behalf. We also use third-party communication platforms such as Zoom and Microsoft Teams to conduct meetings and consultations. These providers may collect and process Personal Information in accordance with their own privacy policies.
COMPLAINT PROCEDURES
If you have concerns about how we handle your Personal Information, you may lodge a complaint with us by contacting our Privacy Officer. We will investigate all complaints promptly and provide a formal response within a reasonable timeframe considering the circumstances.
If you are not satisfied with our response, you may contact the OAIC at enquiries@oaic.gov.au or 1300 363 992.
CONTACT INFORMATION
Privacy Officer and contact information
Privacy Officer: Sarah Bartholomeusz
Email: info@youlegal.com.au
Phone: 1300 870 661
Practice Name: You Legal Pty Ltd
ACN: 166 501 873
For all privacy-related enquiries, access requests, correction requests, complaints, or concerns about how we handle your Personal Information, please contact our Privacy Officer using the details above.
If you think your Personal Information, held by us, may have been compromised in any way or you have any other Privacy-related complaints or issues, you should also raise the matter with the Privacy Officer.
If we do not resolve your enquiry, concern or complaint to your satisfaction or you require further information in relation to any privacy matters, please contact the Privacy Commissioner Australia, whose contact details are below.
Office of the Australian Information Commissioner
Telephone: 1300 363 992
Email: enquiries@oaic.gov.au
Office Address: Level 3, 175 Pitt Street, Sydney NSW 2000
Postal Address: GPO Box 5218, Sydney NSW 2001
Website: www.oaic.gov.au
DATE OF CURRENT VERSION: July 2026