Privacy Policy

Privacy Policy

Effective Date: 15 June 2026 Stratus Legal Group Pty Ltd  |  ACN 652 291 186

Our Commitment to Your Privacy

Stratus Legal Group Pty Ltd ACN 652 291 186 trading as Stratus Legal Group (“Stratus Legal Group”, “we”, “us”, “our”) is an Australian legal practice based in Victoria. We are committed to protecting your privacy and handling your personal information responsibly, transparently and in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and, where applicable, the Health Records Act 2001 (Vic).

As a legal practice operating across conveyancing and property, family law, wills and estates, litigation and commercial law, we collect and use a range of personal information in the course of providing legal services and fulfilling our regulatory obligations.

This policy applies to personal information we collect in the course of providing legal services to clients and operating our business. We maintain a separate internal privacy notice for employees, contractors and job applicants.

This policy explains what personal information we collect, how we collect and use it, who we share it with, and what rights you have in relation to your information.

From 1 July 2026, where we provide services that are designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), we will be subject to obligations under the AML/CTF Act and AML/CTF Rules. We are also subject to Verification of Identity (VOI) standards and electronic conveyancing requirements where applicable. These obligations may affect how we collect and handle certain personal information and, in some cases, limit what we can disclose to you.

We may also provide separate privacy collection notices at the time we collect particular information, including during client onboarding, VOI, AML/CTF customer due diligence, website enquiries or other matter-specific processes. Those notices should be read together with this policy.

1. What Personal Information We Collect

We collect personal information that is reasonably necessary to provide legal services, manage our practice and comply with our obligations. The type of information we collect depends on the nature of your matter and your relationship with us.

1.1 General and Contact Information

Across all practice areas, we may collect:

  • Full name and date of birth
  • Gender, where relevant to your matter
  • Residential, postal and business addresses
  • Phone numbers and email addresses
  • Occupation and employer details
  • Communications between you and us (including emails, letters, attendance notes and file records)

1.2 Identity and Verification Information

Depending on the nature of your matter, we may be required, or may reasonably need, to verify your identity and your authority to instruct us. This may arise under:

  • Legal professional and ethical obligations
  • Electronic conveyancing and VOI requirements
  • Trust account and trust money requirements
  • Court, registry or government authority requirements
  • Fraud prevention and risk management procedures
  • AML/CTF obligations, from 1 July 2026, where we provide designated services

For identity verification, we may sight or collect details from government-issued identification documents, such as a driver licence, passport or Medicare card. Where possible, we record only the information reasonably necessary to demonstrate that verification was completed — including document type, document number, issuing authority, expiry date, verification date, verification method and verification outcome.

We do not retain full copies of identity documents for AML/CTF record-keeping purposes unless retention is required by another law or is necessary for a separately permitted purpose, such as applicable VOI, electronic conveyancing, court, registry, professional or client matter requirements.

We may also collect evidence of your authority to instruct us, such as a power of attorney, company authorisation or trust deed.

1.3 Matter-Specific Information

Depending on your matter, we may also collect:

Conveyancing and Property:

  • Title, property and land details
  • Mortgage, rates, water and tax information
  • Settlement figures and financial adjustment details
  • PEXA workspace and electronic lodgement data

Family Law:

  • Personal, relationship and family history
  • Financial information including assets, liabilities, income and superannuation
  • Information about children and other family members
  • Health, welfare and safety information where relevant to parenting or property matters
  • Court documents and correspondence with opposing parties or their representatives

Wills and Estates:

  • Details of assets, liabilities and beneficiaries
  • Superannuation, insurance and financial account information
  • Personal circumstances of testators, executors and beneficiaries
  • Probate and estate administration records

Litigation:

  • Details of disputes and legal proceedings
  • Witness statements and evidentiary material
  • Court documents and procedural correspondence
  • Details of opposing parties and relevant third parties

Commercial Law:

  • Business, company and trust structure details
  • Financial records and commercial agreements
  • Director, shareholder and beneficial ownership information
  • Regulatory and compliance documentation

1.4 Financial and Transaction Information

We may also collect:

  • Banking and financial account details for settlements and trust transactions
  • Source of funds information
  • Trust account deposit and disbursement records
  • Credit-related personal information incidentally obtained through lender or mortgage documents (see Section 6)

1.5 Sensitive Information

In some circumstances, we may collect sensitive information, including:

  • Health information (e.g. in family law, personal injury, capacity or estate matters)
  • Information about family or domestic violence (e.g. in family law proceedings)
  • Criminal history information (e.g. in relevant litigation matters or AML/CTF screening)
  • Biometric information or biometric templates used for identity verification (see Section 1.6)
  • Racial or ethnic origin, religious beliefs, political opinions or other sensitive attributes where incidentally relevant to legal proceedings or instructions
  • Information relating to politically exposed person (PEP) status or sanctions screening

We will only collect sensitive information where it is reasonably necessary for your matter and with your consent, or where otherwise required or permitted by law.

1.6 Biometric Verification Information

We use an electronic identity verification service (currently InfoTrack) for certain matters. This service may involve biometric verification technology, including facial recognition and liveness detection.

During electronic VOI, the following may occur:

  • Your identity documents are scanned and verified electronically
  • A photograph or video of your face is captured
  • A biometric comparison is conducted between your facial image and your identity document
  • A liveness check is performed to confirm you are physically present

The biometric verification process is performed through InfoTrack. We receive a verification report and outcome record. We do not directly collect, hold or retain biometric templates or raw biometric data. InfoTrack’s handling of biometric information is also governed by its own privacy policy and applicable law. Where we engage InfoTrack or another verification provider to handle personal information in connection with our services, we take reasonable steps to ensure appropriate privacy, confidentiality, security, retention and deletion arrangements are in place.

Where biometric verification is used, we or our verification provider will seek your express consent before the biometric process is undertaken. If you do not consent to biometric verification, or do not wish to participate, please contact us using the details in Section 18 before your matter commences. We will consider reasonable alternative verification methods, although this may affect the timing or manner in which we can act.

1.7 Information About Minors

Some of our matters involve information about minors (persons under 18 years of age), particularly in family law proceedings, estate administration and property transactions. Where we collect or hold information about a minor, we take particular care to ensure it is handled appropriately and disclosed only where necessary for the relevant matter.

We do not collect more information about a minor than is reasonably necessary. Access to that information within our firm is limited to staff who require it for the purposes of the matter.

1.8 Technical and Website Information

When you visit our website, we may automatically collect:

  • IP address, browser type and device information
  • Website usage data and session activity
  • Pages visited, links followed and time spent on site

2. How We Collect Personal Information

We collect personal information:

  • Directly from you through intake forms, client onboarding processes, telephone calls, emails, meetings and correspondence
  • From third parties involved in your matter, including:
    • Real estate agents and property managers
    • Banks, lenders and mortgage brokers
    • Government authorities and registries (e.g. Land Titles Victoria, State Revenue Office, Births Deaths and Marriages, court registries)
    • Other legal practitioners, conveyancers and barristers
    • Our clients, where you are a counterparty or third party to a matter
    • Accountants, financial advisers and valuers
  • Through identity verification providers, including electronic VOI platforms such as InfoTrack
  • Through our practice management systems and digital platforms
  • Through our website and digital communication tools

Where required or permitted by law (including under AML/CTF obligations), we may collect information indirectly where it is impracticable to collect it from you directly.

3. Why We Collect and Use Personal Information

We collect and use your personal information to:

  • Provide legal and conveyancing services to you or on your behalf
  • Verify your identity and authority to instruct us
  • Conduct property transactions and electronic settlements through PEXA
  • Prepare and file court documents, applications and legal correspondence
  • Draft wills, powers of attorney, contracts and other legal instruments
  • Administer estates and trusts
  • Communicate with you and other parties to your matter
  • Comply with our professional, legal and regulatory obligations
  • Satisfy AML/CTF, VOI and client due diligence requirements
  • Manage our trust account and practice administration
  • Maintain adequate professional indemnity insurance and respond to any complaints
  • Improve our services and internal business operations

If you do not provide required personal information, we may be unable to act for you or may be required to withdraw from your matter.

4. Client Confidentiality and Legal Professional Privilege

As a law firm, we owe professional duties of confidentiality to our clients. Some information we hold may also be subject to legal professional privilege. We handle confidential and privileged information in accordance with our legal and professional obligations under the Legal Profession Uniform Law (Victoria), applicable professional conduct rules and the general law.

We do not disclose confidential or privileged information except where:

  • You have authorised the disclosure
  • Disclosure is necessary for the conduct of your matter
  • Disclosure is required or authorised by law
  • Disclosure is required by court order, subpoena or tribunal process
  • Disclosure is permitted under applicable professional conduct rules

Nothing in this privacy policy is intended to, or should be read as, waiving legal professional privilege over any communications or documents.

Where we are required to make disclosures that interact with or limit our confidentiality obligations — for example, under AML/CTF reporting obligations — we will handle those disclosures in accordance with applicable law and our professional obligations.

5. AML/CTF Compliance and Client Due Diligence

From 1 July 2026, where we provide services that are designated services under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), we will be required to comply with AML/CTF obligations. These obligations may apply to services such as:

  • Conveyancing and acting in the sale, purchase or transfer of real estate
  • Managing client money, securities or other assets in connection with a transaction
  • Assisting with business sale or purchase transactions
  • Creating, operating or managing companies, trusts or other legal arrangements
  • Acting as, or arranging for another person to act as, a nominee director, shareholder or trustee

To meet these obligations, we may:

  • Collect and verify information about your identity, authority to act and beneficial ownership
  • Ask you for information about:
    • The source and nature of funds or wealth involved in a transaction
    • The nature and purpose of your matter or business relationship with us
    • Ownership structures, beneficial owners and controlling persons
  • Conduct initial and ongoing customer due diligence and risk assessments
  • Screen against sanctions lists and for politically exposed person (PEP) status
  • Retain records for a minimum of 7 years as required by the AML/CTF Act
  • Submit reports to AUSTRAC, including Suspicious Matter Reports (SMRs) and Threshold Transaction Reports (TTRs)
⚠  Important: In limited circumstances, the AML/CTF Act may prohibit us from telling you that a report has been, may be, or is required to be made to AUSTRAC, or from disclosing other information that would contravene the tipping-off provisions of the Act. If we cannot obtain information required to satisfy our AML/CTF obligations, we may be unable to act, may need to delay work, or may be required to cease acting.

Information collected for AML/CTF purposes will not be used for marketing or other commercial purposes except where permitted by law.

6. Credit-Related Personal Information

In the course of our conveyancing, property and commercial work, we may receive credit-related personal information incidentally — for example, through mortgage documents, lender correspondence or refinancing instructions provided by clients or third parties.

Where we handle credit-related personal information, we do so only to the extent necessary to provide legal services in relation to that transaction. We do not use credit information for credit assessment purposes or beyond the scope of your matter.

Any credit-related personal information we hold is subject to the same security, confidentiality and retention obligations as all other personal information under this policy.

7. Disclosure of Personal Information

We may disclose your personal information where reasonably necessary, including to:

7.1 Parties to Your Matter

  • Banks, lenders and mortgagees
  • Real estate agents and property managers
  • Other legal practitioners, conveyancers and barristers
  • Government authorities and registries (e.g. Land Titles Victoria, State Revenue Office, Australian Taxation Office, courts and tribunals)
  • Mediators and arbitrators in dispute resolution proceedings
  • Executors, beneficiaries and other parties in estate matters
  • Counterparties and their representatives in commercial transactions

7.2 Regulatory and Compliance Bodies

  • AUSTRAC, as required under the AML/CTF Act from 1 July 2026
  • The Legal Services Board Victoria and the Legal Services Commissioner
  • Courts, tribunals and law enforcement authorities, where required by law or court order

7.3 Service Providers

We engage trusted third-party providers to assist in delivering our services. These include identity verification providers, IT and cloud storage providers, our practice management system, PEXA and electronic lodgement platforms, document management and communication tools, accounting and financial systems, and scheduling and messaging platforms. Further detail, including on overseas recipients, is set out in Section 8.

7.4 Other Disclosures

  • Where you have consented to the disclosure
  • Where disclosure is required or authorised by law
  • In connection with the sale, merger or transfer of our legal practice, subject to appropriate confidentiality protections

All disclosures are subject to our professional duties of confidentiality and, where applicable, legal professional privilege. We do not sell personal information. We will not disclose your information to third parties for their own marketing purposes.

8. Third-Party Service Providers and Overseas Disclosure

8.1 Our Service Providers

We engage third-party providers to assist in delivering our services. These include providers of:

  • Practice management and matter management systems
  • Cloud storage, email and productivity platforms
  • Electronic property settlement and lodgement platforms (including PEXA)
  • Identity verification and VOI compliance services (including InfoTrack)
  • Accounting and financial management software
  • Phone, SMS and video communication tools
  • Online scheduling and appointment management platforms
  • Document creation, e-signature and PDF management tools
  • Workforce management and time-tracking systems
  • Digital marketing and advertising providers, including agencies engaged to manage advertising campaigns and review website analytics

We may update our service providers from time to time. Where we engage a new provider that will handle personal information, we will conduct appropriate due diligence before doing so.

8.2 Overseas Disclosure

Some of our service providers store or process personal information outside Australia. The countries in which overseas recipients are currently located include:

  • United States of America
  • United Kingdom
  • New Zealand

Before disclosing personal information to overseas recipients, we take reasonable steps to ensure they handle that information in a manner consistent with the Australian Privacy Principles. These steps may include contractual confidentiality and privacy obligations, security due diligence, data breach notification requirements, limits on use and disclosure, and requirements for secure deletion or return of information.

Where we disclose personal information to overseas recipients, we take steps to remain accountable for that disclosure under the Privacy Act 1988 (Cth) to the extent required by law. Where we seek to rely on your consent to a cross-border disclosure in circumstances where APP 8.1 would not otherwise apply, we will seek that consent separately and explain the relevant consequences to you at that time.

8.3 Our Due Diligence Process

Before engaging any provider that handles personal information, we take reasonable steps to:

  • Review their privacy policy and any applicable security certifications
  • Assess their data breach detection and response capabilities
  • Put in place appropriate contractual protections, including confidentiality obligations and requirements to comply with applicable privacy laws
  • Maintain records of what information is shared and with which providers

9. Storage and Security

We store personal information in electronic format and, where required, in physical (hard copy) format.

We implement reasonable technical and organisational security measures to protect your information from misuse, interference, loss, unauthorised access, modification and disclosure. Our current measures include:

  • Use of Australian-hosted systems where practicable
  • Encryption of data in transit and at rest
  • Role-based access controls limiting access to authorised staff only
  • Multi-factor authentication for system and application access
  • Audit logging and system activity monitoring
  • Physical security controls for paper-based records
  • Staff training on data handling and privacy obligations

While we take reasonable steps to protect your information, no system is entirely secure. If you have concerns about the security of information we hold about you, please contact us.

10. Retention and Disposal

We retain personal information only for as long as necessary to:

  • Provide legal services to you
  • Comply with legal and regulatory obligations
  • Satisfy AML/CTF and VOI record-keeping requirements
  • Respond to any complaints, claims or legal proceedings arising from our work

As a general guide:

  • Legal matter files — minimum 7 years after matter completion, or longer where required by professional obligations or the nature of the matter
  • AML/CTF records — generally for 7 years after the end of the relevant business relationship or transaction, as required by the AML/CTF Act
  • VOI and electronic conveyancing records — for the period required by applicable VOI, electronic conveyancing, registry, professional or risk management requirements
  • Identity document copies — not retained for AML/CTF record-keeping purposes unless required by another law or necessary for another permitted purpose
  • Trust account records — as required by applicable Victorian trust accounting requirements
  • Family law and estate records — may be retained for longer periods given the ongoing legal significance of those matters

When personal information is no longer required, we take reasonable steps to destroy it securely or permanently de-identify it. For identity documents and biometric data, we take additional care to ensure timely and secure destruction once verification is complete and retention is no longer required.

11. Website, Cookies and Analytics

Our website may use cookies and similar tracking technologies to improve functionality, personalise your experience and understand how visitors use our site.

Types of cookies we may use include:

  • Essential cookies — Required for the website to function correctly and securely
  • Analytics cookies — We use Google Analytics to understand visitor behaviour and improve our website. Google Analytics collects device, browser and usage information. Data is processed by Google and may be transferred overseas. You can opt out of Google Analytics tracking at tools.google.com/dlpage/gaoptout
  • Advertising and remarketing cookies — We run advertising campaigns through Google Ads, which involves conversion tracking and remarketing technology. Conversion tracking helps us understand when a website visit results in an enquiry after clicking our advertisement. Remarketing cookies allow Google to show our advertisements to people who have previously visited our website, across other websites and platforms. Our advertising campaigns are managed by a third-party digital marketing agency who may also access associated analytics data. You can manage your Google advertising preferences at adssettings.google.com, or opt out of interest-based advertising at optout.aboutads.info
  • Scheduling and functional cookies — Set by tools such as Calendly when you interact with appointment booking features on our site

You may adjust or disable cookies through your browser settings, although this may affect some website functionality. For information about opting out of personalised Google advertising, visit adssettings.google.com.

Information collected through our website is used only for the purposes set out in this policy.

12. Marketing Communications

We may send you updates, legal information or news about our services where:

  • You have an existing relationship with us; or
  • You have expressly consented to receiving marketing communications from us

We also conduct digital advertising campaigns through Google Ads, which may include remarketing — showing our advertisements to people who have previously visited our website across other websites and platforms. These campaigns are managed by a third-party digital marketing agency, who may also review our website analytics in connection with those services. If you do not wish to see our advertisements on other websites or platforms, you can manage your advertising preferences at adssettings.google.com, or opt out of interest-based advertising at optout.aboutads.info.

We comply with the Spam Act 2003 (Cth) in relation to commercial electronic messages. You may unsubscribe at any time by clicking the unsubscribe link in any electronic communication, or by contacting us.

We will not use information collected for AML/CTF purposes for marketing without your consent and as otherwise permitted by law.

13. Data Breaches

We have a data breach response plan in place. In the event of an actual or suspected data breach, we will take prompt steps to contain, assess and respond to the incident.

Where a data breach is likely to result in serious harm to affected individuals, we will comply with our notification obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner (OAIC) as soon as practicable.

⚠  Note: In limited circumstances, legal restrictions — including the AML/CTF Act’s tipping-off provisions or applicable court orders — may affect the content or timing of information we are able to provide about a breach. Where this occurs, we will still take all reasonable steps to comply with our NDB obligations and to provide affected individuals with appropriate information to the extent permitted by law.

14. Access and Correction

You have the right to request access to the personal information we hold about you, and to request correction of information that is inaccurate, out of date, incomplete, irrelevant or misleading.

To make an access or correction request, please contact us. We will respond within a reasonable timeframe and generally within 30 days.

We also take reasonable steps to ensure that personal information collected for AML/CTF customer due diligence purposes remains accurate, up to date and complete throughout our relationship with you.

We may decline an access or correction request in certain circumstances, including where:

  • Providing access would unreasonably affect the privacy of another individual
  • The request relates to information subject to legal professional privilege
  • Access is prevented by AML/CTF tipping-off restrictions
  • We are required by law to refuse the request

Where we decline access or correction, we will give you written reasons for the decision (unless prohibited from doing so) and advise you of any available complaint mechanisms.

15. Use of Technology and Artificial Intelligence

We use a range of approved technology tools to assist in delivering legal services, including artificial intelligence (AI) tools. AI may assist across a broad range of functions in our practice, including legal research, document drafting and summarisation, document review and analysis, transcription of calls and meetings, client intake, matter management and other operational functions.

We take the following steps to manage the privacy, confidentiality and security risks associated with our use of AI and technology:

  • We use only approved platforms and tools that have been assessed for privacy, security and confidentiality
  • We do not input confidential client information, privileged information or personal information into public or consumer AI tools
  • Where AI tools are used with client or matter information, we use only approved platforms that have been assessed for confidentiality, privacy, security, data handling, retention and access controls
  • AI and technology tools we use are subject to contractual obligations regarding confidentiality, permitted use, data handling and security
  • All AI-assisted outputs used in the provision of legal services are reviewed by a qualified legal practitioner before reliance
  • We periodically review our AI and technology tools for ongoing compliance with applicable privacy and security standards

Use of AI tools may involve processing or storing information through third-party providers, including overseas providers. This is subject to the same overseas disclosure and due diligence processes described in Section 8.

16. Complaints

If you have a concern or complaint about how we have handled your personal information, please contact us in the first instance. We will acknowledge your complaint promptly and aim to resolve it within 30 days.

If your complaint is not resolved to your satisfaction, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner (OAIC)

Website: www.oaic.gov.au

Telephone: 1300 363 992

17. Changes to This Policy

We may update this policy from time to time to reflect changes in our practices, legal obligations or technology. The current version will always be available on our website.

Where we make material changes, we will take reasonable steps to notify affected individuals. We encourage you to review this policy periodically.

18. Contact Us

For all privacy enquiries, access and correction requests, and complaints, please contact us at:

Stratus Legal Group Pty Ltd (ACN 652 291 186)

Trading as Stratus Legal Group

60 Percy Street, Portland VIC 3305

Telephone: 03 5521 7222

Email: privacy@stratuslegal.com.au

Book Online
Scroll to Top