Privacy Policy
1. Introduction
This Privacy Policy applies in respect of Frank Advisory Pty Ltd (ABN 43 659 178 882) and Frank Law Pty Limited trading as Frank Law (ABN 68 602 869 376) (“we”, “our” or “us”) who are committed to protecting your privacy. We collect personal information in accordance with the Privacy Act 1988 (Cth) (Privacy Act) and the Australian Privacy Principles (APPs) it contains. We collect personal information only where the law requires or authorises it, and only where it is reasonably necessary for our functions and activities.
This Privacy Policy explains how we collect, use, hold and manage personal information, and how you can access and correct the personal information we hold about you.
If you (or your organisation) have engaged us to provide legal services or corporate advisory and consulting services, you should read this policy together with our terms and conditions of engagement.
2. What is personal information?
In this policy, “personal information” means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not it is true and whether or not it is recorded in a material form.
“Sensitive information” is a subset of personal information that receives greater protection under the Privacy Act. It includes information about a person’s racial or ethnic origin, political opinions or associations, religious or philosophical beliefs, membership of a professional or trade association or trade union, sexual orientation or practices, criminal record, and health.
3. What personal information we collect
The personal information we collect includes, but is not limited to:
-
your contact details, such as your name, telephone numbers, addresses and email addresses;
-
other personal information you provide in response to our requests;
-
information collected when you access and use our website, such as your IP address, browser type and device information, domain name, email address and the pages you visit;
-
Information voluntarily provided by individuals through paid campaigns, forms, surveys, or other interactions;
-
information provided by a credit reporting body, and information about payment of our accounts and invoices;
-
information you provide when applying for employment with us, such as your contact details, covering letter, CV, employment and volunteer history, education history, personal home addresses, (including previous employers and organisations), academic results and any other information you provide; and
-
information we collect while acting for clients and providing legal services and/or corporate advisory and consulting services.
Where we provide (or propose to provide) “designated services” under anti-money laundering and counter-terrorism financing laws (AML/CTF laws), we collect information for customer due diligence and related compliance activities, including because we are a “reporting entity” for those services. This may include:
-
identity and contact details, such as name, date of birth and residential address;
-
identification and verification information, such as document numbers and expiry dates;
-
the capacity in which a person acts, for example as an agent;
-
information about beneficial owners and other persons associated with a client;
-
information relevant to sanctions or politically exposed person screening; and
-
information about instructions and transactions, to enable ongoing monitoring, reporting and record-keeping.
We may also collect and hold personal information about the creditworthiness of individuals or organisations, and to manage non-payment of our invoices (including debt recovery for unpaid or overdue invoices).
Our Privacy Collection Notice for AML/CTF compliance can be found here: [insert hyperlink to the Privacy Collection Notice here]
4. How we collect personal information
We collect personal information only by lawful and fair means, in accordance with our legal obligations. We may collect personal information about you when you:
-
enquire about us or our services;
-
meet or communicate with us (in person, online, by email or by phone), or otherwise deal with us or our staff;
-
engage us (or your organisation engages us) to provide legal services;
-
have business dealings with us, including where you or your organisation supply goods or services to us;
-
subscribe to our publications, register for a webinar or seminar, or access our website or online platforms;
-
attend an event, webinar or seminar we run or host; or
-
apply for employment with us.
We use reasonable efforts to collect personal information directly from you. Where that is not reasonably practicable, we may collect it from third parties, including publicly available sources.
Website and cookies
A cookie is a small data file a website transfers to your device, which lets the website track the pages you visit. A cookie contains only the information you supply and cannot read data on your device. Our website uses cookies. You can set your browser to refuse cookies, but you may then be unable to use our website fully. We also collect data on the number and frequency of clicks on links and pages on our website.
Unsolicited personal information
We generally collect personal information only when we request it or take active steps to collect it. From time to time we may receive personal information we did not request, such as information beyond what we asked for, or an unsolicited job application.
When this happens, we promptly assess whether we could lawfully have collected the information had we requested it. If we could not, we take reasonable steps to delete or de-identify it as soon as practicable, unless a law or a court or tribunal order requires us to retain it.
5. Why we collect and use your personal information
We collect personal information only where it is reasonably necessary for one or more of our functions and activities as a legal and corporate advisory firm. We use your personal information only for one or more of the following purposes:
-
providing legal services or corporate advisory and consulting services to you and our other clients;
-
to comply with the terms of our engagement agreements;
-
for general management and reporting purposes, such as invoicing and account management;
-
managing and conducting our business as a legal services provider, including administrative and record-keeping activities;
-
marketing our services to you, assessing your creditworthiness and recovering unpaid fees or other debts owed to us;
-
engaging and communicating with barristers, experts, consultants and other parties relevant to a matter involving you or your organisation;
-
liaising with, and appearing before, courts, tribunals, regulators, government agencies and similar bodies in connection with our legal services;
-
receiving goods or services from you, your organisation or third-party service providers, including providers of litigation support, IT and data-storage services;
-
complying with applicable AML/CTF laws where we are a reporting entity, including conducting customer identification and verification, screening and ongoing monitoring, keeping records and making reports to AUSTRAC where required or authorised;
-
complying with our other legal, regulatory and professional obligations;
-
preventing fraud, loss and criminal activity, and investigating suspected unlawful or improper conduct;
-
protecting the rights, property and safety of our firm and third parties, including maintaining a safe working environment for our partners, principals, employees, contractors, students and volunteers;
-
defending actual or threatened claims and enforcing our legal, statutory and contractual rights;
-
assessing eligibility for legal services offered on a discounted basis;
-
considering applications and expressions of interest for employment;
-
other purposes related to our business (for example, photographs or videos we take at seminars or events may be used for training and promotional purposes);
-
seeking feedback about our services, including by inviting you to participate in and administering questionnaires and surveys; and
-
sending you publications and inviting you to seminars, events and other functions that we consider may be of interest to you.
If you do not provide the personal information we request, we may be unable to act for you, continue acting for you or provide you with some or all of our services.
If you do not provide the personal information we request, we may be unable to act for you or continue to provide services, including because some laws (such as AML/CTF laws) require us to collect and verify certain information before we act. If you do not want us to use your personal information as described in this policy, please contact us using the details under “Accessing and correcting your personal information”.
7. Automated processing and artificial intelligence
We may use artificial intelligence and other automated technologies to assist us in complying with our AML/CTF obligations and in providing our legal or corporate advisory and consulting services. These technologies may be used for purposes such as identity verification, customer due diligence, risk assessment, legal research, document review and classification, and administrative processing.
Although some automated processes may inform decisions that have significant consequences, any such decision remains subject to appropriate human oversight and review.
We may use third-party service providers to supply or operate these technologies. Where personal information is disclosed to a provider, we take reasonable steps to ensure that it is handled consistently with this policy and the Australian Privacy Principles and is protected by appropriate privacy and security safeguards.
8. Keeping your personal information accurate
We rely on the personal information you provide to us being accurate, complete and up to date. Unless required by law, we do not independently verify the accuracy of information obtained from you or other sources. Please let us know promptly if your personal information changes.
9. When we disclose your personal information
We may disclose your personal information where reasonably necessary for the purposes described in this Privacy Policy, including where:
-
you have consented to the disclosure, either expressly or implicitly;
-
the disclosure is required or authorised by law; or
-
the disclosure is necessary for us to provide legal or corporate advivsory and consulting services to you or the organisation you represent.
Depending on the circumstances, we may disclose personal information to:
-
courts, tribunals, regulatory bodies, government agencies and law enforcement authorities, including AUSTRAC where required or authorised under anti-money laundering and counter-terrorism financing legislation;
-
clients, counterparties and their representatives, and other parties involved in matters on which we act;
-
legal and professional service providers engaged in connection with your matter, including barristers, external lawyers, consultants, experts, agents and other advisers;
-
identity verification and due diligence providers that assist us to verify identities and meet our regulatory obligations;
-
our related bodies corporate for the purposes outlined in this Privacy Policy;
-
credit reporting bodies and credit providers;
-
referees and other individuals nominated by you in connection with employment applications, credit applications or assessments of prospective contractual arrangements;
-
guarantors or proposed guarantors of payment obligations owed by you or a related entity;
-
our insurers and operational service providers, including providers of information technology, data hosting and storage, document management, archiving, recruitment and other business support services; and
-
industry bodies, complaint-handling organisations, regulators, tribunals or courts in connection with a complaint, investigation, inquiry or dispute involving our services.
We may also use and disclose personal information where reasonably necessary to establish, exercise or defend legal rights, enforce contractual arrangements, respond to lawful requests, or investigate, prevent or address suspected unlawful, fraudulent or improper conduct. We may further disclose personal information where required or authorised by applicable laws, including the Privacy Act 1988 (Cth) and the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
Overseas disclosure
We may disclose your personal information to recipients outside Australia, including in the United States. Where we do, we take reasonable steps to ensure the recipient handles it consistently with the APPs, unless an exception under the Privacy Act applies (including where an Australian law, such as AML/CTF laws, requires or authorises the disclosure). In some cases we may not be able to give details of certain disclosures where doing so would breach our AML/CTF obligations, including “tipping off” prohibitions.
10. How we protect and retain your personal information
We are committed to keeping your personal information secure. We take reasonable steps to protect the personal information we hold from loss, misuse, interference and unauthorised access, modification or disclosure. Personal information may be stored electronically, in physical files, or through secure third-party storage and technology providers. Access to personal information is limited to those who need it to perform their duties or comply with our legal and regulatory obligations.
In carrying out our customer due diligence and AML/CTF obligations, we may collect and hold information that is sensitive in nature. Accordingly, we maintain security measures and internal processes designed to ensure that this information is handled appropriately and only accessed for authorised purposes.
We keep personal information only for as long as it is reasonably required for our business, legal and compliance purposes. Certain records must be retained for minimum periods under applicable laws, including the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). For example, information obtained for customer due diligence purposes may need to be retained for up to seven years after the end of a client relationship or the completion of a relevant transaction.
Where identity verification is undertaken, we seek to retain only the information necessary to demonstrate that verification has occurred. Depending on the circumstances, this may include details such as your name, date of birth, residential address, identification document type, document number and verification outcome. We will not retain full copies of identification documents unless required or permitted by law, or where doing so is reasonably necessary for our legal, regulatory or operational purposes.
When personal information is no longer required for a lawful purpose and we are not required to retain it, we take reasonable steps to securely destroy, erase or de-identify the information in accordance with our record management practices and legal obligations.
11. Accessing and correcting your personal information
To access the personal information we hold about you, request a correction, or complain about a possible breach of this policy, the Privacy Act or the APPs, please contact our Chief Executive Officer, James Frank.
Email (Frank Law)
For accessing personal information relating to the provision of legal services by Frank Law, please email info@franklaw.com.au
Email (Frank Advisory)
For accessing personal information relating to the provision of corporate advisory and consulting services by Frank Advisory, please email hey@frankadvisory.com.au
Mail
James Frank, Frank Law & Advisory
PO Box 438
Parramatta NSW 2124
Telephone
(02) 9688 6023
You may request access to, or correction of, the personal information we hold about you by contacting us using the details set out in this Privacy Policy. We will generally deal with such requests in accordance with the requirements of the Privacy Act 1988 (Cth) and take reasonable steps to ensure that the personal information we hold is accurate, up to date and complete.
Before responding to a request, we may require you to verify your identity and, where relevant, your authority to act on behalf of another individual. In providing access, we may remove or withhold information where necessary to protect the privacy rights of other individuals or where disclosure would otherwise be inappropriate.
There may be circumstances in which we are unable to provide access to some or all of the personal information requested. This may occur where doing so would:
-
prejudice current or anticipated legal proceedings, investigations or negotiations;
-
interfere with law enforcement activities or the investigation of suspected unlawful conduct;
-
create a serious risk to the health, safety or welfare of an individual or the public;
-
involve a request that is frivolous or vexatious; or
-
be inconsistent with, or restricted by, a law, court order or regulatory requirement.
Additional restrictions may apply to information collected or held for AML/CTF compliance purposes. For example, we may be prohibited from disclosing certain information where doing so could contravene anti-money laundering legislation, including restrictions relating to "tipping off" or information connected with AUSTRAC reporting and compliance activities.
If we are unable to comply with a request for access or correction, we will provide reasons for our decision where permitted by law and explain the options available to you for raising a complaint.
We do not ordinarily charge a fee for making a request to access or correct personal information. However, where permitted by law, we reserve the right to recover reasonable costs associated with locating, retrieving and providing access to the requested information.
If you have a question, concern or complaint about how we collect, use, disclose or otherwise handle personal information, please contact us and we will seek to address the matter in accordance with our obligations under applicable privacy laws.
Where an enquiry relates specifically to our AML/CTF compliance activities or customer due diligence processes, you may contact our AML Compliance Officer at info@franklaw.com.au.
If you are not satisfied with our response, you may also make a complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au/privacy/privacy-complaints.
12. Changes to this policy
We may vary this Privacy Policy from time to time. The current version is available on our website.