Privacy // Privacy Act 1988 (Cth)
Privacy policy
What this company holds today, which is correspondence and very little else, what a released tool would and would not do with a practice's documents, how long anything is kept, and how to make us delete it.
Effective 11 August 2026Version 1.0Privacy Act 1988 (Cth)APP 1 to APP 13
1Who we are, and what this policy covers
This policy is published by AI-LAW PTY LTD, an Australian proprietary company registered in Western Australia, ACN 698 421 608, ABN 23 698 421 608. AI-Law is a trading name of AI-LAW PTY LTD. In this document "we", "us" and "our" mean that company, and "you" means whoever is reading it.
What this policy covers
It covers every way personal information can reach this company as things stand in 2026, which is a short list because the company does very little.
- Your use of the website at ailaw.im.
- Email you send to [email protected], and our reply.
- The records the company keeps in order to exist, such as its own corporate and tax records.
What this policy does not cover, because it does not exist
AI-LAW PTY LTD is building document retrieval software for small legal practices. It has not released it. There is no downloadable application, no hosted service, no account system, no login, no customer portal, no application programming interface, no trial and no waiting list. No firm has installed anything and no client document of any kind has been indexed by this company.
That matters for reading the rest of this page. Where a section describes what would happen with a firm's documents, it is describing an intended design that can be held against us later, and it says so. It is not a description of a service in operation. A privacy policy that quietly describes systems the company does not run is worse than no policy at all, because it teaches the reader that the document is decorative.
Read this bit
Do not send us an executed contract, a client file, a matter reference or anything covered by legal professional privilege. There is nothing here to run it through. Material of that kind that arrives unasked is destroyed under the process described at the unsolicited information section below.
Nothing here is legal advice
AI-LAW PTY LTD is not an incorporated legal practice, holds no Australian practising certificate and does not engage in legal practice. This policy is a professionally structured document about our own handling of personal information. It is not advice to you about yours.
2The law this policy answers to
The law that governs this policy is the Privacy Act 1988 (Cth) and, in particular, the thirteen Australian Privacy Principles set out in Schedule 1 to that Act. Throughout this document a reference to "APP 6" or similar means the corresponding Australian Privacy Principle.
Australian Privacy Principle 1, and why this document exists
APP 1 is the reason there is a privacy policy here at all. It requires an entity to manage personal information in an open and transparent way, to take reasonable steps to implement practices, procedures and systems that ensure compliance with the other principles and that allow it to deal with enquiries and complaints, and to keep a clearly expressed and up to date privacy policy. APP 1.4 then sets out what that policy has to cover: the kinds of personal information collected and held, how it is collected and held, the purposes of collection, use and disclosure, how an individual can seek access and correction, how an individual can complain and how the complaint will be handled, and whether the information is likely to be disclosed to overseas recipients and in which countries. Every one of those is answered in a numbered section below rather than left to inference.
The small business threshold, and why it does not get us out of this
Section 6D of the Privacy Act exempts most businesses with an annual turnover of $3 million or less from the Australian Privacy Principles. AI-LAW PTY LTD was registered in 2026 and its turnover is presently below that threshold, so on a narrow reading the Act may not yet bind it.
We are not relying on that. Several of the exceptions in section 6D would in any event pull a business like ours back inside the Act as it grows, including a business that discloses personal information about another individual to anyone else for a benefit, service or advantage. More to the point, the exemption is an accident of turnover, not a statement that the information stops mattering. This policy is written as though the Australian Privacy Principles apply in full, and we will handle requests and complaints on that basis.
If we later become bound by the Act as a matter of law rather than choice, nothing in this policy changes. That is the point of writing it this way now.
Other Australian law that applies
- Spam Act 2003 (Cth), which governs commercial electronic messages, requires consent, sender identification and a working unsubscribe facility.
- Do Not Call Register Act 2006 (Cth), which governs unsolicited telemarketing. We do not telemarket.
- Australian Consumer Law, Schedule 2 to the Competition and Consumer Act 2010 (Cth), which gives you consumer guarantees that cannot be excluded by anything we write.
- Part IIIC of the Privacy Act, the Notifiable Data Breaches scheme, dealt with at its own section below.
- Privacy and Other Legislation Amendment Act 2024 (Cth), which introduced a statutory tort for serious invasions of privacy, provided for a Children's Online Privacy Code, and added transparency obligations for certain automated decisions. Those last two are dealt with in their own sections.
3Who decides, today and later
Australian privacy law does not use the controller and processor language that European law does. It regulates an "APP entity" that holds personal information, whoever it belongs to. Even so, the distinction between deciding what happens to information and merely handling it on somebody else's instruction is the single most useful thing to be clear about, so this section sets out both.
Today, we decide, and there is almost nothing to decide about
Everything covered by this policy is information we collect for our own purposes. Somebody writes to us and we answer. Somebody loads a page and the host records the request. We choose why that happens and what we do next, so responsibility for it rests here and nowhere else.
If retrieval software is ever supplied to a practice
The relationship would invert. A law practice would decide which of its documents to index, which of its people can search them, how long the index lives and when it is destroyed. We would be handling material on that firm's instruction. Two commitments follow from that, and they are written here so a firm can point at them before it signs anything.
- Instruction only. Documents supplied by a practice would be processed only to provide retrieval to that practice, and for no purpose of ours.
- No training. Client documents will not be used to train, tune, evaluate or improve any model, ours or anyone else's. This is a flat prohibition rather than a default that a settings page can reverse.
Any such arrangement would be governed by a written agreement naming where the data sits, who can reach it, what is logged, how long it is retained and how it is destroyed. Until such an agreement exists with an identified firm, none of this is operative, because there is no software and no firm.
4What we collect
Australian Privacy Principle 3 governs the collection of solicited personal information. It permits an organisation to collect personal information only where it is reasonably necessary for one or more of its functions or activities, requires collection by lawful and fair means, and requires collection from the individual themselves unless that is unreasonable or impracticable.
Applied to a company at this stage, that principle mostly operates as a limit rather than as a permission. The tables below are the complete inventory. If a category is not here, we do not hold it.
Information you give us by writing to us
| Category | Example fields | Why it is collected | If you withhold it |
|---|---|---|---|
| Email address | The address in the From header | To reply. There is no other route back to you. | We cannot answer. Nothing else is affected. |
| Name, if you sign the message | A signature block, a display name | To address you properly and to keep a thread coherent. | Write under a pseudonym. We will still answer. |
| Anything else in the body | A description of a practice, a question about scope, a security report | To understand and answer the message. | Entirely your choice what to include. |
| Mail transport metadata | Timestamps, message identifiers, delivery and spam headers | Generated automatically by mail systems. Used to trace a lost or spoofed message. | Not controllable by either of us. It is how email works. |
| Organisation details, if offered | A firm name, a role, a jurisdiction | To understand whether a question is about a small practice or something else. | Never required. |
Information created when you load a page
This website is a set of static files. There is no analytics package, no tag manager, no advertising pixel, no session recording, no heat map and no cookie of ours. What follows exists because a web server cannot answer a request without receiving one.
| Category | What it is | Who holds it | How long |
|---|---|---|---|
| Internet protocol address | The address your request came from, which may identify you indirectly | The hosting and content delivery provider, in its own logs | A short operational period set by that provider, not by us |
| Request line | The page requested, the time, the response status | The hosting provider | As above |
| User agent | Browser and operating system as reported by your browser | The hosting provider | As above |
| Referring page | Where you came from, if your browser sends it | The hosting provider | As above |
| Font request | The fact that your browser asked Google Fonts for two typefaces, which discloses your address to that service | Governed by Google, not by us. Explained in the cookie notice. |
We do not routinely read those logs, we do not export them, we do not join them to anything, and we do not build a profile from them. They exist so that a hosting provider can keep a service running and investigate abuse.
Information about the company itself
Corporate records, tax records, the domain registration and the accounts contain personal information about the people who run the company. Those records are kept because the Corporations Act 2001 (Cth) and the tax law require them to be kept. They are not about you and they are not disclosed on this website.
Sensitive information
Sensitive information has a defined meaning in section 6 of the Privacy Act and includes health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation, criminal record and biometric data. We do not collect sensitive information. No field anywhere in anything we operate is intended to hold it, and we do not ask for it.
If a message you send happens to contain it, we do not use it for anything beyond answering you, and you may ask us to delete the message.
5Notification at the point of collection
Australian Privacy Principle 5 requires that at or before the time we collect personal information about you, or as soon as practicable afterwards, we take reasonable steps to tell you a specific list of things. Our identity and how to contact us, the fact and circumstances of collection, whether collection is required by law, the purposes, the consequences of not providing the information, who we usually disclose it to, that this policy contains our access and correction and complaints processes, and whether we are likely to disclose the information overseas and to which countries.
How that obligation is met here
For a company whose only collection point is a published email address, meeting APP 5 through a notice at the moment of collection is awkward. There is no form to attach a notice to, and an automatic reply that recited a policy at everyone who wrote in would be worse than useless. So the obligation is met in three ways instead.
- This document. It is linked in the footer of every page of this website, including the page carrying the email address, and every element of the APP 5 list is answered in a numbered section rather than left to inference.
- The contact page. It states what happens to a message, what not to send, and what writing to us does not do, before you write rather than after.
- The tables above. Each row states the purpose of collection and the consequence of withholding, which are the two APP 5 items most policies leave out.
The overseas item, answered here
Yes, personal information you send us is likely to be accessible from outside Australia, because the mailbox and the hosting are operated by providers with infrastructure abroad. The countries are named in the recipients section. That section is the authoritative list, and it is kept accurate rather than hedged with a phrase about trusted partners.
6Dealing with us anonymously
Australian Privacy Principle 2 gives you the option of not identifying yourself, or of using a pseudonym, unless it is impracticable for us to deal with you that way or we are required by law to deal with an identified individual.
Here the option is real rather than theoretical. There is nothing on this website to sign into, so browsing it identifies you to us not at all. If you write to us, you may write from a pseudonymous address and sign the message with any name you like. We will answer it on its merits. We have no verification step, no identity check and no reason to want one.
The single place the option genuinely narrows is a request to access or correct personal information about you. To answer that we have to be satisfied you are the person the information is about, otherwise the access right becomes a disclosure risk for somebody else. What that involves in practice is set out in the access and correction section, and it does not involve sending us identity documents.
7Documents and information we did not ask for
Australian Privacy Principle 4 deals with personal information we receive without having asked for it. Where we receive such information, we must decide within a reasonable period whether we could have collected it under Australian Privacy Principle 3. If we could not have, and it is not contained in a Commonwealth record, we must destroy it or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
The scenario this company actually has to plan for
It is not a hypothetical. A company whose stated purpose is searching legal documents will, sooner or later, receive a legal document from somebody who wants to see it work. That attachment may be an executed contract naming individuals, a client file, a matter reference, a statement, or something covered by legal professional privilege that belongs to a client who has never heard of us.
We could not have collected that under APP 3. It is not reasonably necessary for any function of this company, we have no service to run it through, and the person sending it very often has no authority to disclose it. So it is destroyed.
What that means step by step
- The attachment is not opened beyond whatever the mail client shows automatically, and it is not saved anywhere, copied, forwarded or shared.
- It is deleted from the mailbox, including from the deleted items folder, and it leaves any provider level backup on that provider's ordinary cycle. We cannot reach inside a provider's backup rotation and we will not claim we can.
- We reply telling you it has been destroyed and asking you not to send another.
- Where the material appears to have been sent by somebody without authority to disclose it, we say so, because the sender may have a notification obligation of their own that they have not yet thought about.
The same treatment applies to any other unsolicited personal information about a third party, for example a message thread pasted into an email that contains somebody else's contact details.
If you have already sent us something like this, write to [email protected] with "Delete my data" in the subject line and we will confirm the destruction in writing. You do not need to explain yourself.
8Use and disclosure
Australian Privacy Principle 6 governs what may be done with personal information once it is held. Information collected for a primary purpose may be used or disclosed for that purpose, and for a secondary purpose only where you would reasonably expect it and the secondary purpose is related to the first, or where you consented, or where a specific exception in the Act applies.
What we use it for
- Answering your message, and any follow up in the same conversation.
- Keeping a record of a question that came up more than once, so that the website can be fixed rather than the same answer typed again.
- Handling a privacy request, a complaint or a security report, and evidencing that we handled it.
- Complying with a legal obligation, including our own corporate and tax record keeping.
What we do not do with it, stated as flatly as it can be stated
- We do not sell personal information. Not to a broker, not to an advertiser, not bundled into anything described as an audience.
- We do not use correspondence to target advertising. There is no advertising anywhere in this company.
- We do not add you to a mailing list because you wrote to us.
- We do not use anything you send us to train a model. This applies to ordinary correspondence as much as to documents, and it applies whether the model is ours or a third party's.
- We do not profile you across other services, because we have no means of doing so and no interest in acquiring one.
Disclosure required or permitted by law
We may disclose personal information where the Act permits it. That means where the disclosure is required or authorised by or under an Australian law or a court or tribunal order, where a permitted general situation under section 16A exists such as a serious threat to life, health or safety, or to an enforcement body where reasonably necessary for an enforcement related activity.
Where we disclose to an enforcement body we make a written note of it, as APP 6.5 requires. Where the law permits us to tell you a request was made, we will tell you. We will not volunteer information to anybody who merely asks politely without lawful authority, and a request of that kind will be refused in writing.
9Direct marketing, advertising and the Spam Act
Australian Privacy Principle 7 restricts the use of personal information for direct marketing. The Spam Act 2003 (Cth) sits on top of it for anything sent by email, SMS or instant message, and it is a strict regime: consent, accurate sender identification, and a functional unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days.
Our position
We do not run a marketing list. We have never sent a marketing email under this company name. If that changes, it will be opt in, the consent will be recorded with a timestamp and the wording you agreed to, and the first message will say where the address came from.
Writing to our support address does not subscribe you to anything. That is the most common way small companies quietly build a list, and we do not do it.
There is no advertising anywhere in this company
This website carries no advertising and no sponsored placement. The intended product carries none either, because a retrieval tool that put an advertisement next to a client's contract would be an extraordinary thing to build. There is therefore no advertising identifier, no personalisation setting and no advertising network in the supply chain, and nothing in the recipients table serves an advertisement.
We also do not buy advertising that targets you. No pixel on this site reports your visit to an advertising platform, so no audience can be built from it and no remarketing list exists.
The Spam Act, applied to what we actually send
Every message this company sends is a reply to a message somebody sent first. A reply to your own enquiry is not a commercial electronic message in the relevant sense, but the sender identification requirement is met anyway. Our replies say who we are and give the address to write back to. If we ever send anything that is a commercial electronic message, it will carry a working unsubscribe facility that stays live for at least 30 days and is actioned within 5 working days, as the Act requires.
10Who else can see any of it
The shortest honest description of our supply chain is that a company with no product has very little of one. Three providers can see something, and they are named rather than described.
| Recipient | What it does for us | What it can see | Where |
|---|---|---|---|
| Website host and content delivery network | Serves the static files that make up this website | Request logs, including internet protocol addresses and user agents | Edge locations worldwide, including outside Australia |
| Email provider | Receives and stores mail sent to the published address | The full content of any message you send, and its metadata | Provider infrastructure, which may be outside Australia |
| Google Fonts | Serves two typefaces to your browser | Your internet protocol address and browser details, at the moment the font is fetched. It receives nothing else and no content. | Google infrastructure, outside Australia |
| Domain registrar and registry | Holds the registration of the domain name | Registrant contact details for the company, not for visitors | Registrar infrastructure, outside Australia |
| Accountant, if engaged | Statutory accounts and tax lodgement | Company financial records. No visitor or correspondent data. | Australia |
Nobody else
There is no analytics vendor, no customer relationship system, no marketing platform, no support desk product, no chat provider, no error reporting service, no advertising network and no data enrichment service. Each of those is a normal thing for a small company to buy, and each is a place personal information ends up. We have bought none of them, and if that changes this table changes with it before the change takes effect.
A change of ownership
If the company were ever sold, merged or wound up, records could pass to a successor. Personal information would be transferred only with the obligations in this policy attached, and where the change materially affects how information about you is handled, we would say so on this page before it took effect.
11Sending personal information overseas
Australian Privacy Principle 8 governs disclosure of personal information to a recipient outside Australia. Section 16C of the Act makes us accountable for an overseas recipient's act or practice: if an overseas recipient we disclosed information to does something that would have breached the Australian Privacy Principles, that act is taken to have been done by us, and we are liable for it.
We treat that as the operative rule rather than the exceptions, which is why the list of overseas recipients is short and named rather than described as "our trusted partners".
How we meet APP 8
Before disclosing personal information overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, principally by contract. The relevant contractual terms are the data processing terms published by each provider, which bind them to process the data only on our instructions, to keep it secure, to assist with individual rights requests, and to notify us of a breach.
We do not rely on the APP 8.2(a) exception for recipients in countries with substantially similar laws, because assessing that for each jurisdiction is a judgement we are not qualified to make and getting it wrong shifts the risk onto you.
Where the data actually goes
The countries in which personal information may be held or accessed are named in the recipients table in this policy. That table is the authoritative list. If a provider changes region we update the table.
12Government related identifiers
Australian Privacy Principle 9 restricts an organisation from adopting a government related identifier as its own identifier for an individual, and from using or disclosing such an identifier except in narrow circumstances. Government related identifiers include tax file numbers, Medicare numbers, driver licence numbers, passport numbers and Centrelink reference numbers.
Our position
We do not collect any government related identifier. Nothing on this website asks for one. There is no account to open, no age check, no identity verification step and no payment to take, so there is no field anywhere that is intended to hold one. We do not use a government related identifier as our own reference for anybody, which is the specific thing APP 9.1 prohibits.
Why this section is longer than it looks like it needs to be
A company that searches legal documents has a particular exposure here that a company selling, say, a calendar does not. Executed contracts routinely contain identifiers. A licence number in a services agreement, a passport number in an immigration retainer, a tax file number in a document that should never have contained one. Any retrieval product operating over a firm's documents will encounter them, not because it collected them but because they were in the file.
Two things follow, and they are recorded here so they are not invented later under pressure.
- Identifiers occurring inside a practice's own documents would remain that practice's material. They would not be extracted, indexed as identifiers, used as a key for anything, or adopted by us as an identifier for a person.
- Where an identifier reaches us outside that arrangement, for example in an email attachment, it is unsolicited information and it is destroyed under the process described in the unsolicited information section.
Please do not send us a photograph of a licence, a passport page or any similar document. There is no circumstance in which this company needs one, and receiving it creates a problem for both of us that neither of us needed.
13Keeping information accurate
Australian Privacy Principle 10 requires that personal information we collect is accurate, up to date and complete, and that information we use or disclose is also relevant.
Almost everything we hold is something you wrote to us yourself, so accuracy here means whether it was true when you sent it and whether it still is. The category most likely to go stale is exactly that, an email address or a description of a practice sitting in a thread that is now a year old. We do not periodically re-verify those, because doing so would mean contacting people who have finished dealing with us in order to ask whether they are still themselves.
The practical remedy is the correction right under APP 13, described below, which you can use at any time and free of charge.
14Security, and what we do not hold
Australian Privacy Principle 11 requires us to take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure, and to destroy or de-identify it when it is no longer needed for any purpose for which it may be used or disclosed.
What "reasonable steps" means for a company this size
- Transport encryption on every connection. This website is served over HTTPS only, and mail to the published address travels over TLS wherever the sending server offers it.
- Encryption at rest for stored data, provided by the underlying platform.
- Multi-factor authentication on every administrative account this company has, which means the mailbox, the domain registration, the hosting account and the code repositories. There is no other administrative surface, because there is no product.
- Access on a need to know basis. The number of people who can reach the mailbox is very small, and it is reviewed whenever anyone joins or leaves.
- Nothing in production to breach. There is no hosted service, no account system, no customer database and no administrative console behind this site, so what has to be defended is a set of static files, one mailbox, a domain registration and a code repository.
- Collecting less. The most reliable security control available to a company of this size is not holding the data, which is why the collection tables on this page are as short as they are.
What we do not have, stated plainly
AI-LAW PTY LTD does not hold ISO/IEC 27001 certification, a SOC 2 Type I or Type II report, an IRAP assessment, or any other independent security accreditation, and will not represent otherwise until one is genuinely held. We have not engaged a third party to conduct a penetration test. We do not employ a full time security engineer.
We say this because the alternative is a paragraph of confident language that means nothing. No system is perfectly secure, and a company that tells you otherwise is either mistaken or selling something.
What would have to change before we held anybody else's documents
The controls above are proportionate to a company that holds correspondence and nothing else. They would not be adequate for a company holding a law practice's executed contracts, and we are not going to pretend otherwise by carrying this list forward unchanged. The conditions the company has set for itself before any release, including an independent review of the security arrangements by somebody who does not work here, are set out on the approach page of this website.
15Retention
Australian Privacy Principle 11.2 requires that where we no longer need personal information for any purpose for which it may be used or disclosed under the principles, and we are not required by law to retain it, we take reasonable steps to destroy it or ensure it is de-identified. Retention is therefore a rule with an expiry date attached, not a habit.
| Record | Period | Reason for that period |
|---|---|---|
| General correspondence | 24 months from the last message in the thread | Long enough that a conversation resumed a year later still makes sense, short enough that a mailbox is not an archive. |
| A thread you asked us to delete | Deleted on request, confirmed in writing | Your request. There is nothing here we need to keep against your wishes. |
| Privacy requests and our answers | 3 years | Evidence that an APP 12 or APP 13 request was handled properly, and within time, if the Commissioner later asks. |
| Privacy complaints and our answers | 5 years | Complaints can be escalated to the OAIC long after the event, and we would rather have the file than reconstruct it. |
| Security reports and incident records | 5 years | Part IIIC assessment records, and the ability to recognise a repeat of something. |
| Unsolicited documents and attachments | Destroyed as soon as practicable, ordinarily within 7 days | APP 4 requires destruction once we conclude we could not have collected it. |
| Financial and corporate records | 7 years | Section 286 of the Corporations Act 2001 (Cth) requires 7 years, and the tax law is consistent with that. |
| Hosting request logs | Set by the provider, short and operational | Held by the provider rather than by us. We do not extend it and we do not copy the logs out. |
Deletion from a live system does not instantly remove a record from a provider's backup rotation. Where that is the position we say so rather than claim an immediate erasure we cannot deliver. Backups age out on their ordinary cycle and are not consulted to reconstruct something a person asked us to delete.
16Access and correction
Australian Privacy Principle 12 gives you the right to ask for access to the personal information we hold about you. Australian Privacy Principle 13 gives you the right to ask us to correct it.
How to ask
Email [email protected] with "Privacy request" in the subject line. Tell us what you want and give us enough to find it. In practice everything we hold is indexed by the email address it came from, so writing from that address, or naming it, is normally the whole of what we need.
Verifying who you are
We have to be satisfied you are the person the information is about, or an authorised representative. Since there are no accounts, what we can actually verify is control of the email address the correspondence is under, and we will say that plainly rather than pretend to a higher level of confidence. Ordinarily that means replying to a message we send to that address. We will not ask you to send identity documents, and if anybody claiming to be us does, it is not us.
Timing and cost
We respond within 30 days. Access is free. We do not charge for making a request, and we do not charge for correction. If giving access in a particular form imposes a genuine cost, for example producing a bulk export in an unusual format, we will tell you the charge before doing the work and it will not be excessive.
When we can refuse
The Act lists the grounds, and they are narrower than people expect. They include where giving access would have an unreasonable impact on the privacy of others, where the request is frivolous or vexatious, where the information relates to existing or anticipated legal proceedings and would not be discoverable, and where giving access would be unlawful.
If we refuse, in whole or in part, we will give you written reasons, tell you which ground we rely on, and tell you how to complain. Where we can give you part of the information, or give it in another way that meets your need, we will offer that instead of a flat refusal.
Correction
If information is inaccurate, out of date, incomplete, irrelevant or misleading, we will correct it. If we have disclosed the information to someone else and you ask us to notify them of the correction, we will take reasonable steps to do so unless it is impracticable or unlawful.
If we refuse to correct, you may ask us to attach a statement to the record saying that you consider it inaccurate, and we will take reasonable steps to make that statement apparent to anyone who later looks at the record. That right is often overlooked and it is worth knowing about.
17Deleting what we hold
There is no account to close, because there are no accounts. Deletion here means one thing, which is removing the record of your dealings with this company.
How to ask
Email [email protected] with Delete my data in the subject line, from the address the correspondence is under if you can. You do not have to give a reason and we will not ask for one.
What happens
- We find every thread associated with the address and any attachment stored with it.
- We delete them from the mailbox, including from the deleted items folder.
- We confirm in writing what was deleted and what, if anything, was retained.
- We complete the whole thing within 30 days, and usually within a few days.
What may be retained, and why
- A minimal record that a deletion request was made and actioned. Without it we cannot demonstrate that we did what you asked, and it holds the address and the date and nothing else.
- Anything we are required by law to keep, principally financial records under section 286 of the Corporations Act 2001 (Cth). No correspondent has ever been in that category, because the company has invoiced nobody.
- Material inside an open complaint or an active legal proceeding, until it concludes. We would tell you if that applied and why.
Backups age out on their normal cycle as described in the retention section. We do not restore a backup in order to reinstate something a person asked us to delete.
18Confidentiality and legal professional privilege
This section is not required by the Privacy Act. It is here because the intended customers are law practices, and for them confidentiality and legal professional privilege are the whole game.
Two distinct obligations
A solicitor owes a duty of confidentiality to a client under the applicable professional conduct rules. Separately, legal professional privilege attaches to certain communications and belongs to the client rather than the practitioner. Disclosing privileged material to a third party can waive that privilege, and the consequence lands on the client and the practice rather than on the supplier who received it.
What that means for how this company behaves
- We do not want a practice's client documents in our possession, and the intended design keeps indexing on infrastructure a practice controls precisely so that the question of waiver does not arise unnecessarily.
- Where a hosted arrangement were ever chosen by a practice, it would be documented in a written agreement setting out confidentiality obligations, the location of the data, who can reach it and how it is destroyed, so that the practice can put the facts in front of whoever advises it.
- We will never suggest to a practice that using this company's software is consistent with its professional obligations. That is a judgement for the practice, on advice, and a supplier who offers reassurance on the point is doing something improper.
- Documents sent to the published mailbox are destroyed rather than read, which is the only responsible way to handle material that may be privileged and that we had no right to receive.
AI-LAW PTY LTD is not an incorporated legal practice and holds no practising certificate. Nothing in this policy, on this website, or in any reply from the published address is legal advice.
19Children and young people
This is a website about business software for law practices. It is not directed at children, it is not designed to appeal to children, and there is nothing on it for a child to sign up to, buy, download or play.
The Australian position
The Privacy Act does not fix an age at which a person can consent for themselves. The Commissioner's guidance is that capacity should be assessed individually where practicable, and that as a general rule a person aged 15 or over may be presumed to have capacity unless something suggests otherwise. We apply that presumption on the rare occasion it could matter, which would be a young person writing to the mailbox.
The Privacy and Other Legislation Amendment Act 2024 (Cth) provides for a Children's Online Privacy Code to be developed by the Information Commissioner, applying to services likely to be accessed by children. This website is not such a service. If that assessment ever changes, we will comply with the Code as it applies to us and update this page then, rather than guess at its terms in advance.
In practice
- We do not knowingly collect personal information from a child under 15 without the consent of a parent or guardian.
- There is no account, no profile, no social feature, no chat, no user generated content and no advertising anywhere on this website.
- If a child has written to us, tell us at [email protected] and we will delete the correspondence and confirm that it is done. We will not require proof of a legal relationship beyond enough to be satisfied the request is genuine.
20Automated processing and automated decisions
Schedule 1 to the Privacy and Other Legislation Amendment Act 2024 (Cth) adds a requirement that a privacy policy disclose the kinds of personal information used in substantially automated decisions that significantly affect an individual's rights or interests, together with the kinds of decision made. That requirement commences on 10 December 2026. This section is written in advance of the commencement date rather than after it.
Our position today
We make no automated decision of any kind about any individual. Nothing this company runs decides whether a person gets credit, a job, a service, a benefit, a price or a legal entitlement. There is no scoring, no ranking of people, no eligibility logic and no profiling. A person reads every message that arrives and answers it.
What automation would exist in the intended product, and why it is not this
Retrieval ranking is automated. When the software eventually orders passages by similarity to a query, no person picks the order. That is a decision about which paragraph of a contract to show first. It is not a decision about a person, it has no effect on anybody's rights or interests, and describing it as an automated decision in the statutory sense would be a category error that makes the disclosure less useful rather than more.
Two commitments follow, so that this section keeps working if the product ever exists.
- A ranking score will not be presented as a probability, a confidence level, a risk rating or a prediction about a matter or a party.
- If the company ever builds anything that does make a decision about a person, it will be described in this section, with the kinds of information used and the kinds of decision made, before the processing begins.
21Data breaches and the notification scheme
Part IIIC of the Privacy Act establishes the Notifiable Data Breaches scheme. It applies to an eligible data breach, meaning unauthorised access to, unauthorised disclosure of, or loss of personal information where a reasonable person would conclude the access or disclosure would be likely to result in serious harm to any of the individuals to whom the information relates, and the risk has not been prevented by remedial action.
The process we follow
- Contain. Stop the access, revoke the credential, take the affected component offline if that is what it takes.
- Assess. Where we suspect an eligible data breach may have occurred, we carry out a reasonable and expeditious assessment and complete it within 30 days of becoming aware of the grounds for suspicion, which is the period section 26WH allows.
- Remediate. If remedial action means serious harm is no longer likely, the breach is not notifiable and we record why.
- Notify. If it is an eligible data breach, we prepare a statement for the Commissioner and notify the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au as soon as practicable. We then notify affected individuals, or if that is not practicable, publish the statement on this website and take reasonable steps to publicise it.
What a notification will contain
Our identity and contact details, a description of the breach, the kinds of information concerned, and the steps we recommend you take. We will not pad it with reassurance that has not been earned, and we will say what we do not yet know.
If you think a breach has happened
Write to [email protected] with "Security" in the subject line. We would rather chase a false alarm than miss a real one, and we will not treat a good faith report as hostile.
22The statutory tort of serious invasion of privacy
A statutory tort of serious invasion of privacy commenced on 10 June 2025 under Schedule 2 to the Privacy and Other Legislation Amendment Act 2024. It allows an individual to sue for intrusion upon seclusion or misuse of information, where the invasion was intentional or reckless, where a person in the plaintiff's position would have had a reasonable expectation of privacy, and where the invasion is serious.
This is a right you have against anyone, including us, and it exists independently of the complaints process described below. We mention it because most privacy policies do not, and a right you do not know about is not much of a right.
23Cookies and this website
This website sets no cookies of its own. Not one, not for analytics, not for preferences, not for a consent banner. Nothing is written to local storage or session storage by our code.
Because nothing is stored, there is no consent banner, and its absence is deliberate rather than an oversight. Australia has no direct equivalent of the European rule requiring consent for storing information on a device. The relevant Australian obligations are Australian Privacy Principle 3, which limits collection to what is reasonably necessary, and Australian Privacy Principle 5, which requires notification. Collecting nothing satisfies the first, and this page and the cookie notice satisfy the second.
One thing does still leave your browser. Two typefaces are requested from Google Fonts, which discloses your internet protocol address to Google at the moment the font loads. That is the only third party request the website makes, and it is described in full in the cookie notice, along with how to prevent it if you would rather not make it.
24Complaints
Step one: tell us
Email [email protected] with "Privacy complaint" in the subject line. Set out what happened and what you want done. We acknowledge within 5 business days and respond substantively within 30 days. If it will take longer, we will tell you why and give you a date.
Step two: the Commissioner
If you are not satisfied with our response, or we do not respond within 30 days, you can complain to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.
The OAIC will normally expect you to have complained to us first and given us 30 days, but it can accept a complaint without that in appropriate cases. There is no fee. You do not need a lawyer and you do not need our agreement.
What we will not do
We will not require you to sign a non-disclosure agreement as a condition of us dealing with a privacy complaint, and we will not treat making a complaint as a breach of our terms of use.
25If you are outside Australia
This policy is written to Australian law because that is the law that binds us. If you are outside Australia, some additional rights may apply to you, and we do not want the absence of a mention to be read as a refusal.
European Economic Area and United Kingdom
Where the General Data Protection Regulation or the UK GDPR applies to our processing, you have rights of access, rectification, erasure, restriction, portability and objection, and a right to complain to your national supervisory authority. Where we rely on legitimate interests, you may object and we will stop unless we can demonstrate compelling legitimate grounds that override your interests. Where we rely on consent, you may withdraw it at any time without affecting the lawfulness of processing before withdrawal.
Send any such request to [email protected] and say which law you are relying on, so we apply the right timetable. We answer GDPR requests within one month.
California
Under the California Consumer Privacy Act as amended, you have rights to know, delete, correct and opt out of the sale or sharing of personal information. We do not sell personal information and we do not share it for cross context behavioural advertising as those terms are defined in that Act. There is no advertising on this website and none in anything this company is building, so there is no sale and no sharing for anyone to opt out of. Global Privacy Control signals sent by your browser to this website are honoured.
Everywhere else
If a right exists where you live and you tell us about it, we will deal with the request on its merits rather than on whether we are technically obliged to.
26Changes to this policy
We may change this policy. When we do, we update the effective date and the version number in the header of this page.
Where a change materially reduces your rights or materially expands what we collect, we will give notice before it takes effect: a note at the top of this page for at least 30 days, and, if a practice is by then using anything we supply, a direct message to that practice. We will not make a material change effective retrospectively.
Previous versions are not published as separate pages, but we keep them. If you want to know what this document said on a particular date, ask and we will send you that version.
This policy is a professionally structured document. It is not legal advice, and it is not a substitute for advice from an Australian legal practitioner on your own circumstances.
27How to contact us
All privacy matters reach one address.
| Matter | Subject line | Response |
|---|---|---|
| Access to your personal information (APP 12) | Privacy request | 30 days |
| Correction of your personal information (APP 13) | Privacy request | 30 days |
| Deletion of everything we hold about you | Delete my data | 30 days |
| Complaint about our handling of personal information | Privacy complaint | Acknowledged in 5 business days, answered in 30 days |
| Suspected security incident or data breach | Security | Same or next business day |
| A practice describing how it finds clauses today | Practice | 5 business days |
| Anything else | Anything sensible | 5 business days |
Email: [email protected]
Entity: AI-LAW PTY LTD, an Australian proprietary company, Western Australia. ACN 698 421 608. ABN 23 698 421 608. Not currently registered for GST.
We do not publish a postal address on this website. If you need to serve a document, the company's registered office is recorded against ACN 698 421 608 on the register maintained by the Australian Securities and Investments Commission, which is the address that has legal effect for service.
If you would rather not deal with us at all, you can go straight to the Office of the Australian Information Commissioner (OAIC), GPO Box 5218, Sydney NSW 2001, telephone 1300 363 992, oaic.gov.au.