Privacy Policy
Last updated: May 2026
Our Approach to Privacy
Sasphire Legal (“we”, “us”, or “our”) respects your privacy and is committed to complying with the Australian Privacy Principles (APPs) contained in the Privacy Act 1988 (Cth) (Privacy Act).
The Privacy Act contains exemptions and permitted general situations in relation to certain acts and practices, including in relation to employee records, legal claims and litigation, and related bodies corporate. Where appropriate, we make use of relevant exemptions in the Privacy Act. In particular, the APPs do not apply to an employee record held by us in relation to current or former employees where the handling of that record is directly related to the employment relationship. This exemption applies only to our own employees and does not affect our obligations in respect of personal information we collect about other individuals in the course of providing legal services.
This Privacy Policy sets out how we collect, use, store and disclose personal information. It applies to all individuals who interact with our firm, including clients, prospective clients, website visitors, job applicants, employees, contractors, suppliers, event attendees, and any other person whose personal information we may handle in the course of our operations.
We may modify this policy from time to time by publishing updates on our website. We encourage you to check our website periodically to ensure you are aware of our current privacy policy.
What Personal Information Do We Collect?
Personal information includes information or an opinion (whether true or not) about an identified or a reasonably identifiable individual.
We may collect your personal information where:
- you enquire about or instruct us to provide legal services to you, your employer, organisation or other representative;
- you are a director or ultimate beneficial owner of a prospective or existing client or client’s group;
- we have other legal or business dealings with you or an organisation related to you (for example, if you are involved in a corporate transaction or are otherwise related to, employed by, or engaged by a counterparty, regulator, referrer of work, or supplier);
- you are an employee, contractor or office holder of Sasphire Legal;
- you subscribe to or use one of our online services, newsletters, mailing lists or visit our website;
- you register for or attend one of our events, seminars or webinars;
- you enquire about or apply for a role at Sasphire Legal, participate in a work experience program, internship or clerkship, or otherwise work temporarily or on contract for us; or
- you otherwise engage or communicate with us.
The types of personal information we may collect include:
- general, personal or business details such as your name, job title, contact number, address and email address;
- if you apply for a role with us, information about your work history, reference and background check information, identity verification information, and information about your right to work in Australia;
- if you are a current or former employee or contractor, other information as necessary and relevant to your engagement, including emergency contact details, information about remuneration and benefits, and information about your performance, training and development;
- if you are a current or potential client, or employed or engaged by one, your expertise, business interests, attendance at events and identification information for regulatory purposes;
- if you are a current or potential client, or you are providing us instructions on behalf of a client, or you are a director or ultimate beneficial owner of a client or client group: your full name, date of birth, residential address and other information to verify your identity, including government identifiers and government identity documents;
- where necessary as part of undertaking a transaction on your behalf or on behalf of a client: your name and other information to verify your identity such as a copy of your passport, driver’s licence or other identity document;
- your or your organisation’s financial or billing information, such as billing address, bank account, payment and credit card details;
- your marketing and communication preferences;
- information to identify the devices, IP addresses and internet service providers you use to access our website or online services;
- user names and passwords where they are required on our website or for access to our systems as part of our legal services; and
- where relevant and with your consent, sensitive information including:
- information about your health, any disabilities and special dietary needs (for example, where you register for or attend an event or in connection with your engagement with us);
- information we need in order to provide you with legal advice, which may include information about health conditions, racial or ethnic origin, trade union membership, criminal records, or other sensitive matters where relevant to a client matter (for example, unfair dismissal claims, discrimination complaints, workers’ compensation matters, or workplace investigations); and
- your membership of professional associations or boards for conflicts or regulatory assessments.
How Do We Collect Your Personal Information?
We generally endeavour to collect your personal information directly from you. However, in some circumstances we may collect your information from third parties, such as:
- your employer or contracting agency, your business contacts or other organisations that you deal with, regulatory or credit reporting agencies, a supplier or from a publicly available record;
- where you apply for a role with us, from recruitment consultants, your previous employers, universities and others who may be able to assist us in our decision as to whether to offer you employment; or
- where you are a current or potential client (or you work for or are connected with a client), third-party IT providers and verification, screening or onboarding suppliers.
For other methods of collection, please see the section titled “Using Our Website, Electronic Messages and Cookies” below.
Personal Information About Others
In the course of engaging with us, you may provide us with personal information about other individuals (for example, information about your employees, directors, witnesses, respondents, or other persons relevant to a legal matter). If you provide personal information to us about someone else, you must ensure that you are entitled to disclose that personal information to us and that, without our taking any further steps, we may collect, use and disclose that personal information as described in this Privacy Policy. In particular, you must ensure the individual concerned is aware of the matters detailed in this Privacy Policy as they relate to that individual, including our identity, how to contact us, our purposes of collection, our disclosure practices (including disclosure to overseas recipients and use of AI tools), the individual’s right to access their personal information and make complaints, and the consequences if the personal information is not provided. This obligation is particularly important in employment and workplace matters where you may provide us with sensitive personal information about employees or other third parties.
Why Do We Collect, Use and Disclose Your Personal Information?
We may use your personal information to:
- facilitate our client due diligence, client onboarding, anti-money laundering, counter-terrorism financing, “know your client” and other new business acceptance processes;
- verify your identity;
- provide our services and products to you, your organisation and our clients, and to improve them;
- identify and develop new services and products you, your organisation or our clients may be interested in;
- conduct, monitor and analyse our business and internal operations (including staff management);
- communicate with you and build and maintain our relationships with you, your organisation and our clients;
- send you legal updates and insights, marketing and event details, and new service or product offerings (however, if you do not want to receive marketing communications from us, you can opt out at any time using the contact details set out below);
- comply with applicable laws and our other regulatory, accounting, reporting and professional obligations;
- comply with court orders and to protect, exercise or defend our legal rights;
- provide you with work experience opportunities, discuss any potential roles with you, consider your application and test and assess your suitability for roles;
- process and respond to your requests, enquiries or complaints; and
- support the delivery of legal services using approved technology tools, including artificial intelligence tools, in accordance with our AI governance framework (see our “AI at Sasphire” page for further details).
We are also bound to our clients by professional obligations of confidentiality and legal professional privilege. We will continue to treat and protect all client information we receive (including any personal information) in accordance with these obligations.
Confidentiality and Legal Professional Privilege
In addition to our obligations under the Privacy Act, we are bound by professional duties of confidentiality and legal professional privilege. All information provided to us in the course of a solicitor-client relationship is treated as confidential and is protected by legal professional privilege where applicable. These obligations apply regardless of the medium through which information is communicated or stored, including where information is processed using approved technology tools. Our confidentiality obligations continue indefinitely, even after the conclusion of a matter or the termination of a retainer.
To Whom Do We Disclose Your Personal Information?
We may disclose your personal information to:
- our clients, where we have collected your personal information for the purposes of providing services to our clients;
- barristers, legal consultants and other specialists in relation to your matter;
- our suppliers, contractors and agents from time to time that provide services to us or help us to provide and market our services to you;
- specific third parties authorised by you to receive information held by us;
- approved technology service providers, including artificial intelligence platforms, that assist us in delivering legal services (subject to appropriate data security and contractual safeguards); and
- other persons, including government agencies, regulatory bodies, law enforcement agencies and courts, as otherwise required or authorised by law.
While we aim to use services and instances that are located in Australia, some of these suppliers and other parties may receive, access, process, host or store your information in overseas locations, including the United States of America, the United Kingdom, and the European Union. For example, we may disclose your personal information to IT providers or AI platform providers which may store or process the information in an overseas jurisdiction. Where we do so, we take reasonable steps to ensure that recipients of your personal information comply with obligations consistent with the APPs.
Using Our Website, Electronic Messages and Cookies
We may collect and store information about your use of our website, such as which pages you visit, the time and date of your visit, the documents you download, and the IP (internet protocol) address assigned to your device.
We and our internet service providers also collect information such as the pages you access on our website, the amount of time you spend on a page, which links you use to access our site, and the type of device and browser you use. This information is used to improve the services we offer you, for statistical and website development purposes.
Cookies. A cookie is a small text file that is placed on your device when you visit a website. We use cookies and similar tracking technologies to enhance your browsing experience, analyse website traffic, and understand how visitors interact with our website. We use the following types of cookies:
- Strictly Necessary Cookies: These cookies are essential for the website to function properly. They enable basic features such as page navigation and access to secure areas of the website. The website cannot function properly without these cookies, and they cannot be disabled.
- Analytics Cookies: These cookies allow us to count visits and traffic sources so that we can measure and improve the performance of our website. They help us understand which pages are the most and least popular and how visitors move around the site. All information collected by these cookies is aggregated and therefore anonymous.
- Functional Cookies: These cookies enable the website to provide enhanced functionality and personalisation, such as remembering your preferences. If you do not allow these cookies, some or all of these features may not function properly.
Managing Your Cookie Preferences. Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all or some cookies, or to alert you when cookies are being sent. Please note that if you disable or refuse cookies, some parts of our website may become inaccessible or not function properly. You may also manage your preferences through the cookie consent banner displayed when you first visit our website. You can update your preferences at any time by clicking the “Cookie Settings” link in the footer of our website.
Third-Party Services. Our website may use third-party services, such as Google Analytics, which set their own cookies to help us analyse how visitors use the site. We do not sell, trade, or otherwise transfer your personal information to advertisers or unrelated third parties. Where we disclose information to third-party service providers, we have contractual agreements in place to protect your information.
If you click through to our website from any communication we send to you, we may identify and collect information relating to your subsequent and previous use of our website. Subject to your communication preferences, we may contact you in relation to those insights or service areas.
Our website may contain links to websites operated by third parties. We are not responsible for the privacy practices of those websites, and we encourage you to read the applicable privacy policy of any linked site before using it.
How Do We Store and Keep Your Information Secure?
We may hold your personal information in either electronic or hard-copy form. We use a variety of physical and electronic security measures to keep your personal information secure from misuse, interference, loss or unauthorised access, use or disclosure. For example, we restrict physical access to our offices, employ firewalls, secure databases, password-protect our IT systems, regularly update our security software, and conduct regular audit and data integrity checks. All of our employees are also bound to keep your personal information secure and treat it as confidential.
Where we use technology tools, including AI platforms, to assist in the delivery of legal services, we ensure that appropriate technical and organisational safeguards are in place, including data encryption in transit and at rest, access controls, and contractual protections with service providers.
However, we cannot guarantee the security of your personal information. The internet is not a secure environment. If you use the internet to send us any information, including your email address, please be aware that it will be sent at your own risk.
We will update, retain and delete your data in accordance with our policies and procedures, applicable laws and, where applicable, your instructions.
We also comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act. In the event of an eligible data breach that is likely to result in serious harm to any individual whose personal information is involved, we will notify the affected individuals and the Office of the Australian Information Commissioner (OAIC) as required by law.
Are You Required to Provide Your Personal Information?
You may deal with Sasphire Legal anonymously; however, this may affect the services we are able to provide to you. For example, we may not be able to take your instructions as a client or provide legal advice if we are unable to verify your identity or collect necessary information.
Use of Artificial Intelligence
Sasphire Legal uses approved artificial intelligence (AI) tools, including generative AI, to assist in the delivery of legal services. Our use of AI is governed by a comprehensive AI governance framework. For full details on how we use AI, including our data security commitments, governance approach, and answers to frequently asked questions, please refer to our “AI at Sasphire” page.
For further details on how we use AI, including our data security commitments, governance approach, and answers to frequently asked questions, please refer to our “AI at Sasphire” page.
Direct Marketing
You can unsubscribe or opt out of receiving direct marketing communications at any time. You can do this by:
- selecting “unsubscribe” on the relevant marketing communication;
- following the prompts in the relevant marketing communication; or
- contacting our Privacy Officer using the contact information below.
We will action your unsubscribe or opt-out as soon as reasonably practicable and in any event within any mandatory periods required by law (for example under the Spam Act 2003 (Cth)).
Data Retention
We retain personal information only for as long as is necessary to fulfil the purposes described in this policy, or as required or permitted by law. As a general guide:
- client matter files and related personal information are retained for a minimum of 7 years following the completion of a matter, unless a longer period is required by law or the nature of the matter;
- recruitment and job application records are retained for up to 2 years following the conclusion of the recruitment process;
- website analytics and cookie data are retained for up to 12 months unless a longer period is required for ongoing analysis; and
- financial and billing records are retained in accordance with applicable taxation and corporations legislation.
We will, in particular, retain your personal information where required to assert or defend against legal claims until the end of the relevant retention period or until the claims in question have been settled.
Accessing or Correcting Your Personal Information
You have rights under the Privacy Act to:
- request access to personal information we hold about you; and
- ask us to update or correct any information that is inaccurate, incomplete or out of date.
You can do any of these things by contacting us using the contact details below. If you request access to your personal information or ask us to correct or update information about you, we may need to verify your identity. In some circumstances, there may be a valid reason for us to deny your request to access or correct your information. If we do this, we will tell you why.
Making a Complaint
If you think we have breached the Privacy Act, or you wish to make a complaint about the way we have handled your personal information, you can contact us using the details set out below. Please include your name, email address and telephone number and clearly describe your complaint.
Any complaint will be investigated and the outcome of that investigation will be communicated to you as soon as we are able to do so.
If you are not satisfied with the outcome of any internal investigation we conduct, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC) at enquiries@oaic.gov.au or on 1300 363 992. More information is available on the OAIC’s website at https://www.oaic.gov.au/.
Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices or for other operational, legal, or regulatory reasons. We will post the revised policy on this page and update the “Last updated” date above. We encourage you to review this policy periodically.
Contact Us
If you would like more information about how we handle your personal information or our approach to privacy, or to exercise any of your rights outlined above, please contact us at admin@sasphire.com.au.