Privacy Policy

1. Introduction

Skylar Legal (we, us or our) respects your privacy and is committed to protecting your personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

This Privacy Policy explains how we collect, use, store, disclose and protect personal information when you visit our website at https://skylarlegal.com, contact us, make an enquiry, or engage us to provide our professional services.

This Policy also explains how we handle information collected for identity verification, anti-money laundering and counter-terrorism financing (AML/CTF), sanctions screening, fraud prevention and related regulatory compliance purposes.

A current version of this Policy is publicly available on our website without requiring a login.

2. Personal information we may collect

We collect personal information that is reasonably necessary for our business activities and for the services we provide. Depending on your matter and your dealings with us, this may include:

  • your full name, former names or aliases, date and place of birth, nationality, citizenship, residency status and visa information;
  • your residential, postal or business address, email address, phone number and other contact details;
  • information submitted through our website forms, email enquiries, telephone calls, messaging platforms, consultations, questionnaires or client intake forms;
  • identity document information, such as driver licence, passport, Medicare card, national identity card, visa grant notice, birth certificate or other government-issued identification details;
  • copies or images of identity documents where required for verification, client due diligence, professional conduct, conveyancing, trust accounting, migration or regulatory compliance purposes;
  • biometric information, such as a facial image, selfie or short video used for electronic verification of identity;
  • information relevant to your legal or migration matter, including property details, contract information, financial information, bank account details, source of funds or source of wealth information, tax information, company or trust documents, family information, estate planning information, visa and immigration records, employment information and transaction records;
  • information about companies, trusts, partnerships, associations or other legal arrangements connected with a matter, including details of directors, shareholders, trustees, beneficiaries, beneficial owners, settlors, appointors, officeholders, authorised representatives and signatories;
  • screening information relevant to AML/CTF and sanctions compliance, such as politically exposed person (PEP), sanctions, adverse media, fraud risk or other risk assessment information;
  • billing, payment, trust account, cost agreement and transaction records relating to our services;
  • technical and website usage information, such as IP address, browser type, device information, cookies and website analytics data; and
  • any other information you choose to provide to us.

3. Sensitive information

Some information we collect may be sensitive information under the Privacy Act. This may include biometric information, government identifier information, health information, criminal history information, racial or ethnic origin, professional memberships, immigration-related information or other sensitive information relevant to your matter.

We only collect sensitive information where it is reasonably necessary for our functions or activities and where you have consented, or where the collection is required or authorised by law.

4. Why we collect, use and disclose personal information

We may collect, use and disclose personal information for the following purposes:

  • to respond to enquiries and communicate with you;
  • to assess whether we can act for you, open and manage your client file, conduct conflict checks and carry out client onboarding;
  • to provide, manage and administer our professional services;
  • to verify your identity and the authority of any representative, attorney, director, trustee, beneficial owner, signatory or other relevant person;
  • to conduct customer due diligence, ongoing due diligence, sanctions screening, source of funds or source of wealth checks, risk assessments and other AML/CTF compliance steps;
  • to comply with professional, ethical, trust accounting, conveyancing, migration, court, tribunal, tax, AML/CTF and other legal or regulatory obligations;
  • to process payments, manage trust money, issue invoices and maintain accounting and business records;
  • to communicate with third parties involved in your matter, where appropriate and permitted;
  • to protect against fraud, identity theft, cyber incidents, unauthorised access or misuse of our systems;
  • to improve our services, website, client experience and internal processes;
  • to send legal updates, newsletters or other information about our services where you have opted in or where permitted by law; and
  • for any other purpose required or authorised by law or for which you have consented.

We only use or disclose your personal information for the purposes for which it was collected, for a related purpose you would reasonably expect, where you have consented, or where required or authorised by law.

5. AML/CTF compliance and client due diligence

As part of our professional and regulatory obligations, including where we provide designated services to which AML/CTF obligations apply, we may be required to collect and verify information about clients and other relevant persons before we provide certain services, and during the course of a matter. These steps may include identifying and verifying individuals and entities, understanding ownership and control structures, identifying beneficial owners, understanding the nature and purpose of a transaction or matter, and obtaining information about source of funds or source of wealth where required.

We may also conduct screening or checks against sanctions lists, politically exposed person lists, adverse media sources, government records, public registers, commercial databases and other sources reasonably necessary for AML/CTF, fraud prevention, risk management or legal compliance purposes.

If we cannot obtain or verify information that we reasonably require, we may be unable to act, may need to delay or cease acting, may be required to decline or terminate an engagement, or may be required to take steps under applicable law.

Nothing in this Policy limits our duties of confidentiality, legal professional privilege, or our professional obligations as legal practitioners, except to the extent that disclosure is required or authorised by law.

6. Identity verification and Government data matching, including DVS

To verify your identity, we may use electronic identity verification services, including the Australian Government Document Verification Service (DVS).

Where you have consented, your name, date of birth and identity document details may be securely sent to the relevant Commonwealth, State or Territory authority, or other authorised record holder, that issued or maintains the document or record. This may include passport offices, driver licence authorities, the Department of Home Affairs, Births, Deaths and Marriages registries, Medicare or other authorised record holders.

Those authorities or record holders check whether the details you provided match the records they hold. We do not receive a copy of your government records through the DVS. We receive a match result only, usually confirming whether the details match or do not match.

This process may be carried out through authorised identity verification, VOI or onboarding providers and platforms used by us, including APLYiD (APLYiD Pty Ltd, ABN 36 632 866 794), InfoTrack and their authorised providers, related platforms or sub-providers.

More information about the DVS is available at idmatch.gov.au.

7. Biometric information

As part of electronic identity verification, we or our authorised identity verification providers may collect biometric information, such as a facial image, selfie or short video of you holding or presenting your identification document.

Biometric information may be used to:

  • confirm that you are a real person and physically present during the verification process;
  • compare your image with the photograph on your identity document;
  • detect fraud, impersonation, tampering or identity theft; and
  • support compliance with verification of identity, AML/CTF and related legal obligations.

Biometric information is treated as sensitive information. We only use it for identity verification, AML/CTF, fraud prevention and related compliance purposes, and only with your consent or where required or authorised by law.

8. Consent to collection and electronic identity verification

By providing personal information to us and completing an electronic identity verification process, you consent to:

  • the collection, use and disclosure of your personal information for identity verification, AML/CTF, sanctions screening, fraud prevention, legal compliance and related matter-management purposes;
  • the collection and use of biometric information, such as a facial image, selfie or video, for identity verification and related compliance purposes;
  • your information being checked against records held by Commonwealth, State or Territory authorities, or other authorised record holders, including through the DVS; and
  • your information being shared with our authorised identity verification, VOI or onboarding providers and platforms, including APLYiD, InfoTrack and their authorised providers, related platforms or sub-providers.

Your consent is voluntary. You may withdraw your consent by contacting us using the details in section 17. If you do not consent, withdraw consent, or do not provide the information we reasonably require, we may need to verify your identity by another method, may be unable to verify your identity, or may be unable to provide some or all of our services to you.

9. How we collect personal information

We usually collect personal information directly from you. We may also collect personal information from:

  • your authorised representatives, family members, business partners, agents, attorneys, accountants, mortgage brokers, real estate agents or other advisers;
  • counterparties, other solicitors, barristers, courts, tribunals, government departments, regulators, councils, strata managers, PEXA, financial institutions and settlement participants;
  • public registers, company and land title searches, sanctions lists, government databases and commercial information providers;
  • identity verification, VOI and onboarding providers, including APLYiD, InfoTrack and related verification platforms;
  • online forms, cookies, analytics tools and website technology; and
  • other sources where it is reasonable, lawful and necessary for the services we provide.

10. Disclosure of personal information

We may disclose personal information to:

  • our employees, contractors and authorised representatives on a need-to-know basis;
  • barristers, consultants, accountants, auditors, experts, interpreters, mortgage brokers, real estate agents, strata managers, migration-related third parties or other professionals engaged in or relevant to your matter;
  • identity verification, VOI and onboarding providers, including APLYiD, InfoTrack and authorised providers, related platforms or sub-providers;
  • Commonwealth, State or Territory authorities and official record holders through the DVS or other authorised verification channels;
  • courts, tribunals, government departments, regulators, law enforcement agencies, AUSTRAC or other authorities where required or authorised by law;
  • banks, lenders, trust account institutions, payment processors, PEXA and other transaction or settlement participants where relevant to your matter;
  • IT, cloud storage, email, practice management, document management, cyber security, analytics, website hosting and other service providers who help us operate our business;
  • insurers and professional advisers for risk management, insurance, audit or compliance purposes;
  • other parties where you have consented or where disclosure is necessary to provide our services.

We do not sell your personal information.

11. Overseas disclosure

Most of our business operations are conducted in Australia. However, some of the technology platforms, cloud services, website tools, identity verification providers, analytics tools, communication platforms and other service providers we use may store, access or process personal information outside Australia, or may use overseas support teams, related entities or sub-processors.

Where personal information is disclosed to, accessed by or processed by overseas recipients, we take reasonable steps to ensure that it is handled consistently with the Australian Privacy Principles, including by using reputable providers and appropriate contractual, technical and organisational safeguards where practicable.

The countries in which overseas recipients may be located depend on the systems, platforms and service providers used from time to time. It may not always be practicable for us to specify each country in advance.

12. Data security and storage

We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification or disclosure. These steps may include access controls, secure systems, password protection, encryption in transit and at rest where appropriate, staff confidentiality obligations, cyber security measures, secure document management and internal procedures.

No method of transmission or storage is completely secure. While we take reasonable steps to protect information within our control, we cannot guarantee absolute security of information transmitted over the internet or through third-party platforms.

We retain personal information for as long as reasonably necessary for the purposes described in this Policy, to provide our services, to manage legal risk, and to comply with legal, professional conduct, trust accounting, conveyancing, migration, AML/CTF and other record-keeping obligations. When personal information is no longer required, we take reasonable steps to securely destroy or de-identify it, subject to our legal and professional obligations.

13. Access and correction

You may request access to the personal information we hold about you, or ask us to correct it if it is inaccurate, incomplete or out of date.

To make a request, please contact us using the details in section 17. We may need to verify your identity before responding. We will respond within a reasonable time and in accordance with applicable law.

In some circumstances, we may be legally permitted or required to refuse access or correction, including where access would breach legal professional privilege, confidentiality obligations, court orders, legal restrictions, the privacy of another person, or the integrity of an investigation or compliance process. If we refuse a request, we will explain our reasons where it is lawful and reasonable to do so.

14. Website, cookies and analytics

When you use our website, we may collect technical information such as IP address, browser type, device information, pages visited, time spent on pages, referring website and general usage statistics. We may use cookies and analytics tools to operate, protect and improve our website and client experience.

You can usually disable cookies through your browser settings, although this may affect how some website functions operate.

15. Direct marketing

From time to time, we may use your contact details to send you legal updates, newsletters or information about our services that may be of interest to you, where you have opted in or where permitted by law.

You can opt out of marketing communications at any time by using the unsubscribe function in our messages, or by contacting us using the details in section 17.

16. Privacy complaints

If you have a concern or complaint about how we have handled your personal information, please contact us first using the details in section 17.

We will acknowledge your complaint within a reasonable time, investigate it and provide a response. We may ask you for further information to help us assess and resolve the complaint.

If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au.

17. Contact details

If you have any questions about this Privacy Policy, want to access or correct your personal information, withdraw consent, opt out of marketing, or make a privacy complaint, please contact us:

  • Business name: Skylar Legal
  • Privacy contact: Principal Solicitor / Privacy Officer
  • Email: info@skylarlegal.com
  • Phone: +61 478 205 805
  • Website: https://skylarlegal.com
  • Address: Level 3, 410 Concord Road, Rhodes NSW 2138

18. Translated versions

Where we provide a translated version of this Policy, the translation is provided for convenience only. The English version is the official version of this Policy. If there is any inconsistency between the English version and any translated version, the English version prevails to the extent of the inconsistency.

19. Updates to this Policy

We may update this Privacy Policy from time to time to reflect changes in our business, systems, service providers, legal obligations or regulatory requirements.

The latest version will be published on our website with the revised “Last updated” date. Where changes are significant, we will take reasonable steps to notify affected individuals where required or appropriate.