Skip to main content
    Astris Law S IconAstris Law

    Privacy Policy

    Version 1.1 · Effective 27 July 2026 · Supersedes version 1.0

    This policy explains how we collect, hold, use and disclose personal information and the steps we take to comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles. It also explains how you can access and correct the personal information we hold about you, and how to make a privacy enquiry or complaint.

    1. Who this policy applies to

    In this policy, we, us and our means Astris Law Pty Ltd (ACN 662 641 269), including where we trade as Astrons General Counsel, Phronesis Litigation or HeadStart Counsel. Those are registered trading names, not separate legal entities.

    This policy applies to personal information we collect about our clients and their nominated contacts and representatives, including directors, officers, partners, trustees, beneficial owners and other persons connected with a client, and about other individuals whose personal information we collect or that our clients or their representatives give us in the course of our work.

    We may also give you a separate privacy notice when we collect your personal information, including when we collect it to meet our anti-money laundering obligations. Those notices may set out uses and disclosures not described here. If a separate notice is inconsistent with this policy, rely on the notice.

    This policy does not apply to personal information we hold about our own employees in connection with their employment. If you follow a link from our website to another website, this policy does not apply to that website.

    2. Information we collect

    We collect personal information that is reasonably necessary to provide legal services, respond to enquiries and comply with our professional and regulatory obligations. This typically includes your name, contact details, matter background and any information you provide to us.

    We collect additional information where we are required to. Part 6 sets out what we collect for anti-money laundering purposes.

    3. How we use your information

    We use personal information to open and manage client matters, provide legal advice, conduct conflicts and client identification checks, meet our regulatory obligations and communicate with you about your enquiry or engagement. We do not use it for marketing without your consent, and we do not sell personal information.

    4. Dealing with us anonymously

    Because of the nature of legal work, and because the AML/CTF Act requires us to identify and verify our customers, it is generally impracticable to deal with us anonymously or under a pseudonym once we are engaged. For a general enquiry you can contact us without identifying yourself, or use a pseudonym, where that is practicable and lawful.

    5. Disclosure to third parties

    We may disclose personal information to counsel, experts, courts, tribunals, regulators, mediators, our IT and practice management providers and other parties where reasonably necessary to perform legal services or to comply with the law.

    6. Anti-money laundering and counter-terrorism financing

    Astris Law Pty Ltd is a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth). When we provide a designated service under that Act we are required to collect and verify information about you, assess and monitor risk, keep records and, in some circumstances, report to AUSTRAC. This part explains what that means for your personal information.

    6.1 What we collect and why

    What Why we need it
    Name, date of birth and residential address Establishing your identity, as s 28 of the AML/CTF Act requires
    Identification document type, number and expiry and the outcome of verification Verifying your identity from reliable and independent sources
    Beneficial ownership and control information for companies and trusts Identifying beneficial owners and anyone on whose behalf a service is received
    Whether a person acts on behalf of a customer, and their authority Section 28(2) of the AML/CTF Act
    The nature and purpose of the engagement, and occupation or business activities Understanding and assessing money laundering and terrorism financing risk
    Source of funds and, where enhanced due diligence applies, source of wealth Sections 30 and 32 of the AML/CTF Act
    Politically exposed person, sanctions and adverse media screening results Sections 28 and 32 of the AML/CTF Act, and Rule 5-3 of the AML/CTF Rules 2025
    Transaction and matter information Ongoing customer due diligence and our reporting obligations

    We limit what we collect to what is reasonably necessary for these obligations. Some of this information, such as a screening result that discloses a criminal record or political affiliation, is sensitive information. We collect it only because the AML/CTF Act requires and authorises us to.

    6.2 Where we collect it from

    Usually directly from you, through our onboarding questionnaire and identity verification process. We also collect from reliable and independent sources, including government verification services, company and land registries, sanctions and politically exposed person databases and adverse media sources. Where another reporting entity has already carried out due diligence and we are permitted to rely on it, we may obtain the information from them.

    6.3 What we tell you when we collect

    Before we collect your personal information for AML/CTF purposes, or as soon as practicable afterwards, we tell you who we are, what we are collecting and why, that the collection is required or authorised by the AML/CTF Act and the AML/CTF Rules 2025, what happens if you do not provide it, who we usually disclose it to, whether it is likely to go overseas and how to access or correct it or make a complaint.

    One exception. We will not give you a collection notice, or otherwise make you aware of a matter, where doing so would be inconsistent with the tipping off prohibition in the AML/CTF Act. That prohibition prevents us disclosing anything that would or could reasonably be expected to prejudice an investigation.

    6.4 If you do not provide it

    We cannot provide a designated service before we have completed initial customer due diligence, except in the limited circumstances the AML/CTF Act allows. If you do not provide the information we need, we may be unable to act for you, or unable to continue acting.

    6.5 Who we disclose it to

    • AUSTRAC, where the AML/CTF Act requires or authorises us to, including in suspicious matter reports, threshold transaction reports and compliance reports.
    • InfoTrack, which conducts identity verification and screening on our behalf and holds the resulting records.
    • Smokeball, our practice management provider, where records are held on the matter file.
    • Another reporting entity, where we rely on their customer due diligence or they rely on ours, to the extent reasonably necessary and with your consent or another lawful basis.
    • Law enforcement, regulators and courts, where required or authorised by law.
    • Our professional advisers and any independent evaluator of our AML/CTF program, under confidentiality.

    We do not use or disclose personal information collected for AML/CTF purposes for any other purpose unless you consent or an exception under the Privacy Act applies.

    7. Identification documents

    The AML/CTF Act does not require us to keep scanned copies or photocopies of your identification documents. From 1 July 2026 we take reasonable steps to destroy or de-identify copies of full identification documents, such as a driver licence or passport, once they are no longer needed.

    Instead we keep the information taken from the document that we need for our record keeping obligations: your name, date of birth and residential address, the document type, its number and expiry, what we did to verify your identity and the outcome of that verification and our risk assessment.

    Copies of identification documents made before 31 March 2026 are records for the purposes of the AML/CTF Act and we are authorised to keep them for the full retention period. Where another law requires us to retain a copy, we do.

    8. How long we keep information

    We keep AML/CTF records for 7 years after the end of our business relationship with you, or 7 years after the completion of an occasional transaction. We keep other matter records in accordance with our professional obligations and the requirements of the Legal Profession Act 2007 (Qld).

    Once we no longer need personal information for a purpose we are permitted to hold it for, and no law requires us to keep it, we take reasonable steps to destroy it or de-identify it.

    9. Overseas disclosure

    We are an Australian practice and our records are held in Australia. Some of our service providers involve access from outside Australia, as follows.

    Provider Position
    InfoTrack InfoTrack stores and retains personal information in Australia. Data collected for InfoTrackID and verification of identity services is not transferred or stored outside Australia. Data collected for criminal history checks through ACIC and the National Police Checking Service is not transferred or stored outside Australia. InfoTrack's development personnel located in Vietnam may access personal information on a read-only basis under secure protocols and under the supervision of InfoTrack's Australian teams. This is stated in InfoTrack's privacy policy dated 12 March 2026.
    Smokeball Practice management. Smokeball's servers are located in the United Kingdom, the United States and Australia, and its third party service providers operate in the United Kingdom, the United States, Australia and Japan. Personal information held in our practice management system may therefore be processed outside Australia.
    Google Workspace Email and document storage. Google operates data centres in a number of countries and may process data outside Australia.
    Website analytics providers See Part 12.

    Where personal information is disclosed to or accessed from overseas we take reasonable steps to ensure the recipient does not breach the Australian Privacy Principles, except where the disclosure is required or authorised by the AML/CTF Act or the AML/CTF Rules 2025.

    10. Security and data breaches

    Personal information is held on secure systems and in our practice management records. We take reasonable steps to protect it from misuse, interference, loss and unauthorised access, modification or disclosure. AML/CTF records are held in access-controlled systems, are available only to those who need them, and are kept in a form capable of audit and free from unauthorised change.

    We maintain a data breach response plan. If an eligible data breach occurs we will comply with the Notifiable Data Breaches scheme, including notifying the Office of the Australian Information Commissioner and affected individuals, except to the extent that notification would be inconsistent with a secrecy provision.

    11. Access, correction and complaints

    You can ask for access to the personal information we hold about you, and ask us to correct it, by contacting us at mail@astrislaw.com. We will verify your identity before responding and we will respond within 30 days.

    We may refuse access where the Privacy Act allows, including where giving access would be unlawful. Giving access can be unlawful where it would amount to tipping off under the AML/CTF Act. Where we refuse we give written reasons and tell you how to complain, but our written notice will not explain the reason for the refusal where doing so would itself be inconsistent with our legal obligations.

    If you think we have mishandled your personal information, contact us at mail@astrislaw.com. We will acknowledge your complaint, investigate it and respond within 30 days. If you are not satisfied with our response you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. You should generally complain to us first.

    12. Website analytics and cookies

    When you visit this website, certain third-party services may set cookies or collect technical information such as your IP address, browser, device and the pages you view. We use this information to understand how the site is used and to improve it. These services include:

    • Google Analytics: website traffic and usage analytics. IP addresses are anonymised.
    • VisitorTracking: visitor and session analytics.
    • Google Fonts, Google Maps and YouTube: fonts, embedded maps and embedded videos are loaded from Google, which may receive your IP address and device information when those elements load.

    Each provider handles information in accordance with its own privacy policy and terms. You can control cookies through your browser settings.

    Consent. Google Analytics and VisitorTracking are enabled by default when you visit this website. A notice shown on your first visit lets you opt out of either service, and you can change your preferences at any time using the "Cookie Preferences" link in the footer of every page. If you opt out, the relevant service stops from your next page view.

    Email tracking. Emails we send may use Mailsuite (formerly Mailtrack) to confirm delivery and tell us whether an email has been opened and when. This helps us follow up appropriately. If you prefer not to be tracked, you can disable image loading in your email client or ask us to correspond by another method.

    13. Service providers

    Astris Law uses Google Workspace for email and document storage, Smokeball for practice management and InfoTrack for searches, signing, identity verification and AML/CTF compliance.

    14. Disclosure required by law

    We may disclose personal information where we are required or authorised to do so by law, by a court or tribunal order or by a regulator. That includes disclosures to AUSTRAC under the AML/CTF Act. Where the tipping off prohibition applies we will not tell you that a disclosure has been made or was required.

    15. Updates to this policy

    We update this policy as required to reflect changes to our practices or obligations. The current version is always available on our website.

    16. Contact

    Astris Law Pty Ltd ACN 662 641 269
    Privacy contact The Privacy Officer, who is also our AML/CTF Compliance Officer
    Address Level 2, 8 Clunies Ross Court, Eight Mile Plains QLD 4113
    Phone (07) 3519 5616
    Email mail@astrislaw.com

    This policy is available free of charge on our website and, on request, in another reasonable form.

    Talk to us

    You don't need more lawyers.
    You need the right one.

    A fixed-fee legal strategy call with the lawyer who would run your matter. Real advice in the session and a costed scope for anything further.

    Book a strategy call

    Cookies on by default ·Privacy