PLAINLY LEGAL

Website Privacy Policy

Version 1.0 | 21 August 2026

1. About this policy

Plainly Legal Pty Ltd (ABN 88 700 641 229) (Plainly Legal, we, us or our) respects your privacy and is committed to handling personal information responsibly, securely and transparently.

This policy explains how we collect, hold, use and disclose personal information when you visit our website, submit an online enquiry, book an appointment, communicate with us, or receive or seek legal services from us.

We intend to handle personal information consistently with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), where those laws apply. We also take account of applicable Victorian privacy legislation, including the Health Records Act 2001 (Vic), and our professional duties as Australian legal practitioners. The Privacy and Data Protection Act 2014 (Vic) principally regulates the Victorian public sector, but may apply where a private organisation handles personal information on behalf of a Victorian public sector body.

2. What is personal and sensitive information?

Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true or recorded in material form.

Sensitive information is a category of personal information that receives additional protection. In migration and citizenship matters it may include information about:

  • racial or ethnic origin;

  • religious beliefs or affiliations;

  • political opinions or associations;

  • membership of a professional or trade association or union;

  • sexual orientation or practices;

    criminal record;

  • health, disability or genetic information;

  • biometric information or biometric templates; and

  • other information treated as sensitive under applicable privacy laws.

Health information may also be regulated under the Health Records Act 2001 (Vic).

3. Information we may collect

The information we collect depends on how you interact with us and the nature of your matter. It may include:

  • identity and contact information, including name, date of birth, address, email address, telephone number and preferred language;

  • immigration and citizenship information, including nationality, passport and travel-document details, visa status, immigration history, citizenship status and government identifiers;

  • family and relationship information, including details about partners, children, parents, sponsors, nominators, employers and other relevant people;

  • employment, education, qualification, financial and business information;

  • sensitive information, including health, disability, racial or ethnic origin, religious beliefs, sexual orientation, criminal history and biometric information, where relevant;

  • copies of documents, correspondence, decisions, evidence, photographs and records supplied by you or obtained with authority;

  • information required to check conflicts, verify identity, assess whether we can assist, provide legal services, manage costs and comply with legal and professional obligations;

  • payment and billing information (payment-card data may be processed directly by a payment provider rather than stored by us);

  • communications with us, including enquiry forms, emails, telephone notes, appointment records and client feedback; and

  • website and technical information, including IP address, device and browser information, pages viewed, referral source, cookies and similar technologies.

4. Online enquiries and sensitive information

Our online enquiry form is intended to collect only enough information to understand the general nature and urgency of your enquiry, conduct preliminary conflict and suitability checks, and contact you about the next step.

PLEASE MINIMISE WHAT YOU SEND: Do not upload or send via email identity documents, passports, visa records, medical records, criminal-history documents or detailed evidence through the general enquiry form or via email unless we specifically request them and identify a secure method. If documents are needed, we will tell you how to provide them securely.

Because migration matters can involve sensitive information, your enquiry may reveal information about health, disability, racial or ethnic origin, religion, relationships, sexual orientation, criminal history or other protected matters. Where consent is required, we seek your express consent to collect the sensitive information you choose to provide for the purposes described in the collection notice and this policy.

We ask that you provide information about another person only where it is reasonably necessary and you are authorised to do so, or where another lawful basis permits it. If you provide information about another person, you should make them aware of this policy where reasonably practicable.

Submitting an enquiry does not create a solicitor-client relationship and does not mean we act for you. We must complete any required conflict, identity and suitability checks and confirm an engagement in writing. Do not assume that a legal or procedural deadline has been protected merely because you submitted an enquiry.

5. How we collect information

We generally collect personal information directly from you, including through our website, booking tools, telephone calls, video conferences, email, secure portals, forms and documents.

We may also collect information from other sources where authorised, reasonably expected or otherwise permitted by law, including:

  • family members, sponsors, nominators, employers and authorised representatives;

  • government departments, courts, tribunals and regulatory bodies;

  • medical practitioners, educational institutions, translators, experts and other professional advisers;

  • publicly available sources and professional databases; and

  • service providers acting on our behalf.

If we receive unsolicited personal information, we will assess whether we could lawfully have collected it. If not, and if lawful and reasonable to do so, we will destroy or de-identify it.

6. Why we collect, use and disclose information

We may collect, hold, use and disclose personal information to:

  • respond to enquiries and arrange appointments;

  • conduct conflict, identity, eligibility, risk and suitability checks;

  • assess, advise on and conduct migration, citizenship, review or related legal matters;

  • communicate with clients and relevant third parties;

  • prepare, lodge and manage applications, submissions, evidence and correspondence;

  • manage engagements, trust or office accounting, billing, debt recovery, insurance, audits and records;

  • comply with legal, regulatory, court, tribunal, professional, taxation and reporting obligations;

  • protect our clients, staff, systems and legal rights;

  • improve our website, services, security and business operations; and

  • send service updates or marketing communications where permitted, with an option to unsubscribe.

We will ordinarily use or disclose personal information for the purpose for which it was collected, for a related purpose you would reasonably expect, with consent, or as otherwise required or authorised by law. Sensitive information will generally be used or disclosed only for the primary purpose for which it was collected, with consent, or where another legal exception applies.

7. When we may disclose information

Depending on the matter, we may disclose personal information to:

  • the Department of Home Affairs and other Australian or overseas government, diplomatic or consular authorities;

  • courts, tribunals, review bodies, regulators and law-enforcement bodies where permitted or required;

  • barristers, other lawyers, migration professionals, experts, translators, interpreters, medical professionals and other advisers involved in the matter;

  • sponsors, nominators, employers, family members or other participants where authorised or necessary;

  • our professional indemnity insurer, auditors, accountants and professional advisers;

  • technology, hosting, website, scheduling, secure-portal, practice-management, document-management, email, payment, identity-verification, cybersecurity and backup providers; and

  • another party in connection with a proposed restructure, transfer or sale of the practice, subject to appropriate confidentiality and privacy protections.

We do not sell personal information.

8. Overseas recipients and cloud services

Migration work is inherently international. We may communicate with individuals, organisations and authorities outside Australia at your request or where reasonably necessary for your matter.

Some technology and cloud-service providers may store, process, support or back up information outside Australia. The countries in which overseas recipients may be located include but are not limited to the United States of America, Canada, Europe and Ireland.

Where applicable, we will take reasonable steps before disclosing personal information overseas to ensure the recipient handles it consistently with the APPs, unless an exception applies. The protections and remedies available overseas may differ from those in Australia.

9. Website, cookies and analytics

Our website may use cookies and similar technologies to operate, secure and improve the site, remember preferences, understand traffic and measure performance. Depending on our configuration, information may be processed by Squarespace and other providers.

You can adjust browser settings to block or delete cookies, although some website functions may not work properly.

Our website may contain links to third-party sites. We are not responsible for the privacy practices or content of those sites.

10. Direct marketing

We may send information about our services where you have consented or where otherwise permitted by law. You can opt out at any time by using the unsubscribe facility or contacting us. Transactional communications about an enquiry or matter are not marketing and may continue where necessary.

We do not use sensitive information for direct marketing without consent where consent is required.

11. Security and storage

We take reasonable technical and organisational steps appropriate to the nature of the information to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Measures may include access controls, multi-factor authentication, encryption where appropriate, secure portals, staff procedures, backups, vendor review and incident-response processes.

No internet transmission or storage system is completely secure. Email and general website forms may not be appropriate for highly sensitive documents. We will provide a more secure channel where appropriate.

We retain personal information for as long as reasonably necessary for the purposes described in this policy and to meet legal, professional, insurance and recordkeeping obligations. Retention periods vary according to the type of record and matter. When information is no longer required, we take reasonable steps to destroy or de-identify it, subject to lawful retention requirements and our professional obligations.

12. Data breaches

We maintain processes to identify, contain, assess and respond to suspected data breaches. Where the Notifiable Data Breaches scheme applies and an eligible data breach is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner as required. We will also comply with any other applicable breach-notification obligations.

13. Access and correction

You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. Victorian law may provide additional access rights in relation to health information.

To make a request, contact our Privacy Officer using the details below. We may need to verify your identity. We will respond within a reasonable period and may refuse access where permitted or required by law, including where legal professional privilege, another person’s privacy, legal proceedings or another exception applies. If we refuse a request, we will generally explain the reason and available complaint mechanisms where required.

We will not charge for making an access or correction request. We may charge reasonable costs of providing access where permitted, after giving notice.

14. Children and information about dependants

Migration matters often involve children and other dependants. We seek to collect only information reasonably necessary for the matter and to handle it with particular care. A parent, guardian or authorised representative may provide information on a child’s behalf. Depending on the child’s age, maturity and circumstances, we may also seek the child’s involvement or consent where appropriate or required.

15. Privacy questions and complaints

If you have a question or concern about our handling of personal information, please contact:

Privacy Officer
Plainly Legal Pty Ltd
Email: smarco@plainlylegal.com.au
Telephone: 0450 833 669
Postal address: on request

Please describe your concern and provide enough information for us to investigate. We will acknowledge and investigate complaints and aim to respond within 30 days, although complex matters may take longer. We will tell you if more time is needed.

If you are not satisfied with our response and the Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner at www.oaic.gov.au. For matters within Victorian jurisdiction, you may also have rights to contact the Health Complaints Commissioner or the Office of the Victorian Information Commissioner, depending on the information and organisation involved.

16. Changes to this policy

We may update this policy to reflect changes in law, technology or our practices. The current version will be published on our website with its effective date.

Effective date: 21 August 2026