
Privacy Policy
Everyone dealing with our law firm are subject to the following conditions when utilising our services. Please contact our firm if you have any concerns.
1. Introduction
Mildura Law Pty Ltd trading as "Middleton Maisner Legal" ("we", "us", "our" or the "Firm") is committed to protecting the privacy and confidentiality of the personal information entrusted to us by our clients, prospective clients, employees, contractors and other individuals with whom we deal.
We are a legal practice and, in addition to applicable privacy legislation, we are subject to professional obligations concerning the confidentiality of information obtained in the course of providing legal services.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information and how individuals may exercise their rights in relation to that information.
Where applicable, this policy is intended to explain our practices consistently with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Where the Firm provides a service which is a designated service for the purposes of the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) (AML/CTF Act), including certain transactions involving the sale, purchase or transfer of real estate, businesses, body corporates or legal arrangements, the Firm may be required to collect, verify, use, retain and disclose additional personal information for the purposes of complying with the AML/CTF Act, the AML/CTF Rules and related regulatory requirements. This may include information relating to identity, beneficial ownership and control, the nature and purpose of a transaction, source of funds or wealth, and other information reasonably required for customer due diligence, ongoing monitoring, reporting and record-keeping.
The Firm will only collect and retain personal information for AML/CTF purposes to the extent reasonably necessary for compliance with those obligations and the Firm's other lawful functions. Information collected for AML/CTF purposes will be handled in accordance with applicable privacy laws, professional obligations and the Firm's obligations under the AML/CTF Act and Rules. In some circumstances, the Firm may be required or authorised to disclose information to AUSTRAC or another government or regulatory authority. In addition, the Firm may be prohibited by law from disclosing to a client or other person the existence or nature of certain reports, investigations or compliance activities.
This AML/CTF-specific collection and handling of personal information applies only to matters and services to which the relevant AML/CTF obligations apply and does not alter the Firm's general duties of confidentiality in respect of other legal matters. Any application of the Privacy Act is otherwise excluded to the extent permitted by law.
Our obligations of legal professional confidentiality may apply to information beyond the scope of the Privacy Act.
2. What is personal information?
"Personal information" has the meaning given to that expression by applicable privacy legislation and generally means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is recorded in a material form or not.
Depending on the nature of our dealings with you, we may collect information including:
-
your name, address, telephone number and email address;
-
date of birth and identification information;
-
information concerning your family, financial affairs, business affairs, employment or property;
-
information relevant to a legal matter or transaction;
-
information contained in correspondence, documents, forms and instructions;
-
information provided by other people or organisations in connection with your legal matter;
-
information concerning your interactions with our Firm;
-
billing, payment and trust account information;
-
recordings and transcripts of telephone calls;
-
notes of telephone calls, meetings, conferences and other communications;
-
information generated or assisted by technology, including artificial intelligence tools; and
-
any other information reasonably necessary for us to provide legal services or operate our business.
Some information may constitute sensitive information under the Privacy Act. Where applicable, we will handle such information in accordance with the requirements of the Privacy Act.
3. How we collect personal information
We may collect personal information directly from you or from other sources.
Information may be collected:
-
when you contact us by telephone, email, post or other electronic means;
-
when you attend our office;
-
when you become a client or prospective client;
-
when you provide instructions or documents to us;
-
during telephone conferences, meetings, conferences and consultations;
-
through our website or online services;
-
from courts, tribunals, government agencies, registries and other public bodies;
-
from other lawyers, barristers, experts, professional advisers and service providers;
-
from opposing parties and their representatives;
-
from other persons involved in a legal matter; and
-
from publicly available sources where reasonably necessary for the provision of legal services.
Where we collect personal information about an individual from another person, we will generally do so because the information is reasonably necessary for the provision of legal services, the administration of a legal matter, compliance with our legal obligations or the proper operation of the Firm.
4. Recording of telephone calls
All incoming and outgoing telephone calls made through the Firm's telephone system may be recorded.
Telephone recordings may include conversations between:
-
the Firm and clients;
-
prospective clients;
-
other lawyers and legal practitioners;
-
barristers and experts;
-
government agencies and other organisations;
-
witnesses and other persons involved in legal matters; and
-
suppliers and other service providers.
Telephone recordings are made for purposes including:
-
maintaining an accurate record of communications;
-
file management and administration;
-
confirming instructions;
-
quality assurance and staff training;
-
resolving disputes or misunderstandings concerning communications;
-
protecting the interests of the Firm and its clients;
-
complying with legal and professional obligations; and
-
assisting in the provision of legal services.
By communicating with the Firm by telephone, you acknowledge that the call may be recorded.
Where reasonably practicable, callers will be informed at or before the commencement of the call that the call is being recorded.
If you do not wish to have a telephone conversation recorded, you may request we do not record the conversation or an alternative method of communication. We will consider such a request having regard to the circumstances, the nature of the communication and our legal, professional and administrative requirements.
5. Meetings and use of artificial intelligence tools
We may use technological tools, including artificial intelligence ("AI") tools, to assist with administrative and legal support functions.
These tools may be used, where appropriate, to assist with:
-
preparing or organising notes of telephone calls and meetings;
-
transcribing communications;
-
identifying action items;
-
preparing summaries;
-
organising information; and
-
other administrative or legal support functions.
Confidentiality and privilege
We will only use an AI tool to process confidential client information where we are satisfied that the proposed use is consistent with our professional obligations of confidentiality and, where applicable, the maintenance of legal professional privilege.
We will take reasonable steps to ensure that:
-
confidential information is not disclosed to an AI provider for purposes inconsistent with the Firm's obligations;
-
appropriate contractual and technical protections are in place;
-
access to information is appropriately restricted;
-
the AI provider does not use Firm or client information for unrelated purposes where this would be inconsistent with our obligations;
-
appropriate security measures are applied; and
-
the use of the AI tool is appropriate having regard to the nature and sensitivity of the information.
The fact that information is processed using an AI tool does not, of itself, determine whether that information is subject to legal professional privilege. Privilege will be assessed according to the applicable law and the circumstances in which the communication or document was created.
Where we consider that use of an AI tool may create an unacceptable risk to confidentiality, privacy or legal professional privilege, we will not use the tool for that purpose.
6. Purposes for which we use personal information
We may collect, hold, use and disclose personal information for purposes including:
-
providing legal advice and legal services;
-
acting for clients in transactions, disputes, litigation and other legal matters;
-
communicating with clients and other persons involved in legal matters;
-
preparing legal documents and correspondence;
-
complying with legal and professional obligations;
-
establishing and maintaining client records;
-
billing and recovering legal fees;
-
maintaining trust account records;
-
verifying identity and conducting required due diligence;
-
complying with anti-money laundering and counter-terrorism financing obligations;
-
managing conflicts of interest;
-
managing our relationship with clients and other persons;
-
improving the security and operation of our systems;
-
managing our employees and contractors;
-
obtaining professional, technical and administrative services;
-
managing claims and complaints;
-
protecting the rights, property and safety of the Firm, our clients and others; and
-
other purposes reasonably necessary for the operation of a legal practice.
We will generally only use or disclose personal information for the purpose for which it was collected, a related or reasonably expected purpose, or where otherwise permitted or required by law.
7. Disclosure of personal information
Depending on the nature of the legal matter, we may disclose personal information to persons and organisations including:
-
barristers and other legal practitioners;
-
courts and tribunals;
-
government departments, agencies and statutory authorities;
-
land registries and other public registries;
-
experts, investigators, valuers, medical practitioners and other professional advisers;
-
accountants, financial advisers and other advisers;
-
process servers and other persons engaged to assist with legal matters;
-
opposing parties and their lawyers or representatives;
-
insurers and claims managers;
-
banks and financial institutions;
-
settlement agents and other transaction participants;
-
contractors and technology service providers;
-
document management, cloud storage, telecommunications and IT providers;
-
artificial intelligence and related technology providers where permitted under this policy;
-
our professional indemnity insurers and advisers;
-
auditors and other professional service providers; and
-
other persons where disclosure is reasonably necessary for the provision of legal services or is authorised or required by law.
We will not sell personal information to third parties.
8. Cloud storage and electronic information
The Firm stores and manages information electronically.
We use reputable cloud-based technology and storage services for purposes including document management, file storage, email, backup, communications and other business functions.
Our electronic information may be stored or processed using servers located in:
-
Australia;
-
New Zealand;
-
England and Wales / the United Kingdom; and
-
the United States of America.
We do not intentionally use cloud storage providers whose relevant data storage locations are outside those jurisdictions, subject to the possibility that a service provider may route information through other locations for technical or security purposes in accordance with its contractual arrangements.
Where personal information is disclosed to an overseas recipient, we will take reasonable steps required by applicable privacy laws to ensure that the information receives appropriate protection.
The Firm remains responsible for the management of personal information within its control and will take reasonable steps to select and manage service providers having regard to privacy, confidentiality and security requirements.
9. Security of information
We take reasonable steps to protect personal information from misuse, interference and loss and from unauthorised access, modification or disclosure.
Our security measures may include:
-
secure cloud-based information systems;
-
encryption and other technical security measures;
-
access controls;
-
user authentication;
-
multi-factor authentication for access to relevant Firm systems;
-
restricted access based on a person's role and requirements;
-
monitoring and management of user access;
-
backup and recovery systems;
-
physical security measures;
-
staff training and confidentiality obligations;
-
contractual confidentiality and security requirements imposed on service providers; and
-
procedures for responding to suspected or actual data breaches.
Access to Firm systems containing confidential or personal information is restricted to authorised persons who require access for legitimate Firm or client purposes.
No electronic storage system can be guaranteed to be completely secure. However, the Firm regularly reviews its information security arrangements having regard to the nature and sensitivity of the information it holds.
10. Retention and destruction of information
We retain personal information and legal files for as long as we consider reasonably necessary for the purposes for which the information is held, having regard to our legal, professional, regulatory, insurance and business requirements.
The Firm may retain electronic records indefinitely.
Where an original document has been converted into a reliable electronic record, the Firm may ordinarily destroy the original document where the Firm considers that retention of the original is no longer necessary.
However, original deeds will not be destroyed merely because an electronic copy has been made, unless the Firm has determined that destruction is legally permissible and appropriate having regard to the nature and legal effect of the deed and the circumstances of the particular matter.
Other original documents may also be retained where:
-
an original is legally required;
-
the original has evidentiary significance;
-
a court, registry or other authority requires the original;
-
the client has specifically requested that it be retained;
-
retention is required by professional or regulatory obligations; or
-
the Firm considers retention otherwise necessary or prudent.
Where personal information is no longer required and there is no legal, professional or other legitimate reason for retaining it, we will take reasonable steps to destroy or de-identify it in accordance with applicable law.
11. Access to personal information
You may request access to personal information that we hold about you.
Requests for access should be made in writing and addressed to reception.
We will deal with requests for access in accordance with applicable privacy legislation and our professional obligations.
In some circumstances, we may be unable to provide access to information, or may be required to limit or refuse access. This may include circumstances involving:
-
legal professional privilege;
-
our obligations of confidentiality;
-
legal proceedings;
-
the interests of another person;
-
solicitor's lien;
-
a legal requirement preventing disclosure; or
-
another exception recognised by applicable law.
Where we refuse or limit access, we will generally explain the basis for our decision to the extent that we are permitted to do so.
12. Correction of personal information
We take reasonable steps to ensure that personal information we collect, use and disclose is accurate, complete and up to date having regard to the purpose for which it is used.
If you believe that information we hold about you is inaccurate, incomplete or out of date, you may ask us to correct it.
We will consider and respond to correction requests in accordance with applicable privacy legislation.
13. Legal professional privilege and confidentiality
Our obligations concerning client confidentiality are separate from and may be broader than our obligations under privacy legislation.
Information provided to us in the course of a legal engagement may be confidential even if it does not constitute "personal information" for the purposes of the Privacy Act.
Similarly, legal professional privilege may apply to certain confidential communications and documents created for the purpose of obtaining or providing legal advice or for use in legal proceedings.
We will protect confidential client information in accordance with our professional obligations and applicable law.
Nothing in this Privacy Policy is intended to waive or limit any applicable claim of legal professional privilege or any duty of confidentiality owed by the Firm to a client.
14. Data breaches
We maintain procedures for identifying, containing, assessing and responding to actual or suspected data breaches.
Where a data breach occurs that is subject to the Notifiable Data Breaches scheme, we will comply with our obligations under applicable law, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
15. Overseas information handling
The Firm uses cloud-based systems and service providers located in Australia and overseas, personal information may be stored or accessible in Australia, New Zealand, the United Kingdom or the United States of America.
The privacy laws applying in those jurisdictions may differ from Australian privacy law.
Where applicable, we will take reasonable steps to ensure that overseas recipients handle personal information consistently with our obligations under the Australian Privacy Principles, including where required by Australian Privacy Principle 8.
16. Website and electronic communications
When you communicate with us electronically, information contained in those communications may be collected and stored as part of our records.
Our website may also collect limited technical information such as IP addresses, browser information and information concerning the use of our website.
We may use cookies or similar technologies where reasonably necessary for the operation, security and functionality of our website.
17. Complaints
If you believe that we have mishandled your personal information or otherwise breached applicable privacy obligations, you may make a complaint to our Privacy Officer.
Complaints should be made in writing and should provide sufficient information to allow us to investigate the matter.
We will acknowledge and investigate privacy complaints and seek to resolve them within a reasonable period.
If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).
18. Contact details
Our Privacy Officer can be contacted as follows:
Privacy Officer
Lior Maisner
Middleton Maisner Legal
61 Deakin Avenue
Mildura VIC 3500
Telephone: 03 5023 7900
Email: via our online webform found at mmlegal.co
19. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time to reflect changes in our practices, technology, legal obligations or professional requirements.
The current version of this Privacy Policy will be made available through the Firm's website or on request.
Effective date: 16 September 2026
Last updated: 16 September 2026