Privacy Policy
Inhera Legal respects the privacy of our clients, prospective clients and others whose personal information we handle.
This Privacy Policy explains how Inhera Legal collects, holds, uses and discloses personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), where they apply to us.
As a legal practice, we also have professional obligations concerning confidentiality and the handling of client information. Nothing in this Privacy Policy limits those obligations.
Personal information we collect
The personal information we collect depends on the nature of our relationship with you and the services we are providing.
It may include:
your name, date of birth and contact details
identification and verification information
information about your family and personal relationships
financial, property, superannuation, trust, company and business information
information about Wills, estates, beneficiaries and succession arrangements
information about your legal affairs or the legal affairs of another person
correspondence, instructions, file notes and documents provided to us
billing and payment information
information provided through our website, enquiry forms or booking systems
information about professional advisers, executors, beneficiaries, attorneys, guardians, trustees and other people relevant to a matter.
In some matters, we may also collect sensitive information, including health or capacity information, racial or ethnic origin, religious beliefs or other sensitive information where it is relevant to the legal services we provide. Sensitive information is subject to additional protections under the Privacy Act and will generally only be collected where reasonably necessary and with consent, or where otherwise permitted by law.
How we collect personal information
We usually collect personal information directly from you, including when you:
contact or engage Inhera Legal
attend a consultation
complete a form or questionnaire
provide instructions or documents
communicate with us by telephone, email, video conference or in person
use our website or booking systems.
We may also receive personal information from other people or organisations where relevant to a matter. This may include family members, executors, beneficiaries, professional advisers, financial institutions, superannuation funds, government bodies, courts and registries, or publicly available sources.
In legal matters, clients will sometimes provide us with personal information about other people. We only collect and use that information where it is reasonably necessary for our work or otherwise permitted by law.
Where practicable, you may make a general enquiry without identifying yourself. However, we will generally need to know your identity before providing legal advice or acting for you.
Why we collect and use personal information
We collect, hold and use personal information where reasonably necessary for our functions and activities, including to:
provide legal advice and services
assess whether and how we can assist with an enquiry
communicate with clients, prospective clients and other relevant people
prepare legal documents and progress legal matters
conduct conflict checks and establish client relationships
verify identity and undertake due diligence where required
communicate or work with other professional advisers and service providers
manage our files, accounts, billing and business operations
meet our professional, legal, regulatory and insurance obligations
respond to complaints, disputes or claims
improve our services and internal processes
provide legal education, updates or other communications where appropriate.
Where applicable, we may also collect and use information to comply with obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), including customer due diligence, record-keeping and reporting requirements. Certain professional services provided by legal practices became subject to the expanded AML/CTF regime from 1 July 2026.
Disclosure of personal information
We may disclose personal information where reasonably necessary for the purposes for which it was collected or where otherwise authorised or required by law.
Depending on the matter, this may include disclosure to:
barristers, accountants, financial advisers and other professional advisers
courts, tribunals, probate registries and government agencies
financial institutions, superannuation funds, trustees and other organisations relevant to a matter
experts, consultants and other people engaged to assist with legal work
technology, document management, communications, payment and other service providers
our professional indemnity insurer and professional or regulatory bodies where appropriate
law enforcement or regulatory authorities where required or authorised by law.
We do not sell personal information.
Technology and service providers
Inhera Legal uses technology and professional service providers to operate the practice and deliver legal services. These may include practice management, document storage, email, communications, accounting, electronic signing, website hosting, scheduling and other cloud-based systems.
We take reasonable steps to select and use service providers that provide appropriate security and privacy protections having regard to the nature of the information involved.
The use of a service provider does not alter our professional obligations concerning client confidentiality.
Overseas storage and disclosure
Some technology and service providers used by Inhera Legal may store or process information using infrastructure located outside Australia.
Where personal information is disclosed to an overseas recipient and APP 8 applies, we take reasonable steps as required by the Privacy Act to ensure that the information is handled consistently with the Australian Privacy Principles.
Security and retention
We take reasonable technical, organisational and administrative steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure.
These measures may include access controls, secure cloud-based systems, authentication controls, appropriate contractual arrangements with service providers and internal information-handling practices.
We retain personal information for as long as it is reasonably required for the purpose for which it was collected and to meet our legal, professional, regulatory, insurance and record-keeping obligations.
Where personal information is no longer required and there is no obligation or lawful basis to retain it, we take reasonable steps to destroy it or de-identify it.
Website, cookies and analytics
When you visit our website, certain technical information may be collected automatically, such as your IP address, browser type, device information, pages visited and the date and time of your visit.
Our website may use cookies and similar technologies to operate the website, understand how it is used and improve its functionality.
You can generally control cookies through your browser settings. Disabling some cookies may affect the way parts of the website operate.
Access and correction
You may request access to personal information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Requests can be made using the contact details below.
We will respond within a reasonable period. In some circumstances, the Privacy Act or other laws may permit or require us to refuse access to particular information. If this occurs, we will generally explain the reason for the refusal where we are permitted to do so.
Privacy complaints
If you have a question or concern about how Inhera Legal has handled your personal information, please contact us using the details below.
We will consider the matter and aim to respond within a reasonable period.
If you are not satisfied with our response and the Privacy Act applies to the matter, you may be able to make a complaint to the Office of the Australian Information Commissioner (OAIC).
Data breaches
Inhera Legal maintains processes for responding to suspected privacy and data security incidents.
Where the Notifiable Data Breaches scheme applies and a data breach is likely to result in serious harm, we will take the steps required under the Privacy Act, which may include notifying affected individuals and the Australian Information Commissioner.
Changes to this policy
We may update this Privacy Policy from time to time to reflect changes to our practices, technology or legal obligations.
The current version will be available on our website and will show the date on which it was last updated.
Contact us
For privacy enquiries, requests for access or correction, or privacy complaints, please contact:
Inhera Legal
Email: contact@inhera.com.au
Telephone: 02 7248 5814
Last updated: 30 September 2026