Greenhalgh Pickard Privacy Policy

Last updated: 30 September 2026

Greenhalgh Pickard is a business name of Legio Pty Ltd (ABN 59 131 094 016).

At Greenhalgh Pickard, we take the privacy, confidentiality and security of personal information seriously. As a provider of legal, accounting, conveyancing and related professional services, we may handle personal and sensitive information in the course of advising and acting for our clients.

This Privacy Policy explains how we collect, hold, use and disclose personal information and how you can access, correct or raise concerns about the personal information we hold about you.

We manage personal information in accordance with the Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and other laws that apply to our professional services.

1. What personal information we collect

The information we collect depends on your relationship with us and the services we provide.

It may include:

  • your name, date of birth and contact details;
  • residential, postal and previous addresses;
  • identification information, including driver’s licence, passport or other identity documents;
  • government-related identifiers where we are permitted or required to collect them;
  • financial, banking, taxation and superannuation information;
  • employment, business and company information;
  • information about assets, liabilities and transactions;
  • information contained in contracts, correspondence, court documents, financial records and other documents provided to us;
  • information about family members, beneficiaries, directors, shareholders, employees, counterparties or other people connected with your matter;
  • information relating to enquiries submitted through our website;
  • payment and billing information;
  • records of communications with us;
  • website usage, device and technical information; and
  • information relevant to prospective employment, contractors or suppliers.

Because of the nature of legal and professional services, we may also collect sensitive information where it is reasonably necessary for our work or otherwise permitted by law. This may include information about health, racial or ethnic origin, religious beliefs, political opinions, sexual orientation, criminal history or other sensitive circumstances.

We will only collect sensitive information where permitted under applicable privacy laws.

2. How we collect personal information

Where practicable, we collect personal information directly from you.

We may collect information when you:

  • contact us by telephone, email or in person;
  • submit an enquiry, request a quote or complete a form on our website;
  • become or seek to become a client;
  • provide documents or information in connection with a legal or accounting matter;
  • subscribe to communications from us;
  • attend an appointment, event or meeting;
  • interact with our website or online services; or
  • apply for employment or otherwise engage with us professionally.

Where appropriate and subject to applicable law, telephone calls, meetings and other communications may be recorded or transcribed for file management, quality, training, administrative or professional-service purposes.

Recordings and transcripts may be processed using technology, including artificial intelligence tools approved by Greenhalgh Pickard, in accordance with our confidentiality, privacy and information-security requirements.

Where required, we will provide appropriate notice of recording or transcription at or around the time the information is collected.

Depending on the matter, we may also receive personal information from third parties, including:

  • your representatives, family members or authorised contacts;
  • accountants, lawyers, financial advisers and other professional advisers;
  • government departments and regulators;
  • courts, tribunals and law enforcement bodies;
  • banks and financial institutions;
  • insurers;
  • employers and other organisations;
  • counterparties and their advisers;
  • property, company and other public registers;
  • identity verification providers;
  • referral partners; and
  • publicly available sources.

Where you provide us with personal information about another person, you should ensure that you are authorised to provide that information to us where required.

3. Identity verification and regulatory obligations

For certain services, we may be required by law to verify the identity of clients, beneficial owners, representatives or other relevant individuals.

This may include obligations under Australia’s anti-money laundering and counter-terrorism financing laws.

For these purposes, we may collect and verify identification information and other information required to undertake customer due diligence, assess risk, keep required records or make reports to regulatory authorities where required by law.

Information collected for these purposes may include identity documents, information about ownership and control, source of funds or wealth, transaction information and other information required by applicable legislation.

4. Why we collect and use personal information

We collect, hold, use and disclose personal information where reasonably necessary for our functions and activities, including to:

  • respond to enquiries and provide quotes;
  • determine whether we can act for you, including conducting conflict checks;
  • establish and manage our relationship with you;
  • provide legal, accounting, conveyancing and other professional services;
  • communicate with clients and other people involved in a matter;
  • conduct research and prepare documents, advice and correspondence;
  • verify identity and satisfy regulatory requirements;
  • administer client accounts, trust accounts, billing and payments;
  • manage our business and professional obligations;
  • maintain and improve our systems, services and website;
  • protect our systems from fraud, misuse and cybersecurity threats;
  • manage complaints and disputes;
  • recruit and manage employees and contractors;
  • comply with court orders, regulatory obligations and applicable laws; and
  • send updates, information or marketing communications where permitted.

We may also use information for another purpose where you have consented or where the use is otherwise authorised or required by law.

5. Disclosure of personal information

We do not sell personal information.

We may disclose personal information where reasonably necessary to provide our services or operate our business.

Recipients may include:

  • courts and tribunals;
  • government agencies and regulators;
  • barristers, experts and other professional advisers;
  • accountants, auditors and consultants;
  • financial institutions;
  • insurers;
  • property, conveyancing and settlement service providers;
  • identity verification and compliance service providers;
  • technology, cloud hosting and document management providers;
  • software and professional practice management providers;
  • telecommunications and email providers;
  • data security and IT service providers;
  • payment service providers;
  • third parties involved in your matter;
  • service providers assisting us with administration, marketing or website operation; and
  • other parties where you have authorised us to disclose the information.

We may also disclose personal information where required or authorised by law, including to comply with regulatory, taxation, law enforcement, court or AML/CTF obligations.

Our professional confidentiality and legal professional privilege obligations continue to apply where relevant.

6. Artificial intelligence and technology

We use technology, including approved artificial intelligence tools, to support some aspects of our legal, accounting and administrative work.

AI may assist with activities such as research, summarisation, document review, drafting, organisation and routine data processing.

We only permit client information to be processed using artificial intelligence tools that have been approved by Greenhalgh Pickard for that purpose and which are subject to our confidentiality, privacy and information-security requirements.

Where artificial intelligence assists in producing professional work or advice, its output is subject to appropriate human oversight and review before it is relied upon or provided to a client.

More information about how we use AI is available on our How We Use AI page at www.greenhalghpickard.com.au/how-we-use-ai/.

We do not currently use personal information in automated decision-making systems, or systems substantially and directly involved in making decisions, where those decisions could reasonably be expected to significantly affect an individual’s rights or interests.

If this changes, we will update this Privacy Policy to provide the information required by applicable privacy laws.

7. Overseas disclosure and processing

We use service providers and technology platforms, including Microsoft and Actionstep, that may store, process or provide access to personal information from locations outside Australia. Where practicable, our core systems store information in Australia, but information may be accessed from or processed overseas for hosting, support, maintenance and security purposes.

Based on our current technology and service-provider arrangements, personal information may be disclosed to, stored in, processed in or accessible from the United States of America and New Zealand, and other countries where our providers operate support or security services.

We take reasonable steps, as required by Australian privacy law, to ensure that personal information disclosed overseas is appropriately protected. We also consider privacy, confidentiality and information-security arrangements when assessing service providers and technology used for client work.

The countries in which our service providers operate or process information may change from time to time. We will update this Privacy Policy where required to reflect material changes to our overseas disclosure arrangements.

8. Storage and security

We take reasonable technical, organisational and physical measures to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.

These measures may include access controls, authentication, secure document and practice management systems, security monitoring, staff training, backups and other cybersecurity measures.

Client files and information may be stored electronically using professional document management, practice management, cloud and other approved technology platforms.

Where information is held in physical form, we use appropriate physical security measures, including secure premises and storage facilities.

No electronic system or transmission over the internet can be guaranteed to be completely secure. If you send sensitive information electronically, you should take appropriate care.

9. Retention and destruction

We retain personal information for as long as reasonably required to:

  • provide our services;
  • maintain appropriate professional records;
  • satisfy legal, regulatory, taxation, accounting and insurance requirements;
  • resolve disputes; and
  • protect our legitimate legal interests.

Different retention periods may apply depending on the type of information and the professional service involved.

When personal information is no longer required to be retained, we take reasonable steps to securely destroy it or permanently de-identify it, subject to our legal and professional record-keeping obligations.

10. Website, analytics and cookies

When you visit our website, we may automatically collect information such as your IP address, browser and device information, pages visited, referral source, approximate location, date and time of access, and interactions with our website.

We use cookies and similar technologies to operate and secure our website, understand how visitors use it, improve website performance, measure the effectiveness of our advertising and marketing, and provide relevant content.

We use third-party analytics, advertising and technology services which may include Google Analytics, Google Ads, Microsoft Clarity, Meta technologies, MailerLite and Elfsight. These services may collect information about your interactions with our website in accordance with their respective privacy practices.

You can manage non-essential cookies and tracking technologies through the consent controls available on our website.

More detailed information about the cookies and tracking technologies used on our website is available in our Cookie Policy at www.greenhalghpickard.com.au/cookie-policy-au/.

11. Direct marketing

We may use your contact information to send information about our services, legal or accounting updates, events or other material that we reasonably believe may be relevant to you where permitted by law.

You can opt out at any time by:

  • using the unsubscribe function in an electronic communication; or
  • contacting us using the details below.

We will not use sensitive information for direct marketing without consent where consent is required by law.

Opting out of marketing will not prevent us from contacting you about an existing matter, engagement or other non-marketing communication.

12. Accessing your personal information

You may request access to personal information we hold about you.

To make a request, contact us using the details below. We may need to verify your identity before providing access.

In some circumstances, we may be permitted or required by law to refuse access to some information. If this occurs, we will generally explain the reason for the refusal where permitted.

We may charge a reasonable fee for the administrative cost of providing access where permitted by law, but we will not charge you simply for making a request.

13. Correcting your personal information

We take reasonable steps to ensure personal information we use or disclose is accurate, complete, up to date and relevant.

If you believe information we hold about you is inaccurate, incomplete or out of date, please contact us and request that it be corrected.

We will take reasonable steps to correct the information where appropriate.

14. Data breaches

We maintain processes for responding to suspected or actual data breaches.

Where a data breach is likely to result in serious harm and the requirements of the Privacy Act apply, we will comply with our obligations under the Notifiable Data Breaches scheme, including notifying affected individuals and the Office of the Australian Information Commissioner where required.

15. Privacy complaints

If you believe we have not handled your personal information appropriately, please contact us.

Please provide enough information for us to understand your concern and investigate it.

We will acknowledge your complaint, investigate it and aim to give you a response within 30 days.

We encourage you to raise the matter with us first so that we have an opportunity to address your concerns.

If you are not satisfied with our response, you may be able to make a complaint to the:

Office of the Australian Information Commissioner (OAIC)

www.oaic.gov.au

Other complaint or regulatory avenues may also be available depending on the nature of the matter.

16. Contact us

For privacy enquiries, access or correction requests, complaints, or to report a suspected data breach, contact:

Privacy Officer

Greenhalgh Pickard

Legio Pty Ltd

ABN 59 131 094 016

Email: info@gpla.com.au

Phone: (07) 5444 1022

Postal address: PO Box 52, Buddina QLD 4575

17. Changes to this Privacy Policy

We may update this Privacy Policy from time to time to reflect changes to our business, technology, professional practices or legal obligations.

The current version will be published on our website and will show the date on which it was last updated.

Contact Your Nearest Office

If you are interested in meeting with an accountant or lawyer regarding your business or commercial interests, please fill out the form to book an appointment or call (07) 5444 1022