Privacy Policy
Last updated: January 1, 2025. This policy complies with the Australian Privacy Act 1988 (Cth) and the EU General Data Protection Regulation (GDPR).
1. Introduction
LEGAL777-ML-NIGHTWORX ACN 19651504737 ("we", "us", "our") is committed to protecting the privacy of individuals whose personal information we collect, hold, use, and disclose. This Privacy Policy explains how we handle personal information in accordance with the Australian Privacy Act 1988 (Cth), including the Australian Privacy Principles (APPs), and, where applicable, the EU General Data Protection Regulation (GDPR).
This policy applies to all personal information collected through our website (legal777.com), client engagements, marketing activities, and other interactions with us. By using our services or accessing our website, you consent to the collection, use, and disclosure of your personal information as described in this policy.
We also operate within the Dubai International Financial Centre (DIFC) and comply with the DIFC Data Protection Law No. 5 of 2020 where applicable to DIFC-based clients and activities.
2. Definitions
In this Privacy Policy, the following terms have the meanings set out below:
- "Personal Information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether true or not, and whether recorded in material form or not.
- "Sensitive Information" means personal information including racial or ethnic origin, political opinions, religious beliefs, health information, biometric information, and criminal records.
- "Data Subject" means the individual to whom personal information relates.
- "Processing" means any operation performed on personal information, including collection, storage, use, disclosure, and destruction.
- "Controller" means the entity that determines the purposes and means of processing personal information.
- "Processor" means the entity that processes personal information on behalf of the Controller.
3. Information We Collect
We may collect the following types of personal information:
- Identity Information: Full name, title, date of birth, nationality, and identification documents (passport, driver's licence).
- Contact Information: Email address, postal address, telephone numbers, and preferred contact method.
- Professional Information: Occupation, employer, professional qualifications, and job title.
- Financial Information: Bank account details, payment information, and financial history (where relevant to legal services).
- Technical Information: IP address, browser type, device information, operating system, and usage data collected through cookies and analytics.
- Service Information: Records of communications, legal advice provided, matter details, and engagement history.
- Sensitive Information: We only collect sensitive information where it is reasonably necessary for the provision of legal services and with your consent, or where otherwise permitted by law.
4. How We Collect Information
We collect personal information through the following means:
- Direct Collection: Information you provide directly through our website forms, email, telephone, in-person meetings, or document submissions.
- Automated Collection: Technical information collected automatically through cookies, web beacons, server logs, and analytics tools when you visit our website.
- Third Parties: Information from regulatory bodies, referees, counterparties, publicly available sources, and service providers (where you have consented or as permitted by law).
- Client Engagements: Information provided during the course of legal engagements, including documents, correspondence, and disclosures.
5. Purpose of Collection
We collect personal information for the following primary purposes:
- To provide legal services and advice, including tokenisation structuring, compliance advisory, and dispute resolution;
- To verify identity for client onboarding and regulatory compliance (AML/CTF obligations);
- To communicate with you regarding your matter, inquiries, or our services;
- To manage our client relationships and maintain records;
- To comply with legal and regulatory obligations, including reporting to ASIC, AUSTRAC, VARA, or DFSA;
- To improve our website, services, and client experience;
- To send marketing communications (where you have provided consent);
- To protect our legal rights and interests, including managing disputes and enforcing agreements;
- For internal administrative, accounting, and quality assurance purposes.
6. Use and Disclosure
We use and disclose personal information only for the purposes for which it was collected, or for related purposes that you would reasonably expect, or as permitted or required by law. Specifically, we may disclose personal information to:
-
li>Professional Advisors: Barristers, expert witnesses, auditors, and other professional advisors engaged in connection with your matter;
- Regulatory Authorities: ASIC, AUSTRAC, VARA, DFSA, and other regulatory bodies as required by law;
- Service Providers: IT service providers, cloud hosting providers, document management services, and other vendors who assist us in delivering our services (under confidentiality obligations);
- Counterparties: Where necessary in connection with transactions, negotiations, or dispute resolution;
- Courts and Tribunals: Where required in connection with legal proceedings;
- Related Entities: Our associated entities in Australia and Dubai for internal administrative purposes;
- Insurers: Our professional indemnity insurers in connection with claims or potential claims;
- With Your Consent: Any other party where you have expressly authorised disclosure.
We do not sell, rent, or trade personal information to third parties for marketing purposes.
7. International Transfers
As a dual-jurisdiction law firm, personal information may be transferred between Australia and Dubai in the course of providing legal services. We may also transfer data to service providers located in other countries.
When transferring personal information internationally:
- We ensure appropriate safeguards are in place, including contractual protections;
- For GDPR-covered data, we rely on adequacy decisions, standard contractual clauses, or other approved transfer mechanisms;
- For Australian data, we take reasonable steps to ensure overseas recipients do not breach the APPs;
- DIFC data transfers comply with DIFC Data Protection Law requirements.
By engaging our services, you consent to the transfer of your personal information between Australia, Dubai, and other jurisdictions as necessary for the provision of our services.
8. Data Security
We implement appropriate technical and organisational measures to protect personal information against unauthorised access, modification, disclosure, and destruction. These measures include:
-
li>Encryption of data in transit (TLS 1.3) and at rest (AES-256);
- Multi-factor authentication for all systems accessing client data;
- Regular security audits and penetration testing;
- Access controls based on role and need-to-know principles;
- Staff training on data protection and information security;
- Incident response procedures for data breach notification;
- Physical security measures at our offices in Sydney and Dubai.
Despite these measures, no method of transmission over the internet or electronic storage is completely secure. We cannot guarantee absolute security of personal information.
In the event of a data breach that is likely to result in serious harm, we will notify affected individuals and the relevant regulatory authorities (OAIC in Australia, DIFC Commissioner in Dubai, as applicable) in accordance with our legal obligations.
9. Data Retention
We retain personal information for as long as necessary to fulfil the purposes for which it was collected, including:
- The duration of the client engagement and any applicable limitation periods;
- Statutory retention requirements (e.g., AML/CTF records must be retained for 7 years after the cessation of the business relationship);
- Professional indemnity insurance requirements;
- Regulatory obligations applicable to our practice.
When personal information is no longer required, we take reasonable steps to destroy or de-identify it in a secure manner.
10. Your Rights
Depending on your location and applicable law, you may have the following rights regarding your personal information:
Under Australian Privacy Law
- Access: Request access to the personal information we hold about you;
- Correction: Request correction of inaccurate, out-of-date, or incomplete personal information;
- Complaint: Lodge a complaint with us or the Office of the Australian Information Commissioner (OAIC) if you believe we have mishandled your personal information.
Under GDPR (if applicable)
- Right to Access: Obtain confirmation of processing and a copy of your personal data;
- Right to Rectification: Have inaccurate personal data corrected;
- Right to Erasure: Request deletion of your personal data in certain circumstances;
- Right to Restrict Processing: Limit how we use your personal data;
- Right to Data Portability: Receive your data in a structured, machine-readable format;
- Right to Object: Object to processing based on legitimate interests or for direct marketing;
- Right to Withdraw Consent: Withdraw consent at any time (without affecting prior lawful processing);
- Right to Complain: Lodge a complaint with your local supervisory authority.
To exercise any of these rights, please contact our Privacy Officer using the details in Section 13. We will respond to requests within a reasonable timeframe and in accordance with applicable law.
11. Cookies and Tracking
Our website uses cookies and similar tracking technologies to enhance user experience, analyse website traffic, and improve our services. For detailed information about the cookies we use, your choices, and how to manage cookie preferences, please refer to our Cookie Policy.
By continuing to use our website, you consent to our use of cookies as described in the Cookie Policy. You may withdraw or modify your consent at any time through the cookie preference centre.
12. Complaints
If you believe we have breached this Privacy Policy or applicable privacy law, you may make a complaint by:
- Emailing our Privacy Officer at [email protected];
- Writing to us at Level 42, 100 Martin Place, Sydney NSW 2000, Australia; or
- Contacting us by telephone on +61 2 9001 2345.
We will acknowledge receipt of your complaint within 5 business days and aim to resolve complaints within 30 days. If you are not satisfied with our response, you may escalate your complaint to:
- Australia: Office of the Australian Information Commissioner (OAIC) — www.oaic.gov.au
- DIFC: DIFC Data Protection Commissioner — www.difc.ae
- EU: Your local supervisory authority under GDPR.
13. Contact and Changes
If you have any questions, concerns, or requests regarding this Privacy Policy or our handling of personal information, please contact:
Privacy Officer
LEGAL777-ML-NIGHTWORX
Email: [email protected]
Phone: +61 2 9001 2345
Address: Level 42, 100 Martin Place, Sydney NSW 2000, Australia
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or regulatory guidance. Material changes will be notified via our website or direct communication where practicable. The updated policy will indicate the effective date of the changes.
We encourage you to review this policy periodically to stay informed about how we protect your personal information.