You are here:

Privacy Policy

Your rights in relation to privacy

  1. Croftbridge understands the importance of protecting the privacy of an individual’s personal information. This statement sets out how Croftbridge aims to protect the privacy of your personal information, your rights in relation to your personal information managed by Croftbridge, and how Croftbridge collects, holds, uses, and discloses your personal information.
  2. Croftbridge is bound by the Australian Privacy Principles set out in the Privacy Act 1988 (Privacy Act), which means we are obligated to have and share with you our policies and procedures we have in place to protect the personal information we collect about you. 

What kinds of personal information is collected?

  1. Croftbridge collects the following types of personal information:
    • Contact and professional information, including your name, date of birth, residential or business address, email address, phone number, and occupation;
    • Information relevant to the legal services we provide, which may include (with your consent or where required or authorised by Australian law) details about your assets, finances, property interests, income, directorships, employment, health, family relationships, and tax file number.
    • Where required to comply with our obligations under the AML/CTF Act, customer due diligence information such as your date of birth, residential address, identification document details (e.g. passport or driver’s licence), and information needed to assess AML/CTF risk. This may also include details of beneficial owners, politically exposed persons, and sources of wealth or funds; and
    • Where reasonably necessary to meet AML/CTF obligations, sensitive information, such as biometric information or political association membership. We will only collect sensitive information with your consent or where required or authorised by Australian law.

How do Croftbridge collect your personal information?

  1. Croftbridge will generally collect your personal information by:
    • Directly from you through discussions with the solicitor handling your matter, including in person, by phone, video conference, email, or post;
    • Through RealAML, our third-party identity verification provider, which assists us in meeting AML/CTF obligations;
    • From other sources where appropriate, including public records, company and trust registers, financial institutions, professional advisers, and government agencies or service providers such as Landgate, ASIC, the Supreme Court of Western Australia, and InfoTrack; and
    • Where personal information about you is provided by another person, we will inform you and provide relevant privacy information unless doing so would unreasonably impact that person’s privacy.

Why do Croftbridge collect your personal information?

  1. Croftbridge collects, holds, uses and discloses your personal information where it is reasonably necessary for the purposes of;
    • providing you or an entity with which you are connected, or otherwise in connection, with legal advice and associated services;
    • accounting, billing and other internal administrative purposes;
    • developing and facilitating a business relationship with you or an entity with which you are connected;
    • inviting you to events, functions or training events and providing you with updates and publications;
  2. Croftbridge collects your personal information to comply with the ‘Customer Due Diligence’ requirements in the Anti-Money Laundering and Counter-Terrorism Financing Act 2006(AML/CTF Act). This includes:
    • establish and verify your identity before providing certain services to you or the person you are acting on behalf of
    • assess and manage potential money laundering, terrorism financing, proliferation financing risks or related compliance risks associated with the provision of our services
    • make reports required by law under the AML/CTF Act
    • meet record keeping obligations under the AML/CTF Act.
  3. Croftbridge takes reasonable steps to ensure that any personal information we collect, use or disclose is relevant and limited to what is necessary for providing our services, conducting our business, and complying with AML/CTF obligations.
  4. You are under no obligation to provide your personal information; however, without certain information, Croftbridge may not be able to establish your identity and provide its services to you.

To whom do Croftbridge disclose your personal information?

  1. Croftbridge generally only discloses your personal information to provide legal services, meet our AML/CTF obligations, or for related administrative and business purposes. This may include sharing information with our affiliated entities and trusted service providers on a confidential basis. We may also disclose your personal information where you have given consent or where required or authorised by law. To comply with its AML/CTF obligations, Croftbridge may disclose your personal information to:
  2. To comply with its AML/CTF obligations, Croftbridge may disclose your personal information to:
    • AUSTRAC (the Australian Transaction Reports and Analysis Centre), as required by the AML/CTF Act, including in connection with suspicious matter reports and other reports required by law;
    • law enforcement and regulatory bodies, where required or authorised by law; and/or
    • third-party service providers who assist Croftbridge with its AML/CTF obligations, including identity verification services, screening and monitoring services, and data storage providers.
    • Where Croftbridge is required or authorised to use or disclose personal information under the AML/CTF Act or AML/CTF Rules, it is permitted to do so without your consent. Croftbridge will not disclose information where doing so would be inconsistent with its obligations under the AML/CTF Act.

Overseas disclosure

  1. Before disclosing any personal information to an overseas recipient, Croftbridge take steps reasonable in the circumstances to ensure the overseas recipient complies with the Australian Privacy Principles or is bound by a substantially similar privacy scheme unless you consent to the overseas disclosure or it is otherwise required or permitted by law. Where the disclosure is required or authorised by the AML/CTF Act or AML/CTF Rules. Croftbridge will not be responsible for the overseas recipient’s handling of that information.

Security of your personal information

  1. Croftbridge takes reasonable steps to protect personal information from misuse, loss, unauthorised access, modification, or disclosure. Personal information is stored securely in physical and electronic systems and is only accessible to authorised personnel. We use safeguards such as access controls, multi-factor authentication, monitoring, and staff training to help protect your information.
  2. Croftbridge will retain personal information only for as long as necessary to provide our services, meet legal obligations, and comply with AML/CTF requirements. Where information is no longer required, Croftbridge will securely destroy or de-identify it unless we are required by law to keep it. AML/CTF records are generally retained for seven years as required by law. We only keep identification information necessary to demonstrate compliance and do not retain full copies of identification documents unless required.
  3. Croftbridge maintains a data breach response plan. If a data breach involving your personal information is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner where required by law, subject to any applicable AML/CTF confidentiality or non-disclosure obligations.

Can you access and correct the personal information held about you?

  1. Croftbridge takes reasonable steps to ensure the personal information we hold is accurate, up to date, complete, and relevant. We may also update your information as part of our ongoing AML/CTF compliance obligations.
  2. You may request access to, or correction of, your personal information at any time by contacting us. We will respond in accordance with applicable privacy laws.
  3. To protect your privacy, we may require proof of identity and ask you to specify the information you wish to access. Croftbridge can provide you with a copy of your personal information in our current records free of charge.
  4. In some circumstances, Croftbridge may refuse access where permitted or required by law, including where access could prejudice investigations, enforcement activities, or our obligations under the AML/CTF Act.
  5. If Croftbridge refuse a request to access or correct your information, we will provide written reasons and information about available complaint mechanisms, unless we are prohibited from doing so by law.

Our Website

  1. Croftbridge uses ‘cookies’ to improve your experience and provide a more personalised and effective website.
  2. Cookies are small text files stored on your device by your web browser. You can manage or disable cookies through your browser settings.
  3. Cookies are used to:
    • recognise your browser and improve website functionality;
    • personalise your experience on our website;
    • collect website usage statistics;
    • identify referrals from third-party websites; and
    • support website security.

How to contact us?

  1. For further information or enquiries regarding your personal information, please contact our Practice Manager at:
    • Level 1, 8 St Georges Terrace Perth WA 6000
    • T: 08 6372 7790
    • E: admin@croftbridge.com.au

Privacy complaints

  1. Please direct all privacy complaints to Croftbridge’s Privacy Compliance Officer. At all times, privacy complaints:
    • will be treated seriously;
    • will be dealt with promptly;
    • will be dealt with in a confidential manner; and
    • will not affect your existing obligations or affect the commercial arrangements between you and Croftbridge.
  2. Croftbridge’s Privacy Compliance Officer will commence an investigation into your complaint. You will be informed of the outcome of your complaint following completion of the investigation.
  3. If you are dissatisfied with the outcome of your complaint, you may refer the complaint to the Office of the Australian Information Commissioner.

Changes to this Policy

  1. Croftbridge is constantly reviewing all of our policies and attempts to keep up to date with market expectations. Technology is constantly changing, as is the law and marketplace practices.
  2. As a consequence, we may change this privacy policy from time to time or as the need arises.
  3. This privacy policy is accurate as of 22 July 2027.