Russell Kelly & Associates · Norwest NSW
Privacy Policy
Russell Kelly & Associates
Effective date: 1 August 2026
Website: www.kellylaw.com.au
1. Introduction
Russell Kelly & Associates (“we”, “us” or “our”) respects the privacy of our clients, prospective clients and other individuals with whom we deal.
We are committed to protecting personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs) and other privacy, confidentiality and professional obligations applicable to Australian legal practitioners.
This Privacy Policy explains how we collect, hold, use, disclose and protect personal information, including information stored or processed using third-party technology and cloud services, and how individuals may access or correct their personal information or make a privacy complaint.
Our professional duties of confidentiality and obligations concerning legal professional privilege operate in addition to our obligations under privacy legislation.
2. What is personal information?
Personal information is information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether or not the information is true and whether or not it is recorded in a material form.
Depending upon the legal services we provide, some information we collect may also constitute sensitive information under the Privacy Act.
3. What personal information do we collect?
The personal information we collect depends upon the nature of our relationship with you and the legal services being provided.
It may include:
- names, residential and postal addresses, telephone numbers and email addresses;
- dates and places of birth;
- identification information, including driver’s licence, passport and other identity documents;
- electronic identity verification information;
- signatures and copies of identification documents;
- tax file numbers and other government-related identifiers where collection is authorised or required;
- financial information, bank account details and transaction information;
- employment, occupation and business information;
- company, trust, partnership and other entity information;
- property ownership and transaction information;
- information contained in contracts, leases, deeds, wills, powers of attorney and other legal documents;
- information concerning family members, beneficiaries, executors, attorneys, directors, shareholders, business associates and other relevant persons;
- correspondence and communications with us;
- information concerning legal proceedings, disputes, transactions or other legal matters;
- information obtained from courts, tribunals, government departments, regulators and publicly available registers;
- information supplied by other lawyers, accountants, financial institutions, real estate agents, conveyancers, experts and professional advisers;
- billing and payment information;
- information required for client identification, verification, conflict checking, fraud prevention, risk management, sanctions screening and anti-money laundering and counter-terrorism financing compliance; and
- other information reasonably necessary for us to provide legal services or conduct our business.
Depending upon the matter, we may collect sensitive information where it is reasonably necessary for the legal services being provided or where collection is otherwise permitted by law.
4. How we collect personal information
We generally collect personal information directly from you, including when you:
- contact or instruct us;
- meet with or telephone us;
- communicate with us by email or other electronic means;
- complete forms or provide documents;
- use our website;
- engage us to provide legal services; or
- otherwise deal with our firm.
We may also collect personal information from third parties where appropriate or authorised, including:
- authorised representatives;
- other lawyers and law firms;
- courts and tribunals;
- government departments and agencies;
- NSW Land Registry Services and other land registries;
- Australian Securities and Investments Commission;
- Australian Taxation Office;
- Revenue NSW and other revenue authorities;
- PEXA and other electronic conveyancing services;
- banks and financial institutions;
- accountants and financial advisers;
- real estate agents;
- valuers, experts and barristers;
- identity verification and search providers;
- publicly available databases and registers; and
- other persons involved in a transaction, dispute or legal proceeding.
We may receive unsolicited personal information. Where we do, we will deal with that information in accordance with our obligations under the Privacy Act.
5. Why we collect, hold, use and disclose personal information
We collect, hold, use and disclose personal information where reasonably necessary for our legal practice, including to:
- provide legal advice and legal services;
- establish, administer and manage client matters;
- communicate with clients and other parties;
- prepare and complete legal documents and transactions;
- represent clients in negotiations, proceedings and transactions;
- conduct searches and investigations;
- verify identity and authority;
- undertake conflict checks;
- comply with professional and legal obligations;
- comply with applicable anti-money laundering and counter-terrorism financing obligations;
- prevent and detect fraud and unlawful activity;
- manage trust money and financial transactions;
- undertake billing, accounting and debt recovery;
- maintain records;
- manage professional indemnity, risk and compliance requirements;
- operate, administer and secure our information technology systems;
- improve our services and business operations; and
- comply with applicable laws, court orders and regulatory requirements.
We generally use or disclose personal information for the purpose for which it was collected, for a related purpose that would reasonably be expected, or otherwise where authorised or required by law.
6. Computer systems and cloud service providers
We use third-party computer systems, software and cloud service providers in operating our legal practice. Our principal systems include Smokeball, Dropbox, MYOB, Adobe Acrobat Sign and Microsoft 365.
6.1 Smokeball
We use Smokeball as our legal practice management system.
Information stored or processed through Smokeball may include client details, matter information, correspondence, legal documents, file notes, appointments, tasks, billing information and other information relating to client matters.
Based on Smokeball Australia’s published information, its servers and Smokeball Group companies are located in Australia, the United States and the United Kingdom, and relevant third-party service providers and business partners operate in Australia, the United States, the United Kingdom and Japan.
Accordingly, personal information processed in connection with Smokeball may be processed in Australia, the United States, the United Kingdom and Japan.
This does not mean that every client document is permanently stored in each of those countries.
6.2 Dropbox
We use Dropbox Business Standard for electronic document storage, file synchronisation, backup, sharing and collaboration.
Documents stored using Dropbox may contain personal information, confidential client information, legally privileged information and, depending upon the matter, sensitive information.
Dropbox has confirmed directly to Russell Kelly & Associates that data associated with the firm’s KELLYLAW Dropbox account is presently stored in the United States of America.
Accordingly, personal information and client documents stored by the firm using Dropbox may be stored in the United States of America.
Dropbox has also confirmed that the firm’s Dropbox Business Standard subscription provides a 180-day file recovery and version history period. Deleted files and previous versions may therefore remain recoverable through Dropbox for up to 180 days in accordance with the service applicable to our account.
6.3 MYOB
We use MYOB for accounting and financial administration.
Information processed through MYOB may include names and contact details, invoices, accounting records, payment information, transaction records and other financial and administrative information.
MYOB’s published security information states that its Microsoft Azure and Amazon Web Services production platforms and cloud storage providers are hosted in Australia.
Accordingly, the MYOB cloud services used by the firm are principally hosted using infrastructure located in Australia, subject to the particular MYOB products and services used by the firm.
6.4 Adobe Acrobat Sign
We use Adobe Acrobat Sign (Adobe e-sign) to facilitate the electronic signing and execution of documents.
Personal information processed in connection with Adobe Acrobat Sign may include:
- names and email addresses;
- electronic signatures;
- signed and unsigned legal documents;
- information contained within documents submitted for electronic signature;
- signing dates and times;
- authentication and verification information;
- electronic transaction and audit trail information; and
- technical information associated with the electronic signing process.
Documents submitted for electronic signature may contain personal information, confidential client information, legally privileged information and, depending upon the nature of the matter, sensitive information.
Adobe states that Acrobat Sign is hosted using Amazon Web Services (AWS) and Microsoft Azure infrastructure in regional data centres. Adobe identifies Acrobat Sign hosting locations including Australia, the United States, Japan and India. The particular data centre applicable to a customer depends upon the service, settings and deployment configuration.
Accordingly, we do not represent that all information associated with our use of Adobe Acrobat Sign is stored exclusively in Australia.
Adobe’s data governance functionality provides for the retention and deletion of Acrobat Sign agreements and associated transaction data. Agreements may remain within Acrobat Sign while an account remains active unless they are deleted or an applicable retention rule is configured.
6.5 Microsoft 365
We use Microsoft 365, including Exchange Online, for business email and related communications. We may also use Microsoft 365 services including OneDrive, SharePoint and Microsoft Teams.
Personal information stored or processed through Microsoft 365 may include:
- names and email addresses;
- email correspondence and attachments;
- calendar and contact information;
- client and matter information;
- documents and files;
- information exchanged through Microsoft 365 collaboration services;
- confidential and legally privileged information; and
- other personal or sensitive information relevant to legal matters.
The firm’s Microsoft 365 tenant records Australia as both the Current Geography and Committed Geography for Exchange Online.
The firm’s Microsoft 365 tenant also records Australia as the Current Geography and Committed Geography for Microsoft Teams, OneDrive and SharePoint.
Accordingly, these Microsoft 365 services used by the firm are presently provisioned to the Australian geography.
Exchange Online mailboxes reviewed by the firm are subject to Microsoft’s Default MRM Policy.
Under that policy, email may be archived, retained, deleted or recoverable according to applicable Exchange retention tags, mailbox settings and user selections. The policy includes a default rule under which eligible content may be moved to archive after two years, together with other retention and deletion options.
The retention period applicable to particular email may therefore vary according to the applicable retention settings and any legal, regulatory or professional record-retention requirements.
6.6 Other service providers
We may also use other technology providers for website hosting, cybersecurity, backup, document production, electronic conveyancing, identity verification, communications and other professional and administrative functions.
7. Overseas disclosure, storage and processing
Some personal information handled by Russell Kelly & Associates may be disclosed to, stored by, accessible to or processed by technology providers, their related companies or service providers outside Australia.
Based upon the technology services presently used by the firm and information presently available to us, countries in which personal information may be stored, disclosed or processed include the United States of America, United Kingdom, Japan and India.
- Smokeball: personal information may be processed in Australia, the United States, the United Kingdom and Japan.
- Dropbox: data associated with the firm’s KELLYLAW Dropbox account is presently stored in the United States of America.
- MYOB: relevant production platforms and cloud storage infrastructure are hosted in Australia.
- Microsoft 365: the firm’s Exchange Online, Microsoft Teams, OneDrive and SharePoint services are presently provisioned to the Australian geography.
- Adobe Acrobat Sign: Adobe provides Acrobat Sign hosting in a number of regions, including Australia, the United States, Japan and India, with the applicable location depending upon the relevant service and deployment configuration.
The location and identity of cloud infrastructure providers, related entities and subprocessors may change from time to time. We periodically review these arrangements and may update this Privacy Policy where appropriate.
Where personal information is disclosed to an overseas recipient, we take reasonable steps as required by the Privacy Act and Australian Privacy Principles in relation to that disclosure.
We also consider our professional obligations concerning client confidentiality and legal professional privilege when selecting and using technology providers.
8. Automated decision-making
From 10 December 2026, Australian privacy law requires additional transparency in privacy policies concerning certain uses of personal information by computer programs to make decisions, or do things substantially and directly related to making decisions, that could reasonably be expected to significantly affect an individual’s rights or interests.
We have included the following information in this Privacy Policy in advance of those requirements taking effect.
Russell Kelly & Associates uses computer programs and technology to assist with the administration and delivery of legal services. These systems may assist with functions including:
- document and file management;
- accounting;
- conflict checking;
- client and matter administration;
- identity verification;
- compliance and risk management;
- document preparation;
- electronic signatures; and
- workflow management.
We do not presently arrange for computer programs to make decisions solely by automated means that could reasonably be expected to significantly affect an individual’s rights or interests.
We also do not presently arrange for computer programs using personal information to perform something substantially and directly related to making such a significant decision without appropriate professional or human involvement.
Legal advice, professional judgment and substantive decisions concerning the conduct of a client’s legal matter remain subject to human professional judgment and oversight.
If our practices change and personal information is used by computer programs in circumstances to which the automated decision-making provisions of the Privacy Act apply, we will update this Privacy Policy to provide the information required by law.
9. Use of artificial intelligence
(a) Our use of artificial intelligence
We may use artificial intelligence, machine learning and automation in conducting our practice and providing legal services. This may include assisting with onboarding, administration, billing, compliance, document review, legal research, preliminary drafting and summarising information.
Some artificial intelligence services operate through cloud-based or other third-party systems. Where we use them in connection with client work, we take reasonable steps to manage relevant privacy, confidentiality, information-security and legal professional privilege risks.
Artificial intelligence may produce incomplete, inaccurate or unreliable material. We maintain and periodically review safeguards appropriate to those risks. Artificial intelligence does not replace professional legal judgment, and any output that may substantively affect your matter will be reviewed by an appropriately qualified person before it is provided or relied upon.
(b) Your use of artificial intelligence
Unless we first agree otherwise in writing, you must not upload, enter, reproduce or disclose through a publicly accessible artificial intelligence service any correspondence, advice, document or other information relating to your matter, including confidential, sensitive or legally privileged material.
Using such a service may disclose confidential information, result in legal professional privilege being lost, compromise information through a security incident, produce inaccurate or misleading material, or infringe intellectual property rights. You remain responsible for your use of artificial intelligence and for assessing the accuracy and suitability of any output you obtain.
To the extent permitted by law, we are not responsible for loss arising from your use of an artificial intelligence service contrary to this section, except to the extent caused or contributed to by our negligence, breach of an applicable engagement agreement or other conduct for which liability cannot lawfully be excluded.
You indemnify us against any claim, liability, loss or reasonable expense arising from your unauthorised use or disclosure of information through an artificial intelligence service, except to the extent caused or contributed to by our negligence, breach of an applicable engagement agreement or other conduct for which liability cannot lawfully be limited.
10. Disclosure of personal information
In providing legal services and conducting our business, we may disclose personal information where appropriate to:
- courts and tribunals;
- government departments, regulators and statutory authorities;
- other solicitors and law firms;
- barristers;
- experts and consultants;
- accountants, financial advisers and other professional advisers;
- banks and financial institutions;
- insurers and professional indemnity providers;
- property and land registries;
- Revenue NSW and other revenue authorities;
- PEXA and electronic conveyancing participants;
- real estate agents and property professionals;
- process servers, search agents and investigators;
- identity verification and compliance service providers;
- information technology and cybersecurity providers;
- cloud computing, document storage and backup providers;
- accounting and practice management providers;
- persons authorised by you; and
- other persons where disclosure is reasonably necessary for the conduct of your matter or is authorised or required by law.
Where applicable, disclosures are also subject to our professional duties concerning client confidentiality and legal professional privilege.
AML/CTF collection notice
Where applicable to the legal services we provide, Russell Kelly & Associates may be required to collect personal information for the purposes of complying with the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth) and associated rules and regulatory requirements.
This may include collecting and verifying identification information, information concerning beneficial ownership and control, the nature and purpose of a client relationship or transaction, source of funds or wealth information where required, and other information reasonably necessary for customer due diligence and ongoing compliance.
We may obtain this information directly from you or, where permitted or required, from identity verification providers, public registers, government bodies and other appropriate sources.
Information collected for AML/CTF purposes may be used or disclosed where authorised or required by law, including to AUSTRAC and other competent government, regulatory or law-enforcement authorities.
If information reasonably required for identification, verification or other applicable AML/CTF obligations is not provided, we may be unable to commence or continue providing particular legal services or may be required to take other action in accordance with applicable law.
11. Government-related identifiers
We may collect government-related identifiers where reasonably necessary for our functions and permitted by law.
We do not use government-related identifiers as our own identifiers of individuals except where permitted by law.
12. Security of personal information
We take reasonable technical, physical and organisational steps to protect personal information against misuse, interference, loss and unauthorised access, modification or disclosure.
Measures may include, as appropriate:
- access controls and authentication;
- passwords and multi-factor authentication;
- restricted access according to staff roles;
- cybersecurity protections;
- security and software updates;
- secure cloud and practice management systems;
- backup and recovery arrangements;
- staff confidentiality obligations and training;
- physical security measures;
- information-handling policies and procedures;
- oversight of relevant third-party service providers; and
- procedures for responding to suspected data breaches.
No electronic system can be guaranteed to be completely secure. We periodically consider the security measures appropriate to the nature and sensitivity of the information we hold and the risks associated with our operations.
13. Data breaches
We maintain procedures for identifying, assessing and responding to suspected data breaches.
Where a data breach is likely to result in serious harm and the Notifiable Data Breaches scheme applies, we will take the steps required by the Privacy Act, including notifying affected individuals and the Office of the Australian Information Commissioner where required.
We may also take steps to contain, investigate and remediate an incident and reduce the risk of further harm.
14. Retention, deletion and destruction of information
We retain client files and personal information only for so long as reasonably necessary or required or authorised by applicable legal, professional, insurance, taxation, accounting, anti-money laundering and counter-terrorism financing, audit and regulatory obligations, or for other lawful purposes connected with our legal practice.
Individuals may ask us to delete or erase personal information we hold about them. We will consider any such request in accordance with the Privacy Act and other applicable laws. A request for deletion or erasure does not override obligations or lawful reasons requiring or authorising us to retain information. We may therefore be unable to delete some or all information where it forms part of a client or matter record, or is reasonably required for professional, legal, taxation, accounting, AML/CTF, audit, regulatory, insurance, dispute, evidentiary or other lawful purposes.
Where information must or may lawfully be retained, we will continue to protect it and limit its use and disclosure to purposes permitted by law. We do not treat retention of a client file as authority to use personal information for unrelated purposes.
Different categories of records may be subject to different retention periods. We therefore do not apply a single retention period to all personal information.
When personal information is no longer required to be retained, we take reasonable steps to destroy it securely or permanently de-identify it, subject to applicable legal and professional record-retention requirements.
Information stored through third-party cloud services may also be subject to the provider’s backup, deletion, recovery and technical retention processes.
Dropbox: The firm’s Dropbox Business Standard subscription provides a 180-day file recovery and version history period. Deleted files and previous versions may therefore remain recoverable through Dropbox for up to 180 days.
Microsoft 365: Email and associated information may be subject to Exchange Online retention, deletion, recovery and archiving settings. Exchange Online mailboxes reviewed by the firm use Microsoft’s Default MRM Policy, which includes a default two-year move-to-archive rule for eligible content together with other retention and deletion options.
Adobe Acrobat Sign: Agreements and transaction information may remain stored while the relevant account remains active unless deleted or an applicable retention rule is configured. Where a retention rule is configured, information may be deleted in accordance with that rule.
Our own legal and professional obligations may require us to retain information notwithstanding the availability of deletion functionality within a particular technology service.
15. Website privacy, analytics and information assistance
When you use www.kellylaw.com.au, certain technical information may be collected automatically, including:
- IP address;
- browser and device information;
- pages visited;
- date and time of access;
- referring website information; and
- website usage information.
We use Burst Statistics to understand how visitors use our website, monitor website performance and improve its operation and content. Burst Statistics is configured to provide privacy-conscious analytics without relying on conventional visitor-tracking cookies.
Our website uses HelpJet, an artificial intelligence-assisted tool that answers general questions and helps visitors locate information about Russell Kelly & Associates and our services. Its responses are based on website content and other material approved by us, are provided for general information only, and do not constitute legal advice, create a solicitor-client relationship or amount to our acceptance of instructions.
Information entered into HelpJet may be processed and retained by HelpJet or its service providers to generate responses, maintain conversation history and operate or improve the service. You should not enter confidential, sensitive, legally privileged or matter-specific information into HelpJet. Please contact Russell Kelly & Associates directly if you require legal advice or wish to discuss your circumstances.
Our website and its third-party services may use cookies, local storage or similar technologies where required for their operation, security or functionality. You may control or disable cookies through your browser settings, although doing so may affect the operation of some website functions.
Information collected through website analytics and information services is retained only for as long as reasonably required for the relevant operational, security or analytical purpose, subject to our settings and the applicable service provider’s retention practices.
Our website may contain links to third-party websites. We are not responsible for the privacy practices of external websites and recommend reviewing their privacy policies separately.
16. Email and electronic communications
We use Microsoft 365 and Exchange Online for our business email communications.
Email and other electronic communications involve inherent security risks. We take reasonable precautions when communicating electronically but cannot guarantee the security of information transmitted over the internet.
Clients should contact us promptly if they have concerns about the authenticity of an email or communication purporting to come from Russell Kelly & Associates, particularly where it contains or requests bank account or payment information.
17. Anonymity and pseudonyms
Where lawful and practicable, you may deal with us anonymously or using a pseudonym.
However, because of the nature of legal services and our professional, identification and regulatory obligations, it will often be impracticable or unlawful for us to provide legal services without knowing and, where necessary, verifying a client’s identity.
18. Access to personal information
You may request access to personal information we hold about you.
We will respond to access requests in accordance with the Privacy Act. In some circumstances we may lawfully refuse access or provide only limited access. Where required, we will provide reasons for doing so.
Before providing access, we may require reasonable evidence of identity.
Access may also be affected by legal professional privilege, confidentiality obligations owed to other persons, court orders or other legal restrictions.
19. Correction of personal information
We take reasonable steps to ensure that personal information we hold is accurate, up-to-date, complete, relevant and not misleading having regard to the purpose for which it is held.
If you believe information we hold about you is inaccurate, incomplete, out-of-date, irrelevant or misleading, please contact us and request that it be corrected.
We will consider and respond to correction requests in accordance with applicable privacy legislation.
20. Privacy complaints
If you believe we have not handled your personal information appropriately or have breached the Australian Privacy Principles, you may make a complaint to us.
Please provide sufficient information to enable us to understand and investigate your concerns.
We will investigate the complaint and respond within a reasonable period.
If you are not satisfied with our response, you may be entitled to make a complaint to the Office of the Australian Information Commissioner (OAIC).
21. Changes to this Privacy Policy
We may amend this Privacy Policy from time to time to reflect changes in:
- privacy legislation;
- our legal and professional obligations;
- our business practices;
- the technology and service providers we use;
- data storage, processing and retention arrangements; and
- the way in which we collect, hold, use or disclose personal information.
The current version will be published on our website.
We periodically review this policy, including our use of computer programs, automation and artificial intelligence, to ensure that our disclosures remain accurate and up to date.
22. Contact us
Questions concerning this Privacy Policy, requests for access or correction, and privacy complaints should be directed to:
Privacy Officer
Russell Kelly & Associates
Email: info@kellylaw.com.au
Postal address: PO Box 7565, Norwest NSW 2153
Website: www.kellylaw.com.au
Effective date: 1 August 2026
