Privacy Policy
Last updated: 4 September 2026
1. About this policy
Kohinoor Legal (“we”, “us”, “our”) operates the website www.kohinoorlegal.com and a secure client portal accessible from it. Kohinoor Legal handles personal information in accordance with this Privacy Policy and, where applicable, the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
This policy applies to visitors to our public website, people who contact us to make an enquiry, and our clients, including those who use our client portal.
2. What personal information we collect
The personal information we collect depends on how you interact with us.
If you simply browse our website: we do not currently use a public enquiry form or any analytics or advertising tracking technology. Our hosting and security providers may nonetheless process limited technical information associated with your request to view the website — such as your IP address, browser/device information, and request timestamps — as an ordinary and necessary part of delivering and securing a website. We do not use this information to identify or profile individual visitors.
If you contact us directly by phone or email: you provide us with whatever personal information you choose to share, which may include your name, contact details, and a description of your legal matter.
If you become a client, or your enquiry is recorded by our staff: depending on the nature of your matter, we may collect your name and contact details; identity information reasonably required to act for you; information relevant to your legal matter (which may include immigration or visa information, family or personal circumstances, information about a criminal or civil legal matter, or employment or business information); financial information reasonably required for invoicing; documents and evidence you provide to us; records of our communications with you; and, if you use our client portal, authentication and session information needed to secure your access.
Some information we hold in connection with a matter may include sensitive information (for example, a medical report exhibited in a family law or immigration matter). We only collect sensitive information where it is reasonably necessary for the legal matter we are handling for you, or with your consent, consistent with Australian Privacy Principle 3.
3. How we collect personal information
We collect personal information directly from you (by phone, email, or through the client portal), from records our staff create following direct contact with you, and, if you are a client, in the course of providing legal services. Technical information described in section 2 above is generated automatically by the ordinary operation of our website and hosting infrastructure.
We do not currently collect personal information through any public website form. If a public enquiry or consultation-request form is added to our website in future, we will provide a notice at that point of collection before it goes live — see section 12 (Collection Notice) below.
4. Why we collect, use, and hold personal information
We collect, hold, and use personal information to respond to your enquiry; assess whether we can act for you, including any conflict-of-interest check; provide legal services to you as our client; communicate with you about your matter, including through our secure client portal; arrange and manage appointments; prepare and issue invoices; meet our professional and legal obligations as a law practice; maintain security and an internal audit trail of actions taken on your matter; and operate and maintain our website and client portal.
We do not use personal information for direct marketing, and we do not use analytics or advertising technology that profiles website visitors.
5. Who we may disclose personal information to
Depending on your matter, we may disclose personal information to courts, tribunals, or government agencies where necessary to act for you or where required by law; barristers, other legal practitioners, or expert witnesses engaged in connection with your matter; other professionals or service providers reasonably necessary to your matter; our IT and cloud-hosting service providers, to the extent necessary to operate our website and client portal (see section 6); regulators or professional bodies where required by law or our professional obligations; and any other third party you specifically authorise.
We do not sell personal information, and we do not disclose it for another organisation’s marketing purposes.
6. Overseas handling of personal information
We use third-party service providers to operate our website and client portal. Our database and file storage are hosted with Supabase, in the Sydney, Australia region.
Some service providers operate internationally. Whether particular handling constitutes an overseas disclosure for the purposes of Australian Privacy Principle 8 depends on the relevant arrangements, including the degree of control we retain over the information and the provider’s contractual obligations. Where APP 8 applies, we take the steps required by applicable privacy law.
7. Cookies and website tracking
Our public website does not use cookies for anonymous visitors. The only cookies used are session/authentication cookies, set only when you sign in to the secure client portal or staff area, necessary to keep that session secure. We do not use Google Analytics, advertising cookies, or any tracking or profiling technology.
8. Data security
We take the security of personal information seriously. Measures include role-based access controls so staff can only see information relevant to their role; multi-factor authentication for staff accessing sensitive systems; private, access-controlled file storage for documents; encryption of data in transit; an internal audit trail of actions taken on client matters; and restricting client portal document uploads to authenticated, active client accounts only. No method of electronic storage or transmission is completely secure, and while we take reasonable steps to protect personal information, we cannot guarantee its absolute security.
9. How long we keep personal information
We retain personal information for as long as reasonably necessary for the purposes for which it was collected and to meet our legal, professional, regulatory, and record-keeping obligations. When information is no longer required to be retained, we take reasonable steps to securely destroy or de-identify it, subject to applicable law and professional obligations.
10. Access, correction, and complaints
You may ask to access or correct the personal information we hold about you. If you wish to make such a request, or have a concern about how we have handled your personal information, please contact us using the details below. We will respond within a reasonable time. If you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC).
11. Contacting us about privacy
Email: contact@kohinoorlegal.com
Phone: +61 430 446 799
12. Collection Notice
Where we collect personal information at a specific point — for example, if a public enquiry form is added to this website in future — we will provide a short notice at that point covering what is collected, why, and how to find this full policy, consistent with Australian Privacy Principle 5.
13. Changes to this policy
We may update this Privacy Policy from time to time. The version published on our website is the current version.