Legal
Privacy Policy
Contents
- 1.Overview and Application
- 2.Data Controller and Data Processor Roles
- 3.Personal Information We Collect: Platform Data
- 4.Personal Information We Collect: User Content
- 5.How We Collect Personal Information
- 6.AI Processing: Anthropic
- 6A.Email You Send Us, the Calendar Feed, and Register Searches
- 7.Data Storage Infrastructure
- 8.Stripe and Payment Data
- 9.How We Use Personal Information
- 10.Cookies and Tracking Technologies
- 11.Disclosure of Personal Information
- 12.Overseas Disclosure
- 13.Third-Party Data Processing
- 14.Marketing Communications
- 15.Data Retention
- 16.De-Identified and Aggregated Data
- 17.Security
- 18.Data Breaches
- 19.Your Rights
- 20.Privacy Complaints
- 21.Children
- 22.Third-Party Websites and Links
- 23.Relationship with lawreach.com.au
- 24.Changes to This Privacy Policy
- 25.Contact
1. Overview and Application
LawReach Pty Ltd (ABN 27 693 897 862) trading as LawReach AI ("LawReach AI", "we", "us", "our"), operates the AI-powered legal information platform at lawreach.ai ("Platform").
We are committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the Australian Privacy Principles (APPs) contained in Schedule 1 of the Privacy Act.
This Privacy Policy applies to all users of lawreach.ai, including visitors who do not create an account, free-tier (Aware) users, and paid subscribers (Assured and Ahead tiers).
By using the Platform or creating an account, you consent to the collection, use, storage, and disclosure of your personal information as described in this Privacy Policy. Your consent is provided through the act of creating an account (which requires you to agree to these terms) and through your continued use of the Platform.
This Privacy Policy is incorporated into and forms part of our Website Terms and Conditions. If you do not consent to this Privacy Policy, you must not use the Platform.
This Privacy Policy does not cover the practices of third-party service providers or other websites linked to from the Platform. We encourage you to read the privacy policies of those third parties before providing them with your personal information.
For all privacy-related enquiries, complaints, or access and correction requests, contact us at: support@lawreach.ai
2. Data Controller and Data Processor Roles
LawReach AI is the relevant APP entity responsible for complying with the Privacy Act 1988 (Cth) and the Australian Privacy Principles in respect of the personal information we collect, use, and disclose. We may refer to ourselves as a "data controller" elsewhere in this Policy as a general descriptor only, this is not a defined term under Australian law, and its use does not constitute an undertaking to comply with the GDPR or any other jurisdiction's data protection framework beyond what is otherwise required by law.
We engage the following third parties to help us provide the Platform. Each provider accesses only the personal information necessary to perform its specific function, except as otherwise described in this Policy:
- Cloud database and storage provider (Australia): data storage and database management (see Section 7)
- Anthropic PBC (United States): AI query processing (see Section 6)
- Cloud hosting and deployment provider (Australia): platform hosting and application delivery (see Section 7)
- Stripe, Inc. (United States/Australia): payment and subscription processing (see Section 8)
We engage these providers under their respective commercial or API terms of service. We do not control how each provider's infrastructure operates internally, and we rely on each provider's own security practices, terms of service, and (where applicable) industry certifications. While we select reputable providers and take reasonable steps to protect your information, we cannot guarantee a provider's compliance with the Australian Privacy Principles, and our liability in connection with any provider's handling of your information is limited as set out in our Terms and Conditions.
If you believe your personal information has been mishandled by any of our providers, contact us at support@lawreach.ai. We will investigate and, where appropriate, raise the matter directly with the relevant provider.
3. Personal Information We Collect: Platform Data
"Platform Data" means personal information we collect to create and manage your account, deliver the Service, process billing, and operate the Platform. Platform Data is distinct from User Content (see Section 4).
(a) Account Information
- Email address (used as your unique account identifier)
- Password (stored as a one-way cryptographic hash using industry-standard algorithms; we cannot retrieve or view your actual password)
Legal basis: Collection is reasonably necessary for the creation and management of your account (APP 3.2(a)).
(b) Profile Information
This is the information that makes a response specific to your business rather than general. We collect:
- Your first name, surname, and your role in the business (for example owner, director, manager, bookkeeper)
- Your business's legal name and any trading name
- Your Australian Business Number, and where applicable your Australian Company Number. Where you are a sole trader, your ABN is personal information about you
- Entity type, GST registration status, ABN status, and the ABN status effective date, each retrieved from the Australian Business Register using the ABN you give us
- Business structure (for example sole trader, company, partnership, trust, incorporated association)
- State or territory, suburb, and postcode, and the local government area we resolve from your postcode
- Location type (metropolitan, regional, rural, or remote)
- Industry, and optionally a second industry
- Your answers to the activity questions asked during setup, which record what your business does (for example whether you employ staff, lease premises, handle food, hold a licence, hold personal information, or take payment before delivery)
- Staff numbers, including how many are permanent, casual, casual for more than twelve months, under 18, or apprentices, and your pay cycle and pay day
- Key business dates you give us, such as lease end and option dates, insurance and licence renewal dates, and your standard invoice payment terms
- What you tell us you already have in place, such as a privacy policy, written employment contracts, or a safety policy
- The legal priorities you select, and any free-text note you add about your circumstances
- Your correspondence details for drafted letters, being your address for service, postal address, phone number, reply address, the name and title letters are signed in, any logo you upload, and any payment details you want to appear on a letter of demand. Payment details entered for this purpose are placed on documents you send and are never used to bill you
Legal basis: Collection is reasonably necessary to deliver contextualised AI responses and to provide the Service as described in our Terms and Conditions (APP 3.2(a)).
(b1) Staff Records You Choose to Create
If you use the staff records feature, you create a record for each employee containing their name or initials, start date, employment type, award or agreement, classification level, agreed hours, and whether a contract and Fair Work Information Statement were issued, together with any dated notes of warnings, meetings, performance conversations and employee-choice responses you add. If you use the employee-choice date tracking, we also hold the Fair Work business-size answer you confirm, the date a written notification was received, its response due date, and any response date, outcome and factual note you record. This is personal information about your employees, and you are its source. Clauses 4.3 and 4.3A apply to it.
The Platform asks you not to record health or medical information, tax file numbers, dates of birth, bank details, or information about a person's race, religion, union membership, or criminal history, and tells you that initials are sufficient. We do not require full names and the feature works with initials alone.
Legal basis: Collection is at your direction, for the purpose of delivering the Service you have asked for (APP 3.2(a)).
(c) Billing Information
- Stripe customer ID
- Stripe subscription ID
- Subscription tier (Aware, Assured, or Ahead) and status (active, cancelled, past due)
- Billing history, invoicing records, and transaction dates
Your card number, CVV, and expiry date are provided directly to Stripe, Inc. and are never transmitted to or stored on our systems. See Section 8.
Legal basis: Collection is reasonably necessary for subscription management and compliance with tax and financial record-keeping obligations (APP 3.2(a)).
(d) Usage and Technical Data
- IP address
- Browser type, version, and language
- Device type, operating system, and screen resolution
- Pages visited, features used, and navigation paths within the Platform
- Session identifiers, session start and end timestamps, and session duration
- Referral source (the website or link from which you arrived at lawreach.ai)
- Error logs and performance data
Legal basis: Collection is reasonably necessary for the operation, security, and improvement of the Platform (APP 3.2(a)).
(e) Communications Data
- Enquiries and support messages sent to us by email or through the Platform
- Feedback, complaints, and suggestions you submit
Legal basis: Collection is reasonably necessary to respond to your enquiry and to manage and improve our services (APP 3.2(a)).
4. Personal Information We Collect: User Content
"User Content" means the content you create, submit, upload, or generate through your use of the Platform. User Content is distinct from Platform Data (Section 3). User Content includes:
(a) Queries, Responses, and Organisational Data
- Every question and prompt you submit to the AI
- Every AI-generated response you receive
- Any structures you create within the Platform to organise or group related queries, responses, or documents (for example, by topic, project, or legal issue)
- Any AI-generated summaries or syntheses of your queries, responses, or organisational data
- Timestamps and session identifiers associated with each chat interaction
(b) Uploaded Documents
- Files you upload for storage within the Platform
- Contracts and other documents you upload for AI review or processing
- Text extracted from uploaded documents by the Platform for AI processing purposes
- File metadata (file name, file size, file type, upload date)
You retain ownership of your User Content at all times. We do not claim any intellectual property rights over User Content.
We use User Content only for the purpose of delivering the Service to you (including transmitting relevant portions to Anthropic for AI processing, as described in Section 6). We do not use User Content for advertising, marketing, model training, or any purpose unrelated to delivering the Service.
If your User Content contains personal information about third parties (for example, names, addresses, or other identifiable information in a contract you upload), you are responsible for: (a) ensuring you have the legal authority to disclose that personal information to us; (b) notifying those third parties that their information may be processed through the Platform as described in this Privacy Policy; and (c) any consequences arising from your failure to obtain the necessary authority. You acknowledge that uploading third-party personal data without authorisation may constitute a breach of the Privacy Act 1988 (Cth) and that you will be solely responsible for any resulting complaint, regulatory action, or liability, in accordance with the indemnity provisions in our Terms and Conditions.
Third-party information you supply deliberately. Some parts of the Platform are designed for you to enter information about other people, rather than merely allowing it to appear incidentally. These are your staff records, the parties named in documents you upload, the businesses you search on the public registers, and the senders and recipients of any email you copy to a matter address or forward to your vault address. For all of it, you are the source and you decide what is collected. You must have the authority to disclose it to us, and clause 4.3 applies. Where you are an employer, you should tell your employees that you keep their employment records in a third-party system, which is ordinarily something an employer is expected to do in any event.
We strongly recommend you do not submit highly sensitive personal information through the AI chat or document upload features. Highly sensitive information includes (without limitation): tax file numbers, Medicare numbers, passport numbers, financial account or card numbers, health or medical information, criminal records, or classified or legally privileged material.
No Intentional Collection of Sensitive Information. LawReach AI does not design the Platform to request, prompt for, or intentionally collect "sensitive information" within the meaning of section 6(1) of the Privacy Act 1988 (Cth) (which includes, among other things, health information, genetic information, information about criminal records, and information about racial or ethnic origin, sexual orientation, or religious beliefs). The profile collection process and account fields described in Section 3 do not request sensitive information.
Incidental Sensitive Information. Notwithstanding clause 4.5, the nature of the Platform means that User Content you submit as part of a free-text query, matter, or uploaded document may incidentally contain sensitive information about you or a third party, including where you were not specifically asked to provide it (for example, where a workplace dispute query refers to a person's health condition, or an uploaded contract refers to a party's criminal history). You acknowledge that:
- under Australian Privacy Principle 3.3, we are generally required to obtain your consent before collecting sensitive information about you, except in limited circumstances permitted by law;
- by voluntarily entering sensitive information into the Platform (rather than in response to a request from us), you consent to our collection of that information for the purpose of delivering the Service, including transmitting it to Anthropic PBC for AI processing as described in Section 6;
- where the sensitive information relates to a third party (for example, a client, employee, or opposing party), clause 4.3 applies, and you remain responsible for ensuring you have the necessary authority or consent to disclose that third party's sensitive information to us; and
- where sensitive information is submitted, we will not use it for any purpose beyond delivering the Service to you, and it will otherwise be handled in accordance with this Privacy Policy.
In-Product Notices. At every point where you can upload a document, forward an email, or type a question, the Platform displays a short notice asking you to redact tax file numbers, Medicare and passport numbers, financial account or card details, health information, and other highly sensitive information of the kinds described in clause 4.4 before you send it, and linking to this Policy. The staff records screen carries its own notice listing what not to record there. These notices are a reasonable step we take to reduce unnecessary collection of sensitive information. They do not prevent you from submitting such information if you choose to, and if you do, clauses 4.5 and 4.6 apply.
We do not apply a different storage location, security standard, or retention period to sensitive information than applies to other User Content. If you have submitted sensitive information and wish it to be deleted, contact us at support@lawreach.ai.
If you have submitted sensitive information about yourself and have concerns about how it has been handled, contact us at support@lawreach.ai. If your enquiry concerns sensitive information about a third party submitted in breach of clause 4.3, see the indemnity provisions in our Terms and Conditions.
Commercially Sensitive Business Information. This Privacy Policy, and the Australian Privacy Principles it's based on, protect personal information about individuals, not confidential information about businesses. If your User Content includes commercially sensitive business information (for example, details of an unannounced transaction, financial figures, pricing, or trade secrets, whether yours or someone else's), that information falls outside the scope of this Privacy Policy. Our position on handling that kind of information is set out instead in clause 9.5C of our Terms and Conditions. We do, however, store and secure commercially sensitive business information using the same measures described in Sections 7, 13, and 15, we don't treat it any less carefully, we just don't apply Privacy Act protections to it, because those protections only ever apply to individuals.
5. How We Collect Personal Information
We collect personal information through the following means:
(a) Directly from you
- When you create an account on lawreach.ai
- When you complete the profile setup process
- When you update your profile or account settings
- When you submit questions to the AI or organise your queries and documents within the Platform
- When you upload documents to your vault or for AI processing
- When you subscribe to a paid plan or manage your subscription
- When you contact us by email or through the Platform's support channels
(b) Automatically through technology
- Cookies and session tokens placed by the Platform (see Section 10)
- Server logs maintained by our cloud hosting provider
- Database activity logs maintained by our cloud database provider
- Error tracking and performance monitoring tools
(c) From third-party sources
- From Stripe, Inc., in connection with your payment transactions (e.g. subscription status updates, payment success or failure notifications)
We collect personal information only by lawful and fair means, and only to the extent reasonably necessary for one or more of the purposes described in this Privacy Policy (APP 3).
6. AI Processing: Anthropic
The AI functionality on lawreach.ai is powered by Claude, a large language model developed and operated by Anthropic PBC ("Anthropic"), a company incorporated in the United States. We access Claude through Anthropic's commercial API. Anthropic processes your queries as a service provider on our behalf and does not independently determine the purposes of that processing.
What is transmitted. To produce a response that is specific to your business rather than generic, the Platform assembles a context block and sends it to Anthropic with every request, together with your input and the current conversation. You should assume that the following is transmitted to Anthropic's servers in the United States:
- your business's legal name and trading name, ABN and where applicable ACN, entity type, structure, GST status, and ABN status effective date;
- your state, suburb, postcode, local government area, location type, and industry;
- your activity answers, staff numbers, pay cycle, standard invoice terms, and what you have told us you already have in place;
- your compliance register in full, including each obligation, the reason it applies to you, and its due date;
- an index of the documents in your vault, being filenames, document types, summaries, and dates extracted from them, and, where a document is relevant to the question, the full text of that document;
- your open matters, and your upcoming confirmed dates;
- the content of your question or the document you have submitted, and the current conversation.
Where a feature requires it, more is transmitted for that feature only:
- if your question concerns a particular person, your staff records for that business, including names or initials, start dates, employment type, award, classification, and hours;
- if you generate a brief for a solicitor, the full matter file, being the chronology, the correspondence records including sender and recipient email addresses and technical header results, the documents held, the drafts prepared, the counterparty search results, and the name, role, and email address of the person instructing;
- if you generate a draft, the facts of the matter it is drafted from, and where you own the matching template from our store, the text of that template.
What is not transmitted. Your password, your card and payment credentials, your Stripe identifiers, your billing history, and your technical and usage data (Section 3(d)) are never transmitted to Anthropic. Your account email address is not transmitted as part of ordinary chat, and is transmitted only in the circumstances described in clause 6.2A.
Why this is the design. The Platform is built so that you never have to explain your business before asking a question. That is only possible because the business context described above travels with the request. If you would rather a particular fact were not transmitted, remove it from your profile or your vault, and it will not be included.
Our AI provider does not use data submitted through its commercial API to train or improve its AI models. This is the default position under that provider's standard API terms, and is separate from the rules that apply to individual consumer accounts with the same provider, which are not what we use to provide the Service.
We do not use your User Content to train any model, ours or anyone else's, and we do not offer an option to opt in to that. See clause 16.2 for the only use we make of de-identified and aggregated data.
If we change to a different AI provider whose data practices materially differ from those described here, we will update this Privacy Policy and notify you before the change takes effect.
For information on how Anthropic handles data, see: https://www.anthropic.com/legal/privacy
6A. Email You Send Us, the Calendar Feed, and Register Searches
We do not connect to your mailbox. The Platform has no access to your email account, no mail credentials, and no ability to read anything you have not deliberately sent to us. There are two addresses, and you control both.
Per-matter addresses. Each matter you open is given its own email address. If you copy or blind copy that address on an email you send, we receive and store the message body, its attachments, and its technical headers, including the Message-ID, the Date header, and the results of the SPF and DKIM checks. We store the time recorded in the message's own Date header rather than the time we received it. This is what allows a matter chronology to distinguish what you can prove from what you recall.
Your vault address. Your business is given one forwarding address. Anything you forward to it is stored in your vault, read, and processed in the same way as a document you upload.
Personal information of other people. Mail you send to these addresses will ordinarily contain the personal information of the people you were writing to and anyone copied on it, including their names, email addresses, and whatever the message says about them. You choose what to send. Clauses 4.3 and 4.3A apply, and you should not send us mail you are not entitled to disclose.
Mail from anyone else is discarded. These addresses accept mail only from an address registered on your account. Mail from any other sender is rejected at the point of receipt and is not stored. We do not undertake to tell you that mail was rejected.
The calendar feed. If you subscribe to your dates in Google Calendar, Outlook, or Apple Calendar, we publish your confirmed dates at a secret address. Calendar subscriptions work this way in every major calendar application: the address is the credential, and anyone holding it can read the dates in the feed. The feed contains the title, date, and detail of confirmed deadlines only. It contains no documents, no correspondence, and no staff records. You can invalidate the address and issue a new one at any time from your settings, and you should do so if you have shared it.
Australian Business Register checks. When you check another business, we search the Australian Business Register only and store the result against your account so it can appear in a brief. We record the ABN, ACN or name you searched for, the business you selected, the register details returned, and the comparison details you entered for that check. This function does not search ASIC records, directors, PPSR registrations, credit information, litigation, solvency, or ability to pay. We do not tell the searched business that you searched for it because the Australian Business Register provides no notification mechanism for this lookup.
7. Data Storage Infrastructure
- (a) Cloud Database Provider: Primary Data Storage
Your Platform Data and User Content are stored using an Australian-based cloud database service ("Database Provider"). We take reasonable steps to ensure your data is stored within Australia.
The Database Provider processes your data on our behalf, only as directed by us and subject to confidentiality obligations. The Database Provider implements appropriate access controls to protect your data from unauthorised access.
Current details of the Database Provider's privacy practices are available on request by contacting support@lawreach.ai.
(b) Cloud Hosting Provider: Platform Hosting (Data Processor)
The Platform is hosted via a cloud hosting provider incorporated in the United States ("Hosting Provider"). Application requests are processed on our Hosting Provider's infrastructure in Sydney, Australia, consistent with our database location.
Current details of the Hosting Provider's privacy practices are available on request by contacting support@lawreach.ai.
(c) Data Location Summary
Data at rest (your stored account data, profile, queries, organisational data, and documents) is held on Australian-based infrastructure via our Database Provider.
Data in transit (your requests to and responses from the Platform) is processed through our Hosting Provider's infrastructure in Sydney, Australia.
Data processed by AI is transmitted to Anthropic PBC's servers in the United States. This is your input, your business profile, your compliance register, your document index, and, where relevant to the request, the full text of a document, your staff records, or a matter file. Section 6 sets this out item by item.
Payment data is processed by Stripe, Inc. (see Section 8).
Encryption. Personal information stored on our Platform systems is encrypted at rest and is only accessible via keys tied to the relevant user account. Encryption does not remove our obligations under the Privacy Act in respect of your personal information, and you retain all rights described in Section 19.
8. Stripe and Payment Data
All subscription payments are processed by Stripe, Inc. ("Stripe"), a PCI DSS Level 1 certified payment processor. When you subscribe to a paid plan:
- You provide your card details directly to Stripe through Stripe's secure checkout interface
- We do not receive, transmit, or store your card number, CVV, or expiry date at any time
- We receive and store only: your Stripe customer ID, subscription ID, subscription status, and transaction history (amounts and dates)
Stripe acts as a data processor for billing purposes and as an independent data controller in respect of payment card data.
Stripe's privacy policy is available at: https://stripe.com/au/privacy
Stripe's servers may be located in the United States, Australia, and other jurisdictions. By providing payment information through the Platform, you consent to Stripe processing your data in accordance with their terms.
9. How We Use Personal Information
We use your personal information to:
- Create and manage your account
- Deliver AI-generated legal information responses contextualised to your profile (state, location type, business structure, industry, and legal concerns)
- Maintain your query history, organisational data, and stored documents
- Process and manage your subscription and payments through Stripe
- Send you transactional communications (account verification, billing notifications, subscription updates, security alerts), these cannot be opted out of while your account is active
- Send you marketing communications where you have opted in, you may opt out at any time (see Section 14)
- Respond to your support enquiries
- Detect and prevent fraud, misuse, and security incidents
- Improve the Platform using de-identified and aggregated data (see Section 16)
- Comply with our legal obligations
We do not use your chat history or uploaded documents for advertising, marketing, or any purpose other than delivering the Service to you.
We will never share your chat history or uploaded documents with any third party for marketing or advertising purposes.
Multi-User and Team Accounts. Where multiple individuals use the Platform under a business or team arrangement, each user's personal information is collected and processed separately. The business that arranged team access does not have the right to access another individual user's chat history, uploaded documents, or personal information without that user's consent.
10. Cookies and Tracking Technologies
The Platform uses cookies and similar technologies for the following purposes:
- Strictly necessary: to maintain your login session, verify your identity, and protect against cross-site request forgery. These are essential; disabling them will prevent you from logging in.
- Preferences: to remember your display and account settings.
- Analytics: to collect aggregated, de-identified data about Platform usage and performance. No personally identifiable information is shared with analytics providers.
- Payment: cookies set by our payment processor (Stripe) for fraud prevention during checkout, subject to Stripe's own cookie policy.
We do not use third-party advertising cookies, do not allow advertising networks to place cookies on the Platform, and do not track you across other websites.
You may disable cookies through your browser settings. Disabling strictly necessary cookies will prevent you from logging in.
If we introduce additional cookies or tracking technologies, or our use changes materially, we will update this section and notify you.
11. Disclosure of Personal Information
We may disclose your personal information to the following categories of recipients, for the purposes described:
Data Processors (processing on our instructions)
- Anthropic PBC (United States): AI query processing. Receives your questions, your business profile, your compliance register, your document index and document text, and, where the feature requires it, your staff records and matter files (see Section 6)
- Cloud database and storage provider (Australia): data storage and database management (see Section 7)
- Cloud hosting provider (Australia): platform hosting, deployment, and analytics (see Section 7)
- Stripe, Inc. (United States/Australia): payment and subscription processing (see Section 8)
Other Recipients
- Our professional advisors (legal, accounting, and IT), subject to confidentiality obligations, where necessary to obtain professional advice or manage legal proceedings
- Regulators, government agencies (including the OAIC and the ACCC), courts, or law enforcement where required or authorised by or under an Australian law or a court/tribunal order (APP 6.2(b))
- A successor entity in connection with a merger, acquisition, sale of assets, or restructure of LawReach AI or LawReach Pty Ltd, in which case we will provide you with notice before your personal information is transferred and becomes subject to a different privacy policy
We do not sell, rent, or trade your personal information to any third party for any purpose.
We do not disclose your personal information to any third party for that third party's own marketing or advertising purposes.
We do not share User Content (including chat history and uploaded documents) with any third party except Anthropic PBC for the sole purpose of AI processing as described in Section 6.
12. Overseas Disclosure
Some of our service providers are located overseas. The following overseas disclosures occur in the ordinary operation of the Platform:
- Anthropic PBC, United States: AI query processing
- Cloud hosting provider, Australia: platform hosting, deployment, and application request processing (Sydney region)
- Stripe, Inc., United States (with Australian processing for some functions): payment processing
Primary data storage is with our Database Provider, which is located in Australia.
We take reasonable steps to ensure overseas recipients handle your personal information consistently with Australian privacy law. However, data protection laws in the United States differ from Australia's, and we cannot guarantee that an overseas recipient will comply with the Australian Privacy Principles in all circumstances.
By using the Platform, you expressly consent to your personal information being disclosed to the overseas service providers described in this Privacy Policy, where this is necessary to deliver the Service. By providing this consent, you acknowledge that Australian Privacy Principle 8.1 does not apply to such disclosures, and that LawReach AI will not be accountable under the Privacy Act 1988 (Cth) for the overseas recipient’s handling of your personal information once disclosed. We take reasonable contractual steps to protect your information but cannot guarantee that an overseas recipient will comply with Australian Privacy Principles in all circumstances.
13. Third-Party Data Processing
The Platform relies on multiple third-party service providers to operate, including Anthropic PBC (AI processing), cloud infrastructure providers (data storage and hosting), and Stripe, Inc. (payment processing). Each of these providers processes some or all of your personal information as described in this Privacy Policy.
We take reasonable steps to select reputable providers, enter into appropriate contractual arrangements, and verify their security practices (see Sections 6, 7, and 8). However, we do not own or control the systems of our third-party providers, and we cannot guarantee the security, availability, or ongoing compliance of those systems. A security incident at a third-party provider could result in unauthorised access to or loss of your personal information, and our ability to prevent or remedy such an incident may be limited.
Our obligations under this Privacy Policy extend to the steps we take to protect your information within our own systems, and to our selection of and contractual arrangements with our third-party providers. To the maximum extent permitted by law, we do not accept liability for the acts or failures of any third-party provider, except where we have been negligent in selecting or instructing that provider.
Specifically:
- Anthropic PBC provides the AI service on an “as is” basis without warranty of accuracy, completeness, or fitness for purpose (see Section 6). LawReach AI cannot and does not warrant that AI-generated responses will be accurate, current, complete, or appropriate for your circumstances;
- Our cloud database provider stores your data on Australian-based infrastructure and maintains industry-standard security certifications. However, LawReach AI does not independently audit our provider’s compliance and cannot guarantee that their security measures will prevent all incidents;
- Our cloud hosting provider processes application requests and data in transit through its infrastructure in Sydney, Australia. Initial routing may pass through global edge nodes, but function execution occurs in Australia. LawReach AI cannot control all aspects of edge routing through our hosting provider’s network; and
- Stripe, Inc. processes payment data under PCI DSS Level 1 certification. Card details are held by Stripe and are never accessible to us.
By using the Platform, you consent to the processing of your personal information by the providers described in this Privacy Policy. In the event of a data breach involving a third-party provider, we will comply with our obligations under the Notifiable Data Breaches scheme (see Section 18) and notify affected users as required by law.
We may change providers from time to time. If a change materially affects the processing of your personal information, we will update this Privacy Policy and notify you in accordance with Section 24.
14. Marketing Communications
We may send you marketing communications about LawReach AI products and services where you have opted in to receive such communications.
We comply with applicable Australian law regarding commercial electronic messages. All marketing emails include accurate sender information, a functional unsubscribe mechanism, and clear identification as commercial messages.
You may opt out of marketing communications at any time by: (a) clicking the unsubscribe link in any marketing email; or (b) contacting us at support@lawreach.ai.
Opting out of marketing communications does not affect transactional communications, which are necessary for the operation of your account (e.g. billing notifications, subscription status updates, security alerts, and account verification emails).
15. Data Retention
We retain different categories of personal information for different periods, depending on the purpose of collection and our legal obligations:
(a) Account and profile data
Retained for the duration of your account.
When you delete your account, three things happen in sequence, and they are the same three things the deletion screen in your settings describes:
- 1. Immediately. Your account closes, you are signed out of every device, and any active subscription is cancelled so you are not charged again. Your data becomes inaccessible through the Platform.
- 2. For 30 days. Your data is retained in a recoverable state. If you change your mind, email support@lawreach.ai from your registered address within those 30 days and we will restore it.
- 3. After 30 days. Your profile, compliance register, documents and the text extracted from them, matters, chronologies, correspondence records, drafts, briefs, staff records, deadlines, and conversation history are permanently and irreversibly deleted from our database and from storage. This cannot be undone and we cannot recover any of it for you afterwards.
What survives, and only this: billing and tax records we are required to keep under clause 15.1(d); and a minimal audit entry recording that an account existed and that deletion was requested and completed, which contains no document content, no chat content, and no register content. Neither is used for marketing, and neither is used for any purpose other than meeting a legal obligation or defending a claim.
Export before you delete. The export function in your settings gives you everything in one file. Once the 30 days have run, we cannot produce it for you.
(b) Query history and organisational data
Retained for the duration of your account, on the schedule you choose in your settings. You can set your chat history to be kept for 3 months, for 12 months, or until you delete it, and conversations older than the period you set are deleted automatically. Anything attached to a matter stays with that matter regardless of this setting, because it forms part of a record you may need later.
On account deletion, query history follows the same three-step sequence as clause 15.1(a): inaccessible immediately, recoverable for 30 days, permanently deleted after that.
(c) Uploaded documents
Retained until you delete them through the Platform, or until your account is deleted.
On account deletion, documents follow the same three-step sequence as clause 15.1(a): inaccessible immediately, recoverable for 30 days, then permanently purged from both the database and file storage.
If your subscription is downgraded to the free Aware tier, including following a failed payment, your documents are not deleted because of the downgrade. They remain in your vault, and how many of them you can access is governed by the plan you are on. If your account remains on Aware for 1 year from the date of downgrade, documents stored above the Aware limit are then permanently deleted, and we will email you before that happens so that you can export them or resubscribe.
(d) Billing records
Retained for a minimum of 7 years from the date of transaction, as required by tax and financial record-keeping obligations under Australian law (including the Income Tax Assessment Act 1997 (Cth) and the Taxation Administration Act 1953 (Cth)).
(e) Support communications
Retained for a reasonable period (up to 3 years from the date of the communication) for dispute resolution and quality assurance purposes.
(f) Usage and technical data
Retained in identifiable form for the period reasonably necessary for security and fraud prevention purposes. Aggregated and de-identified usage data may be retained for longer for analytics and product improvement purposes.
Where we are required by law to retain information for a specified period (e.g. for tax, regulatory, or dispute resolution purposes), we will retain it for that period regardless of account deletion.
After the applicable retention period, personal information will be securely deleted or permanently de-identified.
16. De-Identified and Aggregated Data
Your personal information stored on the Platform is encrypted at rest (see clause 7.10). Encryption protects your data from unauthorised access but does not constitute de-identification, as encrypted data can still be linked back to your account and remains personal information under the Privacy Act. Separately, we may generate de-identified and aggregated data derived from Platform usage by removing or aggregating all information that could reasonably be used to identify you or your business. Data that has been genuinely de-identified is not personal information within the meaning of the Privacy Act and is not subject to this Privacy Policy.
We may use de-identified and aggregated data (for example, total number of users by state, average session duration, feature usage statistics, and patterns in the types of questions asked) for analytics, product improvement, internal reporting, research purposes, and improving our AI system prompts and response frameworks. This use is not subject to the APPs or this Privacy Policy because the data is no longer personal information and cannot be used to identify you or your business.
We will not attempt to re-identify de-identified data except for the purpose of testing our de-identification processes.
17. Security
We take reasonable technical and organisational measures to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure, as required by APP 11.1. These measures include:
- One-way cryptographic hashing of passwords (we cannot retrieve your password)
- Access controls on our cloud database, ensuring each user’s data is isolated
- Encrypted data transmission using HTTPS/TLS for all data in transit
- Access controls restricting developer and administrative access to production systems
- Environment variable storage of sensitive configuration (e.g. API keys are never stored in source code)
- Periodic review of third-party provider security certifications and practices
You are responsible for maintaining the security of your own account credentials. We are not liable for any unauthorised access to your account resulting from your failure to secure your password or your decision to share it with others.
No data transmission over the internet or method of electronic storage is completely secure. While we take all reasonable steps, we cannot guarantee absolute security and do not warrant that your personal information will be free from unauthorised access.
If you believe your account has been compromised, contact us immediately at support@lawreach.ai.
18. Data Breaches
If we become aware of a data breach that is likely to cause serious harm to any affected individual, we will notify those individuals and, where required, the Office of the Australian Information Commissioner (OAIC) as soon as practicable.
If you believe a data breach may have affected your personal information, contact us immediately at support@lawreach.ai.
For the purposes of this section, an “eligible data breach” has the meaning given to it under Part IIIC of the Privacy Act 1988 (Cth). In summary, an eligible data breach occurs where: (a) there is unauthorised access to, or unauthorised disclosure of, personal information held by us, or personal information is lost in circumstances where unauthorised access or disclosure is likely to occur; and (b) a reasonable person would conclude that the access, disclosure, or loss is likely to result in serious harm to any of the individuals to whom the information relates.
Where we notify you of an eligible data breach, that notification will include: (a) a description of the breach; (b) the kinds of personal information involved; (c) what steps we have taken or are taking in response; and (d) recommendations for steps you can take to protect yourself. Notifications will be sent to your registered email address. Where it is not practicable to notify you directly, we will publish a notification on the Platform.
19. Your Rights
Under the Privacy Act 1988 (Cth), you have the right to:
Access
You may request a copy of the personal information we hold about you. We will respond within 30 days.
Correction
You may request that we correct personal information that is inaccurate, incomplete, or out of date. We will respond within 30 days.
Deletion
You may delete your account and associated personal data yourself, from your account settings, without asking anyone and without giving a reason. You may also ask us to do it by contacting support@lawreach.ai. Either way, your account closes immediately, your data is recoverable for 30 days if you change your mind, and after 30 days it is permanently and irreversibly deleted, subject only to the narrow legal retention obligations described in clause 15.1(a).
Data Export
You do not need to ask us. The export function in your account settings produces a single machine-readable file containing everything held about your business: your profile, your compliance register, your questions and the answers to them, your documents and the extracted text, your matters, chronologies, correspondence records, drafts, briefs, staff records, deadlines, and your activity log. Document files are listed with a download link.
If the export function is unavailable, or you want the information in another form, contact support@lawreach.ai and we will provide it within 30 days.
Complaint
You may complain about a breach of the Australian Privacy Principles. See Section 20.
We may require you to verify your identity before actioning any request.
We may decline a request in limited circumstances permitted by the Privacy Act, and will provide written reasons for any refusal.
20. Privacy Complaints
If you believe we have mishandled your personal information or breached the Australian Privacy Principles, you may lodge a complaint with us at support@lawreach.ai.
We will acknowledge your complaint within 7 business days.
We will investigate and provide a written response within 30 days of receiving your complaint.
If you are not satisfied with our response, or if we fail to respond within 30 days, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC): https://www.oaic.gov.au/privacy/privacy-complaints
21. Children
lawreach.ai is a business-facing platform intended exclusively for use by individuals who are 18 years of age or older. We do not knowingly collect personal information from persons under 18.
If we become aware that personal information has been collected from a person under 18, we will take reasonable steps to delete that information as soon as practicable.
22. Third-Party Websites and Links
The Platform or AI-generated responses may contain links to third-party websites, including government websites, legislation databases, court registries, legal aid services, and other external resources. These links are provided for informational purposes only.
We do not operate or control those websites and are not responsible for their content or privacy practices. We encourage you to read the privacy policy of any third-party website before providing personal information to it.
The inclusion of a link does not imply endorsement of the linked website or any association with its operators.
23. Relationship with lawreach.com.au
LawReach Pty Ltd also operates a separate legal template store at lawreach.com.au. The two websites are operated by the same legal entity (LawReach Pty Ltd) but maintain:
- separate account systems (an account on one site does not create an account on the other);
- separate data collection and storage systems;
- separate privacy policies; and
- separate terms and conditions.
This Privacy Policy applies to lawreach.ai only. The privacy policy for lawreach.com.au is available at lawreach.com.au/policies/privacy-policy.
We do not share personal information between the two platforms without your explicit consent, except where you contact us through a shared support channel (e.g. a general enquiry email).
24. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, our service providers, or applicable law.
Material changes (including changes to the categories of personal information collected, new data processors, or changes to overseas disclosure practices) will be notified to you by email to your registered address and/or by prominent notice on the Platform at least 14 days before the changes take effect.
Non-material changes (such as formatting or clarifications) may be made without notice.
The current version of this Privacy Policy, including the "Last updated" date, is always available at lawreach.ai/privacy.
Your continued use of the Platform after any update constitutes your acceptance of the updated Privacy Policy. If you do not agree with a material change, you should cease using the Platform and delete your account.
25. Contact
LawReach Pty Ltd (trading as LawReach AI)
Email: support@lawreach.ai
South Australia, Australia
ABN: 27 693 897 862
