Smart Law Tech

Privacy policy

Last updated: 27 July 2026

Smart Law Tech Pty Ltd (ABN 39 670 227 540) ("Smart Law Tech", "we", "us") builds practice management software for law firms. This policy explains how we handle personal information, and how we handle data belonging to our customers and the third-party accounts they choose to connect.

We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).

1. Two different roles

It matters which of the following applies:

2. What we collect

Website visitors

If you contact us, we collect the details you provide (such as your name, email address, firm and your message). Our web host records standard server logs, which may include IP address, browser type and the pages requested.

Users of our software

Account details for the individuals a firm authorises to use our software — name, work email address, role within the firm, and records of activity within the platform needed to operate it securely (for example sign-in events and changes made to records).

Information a firm stores in the platform

Firms use our software to record client enquiries, matters and related documents and correspondence. This can include personal and sensitive information about that firm's clients. We access it only where necessary to provide, support, secure or repair the service, or where the law requires it.

3. Connected third-party accounts

A firm may choose to connect accounts it already holds with third-party providers so that information from those accounts appears in our software. Connections are made by the firm, with the firm's own credentials, and can be disconnected by the firm at any time.

Google

Where a firm connects its Google Ads account, we access it using Google's authorised OAuth process, with permissions granted by the firm. We use that access to:

Our use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. We do not use Google user data for advertising, we do not sell it, we do not transfer it to others except as needed to provide the service or where the law requires it, and we do not allow humans to read it except with the firm's consent, for security purposes, to comply with the law, or where the data is aggregated and de-identified.

Meta (Facebook and Instagram)

Where a firm connects its Meta advertising account or lead forms, we receive the enquiries submitted through those forms and information about the advertising that produced them. We use this only to deliver those enquiries into the firm's own workspace and to report on them for that firm.

Microsoft

Where a firm connects its Microsoft 365 account, we access mail and calendar data as authorised by the firm, in order to show and file that information against the firm's matters.

4. How we use information

We do not sell personal information, and we do not use our customers' data, or the data in their connected accounts, to train third-party artificial intelligence models for our own purposes.

5. Keeping firms separate

Each firm's data is logically separated and access-controlled so that one firm cannot see another firm's information. We do not combine or aggregate identifiable data across customers.

6. Storage, security and location

Information is stored using established cloud infrastructure providers, encrypted in transit and at rest. Access by our personnel is limited to those who need it to operate or support the service. Some providers we rely on may store or process data outside Australia; where that occurs we take reasonable steps to ensure the information is handled consistently with the APPs.

No system can be guaranteed completely secure. If a data breach occurs that is likely to result in serious harm, we will act in accordance with the Notifiable Data Breaches scheme.

7. Disclosure

We disclose personal information only: to service providers who help us operate the platform, under obligations of confidentiality; to a firm's own authorised users; where you or the firm asks or consents; or where required or authorised by law.

8. Retention and deletion

We keep information for as long as needed to provide the service and to meet legal obligations. A firm may request export or deletion of its data; on request we will delete or de-identify it within a reasonable period, subject to any legal retention requirements and to routine backups, which expire on their own cycle. Disconnecting a third-party account stops further access immediately.

9. Cookies

This website uses only what is necessary to serve the pages. Our software uses cookies and similar technologies that are necessary for signing in and keeping sessions secure.

10. Your rights

You may ask for access to the personal information we hold about you, and ask us to correct it, by contacting us below. If the information is held in a firm's workspace, we will usually refer the request to that firm, as they are responsible for it.

11. Complaints

If you believe we have mishandled your personal information, please contact us first and we will investigate and respond. If you are not satisfied, you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.

12. Changes

We may update this policy from time to time. The date at the top shows when it last changed.

13. Contact us

Smart Law Tech Pty Ltd
Email: info@smartlawtech.com.au
Queensland, Australia