‍ ‍

Privacy Policy

Last updated: August 2026

Version: 1.0

1.      About This Policy

Horrell Legal Pty Ltd ACN 701 270 206 (“we”, “our”, or “us”) is committed to protecting your personal information. While businesses with an annual turnover of less than $3 million are generally exempt from the Privacy Act 1988, we are a reporting entity under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (AML/CTF Act). Therefore, this Privacy Policy applies specifically to the personal information we collect, hold, use, and disclose for the purposes of, or in connection with, our AML/CTF obligations (such as Customer Due Diligence). We have a separate QPP Privacy Policy which applies to personal information we receive in the course of delivering services under contracts with certain Queensland Government and local government agencies and purchasers.

2.     Types of Personal Information We Collect

For AML/CTF compliance during designated services (e.g., conveyancing, corporate structuring and corporate transactions), we may collect:

  • Full name, residential or business addresses, date of birth, email address, phone number, other contact details

  • Government-issued identification details, such as driver licence, passport, Medicare card or other ID document numbers

  • Biometric information, such as a facial image or short video used to verify your identity

  • Beneficial ownership and control information for corporate clients or trusts

  • Source of wealth or source of funds information

  • Records of transaction monitoring and risk assessments

We only collect personal information that is reasonably necessary to carry out our business activities.

3.     How We Collect Personal Information

  • Directly from you when you onboard as a client or provide identification documents

  • From third-party identity verification providers and public registers

4.    Identity Verification and Government Data Matching (DVS)

To verify your identity, we may use electronic identity verification services, including the Australian Government's Document Verification Service (DVS). Where you have consented, your name, date of birth and identity document details will be securely sent to the relevant Commonwealth or State authority that issued your document.  This may include passport offices, driver licence authorities, the Department of Home Affairs, Births Deaths and Marriages, or other authorised record holders. These authorities check whether the details you have provided match the records they hold. We do not receive a copy of your government records. The authority returns a match result only, confirming whether your details match (yes or no). This process may be carried out through accredited identity verification providers, including APLYiD (APLYiD Pty Ltd, ABN 36 632 866 794) and its sub-providers. More information about the DVS is available at idmatch.gov.au.

5.     Biometric Information

As part of identity verification, we may collect biometric information, such as a facial image or a short video of you holding your ID. Biometric information may be used to:

  • confirm that you are a real person and physically present

  • match your image to the photograph on your identification document

  • reduce the risk of fraud and identity theft

Biometric information is treated as sensitive information under the Privacy Act. We only use it for identity verification and related compliance purposes, and only with your consent.

6.    Why We Collect Your Personal Information

We collect, use and disclose your personal information to:

  • verify your identity

  • provide and manage our services to you

  • communicate with you about your account with us

  • meet our legal and regulatory obligations, including anti-money laundering and counter-terrorism financing (AML/CTF) requirements

  • detect and prevent fraud, and keep our systems secure

  • improve our services

  • conduct ongoing customer due diligence and risk profiling

  • submit required reports (such as Suspicious Matter Reports) to AUSTRAC

Note: We do not disclose the existence of Suspicious Matter Reports to clients, as doing so may breach "tipping off" prohibitions under law.‍ ‍

7.    Consent to Collection and Identity Verification

By providing your personal information and completing the identity verification process, you consent to:

  • the collection, use and disclosure of your personal information for identity verification, AML/CTF and related compliance purposes

  • the collection and use of biometric information, such as a facial image or video, for identity verification

  • your information being checked against records held by Commonwealth and State authorities through the DVS

  • your information being shared with our authorised identity verification providers, including APLYiD

Your consent is voluntary.  You can withdraw your consent at any time by contacting us using the details in section 11. If you do not consent, or do not provide the information we need, we may not be able to verify your identity electronically. In that case, we may need to verify your identity in another way, or we may not be able to provide our services to you.

8.    Disclosure of Personal Information

We may disclose your personal information to:

  • identity verification providers, including APLYiD and its authorised sub-providers

  • Commonwealth and State authorities and official record holders, through the DVS

  • our employees and authorised representatives, on a need-to-know basis

  • our professional advisers, such as lawyers, accountants and auditors

  • trusted technology and service providers that help us operate our business

  • regulators, law enforcement or other third parties where required or authorised by law

We do not sell your personal information.

9.    Overseas Disclosure

Some of our service providers may store or process personal information outside Australia. Where this happens, we take reasonable steps to ensure that your personal information is handled in line with the Australian Privacy Principles, including through contractual protections with our providers.

10. Data Security and Storage

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. These steps include secure systems, access controls, and encryption in transit and at rest where appropriate. We retain personal information only for as long as we need it for the purposes set out in this policy, or as required by law.  When we no longer need your information, we securely delete or de-identify it.

11.  Access, Correction, and Complaints

You have the right to request access to or correction of the personal information we hold about you under the Privacy Act, subject to restrictions where providing access would compromise anti-money laundering tipping-off laws.

If you have a privacy complaint or question, contact our director at:

Email: admin@horrell.com.au‍ ‍

Phone: 1300 452 900

Address: Workspace365, Level 5, 14 Banfield Street, Chermside Qld 4032

If unsatisfied with our response, you can contact the Office of the Australian Information Commissioner.