1 About This Policy
Lex Etheris (accessible at lexetheris.com.au) is a service operated by Lex Stratus Software Pty Ltd (ACN 633 861 275). In this Privacy Policy, "we", "us" and "our" refer to Lex Stratus Software Pty Ltd trading as Lex Etheris.
Lex Stratus Software Pty Ltd complies with the State and Commonwealth Privacy Laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles ("Privacy Law"). Lex Stratus Software Pty Ltd is committed to your privacy and to continuing to provide services in a confidential and safe manner.
This Privacy Policy summarises how Lex Stratus Software Pty Ltd handles your personal information.
We handle all personal and sensitive information you provide in accordance with Privacy Law and the safeguards this Privacy Policy describes. This policy applies to everyone the platform serves — the law practices that subscribe to it, and the people who use it at a representative's invitation.
2 Personal Information
Personal information is defined by the Privacy Act 1988 (Cth) as "information or an opinion about an identified individual, or an individual who is reasonably identifiable: (a) whether the information or opinion is true or not; and (b) whether the information or opinion is recorded in a material form or not."
The information collected is required in order to provide our services — which include case and client management, forms automation, appointment booking, billing and, for law practices that use it, trust accounting — and to improve those services.
Generally, the only personal information Lex Stratus Software Pty Ltd collects about you is that which you choose to tell us, or which you authorise us to obtain. There is one significant exception. Where a law practice uses our platform, it gives us information about its own clients, and it records in its trust books the details of people it pays money to and receives money from — who may have no relationship with us and may never have dealt with us. We hold that information on the practice's behalf and only for the purposes described under trust accounting below.
The type of information we may collect includes:
- identity and contact details — name, postal and email address, telephone number, and the details of the organisation you act for;
- account and billing information — your login details, your subscription and, where you purchase services, payment information (card numbers are handled by our payment provider and are not stored by us);
- professional credentials, where you are a practitioner — including a practising certificate number and expiry date and whether that certificate authorises the receipt of trust money;
- information you or a law practice enters into a matter — which, depending on the service, may include date of birth, passport and travel-document details, country of birth and of passport, and information relevant to an application, including health-related declarations that some visa applications require;
- trust-accounting information, where a law practice uses that module — including client and matter details, amounts, and the bank details of payers and payees. This is described in detail under trust accounting below;
- bank transaction data, where a practice connects its account — described under bank connections below; and
- technical information about your use of the website, described under automatic information below.
Some of this is sensitive information as the Privacy Act defines it — in particular health information supplied as part of an application. We collect it only where it is reasonably necessary for a service you or your law practice has asked us to provide, and we handle it in accordance with Australian Privacy Principle 3.
Sensitive Information in Visa Matters
Visa and immigration matters routinely involve sensitive information beyond the health declarations mentioned above: a person's racial or ethnic origin, health information, criminal record and, where a protection claim makes them relevant, religious beliefs, political opinions or sexual orientation. We collect sensitive information with consent and handle it only for the purposes of the matter it belongs to; we do not use it for any secondary purpose of our own.
Much of this information is not typed in by the person it is about. It is entered by the practitioner acting on that person's behalf, from the instructions and documents the person has given the practice — a collection from a third party rather than from the individual. The practice is responsible for having its client's consent to record it; we hold what is recorded under the protections this policy describes.
3 How Lex Stratus Software Pty Ltd Collects and Holds Your Personal Information
Where possible, Lex Stratus Software Pty Ltd will collect your personal information directly from you.
Personal and sensitive information may be collected from you when you provide it to us directly.
Lex Stratus Software Pty Ltd has established appropriate physical, electronic and managerial procedures to safeguard any information we collect. This helps prevent unauthorised access, maintains data accuracy and ensures that the information is used correctly.
All data transferred to and from Lex Stratus Software Pty Ltd servers is encrypted, and a firewall is in place to prevent intrusion. All data stored within our systems is designed to be accessed only by authorised staff members and the hosting facility.
4 Automatic Information
Lex Stratus Software Pty Ltd receives and stores certain types of technical information whenever you interact with us. This section says what that information is, what it is used for and how long it is kept. None of it is used for advertising, and none of it is disclosed for marketing.
Signed-In Requests and Security Logs
On every authenticated request to our platform we derive, on our own servers, the client IP address and a hashed browser fingerprint computed from browser identity headers, platform and language. Together they bind your session token to the connection that requested it — so that a token presented from a different device or network is refused — and they power rate limiting and the temporary blocking of abusive request patterns.
These values are kept in access-security logs for 180 days. Authorised staff can review a per-account timeline of platform API activity — an activity and audit monitoring console — for security, abuse investigation and support. Access to that console is itself restricted to authorised staff and is used for those purposes only.
Cookies
We use a single strictly-necessary cookie: a refresh-token cookie, set with the Strict same-site attribute, that keeps you signed in. Your browser's session and local storage are used for sign-in state. We set no third-party analytics, advertising or social-media cookies, we use no tracking pixels, and open and click tracking is disabled on the email we send. The full detail is in our Cookie Policy.
5 Purpose for Collecting, Holding, Using and Disclosing Personal Information
Lex Stratus Software Pty Ltd collects personal information that we consider relevant, and which is provided to us when you or a law practice engages our services, for the purpose of providing those services. Sensitive information, in most cases, can only be disclosed with your written consent. Personal information will not be used or disclosed for direct marketing unless you have given Lex Stratus Software Pty Ltd consent to do so.
Some of the ways we use personal information include to:
- personalise your service
- communicate with you and others as part of our core business
- send you information regarding changes to our policies, other terms and conditions, online services and other administrative issues
- enable us to provide a product or service
- allow us to track your service history
- prevent, detect and investigate crime, including fraud and money laundering, and analyse and manage other commercial risks
- verify information you have given to us
- carry out market research and analysis, including satisfaction surveys
- resolve complaints, and handle requests for data access or correction
- comply with applicable laws and regulatory obligations (including laws outside your country of residence)
- comply with legal process and respond to requests from public and governmental authorities (including outside your country of residence)
- establish and defend legal rights, protect our operations, rights or property, you or others, and pursue available remedies or limit our damages
- keep, produce and preserve the trust records that legal profession legislation requires a law practice to keep, and make them available for external examination and regulator inspection
- reconcile a law practice's trust account against its bank records and identify a deficiency or irregularity
- comply with record-retention obligations that require us to keep specific information for a fixed period, even after you have asked us to delete it
6 Disclosure of Personal Information
Lex Stratus Software Pty Ltd may disclose your personal or sensitive information (as defined in the Privacy Act):
- to regulatory authorities;
- where the law requires us to do so;
- where you consent for us to do so;
- to the law practice that engaged us, where we hold the information on that practice's behalf;
- to an external examiner appointed to examine a law practice's trust records, and to the legal services regulator of the practice's jurisdiction (a Legal Services Commissioner or Law Society), where the records are required to be produced for examination or inspection. Trust records are kept precisely so that they can be examined, and a practice cannot decline to produce them; and
- to service providers that host or process information for us under contract and on our instructions — our cloud provider, our email provider and, for bank-transaction data, our accredited CDR data recipient. Each is described in the relevant section of this policy.
Overseas Disclosure
Your data is stored in Australia: our compute and data stores run on Amazon Web Services in the Asia Pacific (Sydney) region. A small number of specific functions involve disclosure to providers that operate overseas. For the purposes of Australian Privacy Principles 1.4(f)–(g) and 8, the recipients and the countries in which they are likely to be located are set out below. Before disclosing personal information to an overseas recipient we take reasonable steps — including contractual safeguards — to ensure the recipient does not breach the Australian Privacy Principles in relation to it.
| Location | Recipient | What is disclosed, and why |
|---|---|---|
| United States | OpenAI | Content submitted to our AI features, for question answering, intent extraction and embeddings. See the artificial-intelligence section. |
| United States | DigiCert / Sectigo | A cryptographic hash of each finalised e-signature PDF, sent to obtain an RFC 3161 trusted timestamp. The hash is not the document and cannot be turned back into it. |
| United States, EU and India | Stripe and its service providers | Payment details, for payment processing. Stripe's service providers operate in the United States, the European Union and India. |
| Asia Pacific — Australia, Japan, Singapore and India (inference may route across these regions) | Anthropic models via AWS Bedrock | Internal error diagnostics, which can include captured request data, analysed to find and fix faults; and public-news material summarised for our practitioner digest. |
| Australia | Amazon Web Services (Sydney); Skript | AWS hosts our storage and compute in the Asia Pacific (Sydney) region. Skript is the Australian CDR-accredited data recipient for the optional bank-feed and trust features. |
Scroll the table sideways to see all columns.
In addition: Zoho processes inbound email sent to our support and privacy mailboxes, and may process it in the United States, India and Australia, the countries in which its data centres and support operations are located; and Google and Microsoft process mailbox and calendar data only where a practitioner has chosen to connect a Gmail or Google Calendar account, or an Outlook mail or calendar account — both are United States providers, and that data may be processed in the United States and in the other countries where they operate infrastructure. Trust records and CDR data are not disclosed outside Australia.
Electronic Signing and Message Recall
Two features disclose information in ways worth stating separately, because the recipients are the other parties to your own documents and conversations.
- Electronic signing. When an e-signature envelope is completed, an audit page is appended to the final PDF recording each signer's name, email address, the time they signed and the IP address they signed from. The completed PDF, including that audit page, is provided to the practitioner and to every signer — so in an envelope with more than one signer, each signer can see the others' IP addresses. The signing browser's technical details are stored for the audit trail but are never printed on the document.
- Message recall. Recalling or unsending a chat message hides it from all participants, but the original text and any attachments are retained for legal audit and record-keeping purposes. Recall changes what is displayed; it does not erase the record.
7 Artificial Intelligence and Your Matter
Some parts of this platform are assisted by artificial intelligence, and wherever AI is at work the product says so on the screen. The AI features are: an assistant that answers questions over Australian legal materials; drafting and action suggestions for your lawyer; and summaries of documents and news. You are never charged for any of this — platform fees are software fees charged to law practices.
When an AI feature runs, what is typed into it is processed by third-party providers: OpenAI, in the United States, for question answering, intent extraction and search; and Anthropic models via AWS Bedrock (Asia Pacific — Australia, Japan, Singapore and India, and inference may route across these regions), which we use internally to analyse error diagnostics — records that can include captured request data — and to summarise public news. Under those providers' published API terms, what goes in and what comes out is not used to train their models. Trust records and bank-feed data are never sent to any AI system, and your lawyer's practice can ask us to switch AI features off for its account.
AI can be wrong. Nothing an AI feature produces is legal advice, and your lawyer — a qualified practitioner — must review it before it is relied on in your matter. The judgement in your matter belongs to your lawyer, not to software.
8 Your Lawyer's Connected Tools
Your lawyer can connect a small number of optional tools to their Lex Etheris account. You never set these up and you never see a consent screen for them — but your information passes through them, so you should know what they do. Each is described in full, from the practitioner's side, in the version of this policy written for law practices.
Email and Calendar
Your lawyer may connect their own mailbox (Gmail, Outlook.com or Microsoft 365) so that correspondence with you can be read and managed inside your matter, and their own calendar so that appointments stay in sync. These connections are to your lawyer's account, not yours. We never send, compose or reply to email on anyone's behalf, and we never permanently delete email.
What this means for you: when you book an appointment through our platform, the calendar event we create in your lawyer's calendar, and the booking record behind it, may include your name, your email address, any note you added to the booking, the meeting details (such as a video-call link or a phone number) and fee information. Depending on the booking, that information is also used to email you a confirmation, rejection, cancellation or reschedule notice.
The Forms Manager Extension
Your lawyer may install an optional Google Chrome extension that fills Australian Department of Home Affairs online forms (ImmiAccount) and runs VEVO visa-entitlement checks using the data already in your file. When they do, the extension retrieves your application data from our systems on their instruction and types it into the government form in their browser.
That data can include personal and sensitive information about you: your name, date of birth, passport and travel-document numbers, country of birth and of passport, and the health-related declarations that some visa applications require. The extension operates only on lexetheris.com.au and on the Department's own site. It does not read browsing history, does not track activity, and holds your data in memory only for the duration of an active session. Beyond the flows just described, it sends nothing anywhere: it contains no telemetry and reports nothing back to us or to any third party.
9 Trust Money Held by Your Lawyer
If your lawyer holds money for you — a deposit, settlement funds, money paid in advance for fees not yet earned — that money sits in a trust account, and the law requires your lawyer to keep a detailed record of every dollar of it. Where your lawyer keeps those records with us, we hold them. This section explains what is recorded about you, who can see it, what you receive, and why some of it cannot be deleted even if you ask.
Whose Information This Is
Your lawyer holds your money and keeps the books. We supply the software the books are kept in, and we hold them on your lawyer's instructions. Your lawyer, not us, decides what a record says, and only your lawyer can authorise a change to one. That does not make us a bystander: under the Privacy Act 1988 (Cth) we are answerable in our own right for how the information is secured, retained, disclosed and destroyed. Both responsibilities apply at the same time.
What Is Recorded About You
Your lawyer's trust records about you may include:
- your name, address, email address and, where supplied, your telephone number;
- the reference and description of your matter, and your ledger account number;
- the balance your lawyer currently holds for you; and
- every receipt and payment on your ledger — the date, the amount, who the money came from or went to, the purpose, and the particulars your lawyer recorded.
Some of these are free-text fields your lawyer fills in. We do not ask for sensitive information in any of them, but what a purpose or particulars line contains is your lawyer's choice, and in some areas of practice such a line can reveal something you would regard as private. We use those fields only to produce the record and the documents made from it.
What You Receive
You receive three kinds of document from your lawyer through our platform: a trust receipt when money is received, a bill or invoice, and a trust account statement.
The statement is deliberately narrow. It has exactly six columns — Date, Particulars, Reference, Received, Paid and Balance. That is what moved, when, why and what remained. It does not carry our internal sequence numbers, our internal identifiers, or the bank-transaction references used to reconcile your lawyer's account, because none of those is information about you and none of them belongs on a document sent outside the practice.
Why You Cannot Log In to the Ledger
There is no way for you to open your trust ledger through our platform, and that is deliberate rather than an omission. Trust records are the law practice's books, kept in a form the law prescribes, subject to examination by an external examiner and inspection by the legal services regulator. Every trust function in our system is available only to the practice. You receive the documents your lawyer sends; if you want a statement, ask your lawyer for one — they are required to provide it.
If You Pay Money In, or Are Paid Money Out
The law requires a trust record to show where money came from and where it went. That has two consequences worth stating plainly.
- When money is paid out to you, your BSB and account number are recorded on the payment record, in full, together with your name. They are held in full rather than masked because a masked account number does not identify the account the money went to, and identifying it is the entire purpose of a payments record that an examiner may later have to trace.
- If you pay money into a law practice's trust account for someone else's matter — a settlement, a purchase, a payment on behalf of a family member — your name and the account details your bank sends with the payment may appear on that person's receipt and in that matter's records, because that is what the receipt has to show.
How Long It Is Kept, and Why It Cannot Be Deleted
Records of trust money must be kept for seven years, counting from whichever is later: the last transaction on your ledger, or the day your matter was finalised. That is not our policy — it is what the legal profession legislation requires of your lawyer, and it is the reason those records exist at all. They are the evidence that your money was handled properly.
Because of that, these records are kept in a form that cannot be altered. Nothing in our system can edit or remove an entry once it has been made. A correction is made by adding an entry that explains it. A cancelled receipt is kept and still appears in the book, marked as cancelled, because a receipt that has simply vanished looks exactly like one that was never issued.
This means that if you ask us to delete your personal information from a trust record, we cannot do it, and we would rather tell you that plainly than agree and quietly not. Australian Privacy Principle 11.2 requires personal information to be destroyed once it is no longer needed — but it does not apply where an Australian law requires the information to be kept. Trust records are exactly that case. Deleting one would itself be a breach.
What can be done: if something recorded about you is wrong — your name, your address, your matter reference — ask your lawyer to correct it. The correction is recorded alongside the original, so the record shows both what it said and what it now says. And once the seven years have run, your matter has been finalised and your balance is nil, your lawyer can direct that the record be destroyed.
What We Do Not Do
- We do not send trust information to any artificial-intelligence or machine-learning system, for any purpose, including training or summarisation.
- We do not use it for marketing, and we do not market to you.
- We do not sell, rent, licence or trade it.
- Our card payment processor does not receive it. Paying a bill online runs through a separate path; see Credit Card Details below.
- We do not disclose it outside Australia.
Asking a Question or Making a Complaint
If your question is about an amount, a receipt, a statement or what a record says, raise it with your lawyer first. Your lawyer keeps the books and only your lawyer can authorise a change to them.
If your question is about how we, as your lawyer's software provider, store, secure, retain or disclose that information, contact our Privacy Officer. You may also complain to the Office of the Australian Information Commissioner at oaic.gov.au.
A complaint about how your lawyer handled your money is a different matter and goes somewhere else entirely: to the legal services regulator in your lawyer's State or Territory — the Legal Services Commissioner or the Law Society. That avenue is yours regardless of anything in this policy, and it is the right one if you believe money was mishandled.
10 Bank Connections (Consumer Data Right)
A law practice using our platform may connect its own bank account so that transactions can be imported automatically for bookkeeping and reconciliation. That connection is made under Australia's Consumer Data Right (CDR).
Who Gives the Consent
The consumer who gives the CDR consent is the law practice, not you. You do not have a Consumer Data Right consent with us, and there is no CDR consumer dashboard here for you to use. We do not connect to your bank, we hold no consent from you, and we never see any of your accounts.
What It Means for You
It is still worth knowing what this means for you. If you pay money into a law practice's trust account, that payment appears in the practice's imported transaction feed — with the date, the amount, and whatever description, reference or name your own bank attached to it. We receive that from the practice's bank as part of the practice's own account activity. If you have a question about what your bank sends along with a payment, that is a question for your bank.
All of this data is stored and processed exclusively within Australia, and is never disclosed to, stored in, or processed in any location outside Australia.
Retention and Deletion of Bank-Feed Data
Imported transaction data is held in stores that are entirely separate from the trust records themselves and, unlike those records, it can be deleted. Deleting it destroys no trust record, because every particular the statutory books require is copied into the trust record at the moment an entry is posted. See Data Retention and Deletion below.
11 Automated Decision-Making
This section sets out, ahead of time, the disclosures about automated decisions that the Privacy and Other Legislation Amendment Act 2024 (Cth) will require of privacy policies when its transparency requirements commence on 10 December 2026.
- Kinds of personal information our automated systems use: account and usage data; the IP address and derived browser fingerprint described under automatic information; matter metadata; and message and form content where AI features are used.
- Decisions made solely by automated means: none that produce legal or similarly significant effects, with one exception — automated security measures. Rate limiting and temporary access blocking operate on request patterns without a human in the loop, because they have to act in seconds. A block can be reviewed by contacting support.
- Automated functions substantially and directly related to decisions a human makes: AI-assisted suggestions, document classification and document summaries, all of which a qualified practitioner reviews before reliance; and account-abuse flags, which our staff review before any action beyond the automated measures above is taken.
12 Information Security
Lex Stratus Software Pty Ltd protects personal information with technical and organisational measures proportionate to its sensitivity. The measures below are the ones we actually run. We hold no security certification — no ISO 27001, no SOC 2 — and this policy claims none; what follows is what we do, not a badge.
- Encryption — data is encrypted in transit using TLS and encrypted at rest on our AWS data stores. OAuth tokens for connected Google and Microsoft accounts are encrypted with AWS Key Management Service.
- Authentication — TOTP two-factor authentication is available on all accounts and required for practitioner accounts.
- Access control — role-based access on a least-privilege, need-to-know basis; application requests are authenticated and authorised server-side against the record owner; and each practice's data is logically separated from every other practice's.
- Audit logging — administrative actions are logged, and changes to financial and ledger records are captured in an append-only audit trail that records who changed what, when and why. That trail records changes; it does not record who has read a record.
- Security monitoring — the request fingerprinting, rate limiting and 180-day access-security logs described under automatic information.
- Backup and recovery — our databases have continuous point-in-time restore enabled, allowing recovery to any second within a rolling 35-day window. All restore data remains within Australia, under the same access controls and encryption as the live store.
- Hosting — our server-side systems and data stores run on Amazon Web Services in the Asia Pacific (Sydney) region. Personal information is stored in Australia; the specific overseas processing this policy discloses is listed under overseas disclosure.
- Subsystem separation — our payment processor and our AI features are architecturally separate from the trust and CDR subsystems and receive neither CDR data nor any trust record.
- Separation of deletable and non-deletable records — bank-feed data, which a consumer may have asked us to delete, and statutory trust records, which we are required to retain, are held in physically separate stores with separate permissions. Exactly one scheduled process in the entire system holds any deletion permission, it holds it on the bank-feed stores only, and it has no read or write access to any trust record. Honouring a deletion request therefore cannot damage a statutory record, and a fault in the deletion process cannot reach one.
- Data-breach response — described under data breaches below.
No system is absolutely secure, and we do not promise that ours is. What we promise is the measures above, honestly described, and candid notification if they fail in a way that affects you.
13 Data Retention and Deletion
We keep data only for as long as it is needed for the purpose for which it was collected, and we take reasonable steps to destroy or de-identify it once it is no longer needed and we are not required to keep it. We apply data minimisation at collection. Some records — trust-accounting records, e-signature audit trails, chat records, support tickets, invoices and financial records among them — are required by law to be kept, or are kept long-term as legal records, and cannot be deleted on request; the strictest case is set out under “Trust Records: A Statutory Retention Exception” below. This section applies to CDR data, to trust records and to other personal information, and is read together with the Trust Accounting, Consumer Data Right and Information Security sections above.
How Long We Keep Data
- Application and system logs are kept for 180 days.
- Access-security logs — the IP address and hashed browser fingerprint records described under automatic information — are kept for 180 days.
- Error diagnostics, which can include captured request data, are kept for up to 180 days; reports derived from them are kept for up to about 400 days.
- Financial and payment records are kept for seven years, consistent with section 286 of the Corporations Act 2001 (Cth).
- Matter and practice records are retained in accordance with the instructing law practice's instructions and its statutory duties — commonly seven years, under rule 14.2 of the Australian Solicitors' Conduct Rules, section 56(5) of the Migration Agents Code of Conduct 2022 and, for trust records, section 147 of the Legal Profession Uniform Law.
- Long-term legal records — e-signature audit trails, chat records (including recalled messages), support tickets, invoices and trust and audit records — are retained long-term as legal records and are not deleted on request.
- CDR transaction data is kept only while the relevant consent is active and the data is needed to provide the service; data derived from it (such as ledger entries, balances and invoices) is kept while it is needed to provide the service.
- Trust-accounting records are kept for seven years from the later of the last transaction entry in the record and the finalisation of the matter, as the legal profession legislation requires. They are not deleted automatically at the end of that period; they become eligible for the law practice to review and direct.
- Account and personal information is kept while your account is active. There is no self-service deletion or export: requests are made in writing to the Privacy Officer, and we take reasonable steps to destroy or de-identify the information once it is no longer required and is not subject to a retention obligation.
Trust Records: A Statutory Retention Exception
Where a law practice uses our trust-accounting module, the records of that trust account are subject to a statutory retention obligation and to a statutory prohibition on alteration. Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information once we no longer need it, but it does not apply where we are required by or under an Australian law, or by a court or tribunal order, to retain that information. Trust records fall squarely inside that exception.
In practical terms: a request to delete personal information from a trust ledger, a statutory book or a sealed monthly copy cannot be granted. Those records are append-only — there is no function in our system that edits or removes a posted entry — and they must be kept for seven years from the later of the last entry and the finalisation of the matter. A cancelled receipt or a voided invoice is retained and still appears in the book, marked as cancelled, because a removed record is indistinguishable from one that never existed.
What we can do instead is correct inaccurate information through the change record the rules require for that purpose, which preserves the old value alongside the new one; delete the separately-held bank-feed data, which destroys no statutory record; and destroy the trust record itself once the retention period has run, the matter has been finalised and the balance is nil. This is set out in full in the trust-records section above.
When We Delete Data
Data is treated as no longer needed — and enters our deletion or de-identification process — when a consent expires or is withdrawn, when a connected account is disconnected or an account is closed, when you request deletion, when the law practice that gave a CDR consent elects that redundant CDR data be deleted, when our accredited data recipient, as our CDR principal, directs us to delete or de-identify CDR data, or when the data is otherwise no longer needed for a permitted purpose. In each case, deletion applies to everything except data we are required by or under an Australian law, or by a court or tribunal order, to retain, and data subject to a preservation direction — which is isolated, restricted, and destroyed when the obligation ends.
CDR-Specific Deletion Obligations
As a CDR representative, we delete or de-identify CDR data in each of these cases: on withdrawal or expiry of the consent the law practice gave; where the practice elects that its CDR data be deleted once it is redundant (an election that overrides de-identification and continues to apply after the consent is withdrawn or expires); and where our accredited data recipient, as our CDR principal, directs us to do so. These obligations arise under CDR Rules 7.12, 7.13 and 1.10AA(4)(e) and Privacy Safeguard 12.
How We Delete Data and Verify Deletion
- Deletion is our default for CDR transaction data. Redundant CDR data is deleted or de-identified to the extent reasonably practicable, consistent with the CDR Rules.
- Where the law practice that gave a CDR consent has elected that its CDR data be deleted once it is redundant, that election overrides de-identification and continues to apply even after the consent is withdrawn or expires.
- Our file storage keeps previous versions of objects and our databases keep rolling backups, so a deleted file can remain internally recoverable for a period after deletion. Where data cannot be irretrievably destroyed immediately, it is isolated and not used or disclosed, and is destroyed as backups and version history cycle. For that reason we promise reasonable steps to destroy or de-identify — never instant or irreversible destruction.
- Each deletion or de-identification is recorded so that we keep an auditable record that it was carried out, and where a service provider holds copies we direct it to delete them.
Records We Must Keep by Law
Where we are required to keep specific records under Australian law, or the data relates to current or anticipated legal proceedings, we suppress automatic deletion for exactly that data, archive it with restricted access, and delete it once the obligation ends.
14 Credit Card Details
Lex Stratus Software Pty Ltd does not store credit-card numbers in its systems. Your credit-card details will be passed to the payment gateway as soon as they have been collected.
Two kinds of payment run through Stripe, our payment provider. For platform subscription fees, which are charged to law practices, Lex Stratus Software Pty Ltd is the merchant and Stripe processes the card; we never store card numbers.
Where you pay a law firm's invoice through the System, your card details are collected and processed by our third-party payment provider, Stripe, and settle into the law firm's own connected payment account. Lex Stratus Software Pty Ltd acts only as a technical provider: it does not hold or receive the funds, is not a party to the payment, and the law firm is the merchant of record. Any payment you make is also subject to Stripe's privacy policy and terms.
15 Direct Marketing
We distinguish between two kinds of message, and the distinction decides what you can opt out of.
- Service and transactional messages — security notices, receipts, appointment and matter notifications, and messages about your account or changes to our terms. These are part of operating the service and cannot be opted out of while an account is active.
- Marketing messages — currently limited to practitioner-facing material such as our immigration digest email. Marketing is strictly opt-in, confirmed by double opt-in, and every message carries a working one-click unsubscribe, which we honour within 5 business days, consistent with the Spam Act 2003 (Cth).
We do not market to visa applicants. We do not use Applicant information for our own marketing, and we do not send marketing to Applicants — at all, not merely on an opt-out basis.
You may ask us where we obtained your details, and we will tell you. Requests go to the Privacy Officer.
16 Data Breaches
We maintain a data-breach response plan. When we suspect a data breach that may be an eligible data breach, we assess it promptly and in any case within 30 days. Where the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) requires it, we notify the Office of the Australian Information Commissioner and the affected individuals as soon as practicable, and our notice says what happened, what information was involved and what we recommend you do.
Where a breach affects information we hold for a law practice — matter data, trust records or client files — we notify that practice without undue delay and cooperate with it so that it can meet its own obligations and inform its clients.
17 External Links
Lex Stratus Software Pty Ltd's website may contain links to other websites. When you access these links we recommend that you read the website owner's privacy statement before disclosing your personal information. Another website's handling of your personal information is governed by that website's own privacy policy, not by this one, and Lex Stratus Software Pty Ltd does not accept responsibility, to the extent permitted by law, for personal information collected outside our website. Nothing in this policy excludes any guarantee or right you have under the Australian Consumer Law.
18 Access to Personal Information
You may request access to the personal information we hold about you. There is no self-service export: requests are made in writing to our Privacy Officer, we take reasonable steps to verify your identity before releasing anything, and we respond within 30 days. Personal information is released directly to you unless you give us a written, signed authority to provide it to a third party.
Where the information you ask about is matter data — information held in a law practice's matter about its client — we route the request through the instructing practice, which holds the client relationship and any legal professional privilege in the material, and we assist the practice to respond. That is not a refusal; it is the practice's file, and privilege in it is the client's to claim and the practice's to assert.
If we refuse access, in whole or in part, we will give you written reasons and the complaint options described under “How a Privacy Complaint Is Handled” below.
19 Updating Your Personal Information
You may ask Lex Stratus Software Pty Ltd to update, correct or delete the personal information we hold about you at any time by writing to the Privacy Officer as specified below. There is no self-service deletion; every request is handled by a person. We take reasonable steps to verify your identity first, and we respond within 30 days. Requests about matter data are routed through the instructing practice, as described under access to personal information above.
Lex Stratus Software Pty Ltd also has obligations to take reasonable steps to correct personal information we hold when satisfied that it is inaccurate, out-of-date, incomplete, irrelevant or misleading for the purpose for which it is held.
Some information cannot be deleted on request because we are required by law to retain it, or because it is kept long-term as a legal record — trust-accounting records, e-signature audit trails, chat records, support tickets and invoices among them. Where that applies we will tell you, tell you why, and tell you when the obligation ends. If we refuse a request we give written reasons and the complaint options described below. See “Trust Records: A Statutory Retention Exception” above.
20 Anonymity and Pseudonymity
Australian Privacy Principle 2 gives you the option of dealing with us anonymously or under a pseudonym where that is lawful and practicable. On this platform it is not practicable, and we would rather say so than pretend otherwise. A visa application is made in a real identity — the identity is the subject matter of the application — and an account is bound to a verified email address and to the security measures described in this policy, which exist to keep other people out of your information. You can read our public pages and make a general enquiry without identifying yourself beyond a reply address, but you cannot hold an account or participate in a matter anonymously or pseudonymously.
21 Children
Accounts on this platform are for adults: you must be at least 18 years old to hold one. Visa applications, however, often contain information about children — as applicants, dependants or family members — and that information is entered by the law practice or by a parent or guardian, not by the child. We handle information about children with the same protections as all other matter information and, as with all Applicant information, we never use it for marketing.
22 Visitors from the EU and UK
Most people this policy applies to are in Australia, but a visa applicant often is not. If you are in the European Union or the United Kingdom, the GDPR or UK GDPR may give you additional rights over your personal data: access, rectification, erasure (subject to the legal holds and statutory retention described in this policy), restriction of processing, data portability and objection. Where those laws apply, we rely on performance of a contract, our legitimate interests and consent as our legal bases, and transfers of your data to Australia are protected by contractual safeguards. You may exercise these rights through the Privacy Officer, and you may complain to your local supervisory authority as well as to the OAIC.
23 Contacting Lex Stratus Software Pty Ltd Regarding Privacy
If you would like to make further enquiries, complain about a breach of the Australian Privacy Principles, or complain about a registered Australian Privacy Principles code (if any) that may relate to Lex Stratus Software Pty Ltd's business, please contact our Privacy Officer at:
Privacy OfficerLex Stratus Software Pty Ltd
Suite 101, 975 Whitehorse Rd
Box Hill VIC 3128
AUSTRALIA
Or email privacy@lexstratus.com.au.
How a Privacy Complaint Is Handled
Complain to our Privacy Officer first. We acknowledge a privacy complaint within 7 days and respond substantively within 30 days. If you are not satisfied with our response, or we fail to give one, you may complain to the Office of the Australian Information Commissioner:
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Post: GPO Box 5288, Sydney NSW 2001
- Web: www.oaic.gov.au
24 Policy Changes
Lex Stratus Software Pty Ltd may revise this Privacy Policy from time to time by updating this page. Where a revision corrects, clarifies or discloses more about what we already do, it takes effect when it is posted. Where a revision broadens how we use or disclose personal information, we will post it at least 14 days before it takes effect and will show both the posting date and the effective date at the top of this page. We suggest you review this Privacy Policy regularly.
What Changed in This Revision
Version 4.0, 17 August 2026. This revision discloses more about what we already do and corrects two overstatements; it does not broaden any use or disclosure, and so takes effect on posting. In summary:
- new sections on artificial intelligence and automated decision-making, ahead of the transparency requirements commencing 10 December 2026;
- an overseas disclosure table naming each overseas provider and its location. The previous statement that we operate no offshore infrastructure was true of hosting but overstated the position on processing, and has been corrected;
- “Automatic Information” now discloses the IP address and hashed browser fingerprint derived on every signed-in request, the security uses they serve and the 180-day retention of access-security logs;
- e-signature audit pages and chat message recall are now disclosed under disclosure;
- new sections on direct marketing, data breaches, anonymity, children and EU and UK visitors;
- “Data Retention and Deletion” now states the retention periods we actually run — 180-day logs, seven-year financial records, practice-directed matter retention — and the legal records that are kept long-term;
- cookie disclosures have moved to a dedicated Cookie Policy; and
- our contact details are unchanged.
Version 3.0, 5 August 2026. This revision adds disclosures about our trust-accounting module and corrects several statements that were incomplete or inaccurate. It describes what we already do; it does not broaden any use or disclosure, and so takes effect on posting. In summary:
- a new section on trust accounting and client money, describing what we hold on a law practice's behalf when it uses the trust module, whose information it is, who can see it, how long it is kept, and why trust records cannot be deleted on request;
- “Personal Information” now lists the categories of information we actually collect, including trust-accounting and bank-transaction data and the bank details of people who pay money to, or are paid money by, a law practice. The previous description was materially incomplete;
- “Disclosure of Personal Information” now discloses that a law practice's trust records are subject to examination by an external examiner and to inspection by the legal services regulator;
- “Data Retention and Deletion” now states the seven-year statutory retention that applies to trust records and the limits it places on a deletion request. The previous statement that account and personal information is deleted on request was wrong as applied to trust records;
- “Information Security” now describes our encryption at rest accurately — our cloud provider's server-side encryption using keys that provider manages, rather than a customer-managed key service — states that our audit trail records changes rather than reads, and describes the separation between deletable bank-feed data and non-deletable statutory records; and
- the “Consumer Data Right” section now names Skript as our accredited data recipient, correcting an earlier reference; states the 24-month transaction-history window we request and why; and discloses that the only personal information we send to that recipient is the law practice's own contact details.
Version 2.0, 14 July 2026. Added sections on the Google and Microsoft integrations, the Forms Manager browser extension, Consumer Data Right data, information security, and data retention and deletion.
Retrieved from https://lexetheris.com.au/User/Privacy — version 4.0, effective 17 August 2026. Printed .