Privacy Policy
Introduction
Senthil & Mukusha (“we”, “us”, “our”) is a New Zealand law firm. Your privacy matters to us, and we are committed to protecting the personal information you entrust to us.
This Privacy Policy explains, in plain language, what personal information we collect, how we use and share it, how we keep it safe, and what rights you have. It applies to our clients, potential clients, people connected with our clients, job applicants, suppliers, service providers and visitors to our website.
We are bound by the Privacy Act 2020 (the “Act”), as well as our professional obligations as lawyers, including the New Zealand Law Society’s Rules of Conduct and Client Care. In this policy, “personal information” means information about an identifiable individual.
By using our services, or by giving us your personal information, you consent to us collecting, using, storing and disclosing it as described in this policy.
What information do we collect?
The personal information we collect depends on your relationship with us. It may include:
- Contact and billing details – your name, email address, phone number, postal and billing address, and payment or bank account details.
- Identity and due diligence information – information required for customer due diligence under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009, such as your driver licence, passport, birth certificate or proof of address.
- Communications and instructions – emails, letters, meeting notes, file notes, voicemails and records of our discussions with you.
- Financial information – credit history and information needed for billing, trust account transactions and credit management.
- Business and marketing preferences – your areas of interest and expertise, your attendance at our events, and your preferences for the communications you receive from us.
- Recruitment information – if you apply for a role with us, your work history, academic record, referee comments, visa status, practising certificate and any relevant criminal record information.
- Website and technical information – IP address, browser type, internet service provider details and similar technical data (see “Our website and cookies” below).
If you do not give us the information we ask for, we may not be able to act for you or provide our services.
How do we collect personal information?
- Directly from you – when you instruct us, meet or speak with us, complete a form, apply for a role, supply goods or services to us, subscribe to our updates, or contact us through our website.
- Information we create – records and evaluative material we generate while acting for you, including file notes and our dealings with third parties. Evaluative information may be confidential to us.
- From third parties – for example, identity verification and screening providers, credit reporting agencies, government agencies, other parties to your matter, and (for job applicants) previous employers, referees, recruitment agencies or educational institutions.
- Information you make public – information you have clearly chosen to make publicly available, including online.
- Automatically – technical information collected when you visit our website.
If we collect your personal information from someone other than you, we will take reasonable steps to make sure you know we have collected it, why, and what your rights of access and correction are unless you already know, or the Act allows us not to tell you.
Personal information we obtain from a third party is used only for the purposes set out in this policy, and your rights under this policy apply to it.
Why do we use your personal information?
We use your personal information to run our practice, deliver our legal services and meet our legal and professional obligations. Specifically, we use it:
- to verify your identity and carry out customer due diligence;
- to carry out your instructions, provide legal services and fulfil our professional duties;
- to respond to your enquiries and communicate with you;
- to manage our client relationship, including billing, payments, trust account transactions, credit management and debt recovery;
- to check for and manage conflicts of interest;
- to improve and develop our services, and to send you legal updates, newsletters and information about our firm (subject to our confidentiality obligations);
- to assess applications for employment with us;
- to enforce our terms of engagement and protect our rights, property and safety, and those of our people, clients and others;
- for any other purpose we tell you about when we collect the information; and
- to comply with any legal or regulatory requirement, including a court order or a request from a regulator.
Who do we share it with?
We do not sell personal information. We share it only where it is necessary for the purposes above, or where you have authorised us to, or where the law requires or permits it. Recipients may include:
- other parties involved in your matter, including our contractors based in New Zealand and outside New Zealand;
- identity verification and screening agencies, document issuers, official record holders, credit bureaux and other authorised data providers (who may keep a record that a check was made);
- credit reporting agencies and debt collection agencies;
- our third party service providers, such as IT and cloud service providers, data storage and processing providers, auditors, banks and other financial service providers, and providers that help us with client analytics;
- courts, tribunals, regulators, enforcement bodies and government agencies; and
- anyone else you authorise us to share it with.
We may also disclose personal information where we are required or authorised to do so by you, by law, or by the Law Society’s Rules of Conduct and Client Care. We require our service providers to protect personal information and to use it only for the purposes we engage them for.
Identity and biometric verification
We are required to verify your identity under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009. We may offer an electronic verification option that collects biometric information (such as a facial scan) where you choose to use it. This is never your only option you may instead verify your identity using certified documents.
Where we collect biometric information, we use it solely to verify your identity. We retain it only for as long as needed for that purpose or as required by law, and then delete or anonymise it. You may access, request correction of, or raise concerns about your biometric information as described below.
Sending information overseas
Some of our service providers, contractors, including cloud storage providers, are located outside New Zealand. This means your personal information may be stored or accessed overseas. We will only disclose personal information to a recipient outside New Zealand in accordance with the Privacy Act that is, where the recipient is subject to comparable privacy safeguards, or where we have put contractual protections in place.
Storage, security and retention
We may hold personal information in hard copy and electronic form, at our offices and with third party data storage and cloud providers in or outside New Zealand. Electronic data held in the cloud is generally encrypted.
We take all reasonable steps to protect personal information from loss and from unauthorised access, use, disclosure, alteration or destruction. Those steps include physical and system security, restricted access to records, and requiring our people to access personal information only for work purposes and to respect its confidentiality.
If personal information we hold is subject to a privacy breach that is likely to cause you serious harm, we will notify you and the Office of the Privacy Commissioner as required by the Act.
We keep personal information for as long as we need it for the purposes described in this policy, for as long as we have a relationship with you, and for any further period required by law or our professional obligations (for example, anti-money laundering and file retention requirements). After that, we delete or anonymise it.
Our website and cookies
When you visit the public areas of our website you remain anonymous. We collect general technical information such as your IP address, browser type and internet service provider details, which we use to administer the site, count visitors and understand broad usage patterns. That information does not identify you personally.
Our website uses cookies – small text files stored on your device – to record how often the site and its pages are visited. We do not use cookies to collect information unrelated to your visit, and you can disable cookies through your browser settings.
If you email us through the website, log in to a password protected area, or otherwise provide personal information on the site (for example, to subscribe to our legal updates), you will no longer be anonymous and we will use that information for the purpose you provided it. We do not provide personal information collected through our website to third parties without consent, except as described in this policy.
Our website may link to sites we do not control. Those sites may use their own cookies and have their own privacy practices, which we are not responsible for. Please review their privacy policies before providing personal information to them.
Marketing communications
We are committed to complying with the Unsolicited Electronic Messages Act 2007. If you subscribe to our updates, or give us your email address or mobile number, you consent to receiving emails or texts from us promoting our services and sharing legal updates and event invitations.
You can opt out at any time by clicking the “unsubscribe” link in any marketing message, or by emailing senthilraj@senthilmukusha.co.nz. We will remove you from the relevant list as soon as reasonably practicable.
Your rights: access and correction
Under the Act you have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is wrong. You can also ask us to stop using or disclosing your personal information, and we will consider that request in light of our legal and professional obligations.
Please make your request in writing to senthilraj@senthilmukusha.co.nz. We will respond as soon as reasonably practicable and within the timeframes set by the Act. If we cannot give you access to some or all of the information, we will explain why.
Please help us keep your information accurate by telling us when your contact details change.
Concerns and complaints
We take privacy concerns seriously. If you have a concern about how we have collected, used, stored or disclosed your personal information, please contact our Privacy Officer at senthilraj@senthilmukusha.co.nz with “ATTENTION: PRIVACY OFFICER” in the subject line.
We will acknowledge your complaint promptly and deal with it fairly and consistently. If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner, or find more information at www.privacy.org.nz.
Changes to this Privacy Policy
We review this Privacy Policy from time to time to reflect changes in the law, technology, and the way we work. Any changes take effect from the date the updated policy is published on our website, or the date stated in the update, and apply to all personal information we hold. If a change is material, we will also try to tell you directly.
Contact us
If you have any questions about this Privacy Policy or about how we handle personal information, please contact us:
Senthil & Mukusha – Privacy Officer
Email: senthilraj@senthilmukusha.co.nz
