07 3088 7714  info@willwise.com.au

 

Privacy Policy

Who we are

1. Introduction and our commitment

Wills & Estates Australia Pty Ltd ACN 639 308 857 trading as Willwise (weus or our) is a boutique Queensland estate planning legal practice. We help clients with Wills, Enduring Powers of Attorney, Advance Health Directives, Estate planning and the administration of deceased estates.

We value your privacy and the confidentiality of the information you share with us. This Privacy Policy explains how we collect, use, hold, disclose and protect personal information, how you can access or correct it, and how to make a privacy complaint. It is written to be clear and useful — please contact our Privacy Officer if anything is unclear.

2. Scope of this policy – how it applies

We handle personal information in accordance with this Privacy Policy, our professional obligations of confidentiality, and applicable privacy laws.

As a small legal practice, our obligations under the Privacy Act 1988 (Cth) and the Australian Privacy Principles apply where the law provides that they apply — including where we collect and handle personal information for anti–money-laundering and counter-terrorism financing (AML/CTF) purposes in connection with certain services. For our other work, we handle your personal information in accordance with this policy, our professional duty of confidentiality, and other applicable laws.

We have chosen to apply consistent privacy standards across our practice as a matter of good practice, client transparency and risk management — whether or not a particular requirement is legally required for a given piece of information.

The specific details of how we collect and handle personal information for AML/CTF customer due diligence are set out in our AML/CTF Privacy Collection Notice (see section 7), which should be read together with this policy.

3. The information we collect

The personal information we collect depends on your matter and our dealings with you. It may include:

  • Contact and identity information — name, address, contact details, date of birth, and identification documents or identifiers where required;
  • Matter information — information relevant to your estate planning or estate administration, including details about your family, assets, wishes and circumstances;
  • Financial information — billing and payment information, and, where relevant to a matter, information about assets or sources of funds;
  • Sensitive information — for example health information — which we collect where you consent and it is reasonably necessary for our legal services, where collection is required or authorised by law, where necessary for legal claims or legal services, or where another applicable exception permits collection; and
  • Technical information — limited information collected automatically when you use our website, such as analytics data (through Google Analytics) and security data set by our website security tools. See section 13 for detail.

We collect only what we reasonably need for the purpose concerned.

4. How we collect personal information

We generally collect personal information directly from you — through our enquiry and intake forms, in correspondence, and in meetings.

We may also collect personal information:

  • from people you authorise us to deal with (such as family members, executors, attorneys or other advisers);
  • from public registers and records (for example, land titles, company and court records); and
  • where AML/CTF customer due diligence applies, through a third-party electronic identity-verification provider.

Where it is reasonable and practicable, we will collect personal information about you from you. Where we collect personal information about you from another person or source, we take reasonable steps to notify you of the relevant circumstances of the collection and the matters required by applicable privacy law, unless an exception applies. Where lawful and practicable, you may make a general enquiry without identifying yourself or by using a pseudonym. We may be unable to provide legal services, conduct conflict checks, verify identity or comply with AML/CTF obligations unless you provide accurate identifying information.

5. Why we collect personal information and how we use it

We collect, hold, use and disclose personal information to:

  • provide estate planning and estate administration legal services to you or our client;
  • communicate with you and administer your matter;
  • conduct conflict checks, assess whether we can accept or continue to act, and complete client-onboarding and risk-management procedures;
  • confirm identity and, where relevant, authority to act for another person or an estate;
  • manage and operate our practice, including billing, quality management and practice risk management;
  • comply with our professional, regulatory and legal obligations; and
  • where a matter involves a designated service, meet our AML/CTF customer due diligence and record-keeping obligations.

We use personal information for the purpose for which it was provided and for related purposes you would reasonably expect, or as otherwise permitted or required by law. We do not sell or trade your personal information, and we do not use it for marketing without your consent.

6. Confidentiality and privilege

Separately from privacy law, we owe you professional duties of confidentiality under the Australian Solicitors’ Conduct Rules, the general law and applicable legal profession legislation. Some communications and documents may also be protected by legal professional privilege. Confidentiality and legal professional privilege are distinct protections. Our duty of confidentiality generally continues after your matter ends. Legal professional privilege belongs to the client and applies where its legal requirements are satisfied. Nothing in this policy reduces those protections.

Nothing in this policy reduces those obligations. Where this policy and our duties of confidentiality or privilege differ, we act consistently with our professional obligations.

7. AML/CTF customer due diligence

From 1 July 2026, law practices that provide certain services known as designated services are subject to Australia’s AML/CTF laws in relation to those services. As part of our ordinary client-onboarding and professional-risk procedures, we generally confirm the identity of clients in most matters. This is separate from the more detailed customer due diligence measures when we provide a designated service. Most everyday estate planning work — including preparing a Will, a testamentary trust created by a Will, an enduring power of attorney or advance health directive, providing advice only, and administering a deceased estate, including a transfer of real property as part of probate or pursuant to a court or tribunal order — will not ordinarily require AML/CTF customer due diligence, though we still verify your identity in our usual way. Where a matter involves a designated service, we carry out the customer due diligence measures required by the AML/CTF laws, having regard to the circumstances and assessed risk.

When those checks apply, we will give you our AML/CTF Privacy Collection Notice, which sets out specifically what we collect for customer due diligence, why, how, and who it may be shared with (including AUSTRAC where required). That notice should be read together with this policy. We do not repeat that detail here.

8. Disclosure of personal information

We keep your information confidential and disclose it only as needed for your matter, with your authority, or as permitted or required by law. Depending on your matter, we may disclose personal information to:

  • people and organisations you authorise us to deal with;
  • other parties to a matter and their advisers, courts, tribunals and government agencies, where appropriate;
  • our service providers who help us operate the practice and deliver services (such as document, email, practice-management, accounting, identity-verification and estate-administration systems); and
  • regulators, our insurers, and others where required or permitted by law.

Where AML/CTF obligations apply, we may also be required to disclose information to AUSTRAC

, or to another  authority where disclosure is permitted or required by law.
AML/CTF information — how it is treated differently. Information we collect and hold for anti–money-laundering and counter-terrorism financing (AML/CTF) customer due diligence — for example, identity documents and identifiers, verification results, and source-of-funds or beneficial-ownership information — is used only for identity verification, AML/CTF compliance checks and client onboarding, and to meet our record-keeping and reporting obligations. We donot use or disclose AML/CTF information for marketing, and we do not disclose it except as permitted or required by the AML/CTF laws (including to AUSTRAC where required) or as otherwise required by law.

Other personal information. Personal information that is not AML/CTF information is handled under the general terms of this policy — including disclosure to our service providers (some of whom are overseas) to operate our practice and deliver services, and use for marketing only with your consent.

9. Overseas disclosure

We use a range of service providers to operate our practice and to deliver legal services — including document and email systems, practice-management software, accounting software, identity-verification services, estate-administration platforms and writing/productivity tools. Some of these providers are Australian and store information in Australia. Others are global businesses, and some personal information may be stored, processed, accessed or disclosed outside Australia.

Where it is practicable to identify them, the countries in which personal information may be stored, processed or accessed include, depending on the provider, New Zealand, the Philippines, Singapore, the United States and other countries. Because global providers and their subprocessors may change their processing arrangements, it may not always be practicable to identify every country in advance. We review and update the countries identified in this policy where reasonably practicable

Before disclosing personal information to an overseas recipient, we take reasonable steps in the circumstances to ensure the recipient handles it consistently with the Australian Privacy Principles, except where an exception under the Privacy Act applies. The level of protection of personal information overseas may differ from that in Australia.

10. Storage, security and retention

We store personal information securely, in physical and electronic form, and take reasonable steps to protect it from misuse, interference, loss, and unauthorised access, modification or disclosure.

Access is limited to authorised personnel and service providers who require access for an authorised purpose, and we use appropriate organisational and technical safeguards. Depending on the system and the sensitivity of the information, these may include access controls, secure document-management systems, personnel training, service-provider due diligence, secure destruction, incident-response procedures, multi-factor authentication where applicable, and backup and recovery arrangements.

We may use electronic and computer-assisted tools to support functions such as identity verification and, using our practice-management system, conflict checking and client-acceptance and AML/CTF risk assessment. These tools support, but do not replace, decisions made by appropriately authorised personnel, and we do not use solely automated decisions that significantly affect an individual’s rights or interests.

We do not ordinarily record or transcribe client meetings or calls without notice. Where a meeting or call is recorded or transcribed, we will make participants aware and explain the purpose, handling and retention of the recording or transcript.

Where identity verification is carried out, we generally retain a record that verification was completed rather than full copies of your identity documents, unless we have a specific reason to keep a copy. Where AML/CTF record-keeping

obligations apply, we retain the required records for the period prescribed by law, which will commonly be seven years but may depend on the type of record and the event from which the retention period runs. We otherwise keep personal information for as long as needed for the purpose for which it was collected and to meet our professional, legal and insurance obligations, after which we take reasonable steps to destroy or de-identify it.

We do not adopt a government-related identifier as our own identifier unless permitted by law. We may collect, use or disclose government-related identifiers where reasonably necessary for identity verification, legal services or AML/CTF compliance, or where otherwise required or authorised by law.

Where the Privacy Act applies to personal information we hold, we will comply with the Notifiable Data Breaches scheme, including notifying you and the Office of the Australian Information Commissioner where a data breach is likely to result in serious harm. If we suspect that an eligible data breach may have occurred, we will undertake a reasonable and expeditious assessment and take reasonable steps to complete that assessment within the period required by law.

11. Access and correction

You may ask to access the personal information we hold about you, or to correct it if it is inaccurate, out of date, incomplete, irrelevant or misleading. Please contact our Privacy Officer (section 14).

We will respond within a reasonable period. Where the Privacy Act applies, your access and correction rights (and the limited grounds on which access may be refused) are governed by that Act, and we will give written reasons if we refuse. In some cases our duties of confidentiality and privilege to clients, or other legal limits, may affect what we can provide — particularly if you are not our client. We may need to verify your identity before acting on a request. We do not charge for making an access or correction request. Where permitted by law, we may charge a reasonable amount for the costs of providing access, but not for correcting personal information.

12. Complaints

If you have a question about this policy, or a concern about how we have handled your personal information, please contact our Privacy Officer in writing. We will acknowledge your complaint promptly, investigate it, and aim to respond within 30 days.

If your complaint concerns information to which the Privacy Act applies and you are not satisfied with our response, you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au. You may also raise a concern with the Queensland Legal Services Commission where it relates to the professional conduct of a solicitor or another matter within the Commission’s jurisdiction.

13. Third-party websites and cookies

Our website may contain links to other websites; we are not responsible for the privacy practices of those sites and encourage you to read their privacy policies.

When you use our website, information may be collected as follows:

  • Enquiry forms — enquiry details you submit are collected through our intake forms (provided by Smokeball).
  • Bookings — appointment bookings are made through the Microsoft 365 Bookings app.
  • Analytics (Google Analytics) — Google Analytics may collect or generate information about your browser, device, approximate location, interactions with our website and online identifiers, including a randomly generated identifier used to distinguish visitors. Reports available to us are generally aggregated, but information processed by Google should not be regarded as necessarily anonymous.
  • Website security (Wordfence) — Wordfence may set cookies or process technical information, including IP address, browser and device information, to help detect malicious activity, prevent unauthorised access and secure the website. Some security cookies apply only to authorised website users or administrators.

14. How to contact us / Privacy Officer

Privacy enquiries, access and correction requests, and complaints are handled by our Privacy Officer.

15. Changes to this policy

We may update this policy from time to time to reflect changes in our practices, our service providers or the law. The current version will be available on our website at https://willwise.com.au/privacy-policy/. Where changes are significant, we will take reasonable steps to bring them to clients’ attention.

Last updated: 1 July 2026 v1.1

The description of AML/CTF obligations in this policy is a general, plain-language summary. Whether customer due diligence applies in a particular matter depends on the services provided and the applicable law. Nothing in this policy limits or overrides our obligations under the AML/CTF legislation, the Privacy Act or our professional obligations.

Scroll to top