Privacy Policy
Last updated: 1 July 2026
Stone Group Lawyers Pty Ltd ACN 161 443 812 as trustee for the Stone Trading Trust ABN 34 573 048 566, practising as Stone Group Lawyers, respects your privacy and is committed to protecting the personal information we collect, use, hold and disclose.
This Privacy Policy explains how we handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles, our professional obligations as legal practitioners, and, where applicable, our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
What information we collect
We may collect personal information about you, including your name, address, date of birth, contact details, occupation, identity documents, signature, bank account details, billing information, matter information, communications with us, and information necessary to provide legal services.
Where required for legal services, client onboarding, verification of identity, conveyancing, electronic lodgement, trust account, or AML/CTF purposes, we may also collect information about your directors, shareholders, trustees, beneficiaries, appointors, beneficial owners, controllers, agents, related entities, source of funds, source of wealth, transaction purpose and related parties.
We may also collect sensitive information where reasonably necessary or where required or authorised by law. This may include information about professional or trade association membership, political exposure, sanctions status, criminal history, health information, biometric information used for identity verification, or other information relevant to the legal services we provide.
How we collect information
We may collect personal information directly from you, from your representatives, from other parties involved in your matter, from public registers, from government bodies, from courts and tribunals, from electronic conveyancing or verification platforms, from search providers, from credit reporting bodies where permitted, and from third-party verification or AML/CTF service providers.
We may collect information when you contact us, complete an enquiry form, instruct us, provide documents, attend our office, communicate with us by email or telephone, use our website, engage with our social media, or participate in client onboarding or verification processes.
Where we use electronic identity verification or AML/CTF verification providers, we may ask you to provide information through a secure third-party platform.
Why we collect, use and disclose information
We collect, use and disclose personal information for purposes including:
(a) providing legal services;
(b) opening, managing and closing client files;
(c) identifying and verifying clients and persons connected with clients;
(d) conducting conflict checks;
(e) complying with verification of identity, electronic conveyancing, trust accounting, costs disclosure and legal profession requirements;
(f) complying with AML/CTF obligations, including customer due diligence, ongoing customer due diligence, risk assessment, source of funds and source of wealth enquiries, sanctions and politically exposed person checks, and reporting obligations;
(g) communicating with you and others involved in your matter;
(h) billing, debt recovery, accounting and administration;
(i) managing professional risk, insurance, audits, complaints and regulatory obligations;
(j) improving our services, systems and client experience;
(k) sending legal updates, invitations and information about our services, unless you ask us not to; and
(l) any other purpose required or authorised by law.
AML/CTF obligations and client due diligence
From 1 July 2026, Australian legal practices providing certain designated services may be required to comply with obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth).
Where those obligations apply, we may be required to collect and verify information about you, your organisation, persons acting on your behalf, beneficial owners, controllers, politically exposed persons, sanctions status, the nature and purpose of your matter, source of funds, source of wealth and the transaction or arrangement involved.
If you do not provide information requested by us, or if we cannot verify that information to our satisfaction, we may be unable to act, continue acting, receive or disburse funds, complete a transaction, or provide the requested legal services.
We may also be required to make reports to AUSTRAC or another government agency. In some circumstances, we may be prohibited by law from telling you that a report has been made.
Nothing in this Privacy Policy limits our professional obligations, including our duties of confidentiality and legal professional privilege. However, there may be circumstances where we are required or authorised by law to disclose information.
Who we may disclose information to
We may disclose personal information to:
(a) courts, tribunals, regulators and government agencies;
(b) AUSTRAC and law enforcement agencies where required or authorised by law;
(c) barristers, experts, consultants, investigators, valuers, accountants, financial advisers, migration agents or other professional advisers involved in your matter;
(d) other parties, solicitors, agents, brokers, financiers, insurers and representatives involved in your matter;
(e) electronic conveyancing, property, company, PPSR, title, search, identity verification, AML/CTF, sanctions, politically exposed person, document management, cloud storage, billing, payment processing and practice management service providers;
(f) our insurers, auditors, external advisers and professional regulators;
(g) debt collection agencies or credit reporting bodies where permitted by law;
(h) third parties involved in a restructure, merger, sale or transfer of our business or practice; and
(i) any other person or entity where you have consented or where disclosure is required or authorised by law.
We take reasonable steps to ensure that third-party service providers handle personal information appropriately and only use it for the purpose for which it is provided.
Overseas disclosure and cloud storage
We primarily store and manage information using secure electronic systems. Some service providers may store, process or support data from locations outside Australia.
Where personal information is disclosed to or accessed by an overseas recipient, we will take reasonable steps to ensure that the recipient handles the information consistently with the Australian Privacy Principles, unless an exception under the Privacy Act applies.
Website, cookies and analytics
When you use our website, we may collect technical information including your IP address, browser type, device information, operating system, pages visited, time spent on pages, referral source and similar website usage information.
Our website may use cookies and analytics tools to improve functionality, measure traffic, understand user behaviour and improve our services. You can disable cookies through your browser settings, although some website features may not operate properly.
Security and storage
We take reasonable steps to protect personal information from misuse, interference, loss, unauthorised access, modification and disclosure.
Those steps may include physical security, secure electronic storage, access controls, password protection, encryption, staff training, confidentiality obligations, data backup, malware protection and secure document transfer systems.
No method of electronic transmission or storage is completely secure. If you send information to us electronically, you do so at your own risk.
Retention of information
We retain personal information for as long as reasonably necessary for the purpose for which it was collected and to comply with our legal, professional, insurance, regulatory and record-keeping obligations.
Where AML/CTF record-keeping obligations apply, we may be required to retain certain client due diligence and transaction records for seven years after the relevant business relationship ends or the transaction is completed.
When information is no longer required, we may take reasonable steps to destroy, delete or de-identify it.
Access and correction
You may request access to personal information we hold about you. You may also ask us to correct personal information you believe is inaccurate, out of date, incomplete, irrelevant or misleading.
We may need to verify your identity before responding. We may refuse access or correction where permitted by law, including where access would prejudice legal proceedings, reveal confidential information, affect legal professional privilege, breach another person’s privacy, or be unlawful.
Marketing communications
We may use your contact details to send legal updates, invitations and information about our services. You may opt out at any time by contacting us or using any unsubscribe function provided. We may use your name, contact details and information about your relationship with us to send you legal updates, invitations, publications and information about our services that may be of interest to you. You may opt out of receiving marketing communications at any time by contacting us or by using any unsubscribe function provided in the relevant communication.
Referrals to Other Professionals
If we are unable to assist you, or if we consider another professional is better suited to assist you, we may refer you to another solicitor, barrister, accountant, financial adviser, broker, consultant or other professional adviser.
By making an enquiry with us or engaging us, you consent to us providing your name, contact details and a general description of your enquiry or matter to that professional for the purpose of facilitating that referral.
We will only disclose information that is reasonably necessary to enable the referral and will not disclose detailed confidential information unless authorised by you or otherwise permitted or required by law.
We may refer you to, or introduce you to, other professional advisers, including solicitors, barristers, accountants, financial advisers, brokers, valuers, engineers, consultants, insolvency practitioners and other specialists who we believe may be able to assist you. We may disclose your contact details and a general description of your enquiry or matter for that purpose. Those professionals are independent businesses and we do not accept responsibility for their advice or services.
Complaints
If you have a concern about how we have handled your personal information, please contact us in writing.
We will consider your complaint and respond within a reasonable time. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner.
Contact details
Privacy Officer
Stone Group Lawyers
Email: admin@stonegroup.com.au
Phone: 1300 088 440
Gold Coast Office: Suite 31106, Level 11, Southport Central Commercial Tower 3, 9 Lawson Street, Southport QLD 4215
Brisbane Office: Level 12, 179 North Quay, Brisbane City QLD 4000
Fraser Coast Office: Unit 19, 58–60 Torquay Road, Pialba QLD 4655
AML/CTF PRIVACY COLLECTION NOTICE
This notice explains how Stone Group Lawyers collects personal information for client due diligence, verification of identity and anti-money laundering and counter-terrorism financing compliance purposes.
Why we collect your information
We may collect your personal information to comply with our obligations under the Anti-Money Laundering and Counter-Terrorism Financing Act 2006 (Cth), including to:
(a) establish and verify your identity;
(b) establish and verify the identity of any person you act for or who acts on your behalf;
(c) identify and verify beneficial owners and controllers of companies, trusts, partnerships and other entities;
(d) understand the nature and purpose of your matter or transaction;
(e) assess and manage money laundering, terrorism financing, proliferation financing, sanctions and related compliance risks;
(f) verify source of funds and source of wealth where required;
(g) conduct ongoing customer due diligence; and
(h) meet reporting and record-keeping obligations.
What information we may collect
Depending on the matter, we may collect:
(a) your full name, date of birth, residential address and contact details;
(b) copies or details of identity documents, including passports, driver licences, Medicare cards or other identification documents;
(c) photographs, biometric information or electronic verification information where required for identity verification;
(d) information about your occupation, employer, business activities and source of funds;
(e) information about source of wealth;
(f) information about whether you or a connected person is a politically exposed person or subject to sanctions;
(g) company, trust, partnership or entity information;
(h) details of directors, shareholders, trustees, beneficiaries, appointors, partners, members, beneficial owners, controllers, agents and authorised representatives; and
(i) information about the transaction, legal service, asset, property, funds or arrangement involved.
How we collect your information
We may collect your information directly from you, from your authorised representatives, from public registers, from government records, from third-party verification providers, from electronic conveyancing or search platforms, from credit reporting bodies where permitted, from other professional advisers, or from other sources reasonably necessary for AML/CTF compliance.
We may ask you to complete electronic verification through a secure third-party provider.
Who we may share your information with
We may share your information with:
(a) identity verification providers;
(b) AML/CTF, sanctions, politically exposed person and beneficial ownership search providers;
(c) electronic conveyancing and property transaction platforms;
(d) government agencies, regulators and law enforcement bodies;
(e) AUSTRAC, where required or authorised by law;
(f) our insurers, auditors, professional advisers and regulators; and
(g) other persons where disclosure is required or authorised by law.
We may be prohibited from telling you if certain reports or disclosures are made.
What happens if you do not provide the information
If you do not provide requested information, or if we cannot verify information to our satisfaction, we may be unable to act for you, continue acting, receive or disburse funds, complete a transaction, or provide the legal services requested.
Your privacy rights
Our Privacy Policy explains how we handle personal information, how you may request access to or correction of your personal information, and how to make a complaint.
Contact
Privacy Officer
Stone Group Lawyers
Email: admin@stonegroup.com.au
Phone: 1300 088 440
Personal Information
This Privacy Policy covers your personal information. Personal information is information or an opinion, whether true or not, and whether recorded in a material form or not, about an identified individual, or an individual who is reasonably identifiable. All personal information received in connection to your matter is subject to strict rules of confidentiality and legal professional privilege. Personal information will not be disclosed unless disclosure is authorised by our client or in accordance with our professional obligations as contemplated by this Privacy Policy.
Common examples include your name, signature, address, telephone number, date of birth, medical records, bank account details, billing and credit card details, photos of you and commentary or opinion about you.
We may collect some or all of the following types of personal information:
By agreeing to this Privacy Policy, you consent to the fact that you are aware that we are collecting your personal information and disclosing it as required by us and in accordance with the Privacy Act 1998 (Cth) and any applicable Australian Privacy Principles.
Information That You Give Us
We may collect your personal information directly from our contact with you. This may include by you completing forms on our website (www.stonegroup.com.au), or by you contacting us via email, telephone, through social media and other similar functions either directly through our site or through third-party host sites, in person, through various marketing channels or competitions either directly through our site or through third-party host sites, and surveys.
You understand that any personal information that you provide to use must be accurate and up to date. We will assume this to be the case. Your failure to comply with this obligation may impact on our ability to provide you with our services.
Information That We Collect About You
Our website may automatically collect the following information about you each time you visit our website:
Sensitive Information
Throughout the course of collecting your personal information, we may collect sensitive information about you. Sensitive information includes:
If we do collect any of your sensitive information, we will only collect it in accordance with Principle 3.3 of the Australian Privacy Principles. This means that we will only collect this information with your consent and for reasons that are reasonably necessary or otherwise related to the provision of our services.
Where you consent to our collection of your sensitive information, you also consent to us using that sensitive information for the purpose/s for which it was collected, including its disclosure to third parties.
We may be required to disclose your personal information for the purposes for which it was collected and also subject to our professional obligations:
To be clear, you consent to our disclosure of your personal information to any of our business partners, supplies, sub-contractors or the like, advertisers and other advertising networks, analytics and search engine providers and other third parties provided the disclosure of your personal information is for the purpose or ancillary to the services that we or these third parties offer you and for the purposes the information was originally collected.
You understand that we are authorised to disclose your personal information to third parties in the event that we buy or sell any business or assets, including our business, if we are under a duty to disclose your information, or if the disclosure of your personal information is necessary for us to conduct an investigation into any unlawful activity that we know or suspect has or may be engaged in.
You consent to the disclosure of your personal information to overseas recipients, and warrant that you are aware that an overseas recipient of your personal information is not required to comply with the Privacy Act 1998 (Cth) or the Australian Privacy Principles. Please notify us immediately if you have any objections to us providing your personal information to any overseas recipient.
We will take all reasonable steps to ensure that any overseas recipient of your personal information does not willingly or knowingly breach the Australian Privacy Policy in relation to your personal information.
We will only keep your information for as long as reasonably necessary to fulfil the purposes for which your personal information was originally collected.
We will delete your information after a reasonable time. You may be required to re-enter your personal information if it has been deleted.
You agree and acknowledge that your personal information may be stored at or transferred within Australia or a destination outside of Australia. This will allow staff operating outside of Australia (whether employed by us or by a third-party engaged by us or otherwise authorised under this Privacy Policy to access your personal information) to process your information for the purposes of providing you with our services.
We will take all reasonable steps and precautions to ensure that any transmission of your personal information via the internet is secure. However, we cannot guarantee the security of any data transmitted to our site and you agree and acknowledge that any such transmissions are at your own risk.
Once we receive your information, we take reasonable steps to protect your personal information. This may include storing any information on a secure server and employing strict procedures and security features to protect your personal information from any unauthorised recipients and to prevent unauthorised access to the same. We may also store your personal information in physical form.
All our employees with access to your information will be held to the confidentiality obligations as set out in this Privacy Policy.
Our website uses “cookies”. Cookies are small pieces of data sent from a website and stored in your web browser. These pieces of data will allow our website to remember who you are and to obtain information from you which allows us to deliver you a better and more customised service. As a result of our website’s use of cookies, we may collect information such as your IP address, online activity and your web browser details. Information that we will not collect or store include your passwords or other sensitive information.
If you enabled cookies when accessing our website, we will take this as consent to our use of cookies and other technologies mentioned in our Privacy Policy.
Please note that you should also refer to our website’s Terms of Use for further information on this issue.
You have the right to request access to the personal information we hold about you by contacting us or our Privacy Officer in writing.
If we cannot provide you with access, we will write to you and provide you with the reasons why we are unable to provide you with access.
If any personal information that we hold about you is inaccurate, incomplete or not up to date, you may write to us or our Privacy Officer and request that we correct the information at the above address.
You have the right to request that we do not disclose your personal information (for example, for marketing purposes). You can exercise your rights by unchecking the relevant check boxes on our website when you provide us with your personal information, or by writing to us at the above address.
You may choose to opt out of receiving any further correspondence from us by writing to us at the above address or emailing us at admin@stonegroup.com.au.
If you are concerned about a possible interference with your privacy or about the potential misuse of your personal information, please contact us or our Privacy Officer in any of the following ways:
We take all complaints very seriously. It is our policy to handle complaints in a timely, effective, fair and consistent manner. If you are not satisfied with our response, you have the right to refer your complaint to the Office of the Australian Information Commissioner.
This Privacy Policy was last updated in December 2016.
We reserve the right to make changes to this Privacy Policy at any time. We encourage you to regularly review this Privacy Policy to make sure you are aware of any changes and how your information may be used.
Ⓒ 2026 Stone Group Lawyers | Site By Merge

