Privacy Policy

 

PRIVACY POLICY
Foundd Legal Pty Ltd
Effective Date: 1 January 2026

INTRO

Who we are and how you can contact us

We are Foundd Legal Pty Ltd (ABN 41 162 433 294) trading as Foundd Legal (“Foundd Legal”, “we”, “us” and “our”), an incorporated legal practice based in Queensland, Australia.

We are committed to protecting the privacy of our clients, customers, suppliers and team. This Privacy Policy applies across everything we do, our legal services, our trade mark work, our templates and digital products, our programs and events, our website founddlegal.com (Site) and our social media channels. It explains how we collect, hold, use and disclose personal information, and it forms part of our Website Terms & Conditions.

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). Businesses under the $3 million turnover threshold are currently largely exempt from the Privacy Act. We do not rely on that exemption. We spend our working lives telling other businesses to take this seriously, so we hold ourselves to the full APP standard whether or not the law compels us to, including the data breach notification standard described below.

This Privacy Policy does not cover information you submit on other platforms, even where we communicate with you there. Anything you post on Instagram, Facebook, Pinterest, X, TikTok, LinkedIn or YouTube is governed by that platform’s own privacy policy, not this one.

Privacy contact. Our Privacy Officer can be reached at heyteam@founddlegal.com, or use the contact form on our Site. Send any privacy question, request or complaint there and it will get to the right person.

Our role and your responsibilities

This Privacy Policy applies to you if you are a client, customer, subscriber, supplier, event attendee or visitor to our Site. As the provider of the services and products offered here, we decide how and why personal information is handled. We do not sell or rent your details to anyone, and we do not disclose your personal information to third parties for their own marketing purposes.

Please read this Privacy Policy together with our Website Terms & Conditions. If you give us information about another person, a business partner, a co-founder, a contractor, a team member, you confirm you are authorised to do so and that they have been made aware of this Privacy Policy.

When and how we collect information

Sometimes you give us information directly. Sometimes we collect it automatically. We may collect personal information when you:

•     book a call with us;

•     send us an enquiry, email or direct message, or complete a contact form;

•     complete a client questionnaire, intake form, trade mark questionnaire or onboarding form;

•     instruct us on a matter, and we open a file and run a conflict check;

•     buy a template, kit, program or other digital product from our Site;

•     subscribe to our newsletter, download a free resource, or enter a giveaway or promotion;

•     attend a webinar, workshop, podcast recording or other event we run;

•     apply to work with us, or supply goods or services to us; or

•     browse our Site and accept cookies and similar technologies.

We also collect personal information indirectly, for example from public registers such as the trade marks register and ASIC, from your team members or advisers, and from the platforms we use to run our business.

The information we collect

Depending on how you deal with us, we may collect:

•     Contact and identity details: name, business name, postal and email address, phone number.

•     Business information: ABN/ACN, entity structure, trading names, brand assets and details of your products and services.

•     Matter information: the facts, documents, correspondence and circumstances relevant to the matter you instruct us on.

•     Payment information:  billing details and transaction records. We do not store full payment card numbers (see “Payment security”).

•     Purchase and engagement data: what you have bought, downloaded or attended, and how you have used it.

•     Technical data:  IP address, device and browser type, operating system, time zone, geolocation and login details.

•     Site usage data: pages viewed, links clicked, time on page, form engagement and other actions.

•     Recruitment and supplier data: if you apply to work with us or supply us, your qualifications, skills, experience, references, products, services and pricing.

Sensitive information. Some of what you tell us in a legal matter may be sensitive information under the Privacy Act,  for example health information, information about a dispute involving those things. We collect sensitive information only where it is reasonably necessary for the matter and you have consented, or where the law requires or authorises it. You do not need to tell us anything sensitive that is not relevant to the work you have asked us to do.

How we use and disclose your information

We use your information for the purpose we collected it and for related purposes you would reasonably expect, including to:

•     provide legal services, trade mark services, templates, programs and events;

•     run conflict checks, open and manage files, and meet our professional obligations as a law practice;

•     take payment, issue invoices and keep the financial records we are required to keep;

•     provide customer support and handle questions, feedback and complaints;

•     operate, secure and improve our Site and our services;

•     seek feedback and carry out market research;

•     send you marketing about our products, services and events, with your consent; and

•     comply with our legal, regulatory and professional obligations.

We may disclose your information:

•     to the service providers and platforms we use to run our business (see “Who we share information with”);

•     to third parties necessary to deliver what you have asked for, for example IP Australia when we file a trade mark application on your behalf;

•     to our professional advisers, insurers and auditors;

•     to courts, tribunals, regulators and law enforcement, where required or authorised by law;

•     to a buyer or potential buyer if we ever sell all or part of our business, subject to appropriate confidentiality arrangements; and

•     with your consent.

Confidentiality and legal professional privilege. If you are a client, your information is also protected by our duty of confidentiality and, where it applies, legal professional privilege. Those duties sit alongside this Privacy Policy and, in places, go further than it does. Where they conflict, the stricter obligation applies.

How we use AI

We use artificial intelligence tools in parts of our business. We think you should know exactly where, so here it is.

•     Call recordings and transcripts:  we record and transcribe some calls so we can prepare accurate notes and follow-up correspondence. We tell you at the start of the call, and we do not record without your agreement. If you would rather we did not, say so and we will take notes the old-fashioned way.

•     Our website chat and enquiry tools:  some of the chat, enquiry and intake features on our Site are AI-powered. They help us understand and route what you have asked us. Anything they generate is produced automatically, may contain errors, and is general information only,  it is never legal advice, and you should not act on it without speaking to us. A person reads every enquiry that reaches us.

•     Marketing and content:  we use AI features inside our email, design, scheduling and analytics platforms to help us segment audiences, plan and produce content, and understand what is working.

•     What AI does not do:  AI does not do our legal work and it does not decide anything about you. Every document, every piece of advice and all matter correspondence is prepared and reviewed by a lawyer, and we remain fully responsible for it.

•     We choose tools that do not train on your information:  we use business, enterprise or API tiers configured so material we input is not used to train the provider’s models, and we have confidentiality and data protection arrangements with those providers.

•     What we do not do:  we do not put client or matter information into free, public or consumer generative AI tools, and we do not use your personal information to train our own models or anyone else’s.

If you would prefer we did not use AI-assisted tools in your dealings with us, tell us and we will talk it through with you.

Automated decisions

We use tools that automatically analyse personal information and act on the result. Here is where, and what happens:

·        Advertising and audience targeting:  we run Google Analytics and the Meta pixel on our Site. These tools build profiles from your browsing and purchasing behaviour, group you into audiences, and generate predictions about how likely you are to buy or to disengage. We use those profiles and predictions to decide who sees our advertising, who is excluded from it, and which marketing you receive. Those are automated decisions about you, made using your personal information, and we make them.

·        Fraud and risk screening on payments and orders: our payment and ecommerce providers automatically assess transactions for fraud risk. That assessment can result in your payment or order being declined or held for review.

·        Email segmentation and timing: our email platform automatically groups subscribers, estimates engagement and selects send times, which affects what marketing you receive and when.

None of these decides whether we act for you, what we charge you, or anything about the conduct or outcome of your matter. A person makes every one of those decisions, and no automated tool contributes to them.

You can switch the advertising and analytics profiling off. Opt out of marketing at any time using the unsubscribe link or by emailing us, manage cookies through your browser settings, use Google's opt-out tools, and change how Meta personalises ads for you in your Facebook ad preferences. If you would rather we did not profile you at all, email heyteam@founddlegal.com and we will suppress you from our audiences and advertising lists.

If an automated process has affected you,  a declined payment, an order held for review, or anything else you want looked at email heyteam@founddlegal.com. A person will review it, we will tell you what we are able to about why it happened, and we will explain your options. We do not treat an automated output as the final word.

If we begin using automated tools to decide something that significantly affects you, we will update this Privacy Policy to describe the kinds of personal information used and the kinds of decisions made, and you will be able to ask for a human review of that decision.

Analytics, tracking and de-identified data

We use analytics and event-based measurement tools to understand how people find and use our Site, pages visited, navigation paths, time on page, content interaction, form engagement and conversions. We use this to spot friction, improve our Site and make our content more useful.

Where it is reasonably practicable, we de-identify or aggregate personal information before using it for analytics, reporting or research. De-identified and aggregated data does not reasonably identify anyone, and we take reasonable steps to minimise the risk of re-identification.

Google. We use Google Analytics, which may include display advertising and remarketing,  meaning you may see our ads across the internet based on your past visits to our Site. You can read how Google collects and processes data at policies.google.com/technologies/partner-sites, and you can opt out using the browser opt-out tools Google provides.

Meta. We use Meta’s insights, analytics and pixel technologies to understand how you interact with our Facebook Page, our Facebook Group and our Instagram content, and to measure our advertising. Meta handles some of that information for its own purposes as well as ours. You can read Meta’s privacy policy at facebook.com/policy.php and change how Meta personalises ads for you in your Facebook ad preferences.

Cookies and tracking technologies

Cookies are small data files placed on your device, usually with an anonymous unique identifier. They are not the edible kind, and they do not harm your device. We use cookies and similar technologies to make the Site work, to analyse traffic, and to support advertising and marketing.

You can block or delete cookies through your browser settings, allaboutcookies.org explains how. If you block all cookies you can still browse our Site, but some features may not work as well.

We may also use web beacons in our emails to see whether an email was opened and which links were clicked, along with your IP address and email client. We use this to improve our emails. You can unsubscribe at any time using the link in any marketing email.

Marketing

Before we collect your information we will tell you what we intend to use it for, and if that includes marketing we will get your consent. You can withdraw that consent at any time.

Our marketing emails always identify us as the sender and include a working unsubscribe link, consistent with the Spam Act 2003 (Cth). You can opt out at any time by clicking unsubscribe in any marketing email, or by emailing heyteam@founddlegal.com. We action opt-outs promptly and in any event within five business days.

Opting out of marketing does not stop essential messages about a matter, a purchase or your account,  those are not marketing.

Dealing with us anonymously

You can choose not to give us personal information. If you do, you can still browse our Site, but we will not be able to provide services or products that require it. Where it is lawful and practicable, a general question about how something works, for example,  you can deal with us anonymously or under a pseudonym. We cannot act for you on a legal matter anonymously, because we need to know who our client is in order to run a conflict check and meet our professional obligations as a law practice.

Your rights

You can exercise any of these rights at any time by emailing heyteam@founddlegal.com or using the contact form on our Site. We may need to verify your identity before we act on a request.

•     Access: you can ask for a copy of the personal information we hold about you. We will respond within 30 days. In limited cases the Privacy Act lets us refuse, for example where giving access would unreasonably affect someone else’s privacy, or where the information is subject to legal professional privilege or relates to anticipated legal proceedings. If we refuse, we will tell you why and how to complain.

•     Correction: you can ask us to correct information that is inaccurate, out of date, incomplete or misleading.

•     Deletion: you can ask us to delete the personal information we hold about you, and we will do so unless we are required or authorised to keep it. Australian law does not give a general “right to be forgotten”, and as a law practice we have real retention obligations, so we will be straight with you about what we can and cannot delete (see “How long we keep information”).

•     Portability: where it is technically feasible, you can ask us to provide the personal information you gave us in a structured, commonly used, machine-readable format.

•     Marketing and profiling: you can opt out of marketing at any time. We may analyse your information to make our communications more relevant, and you can ask us to stop.

•     Complaints: see below.

Complaints

If you are unhappy with how we have handled your personal information, please tell us first, email heyteam@founddlegal.com and we will acknowledge your complaint and respond within a reasonable time, usually 30 days.

If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au. If your complaint is about our conduct as a law practice, you can also contact the Legal Services Commission (Qld) at lsc.qld.gov.au.

Since 10 June 2025, Australian law has also allowed individuals to bring a court action for a serious invasion of privacy in certain circumstances. Nothing in this Privacy Policy limits that right.

How we protect your information

No system is perfect and we cannot guarantee the security of information sent over the internet. What we can tell you is what we actually do. We maintain reasonable physical, technical and organisational safeguards, including:

•     multi-factor authentication and password-protected access to our systems;

•     storing electronic data with reputable providers that maintain appropriate security protections;

•     limiting access to personal information to the people who need it to do their job;

•     confidentiality and data protection terms with our team and our service providers;

•     using PCI DSS compliant payment providers, so we never hold your full card details; and

•     a data breach response plan, which we review periodically.

Data breaches. If we suffer a data breach that is likely to result in serious harm, the Notifiable Data Breaches scheme requires us to notify the Office of the Australian Information Commissioner and affected individuals as soon as practicable, and we will. We will also tell you what happened, what information was involved and what you can do about it.

Who we share information with

We use third-party providers to run our business. They handle personal information on our instructions, under confidentiality and data protection arrangements, and they are not permitted to use it for their own purposes. The main ones are:

•     Shopify: our website and online store.

•     Stripe and PayPal: payment processing.

•     Microsoft 365: email, file storage, bookings, and video calls and their transcripts.

•     ClickUp: managing our work and matters.

•     Klaviyo: email marketing and our newsletter.

•     Google and Meta: analytics and advertising (see the sections above).

We also use a small number of other providers for accounting, design, scheduling and administration, and we use our professional advisers, insurers and auditors where we need to. Where we act for you on a trade mark, we deal with IP Australia on your behalf.

We review our providers at least once a year. If you would like to know exactly who handles a particular piece of your information, ask us and we will tell you.

Where your information is stored

Some of our providers are located, or store data, outside Australia, including in the United States, the European Union, the United Kingdom and Canada. That means your personal information may be stored or accessed overseas.

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure they handle it consistently with the Australian Privacy Principles, unless an exception under the Privacy Act applies. We choose providers that offer Australian or regional data residency where that option exists and it makes sense for the work.

How long we keep information

We keep personal information only as long as we need it, and as long as the law requires. In practice:

•     Client files: we retain client files and matter records for at least seven years after the matter ends, in line with our professional obligations as a law practice.

•     Financial and tax records:  at least five years, as required by Australian tax law.

•     Marketing lists:  until you unsubscribe, and then we keep a minimal suppression record so we do not email you again by mistake.

•     Site and analytics data: generally in de-identified or aggregated form, for as long as it is useful.

When we no longer need information and no legal obligation requires us to keep it, we securely destroy or de-identify it.

Payment security

Our Site runs on Shopify, which provides the ecommerce platform we use to sell our products and services. Card payments are handled by third-party payment gateways that comply with the Payment Card Industry Data Security Standard (PCI DSS). Payments are automated and encrypted, and your full card number is not visible to us. Transaction data is retained only as long as needed to complete and record the transaction, and to meet our tax and record-keeping obligations.

You can read Shopify’s terms at shopify.com/legal/terms and its privacy statement at shopify.com/legal/privacy.

Children

Our Site, products and services are for adults. We do not provide services to children, we do not market to them, and we do not knowingly collect personal information from anyone under 18. By using our Site you confirm you are at least 18. If we become aware that we have collected a child’s personal information, we will take reasonable steps to delete it.

Doxxing and misuse of information

Publishing or sharing someone else’s personal information online without their consent, commonly called doxxing is not allowed in our Facebook Group, our programs or anywhere else we host a community. It is also a criminal offence in Australia. If it happens, we will remove the content and may remove the person responsible.

Where we offer our products and services

Our legal services and trade mark services are offered to clients in Australia only.

Our templates, kits and other digital products are offered to customers in Australia and New Zealand.

We are an Australian company and we handle personal information under Australian law. If you are in New Zealand, the Privacy Act 2020 (NZ) also applies to us because we sell to customers there, and you can take a privacy complaint to the New Zealand Privacy Commissioner at privacy.org.nz as well as to the offices listed above.

We do not target or market to customers in the European Union or the United Kingdom and we do not offer our products or services there. If you are in the EU or UK and you contact us or buy from us anyway, we will handle your personal information in accordance with this Privacy Policy and Australian law.

Governing law and changes to this policy

This Privacy Policy and your use of our Site are governed by the laws of Queensland, Australia.

We may update this Privacy Policy from time to time to reflect changes in our practices, our systems or the law. The current version is always published on our Site with its Effective Date at the top, so you know it is the latest one. Where a change is material, we will take reasonable steps to let you know.

The end

If you have read this far, genuinely, well done. We wrote this to be readable rather than impressive, because a privacy policy nobody can understand is not really a privacy policy. If anything here is unclear, or you think we could explain it better, tell us at heyteam@founddlegal.com. We would like to know.