Privacy Policy

Papico Legal Consulting Pty Ltd ("we", "us", "our") respects your privacy and is committed to protecting the personal information we collect and hold about you.

This policy explains what personal information we collect through our website and in the course of our work, how we use and protect it, who we share it with, and how you can access, correct or complain about the way we handle it.

Last updated: 20 July 2026

1. The law we follow

We handle personal information in accordance with the Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs) set out in that Act.

As a legal practice, we are also bound by professional duties of confidentiality and, where it applies, legal professional privilege. Where we handle health information in the course of a matter, we also comply with the Health Records Act 2001 (Vic).

2. What personal information we collect

The personal information we collect depends on how you interact with us. It may include:

  • your name, email address, phone number and postal address;
  • the contents of any enquiry, message or document you send us;
  • information you choose to provide about your legal matter or situation; and
  • technical information collected automatically when you visit our website, such as your IP address, browser type, device information, the pages you view and how you interact with them (see section 5).

We only collect personal information that we reasonably need for the purposes described in this policy. We do not ask for sensitive information (such as health, racial or ethnic origin, or criminal record information) through our website contact forms. If a matter requires sensitive information, we will collect it directly from you with your consent or where we are otherwise permitted by law.

3. How we collect it

We collect personal information in a few ways:

  • Directly from you — when you complete a contact or enquiry form on our website, email us at francisco@papico.com.au, call us, or provide information during the course of a matter.
  • Through our website — our site is built and hosted on Webflow. When you submit a form, the details you enter are captured through Webflow and passed to us so we can respond to you.
  • Through our practice management system — we use Clio to manage enquiries, client relationships and matter files. Information you give us is stored and administered within Clio.
  • Automatically — through cookies and website analytics tools, as described in section 5.

Wherever it is reasonable and practicable, we collect personal information directly from you.

4. Why we use your information

We use personal information you provide through the website only to:

  • respond to your enquiry and get in touch with you;
  • assess whether and how we can assist you;
  • provide legal services and carry out your matter, if you become a client;
  • keep records and administer our practice; and
  • comply with our legal and professional obligations.

If you contact us but do not go on to become a client, we use your information only to respond to and follow up on that enquiry.

5. Cookies, analytics and website tracking

Our website uses cookies and third-party tools to understand how visitors use the site so we can improve it. Specifically:

  • Google Analytics 4 (GA4) — collects information such as pages visited, time on site, approximate location and device/browser details, to help us understand overall website traffic and usage patterns.
  • Microsoft Clarity — helps us see how visitors interact with our pages (for example, through aggregated click, scroll and session-interaction data and heatmaps) so we can improve the site's layout and usability.

These tools may set cookies on your device and process information about your visit. The information is generally used in an aggregated form and is not used by us to personally identify you.

You can control or disable cookies through your browser settings, and you can opt out of Google Analytics using Google's browser add-on at https://tools.google.com/dlpage/gaoptout. Disabling cookies may affect how parts of the website function.

6. We do not sell your information

We do not sell, rent or trade your personal information to anyone. We do not use the information you provide to us for unrelated commercial purposes.

7. Who we share your information with

We only disclose personal information where it is reasonably necessary for the purposes described in this policy. This may include:

  • Our service providers — including Webflow (website hosting), Clio (form and practice management), Google (analytics) and Microsoft (analytics), who process information on our behalf so we can operate our website and practice. We require our providers to handle personal information consistently with this policy and applicable privacy law.
  • Third parties involved in your matter — where you become a client and it is necessary to progress your matter (for example, courts, tribunals, other parties and their representatives, barristers, or experts), we disclose information as reasonably required, and consistently with our professional duties to you.
  • Where required or authorised by law — for example, in response to a court order, subpoena or a request from a regulator.

8. Disclosure of information overseas

Some of our service providers store or process information on servers located outside Australia. In particular, Webflow, Clio, Google and Microsoft are based in, and may process information in, the United States (and potentially other countries in which they operate).

Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure it is handled in a manner consistent with the Australian Privacy Principles.

9. How we keep your information secure

We take reasonable steps to protect personal information from misuse, interference and loss, and from unauthorised access, modification or disclosure. This includes using reputable service providers, restricting access to information to those who need it, and applying appropriate technical and organisational safeguards.

No method of transmitting or storing data is completely secure. While we work to protect your information, we cannot guarantee absolute security, and any information you send us over the internet is sent at your own risk.

10. Data breaches

If we become aware of a data breach that is likely to result in serious harm to any individual whose information we hold, we will respond in accordance with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth), including notifying affected individuals and the Office of the Australian Information Commissioner where required.

11. How long we keep your information

We keep personal information only for as long as we need it for the purposes described in this policy, or for as long as we are required to keep it by law or our professional obligations.

If you become a client, we are generally required to retain records relating to your matter for at least seven (7) years after the matter is finalised, and in some cases longer. Where we no longer need to hold your information, we take reasonable steps to destroy or de-identify it.

12. Accessing and correcting your information

You have the right to ask for access to the personal information we hold about you, and to ask us to correct it if it is inaccurate, out of date, incomplete or misleading.

To make a request, contact us using the details in section 15. We will respond within a reasonable time. There is no charge to make a request, although we may recover reasonable costs of providing access in some circumstances. If we are unable to give you access or make a correction, we will explain why in writing.

13. Dealing with us anonymously

Where it is lawful and practicable, you may deal with us anonymously or using a pseudonym — for example, when making a general enquiry. In most cases, however, we will need your contact details to be able to respond to you or to provide legal services.

14. Marketing

We use the contact details you provide to respond to your enquiry and to carry out your matter. We do not send marketing communications unless you have asked to receive them or would reasonably expect them, and you can opt out at any time by contacting us or using the unsubscribe option in any such message.

15. Contact us and making a complaint

Francisco Droguett Arias, Firm Principal, is responsible for privacy matters at Papico Legal. If you have any questions about this policy, wish to access or correct your information, or want to make a complaint about how we have handled your personal information, please contact:

Papico Legal Consulting Pty Ltd (Papico Legal)
Attn: Francisco Droguett Arias, Firm Principal
Seaford, VIC 3198
Email: francisco@papico.com.au

We will acknowledge your complaint and aim to resolve it as soon as reasonably possible. If you are not satisfied with our response, you may refer your complaint to the Office of the Australian Information Commissioner (OAIC):

Office of the Australian Information Commissioner
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Website: www.oaic.gov.au
Post: GPO Box 5218, Sydney NSW 2001

16. Changes to this policy

We may update this policy from time to time to reflect changes to our practices or the law. The current version will always be available on our website, and the "Last updated" date at the top shows when it was last revised.