BAY CITY GROUP
Privacy Policy
Who we are
In this policy, “Bay City Group”, “we”, “us” and “our” refer collectively to the following businesses, and individually to the business handling your information:
Bay City Conveyancing Specialists Pty Ltd ACN 628 320 972 Trading name Bay City Conveyancing (BCC)
Bay City Conveyancing & Legal Pty Ltd ACN 097 296 681 Trading name Bay City Legal Property Law (BCL)
Bay City Group is a collective description, not a separate legal entity. Your engagement documents identify the business acting for you. Each business remains responsible for its own handling of personal information.
Our commitment and scope
This policy explains how we handle personal information in providing legal and conveyancing services, administering our businesses and meeting our legal obligations. Personal information means information or an opinion about an identified or reasonably identifiable individual.
We comply with the Privacy Act 1988 (Cth) and Australian Privacy Principles where they apply, including to our anti-money laundering and counter-terrorism financing (AML/CTF) activities. We also comply with applicable tax file number rules, the Health Records Act 2001 (Vic), and our professional confidentiality obligations. This policy does not authorise disclosure of legally privileged information.
What information we collect
We collect information reasonably necessary for our services and obligations. Depending on the matter, this may include:
names, dates of birth, addresses, contact details, occupation, identity documents and verification results;
property, transaction, financial, banking and tax details, including source of funds and wealth where relevant;
company, trust and superannuation information, beneficial ownership, authority to act, and relevant sanctions, political exposure and adverse-media screening results;
instructions, correspondence, file notes and information about other people involved in a matter; and
website usage information, such as IP address, browser and pages visited, collected through server logs and cookies.
We collect sensitive information, such as relevant health or criminal-record information or biometric identity-verification information, only where reasonably necessary and with consent or another lawful basis. Tax file numbers are subject to the additional restrictions below.
How we collect information
We usually collect information directly from you through meetings, correspondence, forms and identity checks. Where lawful, we may also obtain it from your representatives, other parties and their advisers, public registers, government bodies, search and verification providers, and publicly available sources.
We give collection notices where required. If a credit reporting body is used to verify identity, we obtain the express consent and offer the alternative verification method required by law. You may make a general enquiry anonymously where practicable, but we ordinarily need to identify clients. Without necessary information, we may be unable to act or continue acting.
Why we use and disclose information
We use information to provide and administer our services, communicate with you, complete transactions, verify identity and authority, manage accounts and complaints, and comply with legal and professional requirements. These include the AML/CTF Act and Rules, taxation and duties laws, and applicable conveyancing and record-keeping requirements.
For these purposes, and subject to confidentiality, privilege and applicable law, we may disclose relevant information to:
your authorised representatives, other parties and their lawyers or conveyancers, lenders, agents and other professionals involved in your matter;
government and regulatory bodies, including AUSTRAC, the Australian Taxation Office, State Revenue Office, land registries, councils, courts and tribunals;
service providers supporting our work, including triSearch, InfoTrack, electronic settlement and identity-verification providers, and IT, communications, cloud-storage and document-service providers; and
our insurers, auditors and professional advisers where reasonably necessary and lawfully permitted.
Information may be shared between our businesses where reasonably necessary to provide services, support shared administration or meet legal obligations, and only where permitted by law and our confidentiality duties. The group name does not itself authorise unrestricted sharing.
Otherwise, we use or disclose information for the purpose for which it was collected, a related purpose you would reasonably expect (directly related for sensitive information), with your consent, or as otherwise required or authorised by law. Any marketing communications must comply with applicable law and you may opt out.
We may have to provide information to AUSTRAC or another authority without your consent. The law may prevent us from telling you about a report or disclosure, giving reasons, or providing particular information. We will not disclose information in breach of legal professional privilege.
Tax file numbers
We may collect tax file numbers through our questionnaire or an ATO form completed by you, to prepare a foreign resident capital gains withholding clearance-certificate application or provide authorised data-entry and transmission assistance. We handle tax file numbers only as permitted by taxation law, including the Taxation Administration Act 1953 (Cth). Individuals’ tax file numbers are also protected by the Privacy (Tax File Number) Rule 2015.
Providing a tax file number for a clearance-certificate application is voluntary and refusal is not an offence. It helps the ATO identify you and process the application; an application can be made without it. We explain the purpose and any consequences when requesting it.
We use and disclose tax file numbers only for permitted purposes, restrict access to people who need them for those purposes, and do not use them as general client or AML identifiers. We take reasonable steps to securely destroy or permanently de-identify tax file number information once no longer lawfully required or necessary for a permitted purpose.
How we protect and retain information
We hold information in electronic systems and paper files, including systems operated by service providers. We take reasonable physical, organisational and technical steps to protect it against loss, misuse, interference and unauthorised access, modification or disclosure. These steps include appropriate access restrictions, staff instruction and secure storage. We take reasonable steps to ensure service providers protect information entrusted to them.[DR1]
We retain records for the periods required by law, including applicable seven-year AML/CTF and conveyancing retention periods. Once information is no longer needed for a lawful purpose and retention is not legally required, we take reasonable steps to securely destroy or de-identify it. Retention periods depend on the type of record and the applicable legal requirement.
Data breaches
We assess suspected data breaches promptly and notify the OAIC and affected individuals where the Notifiable Data Breaches scheme requires this, including for eligible breaches involving individuals’ tax file numbers.
Accessing and correcting your information
You may ask our Privacy Officer to access or correct personal information we hold about you. We may first verify your identity and clarify your request. We aim to respond within 30 days, subject to any different period required by law.
We take reasonable steps to ensure information is accurate, current, complete and relevant. Where required, we will correct it, notify relevant recipients of a correction on request, or associate a statement of your requested correction with the record if we do not agree to amend it.
Access or correction may be limited where permitted or required by law, including to protect another person’s privacy, legal privilege, an investigation or compliance with AML/CTF restrictions. If we refuse a request, we give written reasons and explain complaint options to the extent required and permitted by law. We do not charge for making a request or correcting information. A reasonable access charge may apply where permitted, which we will explain beforehand.
Privacy enquiries and complaints
Please contact our Privacy Officer if you have a concern about how either business handles your information. Tell us what happened and the outcome you seek. We will acknowledge your complaint promptly, investigate it, and aim to provide a written response within 30 days. If more time is needed, we will explain why and keep you informed.
If you are dissatisfied with our response, or we have not resolved your complaint within 30 days, you may complain to the Office of the Australian Information Commissioner (OAIC) where the matter is within its jurisdiction. Complaints concerning health information may be made to the Victorian Health Complaints Commissioner.
OAIC: oaic.gov.au/privacy/privacy-complaints | 1300 363 992
Health Complaints Commissioner: hcc.vic.gov.au | 1300 582 113
Contact us
Privacy Officer
BCC – Toni Blackwell
Email: info@bayconvey.com.au (attention: Privacy Officer)
Telephone: 03 5221 9805
Post: Privacy Officer, Bay City Group, 13 Star Street, Geelong VIC 3220
BCL – Nick Spanninga
Email: nick@baycitylegal.com.au (attention: Privacy Officer)
Telephone: 03 5221 9805
Post: Privacy Officer, Bay City Group, 13 Star Street, Geelong VIC 3220
Availability and updates
This policy is available free of charge on our websites and on request. Please contact us if you need it in another form. We review it when our information-handling practices or legal obligations change, and publish the current version on our websites.
Website hosting and cookies
Our Bay City Conveyancing website is hosted by Squarespace. Squarespace collects visitors’ IP addresses, browser and device information, referring pages and pages visited to operate, secure and improve its platform and services. The website uses cookies and similar technologies for essential functions and, where enabled, website analytics.
Squarespace may process website information overseas, including in the United States. Further information is available in Squarespace’s Privacy Policy at https://www.squarespace.com/privacy.