Back to site

Privacy Policy

Last updated: 30 April 2026

1.Introduction

Cognitex Consulting (ABN: 75 591 665 747) (“Cognitex Consulting”, “we”, “us” or “our”) is committed to protecting the privacy of individuals whose personal information we collect, hold, use and disclose in the course of our business activities.

This Privacy Policy describes how Cognitex Consulting handles personal information in accordance with the Privacy Act 1988 (Cth) (“Privacy Act”) and the Australian Privacy Principles (“APPs”). It applies to all personal information collected by Cognitex Consulting whether in connection with the delivery of legal technology consulting services, business development activities, or our own internal operations.

Cognitex Consulting provides legal operations consulting, technology selection and implementation, and advisory services to law firms, in-house legal teams and ASX-listed companies across Australia. In the course of these activities, we may collect and handle personal information relating to clients, client personnel, prospective clients, contractors, and other individuals.

By engaging with Cognitex Consulting, providing us with your personal information, or using our services, you consent to the collection, use and disclosure of your personal information as described in this Privacy Policy.

2.Definitions

In this Privacy Policy, the following terms have the meanings set out below:

TermMeaning
AI ToolsArtificial intelligence software, platforms or features used internally by Cognitex Consulting in the delivery of services, including generative AI assistants, document analysis tools and legal technology platforms.
APPsThe Australian Privacy Principles set out in Schedule 1 of the Privacy Act.
Client DataPersonal information provided to Cognitex Consulting by or on behalf of a client in connection with a consulting engagement.
Cognitex ConsultingCognitex Consulting, including its principals, employees and subcontractors.
NDB SchemeThe Notifiable Data Breaches scheme established under Part IIIC of the Privacy Act.
Personal InformationInformation or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information or opinion is true or not, and whether recorded in a material form or not.
Privacy ActThe Privacy Act 1988 (Cth) as amended from time to time.
Sensitive InformationPersonal information including health information, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record, as defined in the Privacy Act.

3.Personal Information We Collect

3.1Types of Personal Information

Cognitex Consulting may collect the following types of personal information:

  • Identity information: names, job titles, employer details, professional qualifications and registration details.
  • Contact information: email addresses, telephone numbers, postal addresses and LinkedIn profiles.
  • Business information: organisational structure, internal legal operations data, technology environments and vendor relationships provided during consulting engagements.
  • Financial information: billing and invoicing details, bank account details for payment purposes.
  • Communications: correspondence, meeting notes, workshop outputs and feedback provided during engagements.
  • Technical information: device identifiers, IP addresses and usage data when you interact with our digital platforms or communications.

3.2Sensitive Information

Cognitex Consulting does not intentionally collect sensitive information. Where sensitive information is incidentally provided in the course of an engagement (for example, within client documents or during scope discussions), we will handle it with additional care and will not use it for any purpose other than the engagement for which it was provided, unless required by law.

3.3Anonymity

Where it is lawful and practicable to do so, we will offer individuals the option of not identifying themselves or of using a pseudonym when interacting with us. However, in most cases anonymity is not practicable given the nature of our consulting engagements and contractual relationships.

4.How We Collect Personal Information

4.1Collection Methods

Cognitex Consulting collects personal information in the following ways:

  • Directly from individuals during the course of client engagements, including through meetings, workshops, interviews, surveys and correspondence.
  • From client organisations when they provide us with contact details or internal data as part of an engagement.
  • From publicly available sources, including ASX announcements, company websites, LinkedIn and professional directories, when conducting business development research.
  • From referrals and introductions made by existing clients, professional contacts or industry networks.
  • Through our website, including via contact forms and email communications.

4.2Collection Notices

At or before the time of collection, Cognitex Consulting will take reasonable steps to notify individuals of the matters required under APP 5, including the purposes of collection, how we handle personal information, and how individuals can access and correct their information. This notice may be provided through this Privacy Policy, through engagement letters, or through other communications at the point of collection.

5.Purposes of Collection, Use and Disclosure

5.1Primary Purposes

Cognitex Consulting collects, holds, uses and discloses personal information for the following primary purposes:

  • Delivering legal technology consulting and advisory services to clients.
  • Managing client engagement relationships, including communications, billing and reporting.
  • Conducting business development activities, including preparing proposals and client profiles for prospective clients.
  • Complying with legal and regulatory obligations.
  • Managing our internal operations, including record-keeping, quality assurance and risk management.

5.2Secondary Purposes

Cognitex Consulting may also use personal information for secondary purposes that are directly related to the primary purpose of collection, where the individual would reasonably expect such use. This includes:

  • Sending service-related communications and updates relevant to an existing engagement.
  • Improving our service delivery and internal processes using anonymised or aggregated insights.
  • Providing references or case studies with appropriate consents.

5.3Direct Marketing

Cognitex Consulting may use personal information of existing clients and professional contacts to send relevant updates, thought leadership materials and information about our services, where the individual would reasonably expect to receive such communications or has provided consent. Each marketing communication will include an option to unsubscribe. We will honour all opt-out requests promptly.

Cognitex Consulting does not use or disclose personal information obtained from third parties for direct marketing without first obtaining consent.

6.Disclosure of Personal Information

6.1Third-Party Disclosure

Cognitex Consulting may disclose personal information to the following categories of third parties where necessary to deliver our services or comply with our obligations:

  • Subcontractors and specialist advisers engaged to assist with specific aspects of a client engagement, subject to confidentiality obligations equivalent to those in this policy.
  • Technology vendors and software providers used in the delivery of our services, including cloud platforms, document management systems and productivity tools.
  • Professional advisers including accountants, insurers and legal advisers acting for Cognitex Consulting.
  • Regulatory bodies or law enforcement agencies where disclosure is required by law or a court order.

6.2Overseas Disclosure

Some of the technology platforms and cloud services used by Cognitex Consulting are operated by entities outside Australia. Where personal information is disclosed to overseas recipients, Cognitex Consulting takes reasonable steps to ensure those recipients handle the information in a manner consistent with the APPs. By providing your personal information to Cognitex Consulting and agreeing to this Privacy Policy, you consent to such overseas disclosure where it cannot reasonably be avoided in the delivery of services.

6.3No Sale of Personal Information

Cognitex Consulting does not sell, rent or trade personal information to third parties for commercial purposes.

7.Use of AI Tools and Technology Platforms

7.1AI Tool Usage

Cognitex Consulting uses AI-assisted tools internally to support service delivery, research, document drafting and analysis. In accordance with guidance from the Office of the Australian Information Commissioner (OAIC), we have established the following practices governing our use of AI tools:

  • We assess AI tools for privacy and security risks prior to use on client engagements.
  • We avoid inputting identifiable personal information into AI systems where it is not necessary for the task.
  • We apply human oversight and review to all AI-generated outputs before they are relied upon or disclosed.
  • We maintain records of the AI tools used in the delivery of services.

7.2Transparency

Where Cognitex Consulting uses AI tools in the delivery of work product, we will disclose this to clients as part of our engagement methodology. Clients are entitled to request that AI tools not be used on their matters, subject to agreement on scope and timing.

7.3Client Data and AI

Cognitex Consulting will not input identifiable client personal information into third-party AI platforms without the prior written consent of the relevant client, unless the platform is a contracted service provider with appropriate data processing terms in place.

7.4AI Governance

Cognitex Consulting maintains an internal AI Use Policy that governs the responsible use of AI tools across our practice. This policy is reviewed annually and is aligned with the National AI Centre's Guidance for AI Adoption and the OAIC's guidance on privacy and the use of commercially available AI products.

8.Data Quality and Security

8.1Data Quality

Cognitex Consulting takes reasonable steps to ensure that the personal information we hold is accurate, up to date and complete. We encourage individuals to notify us of any changes to their personal information by contacting us using the details provided in section 13 of this policy.

8.2Security Measures

Cognitex Consulting implements appropriate technical and organisational measures to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure. Our security measures include:

  • Password protection and multi-factor authentication for systems containing personal information.
  • Encryption of personal information in transit using industry-standard protocols.
  • Access controls limiting access to personal information to authorised personnel on a need-to-know basis.
  • Regular review of third-party software and cloud platform security settings.
  • Physical security measures for any documents containing personal information.

8.3Retention and Destruction

Cognitex Consulting retains personal information for as long as it is required for the purposes for which it was collected, or as required by law. Personal information that is no longer required is securely destroyed or de-identified. Client engagement records are generally retained for a minimum of seven years following the conclusion of an engagement in accordance with applicable professional obligations.

9.Notifiable Data Breaches

Cognitex Consulting has a documented Data Breach Response Procedure that applies in the event of a suspected or actual data breach. In accordance with the NDB Scheme, Cognitex Consulting will:

  • Assess potential breaches promptly to determine whether notification obligations are triggered.
  • Notify affected individuals and the Office of the Australian Information Commissioner (OAIC) where an eligible data breach is identified.
  • Take remedial action to contain and prevent recurrence of any breach.

Individuals who suspect that their personal information held by Cognitex Consulting may have been compromised should contact us immediately using the details in section 13.

10.Access and Correction

10.1Right of Access

Individuals have the right to request access to personal information that Cognitex Consulting holds about them. Requests should be made in writing to the contact details in section 13. We will respond to access requests within 30 days of receipt. In some circumstances, access may be refused where permitted under the Privacy Act, and we will provide written reasons for any refusal.

10.2Correction Requests

If an individual believes that personal information Cognitex Consulting holds about them is inaccurate, out of date, incomplete, irrelevant or misleading, they may request that it be corrected. We will take reasonable steps to correct the information within 30 days of receiving a correction request. Where we disagree with a correction request, we will provide written reasons.

11.Privacy Complaints

11.1Making a Complaint

Individuals who have a complaint about the way Cognitex Consulting has handled their personal information should contact our Privacy Contact using the details in section 13. We will acknowledge receipt of complaints within five business days and aim to provide a substantive response within 30 days.

11.2External Complaints

If an individual is not satisfied with Cognitex Consulting's response to a privacy complaint, they may refer the complaint to the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au or by calling 1300 363 992.

12.Updates to This Policy

Cognitex Consulting reviews this Privacy Policy annually and whenever there are material changes to our information handling practices or applicable law. The current version of this policy is published on our website. We will take reasonable steps to notify clients and contacts of any material changes.

The most recent version of this policy supersedes all prior versions.

13.Contact Details

For all privacy-related enquiries, access and correction requests, or complaints, please contact:

Privacy Contact

OrganisationCognitex Consulting
Emailmccad09@gmail.com
Telephone+61 433 682 845
AddressMelbourne, Australia