Privacy Notice
Last updated: 22 September 2026
Your client files are yours, your cloud is yours, and your AI account is yours. PractitionerHQ is designed as an overlay — not another repository for your clients' files.
We built PractitionerHQ for lawyers, so privacy, confidentiality and control over information aren't optional extras.
This Privacy Notice explains what information PractitionerHQ does collect, what we don't collect, and what we do with the information we have.
1. Who we are
PractitionerHQ is the service available at practitionerhq.com. In this notice, PractitionerHQ, we, us and our refer to the operator of that service.
For privacy questions, access requests or complaints, contact us here.
This notice has been prepared with the Australian Privacy Act 1988 (Cth) and Australian Privacy Principles in mind. We aim to follow those principles in the way we design and operate PractitionerHQ, whether or not every provision of the Privacy Act applies to us in every circumstance.
2. The important bit: your matter files
PractitionerHQ uses a Bring Your Own Cloud model.
Your firm's documents remain in storage controlled by you, such as your connected cloud storage, document system or local environment.
PractitionerHQ's central infrastructure does not receive, upload or store your private matter documents simply because you use PractitionerHQ to work with them.
That includes things such as:
- client files;
- correspondence;
- briefs;
- contracts;
- evidence;
- private precedents;
- confidential memoranda;
- client personal information contained in those files; and
- other private matter material.
Document retrieval, private repository indexing, practice memory and related document processing are designed to occur within your controlled environment.
3. Bring Your Own AI
PractitionerHQ also supports a Bring Your Own AI model.
Where you choose to use an AI provider, such as an available OpenAI, Anthropic, Microsoft, Google or other supported service, your connection is made using the AI service selected and controlled by you.
When private material needs to be sent to that AI service to perform a task, the relevant material is transmitted through the customer-controlled processing environment to the provider you selected.
It is not routed through PractitionerHQ's central servers for us to retain or use.
Your use of a third-party AI provider is also subject to that provider's terms, privacy arrangements and data-handling settings. You should choose and configure your provider appropriately for the type of legal work you perform.
4. We don't train on your client files
PractitionerHQ does not use your private matter material to train a shared AI model or improve drafting for another PractitionerHQ customer.
Your private practice knowledge may help PractitionerHQ work better for your own practice — for example by recognising your preferred precedents, previously approved documents, research history or drafting preferences.
That private practice memory stays separated from other PractitionerHQ customers. There is no cross-customer learning from private matter content by default.
If we later offer something like a voluntary PractitionerHQ community precedent or knowledge programme, participation will be separate and opt-in. We will explain what is being contributed before anything leaves your private environment. Joining that kind of programme will not be a condition of using the normal PractitionerHQ service.
5. What personal information do we actually collect?
Although we don't centrally collect your client files, we do need some ordinary information to run PractitionerHQ.
Account information
Your name, email address, organisation or practice name, account role and login-related information.
Subscription and transaction information
Your plan, subscription status, invoices and basic payment or transaction records. Where a payment provider processes payments for us, we generally do not need to hold your complete payment-card details ourselves.
Communications
Information you give us when you contact support, report a problem, provide feedback or otherwise communicate with us.
Technical and security information
Information such as login events, browser or device information, IP address, system events, security records and diagnostic information reasonably needed to operate and protect the service.
Product usage information
Limited information about how PractitionerHQ features are used. For example, we may record that a user ran a document comparison or used a drafting feature so that we can understand product performance and improve the service.
Our central analytics are designed not to require the contents of the private documents being worked on.
6. Public legal information
PractitionerHQ may retrieve, index or maintain public and official legal materials used by its research tools.
These may include legislation, judgments, court materials, regulatory publications and other publicly available legal sources.
Some public legal materials can contain names or other information about identifiable people. Where we process that information, we do so for the purpose of providing, maintaining and improving PractitionerHQ's legal research and source-verification functionality.
This is separate from your firm's private matter repository.
7. What we use personal information for
We use the personal information we hold to do things such as:
- create and manage your account;
- authenticate users and protect accounts;
- provide PractitionerHQ and its features;
- manage subscriptions and billing;
- communicate with you;
- provide support;
- diagnose technical problems;
- prevent fraud, misuse and security threats;
- understand how the product is being used;
- improve reliability and usability;
- meet legal, accounting and regulatory requirements; and
- establish, exercise or defend legal rights where necessary.
We don't sell your personal information.
We also don't sell your clients' information — because under the core PractitionerHQ architecture we don't centrally receive their matter files in the first place.
8. Product improvement without reading your files
We want PractitionerHQ to get better over time without turning private client material into a communal dataset.
We may therefore use things such as:
- aggregated feature-usage statistics;
- error and performance information;
- user feedback;
- source ratings;
- user-approved workflow preferences;
- public legal sources; and
- PractitionerHQ-created or properly licensed material
to improve the product.
Private customer matter content is not part of that general product-improvement dataset.
9. Cookies and website information
Like most online services, the PractitionerHQ website may use cookies or similar technologies that are necessary for things such as login, security, session management and remembering settings.
We may also use limited analytics to understand whether the website and product are working properly and which features are useful.
Where additional consent or controls are required by applicable law, we will provide them. You can also control many cookies through your browser settings.
10. Who do we share information with?
We may use service providers to operate the parts of PractitionerHQ that we actually run, for example providers supporting:
- website hosting;
- authentication;
- email;
- customer support;
- billing and payments;
- security;
- error monitoring; and
- limited product analytics.
We give those providers only the information reasonably needed for the service they provide.
This is different from your own connected cloud or AI provider. Those services are selected by you and handle your information under the arrangements between you and that provider.
We may also disclose information if required by law, court order or lawful government request, or where reasonably necessary to protect PractitionerHQ, our users or others from fraud, security threats or unlawful activity.
11. Overseas processing
Some of the service providers used to operate PractitionerHQ may be located outside Australia or may process information using infrastructure outside Australia.
Our website infrastructure currently uses Cloudflare services. As the production service develops, we will keep this notice current with material changes to the service providers and processing arrangements we use.
Where Australian privacy law applies to an overseas disclosure made by us, we take appropriate steps to address the applicable requirements.
Importantly, the location of a cloud or AI provider that you independently connect to PractitionerHQ may depend on the provider and configuration you select. You should review that provider's terms and data-location options when deciding whether it is appropriate for your practice.
12. How long do we keep information?
We keep personal information only for as long as reasonably required for the purposes for which we collected it, including providing the service and meeting legal, accounting, fraud-prevention and security requirements.
When information is no longer required, we take reasonable steps to delete it or de-identify it where appropriate.
Disconnecting or deleting private material from your own cloud environment is governed by your systems and providers, because PractitionerHQ does not maintain a central copy of those matter files.
13. Security
We use reasonable technical and organisational safeguards appropriate to the information PractitionerHQ actually holds.
A major part of our security model is architectural: we minimise the amount of sensitive client information that needs to enter PractitionerHQ infrastructure at all.
No internet-connected system is completely risk-free, so we also monitor and improve our safeguards as the platform develops.
If a data breach involving personal information held by PractitionerHQ occurs, we will assess and respond to it in accordance with applicable law, including Australia's Notifiable Data Breaches scheme where it applies.
14. Accessing or correcting your information
You can ask us what personal information we hold about you, request access to it or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.
Contact us here. We may need to verify your identity before acting on a request.
Because PractitionerHQ does not centrally hold your private matter files, requests concerning information held within your firm's own connected cloud will generally need to be handled within that system.
15. Can you use PractitionerHQ anonymously?
You can browse public parts of our website without creating an account.
Using authenticated PractitionerHQ services generally requires us to know enough about you to create and secure an account, manage permissions and, where applicable, administer a subscription.
16. Marketing
If you choose to hear from us about PractitionerHQ updates, new features or related products, we may send you those communications.
You can unsubscribe from marketing communications at any time. We may still send operational communications that are necessary for your account or the service.
17. Automated decisions
PractitionerHQ provides tools to assist legal professionals with tasks such as research, drafting, comparison and document workflows.
PractitionerHQ does not currently use the personal information we hold about users to make solely automated decisions that significantly affect their rights or interests.
Legal professionals remain responsible for reviewing and deciding how to use outputs produced through PractitionerHQ.
18. Privacy questions or complaints
If something doesn't look right, tell us.
Contact us here and give us enough information to understand the issue and investigate it.
We will acknowledge and deal with privacy complaints reasonably and aim to respond within a reasonable period.
If you are not satisfied with our response and the Australian Privacy Act applies, you may be able to complain to the Office of the Australian Information Commissioner (OAIC).
19. Changes to this notice
PractitionerHQ will change as the product develops, so this notice may change too.
When we make material changes, we'll update the date at the top and, where appropriate, let users know through the service or by email.
The current version will always be available on the PractitionerHQ website.
- We need some ordinary account and operational information to run PractitionerHQ.
- We don't centrally host your client files.
- We don't route your private matter files through PractitionerHQ servers just to use the tools.
- You bring your own cloud.
- You bring your own AI.
- Your private practice knowledge stays private to your practice.
- We don't train a shared system on your client material for the benefit of somebody else's firm.