LAPM OS — Privacy Policy
Effective date: 1 July 2026.
1. Who we are
This Privacy Policy explains how LAPM Services Pty Ltd (ABN 58 660 970 141), trading as Lake Australia Practice Management (“LAPM”, “we”, “us”) handles personal information in connection with the LAPM OS legal practice-management platform and related LAPM services (the “Platform”). We are committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Contact: privacy@lapm.com.au | Phone: 1300 808 935 | Post: Suite 1009, Level 1, 241 Adelaide Street, Brisbane QLD 4000, Australia.
2. Our role — controller vs processor
LAPM OS is used by law firms (our “Customers”). The Customer firm decides what client and matter information it puts into the Platform and why. For that firm/client/matter data, the Customer is the controller and LAPM acts as a processor, handling the data on the firm’s instructions. If you are a client of a firm that uses LAPM OS, please direct privacy requests to that firm in the first instance.
For account, billing, and Platform-usage information, LAPM is the controller.
3. Information we collect
3.1 Account information
- Name, work email address, role, and firm details of users we set up or who sign up.
- Authentication data (hashed passwords, multi-factor settings).
3.2 Firm, matter and client data (processed on the firm’s behalf)
- Matter records, contacts and parties, documents, notes, time entries, disbursements, billing, and trust/financial records that the firm enters or uploads.
- This may include personal information about the firm’s clients and third parties, handled under the firm’s instructions.
3.3 Connected mailbox (if a user links Outlook or Gmail)
- OAuth tokens that let the Platform send email on the user’s behalf.
- The content of emails the user composes and sends through the Platform, and a copy filed to the relevant matter.
3.4 Technical and usage information
- Log data (IP address, timestamps, request IDs), device/browser information, and audit records of actions taken in the Platform (for security and support).
4. How we use information
- To provide, operate, secure and support the Platform.
- To send email on a user’s behalf when they use the correspondence feature with a linked mailbox.
- To enable integrations the firm chooses to connect (document generation, court bundling, accounting).
- To send transactional/service email (e.g. password resets, intake links, reminders, scheduled reports).
- To provide optional AI-assistant features.
- To meet legal, regulatory and security obligations, and to detect and prevent misuse.
5. Connected accounts and OAuth
When a user connects a Microsoft or Google mailbox, or a firm connects an accounting platform, we store the resulting access and refresh tokens encrypted at rest and use them only to perform the actions you request (sending email you compose; posting the accounting data the firm chooses). You can disconnect a linked account at any time, which revokes our stored tokens. We request the minimum scopes needed and never full-mailbox read access.
6. Who we share information with (subprocessors)
We use a small number of trusted service providers to run the Platform. They process data only to provide their service to us:
- Amazon Web Services — hosting, database and document storage (Asia Pacific / Sydney region, ap-southeast-2).
- Resend — delivery of our transactional/service email.
- Anthropic — the AI-assistant feature (only the content you submit to the assistant is sent; it is not used to train models).
- Microsoft and Google — only when a user links their mailbox, to send email on their behalf.
- LAPM Precedents, LAPM Bundles and the firm’s chosen accounting platform (e.g. LAPM Accounting, Xero, MYOB, QuickBooks) — only for the integrations the firm enables, and only the data needed for that integration.
We do not sell personal information. We may disclose information where required by law, to protect our rights, or in connection with a business transfer, subject to appropriate safeguards.
7. Storage, location and security
Platform data is hosted in Australia (AWS ap-southeast-2). We protect information with encryption in transit (TLS) and at rest, encrypted storage of secrets and OAuth tokens, role-based access controls, per-firm data isolation, audit logging, and multi-factor authentication options. No system is perfectly secure, but we take reasonable steps appropriate to the sensitivity of legal data.
8. Data retention
We retain firm and matter data for as long as the firm’s account is active and as instructed by the firm, and we honour the legal-retention periods that apply to legal records (commonly 7 years). Account and log data is retained as long as needed for the purposes above and to meet legal obligations, then deleted or de-identified.
9. Your rights
Subject to the Privacy Act and any legal-retention obligations, you may request access to, or correction of, personal information we hold about you. If you are a client of a firm using LAPM OS, please contact that firm; for account/usage data held by LAPM, contact us at privacy@lapm.com.au.
If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
10. AI-assistant features
The Platform offers optional AI features. When you use them, the specific content you submit is sent to our AI provider (Anthropic) to generate a response. This content is not used to train the provider’s models. Do not rely on AI output as legal advice; a qualified person should review it.
11. Cookies
We use strictly-necessary cookies/session tokens to keep you signed in and to secure the Platform. We do not use them for advertising.
12. Changes to this policy
We may update this policy from time to time. We will post the updated version here and change the effective date; significant changes will be notified to Customers.
13. Contact
Questions or privacy requests: privacy@lapm.com.au. We aim to respond within a reasonable time and in any case as required by law.