Privacy Policy

Trust Law & More Limited (Trust Law & More, we, us or our) is committed to protecting your privacy and complying with our obligations under the Privacy Act 2020 and, where applicable, the Biometric Processing Privacy Code 2025.

This Privacy Policy explains how we collect, hold, use and disclose Personal Information in the course of providing legal services and operating our business.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology or legal obligations. The current version will be published on our website.

Definitions

In this Privacy Policy:

Biometric Information means information generated from the measurement of an individual's biological or behavioural characteristics that is capable of being used to identify or verify the identity of that individual.

Biometric Processing Code means the Biometric Processing Privacy Code 2025, as amended from time to time.

Personal Information means information about an identifiable individual and includes Biometric Information.

Privacy Act means the Privacy Act 2020, as amended from time to time.

What Personal Information We Collect

The Personal Information we collect will depend upon the nature of your relationship with Trust Law & More and the services we are providing.

It may include:

  • your name, date of birth, address and contact details;
  • occupation and employment information;
  • payment and financial information;
  • copies of photographic identity documents;
  • facial images and information used for identity verification, including passive liveness detection where an approved electronic identity-verification service is used;
  • evidence of your residential address;
  • information concerning source of wealth or source of funds;
  • information required to satisfy our obligations under anti-money laundering and countering financing of terrorism legislation;
  • information concerning trusts, companies, estates, property, financial arrangements and family or personal circumstances relevant to our instructions;
  • information contained in correspondence, documents or other material provided to us;
  • information provided by your representatives or other persons involved in a matter;
  • information about your use of our website, which may include IP address, browser information, pages visited and other technical information; and
  • any other information reasonably necessary for us to provide legal services, administer our relationship with you, operate our business or comply with our legal and professional obligations.

If you choose not to provide information that we reasonably require, we may be unable to act for you or provide some or all of the services you have requested.

How We Collect Personal Information

Information collected directly from you

Where practicable, we collect Personal Information directly from you.

We may collect information through:

  • email and other electronic communications;
  • telephone or video calls;
  • meetings;
  • forms and questionnaires;
  • our website;
  • electronic identity-verification and document-authentication services;
  • documents provided to us; and
  • communications made in the course of providing legal services.

If you provide us with Personal Information about another person, you should have appropriate authority or another lawful basis for providing that information to us.

Information collected from other people or organisations

In the course of legal practice, it is sometimes necessary or appropriate for us to obtain Personal Information from someone other than the individual concerned.

Subject to applicable law, we may collect Personal Information from:

  • your authorised representatives;
  • trustees, executors, attorneys, family members or other persons involved in a legal matter;
  • other lawyers, accountants, financial advisers and professional advisers;
  • banks and financial institutions;
  • government departments, agencies and statutory registers;
  • courts and tribunals;
  • identity-verification and customer due diligence providers;
  • publicly available registers and databases;
  • insurers and other service providers; and
  • other persons or organisations where collection is authorised by you or permitted by law.

Where Information Privacy Principle 3A of the Privacy Act applies to information that we collect indirectly, we will take reasonable steps to notify the individual concerned of the matters required by law unless an applicable exception permits us not to do so.

There are circumstances in legal practice where notification may not be required or may not be appropriate, including where an individual has already been made aware of the collection, notification would prejudice the purpose of the collection, notification is not reasonably practicable, or another statutory exception applies.

Third-party identity verification

We use approved third-party identity-verification and customer due diligence providers to assist us in meeting our obligations under anti-money laundering and countering financing of terrorism legislation.

These providers may collect Personal Information directly from you, including identity document information, residential address information and, where remote biometric verification is used, a facial image or liveness check. They may verify information against government, credit reporting or other authorised data sources and may undertake screening such as politically exposed person, sanctions or other customer due diligence checks.

Information and verification results necessary for our customer due diligence obligations may then be made available to Trust Law & More.

Third-party providers process information in accordance with their applicable privacy terms and contractual arrangements with Trust Law & More.

Where biometric identity verification is offered, you may contact us if you prefer to use another reasonably practicable method of verifying your identity.

Social media and third-party platforms

Trust Law & More may use third-party platforms such as LinkedIn and Facebook.

If you communicate with us through one of these platforms, the platform provider may collect and process information in accordance with its own privacy policy.

Use of these services is optional. If you do not wish to provide Personal Information through a social media or other third-party platform, you may contact us directly instead.

Information collected automatically

When you use our website, some technical information may be collected automatically, including through cookies and similar technologies.

You can manage or disable cookies through your browser settings, although doing so may affect the operation of some website functions.

Why We Collect and Use Personal Information

We may collect, hold and use Personal Information where reasonably necessary to:

  • identify you and verify your identity;
  • carry out customer due diligence;
  • obtain information concerning source of funds or source of wealth where required;
  • provide legal services;
  • understand and act upon your instructions;
  • establish, administer and manage our relationship with you;
  • communicate with you;
  • respond to enquiries;
  • identify and manage conflicts of interest;
  • maintain client and business records;
  • manage trust account or other financial transactions where applicable;
  • prepare invoices and administer accounts;
  • undertake credit and debt-recovery processes;
  • comply with our legal, regulatory and professional obligations;
  • comply with anti-money laundering and countering financing of terrorism requirements;
  • protect our legal rights and interests and those of our clients;
  • deal with disputes, complaints, claims or legal proceedings;
  • detect, investigate or respond to fraud, cybersecurity incidents or other misuse;
  • maintain and improve our systems, services and business processes;
  • send newsletters, legal updates, invitations or other communications where permitted;
  • administer and improve our website;
  • protect the safety and security of our people, clients, information and systems;
  • use technology to assist with legal and administrative work, subject to appropriate professional and information-security controls;
  • fulfil a purpose authorised by you; or
  • fulfil any other purpose permitted or required by the Privacy Act or other applicable law.

We will not use Personal Information for a purpose that is materially different from the purpose for which it was obtained unless that use is authorised by you or otherwise permitted by law.

Artificial Intelligence and Technology-Assisted Processing

Trust Law & More may use approved artificial intelligence-assisted and automated technology to support aspects of our legal, research, drafting, document review, administrative and business processes.

Artificial intelligence is used as an assistance tool. It does not replace professional legal judgement, and responsibility for the legal services and advice provided to you remains with Trust Law & More.

Where Personal Information may be processed using an artificial intelligence or other technology provider, we consider the nature and sensitivity of the information, the purpose for which the technology is being used, and relevant confidentiality, privacy, security and professional obligations.

We seek to minimise the Personal Information provided to external technology services and, where appropriate and practicable, may remove or limit identifying information before using technology-assisted tools.

We do not rely upon artificial intelligence-generated information as an authoritative source without appropriate human review and, where relevant, verification against appropriate source material.

Our use of artificial intelligence is also subject to our information-security and internal technology-use requirements.

Who We May Disclose Personal Information To

Where reasonably necessary for one of the purposes described in this Privacy Policy, or otherwise permitted by law, we may disclose Personal Information to:

  • people authorised to work within or on behalf of Trust Law & More;
  • barristers and other legal practitioners;
  • accountants, tax advisers, financial advisers, valuers, experts and other professional advisers;
  • other law firms;
  • banks and other financial institutions;
  • insurers and insurance brokers;
  • auditors;
  • identity-verification and customer due diligence providers;
  • information technology, cloud-storage, communications, document-management and cybersecurity providers;
  • approved artificial intelligence and technology providers;
  • accounting, billing and practice-management providers;
  • government agencies, regulators and statutory authorities;
  • courts, tribunals and dispute-resolution providers;
  • law enforcement bodies where disclosure is authorised or required by law;
  • persons or organisations involved in a transaction or matter in which we act;
  • debt recovery and credit-management providers;
  • any person authorised by you; and
  • any other person where disclosure is permitted or required by the Privacy Act or another applicable law.

We take reasonable steps, having regard to the nature of the service and the information involved, to use third-party providers with appropriate privacy, confidentiality and information-security arrangements.

We do not sell Personal Information.

Overseas Processing and Disclosure

Some of the technology and service providers we use operate or store or process information outside New Zealand.

This means Personal Information may, in some circumstances, be stored or processed overseas.

Where the Privacy Act regulates a disclosure of Personal Information outside New Zealand, we will take reasonable steps to comply with Information Privacy Principle 12 and any other applicable requirements.

The privacy protections applying in another country may differ from those applying in New Zealand.

Where an overseas provider processes information on our behalf rather than receiving it for its own independent purposes, we will take reasonable steps to select and use providers whose arrangements are appropriate having regard to the nature and sensitivity of the information concerned.

How We Protect Personal Information

Trust Law & More takes reasonable safeguards to protect Personal Information against loss, unauthorised access, use, modification, disclosure or other misuse.

Those safeguards may include:

  • password and access controls;
  • multi-factor authentication where appropriate and reasonably available;
  • secure premises and physical document storage;
  • reputable cloud and technology providers;
  • access restrictions;
  • secure transmission methods;
  • backup and recovery arrangements;
  • cybersecurity protections;
  • secure disposal of information; and
  • policies and procedures governing the handling of confidential and Personal Information.

Access to Personal Information is limited to persons who have an appropriate reason to access it.

No method of electronic storage or transmission can be guaranteed to be completely secure. Our security measures are therefore reviewed having regard to the nature of the information we hold and the risks reasonably associated with it.

Privacy Breaches

If we become aware of a privacy or information-security incident, we will assess the circumstances and take appropriate steps to contain, investigate and respond to the incident.

Where a privacy breach has caused, or is likely to cause, serious harm, we will notify the Office of the Privacy Commissioner and affected individuals where required by the Privacy Act.

Biometric Information

We may use an approved electronic identity-verification provider that processes facial images or other Biometric Information for the purpose of verifying identity and complying with legal requirements.

Where the Biometric Processing Privacy Code 2025 applies, we will comply with its requirements.

Before using biometric processing, we will consider whether its use is effective and proportionate for the relevant purpose and the privacy risks associated with its use.

Where required, we will also consider:

  • whether there is a less privacy-intrusive reasonably practicable alternative that would adequately achieve the purpose;
  • the benefits of using the biometric process;
  • the risks to the individual;
  • appropriate privacy safeguards; and
  • relevant cultural considerations.

We will not knowingly use Biometric Information collected for identity verification for unrelated profiling or biometric categorisation.

If biometric identity verification is offered to you and you would prefer not to use it, please contact us to discuss whether an appropriate alternative form of identity verification is available.

Accessing and Correcting Your Personal Information

Subject to the Privacy Act, you have the right to ask whether we hold Personal Information about you and to request access to readily retrievable Personal Information that we hold.

You may also ask us to correct Personal Information that you believe is inaccurate.

There are circumstances in which the Privacy Act allows or requires us to withhold information. Legal professional privilege and duties owed to other persons may also affect whether particular information can be provided.

If we refuse a request for access or correction, we will provide the information required by the Privacy Act concerning that decision.

Requests should be made to our Privacy Officer using the contact details below.

Retention of Personal Information

We retain Personal Information for as long as reasonably necessary for the purposes for which it was collected and to meet our legal, regulatory, professional and legitimate business requirements.

This may include retaining information in order to:

  • provide legal services;
  • maintain client and transaction records;
  • comply with statutory and professional record-retention obligations;
  • respond to future enquiries;
  • establish or defend legal claims;
  • meet taxation, accounting and anti-money laundering obligations; and
  • maintain appropriate backup and business-continuity arrangements.

When Personal Information is no longer required to be retained, we will take reasonable steps to securely delete, destroy or otherwise dispose of it.

A request that information be deleted does not require us to delete information that we are legally or professionally required, or otherwise lawfully entitled, to retain.

Privacy Officer and Complaints

If you have any questions about this Privacy Policy, would like to request access to or correction of Personal Information, or have concerns about the way we have handled your Personal Information, please contact:

Privacy Officer
Deeanah Winders
Trust Law & More Limited
24 Sonia Avenue
Remuera
Auckland 1050

Email: deeanah@trustlawmore.com
Telephone: +64 9 875 7111

If you are not satisfied with our response, you may contact the Office of the Privacy Commissioner at privacy.org.nz.

Further Information

You may also wish to read our Security Information Policy, which explains our approach to protecting information and the technology systems used in our practice.

Last updated: August 2026