Privacy Policy

How we collect, use, and protect your personal information.

Effective: 4 August 2026 | Last updated: 4 August 2026

1. Who We Are

Acquit is a legal technology platform operated by Harvey George Pty Ltd (ACN 699 011 651 / ABN 22 699 011 651), trading as Acquit, a Queensland-registered company. Acquit provides practice management tools for Queensland criminal lawyers, including court list matching, client and matter management, calendar synchronisation, document generation, a town agency network for coordinating court agency work, multi-user and firm collaboration features, and a Community legal-research library (judgments, practice directions, benchbooks, and directories drawn from public sources).

For the purposes of the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), Harvey George Pty Ltd is the entity responsible for handling your personal information through the Acquit platform. References to "Acquit", "we", "us", or "our" in this policy mean Harvey George Pty Ltd.

Acquit is a service provider to legal practitioners. Where you enter information about your own clients and matters into the platform, you remain responsible, as the practitioner, for your professional, confidentiality, and privacy obligations to those clients, including obtaining any consents you require to use cloud-based practice tools. We handle that information on your behalf to provide the Service and protect it as described in this policy.

This policy applies to all personal information collected through the Acquit platform, our website, and any related communications. It does not apply to third-party websites or services linked from our platform, which are governed by their own privacy policies.

If you have questions about this policy or your personal information, please see the Contact Us section below.

2. Information We Collect

We collect personal information that is reasonably necessary for us to provide the Acquit platform and related services. We collect information directly from you when you register, use the platform, or contact us.

Account Information

  • Name, title, email address, phone number
  • Law firm or chambers name and business address
  • Website (optional)
  • Password (stored as a salted hash, never in plain text)
  • Profile and firm images you choose to upload

Client & Matter Data

  • Client names, dates of birth, and contact details that you enter into the system
  • Court dates, charges, court locations, and matter reference numbers (including matter "file numbers")
  • Court events, task notes, and file attachments you upload
  • Where one person has several matters, the matters you link together under that person

Town Agency Network Data

  • Agency requests, availability preferences, and town agency history
  • Outcome reports and agency correspondence
  • Messages exchanged with other practitioners through in-app direct and group chat
  • AI-generated content: If you opt in to AI features, we generate plain-English outcome summaries and pre-court briefings using your client names, charge descriptions, and court details. These summaries are stored alongside the corresponding outcome reports and requests.

Calendar Data

  • If you connect your Outlook calendar, we access calendar events to synchronise court dates. We store OAuth tokens and calendar event mappings in our database, which is encrypted at rest.

Data from Public Sources

  • Court list data and other publicly published legal information sourced from Queensland government and court websites. This is described in detail in Public & Court Data Sources below.

Derived Data

  • Smart match results generated by matching your client records against published court lists
  • Aggregated usage statistics and platform analytics derived from your activity

Technical & Usage Data

  • IP address, browser type, and device information (collected in access logs)
  • Session data including login times and activity timestamps
  • Notification preferences and platform settings

Payment Information

Subscription payments are processed by Stripe. We do not store your credit card number. Stripe handles all payment card data under their own privacy policy. We receive and store your Stripe customer ID and subscription status for account management purposes.

3. Public & Court Data Sources

Acquit helps practitioners by collecting and organising information that Queensland courts and government bodies publish to the public. We only access publicly available published material. We do not have, request, or rely on any privileged connection to government case-management systems, restricted portals, or non-public data feeds, and we do not receive any personal information from government agencies under a data-sharing arrangement.

The public sources we collect from include:

  • Daily law lists published by the Queensland courts (Supreme, District, and Magistrates), which list defendant names, charges, court rooms, times, and the presiding judicial officer. We use these for court list matching so you can find your clients' appearances.
  • Published judgments from the Supreme Court Library Queensland's caselaw service (queenslandjudgments.com.au).
  • Practice directions and benchbooks published by the Queensland courts and the Supreme Court Library Queensland (sclqld.org.au).
  • Legislation published on official government legislation websites, used to power our offence lookup tool.
  • Judicial officer rosters and public appointment announcements published by the Queensland courts and the Queensland Government.

We collect this material responsibly: we identify ourselves in our requests, apply rate limiting and change-detection so we only re-fetch material when it actually changes, and respect the access controls of the sites we read. The information is used solely to provide and improve the Service for legal practitioners. We do not sell it, and we do not use it for any purpose unrelated to assisting our users with Queensland criminal practice.

5. How We Use Your Information

We use your personal information for the following purposes:

  • Providing the service: Account authentication, court list matching, client and matter management, calendar sync, task tracking, document generation, and the Community legal-research library
  • Town agency network: Matching practitioners for court agency work based on location, availability, and preferences
  • Firm and matter collaboration: Enabling the sharing and oversight features described in Sharing & Firm Access
  • AI-powered features: Three categories send your data and require your consent, managed from Settings → AI: briefings (client names, charges, notes sent to Anthropic and, for the find-a-time scheduling assistant, OpenAI, to generate pre-court and pre-event briefings, daily agenda summaries, client briefs, and outcome summaries), document reading (uploaded charge sheets, bail conditions, and scans sent to OpenAI to extract text), and the help assistant (your questions in the Ask Acquit in-app chat, plus the relevant records from your account such as court dates, matters, tasks, and calendar sync state, sent to Anthropic to answer you and troubleshoot problems). All three are disabled by default and can be turned off at any time without losing access to any core functionality. Declining just means the underlying data stays on structured fields instead of a written summary. Two further AI features run without a consent step because they never process identifying client information: calendar parsing (masked event structure only: dates, times, abbreviations, never a client's name) and caselaw summaries (public court judgments only).
  • Communications: Sending transactional emails (verification codes, password resets, security notifications, agency updates) via our email service provider
  • Security: Protecting your account through two-factor authentication, session management, breached-password screening, and monitoring for unauthorised access
  • Improving the platform: Aggregated, de-identified usage data to understand how the platform is used and where to improve. Ask Acquit help-assistant conversations are also recorded and may be reviewed by our team and analysed, including with AI assistance (Anthropic), to identify common questions and improve the product and its documentation
  • Legal obligations: Complying with applicable laws, regulations, or court orders

We will not use your personal information for direct marketing without your consent. We do not sell personal information to third parties. We do not use personal information for profiling, credit scoring, or automated decision-making that produces legal or similarly significant effects on you.

6. Disclosure of Your Information

We may disclose your personal information in the following circumstances:

  • Other users of your firm or your matters: Depending on how your account and matters are set up, some information may be visible to colleagues in your firm or to practitioners you collaborate with. This is described in detail in Sharing & Firm Access.
  • Town agency network participants: When you use the town agency network, limited information (your name, firm, and relevant court date details such as the client's name, charges, custody status, court, date, and time) is shared with other practitioners to facilitate court agency work. The full client file is not shared. You control your visibility through your agency preferences.
  • Service providers: We use third-party services to operate the platform (see Cross-Border Data Transfers below). These providers process data on our behalf under contractual obligations to protect your information.
  • Legal requirements: We may disclose information where required or authorised by law, including to law enforcement agencies, courts, or regulators.
  • Business transfer: If Harvey George Pty Ltd is acquired, merges with another entity, or sells all or substantially all of its assets, your personal information may be transferred to the successor entity. We will notify you of any such transfer and any changes to this policy.

If you opt in to AI features, limited client data (such as names and charge descriptions) is processed by our AI providers to generate summaries and briefings. See Cross-Border Data Transfers for details.

7. Sharing & Firm Access

Acquit supports practitioners working together. Because of this, client and matter information you enter is not always visible only to you. The following describes exactly who can see your data and when.

Your own matters

By default, the clients and matters you create are visible only to you, unless one of the situations below applies.

Matters you explicitly share

You can share an individual matter with another practitioner. When you do, you choose whether they have view-only access or collaborator (read and write) access. Sharing is per-matter and always initiated or approved by you. You can stop sharing at any time.

Firm accounts and oversight roles

If your account belongs to a law firm on Acquit, users who hold a firm management role (such as the firm owner, co-owner, administrator, or firm billing account) can access and manage the matters of active members of that firm for legitimate practice-management and oversight purposes. If you join or are added to a firm, you should expect that your firm's management may be able to view and manage matters held in the firm's accounts. This reflects the reality that, within a firm, client matters belong to the firm.

Sharing requests when importing

When you import clients, Acquit may detect that a colleague in your firm already holds a matter that appears to match (for example, the same file number or client name). In that case a sharing request may be raised to that colleague, who can approve or decline it. No matter detail is merged or shared unless the request is approved.

Messages

Direct and group messages are visible only to the participants of that conversation.

You remain responsible for ensuring that any sharing of client information is consistent with your professional and confidentiality obligations.

8. Cross-Border Data Transfers

In accordance with APP 8, we disclose below the countries where your personal information may be processed by our service providers. We take reasonable steps to ensure these providers comply with the APPs or are subject to substantially similar privacy protections.

Service Purpose Data Location Data Processed
MongoDB Atlas Primary database Sydney, Australia (ap-southeast-2) All application data (accounts, clients, court dates, messages)
Application Hosting Web application server Australia All data processed through the platform during active use
Cloudflare R2 File & document storage United States / global edge network Uploaded files and document attachments, profile and firm images, chat attachments, and similar content
Resend Transactional email delivery United States / AWS Asia-Pacific sending infrastructure Email addresses, email content (verification codes, notifications, agency updates)
Better Stack Error tracking & uptime monitoring European Union (Germany) Application error logs, which may include usernames, IP addresses, and fragments of record data present in error messages
Stripe Payment processing United States Name, email, payment card details, subscription status
Microsoft Azure Outlook calendar sync (optional) United States / Global OAuth tokens, calendar event titles and dates (only if you connect your calendar)
Anthropic (Claude API) AI briefings, outcome summaries, daily agenda, the Ask Acquit help assistant, caselaw summaries, and calendar pattern learning United States Briefings and outcome summaries send client names, charge descriptions, court details, and outcome data, but only if you turn on the briefings scope. The help assistant sends your questions and the relevant records from your account, but only if you turn on the help assistant scope; those conversations may later be analysed, including with AI assistance, to improve the service. Calendar pattern learning is always on but sends only masked event structure (dates, times, abbreviations), never a client's name. Caselaw summaries use only public court judgments.
OpenAI Document reading (charge sheets, bail conditions, scanned documents), find-a-time scheduling, and calendar text interpretation United States Document reading sends the full text of documents you upload, but only if you turn on the documents scope. Find-a-time sends the free text you type when asking Acquit to find a slot (part of the briefings scope). Calendar interpretation is always on but sends only masked event structure, never a client's name.

Your primary application data (client records, court dates, messages, and account information) is stored in MongoDB Atlas in the Sydney, Australia region. Uploaded files and attachments are stored with Cloudflare R2. Calendar synchronisation is optional and only activated when you connect a calendar. AI briefings, document reading, and the Ask Acquit help assistant are optional and only activated when you turn them on in Settings → AI; calendar parsing and caselaw summaries are built in and always on because they never see identifying client information.

9. Data Security

We take reasonable steps to protect your personal information from misuse, interference, loss, and unauthorised access, modification, or disclosure. Our security measures include:

  • Encryption in transit: All data in transit is encrypted via TLS/HTTPS. Database connections use encrypted channels.
  • Encryption at rest: Database storage is encrypted at rest using AES-256 encryption provided by our database infrastructure.
  • Password security: Passwords are hashed using industry-standard algorithms (never stored in plain text). Passwords must be at least 12 characters long. New and changed passwords are screened against known data-breach corpora using a privacy-preserving "k-anonymity" check. Only a partial, irreversible hash of your password is sent, never the password itself.
  • Authentication: Optional two-factor authentication (TOTP) with backup codes, and passkey (WebAuthn) sign-in. Configurable session timeouts.
  • Access controls: Role-based access ensures users only see data they own, that has been shared with them, or that they are entitled to manage as described in Sharing & Firm Access. Administrative functions are restricted to authorised personnel. All employees and contractors with access to personal information are bound by confidentiality obligations.
  • Session management: Sessions are stored securely (using an in-memory store, Redis, for session, caching, and real-time messaging) with automatic expiry. Users can view active sessions and terminate them individually or all at once. Security events (password changes, new logins, 2FA changes) trigger email notifications.
  • Infrastructure: Security headers (Content-Security-Policy, HSTS, X-Frame-Options) are enforced on all responses. CSRF protection is enabled on all forms. Rate limiting is applied to authentication endpoints.

No system is completely secure. While we implement industry-standard safeguards, we cannot guarantee absolute security. We encourage you to use a strong, unique password and to enable two-factor authentication.

10. Data Retention

We retain your personal information only for as long as is reasonably necessary for the purposes described in this policy, or as required by law. The following retention periods apply:

Data Type Retention Period
Account information Life of account + 90-day grace period after deactivation
Client & matter data Life of account (deleted on account closure)
Chat messages & agency data (shared) Pseudonymised on account closure (identifiers replaced); retained for other participants
Access & security logs 12 months
Transactional email records 12 months
Payment & billing records 7 years (Australian tax requirements)
Verification codes 10 minutes or less (auto-expire); firm ownership-transfer confirmations up to 48 hours
OAuth tokens (calendar) Until disconnected or account closure
Ask Acquit help-assistant conversations Life of account (deleted on account closure)

When data is no longer required, it is permanently deleted or irreversibly anonymised so that it can no longer be used to identify you. Truly anonymised data (aggregate statistics that cannot be linked back to you) may be retained indefinitely for statistical and analytical purposes. Shared records that are only pseudonymised (see Account Deactivation) remain personal information, and we retain them only so far as necessary to preserve the integrity of other participants' records.

11. Data Breach Notification

In the event of a data breach that is likely to result in serious harm to any individual whose personal information is involved, we will:

  • Assess any suspected eligible data breach expeditiously and, in any case, within 30 days of becoming aware of it; and, where we have reasonable grounds to believe an eligible data breach has occurred, notify the Office of the Australian Information Commissioner (OAIC) as soon as practicable thereafter, in accordance with Part IIIC of the Privacy Act 1988 (the Notifiable Data Breaches scheme)
  • Notify affected individuals as soon as practicable, providing a description of the breach, the types of information involved, and recommended steps to mitigate potential harm
  • Take reasonable steps to contain the breach and reduce any resulting harm

We maintain incident response procedures to ensure breaches are identified, assessed, and responded to promptly.

12. Your Rights

Under the Australian Privacy Principles, you have the following rights in relation to your personal information:

  • Access: You can view and download your personal information at any time through Settings > Security using the Download My Data feature, which exports your profile, clients, court dates, events, tasks, assistance requests, notifications, and activity history in a machine-readable format (JSON).
  • Correction: You can correct your profile information (name, email, phone, firm details) at any time through the Settings page. If you believe any other information we hold about you is inaccurate, contact us and we will take reasonable steps to correct it (APPs 12 and 13).
  • Data export: You can export all your data whenever you can log in, including after your subscription ends or is cancelled. Deactivating your account locks it, so download your data first, or contact us during the 90-day grace period to have it reactivated.
  • Withdraw consent: You can disable optional features (calendar sync, AI features, town agency participation) at any time without affecting core functionality. Withdrawal of consent does not affect the lawfulness of processing carried out before withdrawal.
  • Account deletion: You can deactivate your account at any time through Settings > Security. See Account Deactivation for details on what happens to your data.
  • Complaint: You have the right to lodge a complaint with us or with the Office of the Australian Information Commissioner.

Formal Access Requests

If you require access to personal information not available through the platform, you may submit a written request to us. We will respond within 30 days. We may need to verify your identity before providing access. Access may be refused in limited circumstances permitted by the Privacy Act (e.g., legal professional privilege).

13. Account Deactivation

You can deactivate your account at any time through Settings > Security. We recommend downloading your data before deactivating.

What Happens When You Deactivate

  • Your account is immediately locked and you cannot log in
  • OAuth tokens, 2FA secrets, and active sessions are cleared
  • A security notification email is sent confirming the deactivation
  • Your data enters a 90-day grace period during which you can contact us to reactivate

After 90 Days

  • Sole-party data is permanently deleted: clients, court dates, court events, tasks, notifications, calendar mappings, smart matches, files, and subscription records
  • Shared data is pseudonymised: Town agency requests, outcome reports, agency emails, chat messages, and activity logs are retained with your personal identifiers replaced by a "Deactivated User" placeholder to preserve the integrity of other participants' records. Because these records may still be associated with you in context, we continue to treat them as personal information and retain them only for as long as those participants need them
  • Your user account document is permanently deleted

This process runs automatically. Once completed, deletion is irreversible.

14. Cookies & Local Storage

Acquit uses cookies and browser storage for two distinct purposes, and we treat them differently. Inside the platform, storage is strictly functional. On our public website, we also measure how visitors find and use the site. No analytics or advertising technology of any kind runs on a signed-in page, and none of it ever has access to client or matter data.

Inside the platform (when you are signed in)

We do not use third-party analytics, tracking cookies, or advertising cookies anywhere in the Acquit application. The only storage we set is the following:

  • Session cookie: A secure, HTTP-only cookie that identifies your authenticated session. Expires based on your configured session timeout (default 30 days).
  • CSRF token: A security token embedded in pages to prevent cross-site request forgery attacks. Generated per-session.
  • Trusted device token: If you enable "Trust this device" during 2FA login, a secure cookie is set to skip 2FA on that device for 30 days.
  • Local storage: Used for UI preferences such as sidebar state and notification settings. No client or matter information is stored in local storage.

On our public website (when you are signed out)

Our public marketing pages (such as our home, features, pricing, about and contact pages) use the following. These do not run on any signed-in page of the platform, and they are not present on our dev or staging environments.

  • Google Analytics 4 (provided by Google LLC): measures page views, traffic sources, and actions such as viewing our pricing page or submitting our contact form, so we can understand which parts of our site are useful. Google sets its own cookies (typically _ga) for this purpose. Because we may run advertising campaigns for Acquit, Google Analytics data from our public site may be used by Google for advertising and audience purposes, including showing you Acquit ads on other sites. This applies only to our public marketing pages. You can opt out using the Google Analytics opt-out browser add-on, or by blocking cookies in your browser. Our site remains fully functional either way.
  • First-touch attribution stamp: On your first visit we record how you arrived: any campaign parameters in the link, the referring website, the page you landed on, and the date. This is stored in your browser's local storage and mirrored to a first-party cookie (acq_first_touch) that lasts up to two years. If you later create an account or contact us, we attach this record to your account so we know which of our efforts are worth continuing. It contains no client or matter data.

We do not respond to "Do Not Track" browser signals, as there is no consistent industry standard for how they should be honoured. If you would prefer not to be measured at all, blocking cookies or using the opt-out add-on above is the most reliable method.

15. Children's Privacy

The Service is designed for use by legal practitioners and is not directed at persons under 18 years of age. We do not knowingly collect personal information from children. If we become aware that we have collected personal information from a person under 18 without appropriate consent, we will take steps to delete that information promptly.

16. Changes to This Policy

We may update this privacy policy from time to time. If we make material changes, we will provide at least 30 days' notice to registered users via email and update the effective date at the top of this page.

Minor changes (such as clarifications or formatting updates) may be made without notification. The current version of this policy is always available at /privacy, and previous versions are retained for reference.

17. Browser Extension

Acquit publishes an optional Chrome browser extension that fills Queensland government forms for you, so you do not have to retype client details you have already entered into Acquit. The extension is entirely optional (Acquit works fully without it) and it only does anything when you click an Acquit button to start a search.

What it receives

When you start a search from Acquit, the extension receives only the fields the relevant government form requires: the first name, surname and date of birth of the client you selected. It does not receive your matter notes, documents, charges, court dates, or any other client information, and it cannot read your Acquit account.

What it does with it

The extension types those details into Queensland government websites on your behalf (the same sites you would otherwise fill in by hand) and reads the results back. It operates only on:

  • courts.qld.gov.au: Magistrates Court adjournment and court-event applications, and criminal case lookup.
  • corrections.qld.gov.au: prisoner location search.
  • acquit.app: to receive the search request from your Acquit session and return the results.

Those government departments are separate organisations and handle any information they receive under their own privacy policies, exactly as they would if you completed their forms manually. The extension does not send your data anywhere else. We do not sell it, we do not share it with any other third party, and the extension contains no analytics, tracking, or advertising code.

What it stores, and for how long

  • In your browser: the client details for the search in progress are held in session storage only, and are discarded when you close your browser. Nothing is retained on your device.
  • In Acquit: the results returned from a lookup are saved to your matter so you can refer back to them, and are automatically deleted 30 days after retrieval.

Results are transmitted back to Acquit over an encrypted connection and are cryptographically signed, so that only your own Acquit session can submit them to your account.

Permissions it asks for

Chrome will ask you to approve the following when you install it. Each is limited to the purpose described:

  • Access to the Queensland government sites listed above: to fill their forms and read the results.
  • Tabs and active tab: to open the relevant government form and act on the page you are looking at.
  • Storage: to hold the in-progress search described above.
  • Scripting: to read the results from the government page once it loads.

You can remove the extension at any time from your browser's extensions page. Removing it does not affect your Acquit account or any data already saved to your matters.

18. Contact Us

If you have questions about this privacy policy, wish to make a complaint about our handling of your personal information, or want to exercise your rights under the Privacy Act, please contact us:

Harvey George Pty Ltd (ABN 22 699 011 651) trading as Acquit

Privacy Officer

Suite 1004, Level 10, 203 Robina Town Centre Drive, Robina QLD 4226

Email: [email protected]

Website: www.acquit.app

We aim to respond to all privacy enquiries within 14 days. If your enquiry involves a formal access or correction request, we will respond within 30 days as required by the Privacy Act.

If you are not satisfied with our response, you have the right to lodge a complaint with the Office of the Australian Information Commissioner (OAIC).