We’re actively hiring Legal Associates. Apply now
What we do About Insights Careers Contact Book a call

Australia + Sri Lanka

Privacy Notice

How Jurisa collects, uses, shares and protects personal information across its Australian and Sri Lankan operations.

Last updated 3 August 2026 · Privacy enquiries: team@jurisa.com.au

Summary

Privacy at a glance

Jurisa provides Australian law firms and in house legal teams with legal process outsourcing and AI enabled legal support. This notice explains how Jurisa Pty Ltd handles personal information in connection with our website, business relationships, recruitment and service delivery in Australia and Sri Lanka.

Who this covers

Website users, clients and prospective clients, candidates and referees, suppliers, event participants and other business contacts.

What we collect

Contact, professional, recruitment, engagement, billing, technical, security and client matter information, plus sensitive information where necessary and lawful.

Why we use it

To respond to enquiries, provide and improve services, recruit and manage talent, secure our systems, meet legal obligations and communicate relevant updates.

Where it may be accessed

Primarily Australia and Sri Lanka. Information may also be processed by contracted technology and service providers in locations notified to you or described in relevant engagement documents.

Your choices

You may ask for access or correction, withdraw consent where processing depends on consent, opt out of marketing and raise a privacy complaint.

Contact

Email team@jurisa.com.au with “Privacy” in the subject line, or write to either Jurisa office listed at the end of this notice.

A practical note about client work

When Jurisa handles personal information contained in client files or systems, we commonly do so under the client’s instructions and engagement terms. The client’s own privacy notice may also apply. This notice does not override legal professional privilege, confidentiality obligations or client specific data handling requirements.

1. About this notice

This Privacy Notice describes how Jurisa Pty Ltd (Jurisa, we, us or our) collects, holds, uses, discloses and otherwise processes personal information and personal data. It applies when you use jurisa.com.au, contact us, engage or consider engaging our services, apply for a role, supply goods or services, attend an event, subscribe to communications or otherwise interact with us.

A more specific notice, contract, collection statement or client instruction may apply to a particular service, project, recruitment process or workplace relationship. Where there is an inconsistency, the more specific document will apply to the extent of the inconsistency and subject to applicable law.

We manage personal information in accordance with applicable privacy and data protection laws, including the Privacy Act 1988 (Cth) and the Australian Privacy Principles where they apply, and Sri Lanka’s Personal Data Protection Act, No. 9 of 2022, as amended by Act No. 22 of 2025, together with regulations, rules and directives as they come into operation. Sri Lanka’s framework is being implemented in stages; Jurisa applies the standards in this notice across its operations and will update the notice as the law develops.

In this notice, personal information and personal data mean information or an opinion about an identified individual, or an individual who is reasonably identifiable, whether the information is true or recorded in a material form.

2. Who we are and the role we perform

Jurisa Pty Ltd operates from Melbourne and Colombo. We provide Australian law firms and in house legal teams with flexible legal process outsourcing, in which a client briefs Jurisa on a defined work package, Jurisa manages the work process, and the completed output is returned to the client for review and use. We also provide Jurisa AI, a set of practical AI tools that assist with drafting, research, document review and other routine tasks.

When Jurisa determines how information is used

Jurisa is responsible for personal information collected through our website and for our own business activities, including enquiries, relationship management, recruitment, supplier management, billing, security, marketing and corporate administration.

When Jurisa acts under a client’s instructions

In many client engagements, the client determines the purpose and essential means of processing information in its matters, systems and workstreams. In that context, Jurisa may act as a service provider or processor and will handle the information according to the engagement terms, the client’s lawful instructions, applicable professional and confidentiality obligations, and relevant law.

Where you seek information about personal data held in a client matter, we may need to refer your request to the relevant client or coordinate our response with that client.

3. Personal information we collect

The categories below describe the information we may collect. The information required in a particular case depends on the nature of your interaction with Jurisa.

Clients, prospective clients and business contacts

  • name, work contact details, role, employer or firm, professional profile and preferred method of communication;
  • enquiry details, meeting notes, correspondence, relationship history and areas of interest;
  • proposal, engagement, due diligence, conflict, procurement, billing and payment information; and
  • feedback, survey responses, event attendance and communication preferences.

Client matter and service delivery information

  • documents, emails, contracts, datasets, research materials, instructions and work product supplied by or created for a client;
  • personal information about a client’s employees, customers, counterparties, suppliers, witnesses, advisers or other individuals contained in those materials;
  • matter metadata, task allocation, status, quality control and audit records; and
  • information held in client provided systems or approved Jurisa systems used to perform the engagement.

Candidates, referees and prospective personnel

  • CVs, cover letters, qualifications, professional admissions, skills, employment and education history, work samples and public professional profiles;
  • interview notes, assessments, availability, location, remuneration expectations and role preferences;
  • referee details and references, and information provided by recruiters or professional contacts;
  • identity, work eligibility, visa, background, qualification or criminal record checking information where relevant and lawful; and
  • information needed to consider adjustments, workplace safety or other employment related requirements.

Suppliers, contractors and advisers

  • business contact details, service history, contracts, insurance and compliance information;
  • banking, tax, invoicing and payment information; and
  • security, system access and performance records relevant to the services supplied.

Website, device and security information

  • IP address, browser and device type, operating system, pages viewed, links clicked, referring page, date and time information and approximate location derived from an IP address;
  • cookie identifiers, analytics data, preference settings and marketing interaction data, depending on your choices and our site configuration;
  • account, authentication and access logs where an online service or client environment is used; and
  • security alerts, audit logs and incident records.

Communications, meetings and events

  • emails, telephone calls, meeting notes, chat messages and collaboration records;
  • audio or video recordings and transcripts where we have provided notice and obtained consent where required; and
  • event registrations, attendance, dietary or accessibility requirements and photographs where relevant.

4. How we collect personal information

We collect personal information in a range of ways, including:

  • directly from you when you email, call, meet with us, apply for a role, provide documents, complete a form or engage with our services;
  • from your employer, firm, client or another person involved in a matter or business relationship;
  • from referees, recruitment agencies, professional networks and people who refer you to us;
  • from clients who provide documents or system access for service delivery;
  • from publicly available sources such as professional networking sites, company websites, registers and publications;
  • from service providers, including analytics, communications, recruitment, identity verification and security providers; and
  • automatically through cookies, server logs and similar technologies when you use our website or systems.

Where it is lawful and practicable, you may interact with us anonymously or using a pseudonym. This may not be possible where we need to verify identity, assess a candidate, enter into a contract, provide services, protect confidential information or comply with law.

If you provide personal information about another person, you must be authorised to do so and, where required, ensure that the person has received an appropriate privacy notice.

5. Why we use personal information

We use personal information where reasonably necessary for our functions and activities, including to:

  • respond to enquiries, arrange discovery calls, scope work and prepare proposals;
  • enter into, administer and perform client engagements and other contracts;
  • identify, assess, match, onboard, supervise and support legal professionals and other personnel;
  • deliver contract management, contract administration, legal research, paralegal, review, managed legal service and legal operations work;
  • operate approved AI assisted tools, collaboration platforms and quality control processes;
  • manage client, candidate, supplier and professional relationships;
  • conduct billing, payment, accounting, audit, insurance, risk and corporate administration;
  • maintain, protect, monitor and improve our website, facilities, devices, systems and service delivery;
  • prevent fraud, misuse, conflicts, security incidents and unauthorised access;
  • comply with legal, regulatory, contractual and professional obligations and respond to lawful requests;
  • establish, exercise or defend legal claims;
  • send relevant insights, event invitations and service information where permitted, with a clear opt out; and
  • create aggregated or deidentified analytics, benchmarks and service improvement insights.

Under Australian law, our collection, use and disclosure are governed by the purposes for which information was collected and the permissions and requirements in the Privacy Act and other applicable laws. Under Sri Lankan law, where the relevant provisions apply, processing may be based on consent, steps requested before or performance of a contract, legal obligations, employment related requirements, legitimate interests that do not override individual rights, protection of vital interests, public interest grounds, legal claims or another lawful basis.

Where we rely on consent, you may withdraw it as described in this notice. Withdrawal does not affect processing that was lawful before withdrawal, and we may continue processing where another lawful ground applies.

If we need information to enter into or perform a contract, verify identity, secure our systems or comply with law and you do not provide it, we may be unable to proceed with an enquiry, application, engagement or service.

6. Sensitive and special category information

Some information is considered sensitive under Australian law or a special category under Sri Lankan law. Examples may include health information, racial or ethnic origin, religious or philosophical beliefs, political opinions, trade union or professional association membership, sexual orientation, biometric or genetic information and criminal record information.

Jurisa does not seek sensitive information unless it is reasonably necessary and lawful for a specific purpose, such as recruitment adjustments, workplace health and safety, background screening, legal claims or client work. We obtain consent where required, limit access, and apply heightened confidentiality and security controls.

7. Client work, confidentiality and legal professional privilege

Client work may contain personal information about many individuals and may be confidential, commercially sensitive or subject to legal professional privilege. Jurisa handles that information only for the engagement and in accordance with client instructions, agreed protocols and applicable law.

  • Access is limited according to role, operational need and the principle of least privilege.
  • Jurisa personnel are subject to confidentiality obligations and receive privacy and security training.
  • Where preferred and technically feasible, work is performed inside client provided systems and environments.
  • Information is not used for Jurisa’s unrelated marketing or for another client’s work.
  • Nothing in this notice authorises a disclosure that would waive privilege or breach a duty of confidentiality.

Client responsibility

A client that provides personal information to Jurisa is responsible for ensuring it has a lawful basis and authority to provide the information and for giving any notices required from the client. Jurisa remains responsible for complying with the obligations that apply to it as a service provider, processor or controller.

8. AI assisted tools, automation and recorded meetings

AI assisted legal delivery

Jurisa uses vetted AI and technology tools to support activities such as contract review, drafting, summarisation, research, document review, workflow administration and quality assurance. AI is used to increase speed and consistency without replacing professional judgement. Outputs intended for client delivery are subject to qualified human review in accordance with the engagement model.

The personal information used with an AI or technology tool depends on the task, client instructions and tool configuration. We apply task selection, access controls, confidentiality requirements, provider due diligence and human review. We require service providers to handle information only for authorised purposes under applicable agreements and law.

Jurisa does not ordinarily make decisions about candidates, clients or other individuals solely by automated means where the decision would have a legal or similarly significant effect. If we introduce such processing, we will provide the transparency, human review pathways and safeguards required by applicable law.

Recordings and transcription

We may propose recording or transcribing a call, interview, training session or video conference for note taking, quality, training or service improvement purposes. We will provide notice before recording and obtain consent where required. You may decline a recording; we may instead take written notes or arrange another reasonable method.

9. How we disclose personal information

We do not sell or rent personal information. We may disclose it where reasonably necessary for the purposes in this notice to:

  • Jurisa personnel and authorised contractors in Australia and Sri Lanka;
  • clients and prospective clients, including candidate or professional profiles where relevant, lawful and consistent with the individual’s expectations or consent;
  • technology and operational service providers, such as hosting, cloud productivity, communications, CRM, recruitment, payroll, background checking, billing, document management, cyber security, analytics and AI providers;
  • professional advisers, auditors, insurers, bankers and consultants;
  • regulators, courts, tribunals, law enforcement bodies and other authorities where required or permitted by law;
  • a person involved in a complaint, dispute, investigation or legal claim; and
  • a prospective purchaser, investor, financier or successor in connection with a proposed or completed corporate transaction, subject to appropriate confidentiality safeguards.

We require contracted providers to protect personal information, use it only for authorised purposes and comply with applicable privacy, confidentiality and security requirements. Some providers may act as independent controllers for limited purposes, such as professional advice or legal compliance, and their own privacy notices may also apply.

10. Overseas access and cross border transfers

Jurisa’s delivery model uses professionals and operations in Colombo to perform outsourced work packages for Australian clients. Personal information and client information may therefore be accessed in, or disclosed between, Australia and Sri Lanka for recruitment, onboarding, supervision, service delivery, IT support, administration and related purposes.

Information may also be processed in other countries where contracted cloud, software, communications or professional service providers operate. Where practicable, the relevant locations will be identified in a collection notice, client agreement, security schedule, provider notice or other communication.

  • For disclosures from Australia, we take reasonable steps designed to ensure overseas recipients handle personal information consistently with the Australian Privacy Principles, including contractual controls, confidentiality obligations, access restrictions and security measures.
  • For cross border data flows involving Sri Lanka, we adopt the safeguards, instruments, consents or other transfer grounds required by the Sri Lankan PDPA as applicable and in force.
  • Where Jurisa personnel access data inside a client’s systems, the location, access model and controls are agreed with the client and documented where appropriate.

Privacy protections and enforcement mechanisms differ between countries. Please contact us if you need more information about the safeguards for a particular transfer.

11. Cookies, analytics and online technologies

Our website may use cookies, pixels, server logs and similar technologies to operate the site, remember preferences, understand usage, protect against misuse and improve content and performance. Depending on the site configuration and your choices, these may include:

  • strictly necessary technologies required for site operation and security;
  • preference technologies that remember selections;
  • analytics technologies that help us understand visits and interactions; and
  • marketing technologies used to measure communications or provide relevant content, where enabled and permitted.

You can manage cookies through browser settings and any cookie controls made available on the website. Blocking some cookies may affect functionality. Third party websites, plugins and links are governed by their own privacy practices, and Jurisa is not responsible for those practices.

12. Direct marketing and service communications

We may send business contacts information about Jurisa services, insights, events or opportunities where permitted by law and consistent with the context in which we obtained the contact details. We comply with applicable direct marketing requirements, including the Australian Privacy Principles and Spam Act 2003 (Cth), and Sri Lankan requirements for consent and opt out as they apply.

You may opt out at any time by using the unsubscribe option in a message or emailing team@jurisa.com.au. We will action the request within the period required by law. Even if you opt out of marketing, we may still send operational, security, billing, recruitment process or other service related communications.

13. Security and personal data breaches

Jurisa maintains administrative, technical and physical safeguards designed to protect personal and client information against misuse, interference, loss, unauthorised access, modification and disclosure. Measures are selected according to the nature and sensitivity of the information and may include:

  • secure, access controlled facilities and managed devices;
  • role based access, least privilege, strong authentication and multifactor authentication where appropriate;
  • encryption in transit and, where appropriate, at rest;
  • confidentiality undertakings, confidentiality agreements and personnel screening where appropriate;
  • privacy, confidentiality, cybersecurity and responsible AI training;
  • logging, monitoring, backups, patching, malware protection and incident response procedures;
  • vendor due diligence and contractual security requirements; and
  • secure retention, return, deletion and destruction processes.

No system or internet transmission can be guaranteed completely secure. You are responsible for protecting passwords and access credentials and for notifying us promptly if you suspect unauthorised access.

We assess suspected data breaches, take steps to contain and remediate them, and notify affected individuals and regulators where required. This includes the Australian Notifiable Data Breaches scheme where applicable and Sri Lankan breach notification requirements as they apply and come into force.

14. Retention, deletion and anonymisation

We retain personal information only for as long as reasonably necessary for the purpose for which it was collected, or as required or permitted by law, contract, client instructions, professional obligations, insurance, accounting, tax, audit, security, dispute management or limitation period requirements.

  • Client information is retained, returned, deleted or deidentified in accordance with the engagement terms and lawful client instructions.
  • Candidate information is retained for the recruitment process and may be retained for future suitable opportunities where lawful and consistent with the candidate’s expectations or consent.
  • Business relationship and supplier records may be retained while the relationship is active and for a reasonable period afterwards for administration, audit and legal purposes.
  • Technical, security and backup records are retained according to operational and incident response needs and are overwritten or deleted in the ordinary course.

When identifiable information is no longer required, we take reasonable steps to delete, securely destroy or irreversibly remove identifying details from it. Deidentified or aggregated information that no longer identifies an individual may be retained for analytics, service improvement and statistical purposes.

15. Your privacy rights and choices

Rights commonly available in Australia

Subject to applicable exceptions, you may ask for access to personal information we hold about you and ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading. You may also opt out of direct marketing and complain about how we have handled your information.

Rights under Sri Lanka’s PDPA

As the relevant provisions become operative and where they apply, rights may include access to personal data and processing information; withdrawal of consent; objection or a request to refrain from certain processing; rectification or completion; erasure in specified circumstances; review of a decision based solely on automated processing; and appeal or complaint to the Data Protection Authority of Sri Lanka.

How to make a request

Email team@jurisa.com.au with “Privacy Request” in the subject line and describe what you are requesting. We may ask for information reasonably necessary to verify your identity, authority and the scope of the request. An authorised representative may act for you where permitted by law.

We will respond within the period required by applicable law. We do not ordinarily charge a fee, but a reasonable fee may apply where permitted by law, for example for an excessive, repetitive or manifestly unfounded request. We may refuse or limit a request where the law permits, including to protect another person’s rights, confidential information, legal privilege, security, investigations or legal obligations. Where required, we will explain the reason and available review or complaint options.

16. Privacy complaints and regulators

Please contact Jurisa first if you believe we have mishandled personal information. Email team@jurisa.com.au with “Privacy Complaint” in the subject line and provide enough detail for us to investigate. We will acknowledge, investigate and respond within a reasonable period, and will keep you informed if the matter is complex or requires more information.

If you are not satisfied with our response, you may be able to contact:

  • Australia: the Office of the Australian Information Commissioner (OAIC) at www.oaic.gov.au; or
  • Sri Lanka: the Data Protection Authority of Sri Lanka at www.dpa.gov.lk, where its jurisdiction and applicable provisions permit.

You may also have rights to seek advice or remedies from another regulator, court, tribunal or dispute resolution body depending on the circumstances.

17. Children and young people

Jurisa’s website and services are directed to organisations and legal professionals, not to children. We do not knowingly collect personal information directly from children through the website. Client work may contain information about children; in that case, we handle it under client instructions and with safeguards appropriate to its sensitivity and the applicable law.

18. Changes to this notice

We may update this notice to reflect changes to our services, technology, operating locations, legal obligations or privacy practices. The current version will be published on our website with the date of the latest update. Where a change is material and additional notice or consent is required, we will provide it in an appropriate way.

19. Contact Jurisa

For privacy questions, requests or complaints, contact:

Entity
Jurisa Pty Ltd
Australia
Level 19, 180 Lonsdale Street, Melbourne VIC 3000, Australia
Sri Lanka
Level 35, West Tower, World Trade Center, No. 1 Bank of Ceylon Mawatha, Colombo 00100, Sri Lanka