Privacy Policy
Effective date: 23 August 2026
1. Who we are
This policy is issued by:
- Alvin Legal Pte. Ltd., UEN 202544292K, incorporated in Singapore; and
- Alvin Legal Pty Ltd, ACN 619 560 646, incorporated in Australia,
together "we", "us" and "our".
In this policy, personal data means information that identifies you, or that could identify you.
2. What we collect
When you contact us. Your name, email address, residential address, company, role, and whatever else you choose to tell us.
When we act for you. What we need to do the work and to meet our legal and professional obligations. That usually means your contact details, identity documents, date of birth, nationality, company and role, and information about the matter itself. Where we act for a company, we also collect information about its directors, shareholders, beneficial owners and staff, usually from the company rather than from those people directly.
Identity checks. For certain kinds of work, anti-money laundering law requires us to identify and verify our clients, and in some cases the people behind them. We collect only what those checks reasonably require, and we keep only what we need to show we ran them properly.
Sensitive information. Some of what we collect is more sensitive than the rest, such as your nationality or the result of a sanctions or politically exposed person check. We collect it only where you consent or the law requires or allows it, we handle it with extra care, and we use it only for the purpose we collected it for.
When you visit this website. We do not use tracking cookies, advertising cookies, identifying analytics or chat widgets. Our hosting provider keeps standard server logs, including IP addresses and browser types, for security and performance.
If you do not give us the information we ask for, we may not be able to act for you.
3. Why we collect it
We use your personal data to:
- respond to your enquiry;
- provide legal services, if you engage us;
- run conflict, identity, sanctions and anti-money laundering checks;
- manage our relationship with you, including invoicing;
- keep our records; and
- meet our legal, regulatory and professional obligations.
We do not use your personal data for marketing.
Some of these purposes continue after our work for you ends, because our record-keeping and professional obligations continue.
4. Who we share it with
We do not sell your personal data. We share it only:
- between our two companies, to the extent necessary to provide our services;
- with our service providers, such as those supplying our email, web, software, accounting and search services, under confidentiality obligations;
- with others involved in your matter, as the work requires and as you instruct, such as counterparties, opposing counsel and government agencies; and
- where the law requires or allows it, including to courts, regulators and law enforcement.
5. Where it goes
We store and process personal data in Singapore and Australia. Some of our software providers are in the United States of America.
When we send personal data to another country, we take reasonable steps to make sure the recipient protects it to a standard comparable to our own.
6. How we use technology
We use technology, including AI-assisted tools, to help us draft, research and manage files. We use enterprise versions of these tools, under contracts that keep our information confidential, and we switch off model training. Our information is not used to train anyone's AI models.
We do not use automated systems to make decisions that significantly affect you. A person makes every substantive decision on a matter.
7. How we keep it safe
We take reasonable administrative, technical and physical steps to protect your personal data from unauthorised access, use, disclosure or loss. No system, and no transmission over the internet, is completely secure.
If personal data we hold is lost, or is accessed or disclosed without authorisation, we will investigate, contain it, and fix what caused it. Where the law requires, we will notify the affected people and the relevant regulator as soon as practicable, and tell them what happened and what they can do about it.
8. How long we keep it
We keep personal data only as long as we need it for the purposes above, or as long as the law and our professional obligations require.
9. Your choices
Ask what we hold. You can ask for a copy of your personal data, and for how we have used or disclosed it in the past year.
Ask us to correct it. Tell us if something is wrong or out of date. We will fix it, or explain why we cannot.
Withdraw your consent. You can withdraw your consent to our use of your personal data at any time, by writing to our data protection officer.
Deal with us anonymously. You can read this website without telling us who you are. But we cannot act for you anonymously or under a pseudonym. Before we can act, we must know who our client is, to run conflict checks and, where the work requires it, to complete our anti-money laundering checks.
10. How to complain
If you are not happy with how we have handled your personal data, tell our data protection officer first, at enquiries@alvinlegal.com. We will look into it and respond as soon as we can, and in any event, within 30 days.
If you are not satisfied with our response, you may take your complaint to a privacy regulator: the Personal Data Protection Commission in Singapore, or the Office of the Australian Information Commissioner in Australia.
11. Changes to this policy
We may update this policy. The current version is always published on this website, with its effective date at the top.
12. Contact us
Please send any question, request or complaint about your personal data to our data protection officer at enquiries@alvinlegal.com.