Privacy Policy

Privacy Policy

Mental Health Legal Centre Privacy Policy

The Mental Health Legal Centre (referred to as “MHLC“, “we“, “us” or “our“) is a specialist community legal centre that provides professional services and assistance to people experiencing mental health challenges.

This privacy policy (Privacy Policy) explains how we will collect, use, disclose and handle your personal information. In the course of our business, we may need to gather and use information about you, such as your contact information and legal concerns.

By using our services or our website you consent to the collection, use, disclosure and transfer of your personal information as set out in this Privacy Policy.

Our Obligations

We must follow the Victorian Health Records Act 2001 (Vic) when we collect and manage health information. Even though we are not required to follow the Australian Privacy Principles in the Privacy Act 1988 (Cth), we still follow them when handling personal information. If you are our client, we also comply with our legal and ethical obligations to keep your information confidential. We will only share your information if you give us permission, except in special cases required by law.

What types of information do we collect?

We only gather personal information that is needed for our tasks or activities. The information that we collect about you will depend on the services you use.

If you are a client or ask for legal help, we need to gather some personal and sensitive information to provide our services. The information we collect about you may include:

  • identity and contact details. For example, your name, address, email, phone number, and birth date;
  • information about your financial situation. For example, your housing situation, job, financial status and income;
  • information about your background. For example, your family type, country of birth, race or ethnicity, year of arrival in Australia, language spoken at home, English proficiency, and need for an interpreter;
  • health information. For example, any disabilities;
  • criminal history; and
  • details of the services you have requested or been provided.

We might collect other personal or sensitive information if we give you or a client legal advice. This includes any personal or sensitive details that you or the client shares with us. Because of the kind of services we offer, we might need to collect sensitive information from our clients. “Sensitive information” includes details about your health, your race or ethnicity, your political beliefs, work or professional groups you are part of, your sexual preferences or activities, and any criminal record. We will only collect this sensitive information if you give us permission.

When you use our website, we might collect some information about how you are using it. This can include things like your internet address (IP address) and the location of the data centre your internet provider uses.

How do we collect personal information?

We prefer to collect personal information about you directly, with your permission. You don’t have to agree to share your personal information. However, if you choose not to agree, we might not be able to help you.

We will generally collect information from the following sources:

  • directly from you. This includes if you request or receive legal services from us, contact us, or visit our website. We may collect this information from you in-person, online, by email, or over the phone;
  • referrals from third parties. For example, if we receive information about you from a referring organisation or support person.

How do we use and disclose personal information?

Reasons we might collect, use, or share your personal information include:

  • to provide our services. This means we can give you advice, information, resources, refer you to other organisations, help with your case, or represent you. It also covers small uses and sharing of your information that happen as part of our usual work.
  • to communicate with you. For example, to respond to your enquiries, questions, requests and complaints relating to our services;
  • to follow the law. We may need to use or share your personal information to meet legal and regulatory requirements. If you do not provide us with the required personal information, we may not be able to offer our services or give legal assistance.

We might also use your personal information in a way that does not identify you, such as in anonymous, combined, or de-identified forms. For example:

  • for anonymous case studies. Our staff may compile anonymous case studies based on the experience of our clients. These are used to help explain our services and highlight the needs of our clients;
  • we gather usage data about people who use our Online Help web application. This includes details like how many users there are, what roles they have, and which areas of law they look at. This information helps us improve the web application, add more useful features, focus on the services most people need, and ask for extra funding to support these efforts to comply with out funding agreements. We are required to provide some de-identified information to funding agencies. We do not provide funding agencies with identifying information, such as your name or address;
  • to identify trends and changes in the demographics of people accessing our services. We might also use and share information that does not include any personal details to help us understand and explain who is asking for legal information and services.

We do not use your personal information for commercial marketing activities.

Who do we share your personal information with?

We may share your personal information with employees, volunteers, contractors or service providers for the purpose of providing our services.

Certain third parties may access your personal information. These include:

  • third parties who enable us to provide our services. For example, IT systems administrators, process servers, couriers, electronic network administrators and professional advisors (e.g. accountants, solicitors and barristers); and
  • government bodies, regulatory agencies, law enforcement or exchange bodies or courts. We only do this where we are required to do so by applicable law or regulation or at their request.

Where do we store your personal information?

We, along with our service providers, might keep your personal information in electronic records using cloud technology, other electronic methods, or in paper form.

All the personal electronic information we have is stored on servers in Australia. However, when we use cookies and web analysis on our website, some information might be stored or processed in other places, like the USA or the European Union. It is not practicable for us to specify in advance the location of every service provider or user who we deal with.

How do we protect your personal information?

We take reasonable steps to protect and secure your personal information from misuse, loss and unauthorised access, modification and disclosure.

We will only keep your personal information for as long as we need to, to do what we collected it for or to follow legal, regulatory, or internal rules. Once the matter is finished, we will close your file. We store closed files safely for the time required by law.

How can you access your personal information?

If you want to access the personal information we have about you, you can contact us any time using the contact details at the end of this Privacy Policy. If we have information that you have a right to access, we will try to give it to you in the way you ask. It is generally free to request access to your personal information. However, we may require you to meet any reasonable costs of providing you with access.

There may be instances where we cannot give you access to the personal information held. For example, if this would interfere with the privacy of others or if it would lead to a breach of confidentiality.

If you request access to your client files, the Principal Solicitor will look at the file first and decide which parts can be shared with you. They will approve any copies of the material before you are given access. You will only be able to see the specific parts of your client files that are allowed. We will respond to all requests for access correction within a reasonable time.

How can you correct your personal information?

We take reasonable steps to ensure that the personal information we collect, use and disclose is accurate, up to date, complete and relevant.

If you want to update or fix the personal information that we hold about you, you can contact us using the details at the end of this Privacy Policy.

If you ask us to change your information because it is wrong, outdated, incomplete, not relevant, or misleading, we will consider your request carefully. If we agree that the information needs to be fixed, we will take reasonable steps to correct it. If we do not agree that there are appropriate reasons for correction, then you may request that we add a note to your personal information stating that you disagree with the information. We will take reasonable steps to comply with your request.

We will respond to all requests for correction within a reasonable time.

How do we use cookies?

Sometimes, we might use cookies or other tracking tools on our website (called trackers). These trackers help us access and save information on your device when you visit or use our site. A cookie is a tiny file that a website stores on your device. It helps the website recognise you when you return and remembers details about how you used the site.

Our website uses Google Analytics to see how people visit and use our site. If you don’t want us to track your activity, you can turn off cookies or tracking tools in your browser or device settings. Some devices or browsers also have a quick way to disable tracking automatically.

The Online Help web application on our website does not use Google Analytics. Our Online Help web application uses Matomo Analytics cookies for research purposes. These analytics will capture information, such as the number of users, the user’s role (e.g. person with mental health challenges, family member, carer or referring organisation), and the areas of law viewed. Our Online Help web application uses session cookies, which is a cookie that only exists in temporary memory while you navigate our Online Help web application. Session cookies expire or are deleted when you close the web browser.

The Inside Access web application does not use Google Analytics. Our Inside Access web application uses session cookies, which is a cookie that only exists in temporary memory while you navigate our Inside Access web application. Session cookies expire or are deleted when you close the web browser.

How do we change our Privacy Policy?

We may change or update parts of this Privacy Policy from time to time. For example, to ensure this Privacy Policy is consistent with law or our information collection practices. If we change our Privacy Policy, we will update it on mhlc.org.au/privacy-policy.

How can you make a complaint?

If you have a complaint or question about the way in which we have handled any privacy issue, please contact us. This can be done by email using the subject line “Privacy Complaint” to mhlc@mhlc.org.au or by calling us on (03) 9629 4422.

We treat all complaints confidentially. Once your complaint has been received, we will aim to investigate and respond to your complaint within 30 days.

If you are not satisfied with how we manage your complaint, you may contact the Office of the Australian Information Commissioner. The OAIC can be contacted at GPO Box 5218 Sydney NSW 2001 or oaic.gov.au.

How can you contact us?

If you have any questions about our Privacy Policy or how we handle your personal information, please contact our Manager via email at mhlc@mhlc.org.au or by phone on (03) 9629 4422.

The Privacy Policy was last updated on the 14th of October 2025.