×

our privacy policy

Updated 31/7/26

1. Introduction

Your privacy is important to Muir + Partners Limited (“Muir + Partners”, “we”, “us” or “our”). We are committed to protecting your personal information in line with the Privacy Act 2020 and the Information Privacy Principles (as amended or replaced from time to time). Where we use biometric technology to verify your identity, we also comply with the Biometric Processing Privacy Code 2025 (see ‘Biometric information and identity verification’ below).

This policy explains what information we collect, how we use it, when we may share it, and the steps we take to protect it. By using our website, completing the APLYiD application, providing us with information, authorising someone else to provide us with information on your behalf, or receiving our services, you agree to this policy.

2. Information we collect

We may collect personal information about you in the ordinary course of our work.  The personal information we collect will vary depending on the nature of the services we provide and the extent of your dealings with us. It may include (but is not limited to):

  • Your name, phone number, date of birth, email, postal or physical address, occupation and telephone numbers.
  • Copies of identification documents such as passports or driver’s licences (NZ or overseas).
  • Biometric information, such as a facial image or short video, collected when you complete identity verification through APLYiD.
  • Customer due diligence information (including source of funds).
  • Bank account details.
  • Health information.
  • Records of our interactions with you, including written and verbal interactions and instructions and meeting notes.

3. How we collect information

We collect information in different ways, for example:

  • Directly from you including:
  • through APLYiD when you click on a link to complete the APLYID verification process on your phone, computer or other device.
  • when you complete forms on our website or in hard copy.
  • when you deal directly with our staff or contractors.
  • Indirectly from third parties including from:
  • other law firms when we uplift your files (such as when you transfer your legal work to us).
  • law firms whose practice or client files we have acquired (including Witten-Hannah Howard and Morton Tee).
  • service providers or other third parties.
  • publicly available sources.

4. Biometric information and identity verification

As part of verifying your identity, we may collect biometric information about you – for example, a facial image or short video captured when you complete identity verification through APLYiD. This is regulated separately under the Biometric Processing Privacy Code 2025 (the Biometrics Code), made under the Privacy Act 2020.

We collect biometric information to verify the identity of the persons we act for, for the purposes of completing customer due diligence under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009.

If you are not able or do not wish to complete identity verification through APLYiD, please contact us to discuss an alternative way of verifying your identity.

APLYiD processes biometric information on our behalf. APLYiD is a New Zealand-based provider and does not retain the facial image or video used to verify your identity beyond a short period after verification is complete.

We retain the verification outcome document, which includes a still image taken from the verification, as part of our anti-money laundering records. We keep this for at least five years from the end of our relationship with you or the relevant transaction, as required under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009. We do not download or retain the verification video itself.

We only use your biometric information to verify your identity. We do not use it to assess your health, emotional state, age, or any other characteristic.

You have the same rights of access and correction over your biometric information as over any other personal information we hold about you – see ‘Your rights’ below.

5. Indirect collection and your right to be notified

Where we collect your personal information from a source other than you (indirect collection), we are required under Information Privacy Principle 3A to take reasonable steps to ensure you are made aware of:

  • The fact that your personal information has been collected;
  • The name and contact details of Muir + Partners as the agency collecting and holding the information;
  • The purposes for which the information is being collected;
  • Any law that authorises or requires the collection; and
  • Your rights to access and correct your personal information.

In practice, this obligation commonly arises in the following situations:

  • File uplifts from previous law firms: When you transfer your legal work to us and we receive your file from your previous solicitors, we will notify you that we have received your file and personal information from that firm.
  • Firm acquisitions: Where Muir + Partners acquires another law firm (or its client files), and your personal information is transferred to us as part of that acquisition, we will take reasonable steps to notify you of that transfer and the purposes for which we hold your information.
  • Other third-party sources: Where we receive personal information about you from service providers, other agencies, or publicly available sources in circumstances where you would not reasonably expect this, we will notify you unless an exception applies.

Notification will generally be provided by letter, email, or through our privacy policy and engagement communications. In some cases, notification may not be required – for example, where you have already been made aware of the collection, or where notification is not reasonably practicable. Where we rely on an exception, we will document our reasoning.

We will comply with these obligations for all personal information collected indirectly on or after 1 May 2026.

6. Why we collect and use information

We collect and use your information mainly to:

  • Carry out client due diligence under the Anti-Money Laundering and Countering Financing of Terrorism Act 2009 including to check your identity.
  • Deliver our legal and trustee services.
  • Promote our services (where the law allows).
  • Meet our obligations to government agencies and regulators.
  • For any other purpose you agree to.

If you choose not to provide us with information, or give us incomplete or inaccurate information, we may not be able to provide our services to you.

7. Who we share information with

We only share your personal information where it is necessary for our business or where the law allows. This may include sharing your personal information with:

  • Service providers such as APLYiD who help us with client due diligence and identity verification.
  • Other third parties we work with to provide services to you (for example we may need to share personal information with your bank when are acting for you on the sale of a property and discharge of a mortgage from the record of title to your property);
  • Government agencies, regulators, law enforcement or the courts where required or permitted by law.
  • Anyone else you authorise us to share information with.

We will not share your banking details (such as account numbers) unless required by law or with your consent.

We do not share your biometric information other than with APLYiD for the purpose of verifying your identity, or as otherwise permitted or required by law.

8. How we protect your information

We take reasonable steps to protect your personal information from unauthorised access or misuse. Information is stored on secure servers in New Zealand and Australia with protections such as encryption, firewalls, and password controls. If we no longer need your information and are not required by law to keep it, we will securely destroy it or remove identifying details. If you believe there has been any unauthorised access or a breach of security, please contact us immediately at admin@muirpartners.co.nz.

Biometric information is processed by APLYiD within New Zealand and is protected by APLYiD’s own security safeguards, which we review from time to time as part of our due diligence on service providers.

9. Your rights

You have the right to:

  • Ask for access to the personal information we hold about you.
  • Ask us to correct or update any information you believe is wrong.
  • Withdraw consent where we rely on it to collect, use or disclose your information.

We may charge a reasonable fee to provide access to information.

These rights apply equally to your biometric information under the Biometrics Code.

10. Questions and complaints

If you have any questions about this policy, want to exercise your rights, or have a complaint about how we have handled your information, please contact our Privacy Officer:

Email: admin@muirpartners.co.nz
Phone: +64 9 489 9029
Privacy Officer, Muir + Partners Limited,
Ground Floor, 129 Hurstmere Road, Takapuna, Auckland 0622
Post: PO Box 33825, Takapuna, Auckland 0740

We will work with you to resolve any concerns as quickly as possible. If you are not satisfied, you can contact the Office of the Privacy Commissioner at www.privacy.org.nz. This includes any concerns about our handling of your biometric information under the Biometrics Code.

11. Changes to this policy

We may update this Privacy Policy at any time. The latest version will be available on our website and will apply from the date it is published.

Auckland Legal Services

Copyright © 2026 All Rights Reserved.