Privacy and trust
How MatterPath handles sensitive legal information
A practical explanation of how MatterPath limits collection, organises legal-matter information and gives consumers control before identifying details are disclosed to a selected firm.
Quick answer
The short version
MatterPath collects information needed to organise an assessment, produce a factual summary, support deterministic matching and operate the account. Legal-matter information can be sensitive, so the platform asks for separate active consent before collecting relevant sensitive information and again before identifying information is disclosed to a selected firm. Information entered into MatterPath is not automatically protected by legal professional privilege. MatterPath uses service providers and reasonable technical and organisational safeguards, but no online service can guarantee absolute security. Read the full Privacy Notice and current service-provider schedule for the legally operative detail.
Official context: Australian Privacy Principles
This guide explains the workflow, not the whole Privacy Notice
This guide is a plain-English overview of common privacy questions that arise when using MatterPath. It is not a replacement for the Privacy Notice, which explains the categories of information, purposes, disclosures, retention approach, privacy rights and complaint process in fuller detail. The service-provider schedule identifies current provider roles and any verified location information available to MatterPath.
Legal-matter information may reveal sensitive information, including health information, racial or ethnic origin, political or religious views, trade-union membership, sexual orientation or practices, biometric information used for identification, or a criminal record. It may also include personal information about children, witnesses, family members, opponents or professionals. The exact content depends on what the consumer chooses to enter.
MatterPath is operated by WD Ventures Pty Ltd and is not a law firm. Privacy obligations, confidentiality and legal professional privilege are different concepts. MatterPath applies its privacy controls to platform information, but using MatterPath does not itself create a lawyer-client relationship or make every communication privileged.
Collection and data minimisation
The Australian Privacy Principles require an organisation covered by the Privacy Act to collect personal information only where it is reasonably necessary for its functions or activities. Sensitive information generally requires consent unless a legal exception applies. OAIC guidance also treats proportionality and data minimisation as part of assessing what is reasonably necessary.
MatterPath's assessment asks structured questions to identify the legal category, jurisdiction, practical needs and matching preferences. A free-text answer should contain enough factual context to organise the matter, not every fact or document a future lawyer might eventually need. Avoid passport numbers, full account details, unnecessary health records, intimate material and unrelated third-party information.
A consumer can usually provide more detail directly to a selected firm after the firm has completed initial checks and provided a suitable channel. The fact that information is publicly available elsewhere does not mean MatterPath should collect it without regard to necessity, fairness and the person's reasonable expectations.
Separate consent for collection and disclosure
OAIC guidance says valid consent should be informed, voluntary, current and specific, and given by a person with capacity to understand and communicate it. Merely presenting a privacy notice does not necessarily establish consent to collect sensitive information. MatterPath therefore uses an active, separate consent step before relevant sensitive legal-matter information is collected through the assessment.
A second decision occurs before identifying information is sent to a firm. The consumer reviews the organised summary, chooses a firm and expressly authorises the identified disclosure. Consent is not bundled with starting the assessment, viewing a profile or receiving a suggestion. A firm does not receive identifying information merely because it participates or pays MatterPath.
The consent screen should identify what will be sent, to whom and for what purpose. Consumers should correct factual errors and remove unnecessary details where the workflow permits. If a person does not authorise disclosure, the identifying introduction payload should not be released through that workflow.
Summary, matching and consumer choice
Assessment answers are organised into a factual MatterPath summary. The consumer can review and correct context before matching. The summary is not legal advice, an assessment of merit or a prediction. Translation features are intended to assist understanding, but translated text should be checked against the English source where precise meaning matters.
Deterministic matching uses stated consumer requirements and verified professional-profile information. Relevant factors may include practice area, jurisdiction, service location, consultation mode, language and availability. Commercial payment must not override suitability. A recommendation reason should explain the matching factors without claiming that the firm is objectively best or that it will accept the matter.
The consumer chooses whether to proceed and which firm may receive identifying information. A participating firm then independently considers conflicts, professional scope, capacity and engagement requirements. A suggestion or authorised introduction does not make the firm the consumer's lawyer.
Disclosure payloads and document sharing
A privacy-minimised preview can help a selected firm decide whether the matter appears within its general service scope without exposing unnecessary identity details. Identifying information should be limited to the authorised payload and released only after the consumer's active choice. The exact workflow and any exception must be described consistently in the current Privacy Notice.
Documents can contain hidden metadata, signatures, identity numbers, children's information or facts about other people. Do not upload an entire file merely because it may eventually be relevant. Keep originals secure, use working copies where appropriate, and follow the selected firm's instructions about secure transfer after conflict and engagement checks.
Once information is disclosed to a selected independent law firm, that firm handles it under its professional and privacy obligations. MatterPath's Privacy Notice should explain the boundary between MatterPath and independent recipients. Consumer authorisation does not guarantee that the firm will accept the matter or that privilege applies to every pre-engagement communication.
Service providers and overseas processing
MatterPath relies on service providers for functions such as hosting, database and authentication, email delivery, payments and controlled artificial-intelligence features. The current service-provider schedule should identify each provider's role and the categories of information involved. Providers should receive only the access needed for the contracted function.
An Australian organisation can have obligations when personal information is disclosed to an overseas recipient. OAIC guidance on APP 8 explains a reasonable-steps and accountability framework with legal exceptions. Hosting, support access and sub-processors can make location analysis more complex than the provider's headquarters or the selected cloud region.
MatterPath should not claim that all information remains in Australia unless the full provider configuration and sub-processing chain have been verified. Where countries or processing locations have not yet been confirmed, the service-provider schedule should say so plainly and be updated after verification rather than guessing.
Security, retention and deletion limits
OAIC guidance requires reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. What is reasonable depends on the information, organisation, risks and available measures. MatterPath uses technical and organisational safeguards appropriate to the service, but no website, database, email or third-party system can promise complete security.
Useful safeguards include role-based access, server-side authorisation, encryption in transit, controlled secrets, audit records that avoid legal detail, secure development practices and provider review. Public descriptions should remain at a level that helps users understand protection without exposing operational detail that could increase attack risk. Security claims should be accurate, testable and reviewed when systems change.
Personal information should not be kept indefinitely merely because storage is available. MatterPath's full Privacy Notice describes its documented retention approach, including account, matter, consent, matching, introduction, billing, security and legal records. A deletion request may not require immediate deletion of every record where retention is authorised or required, needed for security, necessary to establish or defend legal rights, or technically subject to a defined backup cycle.
Access, correction, withdrawal and complaints
A person can use MatterPath's privacy-request process to ask for access to, correction of or deletion of personal information. Identity verification may be necessary before information is released or changed. Access and deletion rights can have lawful exceptions, and the Privacy Notice explains how MatterPath responds and communicates any refusal where required.
Consent can be withdrawn for future handling covered by that consent. Withdrawal does not necessarily reverse a disclosure already authorised, erase a law firm's independent record, or require deletion of information that may lawfully be retained. MatterPath should explain the practical effect of withdrawal at the point it is requested rather than promising that every copy can be recalled.
Privacy concerns should first be raised with MatterPath using the contact and complaint process in the Privacy Notice. The Office of the Australian Information Commissioner generally expects a person to complain to the organisation first. If the response is delayed or unsatisfactory, the person may be able to lodge a complaint with the OAIC.
Before entering or sharing sensitive information
Use this check to reduce unnecessary collection and make an informed disclosure choice.
- Read the collection notice and the current Privacy Notice
- Describe the legal issue factually without including unnecessary identity numbers
- Avoid unrelated health, financial, intimate, child or third-party information
- Review the generated summary and correct errors before matching
- Check the selected firm's identity, service details and recommendation reason
- Read the disclosure payload and confirm exactly what will be sent
- Use the firm's secure channel for documents requested after initial checks
- Do not assume information entered into MatterPath is legally privileged
- Review the current service-provider schedule for processing information
- Use the privacy-request process for access, correction, withdrawal or complaints
Privacy controls at key MatterPath stages
| Stage | MatterPath control | Consumer check |
|---|---|---|
| Start an assessment | Active consent before relevant sensitive information is collected | Read the collection notice and enter only information needed for the assessment |
| Create a summary | Structured factual organisation with a consumer review step | Correct factual errors and remove unnecessary third-party or identity detail |
| Calculate matches | Deterministic criteria separate from commercial payment | Review the reason given and independently check the professional profile |
| Select a firm | Separate, specific authorisation for the stated disclosure payload | Confirm the recipient and exactly what identifying information will be sent |
| Continue with a firm | The firm makes its own conflict, capacity and engagement decision | Ask for the firm's privacy, secure-document and engagement information |
| Exercise a privacy choice | Documented access, correction, withdrawal, deletion and complaint process | Understand identity checks and any lawful retention or refusal reason |
Common questions
Frequently asked questions
Is information I enter into MatterPath legally privileged?
Not automatically. MatterPath is not a law firm and using the platform does not itself create a lawyer-client relationship. Privilege can depend on the communication, purpose, recipient and circumstances.
Does a law firm see my identity as soon as it appears in a match?
No through the described consumer workflow. You review the summary, select a firm and expressly authorise the stated identifying disclosure. Read the consent screen to confirm the recipient and payload.
Does MatterPath guarantee that my information is completely secure?
No online service can guarantee absolute security. MatterPath uses reasonable technical and organisational safeguards and reviews its controls, while explaining material limitations in its Privacy Notice.
Is all MatterPath information stored only in Australia?
Do not assume that. MatterPath uses service providers, and hosting, support and sub-processing locations can vary. Review the current service-provider schedule and Privacy Notice for verified information.
Can I withdraw consent after authorising a disclosure?
You can request withdrawal for future handling covered by the consent. Withdrawal may not reverse a disclosure already made, remove an independent firm's record or require deletion of information lawfully retained. Contact MatterPath through the privacy-request process.
How do I correct information or make a privacy complaint?
Use MatterPath's privacy-request and complaint process described in the Privacy Notice. MatterPath may verify identity before providing access or making changes. If a privacy complaint is not resolved, the OAIC explains when and how a complaint may be lodged with it.
Verified references
Sources and official help
These official resources were checked on 26 August 2026. Use the linked service for its latest information.
- Australian Privacy PrinciplesOffice of the Australian Information Commissioner
- Chapter B: Key concepts, including consent and sensitive informationOffice of the Australian Information Commissioner
- APP 3: Collection of solicited personal informationOffice of the Australian Information Commissioner
- APP 8: Cross-border disclosure of personal informationOffice of the Australian Information Commissioner
- APP 11: Security of personal informationOffice of the Australian Information Commissioner
- Lodge a privacy complaint with usOffice of the Australian Information Commissioner