Little William Bourke

BarNetwork Pty Ltd

ABN 32 092 121 198

Little William Bourke Pty Ltd

ABN 65 610 951 089

Level 22, 52 Martin Place, Sydney NSW 2000

Telephone 02 9151 2202

Facsimile 02 9237 0801

michael.green@openlaw.com.au

11 October 2022

Information about our JADE® and OpenLaw Customer Content

The safety and security of the private information you provide to us is at the core of our information management practices and the design of our systems.

Executive Summary. BarNet has designed its systems from the ground up to enhance privacy and confidentiality. We only collect relevant information needed to provide services to you or to ensure the safety of our systems. We encrypt data at rest and in transit. We store data and operate servers in Australia. You own any customer content you provide and can export it from our systems.

When you choose to upload content, we only use that content for the purpose of providing you analysis based upon our JADE legal research platform and including it in your JADE personal document library. The uploaded content is only available to you and stored in an encrypted format. You can grant access to others on the ‘My JADE’ page. You may revoke this access at any time. BarNet has no access to this material.

You may turn off this feature, so that uploaded content is not stored and deleted after analysis either permanently or on an upload-by-upload basis. Enterprise account administrators can set different defaults for users within their organisation according to their policies.

What is Customer Content? When you interact with JADE®, Jasmine™, the Victorian Reports, and our other OpenLaw services, you can do so by typing a search request (Search Request), uploading a document (Document Upload), clicking on a link we provide to you on the page on in material we send you by email (Link Activation), or by annotating content to which you have access (User Annotation) which we call JadeMarks™.

Cases, Statutes, and documents viewing history. Regardless of the way you obtain access to JADE, by default, we do not store a record of the cases, statutes, or documents you view. If you turn on your document viewing history, your search history is available only to you: the history is stored securely encrypted in your user account with your unique user key.

If you chose to click through to JADE using Link Activation, we may pass information in the URL which assists us to provide you with access to public content on JADE and which permits us to validate your access request and improve your JADE user experience.

Is my search history recorded? By default, by popular demand of our users, search history is available in a user's ‘My JADE’ page. Your search history is available only to you. It is encrypted. You may turn off search history in a user's ‘My JADE’ page. BarNet has no access.

Saved searches. In addition to your search history, you may choose to save certain searches you regularly perform as ‘saved searches’. You may also share saved searches with a group you have created. You may revoke access you granted at any time. You can name saved searches using your own terminology or code words understood only by you. Your saved searches are stored encrypted in your user account with your unique user key. BarNet has no access.

What happens when you choose to upload a document? When you choose to upload content, through document upload, we only use that content for the purpose of providing you analysis based upon our JADE legal research platform. This appears in your JADE personal document library marked up with the results of our analysis. The uploaded content is only available to you. By default, only you have access to the resulting analysis. You can grant access to others on the ‘My JADE’ page. You may revoke access you granted at any time. BarNet has no access to this material. If you prefer, you can turn this feature off in the ‘My JADE’ page. You may also turn off the feature on an upload-by-upload basis. You may also delete documents you have uploaded in the ‘My JADE’ page.

By default, uploaded documents which are stored are available to our search system, but only returned in results to you. You may make them invisible to the search system or only accessible if you enter an additional password. These additional restrictive choices are available to all users.

As a further confidentiality precaution, some users tell us that they upload draft content after anonymising or deleting some of the content in the upload. Users may find this useful where they need JADE to analyse the case and legislation citations without needing a complete document.

Group access in Enterprise JADE Professional. If you have an enterprise JADE professional subscription, and you grant group access to a document, your organisation's administrator can set the people within your organisation that may have access to content shared within that group. You and your organisation's administrator may revoke access granted at any time. If you leave the organisation, your organisation's administrator may retain content you shared or reallocate that content to a different owner. BarNet has no access to this process.

We make no other use of the documents you upload. We do not analyse or extract information from the documents you provide otherwise than to provide analysis to you about those documents. We do not apply any machine learning or AI techniques or any other modelling to collect or aggregate information. If you provide us with feedback or ask us for assistance – for example – by sharing a document with us for us to improve our upload or analysis process, you can only do this by a support request, by explicitly and separately providing the document to us.

What happens when I annotate a document? A key feature of JADE is the ability of a user to annotate a document by marking it up or providing comments or tagging – we call these JadeMarks™. By default, JadeMarks are private to you. They are encrypted at rest and in transit. By default, they are available to our search system, but only returned in results to you. You can tag documents and make comments which can be understood only by you. For further confidentiality, you may make JadeMarks invisible to the search system or only accessible if you enter an additional password. These additional restrictive choices are available to all users.

Group access to JadeMarks in Enterprise JADE Professional. As with documents, you may also share JadeMarks with a group. Your organisation's administrator has the same level of control as for documents: that is if you share content with an enterprise group, they can set the people within your organisation that may have access to content shared within that group. You and your organisation's administrator may revoke access granted at any time. If you leave the organisation, your organisation's administrator may retain JadeMarks you shared or reallocate that content to a different owner. BarNet has no access to this process.

What about backups? As you would expect, BarNet backs up data stored on its systems at regular intervals using an automated process to ensure the resilience of its systems. By default, this includes Customer Content. Because your own Customer Content is encrypted with your unique key, as with the information originally stored, so too with the backed-up material, no one at BarNet has access to this material. We keep encrypted snapshots of backed-up material at regular intervals. This information is securely stored in Australia. If you delete your JADE account, the backed-up information we store will eventually disappear from our systems. Enterprise administrators can request that Customer Content be not backed up. When actioned, no backups are taken of this excluded Customer Content.

What happens when I delete my account? If you delete your JADE account, Customer Content is irretrievably deleted (this includes documents, annotations, search history, saved searches, document viewing history (if enabled), and all other Customer Content). Any information replicated on our systems (apart from backups which we address below) is simultaneously deleted. If you are a member of a JADE Enterprise User account, the account is owned by the Enterprise and can only be deleted by your organisation's account administrator.

Operational information we collect. Apart from logging the IP addresses from which you gain access to our systems, session information using a ‘session cookie’, information provided by your browser about its capabilities, and the URL which you are attempting to access, we do not log any further information. You may gain access to content by making a request using a URL which contains search information (Extended URLs) or provides a link to a particular document in JADE (Article URLs). If you do so, we do not store that information beyond short-term storage for system integrity. We do not use that information in any other way. For example, we do not indicate the popularity of any Extended URLs or Article URLs and we will never use them to make suggestions or recommendations to any JADE users. We use Google Analytics through providing a cookie but we do not share that data. We do not host any advertising.

System information. In addition to operational information, we operate systems which generate automatic logging information which we use to ensure that our systems are operating normally and securely. We use this logging information solely for system integrity and technical performance management and tuning purposes. We perform analysis of it and only retain this automatic logging information for a period less than 14 days and usually less than 7 days. After that time, the information is deleted. The automatic logging contains no Customer Content beyond the information we discussed in ‘operational information’ in the previous paragraph.

Can I export my annotations and any of my Customer Content. Yes, you can. You can do this from the ‘My JADE’ page. The information can be exported as a PDF as well as in word and other formats. Because the Link Activations you receive are specific to JADE and may be time-limited, we do not provide a facility to export those URLs. The search terms used in your saved searches are specific to JADE, but can be exported.

Do we have ISO 27001 certification? We are working towards obtaining ISO 27001 certification. We have implemented policies and processes based on ISO 27002.

Require more information or have suggestions? If you are a customer of BarNet or Little William Bourke and have further questions, please feel free to reach out to our support team by email to help@openlaw.com.au. Also see more information at https://openlaw.com.au/security.

Michael Green SC

Director

11 October 2022

BarNet LWB InfoSec 221011v9 FINAL.docx

Last printed: 11 Oct 2022 (@11:05)