Privacy Policy
Murji Legal Professional Corporation, operating as Murjis ("Murjis", "we", "us"), is a law firm licensed by the Law Society of Ontario. This policy explains what personal information we collect, why we collect it, who we share it with, how long we keep it and how you can reach us about it.
1. Two sets of protections
If you are a current, former or prospective client, information you give us is protected by solicitor-client privilege, by our duty of confidentiality under the Law Society of Ontario's Rules of Professional Conduct, and by privacy law. Those professional duties are broader than privacy law and apply whether or not the information is personal information.
If you are not a client, for example a website visitor, a counterparty, a service provider or a job applicant, your personal information is protected by privacy law, principally the federal Personal Information Protection and Electronic Documents Act (PIPEDA) and, where they apply, provincial privacy laws including Quebec's Law 25 and the Alberta and British Columbia Personal Information Protection Acts.
2. Information we collect
From prospective clients
Name, business contact information, the company you represent, and whatever you choose to tell us about your situation when you book or attend a consultation, or write to us.
From clients and in the course of a mandate
- Contact and identification information for you and for the individuals we deal with at your company
- Corporate records, contracts, policies, board and shareholder materials, and other documents you provide or that we create for you
- Information about individuals contained in those materials, including employees, directors, officers, shareholders and counterparties
- Identification collected to satisfy the Law Society's client identification and verification requirements, which can include government-issued identification
- Billing information and payment records
From website visitors
Our hosting provider records standard server information when a page is requested, including IP address, browser type, referring page, pages viewed and time of request. We use this only to operate and secure the site.
3. This website
We want to be specific rather than generic about what this site collects.
- Advertising and measurement cookies. We use Google Ads conversion tracking to measure whether our advertising leads to booked consultations. Google sets cookies on your device and receives your IP address, browser information and the pages you visit on this site. We use this only to measure advertising performance. Google's handling of that information is governed by its own privacy policy, and you can opt out of personalised advertising through Google's Ads Settings.
- No forms. There is no contact form or account on this website. You reach us by email or by booking a consultation.
- Fonts. Typefaces are loaded from Google Fonts, which means Google receives your IP address and browser information when a page loads. Google's handling of that information is governed by its own privacy policy.
- Booking. Consultation booking links open Cal.com, a third-party scheduling service. Information you enter there is collected by Cal.com under its own privacy policy and shared with us so we can hold the appointment.
- Links. Links to LinkedIn and other third-party sites are outside our control and are governed by those sites' policies.
If we later add further analytics, a contact form or additional tracking, we will update this policy before doing so.
4. Why we collect it
- To respond to enquiries and assess whether we can act, including running conflicts checks
- To provide legal services and perform our engagement with you
- To meet the Law Society's client identification, verification and file-keeping requirements
- To bill for services and maintain accounting records
- To manage, secure and improve our systems and this website
- To comply with legal, regulatory and professional obligations
- To send you information about our services where you have asked to receive it
We do not sell personal information. We use advertising measurement only to understand whether our own advertising is working, as described in section 3.
5. Consent
We collect, use and disclose personal information with your consent, which may be express or implied depending on the sensitivity of the information and the circumstances. Retaining us to act implies consent to the collection, use and disclosure of personal information necessary to carry out the engagement. Where we intend to use personal information for a new purpose, we will identify that purpose and, where required, obtain consent first.
You may withdraw consent at any time, subject to legal and contractual restrictions and reasonable notice, by writing to our Privacy Officer. Withdrawing consent may prevent us from continuing to act for you, and does not affect our obligation to retain the client file as described in section 10.
We may collect, use or disclose personal information without consent where privacy law permits or requires it, including where necessary to investigate a breach of an agreement, to comply with a subpoena, warrant or court order, or to collect a debt owed to us.
6. Who we share it with
We share personal information only as needed to act for you or to run the practice:
- Lawyers and staff at Murjis working on your matter
- Agents we retain on your matter, such as local counsel, experts, or a registry service, where you have instructed us or where it is necessary to carry out the engagement
- Counterparties, courts, tribunals and regulators, where the engagement requires it
- Service providers who process information on our behalf under contract, listed in section 7
- Our professional liability insurer, our auditors, and the Law Society of Ontario, where required
- A purchaser or successor of the practice, in connection with a business transaction, subject to appropriate confidentiality obligations and the Law Society's rules
7. Information processed outside Canada
Some of our service providers store or process information outside Canada, principally in the United States. Information stored in another country is subject to the laws of that country and may be accessible to its courts, law enforcement and national security authorities. We select providers that offer appropriate protection and we contract with them to protect the information.
| Provider | Purpose | Location |
|---|---|---|
| Google Workspace | Email, calendar, document storage | Canada / United States |
| Netlify | Website hosting | United States |
| Cal.com | Consultation booking | United States |
| Google Ads | Advertising measurement | United States |
| Anthropic | AI processing (see section 8) | United States |
| Supabase | Client portal database and document storage | Canada |
| Stripe | Payment processing | Canada / United States |
This list reflects the providers in use at the effective date of this policy and is kept current. We do not store payment card numbers; card details are handled by our payment processor.
8. Artificial intelligence
We use AI tools in our practice, and we would rather tell you exactly how than leave it to be discovered.
- AI assists with first-pass drafting, document review and summarizing. A lawyer reviews, corrects and approves every deliverable before it reaches a client. Nothing goes out on machine output alone.
- Client information processed through these tools is not used to train public AI models. Our agreements with our AI providers prohibit it.
- AI processing takes place on servers in the United States, as noted in section 7.
- We do not use AI to make decisions about individuals that produce legal or similarly significant effects.
- Where AI has materially assisted a deliverable, we say so. Our use of these tools follows Law Society of Ontario guidance on technological competence and supervision.
If you would prefer that we not use AI tools on your matter, tell your lawyer and we will accommodate that request.
9. How we protect it
We maintain physical, technical and administrative safeguards appropriate to the sensitivity of the information, including encryption in transit and at rest, access limited to those who need it, multi-factor authentication on our systems, encrypted devices and backups, vendor review before a tool touches a client file, and cyber liability insurance. No system is perfectly secure, and information sent to us by ordinary email travels without end-to-end protection; tell us if you would prefer a secure channel for a particular document.
10. How long we keep it
We keep two categories of information on different schedules.
The client file. Executed documents, advice, correspondence, engagement records and billing records form the client file. As a law firm we are required to retain it, generally for at least ten years after the matter closes, and longer for certain corporate, trust and real estate records. We cannot delete the client file on request, and we will tell you so if you ask. You may request a copy of your file at any time.
Everything else. Enquiries that do not become matters, marketing correspondence and general website server logs are kept only as long as needed for the purpose collected, and server logs are typically retained for twelve months.
Where we operate a client portal, working data in the portal, such as conversation history, drafts and uploads you choose to remove, can be deleted by you at any time, while documents forming part of the client file remain subject to the retention rule above.
11. Your rights
- Access. You may ask what personal information we hold about you and receive a copy. We will respond within 30 days. We may charge a reasonable fee and will tell you the amount before proceeding.
- Correction. If information is inaccurate or incomplete, we will correct it or, where we disagree, note your position on the file.
- Withdrawal of consent. As described in section 5.
- Deletion. Available for information not forming part of the client file. Where we must retain information, we will explain why.
Access rights are not absolute. We must refuse access where the information is subject to solicitor-client privilege, where it would reveal personal information about another person, or where law or professional obligation requires refusal. If we refuse, we will tell you the reason unless prohibited from doing so.
12. Breach notification
If a breach of security safeguards creates a real risk of significant harm to an individual, we will report it to the Office of the Privacy Commissioner of Canada, notify affected individuals, notify any organization that can reduce the risk, and keep a record of the breach, as PIPEDA requires. Where Quebec's Law 25 or another provincial law applies, we will also meet its requirements, including notification to the Commission d'accès à l'information.
13. Contact and complaints
Privacy Officer
Murji Legal Professional Corporation, operating as Murjis
517 Richmond St E, Toronto, Ontario M5A 2W7
info@murjis.com
Write to our Privacy Officer with any question, access request or complaint about how we handle personal information. We will acknowledge your request and respond within 30 days.
If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca, or to the privacy regulator in your province. Complaints about a lawyer's professional conduct may be made to the Law Society of Ontario.
14. Changes
We may update this policy to reflect changes in our practice or in the law. The effective date appears at the top. Material changes will be posted here before they take effect, and we will tell clients directly where a change affects an open matter.