About this policy
This policy applies to visitors to the Semper Fidelis website, people who submit an enquiry or request a consultation, and people who interact with the Semper Fidelis Journal.
Any privacy or confidentiality provisions contained in a client engagement letter or other agreement with the Firm will apply in addition to this policy. Nothing in this policy or an engagement agreement limits any right or obligation that cannot lawfully be limited.
Submitting an enquiry or consultation request does not create a lawyer-client relationship and does not mean that the Firm has agreed to act. The Firm must first complete any necessary conflicts and acceptance procedures and confirm the engagement in writing.
Information we collect
Depending on how you use the website, we may receive:
- Enquiry information, including your name, email address, telephone number, enquiry type and message.
- Consultation information, including your name, contact details, selected service, preferred date and time, and any message you submit.
- Journal information, including a name and comment submitted for moderation, likes and pseudonymous information used to estimate unique article views. If a comment is approved, the supplied author name, comment and publication date will be displayed publicly with the article.
- Technical and security information, including request data, IP address and browser information processed for website delivery, security, abuse prevention and rate limiting. For Journal write requests, the website creates a one-way fingerprint derived from IP-address and browser information. That fingerprint is intended to be deleted after eight days.
- Website usage information collected through Vercel Web Analytics to provide privacy-focused, aggregated information about website visits and page views without the use of advertising cookies.
Please do not submit highly sensitive, privileged or confidential information through a public website form. Contact the Firm first so that conflicts can be checked and, where appropriate, a secure communication method can be arranged.
How we use information
We may use information collected through the website to:
- respond to enquiries and consultation requests;
- conduct preliminary conflicts and client-intake checks;
- assess whether and how the Firm may assist;
- arrange consultations and communicate with prospective or existing clients;
- operate, secure, maintain and improve the website;
- moderate and publish approved Journal comments;
- record and assess Journal views and engagement;
- prevent spam, fraud, misuse and technical disruption;
- comply with professional, regulatory and legal obligations; and
- establish, exercise or defend legal rights.
We do not sell personal information or use information submitted through the website for third-party behavioural advertising.
Service providers and disclosures
The website currently uses:
- Vercel for website hosting, delivery and Web Analytics;
- Supabase for website content, authorised administration and Journal engagement data; and
- Resend to transmit consultation requests and enquiries to the Firm by email.
The active enquiry and consultation submission routes deliver form content to the Firm by email through Resend. They do not intentionally store that form content in Supabase. Technical metadata or temporary records may nevertheless be processed or retained by the relevant service providers in accordance with their own systems and retention practices.
We may also disclose information:
- where required or authorised by law;
- where reasonably necessary to protect the Firm, its clients or others;
- to professional advisers or service providers supporting the Firm;
- in connection with professional, regulatory or insurance obligations; or
- with the affected person’s consent.
We do not authorise service providers to use information processed for the Firm for their own advertising purposes.
Cookies and browser storage
The Journal uses a random first-party cookie named sf_reader_idto help estimate unique article views. The cookie is configured as HttpOnly, uses SameSite=Lax and expires after 365 days.
A view-count request is made when a published article opens. Repeat visits to the same article from the same browser are combined into one unique view while the cookie remains available.
Supabase receives a pseudonymous per-article viewer key and the first and latest recorded view times. It does not receive the underlyingsf_reader_id cookie value. Cookies or similar technologies may also be used where necessary for secure administrator authentication.
The website does not currently use advertising cookies.
How long information is kept
We retain information only for as long as reasonably necessary for the purpose for which it was collected and to meet applicable professional, legal, security and recordkeeping requirements.
Enquiries and consultation messages may remain in the Firm’s email system and relevant service-provider records while the request is handled and for an appropriate recordkeeping period afterward.
Journal comments may remain published until the comment or article is removed. Pseudonymous article-view records are retained for the period reasonably required to measure views and maintain the accuracy and security of article statistics. The sf_reader_idcookie expires after 12 months.
International processing
The Firm serves clients in Tonga, throughout the Pacific and internationally. Its technology providers may process or store information outside Tonga, including in countries whose privacy laws may differ from those applicable in Tonga.
We select reputable providers and take reasonable measures appropriate to the nature and sensitivity of the information. However, we cannot guarantee that every overseas jurisdiction provides protections equivalent to those available in Tonga or in your country of residence.
Security
We use reasonable administrative and technical safeguards intended to protect information handled through the website. These include server-side validation, restricted administrative access and controls intended to reduce automated abuse.
No internet transmission, email service or storage system can be guaranteed to be completely secure. If a matter is urgent or particularly sensitive, please contact the Firm before transmitting information so that an appropriate communication method can be arranged.
Journal comments
Journal comments are moderated before publication. By submitting a comment, you acknowledge that the supplied name and approved comment may be displayed publicly and accessed from countries around the world.
Please do not include personal information about another person, confidential information, privileged material, defamatory content or information that you are not authorised to publish. The Firm may approve, reject, edit or remove comments in accordance with its moderation practices.
External websites and platforms
The website contains links to Google, Facebook, LinkedIn, WhatsApp, government services and other third-party websites. These are outbound links rather than embedded social-media tracking pixels or platform APIs.
When you follow an external link, the third party’s privacy terms and practices apply. The Firm does not control how those services collect, use or retain information.
Children
The website is not directed specifically at children, and the Firm does not knowingly seek to collect personal information from children through the website. A parent or guardian who believes that a child has submitted personal information may contact the Firm to request its review or removal, subject to applicable legal and professional obligations.
Your choices and enquiries
You are not required to submit a website form and may contact the Firm through another published channel.
Subject to applicable law and the Firm’s professional obligations, you may ask:
- whether the Firm holds personal information about you;
- for access to or correction of that information;
- for the removal of a published Journal comment; or
- to raise a concern about the Firm’s handling of personal information.
Requests may be limited where information must be retained because of legal, professional, conflicts, privilege, security or recordkeeping obligations.
Privacy enquiries may be directed to Semper Fidelis Pacific Law & Advisory using the Firm’s email address and business address published on this website.
Changes to this policy
We may update this policy to reflect changes to the website, our service providers, our practices or applicable requirements. The “Last updated” date identifies the most recent version. Material changes may also be highlighted on the website where appropriate.