COMPLYED TERMS OF USE

Version: 1.0
Effective date: 26/08/2026

1. About these Terms

These Terms of Use ("Terms") govern access to and use of the ComplyED platform, including the ComplyED application, website, learning modules, assessments, dashboards, reports, alerts, certificates, administrative tools and related services (collectively, the Platform).

The Platform is operated by [LEGAL ENTITY NAME] ABN [ABN], trading as ComplyED ("ComplyED", "we", "us" or "our").

By selecting Accept when these Terms are presented to you, you agree to be bound by these Terms.

If you do not agree to these Terms, you must not use the Platform.

2. Acceptance and Changes to these Terms

When you first sign in to ComplyED, you will be required to review and accept these Terms before accessing the Platform.

We may update these Terms from time to time to reflect changes to:

  • the Platform or its functionality;

  • our business or services;

  • applicable laws or regulatory requirements;

  • security, privacy or technology requirements; or

  • other matters reasonably necessary for operating ComplyED.

Where we require acceptance of an updated version, the updated Terms will be presented to you and you will be required to accept them before continuing to use the Platform.

ComplyED may record the version of the Terms accepted by you, your account or user identifier, and the date and time of acceptance.

The version presented to and accepted by you will apply from the time of acceptance.

3. Who Uses ComplyED

ComplyED may be used by organisations and individuals including:

  • approved providers;

  • childcare and early childhood education and care services;

  • directors and management personnel;

  • nominated supervisors;

  • responsible persons;

  • centre directors and service leaders;

  • educational leaders;

  • educators;

  • employees;

  • contractors;

  • students and trainees;

  • administrators; and

  • other persons authorised to use the Platform.

In these Terms, an organisation which subscribes to, purchases or is provided access to ComplyED is referred to as a Provider.

A person accessing the Platform is referred to as a User.

A User may have different permissions depending on their role and their relationship with a Provider.

4. Purpose of ComplyED

ComplyED is a workforce compliance education, professional development, knowledge assessment and compliance-readiness platform.

The Platform may provide functionality including:

  • learning and professional development modules;

  • knowledge assessments;

  • scenarios and questions;

  • module completion tracking;

  • assessment results;

  • knowledge or readiness scores;

  • completion records;

  • dashboards;

  • reports;

  • alerts;

  • trends;

  • organisational insights;

  • reminders;

  • certificates or completion records; and

  • tools designed to help Providers identify potential areas requiring further education, training, review or attention.

ComplyED is intended to assist Providers and Users with education and compliance preparedness.

It does not assume the Provider's legal or regulatory responsibilities.

5. ComplyED Does Not Guarantee Compliance

Use of ComplyED does not guarantee that:

  • a Provider or service complies with any law, regulation, standard or regulatory requirement;

  • a service will achieve any particular Assessment and Rating outcome;

  • a regulatory authority will consider a Provider, service or User compliant;

  • a User is competent to perform a particular task;

  • a User will act consistently with their assessment results in practice;

  • a Provider will avoid incidents, breaches, enforcement action or regulatory findings; or

  • completion of a module satisfies every training, induction, competency or professional development requirement applicable to a Provider or User.

ComplyED is an educational and compliance-support tool.

Providers remain responsible for establishing, implementing, monitoring and maintaining their own compliance systems.

6. Provider Responsibilities

Each Provider remains responsible for its operations and compliance with all applicable laws, regulations, standards and requirements.

This includes responsibility for matters such as:

  • child safety;

  • adequate supervision;

  • educator-to-child ratios;

  • staffing arrangements;

  • qualifications;

  • first aid requirements;

  • policies and procedures;

  • risk assessments;

  • incident management;

  • mandatory reporting;

  • child protection;

  • medication administration;

  • health and hygiene practices;

  • sleep and rest;

  • emergency procedures;

  • record keeping;

  • staff induction;

  • ongoing professional development;

  • workplace health and safety;

  • employment obligations; and

  • regulatory notifications.

The Provider must determine whether any information obtained through ComplyED requires action within its organisation.

ComplyED does not replace professional judgement, appropriate supervision or a Provider's internal governance arrangements.

7. Regulatory Information

ComplyED content may refer to legislation, regulations, National Quality Framework requirements, National Quality Standards, regulatory guidance, policies, procedures or other compliance materials.

We take reasonable steps to provide useful and current information. However, laws, regulations, regulatory interpretations and guidance can change.

Users and Providers should verify information against current authoritative sources where necessary.

Where there is any inconsistency between ComplyED content and applicable law or an authoritative regulatory requirement, the applicable law or regulatory requirement prevails.

8. No Legal or Professional Advice

Information provided through ComplyED is general educational and informational material.

It does not constitute:

  • legal advice;

  • employment advice;

  • regulatory advice;

  • medical advice;

  • professional advice; or

  • advice specific to the circumstances of a particular service, Provider, child, employee or incident.

Where appropriate, Providers should obtain independent professional advice.

9. Training and Accreditation

Unless expressly stated otherwise, ComplyED modules are professional development and compliance education activities and are not nationally recognised training or accredited qualifications.

Completion of a module does not grant a qualification, licence, accreditation or regulatory approval.

Any certificate or completion record issued by ComplyED records the activity or result described on that certificate or record only.

10. User Accounts

Users must provide information that is accurate and reasonably current.

A User must not:

  • create an account using another person's identity;

  • knowingly provide false information;

  • allow another person to complete assessments using their account;

  • complete an assessment on behalf of another User;

  • impersonate another User;

  • manipulate assessment results;

  • interfere with Platform records; or

  • attempt to circumvent account or assessment controls.

Users must take reasonable steps to protect their account credentials.

If a User believes their account has been compromised, they should notify ComplyED or their Provider promptly.

11. User Identity and Portability

ComplyED may maintain an individual User profile that allows a User's identity to remain associated with that person even if they change employers, services or Providers.

The purpose of this functionality is to reduce duplicate accounts, maintain appropriate continuity and improve the integrity of User records.

A User's association with one Provider does not automatically give that Provider access to information generated through the User's association with another Provider.

Historical records legitimately generated while a User was associated with a Provider may remain available to that Provider where reasonably necessary for record keeping, compliance, audit, dispute management or other lawful purposes.

ComplyED may establish processes to verify a User's identity or resolve duplicate accounts.

12. Provider Access to User Information

Where a User is associated with a Provider, authorised representatives of that Provider may be able to view information relating to the User's use of ComplyED.

Depending on the functionality and permissions available, this may include:

  • assigned modules;

  • module status;

  • completion dates;

  • outstanding or overdue modules;

  • assessment results;

  • scores;

  • unsuccessful attempts;

  • knowledge gaps;

  • responses or response categories;

  • certificates;

  • compliance or readiness indicators;

  • trends; and

  • other information reasonably related to workforce education and compliance management.

Users acknowledge that ComplyED is designed as a workforce compliance platform and that relevant information may therefore be available to authorised Provider representatives.

13. Assessments and Assessment Integrity

Assessments are intended to measure a User's understanding of the material presented.

Users must complete assessments honestly and independently unless a module expressly allows collaboration or assistance.

Users must not:

  • share answers for the purpose of circumventing an assessment;

  • obtain unauthorised assistance;

  • use another person's account;

  • have another person complete an assessment for them;

  • copy or distribute assessment banks;

  • systematically record assessment questions for redistribution;

  • use automated tools to extract assessment content; or

  • manipulate the Platform to obtain an inaccurate result.

ComplyED may take reasonable steps to protect assessment integrity.

14. Scores, Results and Readiness Indicators

ComplyED may calculate and display scores, completion percentages, readiness indicators, trends, risk indicators or other metrics.

These metrics are decision-support tools only.

They represent information derived from activity recorded within ComplyED and do not provide a complete assessment of a User's workplace performance, competence or conduct or a Provider's regulatory compliance.

A high score does not establish compliance.

A low score does not, by itself, establish misconduct, incompetence or a regulatory breach.

Providers should apply appropriate human judgement and consider relevant circumstances before making significant employment, disciplinary or compliance decisions based on information generated by ComplyED.

15. Provider Administration

Provider administrators may be able to:

  • create or invite Users;

  • associate Users with services;

  • assign modules;

  • view completion information;

  • view assessment information;

  • manage permissions;

  • generate reports;

  • review dashboards;

  • manage service information; and

  • perform other administrative functions.

Providers are responsible for ensuring administrative access is granted only to appropriately authorised persons.

16. Shared Devices

ComplyED may be accessed through shared workplace devices, including tablets.

Providers and Users must take reasonable precautions to prevent unauthorised access to another User's account or information.

Users should sign out or otherwise secure their session when appropriate.

Providers are responsible for appropriately managing devices under their control.

17. Information About Children and Families

Unless a particular ComplyED feature expressly requires it, Users should not enter identifiable information about children, families or other third parties into ComplyED.

Where scenarios or incidents are discussed within the Platform, Users should use de-identified information wherever reasonably practicable.

Providers are responsible for ensuring they have appropriate authority to provide any third-party personal information submitted to ComplyED.

18. Intellectual Property

ComplyED and its licensors own or control all intellectual property rights in the Platform and ComplyED content, except for content expressly identified as belonging to another party.

This includes rights in:

  • software;

  • branding;

  • trademarks;

  • designs;

  • interfaces;

  • graphics;

  • learning modules;

  • assessment questions;

  • question banks;

  • scenarios;

  • written content;

  • videos;

  • diagrams;

  • scoring methodologies;

  • reporting formats;

  • dashboard structures;

  • databases; and

  • other original ComplyED materials.

Users and Providers receive a limited, non-exclusive, non-transferable right to use ComplyED for its intended purpose while they are authorised to access the Platform.

19. Restrictions on Content

Except as permitted by law or expressly authorised by ComplyED, Users and Providers must not:

  • reproduce ComplyED modules or assessments;

  • republish ComplyED content;

  • sell or sublicense ComplyED materials;

  • create competing training materials substantially derived from ComplyED content;

  • copy assessment banks;

  • scrape or systematically extract Platform content;

  • reverse engineer the Platform except where a legal right to do so cannot be excluded;

  • remove copyright or proprietary notices; or

  • use ComplyED intellectual property outside the permitted use of the Platform.

Reasonable screenshots or extracts may be used internally where necessary for legitimate administrative, compliance or support purposes, provided they are not used to reproduce substantial ComplyED content.

20. Provider and User Data

Users and Providers retain their rights in information they lawfully provide to ComplyED.

They grant ComplyED the rights reasonably necessary to host, process, analyse, display and otherwise use that information for:

  • operating the Platform;

  • providing the services;

  • generating authorised reports and dashboards;

  • maintaining records;

  • providing technical support;

  • securing the Platform;

  • preventing misuse;

  • improving the Platform; and

  • complying with law.

Our handling of personal information is further described in the ComplyED Privacy Policy.

21. De-identified and Aggregated Information

To the extent permitted by law, ComplyED may create aggregated or de-identified information from Platform usage.

We may use genuinely de-identified or aggregated information for purposes such as:

  • improving ComplyED;

  • understanding industry knowledge trends;

  • improving educational content;

  • research and analytics;

  • benchmarking;

  • product development; and

  • business planning.

We will not present de-identified benchmarking information in a manner intended to identify an individual User.

22. Acceptable Use

Users must use ComplyED lawfully and reasonably.

Users must not use the Platform to:

  • breach any law;

  • harass, threaten or abuse another person;

  • introduce malware or malicious code;

  • obtain unauthorised access;

  • interfere with Platform security;

  • overload or disrupt the Platform;

  • access data they are not authorised to access;

  • falsely represent another person's results;

  • engage in fraudulent activity; or

  • misuse confidential information.

23. Availability and Changes to the Platform

We aim to provide reliable access to ComplyED but cannot guarantee uninterrupted or error-free availability.

The Platform may occasionally be unavailable due to:

  • maintenance;

  • updates;

  • technical failures;

  • third-party service failures;

  • security incidents; or

  • circumstances outside our reasonable control.

We may reasonably modify, improve, replace or discontinue Platform functionality.

Where a change materially affects a paid service, we will take reasonable steps to communicate the change where appropriate.

24. Third-Party Services

ComplyED may rely on third-party technology and service providers for functions such as hosting, communications, analytics, authentication, payments or other infrastructure.

The availability of those services may affect ComplyED.

Links to external websites or regulatory resources do not mean ComplyED controls or endorses all content available through those services.

25. Fees and Subscriptions

Where a Provider purchases access to ComplyED, fees, billing arrangements, subscription terms and any applicable minimum commitments will be those disclosed to or agreed with the Provider when the subscription is established or subsequently varied by agreement.

Unless expressly stated otherwise, fees are in Australian dollars.

GST will be dealt with as required by law.

Individual Users who access ComplyED through a Provider are not personally responsible for the Provider's subscription fees merely because they accept these User Terms.

26. Suspension and Termination

We may suspend or restrict access where reasonably necessary because of:

  • a serious or repeated breach of these Terms;

  • suspected fraud or impersonation;

  • a material security risk;

  • unlawful use;

  • misuse of ComplyED intellectual property;

  • unauthorised access;

  • a Provider's subscription ending; or

  • circumstances where suspension is reasonably necessary to protect ComplyED, Users, Providers or third parties.

Where reasonably practicable, we will consider the nature and seriousness of the issue before suspending access.

Termination of a Provider's subscription may affect the Provider's access to Platform information.

Certain records may be retained where reasonably necessary or required by law.

27. Privacy

ComplyED handles personal information in accordance with its Privacy Policy and applicable privacy laws.

The Privacy Policy explains how personal information is collected, held, used and disclosed.

Users are presented with the Privacy Policy separately within the ComplyED acceptance process.

28. Security

We take reasonable steps to protect information and the Platform against unauthorised access, loss, misuse, interference and disclosure.

No internet-connected system can be guaranteed to be completely secure.

Providers and Users must also take reasonable security precautions, including protecting login credentials and devices.

29. Australian Consumer Law

Nothing in these Terms excludes, restricts or modifies any consumer guarantee, right or remedy under the Australian Consumer Law or other applicable law that cannot lawfully be excluded, restricted or modified.

30. Warranties

To the maximum extent permitted by law, ComplyED does not warrant that:

  • use of the Platform will guarantee regulatory compliance;

  • every error or knowledge gap will be identified;

  • Platform information will address every factual circumstance;

  • a particular regulatory outcome will be achieved; or

  • the Platform will operate without interruption or error.

Nothing in this clause affects rights that cannot legally be excluded.

31. Liability

To the extent permitted by law, each party is responsible for loss or damage to the extent caused by its own acts, omissions, negligence or breach of these Terms.

ComplyED is not responsible for a Provider's operational, employment, regulatory or professional decisions merely because information from the Platform was considered in making those decisions.

ComplyED does not accept responsibility for a Provider's failure to comply with applicable law or regulatory requirements.

Nothing in these Terms excludes or limits liability where doing so would be unlawful.

32. Employment Decisions

ComplyED does not make employment decisions on behalf of Providers.

Providers are responsible for decisions concerning:

  • performance management;

  • disciplinary action;

  • employment;

  • termination;

  • rostering;

  • promotion;

  • competency;

  • additional training; and

  • workplace responsibilities.

Providers should not treat a ComplyED score or automated indicator as the sole basis for a significant employment decision without appropriate human consideration of the circumstances.

33. Regulatory and Government Requests

ComplyED may preserve or disclose information where required or authorised by applicable law, court order or lawful governmental or regulatory process.

Where legally permitted and appropriate, we will take reasonable steps to ensure disclosures are limited to information relevant to the request.

34. Feedback

If a User or Provider provides suggestions or feedback about ComplyED, we may use that feedback to develop and improve the Platform without an obligation to compensate the person providing it.

This does not transfer ownership of unrelated confidential information or personal information to ComplyED.

35. Confidentiality

Users who gain access to confidential Provider or User information through ComplyED must only use that information for authorised purposes.

Provider administrators must take reasonable steps to protect User information accessible through administrative functions.

36. Disputes and Concerns

If you have a concern about ComplyED, we encourage you to contact us first so that we can attempt to resolve it.

Email: admin@complyed.com.au

Nothing in this clause prevents a person from exercising rights available under applicable law or contacting an appropriate regulator.

37. Governing Law

These Terms are governed by the laws of New South Wales, Australia.

The parties submit to the jurisdiction of the courts of New South Wales and courts entitled to hear appeals from those courts, subject to any rights that cannot lawfully be restricted.

38. General

If part of these Terms is found to be invalid or unenforceable, the remaining provisions continue to apply to the extent permitted by law.

A failure or delay by ComplyED in exercising a right does not necessarily waive that right.

Headings are provided for convenience and do not affect interpretation.

39. Contact Us

END OF TERMS OF USE — VERSION 1.0

COMPLYED PRIVACY POLICY

Version: 1.0
Effective date: 26/08/2026

1. About this Privacy Policy

ComplyED respects the privacy of the people who use our Platform.

This Privacy Policy explains how [LEGAL ENTITY NAME] ABN [ABN], trading as ComplyED ("ComplyED", "we", "us" or "our"), collects, holds, uses and discloses personal information.

This Privacy Policy applies to personal information handled through:

  • the ComplyED application;

  • the ComplyED website;

  • Provider and service accounts;

  • User accounts;

  • assessments and learning modules;

  • customer support;

  • communications; and

  • our related business activities.

We aim to handle personal information consistently with applicable Australian privacy law, including the Australian Privacy Principles where they apply to us.

2. Acceptance of this Privacy Policy

When you first sign in to ComplyED, the Privacy Policy is presented to you separately from the Terms of Use.

You will be required to select Accept before continuing to use the Platform.

If this Privacy Policy is updated and we require renewed acceptance, the updated Privacy Policy may be presented to you the next time you sign in.

We may record:

  • your User identifier;

  • the Privacy Policy version presented;

  • the date and time of acceptance; and

  • other information reasonably necessary to maintain an acceptance record.

3. The Information We May Collect

The information we collect depends on how you interact with ComplyED and the features used by your Provider.

It may include the categories described below.

Identity information

This may include:

  • full name;

  • User ID;

  • account identifiers;

  • date of birth, where used for legitimate identity verification or account matching purposes;

  • profile information; and

  • information used to distinguish Users with similar details.

Contact information

This may include:

  • email address;

  • mobile or telephone number; and

  • other contact information.

Employment and organisational information

This may include:

  • employer or Provider;

  • service or centre;

  • role;

  • job title;

  • employment or service association;

  • service history within ComplyED;

  • permissions or administrative role; and

  • associations with current or previous Providers.

Learning and assessment information

This may include:

  • modules assigned;

  • modules commenced;

  • modules completed;

  • completion dates;

  • assessment responses;

  • assessment results;

  • scores;

  • unsuccessful attempts;

  • knowledge gaps;

  • overdue activities;

  • certificates;

  • readiness indicators;

  • trends; and

  • other information generated through your use of learning or assessment functionality.

Technical information

When you access ComplyED, we may collect technical information such as:

  • IP address;

  • device type;

  • operating system;

  • browser information;

  • app version;

  • login information;

  • timestamps;

  • session information;

  • security logs;

  • diagnostic information;

  • crash information; and

  • Platform activity.

Communications

If you contact us, we may collect:

  • your name and contact details;

  • your message;

  • support requests;

  • correspondence;

  • feedback; and

  • information reasonably necessary to respond.

Provider and billing information

For Provider representatives, we may also collect information relating to:

  • organisation details;

  • billing contacts;

  • subscriptions;

  • invoices;

  • payments; and

  • account administration.

Payment card or banking information may be processed by our payment provider rather than stored directly by ComplyED.

4. Sensitive Information

ComplyED is not generally designed to collect sensitive personal information about Users, children or families unless a particular feature legitimately requires it.

Users should not enter sensitive information into free-text fields unless it is reasonably necessary and authorised.

Where sensitive information is collected, we will handle it in accordance with applicable law.

5. Information About Children

ComplyED is primarily a workforce education and compliance platform.

It is not intended to operate as a child enrolment or child record-management system unless we expressly introduce functionality for that purpose.

Users should not enter identifiable information about children or families into ComplyED unless a specific feature requires it and they are authorised to provide that information.

Where possible, Users should de-identify information used when discussing scenarios or compliance matters.

6. How We Collect Personal Information

We may collect personal information:

  • directly from you;

  • when you create or activate an account;

  • when you sign in;

  • when you complete modules or assessments;

  • when you update your profile;

  • when you communicate with us;

  • automatically through your use of the Platform;

  • from a Provider that creates, invites or associates you with its organisation;

  • from an authorised administrator;

  • from another service within the same Provider organisation where appropriate;

  • from service providers assisting us to operate ComplyED; and

  • from other lawful sources where reasonably necessary.

7. Information Provided by Your Employer or Provider

A Provider may provide information to ComplyED so that your account can be created, invited, matched or associated with a service.

Providers are responsible for ensuring they have appropriate authority to provide personal information to ComplyED.

Information provided by a Provider may be combined with information already associated with your ComplyED account where reasonably necessary to maintain an accurate User identity.

8. Why We Collect and Use Personal Information

We may collect, hold and use personal information to:

  • create and manage accounts;

  • authenticate Users;

  • verify or distinguish User identities;

  • associate Users with Providers and services;

  • provide learning modules;

  • conduct assessments;

  • record assessment responses and results;

  • track module completion;

  • generate certificates and completion records;

  • calculate scores and readiness indicators;

  • provide dashboards and reports;

  • identify potential knowledge gaps;

  • notify Users or Providers about relevant Platform activity;

  • administer subscriptions;

  • provide customer support;

  • investigate technical problems;

  • secure the Platform;

  • prevent fraud and account misuse;

  • maintain audit records;

  • improve ComplyED;

  • analyse Platform performance;

  • develop new functionality;

  • meet legal obligations; and

  • manage our business.

9. Provider Access to User Information

ComplyED is designed to provide organisations with visibility over workforce education and compliance readiness.

If you are associated with a Provider, authorised persons within that Provider may have access to information relating to your use of ComplyED.

Depending on their permissions, this may include:

  • your name and role;

  • assigned modules;

  • completion status;

  • completion dates;

  • overdue modules;

  • assessment results;

  • scores;

  • unsuccessful attempts;

  • identified knowledge gaps;

  • certificates;

  • readiness information;

  • trends; and

  • related Platform information.

Access is intended to be limited to people with appropriate organisational permissions.

10. When You Change Employers or Services

ComplyED may maintain a User identity that can continue with you if you move between participating services or Providers.

This is intended to reduce duplicate accounts and maintain the integrity of User identity records.

Changing employers does not automatically give your new Provider access to all information associated with a previous Provider.

Likewise, a previous Provider does not automatically receive information about activities you undertake through a future Provider.

However, historical records generated while you were associated with a Provider may remain available to that Provider where reasonably necessary for legitimate record keeping, compliance, audit or legal purposes.

The precise information transferred or retained may depend on the feature involved, applicable law and the relationship between the User and Provider.

11. Scores and Automated Processing

ComplyED may automatically process information about Platform activity to calculate or display:

  • assessment scores;

  • completion percentages;

  • readiness indicators;

  • knowledge-gap indicators;

  • trends;

  • alerts;

  • module status; and

  • other workforce compliance information.

These systems are intended to support education, administration and human decision-making.

ComplyED does not intend these indicators, by themselves, to determine whether a person should be employed, dismissed, disciplined or otherwise subjected to a significant employment decision.

Providers remain responsible for their own decisions and should apply appropriate human judgement.

We may update this section as our automated functionality develops or as applicable privacy requirements change.

12. Disclosure of Personal Information

We may disclose personal information where reasonably necessary to:

  • your Provider or authorised Provider representatives;

  • service administrators;

  • companies that provide technology or infrastructure to ComplyED;

  • cloud hosting providers;

  • authentication providers;

  • email, SMS or notification providers;

  • analytics providers;

  • payment processors;

  • customer support providers;

  • professional advisers;

  • insurers;

  • auditors;

  • related entities where appropriate; and

  • regulators, courts, law enforcement bodies or government agencies where required or authorised by law.

We do not sell Users' personal information to data brokers.

13. Service Providers

We use third-party providers to help operate ComplyED.

These providers may process personal information on our behalf for purposes such as:

  • cloud hosting;

  • database management;

  • authentication;

  • communications;

  • monitoring;

  • analytics;

  • payments;

  • security;

  • error reporting; and

  • customer support.

We seek to use reputable providers and take reasonable steps appropriate to the nature of the service and information involved.

14. Overseas Disclosure and Storage

Some technology providers used by ComplyED may process or store information outside Australia.

Our current primary hosting and service-provider arrangements are:

Primary hosting/database location: [INSERT COUNTRY/REGION]
Other countries in which recipients may be located: [INSERT COUNTRIES AFTER TECH STACK REVIEW]

Where Australian privacy law requires us to take particular steps in relation to overseas disclosure, we will take reasonable steps to comply with those requirements.

This section should be updated if our technology or hosting arrangements materially change.

15. Data Security

We take reasonable steps to protect personal information from:

  • misuse;

  • interference;

  • loss;

  • unauthorised access;

  • unauthorised modification; and

  • unauthorised disclosure.

Security measures may include, where appropriate:

  • access controls;

  • authentication;

  • encryption;

  • logging;

  • monitoring;

  • backups;

  • restricted administrative access;

  • security updates; and

  • use of reputable infrastructure providers.

No online system can be guaranteed to be completely secure.

Users and Providers also have responsibility for protecting their login credentials and devices.

16. Shared Workplace Devices

Some Providers may make ComplyED available through shared workplace tablets or other devices.

Users should take reasonable steps to ensure another person cannot access their account.

Providers are responsible for appropriately configuring and managing devices they control.

17. Data Breaches

If we become aware of a suspected data breach, we will assess and respond to it in accordance with our legal obligations and our incident-response procedures.

Where required by applicable law, we will notify affected individuals and relevant regulatory authorities.

18. How Long We Keep Information

We retain personal information only for as long as reasonably necessary for the purposes for which it is held, including:

  • providing ComplyED;

  • maintaining appropriate learning and assessment records;

  • Provider record keeping;

  • account continuity;

  • audit requirements;

  • security;

  • resolving disputes;

  • enforcing agreements; and

  • complying with legal obligations.

Different types of information may have different retention periods.

When information is no longer reasonably required and we are not legally required or otherwise permitted to retain it, we will take reasonable steps to delete or de-identify it.

19. Account Closure

Closing or ceasing to use a ComplyED account does not necessarily result in immediate deletion of all associated information.

Certain records may need to be retained for legitimate purposes, including:

  • historical module records;

  • assessment records;

  • Provider records;

  • audit records;

  • security logs;

  • legal obligations;

  • dispute management; and

  • protection against fraud.

Where appropriate, information may instead be de-identified.

20. Access to Your Personal Information

You may request access to personal information ComplyED holds about you.

Requests can be made to:

admin@complyed.com.au

We may need to verify your identity before providing access.

In some circumstances, applicable law may allow or require us to refuse access to particular information. If this occurs, we will provide an explanation where required.

21. Correcting Your Information

We take reasonable steps to ensure personal information we hold is accurate, up to date, complete and relevant for the purposes for which it is used.

If you believe information about you is incorrect, you may:

  • update information available through your account where functionality permits;

  • contact your Provider administrator; or

  • contact ComplyED at admin@complyed.com.au

Assessment results and historical records will not necessarily be altered simply because a User disagrees with the result, but we may correct information that is factually inaccurate or incorrectly attributed.

22. Identity Verification

Where reasonably necessary, ComplyED may ask for information to verify your identity before:

  • changing important account information;

  • merging duplicate accounts;

  • transferring or associating an account;

  • providing access to personal information; or

  • processing a privacy request.

We will seek to collect only information reasonably necessary for the verification process.

23. Anonymous Use

Some general interactions with ComplyED may be possible without identifying yourself.

However, because the core purpose of the Platform includes recording individual module completion and assessment activity, it will generally not be practicable to use core User functionality anonymously or under a pseudonym.

24. Analytics and Platform Improvement

We may analyse Platform usage to:

  • understand how ComplyED is used;

  • identify technical issues;

  • improve modules;

  • improve user experience;

  • improve assessments;

  • develop features;

  • improve security; and

  • understand general learning and compliance trends.

Where reasonably practicable, we may use aggregated or de-identified information for these purposes.

25. De-identified and Aggregated Information

We may create aggregated or de-identified datasets from information collected through ComplyED.

Where information has been appropriately de-identified so that it is no longer personal information, we may use it for purposes including:

  • research;

  • benchmarking;

  • product development;

  • educational improvement;

  • industry insights;

  • analytics; and

  • business planning.

We will not intentionally publish benchmarking information in a way designed to identify an individual User.

26. Marketing Communications

We may communicate with Provider representatives about ComplyED services, updates or related products where permitted by law.

Users may be able to unsubscribe from marketing communications using the unsubscribe method provided.

Operational communications concerning accounts, security, assigned learning, Platform changes or service administration are not necessarily marketing communications.

27. Privacy and Employment Records

Information accessible to a Provider through ComplyED may form part of that Provider's own employment, training or compliance records.

A Provider may have separate legal obligations concerning its handling of that information.

This Privacy Policy governs ComplyED's handling of personal information and does not replace a Provider's own privacy, employment or record-management obligations.

28. Requests from Regulators and Authorities

We may disclose personal information where required or authorised by:

  • Australian law;

  • a court or tribunal order;

  • a lawful regulatory requirement; or

  • another legally valid process.

We may also preserve information where reasonably necessary to comply with legal obligations.

29. Privacy Complaints

If you believe ComplyED has not handled your personal information appropriately, please contact:

Privacy Officer — ComplyED
Email: admin@complyed.com.au

Please provide enough information for us to understand and investigate your concern.

We will aim to acknowledge and investigate privacy complaints within a reasonable period.

If you are not satisfied with our response, you may have the right to make a complaint to the Office of the Australian Information Commissioner (OAIC) or another applicable regulator.

30. Changes to this Privacy Policy

We may update this Privacy Policy when our information-handling practices, technology, Platform functionality or legal obligations change.

The current version and effective date will be identified at the beginning of this Privacy Policy.

Where we determine that renewed acceptance is appropriate, the updated Privacy Policy may be presented when you next sign in and you may be required to accept it before continuing to use ComplyED.

31. Availability of this Privacy Policy

The current Privacy Policy will be made reasonably accessible through ComplyED and/or the ComplyED website.

You may request a copy in an alternative reasonably available form by contacting us.

32. Contact Us

For questions, access or correction requests, or privacy complaints:

END OF PRIVACY POLICY — VERSION 1.0