RTO Assess & Assist — Privacy Policy
DRAFT — have an Australian lawyer review this document before accepting paying customers. Items in [square brackets] must be completed first.
Last updated: 15 July 2026
This policy explains how [LEGAL ENTITY NAME] (ABN [ABN]) ("we", "us") handles personal information when you use RTO Assess & Assist ("the Service"). We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
The Service is used by Registered Training Organisations (RTOs) to support the marking of student assessments. That means we handle two kinds of personal information: account information about you and your staff, and student information contained in the assessment documents you upload.
1. What we collect
Account information (about the RTO's staff): - Name, email address and login credentials of account holders and invited assessors - Assessor names recorded against marking runs and review decisions - Billing records (payments are processed by Stripe — we do not see or store full card numbers)
Student information (inside uploaded documents): - Assessment submissions typically include the student's name, student number, contact details (on the assessment cover sheet) and their written answers - The Service reads the cover sheet in order to know exactly which name and details to protect (see section 3)
Technical information: - Standard server logs (IP address, time, pages requested) used for security and troubleshooting
2. Why we collect it
- To provide the Service: marking support, review workflow, reports and audit records
- To operate accounts, billing and support
- To meet our own legal obligations
We do not sell personal information. We do not use student work to train AI models.
3. AI processing and the redaction guarantee
The Service uses third-party AI providers to analyse assessment answers. Before any text is sent to an AI provider:
- The student's name and details are read from the document's own cover sheet, so the Service knows exactly who to protect — it does not rely on file names, which are often wrong.
- Names, email addresses, phone numbers, street addresses and ID numbers
found in the answer text are replaced with anonymous tokens (for
example,
[NAME_1]). - Only this redacted answer text and the RTO's marking benchmarks are sent to the AI provider. Cover sheets are never sent.
- When results come back, tokens are restored to the original values on our server so reports read normally. The original values never leave the Service.
Each marking run's audit record shows how many personal-information items were redacted for each student ("PII redacted — N items" or "screened — none found", meaning the answers contained no personal information).
Cross-border disclosure (APP 8): our AI providers process the redacted text on servers that may be located outside Australia (including the United States). Because personal identifiers are removed before sending, the content disclosed overseas is de-identified answer text. Provider names/models used for each assessment are recorded on your audit log. Current providers: [LIST CURRENT AI PROVIDERS, e.g. OpenRouter (routing to Moonshot AI, OpenAI)].
4. Where data is stored
- Uploaded documents, marked documents, reports and the Service database are stored on [HOSTING DETAILS — e.g. servers located in Australia].
- Finalised ("completed") assessment documents are stored in the customer's account and can be downloaded by the customer at any time from the Reports page. Once downloaded, those copies are under the customer's control, not ours.
- Payments are handled by Stripe under Stripe's own privacy policy.
5. How long we keep it
| Data | Retention |
|---|---|
| Uploaded student files (originals) | Automatically deleted after [180] days (configurable per deployment) |
| Marked documents and reports | Retained while the account is active, subject to the same purge schedule for raw uploads |
| Audit records (who decided what, when, AI model used, redaction counts) | Never purged — they are the compliance evidence trail and are retained even after uploads are deleted |
| Account and billing records | Retained as required by law (typically 7 years for financial records) |
| Database backups | Rolling backups; the newest 14 daily copies are kept |
RTO customers remain responsible for their own record-keeping obligations under the Standards for RTOs 2025 (for example, retaining assessment evidence for the required period). The Reports page downloads (single document or "Download all") and audit exports exist to support that; we recommend customers regularly download and back up their own copies.
6. Who can see what
- Your account's data is visible only to your account owner and the assessor users they invite.
- Our administrators can access data only for support, security and legal compliance purposes.
- We disclose personal information only: to the AI providers as described in section 3 (redacted); to Stripe for payments; where you direct us to; or where the law requires.
7. Security
- Access to the Service requires authenticated login; assessor accounts are linked to and controlled by the account owner.
- Personal identifiers are redacted before any external AI call (section 3).
- The database is backed up daily.
- [ADD when deployed: HTTPS/TLS in transit, disk encryption, hosting security details.]
No system is perfectly secure. If a data breach occurs that is likely to result in serious harm, we will notify affected customers and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme.
8. Students' rights and your obligations as an RTO
The RTO (not us) has the direct relationship with students. If you are a student whose assessment was processed by the Service, contact your training provider first — they control the data. We will assist RTO customers to meet access and correction requests.
RTO customers are responsible for their own privacy obligations to students, including any required notice that assessment marking is supported by AI tooling. (Our customer policy template includes suggested wording.)
9. Access, correction and complaints
You can ask us for access to, or correction of, personal information we hold about you: [SUPPORT EMAIL]. If you have a privacy complaint, contact us first and we will respond within 30 days. If unresolved, you can complain to the Office of the Australian Information Commissioner (www.oaic.gov.au).
10. Changes
We will notify account owners by email of material changes to this policy at least 14 days before they take effect.
Contact: [LEGAL ENTITY NAME], [ADDRESS], [SUPPORT EMAIL]