Last updated 31 July 2026
Privacy Policy
This policy explains how Transpose Labs Pty Ltd (we, us, our) handles personal information in the Transpose Skills platform. We are an Australian company and handle personal information under the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
Our customers are education and training providers. Nobody signs up for the platform independently — access is always given by a provider. Below, “you” means whoever is using the platform or whose information is described, usually a student or a provider’s staff member; where a point is about the provider’s own role, we say “your provider”.
On this page
1. Scope
This policy covers our public website, the Transpose Skills platform, and related support. It does not cover your provider’s own privacy practices, or third-party services you separately choose to use. It works together with our Terms of Service.
2. Our two roles
For records inside a provider’s workspace — accounts, applications, evidence, decisions, and the audit trail — the provider decides the purpose and we act on its instructions; the provider is accountable and the right first contact for anyone asking about their own records. For information we hold in our own right (billing, support, enquiries, security logs), we are accountable. If your provider is subject to privacy law outside Australia, additional terms may be needed.
3. What we collect
What we collect depends on who you are. In summary:
- Account and identity — name, email, authentication data, role, organisation, and language preference.
- Provider details — organisation name, sector, regulator code, and configuration.
- Evidence and submissions — documents and materials submitted for assessment or review.
- AI-derived records — extracted text, findings, and which model produced them.
- Assessment records — decisions, outcomes, and the audit trail.
- Communications — messages, notifications, and support conversations.
- Billing — payment references and amounts; never a full card number.
- Enquiries — your details if you request a demo or contact us.
- Technical data — IP address, timestamps, and security logs.
We collect this directly from you, from your provider, from an identity provider you sign in with, and automatically as you use the platform.
4. Sensitive information
We do not ask for government identifiers (tax file, national, or student ID numbers). Evidence can incidentally include sensitive information — we treat all evidence as our most protected category of data. Full card numbers and security codes never reach our systems.
5. How we use it
- operate, secure, and enforce access to accounts and organisations;
- process applications and produce advisory AI output (section 7);
- record decisions and the audit trail;
- provide support, billing, and account notifications; and
- comply with law and support your provider’s regulatory obligations.
6. What we do not do
- We do not sell personal information or use it for third-party advertising.
- We do not use your content to train AI models.
- We do not let AI make or present an assessment decision.
7. AI processing
AI helps read and structure submitted material. It never makes or finalises an assessment outcome — a qualified person always does, and low-confidence output routes to human review rather than becoming an outcome. Processing runs under our own enterprise cloud accounts, not consumer AI products. Output can be wrong and should be verified against the source material.
8. Who can see your information
Access follows role and is enforced by us on every request, not by hiding information in the interface. Our own staff access is least-privilege, permission-gated, and audited; support impersonation is logged and can never exceed what the user could do themselves.
9. Sub-processors and disclosure
We use the providers below to operate the platform, each bound by confidentiality and data-protection obligations.
| Provider | Function |
|---|---|
| Google Cloud | Hosting, infrastructure and document storage |
| Neon | Database |
| Microsoft Azure | Document and AI-language processing |
| Stripe | Payments |
| Tawk.to | Live chat, where enabled |
| Email provider | Transactional email |
| Identity providers | Single sign-on, where used |
We may also disclose personal information to your provider, our professional advisers, a regulator or law-enforcement body where legally required, or an acquirer of our business (on equivalent privacy terms). We keep this list current as our providers change.
10. Cross-border processing
Our infrastructure runs in the Australia (Sydney) region wherever our providers offer it — compute, storage, database, and AI processing are all hosted there. Some providers above are global companies and may perform support or payment functions overseas, including in the United States and European Union; we require them to handle information consistently with the APPs.
12. Security
We use industry-standard technical and organisational safeguards — including encryption, server-side access controls, and regular security testing — to protect personal information. No system is completely secure; if you believe you have found a vulnerability, report it to security@transposeskills.com rather than testing further.
13. Retention and deletion
Retention periods are configurable by your provider within legal requirements. Records under legal hold are kept until the hold is released. You may request permanent deletion of your uploaded content at any time, subject to legal hold and any statutory retention period. Live-chat transcripts sit in the chat provider’s own systems and are not reached by our deletion process.
14. Access and correction
Under the APPs you can ask for access to, or correction of, personal information we hold about you. For records in your provider’s workspace, contact your provider first — it controls them, and we will support it in responding (a finalised assessment decision and its audit trail are not deleted on request, as retention or legal hold requires them to be kept). For information we hold in our own right, contact us (section 19); we will verify your identity and respond within a reasonable time, usually 30 days, at no cost. You can opt out of marketing at any time; transactional account messages cannot be turned off while your account is active. The platform cannot be used anonymously, as an assessment record must be attributable.
15. Children
Accounts are provisioned by providers; we do not knowingly collect information directly from a child. Where a provider enrols someone who cannot consent for themselves, the provider is responsible for the required parental or guardian consent.
16. Data breaches
If an eligible data breach is likely to cause serious harm, we will notify the affected provider without undue delay so it can meet its obligations under the Notifiable Data Breaches scheme. Where we are the accountable entity, we will notify directly.
17. Complaints
Tell us at compliance@transposeskills.com; we will investigate and respond, normally within 30 days. If unresolved, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au), or, if your complaint concerns your assessment, to your provider and its regulator.
18. Changes
We may update this policy as the platform changes; the date above reflects the latest revision, and we give providers reasonable notice of a material change.
19. Contact
Transpose Labs Pty Ltd, 1/457-459 Elizabeth Street, Surry Hills, NSW 2010, Australia.
Privacy: compliance@transposeskills.com. Security: security@transposeskills.com. General: hello@transposeskills.com. For a specific application, submission, or result, contact your provider — they hold and control those records.