Legal & Compliance
Privacy Policy
1. Who This Policy Covers
This Privacy Policy applies to Educli Pty Ltd (ABN: 22 627 450 122) and all services provided through our platform at educli.com and associated domains.
We are committed to protecting the privacy of our users in accordance with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth).
Important: This policy covers data we collect directly. Third-party services integrated with Educli (such as Moodle, payment processors, or government systems) have their own privacy policies.
2. What We Collect
Personal Information
- Identity information: Name, date of birth, nationality, passport details
- Contact information: Email addresses, phone numbers, postal addresses
- Professional information: MARA registration numbers, education provider details, qualifications
- Financial information: Payment details (processed securely through third-party providers)
- Immigration information: Visa applications, supporting documents, case files
Usage & Technical Data
- Platform usage patterns and feature interactions
- Device information (IP address, browser type, operating system)
- Login times and session data
- File uploads and document metadata
AI & Analytics Data
- Content submitted to AI features (document analysis, form completion assistance)
- Platform interactions for service improvement
- Aggregated usage statistics (anonymized)
3. How We Collect
Direct Collection
- Account registration and profile setup
- Form submissions and case management
- Direct communications (support tickets, emails)
- Document uploads and file sharing
Automatic Collection
- Website cookies and tracking technologies
- Server logs and analytics platforms
- Third-party integrations (Moodle, payment systems)
- API interactions with government systems
4. How We Use Data
Primary Purposes
- Service delivery: Managing visa applications, student enrollments, and compliance tracking
- Platform functionality: User authentication, file storage, and feature access
- Compliance support: MARA audits, ESOS reporting, and regulatory requirements
- Communication: Updates, notifications, and customer support
Secondary Purposes
- Product improvement and feature development
- Security monitoring and fraud prevention
- Analytics and performance optimization
- Marketing communications (with consent)
5. Automated Decision-Making
Educli uses automated systems for specific functions:
AI-Assisted Features
- Document analysis: Automated checking of visa application forms
- Compliance monitoring: Automated alerts for missing documentation
- Risk assessment: Flagging potential compliance issues
Important: No fully automated decisions are made that significantly affect users without human review. All AI outputs are recommendations that require professional judgment.
6. Third-Party AI Providers
We integrate with external AI services to enhance our platform:
- OpenAI/Anthropic: Document processing and content generation
- Google Cloud AI: Translation and text analysis
- AWS AI Services: Data processing and analytics
Data Protection: We have data processing agreements with all AI providers. Personal information is only shared as necessary for service functionality, and providers are contractually required to protect your data.
7. Data Storage & Security
Storage Locations
- Primary: AWS data centers in Australia (Sydney region)
- Backup: Encrypted backups in Australian data centers
- CDN: Non-personal content via global content delivery networks
Security Measures
- AES-256 encryption for data at rest
- TLS 1.3 encryption for data in transit
- Multi-factor authentication for platform access
- Regular security audits and penetration testing
- Role-based access controls
- Automated backup systems with point-in-time recovery
8. Disclosure
We may disclose your personal information in the following circumstances:
Required Disclosures
- Government agencies: Department of Home Affairs, ASQA, TEQSA (as required by law)
- Legal compliance: Court orders, subpoenas, or regulatory investigations
- OMARA: For MARA compliance and audit purposes
Authorized Disclosures
- Service providers: Payment processors, cloud hosting, technical support
- Educational institutions: For student enrollment and progress tracking
- Third-party integrations: Moodle, assessment platforms (with consent)
9. Overseas Transfer
Your personal information may be transferred overseas in limited circumstances:
- AI processing: Document analysis by US-based AI providers (OpenAI, Anthropic)
- Cloud services: Backup and disaster recovery systems
- Support services: Technical support provided by global teams
All overseas transfers are protected by:
- Data processing agreements compliant with Australian privacy law
- Contractual protections equivalent to APPs
- Encryption and access controls
10. Cookies
We use cookies and similar technologies for:
Essential Cookies
- User authentication and session management
- Security and fraud prevention
- Platform functionality and preferences
Analytics Cookies
- Google Analytics (anonymized)
- Platform usage statistics
- Performance monitoring
You can control cookies through your browser settings. Disabling essential cookies may affect platform functionality.
11. Data Retention
Active Users
- Account data: Retained while account is active plus 7 years
- Case files: Retained as required by MARA regulations (minimum 7 years)
- Student records: Retained as required by ESOS Act (30 years)
Inactive Users
- Personal data: Deleted after 3 years of inactivity (subject to legal requirements)
- Anonymized data: May be retained for analytics and improvement
You may request earlier deletion of your data, subject to our legal and regulatory obligations.
12. Your Privacy Rights
Under the Privacy Act 1988, you have the following rights:
Access & Correction
- Access: Request copies of your personal information
- Correction: Request correction of inaccurate or incomplete data
- Explanation: Understand how we use your information
Control & Deletion
- Opt-out: Unsubscribe from marketing communications
- Restrict processing: Limit how we use your data
- Data portability: Receive your data in a portable format
- Deletion: Request deletion (subject to legal requirements)
To exercise your rights, contact our Privacy Officer at privacy@educli.com
13. Privacy Complaints
Internal Complaints Process
- Contact us: Email privacy@educli.com with details of your complaint
- Investigation: We will investigate and respond within 30 days
- Resolution: We will work with you to resolve the issue
External Complaints
If you're not satisfied with our response, you may lodge a complaint with:
- Office of the Australian Information Commissioner (OAIC)
- Phone: 1300 363 992
- Email: enquiries@oaic.gov.au
- Web: www.oaic.gov.au
14. Notifiable Data Breaches
In the event of a data breach that could cause serious harm:
- OAIC notification: We will notify the OAIC within 72 hours
- User notification: Affected users will be notified as soon as practicable
- Remediation: We will take immediate steps to secure the data and prevent further breaches
Our incident response procedures are regularly tested and updated to ensure rapid response to any security incidents.
15. Policy Changes
We may update this policy from time to time to reflect:
- Changes in Australian privacy law
- New platform features or services
- Improved privacy practices
We will notify you of material changes by:
- Email notification to registered users
- Prominent notice on the platform
- Updated version number and date
16. Contact Us
Privacy Officer
For any privacy-related questions or concerns:
Email: privacy@educli.com
Mail: Privacy Officer, Educli Pty Ltd, 12 Elkhorn Avenue, Surfers Paradise QLD 4217
Phone: +61 7 5528 1757