You are on CAQA Online
CAQA Online - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Data and Security Notice

Data and Security Notice

How information is collected, hosted and protected across CAQA Online and the portals we host.

1. Purpose

This Data and Security Notice explains how CAQA Online, part of CAQA Groups and operated by Career Calling International Pty Ltd (ABN 53 162 651 238), handles and protects information across this website and the portal environments we host. CAQA Online provides online portals, account access and digital environments for learners, trainers, providers and support teams, so two quite different kinds of data pass through our hands: the small amount you give us through this website, and the much larger sets of education records held inside provider portal environments. This notice covers both and should be read with our Privacy Policy.

2. Data collected through this website

This website collects only what you choose to give it: the name, organisation and contact details you enter in the contact form when you make an enquiry or request a demonstration campus, and the email address you enter in the newsletter form. Like most websites it may also use cookies and analytics technologies to understand traffic and improve content, as described in our Privacy Policy. No payments are taken through this website, so no payment card data is collected here. Emails you send us and phone enquiries are handled in the same way and are kept only as business records of the conversation.

3. Data held in portal environments

Portal environments hold the information an education provider and its users put into them: enrolment and contact details, course progress, assessment submissions and results, attendance, messages, and the dashboard views shared with parents or employers. That information belongs to the provider and its users. The provider is the collector and controller of those records and remains responsible for their lawful collection, accuracy and use; CAQA Online hosts and processes them on the provider's behalf under a written agreement.

4. How we protect data

We apply layered safeguards appropriate to education data, including role-based access controls so users see only what their role permits; encryption of data in transit; hardened, monitored hosting; routine backups tested for restorability; least-privilege administrative access for our own team; logging of administrative and security-relevant activity; and separation between different providers' environments. No system is immune to every threat, but security is designed into our platforms from the start rather than patched on afterwards. Our own team's access to provider environments is limited to the people who need it for implementation and support, is protected by strong authentication, and is reviewed on a recurring schedule.

5. Security incidents

If we detect or are told about a suspected security incident affecting a portal environment, we investigate and contain it, preserve evidence, and notify the affected provider's administrators promptly with what we know and what we are doing. Where an incident involves personal information, we assist the provider to assess its obligations under the Privacy Act 1988 (Cth), including the Notifiable Data Breaches scheme, and we meet our own obligations where they apply.

6. Retention, return and deletion

Website enquiry and newsletter data is kept only as long as needed for the purpose it was given. Portal data is retained according to each provider's agreement and regulatory retention duties; on termination of an engagement we return or delete provider data as the agreement directs, allowing for backup cycles that age out on a fixed schedule. Where records must be kept longer to satisfy a regulator, the provider's documented retention schedule prevails.

7. Your part in security

Good security is shared. Users should keep credentials private, sign out on shared devices and report anything unusual. Provider administrators should keep role assignments current, remove departed users promptly and use the administrative controls the platform gives them. Our Account Access Terms and Acceptable Use Policy set out these responsibilities in detail.

8. Questions and contact

Questions about this notice, or reports of a suspected data or security issue, can be sent to info@caqa.com.au, raised by phone on 1800 266 160, or lodged through our contact page. Privacy-specific questions and complaints are handled as described in our Privacy Policy.

Newsletter Subscription

To Receive Updates And Offers