Legal
Privacy Policy
Version: 2.0 Published: 6 September 2026 Effective Date: 6 October 2026 Supersedes: Version 1.0 (18 February 2026)
RTO MATE PTY LTD (ABN 41 684 275 401) trading as Qualticks ("Qualticks", "we", "us", "our").
1. Introduction
1.1 About This Policy
This Privacy Policy explains how RTO MATE PTY LTD (ABN 41 684 275 401) trading as Qualticks ("Qualticks", "we", "us", or "our") collects, uses, discloses and protects your personal information.
1.2 Our Commitment
Qualticks is committed to protecting your privacy in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). We are an Australian-owned and operated company.
1.3 Scope
This policy applies to:
Visitors to our website (qualticks.com.au)
Users of our Platform
Subscribers to our newsletter
Anyone who contacts us
1.4 Controller and Processor Roles
For personal information about your students, staff and contacts that you upload to the Platform, you decide what is collected and why. We handle that information on your instructions in order to provide the Services. You are responsible for having a lawful basis to collect it and to provide it to us.
For personal information about your account and our relationship with you (your name, email, billing details, usage data), we determine the purposes and this policy governs our handling of it.
2. Australian Privacy Principles Compliance
We comply with the 13 Australian Privacy Principles. This policy addresses each as follows:
APP Principle Section
APP 1 Open and transparent managementSection 2
APP 2 Anonymity and pseudonymitySection 6
APP 3 Collection of solicited informationSections 3–4
APP 4 Unsolicited personal informationSection 5
APP 5 Notification of collectionSection 4
APP 6 Use or disclosureSections 7–8
APP 7 Direct marketingSection 9
APP 8 Cross-border disclosureSection 10
APP 9 Government identifiersSection 11
APP 10 Quality of informationSection 12
APP 11 SecuritySection 13
APP 12AccessSection 14
APP 13 CorrectionSection 15
3. Information We Collect (APP 3)
3.1 Information You Provide
Account Information: full name; email address; phone number (optional); job title/role; organisation name; RTO registration number (if applicable).
Payment Information: billing address; payment method details, which are collected and processed directly by our payment provider. We do not store full payment card numbers.
Communications: contact form submissions; support requests; newsletter subscriptions; demo requests.
Records of Agreement: when you create an account, we record which versions of our Terms of Service, Privacy Policy, Acceptable Use Policy and Security Policy you accepted, together with your name, the date and time of acceptance, the exact text of each document as it was presented to you, your IP address and your browser user agent. We keep this as evidence that agreement was given and to show what was agreed. See Section 16 for how long we keep it.
3.2 Information Collected Automatically
Technical Information: IP address; browser type and version; operating system; device information; access times and dates.
Usage Information: pages viewed; features used; clickstream data; session duration.
Security Events: sign-in successes and failures, multi-factor authentication activity, password changes, session revocations and similar events, as described in our Security Policy.
3.3 Information from Third Parties
We may receive information from Training.gov.au (public RTO and qualification data), third-party analytics providers, and our CRM provider.
Training.gov.au Data Synchronisation. We periodically synchronise data from Training.gov.au including RTO information, qualification specifications and VET product details. This synchronisation occurs at scheduled intervals (not in real time), may result in temporary discrepancies with current Training.gov.au data, does not guarantee accuracy or currency, and is subject to Training.gov.au system availability. We cannot guarantee that Training.gov.au data displayed in the Platform is current, accurate or complete. See Section 10 of our Terms of Service.
3.4 Sensitive Information
We do not intentionally collect sensitive information (such as health information, racial or ethnic origin, political opinions or religious beliefs) in relation to your account.
Note that you may upload documents to the Platform that contain sensitive information about your own students or staff. You are responsible for obtaining any consent required for that collection and for ensuring you are permitted to provide it to us.
4. How We Collect Information (APP 3 & 5)
4.1 Direct Collection
We collect information directly when you register for an account, subscribe to our newsletter, submit a contact or demo request, communicate with us by email or phone, or use the Platform.
4.2 Cookies and Tracking
We use cookies and similar technologies to maintain your session and preferences, analyse Platform usage, and improve our services.
TypePurposeDurationEssentialPlatform functionalitySessionAuthenticationKeep you logged in30 daysAnalyticsUsage statistics12 monthsPreferencesRemember your settings12 months
You can manage cookies through your browser settings. Disabling cookies may affect Platform functionality.
Our analytics are provided by Google Analytics 4, a Google service. It sets cookies in your browser and sends Google information about your visit, including pages viewed, approximate location derived from your IP address, and your browser and device type. We use it to understand how the website is used; we do not use it to identify you personally. You can opt out of Google Analytics across all websites by installing Google's opt-out browser add-on, or by blocking cookies as described above. Google Analytics runs on this marketing website only — it is not loaded inside the Qualticks Platform itself.
4.3 Collection Notice
At the time of collection we will notify you of: the information being collected; the purposes of collection; who we may disclose it to; how you can access and correct it; and the consequences of not providing it.
5. Unsolicited Personal Information (APP 4)
If we receive personal information we did not solicit, we will determine whether we could have collected it under APP 3 and, if not, destroy or de-identify it as soon as practicable, unless required by law to retain it.
6. Anonymity and Pseudonymity (APP 2)
You may browse our public website without identifying yourself. Creating an account, subscribing to the Platform, contacting us for support and subscribing to our newsletter all require identification.
You may use a pseudonym for general enquiries, but must use your real name when registering for an account so that compliance records are accurate.
7. Use of Personal Information (APP 6)
7.1 Primary Purposes
To provide access to the Platform and Services; process payments and manage subscriptions; respond to enquiries and support requests; send service-related communications; verify your identity; maintain security and prevent fraud; and maintain records of your acceptance of our policies.
7.2 Secondary Purposes
With your consent or where permitted by law: to send marketing communications; to conduct research and analytics to improve our services; to personalise your experience; and to comply with legal obligations.
7.3 Aggregated and De-identified Data
We may create aggregated, de-identified statistical data from Platform usage to operate and improve the Services. This data does not identify you, your organisation or any individual, and is not personal information.
7.4 No Use for AI Model Training
We do not use your Customer Data to train machine learning or artificial intelligence models, and we do not provide your Customer Data to third parties for that purpose.
8. Disclosure of Personal Information (APP 6)
8.1 Who We Disclose To
We disclose personal information to the service providers listed in Section 10.2, and additionally to:
Professional advisors — lawyers, accountants and auditors as necessary
Regulatory authorities — ASQA, the OAIC or others when required by law
A purchaser — in connection with a sale or transfer of our business, on notice to you
8.2 When We Disclose
We will only disclose your personal information for the purposes for which it was collected; where you have consented; where required or authorised by law; or to establish, exercise or defend a legal claim.
8.3 No Sale of Personal Information
We do not sell your personal information to third parties.
9. Direct Marketing (APP 7)
9.1 When We May Market
We may send marketing communications about our products and services if you have consented, or you would reasonably expect us to use your information that way, and we provide a simple opt-out.
9.2 What We Send
Product updates and new features; industry news and compliance updates; webinar and event invitations; special offers and promotions.
9.3 Opt-Out
Opt out at any time by clicking "unsubscribe" in any marketing email, updating your account preferences, or contacting support@qualticks.com.au. We will process opt-out requests within 5 Business Days. Opting out of marketing does not affect service-related communications, which are necessary to operate your account.
10. Cross-Border Disclosure (APP 8)
10.1 Where Your Data Is Stored
Customer Data in our production database is hosted in Australia.
However, storage location and provider nationality are different things. Several of the providers we rely on are companies incorporated in the United States, even where the data itself is stored in an Australian region. Their personnel may be able to access data in the course of operating, supporting or securing their services. We treat disclosure to those providers as a cross-border disclosure under APP 8 and disclose it to you here.
10.2 Our Service Providers
ProviderPurposeWhat it handlesEntity countrySupabaseDatabase, authentication, file storageAccount data and Customer DataUnited StatesDigitalOceanApplication hostingData in transit and in processUnited StatesStripePayment processingName, email, billing detailsUnited StatesResendTransactional email deliveryName, email address and email contentUnited StatesHubSpotCustomer relationship managementContact and marketing informationUnited StatesGoogleWebsite analyticsIP address, pages viewed, browser and device informationUnited States
Countries to which personal information may be disclosed: Australia and the United States.
10.3 Safeguards
Before disclosing personal information to a provider we take reasonable steps to ensure that it is bound by contractual terms requiring protection comparable to the APPs, maintains appropriate security measures, and will use the information only for the disclosed purposes.
10.4 Acknowledgement
By using the Platform you acknowledge that your personal information will be handled by the providers listed in Section 10.2, and that United States law differs from Australian privacy law. We have taken reasonable steps to ensure your information is protected, but we cannot guarantee that an overseas recipient will not be compelled to disclose information under the law of its own jurisdiction.
10.5 Changes
We may add, remove or change providers. Where a change materially affects how personal information is handled, we will update this policy and notify subscribers by email.
11. Government Identifiers (APP 9)
We may collect ABNs, ACNs and RTO registration numbers. We will only use or disclose them for the purposes for which they were collected (for example, verifying RTO registration), as required or authorised by law, or to verify identity. We will not adopt a government identifier as our own identifier for you.
12. Data Quality (APP 10)
We take reasonable steps to ensure personal information is accurate, up to date, complete and relevant.
You are responsible for providing accurate information, updating it when it changes, and ensuring the accuracy of compliance-related data you enter into the Platform.
We may verify information against Training.gov.au (for RTO data) and ABN Lookup (for business details).
13. Data Security (APP 11)
13.1 Our Measures
We take reasonable steps to protect personal information from misuse, interference, loss and unauthorised access, modification or disclosure. Our measures include:
AES-256-GCM envelope encryption of sensitive fields at the application layer, before they are written to storage
TLS encryption for all data in transit
Password hashing (bcrypt) by our identity provider; we never store or see your password
Multi-factor authentication, available to all users and enforced after a grace period
Row Level Security enforced at the database layer
Role-based access control within each organisation
Rate limiting on authentication endpoints
Audit logging of security-relevant events
Session management, including the ability to revoke sessions
13.2 Full Details and Limitations
Our Security Policy sets out precisely what we do and — importantly — what we do not do. It states plainly that we do not hold ISO 27001 certification or a SOC 2 attestation, do not engage third-party penetration testers, do not operate a SIEM or 24-hour monitoring, and do not commit to a Recovery Point or Recovery Time Objective. Please read it before subscribing: https://www.qualticks.com.au/security-policy
13.3 No Absolute Guarantee
No method of transmission or storage is completely secure. While we take reasonable steps, we cannot guarantee absolute security. You should maintain your own backups of compliance-critical records.
13.4 Data Breach Response
In the event of a data breach we will contain it, assess whether it is an "eligible data breach" under the Privacy Act 1988(Cth), notify the OAIC and affected individuals where required, notify affected customers by email without undue delay, and take steps to prevent recurrence. See Section 18 and our Security Policy.
14. Access to Personal Information (APP 12)
You may request access to the personal information we hold about you.
How: email our Privacy Officer at support@qualticks.com.au with the subject line "Personal Information Access Request".
To process your request we may need to verify your identity, understand what information you are seeking, and confirm your preferred format.
Timeframe: we will respond within 30 days. If we need more time, we will tell you why.
Exceptions. We may refuse access where: providing access would pose a serious threat to health or safety; access would have an unreasonable impact on others' privacy; the request is frivolous or vexatious; access would prejudice legal proceedings; access would be unlawful; or refusal is required or authorised by law. If we refuse, we will give written reasons unless it would be unreasonable to do so, and tell you how to complain.
Fees. We may charge a reasonable fee for the administrative cost of providing access. We will tell you the amount before proceeding. There is no fee to make the request.
15. Correction of Personal Information (APP 13)
You may request correction of personal information that is inaccurate, out of date, incomplete, irrelevant or misleading. Update it directly in your account settings, or contact support@qualticks.com.au.
If correction is warranted we will make it within a reasonable time, at no charge, and — if you ask and it is practicable — notify third parties to whom we disclosed the information.
If we refuse, we will give written reasons, tell you how to complain, and if you ask, attach a statement to the information noting that you believe it is inaccurate.
16. Data Retention
16.1 General Retention Periods
Information TypeRetention PeriodAccount dataDuration of account + 7 yearsTransaction records7 years (legal requirement)Records of policy acceptanceDuration of account + 7 yearsMarketing dataUntil consent withdrawnSupport communications3 yearsUsage logs12 monthsSecurity event logs24 monthsCookie dataAs per cookie settings
16.2 Extended Retention for RTO Compliance
For Registered Training Organisations we maintain extended retention for compliance-critical data in accordance with the Standards for RTOs and the VET Quality Framework:
RTO-Specific InformationRetention PeriodLegal BasisUser qualifications and credentials10 years from account deactivationStandards for RTOs 2025Resumes and employment records10 years from account deactivationASQA audit requirementsProfessional development records10 years from account deactivationVET Quality FrameworkCompetency mapping records10 years from account deactivationTrainer/assessor currency requirementsTrainer/assessor competency evidence10 years from employment end dateStandards for RTOs 2025 §2.1–2.2Assessment outcome records10 years from record creationNational VET Outcome StandardsValidation evidence documentation10 years from validation dateASQA audit trail requirementsComplaints and resolution records10 years from complaint closureContinuous improvement requirements
Rationale. RTOs must produce evidence of compliance in regulatory audits. These periods enable Qualticks to support you in meeting obligations under the Standards for Registered Training Organisations, the VET Quality Framework, state training authority requirements (including VRQA and TAC), and ASQA audit requirements.
16.3 Relationship to Termination of Your Subscription
Section 15.5 of our Terms of Service gives you a 30-day window to export your Customer Data after termination. That export window is separate from retention. After the export window closes we may remove your access, but we retain data for the periods in Sections 16.1 and 16.2 above, and those periods prevail.
16.4 Security During Extended Retention
Data retained under Section 16.2 remains subject to the security measures in Section 13 and our Security Policy.
16.5 Access to Retained Data After Account Closure
Account holders may request copies of retained data within 30 days of closure. After that, access to retained RTO compliance data is limited to the former account holder (on verification, for audit purposes), regulatory authorities when legally required, and law enforcement or courts with appropriate legal orders.
16.6 Deletion
We will securely destroy or de-identify personal information when it is no longer needed and is not subject to extended retention, unless it is subject to a legal hold for litigation or investigation, regulatory authorities require continued retention, or you have asked us in writing to retain it.
16.7 Requesting Earlier Deletion
You may ask us to delete personal information earlier. We will do so where we are not required to retain it by law or by the periods above. Where we cannot, we will tell you why.
17. Children's Privacy
The Platform is not intended for individuals under 18. We do not knowingly collect personal information from children in relation to accounts. If we become aware we have, we will delete it promptly.
18. Notifiable Data Breaches Scheme
We comply with the Notifiable Data Breaches (NDB) scheme under Part IIIC of the Privacy Act 1988 (Cth).
An eligible data breach occurs where there is unauthorised access to, unauthorised disclosure of, or loss of personal information; a reasonable person would conclude that serious harm is likely to result; and we have not been able to prevent the likely risk of serious harm through remedial action.
If an eligible data breach occurs we will notify the OAIC as soon as practicable, notify affected individuals as soon as practicable, and include a description of the breach, the kinds of information involved and our recommended steps.
Where a breach affects personal information you uploaded about your own students or staff, we will notify you so that you can meet your own obligations.
19. Complaints
How to complain: email our Privacy Officer at support@qualticks.com.au with the subject "Privacy Complaint". Include your name and contact details, a description of your complaint, any relevant documents, and the outcome you are seeking.
Our response: we will acknowledge your complaint within 5 Business Days, investigate, and respond within 30 days. We will keep you informed of progress.
If you are not satisfied, you may complain to the Office of the Australian Information Commissioner:
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
Address: GPO Box 5218, Sydney NSW 2001
20. Changes to This Policy
We may update this policy. Where a change materially affects how we handle personal information, we will notify subscribers by email at least 30 days before it takes effect, publish the revised policy with a new version number and effective date, and update the "Published" date above.
Where a change requires your consent, we will ask you to accept the new version before you continue to use the Platform.
21. Contact Us
Privacy Officer RTO MATE PTY LTD (ABN 41 684 275 401) trading as Qualticks
Email: support@qualticks.com.au Postal address: PO Box 101, Craigieburn VIC 3064, Australia
We aim to respond to privacy enquiries within 5 Business Days. General support response targets are set out in Section 6 of our Terms of Service.