Privacy Policy
Version 2026-09-24.1
HA Assure Group Pty Ltd (ABN to be inserted) operates Engineering HA Assure. We comply with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.
1. Our role
For student and staff records entered by an institution, the institution decides what is collected and why; we process that information on its behalf. For our own customer contacts (for example, the person who subscribes), we are responsible for the information.
2. What is stored
- User accounts: name, email, role, sign-in history, a hashed password (never readable), and an encrypted two-factor secret.
- Student records entered by the institution: name, student number, email, program, cohort, assessment results, practice-exposure records, reflections and uploaded evidence.
- Staff profile information entered by the institution for accreditation purposes.
- Security records: an audit trail of changes, and IP addresses of sign-ins and changes.
3. How it is used
Only to provide the service: showing each user what their role permits, calculating attainment, producing reports the institution requests, securing the service, and billing. We do not sell data, show advertising, or use institution data to train artificial intelligence.
4. Who can see it
Within an institution, access follows role: a student sees only their own record; trainers see their assigned units; auditors have read-only, time-limited access and see pseudonyms for students unless the institution turns this off. Institutions cannot see each other's data. Our staff do not access institution data except to provide support you request, or where required by law.
5. Where it is stored
The service runs on Cloudflare. The database is placed in the Oceania region. Cloudflare may process data in transit through its global network. Card payments are handled by Stripe; we never see or store card numbers.
6. Security
Encryption in transit, hashed passwords, mandatory two-factor authentication for staff and auditors, session timeouts, rate limiting, per-institution isolation checked by automated tests, an append-only audit trail, and daily backups.
7. Data breaches
If we become aware of a breach likely to result in serious harm, we will notify the affected institution without undue delay and support it, and the Office of the Australian Information Commissioner where required, under the Notifiable Data Breaches scheme.
8. Retention and deletion
Data is kept while the subscription is active. After cancellation, the institution has 60 days to export; the data is then deleted, and backups age out within 35 days after that.
9. Access and correction
Students and staff should contact their institution first. You can also contact us at info@ha-assure.com. If you are not satisfied with our response, you may complain to the OAIC.
Document fingerprint (SHA-256): 1940858d258b02377f2198787d56b16959b9f166dcb841b9d76db39aaee69d2b