Legal
Privacy policy
How we handle your personal information, in plain English.
This policy is a starting template and should be reviewed by your legal adviser before the site goes live. It is written to align with the Australian Privacy Principles under the Privacy Act 1988 (Cth).
What we collect
- Account details — name, email address, and optionally phone number, job title and organisation.
- Learning records — which lessons you have completed, assessment attempts and scores, and certificates issued.
- Technical data — IP address, browser type and page requests, held in server logs.
- Enquiries — anything you send us through the contact form.
We do not collect payment card details on this site, and we do not ask for a Unique Student Identifier, because non-accredited training does not require one.
Why we collect it
- To provide the training and issue certificates in your legal name;
- To let you and, where applicable, your employer see your training status;
- To allow third parties to verify a certificate you present to them;
- To keep the service secure and to investigate misuse;
- To reply to your enquiries.
What is public
Certificate verification pages are public and are not indexed by search engines. Someone with a certificate number can see the holder's name, the course, the issue and expiry dates, the assessment score and the organisation recorded on the account. That is the point of verification — but be aware of it before entering an organisation name you would rather not share.
Who we share it with
- Your employer, where they hold a team account you are linked to — they can see your progress, scores and certificates.
- Service providers who host the site and process payments, under contract and only as needed to run it. See Where your information is stored below.
- Where required by law, including a lawful request from a regulator or court.
We do not sell personal information, and we do not use it for advertising.
Where your information is stored
The site and its database are hosted in Australia. Card payments are processed by Stripe, whose servers are in the United States; we never see or store your card details.
Payment processing therefore involves information leaving Australia. Under Australian Privacy Principle 8 we remain accountable for it: we take reasonable steps to ensure our providers handle it consistently with the Australian Privacy Principles, and a breach by them is treated as a breach by us.
Cookies
We set a single essential cookie to keep you signed in. We do not use advertising or third-party analytics cookies. Fonts are served from Google Fonts, which means your browser makes a request to Google's servers when a page loads.
How long we keep it
Training records and certificates are retained for at least seven years, because they are compliance records your employer may need to produce in an audit. Server logs are retained for 90 days. Enquiries are retained for two years.
Security
Passwords are stored hashed with bcrypt and are never visible to us. Traffic is encrypted in transit. Access to the administration area is restricted and every administrative action is written to an audit log.
Your rights
You may request access to the personal information we hold about you, ask us to correct it, or ask us to delete your account. Deleting your account also deletes your certificates and their verification records, which cannot be undone — if your employer relies on them, talk to them first.
Email kirby@oakmedspa.com.au. We respond within 30 days. If you are not satisfied with our response you may complain to the Office of the Australian Information Commissioner at oaic.gov.au.
Last updated: October 2026.