You are on CAQA SMS
CAQA SMS - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Data Processing and Security Notice

Data Processing and Security Notice

How data is processed, stored and protected across the CAQA SMS website and platform.

This Data Processing and Security Notice explains how CAQA SMS, part of CAQA Groups and Career Calling International Pty Ltd (ABN 53 162 651 238), processes, stores and protects the information handled through this website and through the CAQA SMS student management platform. It should be read together with our Privacy Policy, which covers personal information more broadly, and with the subscription agreement that governs each organisation’s use of the platform.

Who this notice is for

This notice is written for the education providers who evaluate or subscribe to CAQA SMS, including registered training organisations, CRICOS and ELICOS colleges, higher education providers and TAFEs, and for the administrators, compliance managers and data officers responsible for student information within those organisations. It is also relevant to any visitor who submits information through this website.

Data collected through this website

This website is an information and enquiry site. The only data collected here is the information you submit through the contact and enquiry forms (such as your name, organisation, phone number, email address and message), the email address you provide if you subscribe to The VET Sector newsletter, and standard analytics information about how visitors use the site. No payments are taken through this website, so no payment card or banking details are collected or stored here.

Data held in the CAQA SMS platform

Subscribing organisations use the platform to manage enrolment applications, student records, results and certification, attendance and timetabling, funding data and government reporting extracts. That data belongs to the subscribing organisation. CAQA processes it only to provide, support and maintain the platform under the subscription agreement, and does not use student records for marketing or any unrelated purpose.

Your organisation’s responsibilities

The client organisation remains responsible for the lawful collection, accuracy and currency of the student records it enters into CAQA SMS. This includes collecting information with appropriate notice and consent, keeping records up to date, limiting staff access to what each role requires, and meeting the organisation’s own obligations under the Privacy Act 1988, VET data provisions, funding contracts and the Standards for RTOs. The platform’s validation and audit tools support those obligations; they do not transfer them to CAQA.

Hosting, access controls and security measures

Platform data is hosted in secure data-centre environments with encryption of data in transit, role-based access control, authentication requirements for all users, logging of administrative actions and separation between client environments. Access by CAQA personnel is limited to staff who need it to deliver support or maintenance, and that access is logged and reviewed.

Backups and continuity

Backups run on a scheduled cycle and are retained in line with the subscription agreement. Restoration processes are tested so that service can be recovered after hardware failure, data corruption or another incident. Planned maintenance that could affect availability is notified in advance wherever practicable.

Incident reporting

If we become aware of a security incident affecting client data, we will assess and contain it promptly and notify affected subscribing organisations without undue delay, so that they can meet their own obligations, including any notification duties under the Notifiable Data Breaches scheme. Clients and users should report suspected incidents, lost credentials or unusual account activity to us immediately using the contact details below.

Data return and deletion

When a subscription ends, the organisation may export its data in standard formats within the period set by the subscription agreement. After that period, data is deleted or de-identified in accordance with the agreement and any retention obligations that apply to us at law.

Limits of this notice

This page is general information about our approach to data handling and security. It is not a security certification, a contractual service level or legal advice. The binding commitments that apply to a particular organisation are set out in its subscription agreement and related schedules.

Contact

Questions about this policy can be emailed to info@caqa.com.au, raised by phone on 1800 266 160, or submitted through our contact page. We respond to most enquiries within two business days.

Newsletter Subscription

To Receive Updates And Offers