You are on CAQA Data
CAQA Data - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Data Processing and Security Notice

Data Processing and Security Notice

How CAQA Data processes, secures, retains, returns and deletes the datasets handled during our data services engagements.

Section 1: Purpose of this notice

This Data Processing and Security Notice explains how CAQA Data, part of CAQA Groups and Career Calling International Pty Ltd (ABN 53 162 651 238), processes, stores, secures and ultimately returns or deletes the data entrusted to us. CAQA Data provides AVETMISS validation and lodgement support, USI data support, data cleaning, system migrations, funding data review, data quality programs and reporting services, and this notice covers the datasets handled in that work as well as the information collected through this website.

Section 2: Our role in processing your data

When your organisation engages CAQA Data, we process student and operational data on your behalf and on your instructions. Your organisation remains the custodian of its records and the party responsible for its regulatory reporting obligations. We do not use client datasets for our own purposes, we do not sell or share them, and we do not combine one client's data with another's. Our own handling of personal information collected through this website is described in our Privacy Policy.

Section 3: Categories of data we process

Depending on the engagement, we may process AVETMISS and NAT file data, unique student identifiers and supporting identity fields, enrolment, participation, result and completion records, funding and claims data, student management, learning management and CRM system exports, and the reference data needed to validate and reconcile them. We ask clients to limit datasets to what the engagement genuinely requires.

Section 4: How data enters and leaves our environment

Datasets are exchanged only through the secure transfer method agreed at the start of an engagement, such as an encrypted transfer channel or a secure shared workspace, as set out in our Data Services Terms. We discourage and do not initiate the exchange of student data through ordinary email. Deliverables are returned through the same agreed channel.

Section 5: Where data is stored and who can access it

Client datasets are held in access-controlled environments, with client material kept separate and access limited to the team members working on your engagement. Access is authenticated, granted on a need-to-know basis and removed when no longer required. Our confidentiality obligations, and those of everyone who works on your data, are described in our Confidentiality policy.

Section 6: Security measures

We apply layered safeguards appropriate to the sensitivity of education data, including encryption of data in transit, authenticated and least-privilege access, separation of client environments, secure disposal of working files, and regular review of who holds access to what. No system can be guaranteed absolutely secure, but we design engagements so that data is held in as few places, for as short a time, and by as few people as the work allows.

Section 7: Retention, return and deletion

We keep client datasets only for the duration of the engagement plus any short retention period agreed for warranty or support purposes. At completion we return final datasets and deliverables and delete or de-identify our working copies within the agreed window, unless the law requires longer retention. Written confirmation of deletion is available on request. Engagement records such as proposals, correspondence and invoices are retained as ordinary business records.

Section 8: No payment data

No payments are taken through this website, and we therefore collect no cardholder or payment data through it. Engagement fees are invoiced under the agreed scope and paid through ordinary banking channels; this website stores no payment credentials of any kind.

Section 9: Data breach response

If we become aware of a data breach affecting client data, we will act promptly to contain and assess it, notify the affected client without undue delay with the facts as we know them, cooperate with the client's own obligations to students and regulators, and comply with the Notifiable Data Breaches scheme under the Privacy Act 1988 (Cth) where it applies to us.

Section 10: Service providers

We use a small number of reputable infrastructure and productivity providers to operate our business, selected with regard to their security practices. We do not engage subcontractors to work on your datasets without your agreement, and specialists from other CAQA Groups brands are involved only where the agreed scope requires it.

Section 11: Your responsibilities

Effective security is shared. Your organisation is responsible for the accuracy and lawful provision of source data, for scoping any system credentials it issues to us and revoking them at engagement end, for authorising submissions made from prepared data, and for maintaining its own backups of source systems before any migration or bulk correction commences.

Section 12: Contact

Questions about this notice, our security practices, or the handling of a specific dataset can be raised through our contact page, by email to info@caqa.com.au, by phone on 1800 266 160, or by mail to 2/10 Lawn Court, Craigieburn, Victoria 3064.

Newsletter Subscription

To Receive Updates And Offers