Skip to main content
Legal

Acceptable Use Policy

Effective 9 October 2026 · Last updated 9 October 2026 · Version 3.0 · ACADEMYSHIP PTY LTD · ACN 698 283 448 · ABN 89 698 283 448

#01Purpose and scope

This Acceptable Use Policy ("AUP") sets out the rules for using the ACADEMYSHIP platform provided by ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448). It forms part of, and is incorporated into, our Terms of Service. It applies to the web application, portals, APIs and related services. A breach of this AUP is a breach of the Terms. Capitalised terms not defined in this AUP have the meanings given in the Terms.

#02Who must comply

This AUP applies to every institution that uses Academyship and to every authorised user — administrators, staff, teachers, trainers, assessors, students, parents, guardians, contractors and anyone using our APIs.

The Institution is responsible for making its Users aware of this AUP and for managing User access. Student and guardian accounts are created, authorised and managed by the Institution. Academyship does not contract directly with students or guardians through ordinary platform use.

People who use a public or transaction feature that an Institution makes available, such as a booking, enquiry, payment, signing or credential-verification page, must also follow the rules in this AUP that apply to that feature. Doing so does not make them a party to the Terms.

#03Accounts and credentials

Keep your account credentials confidential and do not share them where individual accounts are available. Do not use another person's account, allow another person to use yours, or attempt to gain access to accounts, records or areas you are not authorised to use. Notify your institution administrator, or security@academyship.com.au, of any suspected unauthorised access.

#04Lawful use, payments and bookings

Use the platform only for lawful, authorised and education-related purposes, consistent with your institution's policies and your role. Do not use the platform to break the law, to infringe others' rights, or for any purpose the institution has not authorised.

Payments, wallets, bookings and access links

Do not:

  • make, request, approve or reverse a payment, debit, top-up, transfer or refund that you are not authorised to make, including by using a Payment Mandate beyond its terms or after it has been cancelled or paused, or has ended;
  • use a payment card, bank account, Wallet Balance, campus card or student card that is not yours, or that you are not authorised to use;
  • get around spending limits, card locks, meal or dietary restrictions, Payment Mandate limits or other payment controls set by an Institution, a Payer or the platform;
  • hold or reserve bookings, appointments, event places or waitlist positions you do not intend to use, or use bots or scripts to reserve them; or
  • share, reuse, alter or forward an invitation, booking, payment, signing, verification or other access link so that someone who is not entitled to use it can do so.

These rules do not stop anyone from asking for a refund, disputing a payment in good faith or using the dispute process of their bank, card issuer or payment-service provider (see section 17).

#05Privacy, records and identifiers

Only access personal information you are authorised and need to access for your role. Do not browse, collect, disclose or misuse personal information, and do not remove personal information from the platform other than as your role and institution policy permit. Take particular care with sensitive information, including health, disability, wellbeing and behaviour records.

Records, allegations and other people's information

Do not:

  • create or submit a complaint, incident, behaviour or welfare record, allegation or piece of evidence that you know is false or misleading;
  • use records, notes, behaviour points or welfare information to retaliate against, intimidate or punish someone for raising a concern, making a complaint or taking part in an investigation;
  • record discriminatory or demeaning labels about a person, or record an opinion or unverified allegation as if it were an established fact;
  • reveal health, welfare, behaviour, counselling or safeguarding information to anyone who is not authorised to see it;
  • disclose another person's library borrowing history, reviews, marks, grades, feedback, payment information or other records to anyone who is not authorised to see them; or
  • send documents containing personal information, such as reports, Generated Credentials, signed forms or exports, to recipients who are not authorised to receive them.

Identifiers, payroll and financial details

Tax file numbers (TFNs), Unique Student Identifiers (USIs), superannuation details, bank account and card details, passport and visa numbers and similar identifiers have additional legal protections. Use them only for the purpose they were collected for, and only if your role permits it. Do not:

  • view, reveal, export or copy a TFN, USI, bank details or payroll record unless your role and the Institution's authorisation permit it for that purpose;
  • download, share or keep a restricted payroll or sensitive-data export beyond the purpose and audience it was authorised for;
  • enter these identifiers, or other Sensitive Information, into AI prompts, support requests, comments, messages or free-text fields where they are not needed; or
  • use a TFN or USI as a general identifier, username or reference number.

#06Child safety and harmful conduct

The platform must never be used for conduct that harms or endangers others, including: bullying, harassment, discrimination or vilification; threats or incitement of violence; or content that promotes self-harm, extremism or other serious harm. Child safety is paramount. Any conduct that suggests a risk to a child must be treated seriously and reported (see sections 15 and 16).

The following are strictly prohibited:

  • child sexual abuse, child sexual exploitation, grooming, sexual solicitation of a child, sextortion, and any sexual content involving or directed at a child;
  • child sexual abuse material, including simulated, altered or AI-generated exploitative material involving children, and facilitating access to it;
  • trafficking, or arranging or attempting to arrange unlawful in-person contact with a child;
  • harassment, stalking, intimidation, coercion, blackmail or threats directed at a child;
  • encouraging or instructing a person to self-harm or take their own life;
  • unauthorised access to, or disclosure of, student information, including a child's personal or sensitive information;
  • requesting secrecy from a child, or pressuring a child to move a communication to private email, personal messaging, social media or another unapproved off-platform service;
  • retaliating against a child, a reporter, a witness or a support person for raising a safety concern in good faith; and
  • interfering with a safety investigation, including concealing evidence, destroying relevant records, pressuring a person not to report, providing knowingly false information to obstruct a genuine investigation, or alerting a suspected offender where doing so may create danger or compromise an investigation.

Attempting, encouraging, assisting, facilitating, planning or conspiring to engage in any of the above may itself breach this AUP, even where the intended conduct is not completed. See the Child Safety & Online Safety Statement for the full description of prohibited conduct and the division of responsibilities.

#07Impersonation, credentials and signatures

Do not impersonate any person or organisation, misrepresent your identity or role, or misuse another person's identity information. Do not create accounts or records using false or unauthorised identities.

Credentials, results and signatures

Do not:

  • create, issue, alter or present a certificate, statement of attainment, transcript, card or other credential that is forged, false or not authorised by the issuing Institution;
  • manipulate enrolment, attendance, completion, assessment or result records to misstate what a person has done or achieved;
  • put an accreditation, regulator, government or other organisation's mark, logo, seal or signature on a document without authority to use it;
  • sign as another person, use another person's signature, signature image or signing link, or sign for an organisation, a child or another person without authority to do so;
  • record or fabricate a consent that a person has not given; or
  • alter, delete or tamper with a signed document, its audit trail or other evidence of the signing process.

An Institution correcting, reissuing, superseding or revoking a credential or record through its own lawful processes does not breach this section.

#08Recording, photography and location

Do not make unauthorised recordings or photographs, share another person's location, or disclose personal information about others without authority. Follow your institution's policies on photography, recording and consent. Location features, where offered, may be used only as enabled by the institution and with appropriate notice and consent.

#09Uploads, content and intellectual property

Do not upload or distribute malware, viruses, or malicious or executable content, or files intended to disrupt or compromise the platform or its users. Do not upload content you do not have the right to use, and respect copyright and other intellectual property rights. The institution is responsible for the content its users upload and for having the rights and consents needed to do so. Academyship may reject, quarantine, disable access to or remove a file where its type, content, security status or use creates a legal, security or platform-integrity risk.

Learning materials, reviews and comments

Do not upload, copy or share learning materials, assessment materials, textbooks, images or other content in breach of copyright, licence terms or the Institution's rules. Do not post reviews, ratings or comments, for example on library items, events or submissions, that are abusive, harassing, discriminatory or defamatory, or that reveal personal information about others. An honest negative review, or fair criticism of a course, item, service, Institution or Academyship, is not misuse (see section 17).

#10Messaging and communications

Where messaging, comments, notices or community features are available, use them respectfully and for legitimate institutional purposes. Do not send spam, harassing or misleading messages, or use communications features to distribute prohibited content. Institution-controlled communications must follow the institution's communications and safeguarding policies.

Do not use Academyship messaging or SMS for spam; misleading sender identities; impersonation; evading opt-outs; unlawful, harmful, fraudulent or deceptive content; or any other abusive or non-compliant purpose. Do not include unnecessary Sensitive Information in SMS. Do not use notification, reminder, booking, payment or other operational messages to send marketing that the recipients have not agreed to receive or that the law does not otherwise permit. Institutions must ensure their messaging has the required consent or other lawful authority, notices and opt-out handling.

#11Academic integrity and AI use

Use assessment, examination and course features honestly. Do not engage in plagiarism, cheating, unauthorised collaboration, or dishonest use of AI-assisted features to misrepresent authorship or to gain an unfair advantage. Institutions set and enforce their own academic-integrity rules; this AUP supports, but does not replace, those rules.

#12Automation, scraping and verification pages

Do not scrape, harvest or bulk-extract data except through features or APIs provided for that purpose and within their limits. Do not use automation, bots or scripts that place an unreasonable load on the platform, interfere with its operation, or circumvent usage limits. Reasonable, authorised API use consistent with your plan is permitted.

Do not scrape, crawl, enumerate or systematically query credential-verification pages, links, codes or endpoints, booking or availability pages, or other public features, for example by guessing or generating verification codes or links or by harvesting the details they show. Checking a credential with a verification link or code you have legitimately received is permitted.

#13Security testing and unauthorised access

Do not probe, scan, exploit or test the platform or any other Academyship system without Academyship's prior written authorisation. Without that authorisation, the only security research permitted is passive, non-invasive observation of Academyship's public, unauthenticated web pages at academyship.com.au, carried out as described in our security disclosure policy. Any testing of an authenticated service, portal, account or tenant, a payment or wallet function, an electronic-signing workflow, or a credential-verification page, endpoint, link or code requires Academyship's prior written authorisation. Any authorised testing is subject to the written scope and conditions Academyship provides.

If you identify a suspected vulnerability through ordinary use or passive observation, stop before accessing Customer Data or causing disruption and report it to security@academyship.com.au.

Do not attempt to gain unauthorised access to the platform, other tenants, accounts or infrastructure, conduct credential-stuffing or brute-force attacks, or otherwise interfere with or disrupt the service.

#14Bypassing permissions and boundaries

Do not attempt to bypass or defeat tenant isolation, role and permission controls, record-level access limits, AI feature boundaries, integration controls, or file and upload restrictions. Do not exploit misconfigurations to access data or functions you are not authorised to use; instead, report them (section 15).

#15Reporting misuse and concerns

Report concerns through the right channel so they reach the right people quickly:

Where to report misuse, privacy, security and child-safety concerns
Type of concernWhere to report
Ordinary misuse or policy breachYour institution administrator, or support@academyship.com.au
A decision, charge or record made by your institutionYour institution, through its own complaint process. If the concern is about Academyship's platform or conduct, or your institution is involved in a safety or access problem, you can also contact Academyship directly using the channels in this table.
Privacy concernprivacy@academyship.com.au
Security vulnerability or incidentsecurity@academyship.com.au
Child-safety or online-safety concernsafety@academyship.com.au (see section 16)

#16Child-safety reports

If a child is in immediate danger, contact emergency services on 000 first. Academyship is not an emergency service and cannot provide an emergency response.

Report child-safety and online-safety concerns to safety@academyship.com.au and, where appropriate, to the relevant Institution. Anyone, including a child or young person, may report directly to Academyship, and does not have to tell the Institution first, particularly if the concern is about the Institution or someone who works there. Include enough information for the concern to be assessed. Reports are reviewed through Academyship's applicable support, safety and legal processes; the reporting channel is not an emergency service and reports may not be reviewed immediately.

Do not download, copy, screenshot, save, forward, share or re-upload suspected child sexual abuse material or other illegal exploitative material, and do not attach it to a support ticket or email it to Academyship. Where safe to do so, record only non-content information such as the account name, URL, message identifier, date, time and location within the platform.

Depending on the circumstances and the available technical controls, Academyship may restrict access to an account, feature or item of content while a concern is assessed, preserve available account, system or activity records where reasonably necessary and permitted or required by law, cooperate with the Institution, and make or support a referral to an authority where required or permitted by law. Academyship is not an emergency service and does not replace the Institution's safeguarding, duty-of-care or mandatory-reporting obligations. A report to Academyship does not satisfy a legal obligation to report to police, a child-protection authority or another government body — see the Child Safety & Online Safety Statement.

#17Investigation, enforcement and protected activity

Where we reasonably believe this AUP has been breached, we may investigate suspected misuse, preserve available records where reasonably necessary and permitted or required by law, and take proportionate action — including warning, restricting or suspending access to an account, disabling a feature, removing or restricting content where technically possible and lawful, contacting the Institution, responding to a lawful request or valid legal process, reporting suspected unlawful conduct to an authority, and terminating services for serious or repeated violations — and we will cooperate with the Institution. We prefer to work with the Institution to resolve issues, and enforcement will be proportionate to the seriousness of the conduct. We do not continuously monitor every User or proactively moderate all content; Institutions manage their Users and enforce their own conduct, academic-integrity and safeguarding policies where applicable.

Except where urgent action is needed under section 19, Academyship will, where reasonably possible, tell the Institution about a suspected breach and give it a reasonable opportunity to address the issue before restricting or suspending access.

What this AUP does not prohibit

This AUP does not prohibit, and Academyship will not treat as misuse:

  • making a genuine complaint, or raising a concern about safety, misconduct, privacy, discrimination or the conduct of an Institution, its staff, a User or Academyship, even if the complaint is not upheld;
  • making a disclosure that is protected by whistleblower, public-interest-disclosure or other law, or cooperating with a regulator, court, police or other authority;
  • posting an honest negative review or fair criticism;
  • asking for a refund, disputing a payment in good faith, or using the dispute process of a bank, card issuer or payment-service provider. A refund request or payment dispute is not fraud merely because an Institution disagrees with it;
  • making or defending a legal claim; or
  • reporting a suspected vulnerability in good faith in line with section 13 and our security disclosure policy.

Institutions must not use records, access controls or messaging features to retaliate against a person for any of these activities. A report or complaint the person knows to be false, or conduct that is itself prohibited by this AUP, such as harassment or unauthorised access, is not protected merely because it is presented as a complaint, review or report.

#18Institution responsibilities

Institutions manage their Users and enforce their conduct, academic-integrity and safeguarding policies where applicable. They are also responsible for student supervision, moderation of their own content and communications, configuring roles and permissions appropriately, and making disciplinary decisions. Academyship provides tools to support these responsibilities but does not assume them.

#19Urgent action by Academyship

Where necessary to protect users, data, systems, or to meet a legal obligation, we may act urgently — including restricting access or removing content — with or without prior notice, and will inform the affected institution as soon as reasonably practicable. Such action will be limited to what is reasonably necessary.

#20Changes, review and version history

We review this AUP at least annually, and out of cycle after a material legal, product, security or safety change. We will update the effective date when we change it, and prior versions can be requested from legal@academyship.com.au.

Version history

Version history for this Acceptable Use Policy.
VersionDateSummary of changes
3.09 October 2026Applied the relevant rules to people using public and transaction features without becoming parties to the Terms. Added concrete prohibitions for payments, Wallet Balances, Payment Mandates, bookings and access links; false allegations, retaliatory or discriminatory records and disclosure of welfare, borrowing, marks and other records; misuse of TFNs, USIs, payroll exports, bank details and other identifiers, including in AI prompts and support requests; forged or false credentials and results, unauthorised marks, signing as someone else, fabricated consent and tampering with signing evidence; unlicensed learning materials and abusive reviews or comments; marketing through operational messages; and scraping or enumerating credential-verification pages. Set one security-testing rule shared with the security disclosure policy: passive, non-invasive observation of public pages only, with prior written authorisation needed for authenticated, tenant, payment, signing and credential-verification testing. Added notice before restriction where reasonably possible, and protections for genuine complaints, protected disclosures, regulatory cooperation, honest negative reviews, good-faith refund requests and payment disputes, legal claims and good-faith security reports. Added a routing row for complaints about an institution's decisions and this version history. Confirmed in section 16 that anyone, including a child or young person, may report a child-safety concern directly to Academyship without telling the Institution first.
2.012 September 2026Version in effect from 12 September 2026 until replaced by version 3.0.

#21Related documents