If a child is in immediate danger, call Triple Zero (000). Academyship is a software provider — not an emergency service, a school, a carer, a child-protection authority or a monitoring service. If a child is in immediate danger, a serious offence is occurring now, or urgent police, ambulance or fire assistance is required in Australia, call 000 first. Outside Australia, contact your local emergency service. Then, where the concern involves the platform, tell the child's Institution and email safety@academyship.com.au. See section 17 for official reporting pathways.
#01Purpose, scope and audience
This statement describes the commitments of ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) ("Academyship", "we", "us") to the safety, wellbeing and online safety of children and young people, in our role as the technology provider of a multi-tenant education and institution management platform (the "platform" or "Services"). Modules are available by plan and configuration, so not every feature described in this statement is used by every Institution.
It is written for Institutions and their staff, parents and guardians, students, procurement and safeguarding teams, regulators and the public. Academyship's customers ("Institutions") include universities, colleges, registered training organisations, vocational and workforce-development providers, schools and other education and training organisations. Some Institutions serve children and young people (people under 18); others serve only adult learners. Where this statement refers to "children and young people", it means learners who are minors; where it refers to "learners" or "Users", it includes adults.
This statement explains Academyship's child-safety approach and the respective roles of Academyship and Institutions. Contractual obligations are contained in the applicable Order Form, Terms of Service, Data Processing Addendum, Acceptable Use Policy and any other agreement entered into with Academyship. It does not replace an Institution's own child-safety, safeguarding or duty-of-care policies, or any legal obligation an Institution or individual has.
#02Definitions used in this statement
Defined terms used here — including Customer, Institution, User, Authorised User, Customer Data, Student Data, Sensitive Information, Integration, Subprocessor and AI Features — have the meanings given in our Terms of Service, Privacy Policy and DPA. In addition, in this statement:
- Child or young person means a person under 18 years of age.
- Child sexual abuse material (CSAM) means material that depicts or describes the sexual abuse or exploitation of a child, including simulated, altered or artificially generated material.
- Grooming means conduct intended to build a relationship, trust or emotional connection with a child, or with a person who has care of a child, in order to enable sexual abuse, exploitation or another form of harm.
- Safeguarding means the arrangements an organisation puts in place to protect children from harm, including policies, screening, training, supervision, reporting and response.
- Reporting channel means Academyship's designated child-safety and online-safety reporting address, safety@academyship.com.au.
#03Our child-safety principles
Academyship places the safety, wellbeing, dignity, privacy and rights of children and young people at the centre of how we design, build, operate and support the platform. We hold zero tolerance for child sexual abuse, child sexual exploitation, grooming and child sexual abuse material. We are committed to reducing the risk that our technology is used to harm a child, and to responding appropriately when a concern involving the platform is raised with us.
We seek to align our practices, as a technology vendor supporting Institutions, with the National Principles for Child Safe Organisations and with the principles of Safety by Design published by the eSafety Commissioner — service provider responsibility, user empowerment and autonomy, and transparency and accountability — to the extent those principles apply to an organisation in our role.
We do not claim any child-safety certification, accreditation, audit result or regulator endorsement, and this statement should not be read as one. Our role complements — it does not replace — the safeguarding responsibilities of the Institutions that use the platform.
#04Shared responsibility model
Child safety on the platform depends on both parties doing their part. Academyship builds, operates, secures and supports the software. The Institution operates the educational service and decides who has an account, what roles and permissions those accounts have, which features are enabled, how communication and safeguarding processes work, and what information is collected and kept within its tenant.
| Area | Academyship | Institution |
|---|---|---|
| Platform | Builds, hosts, secures, maintains and supports the Services; provides administrator controls. | Configures the Services for its students, staff, jurisdiction and safeguarding model. |
| People | Manages its own personnel and their authorised, least-privilege access. | Authorises, screens, trains and supervises its own staff, contractors, volunteers, students and guardians. |
| Supervision | Does not supervise learners and does not continuously monitor or pre-screen Institution activity, communications or content. | Supervises learners, moderates its own content and communications, and enforces its own conduct rules. |
| Safeguarding decisions | Acts on platform-related reports within its technical and contractual ability. | Makes safeguarding, welfare, disciplinary and duty-of-care decisions about its students. |
| Reporting to authorities | May make or assist with a report where required or permitted by law. | Determines and discharges its own mandatory-reporting and statutory notification obligations. |
White-label configuration must not hide or prevent access to required child-safety, reporting, privacy, accessibility or emergency information. Institutions that apply their own branding must ensure Users can still locate their safeguarding contacts and Academyship's platform-related reporting channel, consistent with section 7A of our Terms of Service.
#05Institution responsibilities
Each Institution is responsible for establishing, maintaining and enforcing child-safety arrangements appropriate to its services, its students, its jurisdiction and its legal obligations. Academyship provides tools that can support those arrangements; it does not assume them, and it cannot discharge them on an Institution's behalf.
Governance and policies
The Institution must:
- maintain its own child-safety, safeguarding and student-welfare policies;
- maintain codes of conduct for staff and contractors;
- establish clear professional-boundary requirements;
- define who is responsible for receiving and escalating child-safety concerns;
- maintain appropriate internal complaint and investigation procedures;
- review its safeguarding procedures periodically; and
- ensure its Academyship configuration supports its safeguarding model.
Screening and suitability
The Institution must:
- determine which staff, contractors and volunteers perform child-related work;
- complete Working with Children Checks or equivalent screening where legally required for the role and jurisdiction;
- perform appropriate identity, qualification, reference and suitability checks;
- prevent unauthorised or unsuitable personnel from accessing student information;
- remove or change access when a person's role changes; and
- disable access promptly when employment, engagement or enrolment ends, where appropriate.
Screening requirements are not universal. Whether a person requires a Working with Children Check or another clearance depends on the nature of the role and the law of the relevant state or territory. The Institution — not Academyship — determines which of its roles require screening.
Training and awareness
The Institution must:
- provide safeguarding and child-safety training appropriate to staff roles;
- train staff on professional communications with students;
- explain mandatory-reporting and escalation pathways to those who need them;
- provide students and families with age-appropriate safety information;
- explain how a concern can be raised; and
- ensure staff understand the difference between a technical support request to Academyship, an institutional safeguarding response, and a report to an authority.
Accounts and access
The Institution must:
- approve users before granting access, and verify identity where appropriate;
- assign minimum-necessary permissions;
- prevent account sharing;
- review administrative access periodically and monitor privileged accounts;
- remove inactive or unauthorised accounts;
- supervise temporary workers and contractors;
- configure parent, guardian and student access appropriately;
- restrict access to sensitive student information; and
- review Integrations and exported information.
Communications
The Institution must:
- establish rules for staff-to-student communications;
- decide when one-to-one communication is permitted;
- establish rules for out-of-hours communication;
- require professional language and conduct;
- determine when a parent, guardian or additional staff member should be included;
- prohibit requests for secrecy and inappropriate personal contact;
- prevent Users from moving safeguarding-sensitive communication to unapproved private services;
- supervise messaging functions appropriately; and
- determine suitable record-retention practices for communications.
Consent and transparency
The Institution must:
- provide the privacy collection notices required of it;
- obtain parental, guardian or student consent where legally required;
- explain how the Institution uses Academyship;
- explain which external services or Integrations receive information;
- explain how images, recordings and student work may be used;
- respect lawful withdrawal, correction and deletion requests; and
- avoid collecting unnecessary information about children.
Incident response
The Institution must:
- maintain emergency escalation procedures;
- identify the relevant police, child-protection and regulatory channels for its jurisdiction;
- determine which of its people are mandatory reporters;
- avoid delaying a statutory or emergency report;
- preserve relevant institutional records;
- protect reporters from retaliation;
- support affected students;
- cooperate with lawful investigations; and
- avoid any action that may endanger a child or compromise an official investigation.
Configuration responsibility
Each Institution must configure Academyship in a manner appropriate to the age, maturity, vulnerability, location and circumstances of its students and the Institution's legal and safeguarding obligations. Accepting default platform settings is not, by itself, sufficient to satisfy an Institution's safeguarding obligations. Where the Institution's risk assessment requires a feature to be restricted or disabled, it is the Institution's responsibility to make that change.
#06Academyship's role and limits
Academyship operates and maintains the platform and provides it to Institutions under the Terms of Service. We provide administrator controls, role-based permissions, tenant isolation, auditability of key actions, and a channel through which platform-related child-safety concerns can be raised with us.
Academyship is not a school, registered training organisation, educator, carer, guardian, counsellor, emergency service, child-protection authority or live monitoring service. We do not supervise learners, do not provide pastoral or clinical care, and do not continuously monitor, pre-screen or moderate Institution communications or content in real time. We do not confirm that harmful conduct or harmful content will be detected or prevented.
Responsibility for supervision, safeguarding decisions, mandatory reporting by the Institution, and the day-to-day care of students rests with the Institution and its staff, consistent with the role allocation in our Terms and DPA. Nothing in this statement transfers an Institution's safeguarding function to Academyship, and nothing in it suggests that Academyship has no responsibility for the platform it provides.
The platform records what Institutions and Users enter; it does not establish that a person is safe to be around children. An account, a staff role, a guardian link, a booking or a visitor sign-in record does not mean that a Working with Children Check, background check or identity verification has been completed. Academyship does not determine whether a person is suitable for child-related work or whether a person is a mandatory reporter. Those matters belong to the Institution's own screening and safeguarding processes (section 5) and to the law.
#07Safety by design in the platform
The platform is built as an institution-controlled system rather than an open social network. Depending on how an Institution configures it, safety-relevant controls can include:
- institution-controlled accounts and enrolment, so access is authorised rather than open to the public;
- role-based permissions that limit what each account can see and do;
- tenant isolation, so one Institution's data and users are logically separated from another's;
- administrator controls for enabling, restricting or disabling features;
- auditability of key actions to support accountability and later review;
- restrictions on who can communicate with whom; and
- the ability to restrict or remove access to content or accounts where required for safety, security or law.
We describe controls at a general level and do not publish implementation detail that could help someone misuse the platform. Not every control listed is enabled in every Institution or module; availability depends on the Institution's plan, configuration and the features it has turned on.
Student access is authorised and managed by the Institution, and accounts operate within the Institution's tenant rather than being open to the general public. Where guardian or parent access is available, the Institution decides whether it is enabled and what it can see.
#08Accessible and child-friendly reporting
Children and young people should be able to raise a concern in a way they can understand and use. Institutions are responsible for making this possible within their own services; Academyship supports it through plain-language materials such as the Student Privacy Guide and the Student Guide to Acceptable Use.
The following principles should apply wherever a child may need to speak up:
- Children should be listened to and taken seriously.
- Children can raise a concern themselves, including directly with Academyship. A trusted adult can help, but a child should never be required to go through an adult in order to report.
- A child should never be directed to raise a concern only with the person it is about, or only with an Institution whose staff are involved; another route should always be available.
- A child should not be punished for raising a concern in good faith.
- Reports should be handled respectfully and without retaliation.
- Information should be provided in age-appropriate language.
- Reporting information should be available in accessible formats where reasonably possible.
- Institutions should provide alternative reporting methods for children who cannot use a standard online form or written process.
- Institutions should consider disability, language, cultural background, literacy, digital access and communication needs.
- Children should be told what may happen after they make a report, subject to safety and confidentiality requirements.
- Parents or guardians should be involved where lawful, appropriate and safe.
- A parent or guardian should not automatically be contacted where doing so may place the child or another person at greater risk.
- Institutions should obtain professional or authority guidance where disclosure decisions are sensitive.
- A child's report should not be dismissed only because it is incomplete, delayed, unclear or made through an informal channel.
- Good-faith reports must be protected even where an allegation is not ultimately substantiated.
Some children face additional barriers to reporting safely, or additional risk if a report is mishandled. Circumstances that may create such barriers include disability, limited English proficiency, low digital literacy, cultural or linguistic barriers, trauma history, out-of-home-care experience, geographic isolation and limited family support. No child should be labelled as inherently vulnerable; what matters is that the individual circumstances and barriers in front of you are considered, and that reporting is adjusted so the child can actually use it.
#09Prohibited conduct
The following conduct is prohibited on the platform. These prohibitions apply to every User, are consistent with our Acceptable Use Policy, and apply in addition to the law and to an Institution's own rules.
Sexual exploitation and abuse
- Child sexual abuse and child sexual exploitation.
- Grooming, sexual solicitation and sextortion.
- Requests for sexual images or recordings.
- Sharing, or threatening to share, intimate images.
- Sexualised communication with a child.
- Child sexual abuse material, including simulated, altered or AI-generated exploitative material involving children.
- Facilitating access to exploitative material, or encouraging another person to exploit a child.
- Trafficking or attempted trafficking.
- Arranging or attempting to arrange unlawful in-person contact with a child.
Coercion and manipulation
- Blackmail, coercion, intimidation, threats, manipulation or bribery.
- Requests for secrecy.
- Attempts to isolate a child from trusted adults.
- Attempts to move a child to an unapproved private communication service.
- Requests for personal contact details for an inappropriate purpose.
- Requests for live location or private location information.
- Attempts to arrange private meetings without lawful authority and appropriate safeguards.
Harassment and harmful behaviour
- Bullying, cyberbullying, harassment and stalking.
- Hate-based abuse, humiliation and doxxing.
- Threats of violence.
- Encouragement of self-harm or suicide.
- Deliberately exposing children to violent, sexual, exploitative or degrading content.
- Retaliation against a child, a reporter, a witness or a support person.
Account and access misuse
- Creating fake student, parent, guardian or staff accounts.
- Impersonating another person.
- Accessing student information without authority.
- Sharing credentials, or using another person's account to contact a child.
- Circumventing supervision or access controls.
- Using hidden, misleading or unauthorised communication channels.
- Exporting student information for an unauthorised purpose.
- Sharing a child's personal or sensitive information without authority.
Interference with reporting or investigations
- Concealing evidence or destroying relevant records.
- Pressuring a person not to report, or threatening a reporter.
- Providing knowingly false information to obstruct a genuine investigation.
- Alerting a suspected offender where doing so may create danger or compromise an investigation.
- Interfering with an Institution, police, regulator or child-protection investigation.
Attempting, encouraging, assisting, facilitating, planning or conspiring to engage in prohibited conduct may itself violate this policy, even where the intended conduct is not completed.
#10Communications involving children
Communication features, where offered, are configured by the Institution. The Institution decides whether a feature is available, who may use it and which audiences it applies to, and can restrict or disable it. Where a communication involves a child:
- the communication must have a legitimate educational, administrative, welfare or support purpose;
- Users must maintain professional boundaries;
- staff must use Institution-approved accounts and channels;
- Users must not request secrecy from a child;
- Users must not pressure a child to move communication to private email, personal messaging, social media or another unapproved platform;
- personal contact details must not be requested or shared for an inappropriate purpose;
- one-to-one communication must comply with Institution policy and applicable law, and the Institution should determine whether another staff member, parent or guardian must be included;
- out-of-hours communication is governed by the Institution's rules;
- attachments, images, audio, video and links must be appropriate and authorised;
- unnecessary images, recordings, identification documents or location information must not be requested; and
- staff must not use Academyship to pursue a personal, romantic, sexual or exploitative relationship.
Institutions must decide how communication records are reviewed, retained and escalated. Academyship does not continuously monitor or moderate the content of messages and is not responsible for supervising an Institution's staff-to-student communications. The fact that the platform technically permits a communication does not mean Academyship has reviewed or approved it. Learners should follow their Institution's rules and the plain-language Student Guide to Acceptable Use.
Bookings, appointments, events and meeting links
Booking and event features are designed for an Institution's own scheduling and communication, not as an open social network. Where an Institution uses them, these points need particular care:
- Booking forms and invitations. Booking forms and invitations can collect names, email addresses and phone numbers, and can link a booking to a student or a guardian. A link sent by email or message can be forwarded, so it should not be the only check on who may book an appointment that concerns a child.
- One-to-one appointments. A booking can arrange a meeting between a staff member and a child. The Institution's rules on one-to-one contact apply to appointments booked through the platform, including whether a parent, guardian or another staff member must be present or told, and where and how the meeting takes place.
- Event comments. Comments on an event may be visible to other people who can view that event, so they are not a private channel. Institutions should set rules for who may comment and should review comments on events that children can see.
- Meeting links. An event or appointment can include an online meeting link. Depending on the meeting service's settings, anyone who obtains the link may be able to join. Institutions should share meeting links only with the intended audience and use the meeting service's own access controls for sessions involving children.
- Calendar exports. Adding an event or appointment to a Google, Outlook or Yahoo calendar, or downloading a calendar file, sends the selected details to that provider or device, outside the platform's access controls. Such a calendar link is not an Academyship Subprocessor or a connected Integration. Event titles, descriptions and locations should not contain a child's sensitive information.
#11Images, recordings and student content
Images, audio, video and student work involving children are handled by the Institution under its own consent, photography, recording and record-keeping policies. The Institution is responsible for obtaining any consent required, for explaining how images, recordings and student work may be used, and for honouring a lawful withdrawal of that consent.
The non-consensual or harmful sharing of images, recordings or personal information is prohibited, as is the making of unauthorised recordings or photographs. Where content of this kind is identified or reported to us, Academyship may — depending on the circumstances and the available technical controls — restrict access to an account, feature or item of content while the concern is assessed, preserve available records where reasonably necessary and permitted or required by law, and make a referral where required by law. We do not scan or pre-screen all content proactively, and we do not publish the operational detail of how content is assessed.
Do not download, copy, screenshot, save, forward, share or re-upload suspected child sexual abuse material or other illegal exploitative material. Where safe to do so, record only non-content information such as the account name, URL, message identifier, date, time and location within the platform. Follow instructions provided by police, the eSafety Commissioner, the Australian Centre to Counter Child Exploitation or another authorised agency. Do not attach or send suspected illegal material to Academyship.
Student cards, credentials and documents for signature
Certificate and card templates can include a student's photograph and, where an Institution chooses, other details such as a student identifier, an emergency contact or health information. A printed or digital card can be lost, shared or photographed, so Institutions should print only the details a card actually needs and take particular care with details that could help someone locate or contact a child. Where an Institution uses certificate and card review and fix assistance, a rendered image of a card, including any photograph on it, may be sent to Academyship's AI provider to propose a fix; it is not used to identify the child or analyse their features (see the Responsible AI Statement).
Documents sent for electronic signature, such as consent or enrolment forms, may concern a child. Signing on the platform does not by itself show that the signer has authority to sign for that child, and a guardian link in a portal is not, by itself, authority to sign every document, consent to medical treatment or accept a financial obligation. The Institution decides who must sign each document and should confirm that person's authority before relying on the signature. Completed documents may be sent to signers and other recipients, who then hold their own copies.
#12Privacy and access controls for children
Academyship does not sell Student Data, does not use Student Data for advertising, and does not use Customer Personal Data to train general-purpose AI models. Academyship hosts its core production platform and Customer Data in Sydney, Australia; the limited circumstances in which processing may occur outside Australia are described in our Privacy Policy, DPA and Subprocessor Register.
Within the platform, access to information is limited by role and by the principle of least privilege, and sensitive information is subject to additional controls where the Institution configures them. Institutions should collect the minimum information about a child that their purpose actually requires, and should restrict access to welfare, health, disability, behaviour and other sensitive records to the people who genuinely need it.
Institutions are responsible for providing privacy notices to students, parents and guardians, and for obtaining any consents required for their collection and use of Student Data. How we handle personal information is described in our Privacy Policy and, for children specifically, in plain language in the Student Privacy Guide. Handling of Customer Personal Data on behalf of Institutions is governed by our DPA.
Behaviour, wellbeing and support records
Where an Institution uses behaviour and wellbeing features, staff can record incidents, allegations and remarks, goals, interventions and follow-up notes, evidence files, and points or rewards. These records can be sensitive and can affect how a child is treated. Institutions should:
- record an allegation as an allegation, separately from what has been established, and note who made it;
- keep records factual and proportionate, without unnecessary health, family or other sensitive details;
- restrict who can see allegations, wellbeing notes, interventions and evidence to the people who genuinely need them;
- give students, and parents or guardians where appropriate, a way to ask for a record to be reviewed or corrected and to challenge a decision made using it; and
- handle a safeguarding concern through the Institution's safeguarding and reporting processes, not only as a behaviour entry.
Behaviour notifications can be sent automatically to students, parents, guardians or staff when rules the Institution configures are met, such as a points threshold or a type of incident. These alerts are rule-based notifications. They are not clinical triage, a risk assessment, emergency monitoring or a report to an authority, and Academyship does not watch or respond to them. An alert can be delayed or fail to arrive, so it must not be relied on for an urgent matter. Before enabling notifications to a parent or guardian, the Institution should consider whether telling that person could place the student at risk. Academyship does not use AI to score a child's behaviour or wellbeing.
Guardian linking, custody and adult learners
A linked parent or guardian sees only what the Institution has authorised for that relationship; a parent or guardian does not automatically see every record about a student. Before linking a guardian account, or sending notifications or records about a child to a guardian, the Institution should confirm that person's authority for that purpose. A family relationship or a matching email address is not, by itself, proof of authority. The Institution should apply any court order, parenting arrangement, custody restriction or safeguarding restriction it is aware of, review links when circumstances change, and remove access that is no longer authorised. Notifications sent by email or SMS can be read by anyone with access to the recipient's inbox or phone.
Not every learner is a child. An adult learner has their own privacy rights, and a parent or guardian's access to an adult learner's information needs a lawful basis; it does not continue automatically because it existed when the learner was under 18.
Information that can be seen outside the platform
Some features can make limited information about a student available outside the authenticated portals:
- Public credential verification. Where an Institution enables it, anyone holding a valid verification link or code can see limited credential details: the holder's name, credential number and type, course, issue date, issuing Institution and the credential's current status. This is not a searchable public profile, and not every field on a certificate template is shown. A verification link or code printed on a certificate can be passed on by whoever holds it. For a child, the Institution should consider whether public verification is needed and whether a course name could itself reveal something sensitive.
- Documents and copies shared outside the platform. Certificates, cards, signed documents, exports, emails, SMS messages and calendar files can be downloaded, printed or sent to people outside the platform. Once a copy has been delivered or downloaded, removing access in the platform does not retrieve it.
The Institution decides whether to enable these features and what to share, and must have lawful authority to disclose the information involved.
#13Third-party services and integrations
Institutions may connect third-party services (Integrations) to Academyship. The Institution — not Academyship — selects, authorises and is responsible for those services and for the resulting data flows. An Integration does not automatically gain the ability to contact students; it operates according to the access the Institution grants it and its own terms.
Before connecting an Integration that may touch information about children, the Institution should consider:
- whether the service is suitable for children, and its minimum-age requirements;
- whether parent or guardian consent is required;
- what student information is transferred, and whether the transfer is necessary;
- where the data is stored, and whether cross-border disclosure occurs;
- the service's privacy terms and security controls;
- whether the service uses advertising, creates user profiles, or uses information for AI training;
- whether the service permits direct messaging or exposes students to public content;
- how accounts are created and deleted, and how permissions are revoked;
- how data is exported or removed;
- how safety complaints are handled; and
- whether Institution staff retain appropriate oversight.
Once information is transferred to an Institution-selected third-party service, that service's separate terms, privacy practices and security arrangements may apply. Academyship does not control the independent conduct of an external service.
Institutions must not connect unnecessary or unsuitable services, must disable Integrations that are no longer required, and must review Integration permissions periodically. Academyship's own subprocessor arrangements are described separately in the DPA and the Subprocessor Register; an Institution-selected Integration is not an Academyship Subprocessor and must not be described as one.
#14AI Features and children
Each Institution may enable, disable or restrict AI Features through its configuration and role permissions. The AI Features Academyship currently makes available are for use by authorised Institution personnel, and Academyship does not currently make a generative-AI feature available for students to use. Access is limited to the Tenant and to the requesting User's permissions.
Where AI Features are used with information about children:
- the Institution controls availability, role-based access and age-appropriate use;
- outputs are decision support subject to authorised human review;
- an AI Feature must not autonomously make, and must not be the sole basis for, a decision with a legal or similarly significant effect on a child;
- Users should avoid placing unnecessary Sensitive Information about a child into a request;
- the Institution is responsible for reviewing AI-assisted content before it is relied on or placed into an official record;
- AI Features must not be used to groom, exploit, harass, deceive or unlawfully profile a child; and
- incorrect, unsafe or inappropriate AI output should be reported (see section 16).
Academyship does not use AI for biometric identification, emotion inference, or automated wellbeing, health or behavioural scoring of children. Customer Personal Data, including information about children, is not used to train general-purpose models.
AI output may be inaccurate, incomplete or unsuitable for its intended context. It must not be treated as professional welfare, medical, psychological, counselling or legal advice about a child. Full detail of Academyship's AI governance, the feature inventory, the AI provider arrangements and the processing locations is set out in the Responsible AI Statement, with the corresponding privacy and contractual detail in the Privacy Policy, DPA and Subprocessor Register.
#15Academyship personnel and support access
Academyship personnel and contractors are subject to confidentiality obligations and access information only on a least-privilege, need-to-know basis for an authorised purpose, such as providing support, operating the service or meeting a legal obligation. Support access is authorised, limited to the minimum necessary scope and logged.
Support involving a student is mediated through the Institution rather than conducted privately with the student. Academyship personnel must not form a private, off-platform relationship with a student, and must not use their access for any purpose other than the authorised one.
Academyship assesses whether particular roles require screening, suitability checks or legally required clearances based on the nature of the role and applicable law. We do not claim that every member of personnel holds a Working with Children Check; requirements depend on the role and the applicable state or territory law. Where a check is obtained, the record is treated as sensitive and held with restricted access. Academyship may provide relevant personnel with guidance or training appropriate to their responsibilities, including how to recognise and escalate a child-safety concern.
#16Reporting a concern to Academyship
Reporting a concern. If a child is in immediate danger, call 000 first (see section 17). For a concern involving the platform, tell the child's Institution — it is usually best placed to act and holds the safeguarding responsibility — and email Academyship at safety@academyship.com.au. If the concern is about the Institution or someone who works there, you do not have to raise it with them first: you can contact Academyship or an authority directly. Children and young people can report to us themselves; see If you are a child or young person.
Reports submitted through Academyship's designated reporting channel are reviewed through Academyship's applicable support, safety and legal processes. The reporting channel is not an emergency service, and reports may not be reviewed immediately. It does not replace an Institution's safeguarding, duty-of-care or mandatory-reporting obligations.
Where it is safe and lawful to do so, it helps to include:
- the Institution's name;
- your name and contact details;
- the affected account or user, and the account or user you are concerned about;
- a description of the concern;
- the date and time;
- the relevant page, account, message identifier or feature;
- whether a child is in immediate danger;
- whether police, a child-protection authority or another authority has been contacted; and
- any non-illegal supporting records.
You do not need to provide every item before we will accept a report. Anonymous or incomplete reports may still be assessed, although limited information can affect our ability to identify the accounts involved or to investigate.
Do not attach or send suspected child sexual abuse material to Academyship. Do not upload it to a support ticket, email it to us, or circulate it to colleagues. Describe it instead, using non-content details such as the account name, URL, message identifier, date and time, and follow the directions of police, eSafety or the Australian Centre to Counter Child Exploitation.
Do not confront a suspected offender where doing so may increase risk, do not alert a suspected offender that a report has been made, and do not conduct your own unlawful investigation. For ordinary evidence of bullying, threats, harassment or a policy breach — which is not illegal material — an Institution may instruct authorised personnel to preserve relevant records or screenshots in accordance with its own procedures.
Concerns that also involve a privacy issue or a security vulnerability can additionally be sent to privacy@academyship.com.au or security@academyship.com.au; see our security disclosure page for vulnerabilities.
If you are a child or young person
You can tell us yourself about something on Academyship that worries you. You do not need an adult's permission. Email safety@academyship.com.au and say what happened in your own words; you do not need to know every detail. A trusted adult, such as a parent, carer, teacher, school counsellor or another adult you trust, can help you if you want, but you do not have to involve anyone.
If the problem is about a teacher or someone else at your school, college or training provider, you do not have to tell them first. You can tell us, another adult you trust, or a service such as eSafety or the police. If you are in danger right now, call 000. You can also talk to Kids Helpline on 1800 55 1800 at any time.
Please do not send us private or sexual pictures or videos of anyone under 18, even of yourself. Just tell us where you saw them. If someone is threatening to share a picture of you, it is not your fault, and you can get help from eSafety or the ACCCE (see section 17).
We will take what you tell us seriously. You will not be in trouble with Academyship for telling us about something that worries you, even if it turns out to be a mistake. We will try to keep what you tell us private, but if someone may be in danger we may need to tell people who can help keep them safe, such as your Institution, the police or a child-protection service. If your concern is about someone at your Institution, we will think carefully about who we contact so that you are not put at greater risk.
#17Immediate danger and official reporting pathways
If a child is in immediate danger, a serious offence is occurring now, or urgent police or medical assistance is required in Australia, call Triple Zero (000) immediately. If you are outside Australia, contact your local emergency service. Do not wait for Academyship to respond.
Depending on the nature of the concern, the following official Australian services may be appropriate. Academyship is not affiliated with these agencies and does not control their processes.
eSafety Commissioner
Reports can be made through the eSafety Commissioner's Report online harm service (esafety.gov.au). Depending on eligibility, eSafety may accept reports about matters such as serious cyberbullying involving an Australian child, image-based abuse, and illegal or restricted online content, along with certain other online-safety complaints within its jurisdiction. A guide to what can be reported is published at What you can report to eSafety. eSafety does not handle every child-protection matter, and for many concerns eSafety asks that the content first be reported to the service on which it appeared.
Australian Centre to Counter Child Exploitation
Reports can be made through the ACCCE Report abuse service (accce.gov.au). This may be appropriate for suspected online grooming, inappropriate sexual contact involving a child, online child sexual exploitation, child sexual abuse material, and sextortion involving a child.
Police, child protection and other authorities
Depending on the circumstances and the jurisdiction, you may also need to contact:
- state or territory police;
- the state or territory child-protection agency;
- the relevant education regulator;
- a relevant professional regulator; and
- any other authority required by applicable law.
Institutions should identify the correct contacts for their own jurisdiction in advance, as part of their escalation procedures, rather than searching for them during an incident.
#18Mandatory reporting and statutory notifications
A report to Academyship does not replace emergency reporting, mandatory reporting or notification to a child-protection authority, police, regulator or other appropriate authority.
Mandatory-reporting laws differ between Australian states and territories. Requirements may also differ according to profession, role, Institution type, student age and the circumstances of the matter. A person who is a mandatory reporter in one state or role may not be in another.
Academyship does not determine whether an Institution or an individual is a mandatory reporter. Institutions and Users must understand and comply with their own obligations, and Institutions should identify which of their people carry them.
Reporting a concern to Academyship does not satisfy a legal obligation to report to police, a child-protection authority, a regulator or another government body. Reporting internally to an Institution may also not replace an external statutory report. No person should delay an emergency or statutory report while waiting for Academyship to respond.
Academyship may make or assist with a report where required or permitted by law. Academyship does not provide individual legal advice about mandatory-reporting obligations; where an obligation is unclear, obtain advice from the relevant authority or a qualified adviser — and, where a child may be at risk, report first.
#19How Academyship may respond
Our response to a platform-related child-safety report depends on the nature of the report, the immediate safety risk, the information available to us, our technical capability, our contractual rights, our privacy obligations, legal restrictions, preservation requirements, any direction from law enforcement or a regulator, and the Institution's own role in the matter.
Depending on those circumstances, we may:
- acknowledge and assess a report;
- request additional non-illegal information;
- contact the Institution;
- restrict access to an account, feature or item of content while the concern is assessed;
- disable access where appropriate;
- preserve available account, system or activity records where reasonably necessary and permitted or required by law;
- remove or restrict content where technically possible and lawful;
- refer the matter internally for a decision;
- refer the matter to police, a regulator or another authority;
- respond to valid legal process; and
- suspend or terminate access for serious or repeated misuse.
We do not promise a fixed response time or a particular outcome, immediate review, the removal of all copies of content, the recovery of information outside our control, notification to every person involved, or the disclosure of confidential investigative details. Appropriate timeframes and actions depend on the nature and seriousness of the matter.
Academyship may be unable to provide detailed updates where doing so could compromise safety, privacy, legal obligations, an investigation or another person's rights.
#20Evidence, confidentiality and good-faith reporting
We treat reports about children with care and respect, and we recognise that a child or young person may find it hard to raise a concern. Academyship will not retaliate against a person for making a good-faith report about child safety on the platform. Institutions must not punish a child for raising a safety concern in good faith, and must protect reporters, witnesses and support people from retaliation.
There is an important difference between a knowingly false or malicious report and a report that simply cannot be substantiated. A person will not be treated as having made a false report merely because the available evidence is insufficient, because the report was incomplete or delayed, because a reasonable mistake was made, or because it was made by a frightened or distressed child. Deliberate misuse of the reporting process — for example, a knowingly false report made to harass another person or to obstruct an investigation — may result in action under our Acceptable Use Policy or by the Institution.
We handle these matters on a need-to-know basis and limit information to the people who reasonably need it. Confidentiality cannot be guaranteed: disclosure may be required to protect a person, to investigate a concern, to respond to an Institution's lawful request, or to comply with the law or valid legal process.
On evidence, follow section 16. Do not duplicate or circulate suspected illegal material. For ordinary bullying, threats, harassment or policy-breach records, the Institution's own preservation procedures apply.
#21Cooperation with Institutions and authorities
The Institution typically leads the response for its own students, and we cooperate with it. Where a concern is about an Institution or its staff rather than the platform, we will, where appropriate, direct you to the relevant authority and, where it is safe to do so, to the Institution's own complaints process — and, where the matter involves platform misuse, we may still act under our Acceptable Use Policy. We will not direct a child to raise a concern only with the person, or only with the Institution, that the concern is about.
Academyship cannot control the conduct of an Institution or its staff and has no authority over how an Institution handles its own safeguarding matters. We cooperate with police, child-protection authorities, regulators and other authorities where required or permitted by law, and we respond to valid legal process. If you are not satisfied with how we have handled a platform-related concern, you can escalate to complaints@academyship.com.au. If your complaint concerns the person who handled your concern, say so, and it will be handled by someone who was not involved. Our Complaints page explains the process.
#22Enforcement
Where we reasonably believe the platform has been misused in a way that affects child safety, we may investigate, take proportionate action and cooperate with the Institution, consistent with sections 17 and 19 of the Acceptable Use Policy and sections 29 and 30 of the Terms of Service. Action may include warning, restricting or suspending access to a feature or an account, removing or restricting content, or terminating services for serious or repeated violations.
Enforcement is proportionate to the seriousness of the conduct, and we prefer to work with the Institution to resolve an issue. Where urgent action is necessary to protect a person, data or systems, or to meet a legal obligation, we may act with or without prior notice and will inform the affected Institution as soon as reasonably practicable. We do not continuously monitor every User or proactively moderate all content.
#23Records and retention
Where we handle a platform-related child-safety matter, we keep records of it with restricted access and retain them in accordance with the law and our retention arrangements. We may preserve available account, system or activity records where reasonably necessary and permitted or required by law, including where an authority or valid legal process requires it.
We do not publish details of individual matters. Personal information involved is handled in accordance with our Privacy Policy and, where it is Customer Personal Data, our DPA, including the deletion and return arrangements described there. Institutions are responsible for the retention of their own safeguarding records.
#24Online-safety and children's privacy regulation
Australian online-safety requirements — including the Online Safety Act 2021 (Cth), the Basic Online Safety Expectations and eSafety's Safety by Design guidance — may apply differently depending on the nature and functionality of a service. Whether a feature falls within a category of service regulated under that Act, or under an industry code or standard made under it, depends on how the feature works and on the instruments in force at the time. We do not claim that every provision applies to every Academyship feature, and we make no blanket claim of full compliance with every requirement of that framework.
Academyship considers relevant online-safety expectations in the design and operation of applicable platform features, and may review its obligations as messaging, file-sharing, community, AI or other interactive functionality changes. Institutions remain responsible for their own use and configuration of the platform, and Academyship may take action against unlawful or seriously harmful platform misuse.
Children's privacy regulation in Australia continues to develop, including through the Office of the Australian Information Commissioner's work on a Children's Online Privacy Code. The Privacy Act requires the Australian Information Commissioner to register that Code by 10 December 2026, and the OAIC has consulted on a draft. A draft Code is not binding: the registered Code will determine which services it covers, what it requires and when its obligations commence. Academyship will assess how the registered Code applies to its services using the final instrument, and does not assume that its services fall outside the Code, or outside the online-safety framework, merely because they are education services. Academyship monitors relevant developments in children's privacy and online-safety regulation and may update its services and policies where new obligations apply. We do not claim compliance with a code that is not yet in force.
#25Review and changes to this statement
We review this statement at least annually, and may also review it following a serious incident, a material service change, or a relevant legal or regulatory development. Accountability for this statement, for the handling of platform-related child-safety reports and for its review sits with Academyship's management.
We welcome feedback from Institutions, students, families and affected Users, and we use it — together with what we learn from incidents — to improve our controls and this statement. Where we change this statement we will update the effective date and the change history below; prior versions can be requested from legal@academyship.com.au.
#26Contact details
Use the channel that matches the concern so that it reaches the right people:
| Situation | Where to go |
|---|---|
| Immediate danger to a child | Call 000 (Australia), or your local emergency service. Do not wait for Academyship. |
| Child-safety or platform-abuse report | safety@academyship.com.au — see section 16. Do not attach suspected illegal material. |
| Institutional safeguarding concern | The child's Institution, through its own safeguarding or complaints process. Academyship cannot act in the Institution's place. |
| Report to an authority | eSafety Commissioner, the ACCCE, police or your state or territory child-protection agency — see section 17. |
| Privacy complaint | privacy@academyship.com.au |
| Security vulnerability or incident | security@academyship.com.au — see the security disclosure page. |
| Legal request or legal process | legal@academyship.com.au |
| Complaint about our handling | complaints@academyship.com.au |
| General technical support | Your Institution administrator, or support@academyship.com.au — see Support. |
Post: Child Safety, ACADEMYSHIP PTY LTD, Unit 44, 3-7 Fetherstone Street, Bankstown NSW 2200, Australia.
#27Related policies
This statement sits alongside the following documents, which continue to apply:
#28Change history
| Version | Date | Summary of changes |
|---|---|---|
| 1.1 | 9 October 2026 | Added module-specific guidance on behaviour, wellbeing and support records and rule-based behaviour alerts (which are not clinical triage or emergency monitoring); guardian linking, custody restrictions and adult learners; booking forms, one-to-one appointments, event comments, meeting links and calendar exports; student cards, credentials and documents for signature; and public credential verification and copies shared outside the platform. Added direct reporting guidance for children and young people, confirmed that a trusted adult can help but is never required, and that a child will not be directed to report only to the person or Institution a concern is about. Clarified that platform records are not screening or vetting. Updated the Children's Online Privacy Code and Online Safety Act position, and aligned the AI Features wording with version 2.0 of the Responsible AI Statement, including removal of the launch-availability statement. Complaints about the person who handled a concern now go to complaints@academyship.com.au, to be handled by someone not involved, with a link to the Complaints page. |
| 1.0 | 12 September 2026 | Initial publication of the Child Safety & Online Safety Statement. |