#01Purpose and status
This page explains how long records in Academyship are kept, who decides, what brings each retention period to an end, how records can be exported, and what happens when information is deleted or an Institution stops using Academyship. It is published by ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) ("Academyship", "we", "us").
This page is an information schedule. It is not a contract and does not form part of the Terms of Service or the Data Processing Addendum unless a signed Order Form expressly says so. The contractual commitments on backups, export, termination and deletion are in section 22 and section 23 of the Terms of Service, and in section 20 and Annexes I and II of the Data Processing Addendum (DPA). This page explains those commitments in more detail. It does not reduce them, and if it ever appears to conflict with them, the Terms, the DPA or the applicable Order Form govern.
Capitalised terms such as Institution, User, Customer Data, Tenant, Sensitive Information, Regulated Identifiers, Fees and Order Form have the meanings given in the Terms, the DPA and the Privacy Policy. "Institution Charges" means amounts an Institution charges its students, payers or others (for example, tuition, instalments, canteen purchases, library fines or booking fees). Those are different from Academyship's own Fees.
Not every module described below is available to every Institution. Modules are available by plan and configuration, and a row applies only where the Institution uses that feature.
#02Key terms: deleting is not the same as archiving
Several actions can make information disappear from view. They have very different effects, so this page uses the following terms consistently.
| Term | What it means | Is the information still held? |
|---|---|---|
| Deactivation | A User account is switched off, so that person can no longer sign in. The records linked to the person stay in the Institution's workspace. | Yes. Deactivating an account ends access. It does not delete records. |
| Archive | A record is moved to an inactive or read-only state, for example when a student completes a course. Archived records are kept for record-keeping and can usually be viewed by authorised Users. | Yes. Archiving is a form of retention, not deletion. |
| Soft deletion | A record is marked as deleted and hidden from ordinary screens, but it remains stored so that it can be recovered from a mistake or until permanent deletion runs. Some parts of the platform may use this approach. | Yes. A soft-deleted record is still personal information and is protected and handled as such until it is permanently deleted. |
| Permanent deletion | A record is removed from Academyship's active systems (the live database, file storage and the indexes and previews derived from them). Copies in backups are not erased at the same moment. They expire as described in section 10. | Not in active systems. A copy may remain in a backup until that backup expires, and copies already held by others are covered in section 13. |
| De-identification | Identifying details are removed or altered so that the information is no longer about an identified or reasonably identifiable individual in the context in which it is held. Whether information is de-identified depends on who holds it and what other information is available to them, so it needs ongoing safeguards (section 11). | A changed version is kept. It is no longer personal information only while re-identification is not reasonably possible. |
| Anonymisation | A stricter form of de-identification, where the information is altered or aggregated so that no individual can be identified from it by anyone using reasonably available means, and the change cannot reasonably be reversed. | Only an anonymous or aggregated version is kept. |
| Link or access expiry | A download link, signing link, invitation or similar access route stops working after a set time. | Yes. Expiry ends that route of access. It does not delete the underlying record. |
| Backup expiry | A backup recovery point reaches the end of its life in the backup cycle and is removed. | This removes the backup copy only. It is not the same as deletion from active systems, and data deleted from active systems can still exist in unexpired backups. |
| Legal hold | A direction to preserve specified information even though it would otherwise be deleted (section 12). | Yes, for the held information, with restricted access, until the hold is released. |
#03Who decides how long records are kept
Records in an Institution's workspace. The Institution controls the records in its workspace and decides how long they are kept, subject to the laws that apply to it. Those can include education, vocational training, employment, tax, financial, health-records, child-safety and (for public bodies) public-records and state or territory privacy laws. Academyship stores and processes those records on the Institution's instructions under the DPA. Academyship does not decide, for example, how long a school keeps a behaviour record or how long a training organisation keeps assessment evidence.
Records Academyship controls. Academyship decides how long it keeps its own business records (for example, customer contacts, its own billing, contract and acceptance records, support tickets and complaints) and the technical records it needs to run and secure the service (for example, infrastructure and security logs and backups). Academyship also sets platform rules that apply across workspaces, such as how long sign-in events are kept and how long a generated download remains available.
Records held by others. Payment providers, banks, email and calendar services chosen by a User, Institution-selected Integrations and government recipients keep their own copies under their own obligations. See section 13.
Whoever decides, the same principles apply:
- keep information only for a clear purpose, and only for as long as that purpose or a legal obligation requires;
- do not keep detailed histories indefinitely simply because storage is inexpensive;
- prefer deletion or de-identification once a record is no longer needed, as Australian privacy law generally requires for personal information an organisation no longer needs, unless the law or a court or tribunal order requires it to be kept;
- keep sensitive records, such as welfare notes, identity-document images, dietary and health details and Regulated Identifiers, for shorter periods and with tighter access where the law allows; and
- do not confuse the end of an Academyship subscription with the end of an Institution's own legal duty to keep records.
#04How to read the schedule
Schedules A to E below group records by type. Each row states:
- Responsible decision-maker: who sets the retention period;
- Purpose and retention rule: why the record is kept and the rule that decides how long;
- What ends the period: the event that brings retention to an end, such as the Institution's own period expiring, a record being deleted, or the end of the export window after an Institution leaves;
- Export and access: how the record can be obtained;
- Deletion and backup exceptions: what can remain after deletion; and
- Contact and reference: where to go with a question.
A retention rule is different from a legal minimum period, from a period an Institution configures, from the event that triggers deletion, from how often a clean-up process runs, and from how long a copy can remain in a backup. This page states a fixed number only where Academyship has committed to that number: infrastructure and security logs are kept for 30 days; Customer Data remains available for authorised export for at least 60 days after termination or expiry; and platform backups keep 30 daily, 15 weekly and 7 monthly recovery points. Each of those numbers applies only to the records it describes. Where no number is stated, the rule, the decision-maker and the ending event are stated instead.
To keep the tables readable, they use these short forms:
- "Standard exceptions" means: information under a legal hold (section 12); copies in platform backups until the recovery points that contain them expire (section 10); and copies outside Academyship's control (section 13).
- "Workspace export" means: authorised Institution administrators can export the record through Academyship's export functions during the subscription and during the export window after termination. When an Institution leaves, it can export all of its records, including attachments, audit trails and signing evidence (section 14). Students, staff, guardians and other individuals ask the Institution for access.
#05Schedule A: admissions, academic and credential records
| Record class | Responsible decision-maker | Purpose and retention rule | What ends the period | Export and access | Deletion and backup exceptions | Contact and reference |
|---|---|---|---|---|---|---|
| Student, enrolment and academic records (enrolments, classes, attendance, timetables, results and academic history) | The Institution. | Kept to provide and evidence education and to meet the Institution's education, records-management and reporting duties. Legal minimums differ by sector, state or territory and record type, and some academic records must be kept for many years. | The Institution's own retention period for the record type ends, or the export window after termination ends. | Workspace export. | Standard exceptions. Archiving a record keeps it. | The Institution. Terms section 23. |
| Unsuccessful applicants, withdrawn applications and prospective-student enquiries | The Institution. | Kept to process the application or enquiry, to answer questions about the decision, and to meet any legal obligation. They should not be kept indefinitely after a decision or withdrawal. | The Institution's admissions retention period after the decision, withdrawal or last contact ends. | Workspace export. | Standard exceptions. The Institution may keep a minimal record of a decision while a complaint, appeal or legal claim about it remains possible. | The Institution's admissions office. |
| Assessment evidence, recognition of prior learning (RPL) evidence and vocational compliance records | The Institution, under the rules of its regulator. | Kept to evidence assessment and RPL decisions and to meet reporting and audit obligations. Sector rules can require long periods. For example, current ASQA guidance for registered training organisations describes keeping completed assessment items for at least two years after completion and keeping the records needed to reissue AQF certification documentation for 30 years. Those are the Institution's obligations. They are not periods for which Academyship hosts a workspace after the Institution leaves. | The Institution's regulatory retention period ends. At exit, the Institution must export what it still needs before the export window ends. | Workspace export. Long-term archiving after exit is the Institution's responsibility unless an Order Form provides for separately agreed hosting. | Standard exceptions. | The Institution. Education Operations. |
| Certificates, letters, cards and the templates used to generate them | The issuing Institution. | Kept so the Institution can reissue, verify and correct credentials. A correction or revocation should be recorded as a change of status or a superseding credential, not by silently overwriting what was issued. | The Institution deletes the credential record or its retention period ends, or the export window after termination ends. | Workspace export. Holders obtain copies from the Institution. | Standard exceptions. Copies already delivered to holders or shared with others remain with them. | The issuing Institution. |
| Public credential verification, and verification look-up records if collected | The Institution decides whether verification is enabled for a credential. Academyship decides the retention of any security records of look-ups. | Where enabled, anyone holding a valid verification link or code can see limited details: the holder's name, the credential number and type, the course, the issue date, the issuing Institution and the credential's current status. This is not a searchable public profile. If Academyship records verification look-ups, it uses those records only to protect the verification service (for example, to detect scraping or attempts to guess codes), keeps them for a limited period, and does not use them to profile who checked a credential. | The Institution turns verification off, revokes or deletes the credential, or the workspace is deleted after exit. Any look-up records end when their security-retention period ends. | Verification shows only the limited details above. The full record is available through the Institution. | Standard exceptions. People who have already viewed or saved the details keep them. | The issuing Institution. Misuse of verification links: security@academyship.com.au. |
#06Schedule B: student services and operations
| Record class | Responsible decision-maker | Purpose and retention rule | What ends the period | Export and access | Deletion and backup exceptions | Contact and reference |
|---|---|---|---|---|---|---|
| Behaviour incidents, goals, interventions, points, rewards and related notes | The Institution. | Kept for the Institution's welfare, discipline and safeguarding purposes. These records can contain allegations and opinions as well as established facts, so they should be accurate, proportionate and reviewed. Records relevant to child safety can be subject to long retention periods or disposal restrictions under state or territory law. | The Institution's retention period for the record type ends, or the export window after termination ends. | Workspace export. Individuals ask the Institution for access or correction. | Standard exceptions. Notifications already sent to guardians or staff remain with those recipients. | The Institution. Platform-related child-safety concerns: safety@academyship.com.au. |
| Behaviour evidence files (uploaded photos, documents and other attachments) | The Institution. | Kept with the incident record they support. Only evidence that is needed should be uploaded. Suspected child sexual abuse material must never be uploaded. Report it to police or the ACCCE instead. | The evidence file or its incident record is deleted, or the incident record's retention period ends. | Workspace export. An exit export includes these files (section 14). | Deleting a record includes its associated uploaded files and derived previews. Standard exceptions. | The Institution. Child Safety section 16. |
| Homework submissions, evaluations, grades and feedback (individual and group) | The Institution. | Kept for assessment, feedback, academic-integrity and appeal purposes, under the Institution's academic-records rules. | The Institution's retention period ends, or the export window after termination ends. | Workspace export. Students ask the Institution. | Standard exceptions. | The Institution. |
| Library borrowing history, reservations, fines, reviews and reminders | The Institution. | Loan details are needed to manage current loans, returns and fines. A detailed borrowing history can reveal a person's interests and sensitive matters, so it should not be kept longer than needed once an item is returned and any fine is resolved. Fine and payment records may need to be kept longer for financial-record purposes than the loan details themselves. Reviews are kept while published under the Institution's moderation rules. | The item is returned and any fine is resolved and the Institution's period for loan history ends; a review is removed; or the export window after termination ends. | Workspace export. Borrowers ask the Institution. | Standard exceptions. Reminder emails and messages already delivered remain with recipients. | The Institution's library. |
| Bookings and appointments | The Institution. | Kept to deliver the appointment and to handle changes, attendance and any related Institution Charge. | The Institution's retention period after the appointment ends, or the export window after termination ends. | Workspace export. | Standard exceptions. Entries a User has added to an external calendar are copies outside Academyship's control. | The Institution. |
| Abandoned bookings, temporary holds and waitlist entries | The Institution. | A temporary hold reserves a slot while someone completes a booking. It is not a confirmed booking. When a hold lapses, the slot is released, but details already entered may remain stored. Waitlist entries are kept while the waitlist is open and offers can be made. Lapsed holds, abandoned bookings and closed waitlists should be removed once they no longer serve a purpose. | The Institution removes the entry or its period for these entries ends; the waitlist closes; or the export window after termination ends. Expiry of a hold changes its status only. | Workspace export. | Standard exceptions. Details typed into a booking form may also be held briefly in the person's browser (see Schedule D). | The Institution. |
| Events, RSVPs, comments, attachments and event history | The Institution. | Kept to run the event and for the Institution's records of what was arranged and changed. | The event, comment or attachment is deleted, or the Institution's period ends, or the export window after termination ends. | Workspace export. | Standard exceptions. Calendar entries and meeting links people have copied elsewhere remain with them. | The Institution. |
| Visitor sign-in records | The Institution. | Kept to know who was on the premises and to support site safety. A visitor log is not a background check or a child-safety clearance. | The Institution's visitor-record period ends. That period should be short unless an incident or a legal requirement needs the record. | Workspace export. Visitors ask the Institution. | Standard exceptions. | The Institution's front office. |
| Visitor identity-document images | The Institution. | Should be collected only where necessary. Sighting a document without storing an image is often enough. Where an image is stored, it should be kept for the shortest practical period with access limited to the roles that need it. Storing an image is not identity verification by Academyship. | The Institution deletes the image or its period for identity images ends, which should be soon after the visit unless an incident or legal requirement applies. | Workspace export, limited to authorised roles. | Deleting the image includes its derived previews. Standard exceptions. | The Institution. Academyship's handling: privacy@academyship.com.au. |
| Front-office enquiries, call logs, correspondence and complaints received by the Institution | The Institution. | Kept to respond, follow up and keep a record of what was raised. Call logs hold the details staff enter, such as the caller, time, duration and notes. Complaints recorded in this module are the Institution's own complaint records, handled under the Institution's complaints process. | The Institution's period after the matter is closed ends, or the export window after termination ends. | Workspace export. | Standard exceptions. | The Institution. |
| Canteen orders, meal plans, dietary and allergy restrictions, and campus card identifiers | The Institution (and any food-service operator acting for it). | Orders are kept for service, collection and financial records. Dietary and allergy information should be kept current and removed or updated when it is no longer accurate or the student leaves. A campus card identifier is kept while the card is active. It is not a bank card credential. | The card is cancelled or replaced; the plan ends; the student leaves; the Institution's period ends; or the export window after termination ends. | Workspace export. Families ask the Institution. | Standard exceptions. Wallet balances are covered in Schedule C. | The Institution. |
#07Schedule C: money, payroll and signing
| Record class | Responsible decision-maker | Purpose and retention rule | What ends the period | Export and access | Deletion and backup exceptions | Contact and reference |
|---|---|---|---|---|---|---|
| Institution Charges: invoices, payments, refunds, payment authorities (such as PayTo mandates) and payment disputes | The Institution for its records. The payment provider and banks for their own records. | Kept for receipts, reconciliation, refunds, disputes and the Institution's tax and financial-record obligations. A requested refund and a completed refund are separate records, and both are kept. | The Institution's financial-record period ends, or the export window after termination ends. A dispute or open refund keeps the related records until it is resolved. | Workspace export. Payers ask the Institution, and can ask their bank or the payment provider about records those organisations hold. | Standard exceptions. Records held by the payment provider and banks are outside Academyship's deletion control. | The Institution. Payments and Wallets. |
| Wallet balances, top-ups and transfers (where the Institution uses wallets) | The Institution. | Transaction history is kept for financial records and to resolve disputes. A wallet record with an unresolved balance is not deleted until the balance has been dealt with. What happens to a remaining balance when a student leaves, a wallet is closed or the Institution stops using Academyship is explained in Payments and Wallets. | The wallet is closed and any balance resolved, and the Institution's financial-record period ends. | Workspace export. Families ask the Institution. | Standard exceptions. | The Institution. |
| Payroll, time and wage records (pay, leave, superannuation, bank details, reimbursements and corrections) | The employer (the Institution). | Kept to pay staff correctly and to meet employment, tax and superannuation obligations. Employers generally must keep time and wages records for seven years under Australian workplace law, and other tax and superannuation rules may also apply. That is the employer's obligation. It does not mean Academyship hosts payroll records for seven years after the employer leaves unless an Order Form says so. | The employer's legal retention period ends. At exit, the employer must export what it still needs before the export window ends. | Workspace export, restricted to roles the employer authorises for payroll exports. Staff ask their employer. | Standard exceptions. Information already sent to banks, superannuation funds or government recipients is outside Academyship's control. | The employer. Payroll and STP, Staff Privacy Guide. |
| Tax file numbers (TFNs) and tax declarations | The employer. | TFN information may be collected and kept only for permitted tax, superannuation and related purposes. TFN rules require TFN information to be securely destroyed or de-identified once it is no longer required by law or administratively necessary. Access to full TFNs and TFN exports is limited to roles the employer separately authorises. | The TFN information is no longer required by law or administratively necessary. | Through the employer only. TFNs must never be sent to Academyship support. | Standard exceptions. | The employer. Academyship's handling: privacy@academyship.com.au. |
| Electronic-signature draft documents (not yet sent) | The sender, under a clean-up rule set by Academyship. | Kept only so the sender can finish and send the document. A draft that is not sent becomes eligible for clean-up after a set period. An eligible draft may remain stored until clean-up next runs. | The sender deletes or sends the draft, or clean-up removes it. | Available only to the sender and authorised Institution Users. | Standard exceptions. | support@academyship.com.au. |
| Electronic-signature records: sent and completed documents, signer details, consent and disclosure versions, and the signing audit trail | The Institution that sent the document. | Kept for the period the Institution sets, so that the document, the version presented and how it was signed can be shown later. Signing evidence is preserved and not edited. Corrections are made by a new or superseding document. A signing link stops working after a set time, but its expiry does not delete the document or its evidence. | The Institution's retention period for the document ends, or the export window after termination ends. | Workspace export. An exit export includes the signing evidence. Signers keep the copies they received or downloaded and ask the sending Institution for any further copy. | Standard exceptions. Signers' copies remain with them. | The sending Institution. Electronic Signatures. |
#08Schedule D: accounts, messages, logs and technical records
| Record class | Responsible decision-maker | Purpose and retention rule | What ends the period | Export and access | Deletion and backup exceptions | Contact and reference |
|---|---|---|---|---|---|---|
| User accounts, including deactivated accounts of staff, students and guardians who have left | The Institution. | An account is kept while the person needs access. The Institution should deactivate access promptly when it is no longer needed. Deactivation ends access but keeps the records linked to the person, which follow their own rows in this schedule. | The Institution deletes the account, or the export window after termination ends. | Workspace export. | Standard exceptions. | The Institution. Terms section 6. |
| Portal invitations and sign-in events (time, IP address, browser and device information, and outcome) | The Institution manages invitations. Academyship sets the retention rule for sign-in events. | An invitation link expires after a set time. Sign-in events are kept for a limited period for security and access review, and are removed when that period ends unless a legal hold or an open security investigation applies. | The invitation is accepted, revoked or expires; the sign-in event reaches the end of its security-retention period. | Available to authorised Institution administrators where the platform displays them, or through support for a security investigation. | Legal hold or open security investigation. Copies in backups until those recovery points expire. | The Institution. security@academyship.com.au. |
| Notification content (email, SMS, push and in-app messages and reminders) | The Institution for message content and in-platform message history. Academyship for delivery records. | In-platform copies of messages follow the Institution's records. Academyship's appointed email and SMS delivery services keep delivery records under their agreements with Academyship. | The Institution's period for message history ends, or the export window after termination ends. | Workspace export for in-platform history. | Delivered messages, including lock-screen previews, stay on recipients' devices and in their mailboxes and cannot be recalled. Standard exceptions. | The Institution. privacy@academyship.com.au. |
| AI Features: inputs, outputs and usage records | The Institution decides whether an output is saved into a record. Academyship decides the retention of its logs. | An output that an authorised User saves into a record is kept with that record. AI usage, security and audit events recorded in Academyship's infrastructure and security logs are kept for 30 days. Customer Data is not used to train general-purpose AI models. Prompts and outputs that are not saved into a record are handled as described in the Responsible AI Statement. | The record holding a saved output is deleted; the 30-day log period ends. | Saved outputs are exported with their record. | Legal hold or open security investigation. Standard exceptions. | Responsible AI section 14. |
| Browser storage on your device | Academyship decides what its pages store. The person controls their own browser. | Some pages keep limited information in the browser so that the page works, such as display preferences or the progress of a multi-step form. The Cookie Policy describes the items and their lifetimes. | The item's lifetime ends as described in the Cookie Policy, or the person clears their browser's site data. | Held on the device, not by Academyship. | Academyship's server-side deletion does not reach a device. On a shared device, clear the browser's site data after use. | Cookie Policy. |
| Generated exports, reports and audit packs, and their download links | The User who requested the export. Academyship sets the clean-up rule. | A download link works for a limited time. The generated file is kept for a limited period so that it can be downloaded, and is then removed. | The link expires (this ends access only); the generated file is removed by clean-up. | This is itself an export. | Expiry of the link does not delete the underlying records. A copy already downloaded stays with whoever downloaded it. Standard exceptions. | support@academyship.com.au. |
| Uploaded files, previews and thumbnails, and search and AI-related indexes | Follows the record they belong to. | Derived copies exist so that records can be displayed and searched. They are kept only as long as the record they come from. | The source record is deleted. Deletion includes associated uploaded files, derived previews, search indexes and AI-related indexes where applicable. | With the source record. An exit export includes uploaded files (section 14). | Standard exceptions. | Section 10. |
| Infrastructure and security logs | Academyship. | Kept to operate, secure, troubleshoot and investigate the service. Infrastructure and security logs are retained for 30 days. | 30 days after the log entry is created. | Not a workspace export. Relevant information is shared with an affected Institution during an incident where appropriate. | Kept longer only where needed for an open security investigation, a complaint or dispute being handled, a legal hold or a legal requirement. | security@academyship.com.au. DPA Annex II. |
The 30-day rule applies to infrastructure and security logs. It does not apply to business audit trails kept inside an Institution's workspace, such as the history of changes to a record, signing evidence or the record of who viewed or exported a sensitive field. Those trails are part of the Institution's records and follow the row for the record they relate to.
#09Schedule E: Academyship's own records
Academyship is the responsible entity for these records under the Privacy Policy. Where they contain Customer Data (for example, a screenshot attached to a support ticket), Academyship also handles that Customer Data under the DPA.
| Record class | Responsible decision-maker | Purpose and retention rule | What ends the period | Export and access | Deletion and backup exceptions | Contact and reference |
|---|---|---|---|---|---|---|
| Institution business contacts and account administration records | Academyship. | Kept to administer the customer relationship, send service and account notices, and meet legal obligations, while the relationship continues and for a reasonable period afterwards to deal with follow-up questions. If someone opts out of marketing, a minimal record is kept so that the opt-out continues to be respected. | The customer relationship ends and the follow-up period passes, or a contact asks to be removed and there is no other reason to keep the details. The information is then deleted or de-identified. | On request to privacy@academyship.com.au. | Legal and tax obligations; potential legal claims; backups until expiry. | Privacy Policy section 26. |
| Website enquiries, sign-up details and prospective customers | Academyship. | Kept to respond to the enquiry or sign-up and to follow up while it is active. | The enquiry is closed and no relationship follows, or the person asks to be removed. The information is then deleted or de-identified. | On request to privacy@academyship.com.au. | Marketing opt-out records; backups until expiry. | Privacy Policy section 26. |
| Partner and program applications, including unsuccessful applicants | Academyship. | Kept to assess the application and to answer questions about the outcome. Unsuccessful applications are kept only for as long as needed for that purpose and any legal obligation. | The outcome is final and the period for questions or complaints about it passes. The application is then deleted or de-identified. | On request to privacy@academyship.com.au. | Legal obligations; potential legal claims; backups until expiry. | Privacy Policy section 26. |
| Academyship's own billing, invoices and tax records (for its Fees) | Academyship. Stripe keeps its own records as payment provider. | Kept for as long as tax, corporate and accounting laws require. | The legal period ends. | Invoices are available to the Institution's billing contacts. | Legal and tax obligations; backups until expiry. | support@academyship.com.au. Terms section 8. |
| Contract and acceptance records (Order Forms and the versions of documents accepted) | Academyship. | Kept for the life of the agreement and afterwards for as long as needed to show what was agreed and to establish or defend legal claims. Earlier accepted versions are preserved and are not rewritten. | The period in which a claim about the agreement could reasonably be made ends. | A copy is available to the Institution's authorised contacts on request. | Legal holds. | Terms section 31. |
| Support tickets, attachments and screen-sharing sessions | Academyship. | Kept to resolve the request and to keep a service history. Attachments should contain only what is needed, with sensitive information redacted. Academyship deletes or redacts attachments containing Customer Data once they are no longer needed to resolve the matter. Screen-sharing sessions are recorded only where that is separately disclosed. | The matter is resolved and the service-history period passes, or, for attachments, they are no longer needed to resolve the matter. | A User can ask for their own tickets through privacy@academyship.com.au. An Institution can ask for its tickets through support@academyship.com.au. | Legal hold or open security investigation; backups until expiry. | Support section 8. |
| Complaints made to Academyship | Academyship. | Kept to handle and review the complaint, to show how it was handled, and to identify recurring problems. Access is limited to the people who need it. | The complaint and any review are closed and the period in which further action could reasonably follow passes. The record is then deleted or de-identified. | On request to privacy@academyship.com.au, subject to the privacy of other people involved. | Legal holds; backups until expiry. | Complaints. |
| Child-safety and online-safety reports made to Academyship | Academyship. | Kept with restricted access in accordance with the law and Academyship's retention arrangements, and preserved where reasonably necessary and permitted or required by law, including for police or another authority. Suspected illegal material must never be sent to Academyship. | The matter is closed and no legal requirement or preservation request applies. | Limited, to protect the people involved and any investigation. | Legal holds and preservation requests; backups until expiry. | safety@academyship.com.au. Child Safety section 23. |
| Security vulnerability reports and incident records | Academyship. | Kept to remediate issues, confirm fixes and show how incidents were handled. Access is restricted. | The issue is resolved and the records are no longer needed for incident evidence or legal obligations. | Not generally available, because of security risk. Affected Institutions receive incident information as described in the DPA. | Legal holds; backups until expiry. | security@academyship.com.au. Security Disclosure. |
#10Deletion, backups and restoration
What deletion covers
When information is permanently deleted, Academyship removes it from its active systems. Deletion includes associated uploaded files, derived previews, search indexes and AI-related indexes where applicable. Academyship's deletion process also covers the other copies Academyship controls, including copies held for it by the infrastructure providers it appoints: stored versions of uploaded files, generated documents and exports, temporary processing copies such as queues and caches, and copies made for support. Where a feature first places a record into a recoverable deleted state (soft deletion), that record remains stored until it is permanently deleted.
During the subscription, authorised Institution Users delete workspace records using the platform's deletion functions, within the permissions the Institution assigns. Academyship deletes Customer Data on the Institution's documented instructions, subject to the DPA.
Backups
Academyship maintains daily backups of the platform in Sydney, Australia (ap-southeast-2), with 30 daily recovery points, 15 weekly recovery points and 7 monthly recovery points, together with recovery procedures and a defined backup-expiry lifecycle. Backups exist to recover the platform after an incident. They are not used for ordinary access to records, and they are not a substitute for an Institution's own records management.
Deleting information from active systems does not immediately remove it from backups. A deleted item can remain in a backup recovery point taken before the deletion until that recovery point expires in the ordinary backup cycle. Backup expiry is not the same as deletion from active systems, and the backup cycle is not a retention period for active records.
Restoring from a backup
Restored backups do not bring deleted information back. If Academyship restores data from a backup, it will reapply deletions made after that backup was taken before the restored data is returned to use, so that information deleted from active systems is not made available again.
Where an Institution asks Academyship to help recover records it deleted by mistake, the Institution decides what is restored, and the restored records become part of its workspace again.
Confirmation of deletion
On written request, Academyship will provide confirmation of deletion. A specific certified-deletion process or a shorter timeframe may be agreed in an Order Form.
#11De-identification and small groups
Academyship does not use identifiable Customer Data outside the Institution's instructions. Under the DPA, Academyship may use Aggregated or De-identified Data, meaning data that does not identify an Institution or an individual and is not reasonably capable of re-identification by Academyship, for purposes such as service improvement, security and benchmarking.
Removing names is not enough. In education settings, small classes, small schools, rare courses, rare combinations of attributes (such as a disability, a language background and a year level), free-text notes and dates can identify a person even without a name. Before Academyship treats information derived from Customer Data as de-identified or aggregated, it applies these safeguards:
- direct identifiers, Regulated Identifiers and free-text fields are removed;
- detailed values are grouped into broader categories where detail is not needed;
- results are produced only for groups above a minimum size, and small counts are suppressed or combined;
- an Institution is not identified, directly or by reference to features that point to it;
- de-identified information is not combined with other information in a way that could re-identify people;
- access to de-identified datasets is restricted, and Academyship personnel and any recipient are prohibited from attempting re-identification; and
- the re-identification risk is reassessed before de-identified information is shared outside Academyship or used for a new purpose.
If information that was treated as de-identified turns out to be reasonably identifiable, Academyship treats it as personal information again, deals with it under the DPA and the Privacy Policy, and handles any resulting risk under its incident process. De-identification is not a way to keep an Institution's records after it leaves: identifiable Customer Data is deleted under section 14.
#12Legal holds
A legal hold preserves specified information that would otherwise be deleted, because a law, a court or tribunal, a regulator, a valid preservation request from law enforcement, an actual or reasonably anticipated legal claim, a complaint or dispute being handled, or an open security investigation requires it.
- Who can authorise a hold. An Institution can ask Academyship to preserve Customer Data in its workspace. Academyship applies a hold on its own initiative only where it is required or permitted by law, responding to valid legal process, investigating a security incident, handling a complaint or dispute, or establishing or defending a legal claim. Each hold is approved by a designated Academyship decision-maker and recorded.
- Telling the Institution. Academyship will tell an affected Institution about a hold over its Customer Data unless the law or the terms of the request prevent it.
- Scope and access. A hold covers only the information needed for its purpose. Held information is kept with restricted access and is not used for any other purpose.
- Review and release. Holds are reviewed periodically. When a hold is no longer required it is released, and ordinary deletion then resumes, including deletion that was postponed because of the hold.
A legal hold does not give Academyship any broader right to use the held information.
#13Copies outside Academyship's control
Some copies of information leave Academyship's systems in the ordinary course of using the platform. Academyship cannot delete them, and deleting the original in Academyship does not recall them. They include:
- files exported or downloaded by an Institution or its Users, and printouts or screenshots;
- emails, SMS messages and notifications already delivered to recipients;
- entries a User has added to an external calendar such as Google, Outlook or Yahoo, or through a calendar file, which send selected event details to that calendar provider;
- certificates, letters, signed documents and other files delivered to holders, signers or other recipients;
- records held by payment providers, banks and superannuation funds about payments and authorities;
- information an Institution sends to government agencies, regulators or other bodies;
- information shared with services an Institution chooses to connect (Integrations); and
- information stored in a person's own browser or device.
To ask for one of these copies to be deleted, contact the organisation or person holding it. The Institution can often help with recipients it chose.
This does not reduce Academyship's own obligations. Academyship deletes the copies it controls, including copies held for it by the subprocessors it appoints, in line with this page, the Terms and the DPA.
#14Leaving Academyship: export and exit
When an Institution stops using Academyship, its records do not simply disappear, and its own legal duties to keep records do not end. The exit process works as follows.
- Plan early. Before the subscription ends, the Institution should identify the records it must keep under the laws that apply to it, such as academic, assessment, credential, payroll, financial and safeguarding records, and plan how it will keep them after it leaves. Academyship is not the Institution's long-term archive unless an Order Form provides for separately agreed hosting.
- Authorised request. Cancellation, non-renewal or termination is given by an authorised representative, as described in section 9 and section 30 of the Terms of Service and the Order Form. Academyship may confirm a person's authority before giving exit-period access or acting on a deletion request.
- What can be exported. The Institution can export all of its records, including attachments, audit trails and signing evidence, in commonly used formats. Authorised administrators do this through Academyship's export functions. Additional migration or transition help is available where agreed in writing, at agreed charges.
- Secure delivery. Exports are delivered through the authenticated export functions in the platform, or by another secure method agreed in writing. They are not sent as ordinary email attachments.
- Checking the export. The Institution should check that its exports are complete and readable (for example, by comparing record counts and opening a sample of files) while the export window is still open. If an export fails or appears incomplete, Academyship will investigate and help the Institution obtain the records it still holds.
- Time to download. Following termination or expiry, Academyship makes Customer Data available for authorised export for at least 60 days, unless a different period is stated in an Order Form or required by law. During that period, access may be limited to export and transition functions.
- Reminder. Academyship will notify the Institution's account contacts before the export window closes.
- Billing disputes. Academyship will not withhold access to an otherwise available Customer Data export solely because of a good-faith billing dispute.
- Deletion. After the export window, Academyship deletes Customer Data from active systems in the ordinary course, and backup copies expire through the backup lifecycle described in section 10. Legal holds and legal retention requirements override deletion.
- Confirmation. On written request, Academyship will confirm deletion.
If an account is suspended, terminated for non-payment, or trial access expires, export and deletion rights follow the Terms, the Order Form and applicable law.
What ending the subscription does not do
- It does not cancel a payer's payment authority (such as a PayTo mandate) or any Institution Charge that is owed. Those are matters between the payer, the Institution and the payer's bank. See Payments and Wallets.
- It does not settle wallet balances. These are dealt with as explained in Payments and Wallets.
- It does not end the Institution's own legal obligations to keep records.
- It does not delete copies outside Academyship's control (section 13).
After exit, Academyship keeps its own records about the relationship (such as contract, acceptance, billing, support and complaint records) under Schedule E.
#15Requests about your own information
Records in an Institution's workspace. If you are a student, guardian, staff member or other person whose information is held in an Institution's workspace, ask that Institution to see, correct or delete it. The Institution decides, because it controls those records and may be legally required to keep some of them. Academyship assists the Institution as described in the DPA.
Records Academyship controls. For information Academyship holds in its own right, contact privacy@academyship.com.au. Academyship will check your identity in a way that is proportionate to the request, will not ask for more identity information than it needs, and will explain its decision.
Australian privacy law does not give an unconditional right to have every record erased. It does require organisations to take reasonable steps to destroy or de-identify personal information they no longer need for a permitted purpose, unless the law or a court or tribunal order requires it to be kept. Academyship applies that rule to the records it controls.
#16Keeping this schedule accurate
Academyship reviews this schedule at least annually, and whenever a module, a retention rule, a clean-up process, the backup lifecycle or an export function changes. A rule is published here only when Academyship can operate it. Earlier versions of this page are kept, and changes are listed in the change history below.
If you think a record has been kept longer than this page describes, or deleted when it should have been kept, contact privacy@academyship.com.au or make a complaint as described on the Complaints page.
#17Contact, related documents and change history
Questions about retention, export or deletion: privacy@academyship.com.au. Technical help with an export: support@academyship.com.au. Complaints: complaints@academyship.com.au. If you need this page in another format, contact accessibility@academyship.com.au.
| Version | Date | Summary of changes |
|---|---|---|
| 1.0 | 9 October 2026 | First version. Dataset-by-dataset retention schedule with the responsible decision-maker, retention rule, ending event, export route, deletion and backup exceptions and contact for each record class; explanation of deactivation, archive, soft deletion, permanent deletion, de-identification and anonymisation; small-group re-identification safeguards; legal holds; copies outside Academyship's control; the exit and export process, under which a leaving Institution can export all of its records, including attachments, audit trails and signing evidence, in commonly used formats during the export window of at least 60 days; and the commitment that restored backups do not bring deleted information back. |