This Data Processing Addendum ("DPA") forms part of the Terms of Service between ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) of Unit 44, 3-7 Fetherstone Street, Bankstown NSW 2200, Australia ("Academyship", "we") and the customer institution ("Customer", "you"). It governs Academyship's processing of Customer Personal Data when Customer uses the Academyship student management platform and related services. This DPA takes effect through the Customer's acceptance of the Terms or an Order Form that incorporates it, and a countersigned copy or customer-specific privacy/security schedule is available on request.
| Question | DPA position |
|---|---|
| Who controls workspace records? | Customer institution. |
| What is Academyship's role? | Processor / service provider for Customer Personal Data; independent controller for its own billing, security, support and business records. |
| Where is Australian customer platform data hosted? | Academyship hosts its core production platform and Customer Data in Sydney, Australia (ap-southeast-2). Limited processing outside Australia may occur through disclosed telecommunications delivery, Stripe-hosted payment services, Customer-selected Integrations or authorised access, subject to applicable privacy, contractual and security safeguards. |
| Are student records sold or used for advertising? | No. |
| Is Customer Personal Data used to train general AI models? | No. |
| Are subprocessors allowed? | Yes, with general authorisation, listed subprocessors and a change notice / objection process. |
| What happens after termination? | Export window, then deletion from active systems and backup purge according to this DPA, the Terms and the rolling backup cycle. |
#01Parties, roles and Australian terminology
Each party must comply with the privacy, data-protection, education, health-records, public-records and other information-handling laws applicable to it. Academyship complies with the Privacy Act 1988 (Cth) and the Australian Privacy Principles to the extent they apply to Academyship. A Customer may instead be, or may also be, subject to state or territory privacy and records legislation, including where it is a government education Institution, TAFE, public university or other public-sector body.
For Customer Data, the Customer determines the purposes for which the information is handled and controls the configuration and authorised use of its Tenant. Academyship processes Customer Data on the Customer's documented instructions to provide the service. The international terms "controller" and "processor" are used only as practical shorthand and do not displace the Australian legal framework applicable to either party.
Academyship acts independently for its own business records, including billing, account administration, sales enquiries, service security, internal governance and support records, as described in the Privacy Policy. Academyship engages approved Subprocessors to help deliver the Services, as described in section 18 and Annex III.
White-label presentation, Institution branding or an Institution-controlled domain does not alter the parties’ controller, processor, responsible-entity or service-provider roles under this DPA.
#02Definitions
Applicable Data Protection Laws means the privacy, data protection, data breach notification, student data, education, tax, payroll and records-management laws that apply to a party's processing of personal information under this DPA.
Customer Personal Data means personal information or personal data contained in Customer Content or otherwise processed by Academyship on Customer's behalf through the Services. In this DPA, references to "Customer Data" mean Customer Personal Data and Customer Content.
Customer Content means records, files, messages, documents, uploads, configuration, communications, AI outputs, reports, certificates, letters, exports and other content submitted to, stored in, imported into, generated within or exported from a Customer workspace.
Services means the Academyship platform, portals, APIs, modules, support and related services ordered by Customer or made available under the Terms or an Order Form.
Tenant means the logically and operationally isolated workspace and dedicated database provisioned for a Customer.
Subprocessor means a third party engaged by Academyship to process Customer Personal Data for the Services.
Security Incident means an event that compromises or may compromise the security, availability, integrity or confidentiality of the Services or Customer Personal Data.
Personal Data Breach means a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data.
Usage Data / Service Data means operational logs, diagnostic events, authentication events, feature usage, device/browser metadata, performance data and support metadata generated by use of the Services. Usage Data may include personal information depending on context.
Aggregated or De-identified Data means data that has been aggregated, de-identified or anonymised so that it does not identify an individual or Customer and is not reasonably capable of re-identification by Academyship.
Order Form means an ordering document, signed proposal, customer agreement or schedule that identifies Customer, Services, commercial terms, regional terms or special privacy/security commitments.
Student Data means Customer Personal Data relating to students, learners, applicants, alumni and similar education participants, including minors.
Sensitive Information means personal information treated as sensitive or special-category information under applicable law, including health information, disability information, racial or ethnic origin, religious beliefs, sexual orientation and biometric information used for identification.
Regulated Identifiers means TFNs, USIs, state student identifiers, passport numbers, visa identifiers and similar identifiers subject to additional legal handling requirements.
Academyship may use Usage Data / Service Data to operate, secure, support, monitor and improve the Services, subject to this DPA and the Privacy Policy. Aggregated or De-identified Data may be used for service improvement, analytics, benchmarking, security and business purposes, provided it does not identify Customer or individuals and is not reasonably capable of re-identification by Academyship.
#03Order of precedence
If there is a conflict between documents, a signed Order Form or customer agreement prevails for commercial terms. This DPA, or a signed privacy/security addendum, prevails for processing of Customer Personal Data to the extent of that conflict. The Terms of Service apply otherwise.
The Privacy Policy, Cookie Policy and Trust & Security page provide public descriptions of Academyship's practices. They do not reduce any contractual protections expressly agreed in this DPA, a signed Order Form or a signed privacy/security schedule.
#04Subject matter and duration
The subject matter of processing is Academyship's provision of a configurable student management system and related services for Customer. Processing continues for the subscription term, any renewal term, support and transition period, export window and return/deletion period, unless a longer period is required by law, contract, legal hold, security investigation, dispute, backup integrity or disaster recovery requirements.
#05Nature and purpose of processing
Academyship processes Customer Data only to provide, secure, support, maintain and administer the platform, comply with applicable law and carry out the Customer's documented instructions for the duration of the Customer's subscription and the agreed wind-down period. Academyship may improve the platform using aggregated or de-identified information that is not reasonably capable of identifying the Customer or an individual, but does not repurpose identifiable Customer Data outside the Customer's instructions.
Processing includes performing admissions, enrolment, attendance, timetable, assessment, reporting, communications, finance, payroll, portal, document, integration and other configured functions, and troubleshooting, abuse prevention and service-reliability activities carried out to operate and protect the Services.
Academyship does not use identifiable Customer Personal Data for unrelated product analytics, advertising, behavioural marketing, sale of data, or general AI model training.
#06Categories of data and data subjects
Data subjects may include students, including minors; parents, guardians and emergency contacts; applicants and enquiries; staff, trainers, teachers and contractors; institution administrators; alumni where configured; payers and debtors; visitors; and candidates where relevant modules are used.
Categories of personal data may include identity and contact details; admissions and enrolment data; guardian relationships; attendance, timetable and calendar records; assessment, exam and academic progress data; behaviour, wellbeing, support and safety records; health, disability, accessibility and accommodation information; certificates, documents, uploads and media; finance, fees, invoices and payment metadata; payroll, HR, timesheet, leave, bank, superannuation and STP-related records; USI, VET, AVETMISS and RTO compliance data; TFNs where payroll is used and lawful; international-student, visa and passport-related fields where configured; communications content and logs; audit, security, device and usage logs; and AI inputs, authorised context, outputs and related usage or audit events where AI Features are enabled.
#07Sensitive, regulated and special-category data
The Services can process Sensitive Information where Customer configures relevant modules or fields. This may include health information, disability and accessibility needs, and other information treated as sensitive or special-category information under Applicable Data Protection Laws. The Services can separately process Regulated Identifiers where Customer configures the relevant education, payroll, migration or compliance function.
Customer is responsible for lawful basis, notices, consents, minimisation, retention and access permissions for Sensitive Information. Sensitive Information should not be entered into general notes or free-text fields unless necessary, authorised and appropriate for the relevant record.
Academyship processes Sensitive Information only to provide the Services and does not use it for advertising, model training, unrelated analytics or independent commercial purposes. Access should be role-restricted and configured by Customer.
#08USI, TFN and regulated identifiers
Unique Student Identifiers (USIs) are processed only for lawful education, VET/RTO verification, reporting or compliance functions configured by Customer. Tax File Numbers (TFNs) are processed only where Customer uses payroll, tax or superannuation functions and is lawfully entitled to collect and process them.
USIs and TFNs are Regulated Identifiers, not Academyship account identifiers. Customer must not enter USIs, TFNs or similar Regulated Identifiers into unrelated free-text fields. Academyship applies access controls and masking or encryption controls where supported. Customer remains responsible for being a lawful recipient or collector of those identifiers and for required notices, consents and handling rules.
#09Processor obligations
Academyship will process Customer Personal Data only on documented instructions from Customer, including the Terms, this DPA, Order Forms, Customer configuration and authorised use of the Services. Where legally permitted, Academyship will notify Customer if it believes an instruction infringes Applicable Data Protection Laws.
Academyship will ensure authorised personnel are bound by confidentiality, restrict access on a need-to-know and least-privilege basis, maintain the technical and organisational measures in Annex II, assist with rights requests, DPIAs/PIAs, breach response and regulator enquiries as stated in this DPA, and ensure Subprocessors are bound by data-protection obligations appropriate to their processing.
Academyship will not sell Customer Personal Data, use Customer Personal Data for advertising, or use Customer Personal Data for general AI model training. Academyship will make compliance information reasonably available as described in section 19.
#10Customer responsibilities
Customer is responsible for lawful basis, notices, consents and parental or guardian consents where required; configuring roles, permissions and portal visibility; deciding what students and guardians can view; minimising Sensitive Information; and setting retention, export and deletion practices appropriate to Customer's obligations.
Customer is responsible for managing staff access and removing leavers; lawful use of payroll, TFN, USI and RTO features; payment and finance compliance; reviewing AI outputs before decisions; ensuring staff do not misuse notes or free-text fields; managing API keys, tokens and connected integrations; and responding to data subject requests where Customer is the controller or responsible entity.
Where Customer uses SMS, Customer controls message content, recipients, timing and any authorised sender identity, and is responsible for consent, other lawful authority, notices, opt-outs and communications-law compliance. Academyship uses AWS End User Messaging SMS for delivery; AWS may process recipient mobile numbers, message content and delivery metadata, and telecommunications carriers participate in delivery and may route messages through recipient-country networks. Academyship does not guarantee carrier delivery or exact sender-ID display. A sender identity does not alter the parties’ controller, processor, responsible-entity or service-provider roles under this DPA.
Customer remains responsible for records-management and public-sector obligations, safeguarding and duty-of-care responses outside the platform, local policies, student/family communications and ensuring its instructions to Academyship comply with Applicable Data Protection Laws.
#11AI-assisted features
AI Features are available from Academyship’s launch on 12 September 2026. Each Customer may enable, disable or restrict AI Features through its administrative configuration and role permissions. Academyship processes the related inputs, permitted Customer Data and outputs only to provide the AI Feature on the Customer’s instructions. Academyship:
- does not use Customer Data or Student Data to train general-purpose AI models;
- uses Amazon Bedrock as identified in Annex III;
- processes Amazon Bedrock requests in Sydney, Australia (
ap-southeast-2), with cross-region inference disabled; - requires any enabled feature to apply Tenant isolation and the requesting User's roles and permissions;
- requires authorised human review for significant decisions;
- applies feature-specific administrative controls; and
- keeps institution-specific fine-tuning or model customisation disabled unless the Customer enters a separate written opt-in agreement.
AI outputs may be incomplete or inaccurate and must be reviewed before use in any decision or official record.
The verified production inventory is limited to the institutional AI assistant, tenant knowledge and cross-module search, summarisation, drafting, report assistance, document analysis, administrative recommendations and action previews. It uses only the requesting User’s permitted Tenant sources. Outputs are advisory; Academyship AI does not autonomously perform an action, and an authorised person must confirm any resulting platform action. See the Responsible AI Statement for the public inventory.
#12Razi voice typing and student-facing generative-AI status
Razi is a browser/device voice-typing input method, not an Amazon Bedrock feature and not part of Academyship’s generative-AI feature inventory. Razi uses speech-recognition capabilities supplied by the User’s browser, operating system or device to convert spoken words into text for supported Academyship fields and editors. Academyship does not receive or store raw audio through Razi, and Amazon Bedrock is not involved in Razi.
Once a User inserts the resulting text into an Academyship field, that text is Customer Data and Academyship processes it in the same way as text manually entered into that field, subject to this DPA and the Customer’s instructions. The Customer and its Users are responsible for their browser/device permissions and for ensuring that use of browser/device speech recognition is authorised under the Customer’s policies and applicable law. The applicable browser or device provider may process speech under its own privacy terms and technical configuration. Users must review transcribed text before saving or relying on it. Razi does not make decisions, analyse student behaviour or generate autonomous actions. The Customer can control whether Razi is available to Users where the relevant configuration exists.
No Academyship voice or transcription feature using generative AI, and no student-facing generative-AI function, is represented in the verified production AI inventory or Annex III.
#13Optional integrations and APIs
Customer controls which integrations and APIs it enables. Data shared with an integration depends on the integration scope, permissions and Customer configuration. Customer is responsible for the terms, privacy practices and lawful use of third-party providers where Customer chooses or authorises the integration.
Optional institution-selected integrations are not Academyship Subprocessors unless Academyship contracts with the provider to process Customer Personal Data for the Services. Customer must protect API keys, tokens and integration credentials. Academyship may log integration activity for security, troubleshooting and audit purposes, and may suspend or disable an integration that creates a security, privacy, legal or service reliability risk.
#14Support and personnel access
Academyship support and engineering access to Customer Personal Data is role-restricted, logged and limited to support, security, debugging, legal compliance or service operation. Access may be tied to a ticket, incident or approved task where practical.
Personnel are bound by confidentiality. Access is removed when no longer needed and reviewed periodically. Remote access from outside Australia remains subject to APP 8 safeguards or equivalent controls where applicable.
#15Security measures
Academyship maintains the technical and organisational security measures described in Annex II. Those measures form part of this DPA and apply to production Customer Data. Academyship may update the measures as technology and risk evolve, provided that the overall level of protection is not materially reduced during the Customer's subscription. Security is a shared responsibility: Academyship secures the platform and managed infrastructure, while the Customer is responsible for its Users, credentials, configuration, role assignments and Institution-selected Integrations.
Academyship does not claim its own SOC 2, ISO 27001 or equivalent certification unless and until those certifications are obtained and stated in official materials.
#16Assisting with rights, DPIAs and regulator requests
Academyship will provide reasonable assistance to Customer through self-service tools, exports, correction tools, deletion tools, logs and support where reasonable and technically feasible. If Academyship receives a direct request about Customer Personal Data, it will refer the requester to Customer unless legally required to respond otherwise.
Customer remains responsible for responding to individuals as controller or responsible entity. Assistance is subject to authentication, technical feasibility, lawful retention, confidentiality and the scope of the Services.
Academyship will provide reasonable information to help Customer with DPIAs, PIAs, public-sector privacy assessments, security questionnaires and regulator enquiries. Assistance is subject to confidentiality, scope, reasonable frequency, available information and fees for excessive or custom requests where permitted by agreement. Academyship will not provide information that compromises security or other customers.
#17Personal data breach notification
Academyship maintains a documented incident-response and data-breach process. Where a Personal Data Breach affects Customer Data, Academyship will notify the affected Customer without undue delay and no later than 72 hours after Academyship becomes aware that Customer Data has been affected, unless the information available at that time does not reasonably permit identification of the affected Customer. Academyship may provide information in stages as the investigation progresses.
The notice will include, to the extent reasonably available:
- the nature of the incident;
- the categories of information and data subjects affected;
- the likely consequences;
- the containment and remediation actions taken or proposed;
- recommended actions for the Customer; and
- an Academyship contact for further information.
Each party remains responsible for its own statutory assessment and notification obligations. Where both parties hold affected personal information, the parties will coordinate promptly and agree which party will lead communications with affected individuals and regulators. Unless otherwise agreed or required by law, the Customer will ordinarily lead communications concerning its data subjects, with Academyship providing reasonable assistance.
Nothing in this DPA prevents Academyship from notifying a regulator, affected person or other party where Academyship is independently required or permitted to do so by law. Customer must notify Academyship promptly if Customer becomes aware of security issues caused by its users, integrations, credentials, devices, configurations or third-party providers.
#18Subprocessors
Customer gives general authorisation for Academyship to engage the active approved Subprocessors listed in Annex III. Academyship will impose data-protection obligations on each Subprocessor appropriate to its processing and remains responsible to Customer for Subprocessors engaged by Academyship.
Academyship will provide reasonable advance notice, and at least 30 days' notice where practical, of a new or replacement Subprocessor that will process Customer Data. Customer may object on reasonable data-protection grounds. If the parties cannot resolve an objection, Customer may terminate the affected Services according to the Terms or this DPA. Emergency replacement Subprocessors may be used where needed for security, continuity or legal reasons, but will be limited to the affected service and notified as soon as reasonably practicable.
Optional Customer-selected integrations are not Academyship Subprocessors unless Academyship contracts with the provider to process Customer Personal Data for the Services.
#19Audits and compliance
Academyship will make information reasonably necessary to demonstrate compliance with this DPA available to Customer. Customers may review Academyship security documentation, this DPA, the Privacy Policy, Trust & Security page, security questionnaire responses and relevant infrastructure-provider reports where available.
AWS compliance reports may be referenced as AWS infrastructure-provider reports, not Academyship certifications. Academyship does not represent AWS reports as Academyship SOC 2, ISO 27001 or similar certification.
Customer audit rights are subject to reasonable notice, confidentiality, scope, security controls, no disruption to Academyship or other customers, no access to other customers' data, and no more than annually unless following a material breach or regulator requirement. Academyship may satisfy audit requests through independent reports, questionnaires or documentation where sufficient.
Any Customer-led audit must be conducted by Customer personnel or an independent auditor bound by confidentiality and appropriate security obligations. Customer is responsible for its own audit costs unless otherwise agreed.
Academyship is not required to provide access to source code, production systems, other customers' data, highly sensitive security details or information that would increase security risk.
#20Return and deletion
During the subscription, the Customer can export Customer Data through Academyship's authorised export functions. Following termination, Academyship will make Customer Data available for authorised export for at least 60 days unless a different period is agreed in an Order Form or required by law. During that period, access may be restricted to export and transition functions.
After the export period, Academyship deletes Customer Data from active systems in the ordinary course and causes backup copies to expire through the documented backup lifecycle: daily backups, 30 daily recovery points, 15 weekly recovery points and 7 monthly recovery points. This remains subject to legal holds and legal retention requirements. Deletion workflows include associated uploaded files, derived previews, search indexes and AI-related indexes where applicable. On written request, Academyship will provide confirmation of deletion. A specific certified-deletion process or shorter timeframe may be agreed in an Order Form.
If an account is suspended, terminated for non-payment or trial access expires, export and deletion rights follow the Terms, Order Form and applicable law.
#21International transfers
Academyship hosts its core production platform and Customer Data in Sydney, Australia (ap-southeast-2). Limited processing outside Australia may occur through disclosed telecommunications delivery, Stripe-hosted payment services, Customer-selected Integrations or authorised access, subject to applicable privacy, contractual and security safeguards.
Customer-selected Integrations transfer data according to Customer configuration and third-party terms.
Where Academyship discloses personal information outside Australia through a Customer-selected Integration or another disclosed recipient, APP 8 safeguards apply. EU/UK GDPR transfers use Standard Contractual Clauses, the UK IDTA or the UK Addendum only where agreed or required in an Order Form or regional addendum; this public DPA does not itself attach those transfer terms.
#22Legal requests
Academyship will notify Customer of legal, regulatory or law-enforcement requests for Customer Personal Data unless prohibited by law or the request's terms. Where appropriate, Academyship may challenge, narrow or redirect requests. Customer is responsible for responding to requests directed to Customer.
#23Government and public-sector Institutions
Public-sector customers may require additional privacy, security, data residency, records-management or departmental-policy terms through Order Forms, security schedules or procurement documents. Academyship supports those requirements through agreed contractual schedules, security documentation, access controls, audit logs and data-residency commitments where agreed.
Customer remains responsible for records management, notices, consents, local policies, student and family communications and public-sector obligations that apply to Customer.
#24Safeguarding and emergency-response limitation
Academyship may store wellbeing, behaviour, support or safety records where Customer configures those modules. Academyship is not an emergency response, safeguarding monitoring or clinical service.
Customer is responsible for reviewing records and responding under its duty-of-care, safeguarding, mandatory reporting, emergency and escalation procedures. Nothing in the Services replaces Customer's mandatory reporting, child-safety, wellbeing, clinical, emergency or legal obligations.
#25Liability, governing law and acceptance
Each party's liability under this DPA remains subject to the limitations and exclusions of liability in the Terms of Service, unless a signed agreement says otherwise. Nothing in this DPA limits rights or obligations that cannot be limited under applicable law.
This DPA is governed by the laws of New South Wales, Australia, and otherwise forms part of, and is subject to, the Terms.
This DPA takes effect through the Customer's acceptance of the Terms or an Order Form that incorporates it, and does not require separate signature. Enterprise and public-sector customers that require a countersigned copy may request one from legal@academyship.com.au.
#A1Annex I — Processing details
| Item | Processing detail |
|---|---|
| Subject matter | Provision of the Academyship multi-tenant student management platform, portals, APIs, modules, support and related services. |
| Duration | Subscription term, renewal term, support/transition period, export window and deletion/backup purge period, unless a longer period is required by law, legal hold, dispute, security investigation, backup integrity or disaster recovery requirements. |
| Nature of processing | Collection, recording, storage, organisation, retrieval, consultation, use, display, transmission, disclosure to authorised users/subprocessors, restriction, export, deletion, backup, restoration and support activities. |
| Purpose | To provide, secure, support, maintain and administer the Services and Customer-configured functions, and to comply with applicable law and Customer's documented instructions. Academyship may improve the platform using aggregated or de-identified information only, and does not repurpose identifiable Customer Personal Data outside Customer's instructions. |
| Data subjects | Students including minors; parents, guardians and emergency contacts; applicants and enquiries; staff, trainers, teachers, contractors and administrators; alumni where configured; payers/debtors; visitors and candidates where modules are used. |
| Categories of personal data | Identity/contact, admissions/enrolment, guardian relationships, attendance/timetable/calendar, assessment/exam/progress, behaviour/wellbeing/support/safety, documents/uploads/media, finance/payment metadata, HR/payroll/timesheets/leave/bank/superannuation/STP-related records, communications, audit/security/device/usage logs, and AI inputs, authorised context, outputs and related usage or audit events where AI Features are enabled. |
| Sensitive / regulated data | Sensitive Information only where the applicable privacy law treats it as sensitive or special-category information. Regulated Identifiers may include USIs, TFNs, state student identifiers, passport numbers and visa identifiers where the Customer configures the relevant function. Other records, including demographic fields and emergency contacts, are not classified as Sensitive Information solely by appearing in this list. |
| Frequency | Continuous while Customer uses the Services, with event-based processing for support, integrations, AI, backups, exports and deletion. |
| Retention | Customer Personal Data is retained in the Customer workspace according to Customer configuration, applicable law and the Terms. Logs and backups follow operational retention cycles unless otherwise agreed. |
| Deletion / return | Customer export for at least 60 days after termination, deletion from active systems after the export window, and expiry through the backup lifecycle of 30 daily recovery points, 15 weekly recovery points and 7 monthly recovery points, subject to stated exceptions. |
| Location / transfer | Academyship hosts its core production platform and Customer Data in Sydney, Australia (ap-southeast-2). Limited processing outside Australia may occur through disclosed telecommunications delivery, Stripe-hosted payment services, Customer-selected Integrations or authorised access, subject to applicable privacy, contractual and security safeguards. |
#A2Annex II — Technical and organisational measures
The measures below are Academyship's production technical and organisational controls for protecting Customer Data. They are stated at a control level and intentionally omit sensitive implementation details.
| Control area | Academyship measures |
|---|---|
| Tenant isolation | Database-per-tenant architecture with tenant context enforced across application, API, reporting, file-access and AI-processing paths to prevent cross-tenant access or discovery. |
| Encryption in transit | HTTPS is enforced for public network connections to the Services and APIs, and TLS 1.2 or later is required. |
| Encryption at rest | AWS-managed KMS keys protect configured encrypted services. |
| Identity, authentication and MFA | Authenticated access to the platform, multi-factor authentication for privileged and administrative access, and session and secure sign-in controls. |
| Role-based and least-privilege access | Role-based access control applying least-privilege principles, with permissions and portal visibility configurable by the Customer. |
| Academyship support access | Support and engineering access to Customer Data restricted by role, limited to the minimum necessary scope and duration, tied to an authorised purpose, and logged. |
| Audit logging and monitoring | Audit and security logging of key actions with user identity, timestamp and context, and monitoring and alerting for suspicious activity. Infrastructure and security logs are retained for 30 days. |
| Secure software development and code review | Secure development practices, code review and testing prior to release, and controlled release management. |
| Dependency, vulnerability and patch management | Dependency and vulnerability scanning, risk-based prioritisation and security patching. |
| Network and cloud-platform protections | Network segmentation, security groups and firewalling. Production RDS and internal services are private and not publicly accessible. S3 public access is blocked except for deliberately public assets. |
| Backup, restore and disaster recovery | Daily backups with 30 daily recovery points, 15 weekly recovery points and 7 monthly recovery points, together with recovery procedures and a defined backup-expiry lifecycle in Sydney, Australia (ap-southeast-2). |
| Incident response | Documented incident triage, containment, assessment, notification, remediation and post-incident review. |
| File and upload security | Allowed file-type controls; MIME and file-signature validation; malware scanning with quarantine or rejection of unsafe files; file-size restrictions; authorisation checks at download time where configured; removal of embedded GPS location metadata from supported images while preserving orientation; deletion of derived files on record deletion; and audit events for upload, download and delete actions. |
| Data minimisation and sensitive-field controls | Configurable fields, role and portal visibility controls, sensitive-field restriction, and export and masking controls where supported. |
| Subprocessor governance | Due diligence, contractual data-protection obligations, an active subprocessor register and a change-notice/objection process. |
| Change management | Controlled configuration and release change management with review and rollback capability. |
| Personnel confidentiality and security training | Confidentiality obligations for personnel and security-awareness training appropriate to role. |
| AI security and tenant/role isolation | AI Features are constrained to the Tenant and requesting User's roles and permissions, have a documented logging and retention position, and do not use Customer Personal Data to train general-purpose AI models. Each Customer may disable or restrict AI Features through its configuration. |
These control statements omit sensitive implementation details and do not assert that Academyship holds SOC 2, ISO 27001 or similar certification.
#A3Annex III — Subprocessors
Annex III records the contractual subprocessor snapshot applicable to this DPA. The current public register is available on the Subprocessor Register page. Academyship will provide reasonable advance notice of a new subprocessor that will process Customer Data, and Customer may object as described in section 18. To request subprocessor-change notifications, contact legal@academyship.com.au.
| Contracting entity | AWS service | Service and purpose | Data categories | Processing location | Status |
|---|---|---|---|---|---|
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | AWS core infrastructure | Application hosting, tenant RDS databases, S3 files, logs, snapshots and backups. | Hosted Customer Data, files, logs and backup copies. | Sydney, Australia (ap-southeast-2). | Active |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | Amazon SES | Transactional and Institution-sent email. | Email recipient details, message content and delivery metadata. | Sydney, Australia (ap-southeast-2). | Active |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | AWS End User Messaging | SMS processing through AWS. | Mobile numbers, message content and delivery metadata. | Sydney, Australia (ap-southeast-2); telecommunications carriers may route messages through the recipient’s carrier network. | Active |
| Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) | Amazon Bedrock | Academyship AI Features. | Permitted inputs, authorised workspace context and outputs. Customer Data is not used to train general-purpose models. | Sydney, Australia (ap-southeast-2); cross-region inference is disabled. | Active |
For Academyship's Australian AWS account, the AWS Customer Agreement identifies Amazon Web Services Australia Pty Ltd (ABN 63 605 345 891) as the AWS contracting party. SMS messages are handed to telecommunications carriers for delivery and may be routed through carrier networks in the recipient's country. Customer Personal Data is not used to train general-purpose AI models; Amazon Bedrock requests are processed in Sydney, Australia (ap-southeast-2), with cross-region inference disabled.
For questions about this DPA or the subprocessor list, contact legal@academyship.com.au. See also the Privacy Policy, Cookie Policy and Terms of Service.