Skip to main content
Security & Service

Security incidents and data breach response

Effective 11 October 2026 · Last updated 11 October 2026 · Version 1.0 · An informational statement; not the internal incident runbook · ACADEMYSHIP PTY LTD

#01Purpose and status

ACADEMYSHIP PTY LTD (ACN 698 283 448, ABN 89 698 283 448) publishes this page to explain how to report a suspected security incident and how Academyship's published response and notification commitments fit together.

This page is informational. It does not replace Academyship's confidential incident-response procedures or add to or reduce the Terms of Service, Data Processing Addendum (DPA), an applicable Order Form or a legal obligation.

#02Incidents and vulnerabilities are different

A Security Incident is an event that compromises, or may compromise, the security, confidentiality, integrity or availability of the platform or Customer Data. A Personal Data Breach is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to Customer Personal Data, as defined in the DPA.

A vulnerability is a weakness that could be exploited. An outage is a service interruption and does not necessarily involve a personal data breach. Report a suspected incident even if you cannot yet tell which description applies. For a weakness discovered without an active incident, follow Report a Security Issue and its research rules.

#03How to report

Email security@academyship.com.au promptly. Say at the start of your message if you believe an incident is in progress. Where safe and appropriate, also tell your Institution if the report concerns its account or records. You may contact Academyship directly; you do not have to report only to the person or Institution your concern is about.

For an ordinary service fault, use support@academyship.com.au. For a privacy request or concern, use privacy@academyship.com.au. For a child-safety or online-safety concern, use safety@academyship.com.au. If someone is in immediate danger in Australia, call 000 first. Academyship is not an emergency service.

#04Information to include safely

Include a short description, the approximate time and time zone, the affected Institution or account if known, the relevant page or function, what you observed and a way to contact you. You do not need a complete investigation before reporting.

Do not email passwords, one-time codes, full tax file numbers, full bank or card details, identity documents, customer database exports or other people's signed records. Redact screenshots and remove live invitation, verification, payment and signing tokens. Describe any sensitive evidence first so Academyship can agree a suitable way to receive it. Never send suspected illegal material.

#05What to do while waiting

Stop the activity that exposed the problem and do not explore other accounts or records. Do not repeat a payment or signature merely to investigate. If an account may be compromised, use the Institution's approved process to secure access and tell its administrator. Preserve relevant times and non-sensitive references, but do not copy or circulate someone else's information.

Institution administrators should preserve available relevant evidence through authorised processes and coordinate urgent containment with Academyship. Do not delete evidence simply to hide the incident. Emergency action needed to protect people must not wait for a platform investigation.

#06Response stages

The DPA requires a documented incident-response process. Depending on the circumstances, response includes receiving and triaging the report; assessing affected services, information and people; containing the event; preserving relevant evidence; investigating the cause and impact; remediating and recovering; communicating with affected Institutions and other parties where required; and reviewing what should change afterwards.

These stages can overlap. Containment and notification do not need to wait until every fact is known. Academyship may provide information in stages and may restrict access or a feature where justified by its agreement and the circumstances. This page does not guarantee a fixed acknowledgement time, a resolution time or a particular investigative outcome.

#07Customer notification under the DPA

Where a Personal Data Breach affects Customer Data, DPA section 17 requires Academyship to notify the affected Customer without undue delay and no later than 72 hours after Academyship becomes aware that Customer Data has been affected, unless the information available at that time does not reasonably permit identification of the affected Customer. Academyship may provide information in stages as the investigation progresses.

To the extent reasonably available, that notice includes the nature of the incident, the categories of information and people affected, likely consequences, containment and remediation taken or proposed, recommended Customer actions and an Academyship contact.

The 72-hour period is the existing contractual customer-notice commitment. It is not a general statement of Australian statutory notification deadlines, and it is not a reason to wait where earlier notice is possible or another obligation requires it.

#08Statutory assessment and notification

Where the Notifiable Data Breaches scheme applies, a suspected eligible data breach requires a reasonable and prompt assessment, with reasonable steps to complete it within 30 days. Where there are reasonable grounds to believe an eligible data breach has occurred, notification to the Office of the Australian Information Commissioner and affected individuals is required as soon as practicable, unless an exception applies. The assessment period is not permission to delay containment or a contractual customer notice.

Other legal and regulatory requirements may also apply. For example, where the ATO's Digital Service Provider reporting requirements apply to an incident, its published requirements call for reporting an identified data breach involving confidential taxpayer information within one business day, with initial notification as soon as practicable. That obligation is separate from the DPA's customer notice and from the NDB scheme. This statement does not claim that Academyship's STP lodgement service is currently available or that Academyship holds ATO production approval.

#09Coordination with Institutions and providers

Academyship and an affected Institution each remain responsible for their own legal obligations. Where both hold affected personal information, they coordinate promptly on investigation and communications. Unless otherwise agreed or required by law, the Institution ordinarily leads communications concerning its students, staff and other data subjects, with reasonable assistance and relevant information from Academyship, as described in the DPA.

Coordination does not give either party a veto over a legally required notification and must not delay it. Academyship can notify a regulator, affected person or other party where independently required or permitted by law. Relevant providers may also need to participate according to their roles and obligations.

#10Records, privacy and confidentiality

Incident information is handled with restricted access and used for response, remediation, evidence, legal obligations and appropriate review. An incident may require preservation of selected records beyond their ordinary retention period, as explained in Data Retention, Export and Deletion.

The 30-day period stated for infrastructure and security logs is not a promise to delete every incident record after 30 days. Academyship does not publish confidential investigative details or records about other customers. Information received from a reporter is handled under the Privacy Policy.

#11Questions and escalation

Use security@academyship.com.au for an incident report and relevant follow-up. For a complaint about Academyship's handling of a matter, contact complaints@academyship.com.au and see Complaints and Escalation. Access, correction and other privacy requests go to privacy@academyship.com.au.

#12Review and related documents

Academyship reviews this public explanation when material changes to its response commitments, services or applicable notification requirements make an update necessary. The DPA remains the source of contractual customer-notification commitments.

Version history for this Security Incidents and Data Breach Response page.
VersionDateSummary of changes
1.011 October 2026Initial publication explaining security reporting, response stages, customer notice and separate statutory or regulatory reporting obligations.