Privacy
Privacy policy
ConnectedIn is a platform that Australian training organisations use to analyse their student pipeline and build partnerships with employers. This policy explains, in plain English, what personal information passes through the platform, why, where it is kept, who can see it, and what you can do about it.
1. Who we are and our role
ConnectedIn is operated by [LAWYER: legal entity name, ABN and registered address of the operator] ("ConnectedIn", "we", "us"). We are bound by the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). [LAWYER: confirm the operator is an APP entity, or state the basis on which it opts in]
ConnectedIn is not a consumer service. Each organisation that uses it (a registered training organisation, or RTO, referred to below as a training organisation) has its own isolated workspace. The training organisation holds the relationship with its students and partners, decides what information goes into its workspace and why, and is responsible for the basis on which it collects that information. We provide and operate the platform on the training organisation's instructions and do not use the information in a workspace for our own purposes.
In practical terms: if you are a student or an employer contact, the training organisation you deal with is the organisation that holds your information.This policy describes what the platform does with it. The training organisation's own privacy policy describes why it collected it. [LAWYER: confirm the controller/processor-style allocation of responsibility under the APPs, and whether ConnectedIn also "holds" personal information for APP purposes]
2. What we collect
The platform holds three kinds of personal information, each from a different source.
| About | What | Where it comes from |
|---|---|---|
| Students and recent completers | Name, contact details (mobile number, email), residential address, the qualification being studied, enrolment status and expected completion date, and, later, employment outcomes recorded against an introduction. | Uploaded or synchronised by the training organisation from its student management system. Students do not create accounts on ConnectedIn. |
| Students: consent choices | Whether you opted in or out, the exact wording you were shown, what the opt-in covers, and the evidence of the choice: the date and time, the method (a one-tap link), the IP address and browser identifier of the device that made it. | Recorded directly from you when you use a consent link. |
| Employer (partner) contacts | Name, role, work email, the organisations and sites you represent, the vacancies you submit, and the activity and outcomes you record against a referral. | Entered by the training organisation, and by you if you use the partner portal. |
| Training organisation staff | Work email, authentication details (a password and a multi-factor authentication secret, both held by our authentication provider), role, and a record of your actions in the workspace. | Your organisation invites you; you set your own credentials. |
We also keep technical logs of requests to the platform (request identifiers, paths, timings, error details) for operating and securing it. These are scrubbed of personal information before they leave our infrastructure (see section 6).
We do not collect sensitive information (such as health, ethnicity or criminal record) as part of the platform's design, and we ask training organisations not to include it in uploads. If a free-text field is used to add it, the training organisation is responsible for that content.
3. How we use it
The platform uses personal information only to do the following.
- Pipeline analysis. Student addresses are converted into map coordinates (see section 6 on Google) so that the platform can count how many students and recent completers are within a given distance of each employer site, grouped by how close they are to completing. The figures a training organisation shows an employer are counts of people, never lists of names.
- Introductions, only with consent.A student's name and contact details are released to an employer only after the student has recorded an opt-in that covers contact release. This rule is enforced inside the database, not just in the application, so the platform is structurally unable to release details without a live, matching opt-in. Until then an employer sees a de-identified preview: readiness tier, suburb, qualification and expected completion.
- Messages to students. Where a training organisation sends messages through the platform (for example, an invitation to opt in, or a notification about a role near you), the platform records what was sent and to whom, and every message carries a way to opt out or change your choice.
- Employer partner management. Recording the relationship between the training organisation and each employer, vacancies, referrals, activity and outcomes.
- Reports. Producing reports and presentation decks for the training organisation and its partners. These contain aggregate figures and site-level counts; they do not contain student names or contact details.
- The workspace assistant. Training organisation staff can ask an AI assistant questions about their own workspace. The assistant can only read what the signed-in person can already see, and any change it proposes must be approved by that person before it happens. See section 6 on where this processing occurs.
- Operating and securing the platform. Authentication, access control, rate limiting, error monitoring and an audit trail of who did what.
We do not sell personal information, use it for advertising, or use it to train any machine learning model, ours or anyone else's.
4. Students: your choice and your details
If you are a student, this section is the one that matters most.
- Nothing about you is shared with an employer until you say yes. Your training organisation may show employers a count of people in an area, and a de-identified preview (tier, suburb, qualification). Your name and contact details are released to a specific employer only against an opt-in you recorded.
- You are shown exactly what you are agreeing to. The consent page lists each thing an opt-in permits (for example: share my details for a specific role; send me messages about roles near me; check in with me later about how a job is going). The exact wording you saw is stored with your choice.
- You can withdraw at any time. Open the same link you were sent (or any later one) and choose to withdraw. Your withdrawal takes effect immediately, and no further details are released. Details already released to an employer before you withdrew remain with that employer; your training organisation can tell you which employers, if any, received them.
- The consent page shows very little. It displays your first name and your current choice, and nothing else, so a link that reaches the wrong hands reveals nothing about where you live or how to contact you. Links are signed, bound to your training organisation, and expire.
5. Who we share it with
- Your training organisation. Staff of the training organisation that holds your information can see it in their workspace, according to the role they have been given.
- Employers, only as described in sections 3 and 4. Counts and de-identified previews by default; contact details only against your recorded opt-in, and only to the employer the referral is for.
- Service providers we use to run the platform, listed in section 6. Each receives only what its function needs.
- Where the law requires it, for example in response to a lawful request from a court or regulator. We would notify the training organisation unless prohibited from doing so.
ConnectedIn staff do not access the contents of a workspace except to provide support at the training organisation's request, or to investigate a security incident, and every such access is recorded in the audit trail. [LAWYER: confirm the support-access statement matches the operator's actual operating procedure]
6. Overseas disclosure
Your data is stored in Australia.The database and file storage that hold workspace data run in Sydney (Amazon Web Services region ap-southeast-2, operated for us by Supabase). Every organisation's data is isolated from every other's at the database level.
Some processing necessarily involves providers outside Australia. Each is listed here with what it receives and why.
| Provider | Where | What it receives and why |
|---|---|---|
| Netlify (application hosting) | [LAWYER: confirm the region in which Netlify executes the application's server functions for this site] | Runs the application code that serves pages and processes requests. Data passes through it in transit and in memory; it is stored in Sydney. |
| Sentry (error monitoring) | European Union | Receives reports of application errors so we can fix them. Before any report leaves the platform it is scrubbed: request bodies, cookies, authorisation headers and query strings are never sent; consent-link tokens are removed from URLs; any field whose name suggests a person (name, email, phone, address, suburb, postcode, date of birth and similar) is replaced with "[redacted]"; email addresses and phone numbers found in free text are masked; and the only user detail kept is an opaque account identifier (no email, no username, no IP address). What remains is stack traces, error messages, the page path, and record identifiers. Free-text names cannot be recognised by pattern, so our engineering rule is that a person's record is never written into an error message in the first place. |
| Anthropic (workspace assistant) | United States | When a training organisation staff member asks the assistant a question, the question and the workspace records needed to answer it (which can include student and employer details the staff member is already permitted to see) are sent to Anthropic's API to generate the answer. This happens only when the assistant is used. Under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models. [LAWYER: cite the specific Anthropic commercial terms and data retention period that apply to the account in use] |
| Google (Maps Geocoding) | [LAWYER: confirm the processing location Google states for the Geocoding API] | Receives street addresses (of students, employer sites and campuses), with no names attached, and returns map coordinates. Results are cached so an address is sent once. |
| Message delivery provider | [LAWYER: name the SMS and email delivery provider(s) once selected, and their processing location] | Receives the recipient's mobile number or email address and the message text in order to deliver messages the training organisation sends through the platform. |
| Supabase (authentication) | Sydney, Australia | Holds staff and partner sign-in credentials and multi-factor authentication secrets, alongside the database. |
[LAWYER: confirm the APP 8 position: whether ConnectedIn takes reasonable steps to ensure each overseas recipient complies with the APPs, or relies on another APP 8.2 exception, and the wording to use]
7. How we keep it secure
- Isolation in the database.Each training organisation's data is separated by row-level security policies enforced by the database itself, so application code cannot reach across workspaces.
- Multi-factor authentication, enforced. Every staff and partner user must verify a second factor before any data is accessible. There is no opt-out.
- Encryption in transit. All connections to the platform and between the platform and its providers use TLS. [LAWYER: confirm and state the encryption-at-rest position for the database and file storage]
- The consent gate. Contact details are released only through a database function that refuses unless a live, matching opt-in exists.
- Audit trail. Data access, exports, releases, consent events, purges and every administrative action are written to an append-only log that the training organisation can see and that application code cannot alter or delete.
- Least exposure on public pages. The consent page shows only a first name and current choice; link tokens are signed and expire; requests are rate limited.
No system is perfectly secure. If we become aware of a data breach that is likely to result in serious harm, we will notify the affected training organisation without delay so that it can meet its obligations under the Notifiable Data Breaches scheme, and we will meet our own. [LAWYER: confirm breach notification allocation between operator and training organisation, and timeframes]
8. How long we keep it
- Student cohort data (the uploaded records) is deleted automatically 90 days after the last analysis run that used it. Each new run extends the date by another 90 days, so data the training organisation is actively using stays, and data it has stopped using goes.
- Analysis results and reports (site-level counts and generated decks) are kept after the cohort is deleted. They contain figures, not names, and are the record of what was reported.
- Map coordinates for addresses are cached without any link to a person, so an address that reappears is not sent to Google again.
- Consent records are kept as evidence of the choices made. [LAWYER: state the retention period for consent events and the audit log]
- Employer, vacancy and outcome recordsare kept for as long as the training organisation's workspace exists. [LAWYER: state what happens to a workspace on termination of the training organisation's agreement, and within what period it is deleted]
9. Access and correction
You can ask to see the personal information held about you and ask for it to be corrected. Because the training organisation holds your information, the fastest route is to contact it directly; it can view and correct your record in its workspace. You can also contact us (section 12) and we will pass the request to the training organisation and help it respond. [LAWYER: confirm response timeframe and whether any fee may be charged]
If you are a student, you do not need to make a request to change your consent: use the link you were sent, at any time.
10. Complaints
If you think we have mishandled your personal information, contact us at privacy@connectedin.app. We will acknowledge your complaint, investigate it, and reply in writing. [LAWYER: state the acknowledgement and resolution timeframes]
If you are not satisfied with our response, you can complain to the Office of the Australian Information Commissioner (OAIC). [LAWYER: confirm the OAIC contact details to publish, and whether any sector-specific complaints body applies to the training organisation's handling]
11. Changes to this policy
We will update this policy when the platform changes in a way that affects how personal information is handled, for example when a new provider is added to section 6. The date and version at the top of this page change with it. Training organisations are notified of material changes; the current version is always at this address.
12. Contact
Privacy enquiries, access and correction requests, and complaints: privacy@connectedin.app.
[LAWYER: postal address and, if one is appointed, the name of the privacy officer]
The terms on which training organisations use the platform are at connectedin.app/terms.
Back to top