How CAQA Analytics stores, secures, accesses and de-identifies website data and the client datasets supplied for analytics engagements.
This Data Processing and Security Notice explains how CAQA Analytics, part of CAQA Groups and Career Calling International Pty Ltd (ABN 53 162 651 238), stores, secures, accesses and de-identifies the data it handles - both the information visitors submit through this website and the datasets clients supply to us for analytics engagements. It should be read together with our Privacy Policy, which explains how personal information is collected, used and disclosed.
Through this website we collect enquiry details submitted on our contact and booking forms (your name, organisation, email address, phone number and message), newsletter subscription email addresses, and standard website analytics information such as pages visited and the type of device used. This information is used to respond to you, arrange appointments and improve the website. No payments are taken through this website, so no cardholder or banking details are collected here.
When an education provider, business or government body engages CAQA Analytics under a scoped proposal, we may receive datasets to analyse on the client's behalf. Depending on the engagement, these can include enrolment and completion records, AVETMISS or other regulatory reporting extracts, survey responses, website and marketing metrics, financial and operational records, workforce data and system logs. The client remains the owner of this data and is responsible for ensuring it was collected lawfully and may be shared with us for the agreed purpose. We process it only on the client's instructions as set out in the proposal or service agreement.
Client datasets are stored in access-controlled systems used by CAQA Groups, with Australian-based storage preferred wherever practicable. Working files are kept within the engagement's designated project space rather than on personal devices. Where a cloud platform, business-intelligence tool or AI service is proposed for an engagement, we identify the platform in the proposal so the client can assess it before any data is transferred.
Access to client data is limited to the analysts and support staff working on the engagement, on a need-to-know basis. Staff access is authenticated, and administrative access to storage systems is restricted. Client data is used only for the engagement it was supplied for, and is never sold or shared with unrelated third parties.
We ask clients to supply datasets through secure channels agreed at the start of the engagement, such as encrypted file transfer or a shared secure workspace, rather than by unprotected email. This website is served over HTTPS, so form submissions are encrypted in transit.
Where an engagement can be delivered with de-identified or aggregated data, we encourage clients to remove direct identifiers before transfer. When we publish benchmarks, case studies or methodology examples, we use aggregated or synthetic figures so that no individual or client organisation can reasonably be identified without written consent.
At the end of an engagement, client datasets are returned, archived or securely deleted according to the proposal. Unless a different period is agreed or required by law, working copies of client data are removed from active systems once deliverables are accepted, and any retained records are kept only for contractual, insurance or legal compliance purposes.
If we become aware of unauthorised access to, or loss of, client data or website enquiry data, we will assess the incident promptly, contain it, notify affected clients without undue delay and meet any notification obligations that apply under the Privacy Act 1988 (Cth), including the Notifiable Data Breaches scheme where relevant.
Clients remain responsible for the accuracy and lawful collection of the data they supply, for obtaining any consents required, for limiting datasets to what the engagement genuinely needs, and for managing access to dashboards and reports once we deliver them into the client's environment.
Questions about this notice, requests about data handling, or reports of a suspected security issue can be sent to info@caqa.com.au, by phone on 1800 266 160, or through our contact page.
To Receive Updates And Offers