You are on CAQA Labs
CAQA Labs - Part of CAQA GroupsCall 1800 266 160  |  info@caqa.com.au
Home / Data and Security Notice

Data and Security Notice

How CAQA Labs hosts, protects and manages data collected through this website and our virtual lab environments.

This Data and Security Notice explains how CAQA Labs, part of CAQA Groups and a Career Calling International Pty Ltd initiative, hosts, protects and manages the data that passes through this website and through the virtual lab environments we provision for clients. It supplements our Privacy Policy, which governs personal information; this notice focuses on where data lives, how it is secured and who is responsible for what.

Who this notice is for

It is written for the education providers, TAFEs, universities, enterprise learning teams and government bodies that use or are considering CAQA Labs, for the administrators who manage their environments, and for the trainers and learners who work inside them.

Data collected through this website

This public website collects the details you choose to give us through the contact form (name, organisation, contact details and the content of your enquiry), the email address you submit to the newsletter form, and routine technical information such as browser type and pages visited, used to keep the site working and understand how it is used. No payments are taken through this website, so no payment card details are collected or stored here; fees for CAQA Labs services are invoiced under written agreements as described in our Subscription Terms.

Data within hosted lab environments

When we provision environments for a client, we hold account identifiers for authorised users (or federate to the client's own sign-on system), roster and course-mapping information the client supplies, activity and completion logs used for support, security and training-evidence purposes, and environment telemetry such as resource usage. Lab environments are simulated practice spaces: clients and users must not load live production data, real student records or other confidential data sets into them, and content inside a lab may be reset or deleted as part of normal re-imaging.

Hosting and security controls

Environments are hosted in reputable commercial data centres, with Australian-region hosting used where available and agreed. Controls include encryption of traffic in transit, isolation between client tenancies, role-based access controls, multi-factor authentication for administrative access, hardening and patching of platform components, and logging of administrative actions. Backups of platform configuration are taken on a scheduled basis; lab workspaces themselves are treated as disposable and are not a storage service.

Incident reporting

We monitor for security events and investigate suspected incidents promptly. If we confirm an incident that affects a client's environment or data, we will notify the client's nominated administrator without undue delay, describe what happened and what we are doing about it, and cooperate with the client's own notification obligations. Where the incident involves personal information covered by the Notifiable Data Breaches scheme, we assess and respond in line with the Privacy Act 1988 (Cth) and our Privacy Policy.

Client responsibilities

Security is shared. Clients are responsible for managing their own user lists and removing departed staff or learners, for the strength and confidentiality of credentials on their side, for the lawfulness of any information they supply to us, for keeping real personal and production data out of lab environments, and for ensuring their users follow our Acceptable Use Policy. Client-side networks, devices and identity providers remain the client's responsibility.

Retention, return and deletion

Enquiry and subscription records are kept only as long as needed for the purposes described in our Privacy Policy or as required by law. When a client's subscription ends, environments are decommissioned, and configuration or exported artefacts the client asks us to hand over are provided within a reasonable period before deletion. Activity logs are retained for a limited period for security and audit purposes and then destroyed or de-identified.

Limits of this notice

This notice is general information about our practices and is not security, legal or compliance advice for your organisation. Specific security commitments for a given client, including any additional controls, certifications or data-location requirements, are recorded in that client's service agreement, which prevails over this notice to the extent of any inconsistency.

Contact us

Questions about this policy, or anything it covers, can be sent to info@caqa.com.au, raised by phone on 1800 266 160 (or 03 8103 8000), or submitted through our contact page. We respond to most enquiries within two business days.

Newsletter Subscription

To Receive Updates And Offers