Privacy Policy
Effective August 2026 · Version 2026-08
Kestrel Assurance Pty Ltd (we, us) is committed to protecting your privacy and handling personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs). This policy explains what we collect and how we handle it.
1. Information we collect
- Account & contact details — name, email, phone, firm/business name, and password (stored only as a secure hash).
- Training & usage data — courses purchased, progress, assessment results and certificates issued.
- Enquiry data — information you submit through contact forms and during engagements.
- Payment data — processed by Stripe; we receive transaction metadata (amount, status, last-4, invoices) but do not store full card numbers.
- Technical data — IP address, device/browser information and essential cookies needed to run the site and keep you signed in.
In the course of compliance engagements we may handle additional information you provide. Where that includes personal information about your customers, you are responsible for having a lawful basis to share it with us.
2. Why we collect it
- To create and secure your account, including email one-time-code MFA.
- To deliver training and services you purchase and issue certificates.
- To process payments and issue tax invoices.
- To respond to enquiries and provide support.
- To meet our own legal and record-keeping obligations.
3. Disclosure & overseas providers
We disclose personal information to service providers who help us run the platform, under contractual protections. These include:
- Neon (database hosting) — data stored in Australia (Sydney).
- Stripe (payments & invoicing) — United States and other jurisdictions.
- Mux (video streaming) — United States.
- Resend (transactional email) — United States.
- Vercel (application hosting/CDN) — global edge.
Some providers are located overseas, so your information may be processed outside Australia. We take reasonable steps to ensure they handle it consistently with the APPs.
4. Security
We use appropriate technical and organisational measures, including encryption in transit, hashed passwords, MFA and access controls. No system is perfectly secure; you help protect your account by keeping your credentials confidential.
5. Retention
We keep personal information only as long as needed for the purposes above or as required by law. Records connected to compliance engagements may be retained in line with applicable record-keeping obligations (commonly seven years).
6. Access & correction
You may request access to, or correction of, the personal information we hold about you by emailing hello@kestrelassurance.com.au. We will respond within a reasonable period.
7. Cookies
We use essential cookies to keep you signed in and to run core functionality. We do not use advertising cookies. You can control cookies in your browser, though some features may not work without them.
8. Complaints
If you have a privacy concern, contact us at hello@kestrelassurance.com.au. If you are not satisfied with our response, you may contact the Office of the Australian Information Commissioner (OAIC) at oaic.gov.au.
9. Contact
Privacy enquiries: Kestrel Assurance Pty Ltd — hello@kestrelassurance.com.au — 1300 557 173.