Privacy Policy
Effective Date: 20 August 2026 | Version 1.0
1. Introduction
Koios Professional ("the App") is a continuing professional development (CPD) platform developed and operated by Koios Pty Ltd (ABN 85 696 558 951) ("we", "us", or "our"). The App serves two distinct user types:
Professionals: Professionals — individuals who use the App to log, track, manage, and export their own CPD records.
CPD Providers: CPD Providers — individuals (e.g. independent trainers) and organisations (e.g. training companies, professional associations, employers) who list CPD activities, manage learner records, and issue certificates through the App.
We are committed to protecting all personal information we handle in accordance with the Privacy Act 1988 (Cth) ("Privacy Act") and the thirteen Australian Privacy Principles (APPs). This Privacy Policy explains what personal information we collect from each user type, why we collect it, how we use and disclose it, and the rights you have in relation to it. By using Koios Professional, you agree to the practices described in this Policy.
2. Open and Transparent Management of Personal Information (APP 1)
We manage personal information openly and transparently. This Privacy Policy is freely available within the App and on our website at all times. If you have questions, please contact our Privacy Officer using the details in Section 14.
3. Anonymity and Pseudonymity (APP 2)
Where practicable, you may interact with us anonymously — for example, when submitting a general enquiry. However, both Professionals and CPD Providers must provide identifiable information to access the App's core features, as described in Section 4.
4. Collection of Personal Information (APP 3)
4.1 Information collected from Professionals
We collect the following personal information from Professionals:
Identity & Contact: Full name, email address, and password (hashed); phone number (optional).
Employment & Professional Info: Employer or organisation name, job title, profession or industry, and professional registration or membership numbers where relevant.
CPD Activity Records: CPD activity records including activity type, date, duration, provider, learning outcomes, supporting documents and images, and reflective notes.
Payment & Billing: Subscription tier, billing name, and payment details (processed by our third-party payment processor; we do not store full card numbers).
Location: General geographic location (city/region level) where you enable location services, to assist with recommending local CPD opportunities.
Technical & Usage Data: Device type, operating system, App version, and anonymised usage analytics.
4.2 Information collected from CPD Providers
We collect the following personal and organisational information from CPD Providers:
Identity & Contact: Individual trainer name or organisation name, ABN (where applicable), email address, phone number, and postal address.
Provider Profile: Provider profile information, contact details, presenter information, credentials, areas of expertise, and profile images.
CPD Activity Listings: Details of CPD activities listed on the platform, including activity title, description, category, delivery format, duration, dates, location (physical or online), and pricing.
Learner Data (on behalf of Providers): Names, email addresses, and CPD completion data of learners (Professionals) who register for or complete a Provider's activities, to the extent the Provider manages these records through the App.
Certificate Data: Certificate data generated through the App's certificate issuance feature, including recipient name, activity details, and date of completion.
Payment & Billing: Subscription and billing details where the Provider holds a paid account.
Technical & Usage Data: Device type, operating system, webapp version, and anonymised usage analytics.
4.3 Data processor / data controller relationship
Where a CPD Provider uses the App to manage learner (Professional) records and issue certificates, the CPD Provider acts as a data controller in respect of that learner data, and we act as a data processor on the Provider's behalf. In that capacity, we process learner data only on the Provider's instructions and as necessary to provide the App's services. CPD Providers are responsible for ensuring they have a lawful basis for collecting and submitting learner personal information to the App, and for complying with their own obligations under the Privacy Act in relation to that information.
4.4 How we collect information
We collect personal information:
Directly from you when you register, create a profile, list activities, log CPD records, or contact our support team.
Automatically through the App's analytics and crash-reporting tools.
From third-party identity providers (Google, Apple) when you choose to sign in using those services.
From CPD Providers, in relation to learner data they submit or manage through the App.
4.5 Consequences of not providing information
Information marked as required during registration must be provided to access the App's core features. Optional information may be withheld without affecting core functionality. CPD Providers who choose not to provide complete profile information may have reduced visibility on the platform.
5. Unsolicited Personal Information (APP 4)
If we receive personal information that we did not solicit and could not have collected under APP 3, we will destroy or de-identify it as soon as practicable, provided it is lawful and reasonable to do so.
6. Notification of Collection (APP 5)
We notify you of the collection of your personal information at or before the time of collection through this Privacy Policy (presented at registration and accessible at any time in the App) and through in-context notices where we collect information for a new or different purpose.
CPD Providers are responsible for providing their own collection notices to learners at the time they collect learner personal information, and for directing learners to this Privacy Policy where relevant.
7. Use and Disclosure of Personal Information (APP 6)
7.1 Use of Professional data
We use Professionals' personal information to:
Create and manage accounts.
Enable logging, tracking, and export of CPD records.
Recommend relevant CPD activities listed by Providers, based on profession and location.
Process subscription payments.
Respond to support requests.
Send service-related notifications.
Maintain security and integrity of the App.
7.2 Use of CPD Provider data
We use CPD Providers' personal and organisational information to:
Create and manage Provider accounts and profiles.
Display Provider profiles and activity listings to Professionals on the platform.
Enable Providers to manage learner enrolments and records.
Support the issuance of CPD certificates by Providers.
Process Provider subscription payments.
Respond to support requests.
Maintain security and integrity of the App.
7.3 Disclosures to third parties
We may disclose personal information to the following parties:
Professional Bodies / Regulators (Professionals only): Professional CPD records may be shared with professional bodies or regulators only where the Professional has explicitly requested an export or submission, or where required by law.
CPD Providers: Where a Professional registers for or completes a CPD Provider's activity, relevant information (including name, email, and completion status) is shared with that Provider to enable the Provider to manage records and issue certificates.
Public Listings (CPD Providers): Provider profile details and activity listings are displayed publicly within the App to Professionals searching for CPD opportunities.
Cloud Infrastructure: AWS Sydney region, under a data processing agreement requiring APP-consistent handling.
Payment Processor: For processing subscription and payment transactions, in accordance with PCI-DSS standards.
Google / Apple: To the extent necessary to support single sign-on authentication.
Legal & Regulatory Authorities: Where required or authorised by law.
We do not sell personal information to third parties, and we do not disclose it for third-party direct marketing without consent.
8. Direct Marketing (APP 7)
We may send marketing communications to both Professionals and CPD Providers about platform features, updates, and relevant opportunities. You may opt out at any time by clicking "unsubscribe" in any marketing email, adjusting notification preferences in the App's Settings, or contacting our Privacy Officer. Opting out does not affect transactional or service-related notifications.
CPD Providers must not use contact information obtained through the App for direct marketing to Professionals outside the App without first obtaining those Professionals' express consent in accordance with the Spam Act 2003 (Cth) and the Privacy Act.
9. Cross-Border Disclosure of Personal Information (APP 8)
All personal information is stored on servers located in Australia (AWS Sydney region). We do not routinely transfer personal data overseas. Where an overseas disclosure is necessary (for example, certain support tools or sub-processors operating internationally), we will take reasonable steps to ensure the overseas recipient handles personal information consistently with the APPs, including through contractual obligations. Authentication data processed via Google or Apple SSO may involve overseas processing under those providers' own privacy policies.
10. Government Related Identifiers (APP 9)
We do not adopt, use, or disclose government-related identifiers (such as Tax File Numbers or Medicare numbers) as our own identifier for individuals. ABNs collected from CPD Provider organisations are used solely for the purpose of identifying the Provider on the platform and are not used as an individual identifier. Professional registration numbers collected from Professionals are used solely to support CPD logging and compliance reporting.
11. Quality of Personal Information (APP 10)
We take reasonable steps to ensure that personal information we collect, use, and disclose is accurate, up-to-date, and complete. Professionals can update their profile and CPD records at any time via the App. CPD Providers are responsible for ensuring their profile details, activity listings, and learner records are accurate and kept current. We encourage all users to review and update their information regularly.
12. Security of Personal Information (APP 11)
We implement reasonable technical and organisational security measures to protect all personal information from misuse, interference, loss, and unauthorised access. These include:
Encryption of data in transit (TLS/HTTPS) and at rest.
Password hashing using industry-standard algorithms.
Role-based access controls, including controls limiting CPD Provider access to only the learner data associated with their own activities.
Regular security reviews and vulnerability assessments.
AWS Sydney-region infrastructure with SOC 2-compliant controls.
In the event of a data breach likely to result in serious harm, we will comply with our obligations under the Notifiable Data Breaches (NDB) scheme in Part IIIC of the Privacy Act, including notifying affected individuals and the OAIC as required.
CPD Providers are responsible for maintaining appropriate security practices in relation to any learner personal information they access or download through the App.
13. Access and Correction of Personal Information (APPs 12 & 13)
13.1 Access
All users have the right to access the personal information we hold about them. Professionals may access and update their profile and export their CPD records at any time within the App. CPD Providers may access and update their profile and activity listing information at any time within the App. All users may request a copy of all personal information we hold by contacting our Privacy Officer.
We will respond to access requests within 30 days. We will advise you in writing if we are unable to provide access and explain the reason. We do not charge a fee for access requests, though a reasonable fee may apply for complex requests.
Note: Professionals seeking access to their records held by a CPD Provider (for example, enrolment or completion records managed by a Provider) should contact that Provider directly, as the Provider is the data controller for that information.
13.2 Correction
If you believe personal information we hold is inaccurate, out-of-date, incomplete, irrelevant, or misleading, you may request correction. We will take reasonable steps to correct the information within 30 days. If we disagree that correction is warranted, we will advise you in writing and you may request that a statement of your claim be associated with the information.
14. Analytics and Tracking Technologies
The App uses privacy-preserving analytics to collect anonymised and aggregated usage data. This data does not identify you individually and is used to improve the App's functionality and user experience for both Professionals and CPD Providers.
15. Children's Privacy
Koios Professional is intended for users aged 18 years and over. We do not knowingly collect personal information from individuals under 18. If we become aware of such collection, we will take steps to delete that information promptly.
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify users via the App or email prior to the changes taking effect and will update the effective date. Continued use of the App after the effective date constitutes acceptance of the updated Policy.
17. Complaints and Contact
17.1 Contact us
For questions, concerns, or complaints about how we handle personal information:
Privacy Officer, Koios Professional
Koios Pty Ltd
Email: hello@koiosprofessional.com
Response time: within 30 days of receipt
17.2 Our complaints process
We will acknowledge receipt within 5 business days, investigate, and provide a written response within 30 days.
17.3 Office of the Australian Information Commissioner (OAIC)
If you are not satisfied with our response, or believe we have breached the Privacy Act or the APPs, you may lodge a complaint with the OAIC:
Office of the Australian Information Commissioner
Website: www.oaic.gov.au
Phone: 1300 363 992
Email: enquiries@oaic.gov.au
GPO Box 5218, Sydney NSW 2001