Privacy Policy

Version 2026-09 · Effective 7 September 2026

StreamClass is operated by Skillfull (Aust) Pty Ltd, Australian Business Number 82 696 827 479 ("we", "us", "our"). This policy explains what we do with personal information. Its version number and effective date appear at the top of this page.

1. About this policy

1.1 It covers the StreamClass platform at www.streamclass.com.au, live sessions and our public website, and only Skillfull (Aust) Pty Ltd.

1.2 We handle personal information in accordance with the Australian Privacy Principles (APPs) in Schedule 1 to the Privacy Act 1988 (Cth). Where that Act applies to us we comply as a matter of law; where it does not, we apply the same standard as policy. "Personal information" means information or an opinion about an identified individual, or an individual who is reasonably identifiable. "Sensitive information" is the narrower category defined in section 6 of that Act, and clauses 3.5 and 3.6 explain how we treat it.

1.3 If an organisation gave you your account, it decides what goes into the platform, who inside it sees your records and how long they are kept, and its own privacy policy applies to you too.

1.4 We change this policy when what we do changes, publish each version here with its own number and date, and keep every version. Significant changes get account holders 30 days' notice, by email or at your next sign in. Single sign on and invitation links do not show that prompt, so check this page too.

2. Who this policy is about

2.1 Account holders are staff of a customer organisation with their own account: administrators, course creators, trainers, group leaders and billing contacts. You sign in yourself and can use clause 11 with us directly.

2.2 Learners are people whose records a customer organisation uploads, imports, invites or generates. We hold those records for that organisation and do not decide what goes in, what it is used for, or when it goes. Ask that organisation why a record exists and how long it will be kept.

2.3 A person can be both. We also hold information about website visitors and business contacts we approach. StreamClass is for workplace learning and is meant for people aged 18 or over, though nothing in the platform checks age. If we learn we hold a child's information without the consent the law requires, we will delete it or require the organisation to.

3. What we collect, and how

3.1 Account holders: name, email address, a password held only as a one way hash, optional profile details, role and permissions, multi-factor authentication settings, sign in and session records for each device (time, internet protocol (IP) address, browser user agent), your record of accepting our legal documents, support messages, billing and invoice records, and a log of significant actions under your account. Card numbers are entered on our payment provider's page and we never see them.

3.2 Learners: identity details the organisation supplies or you enter; enrolments, progress, completion and due dates; assessment answers, grades and attempts; attendance at live sessions, guests included; recordings where the host turned recording on, and transcripts and captions naming the speaker; messages and questions you type in; certificates and ratings; and usage records including pages viewed, IP address and user agent.

3.3 Uploaded content: video, audio, documents and images a customer uploads, and transcripts made from them. Any of it can contain personal information. We hold it as the customer put it in and do not inspect it.

3.4 Visitors and business contacts: page paths, event names, a session identifier, IP address, user agent and contact form entries; and a business contact's name, role, business email address, employer and our notes.

3.5 Sensitive information that reaches us unasked. Sensitive information includes health, disability, racial or ethnic origin, religious beliefs, political opinions, union membership, sexual orientation, criminal record and biometric information. Most of it arrives without us asking, inside a recording, transcript, chat message, support request or uploaded document. We do not seek it, we treat it as sensitive where we can see that it is, and we use it only to provide the service. No automated control detects it on those paths, so this is a commitment about how we behave, not a technical guarantee. We ask customers not to put sensitive information into the platform without the consent the Privacy Act requires.

3.6 Voice samples, which we do ask for. One feature collects sensitive information deliberately, and we would rather say so than leave you to find it. A customer can make a Signature Voice so that the voice on a recording can read new course text aloud. To make one, the customer picks a prepared course recording or uploads a clip of one person speaking. A recording of an identified person's voice, used to build a voice model, is biometric information and so is sensitive information. The form will not submit, and the platform will not accept the request, without a tick confirming that it is the speaker's own voice or that the speaker gave permission, and that the sample is processed by ElevenLabs in the United States. We record the account holder who ticked it, the date and time, and the IP address and browser user agent it came from. We do not separately check with the speaker, so the consent we hold is that account holder's word. The sample and the voice model built from it go to ElevenLabs, which holds the model. Removing the voice withdraws that consent: the voice stops working at once, we ask ElevenLabs to delete the model, and we delete the audio we made with it. The sample recording stays in our Australian storage until you ask us to remove it, and we will. We do not use voice recognition or face recognition to identify anybody.

3.7 We collect it from you as you use the platform; from the organisation that enrolled you; automatically, through sign in records, analytics, attendance and progress; from Zoom, where a customer connects an account to import a recording; and from published sources, for business contacts only.

4. Where we hold it

4.1 The platform runs on Amazon Web Services in the Asia Pacific (Sydney) region in Australia, and our database, files, video and transcripts are in that region. Uploaded material sits in storage closed to the public, and private video is delivered through signed links that expire. Material a customer deliberately publishes, such as a course cover image, sits in separate storage anyone with the link can read.

5. Why we use it

5.1 To create and secure accounts; deliver courses, record progress, mark assessments and issue certificates; run live sessions, record attendance, produce captions and transcripts, and record where the host turns recording on; store and serve uploaded content and build course material from it; let administrators, trainers and group leaders manage the people they are responsible for; support and bill customers; send service messages such as invitations, reminders, receipts and security notices; keep the platform secure; meet our legal obligations; and market our services, subject to clause 12.

5.2 We do not sell personal information, disclose it to advertising networks, or use it for advertising profiling.

6. Who we disclose it to

6.1 The organisation that enrolled you sees your enrolments, progress, results, attendance, certificates, and what you said or typed in a recorded session, through its administrators, trainers and group leaders. That is its record.

6.2 Other people in a live session. Your display name is visible to everyone else in the session, and anything you say or type becomes part of the transcript and chat that the host and the host's organisation can read afterwards.

6.3 Our service providers, each receiving only what it needs:

  • Amazon Web Services, Inc. Hosting, database, storage, email, speech to text, narration audio, and text and image generation. Hosting, database, storage and live captioning are in Australia; image generation in the United States. Text generation goes through Amazon's global routing, which Amazon may serve from a region outside Australia and outside the United States. The text sent that way can include course material, a session transcript, or a question a learner typed.
  • Stripe. Payments, invoices and refunds. Gets the billing contact name and email address and the charge details; card details go straight to Stripe and never to us. United States, plus the other countries in Stripe's published privacy documents.
  • Zoom Video Communications, Inc. Meetings, cloud recordings and transcripts where a customer uses Zoom. Gets participant names, email addresses and the meeting audio and video. United States, or the data region set on the customer's own Zoom account.
  • OpenAI, L.L.C. Turns course narration text into audio. United States.
  • ElevenLabs Inc. Turns course narration text into audio. Where a customer makes a Signature Voice under clause 3.6, ElevenLabs also receives the voice sample and holds the voice model built from it. United States.
  • Cloudflare, Inc. Checks a form came from a person, and gets your IP address. United States.
  • Google LLC. Carries outbound email where our own mail service is not enabled. United States.
  • Slack Technologies, LLC. Carries internal alerts that can hold an organisation name, user identifier or error message. United States.

6.4 We also disclose to professional advisers under a duty of confidence; where disclosure is required or authorised by an Australian law or a court order, or where a permitted general situation under section 16A of the Privacy Act 1988 (Cth) applies, which includes a disclosure reasonably necessary to lessen or prevent a serious threat to a person's life, health or safety; and to a buyer if we sell the business, on terms no less protective than this policy.

7. Sending information overseas

7.1 Yes, we are likely to disclose personal information to overseas recipients, and the country they are likely to be in is the United States. Clause 6.3 says which provider gets what, and where. One path is wider than a single country, and we will not pretend otherwise: text generation runs through Amazon's global routing, so Amazon may serve it from a region outside Australia and outside the United States, and we cannot name that region in advance.

7.2 What goes overseas, in practice: billing details to our payment provider; meeting audio, video and participant details to Zoom where a customer uses it; narration text to our speech providers, and a voice sample and voice model where a customer makes a Signature Voice; your IP address to our automated abuse check provider; course material, session transcripts and questions typed inside a course to text generation; and internal alerts that can contain an identifier.

7.3 What is held in Australia: account records, learner records, uploaded files, video, stored transcripts, and the audio of a live session while it is being captioned. The platform refuses to start unless its speech to text service is inside our own network in the same region. Being held here does not stop a copy going overseas for a purpose in clause 7.2.

7.4 We do not claim United States law, or the law of any other country a global service may route to, protects your information in a way substantially similar to the APPs. We take reasonable steps instead: established providers with published security commitments, under agreements restricting use of the information to providing the service to us. Where the Privacy Act applies to us, section 16C keeps us accountable for an overseas recipient's act that would breach the APPs.

8. Live sessions, recordings and transcripts

8.1 The host decides whether a session is recorded. Turning recording off does not turn off everything: no video recording is made, but attendance is still recorded and a transcript is still produced and kept. Assume what you say is written down and attributed to you.

8.2 The platform does not currently show participants an automatic on screen notice that a session is being recorded or transcribed, so the organisation running it must tell them beforehand. A customer can ask us to delete a session's transcript and chat, and we will.

9. How we protect it

9.1 These measures are in place, and we have deliberately not claimed anything else.

  • Passwords are one way hashes using the Password-Based Key Derivation Function 2 (PBKDF2) with the Secure Hash Algorithm 256 (SHA-256), 600,000 iterations and a random salt each, so we cannot read them. Multi-factor authentication with an authenticator application is available, its secret encrypted at rest and backup codes hashed.
  • Connections are encrypted in transit. Sign in cookies cannot be read by scripts and lapse after eight hours idle, sessions are revocable per device, a password change signs out every other session, and repeated failed sign ins from one address trigger a temporary block. A web application firewall with managed rules and a rate limit sits in front.
  • The database is encrypted at rest with a customer managed key with automatic rotation, sits in a private network rather than on the public internet, and has backups kept 35 days. Credentials for connected services, such as a customer's Zoom connection, are encrypted with 256-bit Advanced Encryption Standard encryption in Galois/Counter Mode before being written, and will not be stored at all without their key.
  • Access is by role, and staff reach customer information only to run, support or bill for the service. Support staff signing in as a user to reproduce a fault is written to our activity log.

9.2 We have not been independently certified or audited against an external security standard, and do not claim to have been. If you think somebody else has reached your account, tell us at once using clause 14.

10. How long we keep it, and deleting it

10.1 We keep account records, course content, learner records, recordings and transcripts while the customer's account is open. When an account closes, the customer has 30 days to export what it needs. After that window we delete or irreversibly de-identify that customer's content on request, by hand. We may keep information longer where the law or an unresolved claim requires it.

10.2 We are being direct about a limitation. Nothing deletes customer content or learner records on a schedule, and they do not expire by themselves. The deletion in clause 10.1 is done by our staff by hand, and so is a deletion a customer asks for while its account is open. Australian Privacy Principle 11.2 requires us to destroy or de-identify personal information we no longer need, and today we meet that by hand rather than on a timer. Ask us in writing if you need a deletion confirmed.

10.3 Discarded automatically, and this is the whole list: database backups after 35 days, superseded file versions after 90 days, application server logs after one week, and temporary address blocks once they expire. Our analytics records, which include IP addresses and user agents, have no automatic deletion today. We clear them by hand, and we will publish a fixed period here once that is automated.

10.4 Deleting your account. Ask on the account page in your profile. Deletion is scheduled 30 days ahead and you can cancel any time in those 30 days. When it runs we replace your email address with a non working address and your name with "Deleted User", clear your password, multi-factor settings and profile details, revoke every session, and delete your notes, saved courses, ratings and notifications.

10.5 What deletion does not do. It does not erase your learning record, your attendance, or the transcript of a session you were in. Your name, email address and the link to you go, but the record stays, because other people rely on a training record and a transcript with lines removed misleads everyone else who was there. Files and video belonging to a customer's account are untouched, and deletion does not reach the providers in clause 6.3 unless you ask us to pass it on. We may refuse or delay a deletion where the law requires us to keep the record. Copies stay in our backups for up to 35 days and in superseded file versions for up to 90 days.

10.6 Disconnecting Zoom. If a customer disconnects Zoom, or removes our app inside Zoom and Zoom tells us so, we erase the stored Zoom access and refresh credentials, the Zoom user identifier, the Zoom login email address, the granted permissions and the recording settings for that connection. Recordings, transcripts and courses already imported are not affected, and you can ask us to remove those separately.

10.7 A learner enrolled by an organisation should ask that organisation first, because the record sits in its account.

11. Access, correction and anonymity

11.1 The account page in your profile shows your details and your record of accepting our legal documents, and a button downloads a file of your profile, roles, enrolments, results, attendance and the caption lines attributed to you. An administrator with the data export permission can export their organisation's records, without passwords or stored credentials.

11.2 For anything else, write to us using clause 14, and we will ask for enough to be confident we are dealing with the right person. There is no particular form and no charge, though if access involves significant work we may ask you to pay our reasonable costs, telling you the amount first. We respond within 30 days.

11.3 If we refuse access or a correction we will say so in writing, give reasons unless it would be unreasonable to, and explain how to complain. If we refuse a correction you can ask us to attach a statement saying you consider the record inaccurate.

11.4 Account holders can correct their own profile at any time, and we take reasonable steps to keep what we collect, use and disclose accurate and up to date. A learner should ask the organisation holding the record, because it entered the record and can act faster; come to us and we will refer you there and help them respond.

11.5 You can read our public website without telling us who you are, and a guest can join a live session under a display name, though attendance is still recorded. You cannot use the learning platform anonymously or under a pseudonym, because a learning record, a result and a certificate only mean something attached to a known person. That is the exception in Australian Privacy Principle 2.2(b).

12. Cookies, analytics and marketing

12.1 Our cookies keep you signed in, protect forms against cross-site request forgery, let a guest into a live session, and let your browser play private video. They are needed for the platform to work, so blocking them stops you signing in or playing video. Our automated abuse check provider, named in clause 6.3, may set a cookie of its own on the sign in, registration, account recovery, sign up and contact forms.

12.2 We set no advertising cookies, we do not track you across other websites, and we run no third party advertising or tag management script. So there is no cookie consent banner, and we do not act on browser "do not track" signals. Our analytics records stay in our own database: a session identifier, page path, event name, IP address and user agent.

12.3 We may send account holders and business contacts information about our services. Where we write to a business person for the first time, we use business contact details that were conspicuously published for their work role, we write only about matters relevant to that role, and we do not use an address published with a statement declining unsolicited messages. Every marketing email carries an unsubscribe link and names Skillfull (Aust) Pty Ltd as the organisation that authorised it, with contact details valid for at least 30 days. Unsubscribing takes effect promptly and, under the Spam Act 2003 (Cth), no later than five business days. It does not stop service messages. You can ask us at any time where we got your contact details and to stop using them, and we will act on that. We do not sell or rent contact details.

13. Data breaches and complaints

13.1 Part IIIC of the Privacy Act 1988 (Cth) creates the Notifiable Data Breaches scheme. An eligible data breach is unauthorised access to, unauthorised disclosure of, or loss of personal information likely to result in serious harm, where remedial action has not prevented it.

13.2 If we suspect one we will contain it, then assess it within 30 days as the scheme requires. If there has been an eligible data breach we will give the Office of the Australian Information Commissioner (OAIC) a statement as soon as practicable and notify the individuals at risk, or publish the statement where notifying them is not practicable, and tell any customer organisation whose information is involved. We promise no fixed number of hours, because a promise we could miss is worse than none: we act without undue delay and within the periods the law requires.

13.3 Complaints. Tell us first, using clause 14: what happened, when, and what you would like us to do. We will acknowledge it, investigate, and give you a written response saying what we found and what we have done. We aim to resolve a complaint within 30 days, and will say why and when to expect an answer if it takes longer.

13.4 If you are not satisfied, or we do not respond within 30 days, you can complain to the OAIC at www.oaic.gov.au or on 1300 363 992. It generally expects you to come to us first and allow 30 days. Complaining costs you nothing, and we will not treat you differently for it.

14. How to contact us

14.1 Skillfull (Aust) Pty Ltd, Australian Business Number 82 696 827 479. Privacy enquiries, access and correction requests, suspected breaches and complaints go to our Privacy Officer:

  • Email: support@streamclass.com.au
  • Post: Privacy Officer, Skillfull (Aust) Pty Ltd, Suite 12, 79 Manningham Rd, Bulleen, VIC 3105

14.2 We publish no telephone number for privacy enquiries, because we cannot yet staff one reliably and an unanswered number is worse than none. Email and post are monitored, and we aim to respond promptly. Our registered office is Suite 12, 79 Manningham Rd, Bulleen, VIC 3105. This policy is free, and we will provide it in another reasonable form if you ask.