Privacy Policy

Effective Date: 31 August 2026.

1. Introduction

RTO Point (“RTO Point”, “we”, “us” or “our”), based in Geelong, Victoria, provides consultancy services to Registered Training Organisations (RTOs) across Australia, including advice on buying, selling, establishing, registering and growing RTOs, compliance and audit support, and related professional services (the “Services”). This Privacy Policy explains how we collect, hold, use and disclose personal information, and how you can access or correct your information or raise a concern.

We are committed to handling personal information in line with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs) issued by the Office of the Australian Information Commissioner (OAIC). Even where a small business exemption may apply to us, we have chosen to adopt APP-standard practices because our clients and website visitors are entrusting us with sensitive business, compliance and personal information.

By using our website, submitting an enquiry, or engaging us for Services, you agree to the collection and use of your personal information as described in this Policy.

2. Personal Information We Collect

The personal information we collect depends on how you interact with us. It may include:

  • Contact details: first name, last name, email address, phone number, and business/organisation name.
  • Enquiry content: the content of any message, form submission, phone call, email or meeting notes when you contact us through our website contact form or otherwise.
  • Client and engagement information: information provided in the course of an engagement, which may include details about your RTO, its compliance status, staff, and business operations, to the extent reasonably necessary to provide our Services.
  • Technical and usage information: information generated by your use of our website, such as IP address, browser type, device information, pages viewed and referring pages, generally collected automatically through cookies or similar technologies (see Section 6).
  • Publicly available information: information about your organisation that is publicly available (for example, via ASQA, the National Register, or your own website or LinkedIn page), where relevant to our Services.

We do not intentionally collect sensitive information (such as health information) unless it is volunteered by you and reasonably necessary for the Services, and only with your consent or as otherwise permitted by law.

3. How We Collect Personal Information

  • Directly from you, when you complete our website contact form, email or call us, or engage our Services.
  • Automatically, through your use of our website (see Cookies and Analytics, Section 6).
  • From third parties, such as referral partners, regulators, or publicly available sources, where reasonably necessary for our Services and permitted by law.

Where practicable, we collect personal information directly from you. If we receive unsolicited personal information we did not request, we will assess whether we could have lawfully collected it and, if not, will destroy or de-identify it as soon as practicable, in accordance with APP 4.

4. Why We Collect, Hold, Use and Disclose Personal Information

We collect, hold, use and disclose personal information for purposes including to:

  • respond to enquiries submitted through our website or by phone/email;
  • provide, manage and deliver our consultancy and compliance Services;
  • communicate with you about your enquiry or engagement, including quotes, invoices and scheduling;
  • improve our website, Services and client experience;
  • comply with our legal and regulatory obligations, including obligations under Australian consumer, tax and privacy law;
  • with your consent, send marketing communications about our Services (see Section 8); and
  • protect the rights, property or safety of RTO Point, our clients or others.

We will not use or disclose personal information for a purpose other than the purpose for which it was collected, unless you would reasonably expect that use, the law requires or permits it, or you have consented.

5. Disclosure of Personal Information

We do not sell personal information. We may disclose personal information to:

  • our staff and contractors, on a need-to-know basis, to deliver the Services;
  • service providers, such as our website host/developer (Code n Design), email and office software providers, form and analytics providers, and accounting or scheduling tools, engaged to help us operate our business;
  • professional advisers such as our accountant, auditor or lawyer, where reasonably necessary;
  • regulators or government bodies (for example ASQA), where you have engaged us in connection with a regulatory matter and disclosure is necessary for that purpose, or where required by law; and
  • any other party where you have given consent, or where required or authorised by law.

Some of our service providers (for example, cloud email, hosting, or software platforms) may store or process information on servers located outside Australia. Where this occurs, we take reasonable steps to ensure any overseas recipient handles personal information consistently with the APPs, in line with APP 8, including by relying on providers with appropriate privacy and security safeguards.

6. Cookies and Website Analytics

Our website may use cookies and similar technologies (such as tags or scripts embedded by our website platform) to operate correctly, remember preferences, and to understand how visitors use the site — for example, through analytics tools that report on page views and general visitor behaviour, and social media links or embeds in the footer.

These technologies may collect technical information such as your IP address, browser and device type, and pages visited, but do not typically identify you personally. You can control or disable cookies through your browser settings; doing so may affect some website functionality.

7. Data Quality and Security

We take reasonable steps to ensure the personal information we hold is accurate, up to date and complete, and to correct it where we become aware it is not.

We take reasonable technical and organisational steps to protect personal information from misuse, interference, loss, and unauthorised access, modification or disclosure, including:

  • restricting access to personal information to staff and contractors who need it;
  • using reputable, password-protected software and cloud service providers;
  • securing physical and electronic records; and
  • reviewing our practices periodically.

No method of storage or transmission is completely secure. If we become aware of a data breach likely to result in serious harm, we will assess and respond in accordance with the Notifiable Data Breaches scheme under the Privacy Act, including notifying affected individuals and the OAIC where required.

We retain personal information only for as long as reasonably necessary to fulfil the purposes described in this Policy, or as required by law (for example, tax and record-keeping obligations), after which it is securely destroyed or de-identified.

8. Direct Marketing

We may use your contact details to send you information about our Services that we think may interest you, where we have your consent or another lawful basis to do so (for example, because you are an existing client and the communication relates to our Services).

You may opt out of marketing communications at any time by using the unsubscribe function in the communication, or by contacting us using the details in Section 11. We will not charge you for giving effect to an opt-out request.

9. Access and Correction

You may request access to the personal information we hold about you, or ask us to correct it, by contacting us using the details in Section 11. We will respond within a reasonable period (generally within 30 days), and will not charge for making a request, although reasonable costs may apply to fulfilling it.

We may need to verify your identity before providing access. In limited circumstances permitted by the APPs, we may decline to give access or refuse a correction request, and if so we will explain why and how you can seek a review of that decision.

10. Complaints

If you believe we have breached the APPs or mishandled your personal information, please contact us first using the details in Section 11 so we can investigate and respond. We will acknowledge your complaint and aim to resolve it within a reasonable time, generally within 30 days. If you are not satisfied with our response, you may lodge a complaint with the Office of the Australian Information Commissioner (OAIC):

11. Contact Us

For any questions, requests or complaints about this Privacy Policy or your personal information, please contact:
Business RTO Point
Address Unit 1, Level 3/65 Brougham St, Geelong VIC 3220
Phone 0403 215 566
Email info@rtopoint.com.au

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices or the law. The current version will always be available on our website, with the effective date shown at the top. Continued use of our website or Services after an update constitutes acceptance of the revised Policy.