G.03/25 Solent Circuit, Norwest, NSW, 2153

Privacy Policy

Privacy Policy

Insources Group Pty Ltd
ABN 74 625 075 041
Email: [email protected]
Website: www.insources.edu.au

Effective date: 20/06/2026 Version: 2026.02
On this page

1. About this Policy

Insources Group Pty Ltd, referred to as Insources, we, us or our, respects the privacy of its customers, training participants, subscribers, consulting clients, research participants and website users.

This Privacy Policy explains how we collect, hold, use and disclose personal information in connection with:

  • our website and online portals;
  • training programs, webinars, conferences and events;
  • subscriptions and digital products;
  • consulting, audit, validation and rectification services;
  • strategy and resource-development projects;
  • research projects; and
  • enquiries and other business interactions.

We handle personal information in accordance with applicable privacy laws and, where applicable, the Privacy Act 1988 and Australian Privacy Principles.

This Policy operates alongside our Terms of Use, Terms of Sale & Subscription and any applicable contract, research information sheet or consent form.

2. What Is Personal Information?

Personal information is information or an opinion about an identified individual or an individual who is reasonably identifiable.

Sensitive information includes information about matters such as a person’s health, disability, racial or ethnic origin, political opinions, religious beliefs, sexual orientation or criminal record.

We collect sensitive information only where reasonably necessary, authorised by law or provided with appropriate consent.

3. Information We Collect

Depending on your interaction with us, we may collect:

Contact and account information

  • name;
  • email address;
  • telephone number;
  • postal or billing address;
  • organisation;
  • job title;
  • account username;
  • communication preferences; and
  • records of enquiries and correspondence.

Transaction information

  • products or services purchased;
  • subscription information;
  • invoices;
  • billing details;
  • payment status;
  • refunds, credits and cancellations; and
  • limited payment identifiers supplied by payment providers.

Training and event information

  • registrations and attendance;
  • employer and job-title information;
  • course progress;
  • assessment responses and results;
  • certificates and continuing professional development records;
  • participant questions, feedback and survey responses;
  • photographs; and
  • webinar, training or event recordings.

Consulting and project information

During audits, validation, rectification and consulting projects, we may receive or access:

  • learner assessment evidence;
  • learner names and contact details;
  • employee and contractor records;
  • assessor files;
  • complaints and incident reports;
  • health or disability information;
  • regulator correspondence;
  • disciplinary or performance records;
  • organisational policies and systems; and
  • other information required for the agreed project.

We seek to limit access to information reasonably required for the agreed scope.

Research information

Research projects may involve:

  • surveys;
  • interviews and focus groups;
  • audio or video recordings;
  • participant contact details;
  • demographic information;
  • opinions and experiences;
  • sensitive information;
  • consent records;
  • research data;
  • participant incentive records; and
  • information supplied by government or institutional clients.

Project-specific research information sheets, consent forms, ethics approvals and research agreements may provide additional information about how research data will be handled.

Website and technical information

When you use our website or digital services, we may collect:

  • IP address;
  • browser and device type;
  • operating system;
  • pages visited;
  • referral source;
  • date and time of access;
  • account and login activity;
  • cookie identifiers;
  • website interactions; and
  • security and diagnostic information.

When you browse without signing in, we may not know your name, but technical information may still identify or be linked to you in some circumstances.

4. How We Collect Information

We may collect personal information:

  • directly from you;
  • through our website, forms and portals;
  • when you register, purchase, subscribe or attend;
  • through Moodle and other learning systems;
  • during consulting or research activities;
  • from your employer or sponsoring organisation;
  • from a client that engages us to perform services;
  • from event organisers, speakers or project partners;
  • from publicly available professional sources;
  • from authorised service providers; and
  • where required or authorised by law.

Where a client provides personal information to us, the client is responsible for having appropriate authority to disclose it.

5. Why We Use Personal Information

We may use personal information to:

  • respond to enquiries;
  • create and administer accounts;
  • process purchases and payments;
  • manage subscriptions;
  • deliver training and events;
  • monitor course progress;
  • assess responses and issue certificates;
  • provide customer and technical support;
  • conduct audits, validation and consulting services;
  • develop strategies, systems and resources;
  • complete rectification projects;
  • conduct and report research;
  • communicate service, account and contractual information;
  • improve our products, services and website;
  • conduct quality assurance;
  • prevent fraud, misuse and security incidents;
  • comply with legal, contractual and regulatory obligations;
  • manage complaints and disputes; and
  • send marketing communications where permitted.

We will not use personal information for a materially different purpose unless:

  • you have consented;
  • you would reasonably expect the use;
  • it is related to the original purpose and permitted by law; or
  • the use is otherwise required or authorised by law.

6. Training, Events, Photographs and Recordings

We may photograph or record training programs, webinars, conferences and events for:

  • delivering the program;
  • providing recordings to registered participants;
  • quality assurance;
  • maintaining attendance or participation records; and
  • other purposes disclosed before recording.

We will provide notice where a session or event is being recorded.

Where practicable, participants may request not to appear in a recording used for service delivery.

We will seek express or otherwise appropriate consent before using an identifiable participant’s image, voice or testimonial for promotional or marketing purposes.

7. Direct Marketing

We use Mailchimp to distribute newsletters and electronic direct marketing communications.

We do not automatically add customers or event attendees to marketing lists merely because they have purchased a product, registered for an event or attended training.

We may send marketing communications where:

  • you have subscribed;
  • you have otherwise consented;
  • you would reasonably expect the communication; or
  • the communication is otherwise permitted by law.

Every marketing email includes an unsubscribe facility.

You may unsubscribe at any time. We may retain limited details on a suppression list so that we can record and respect your request not to receive further marketing.

Unsubscribing from marketing does not prevent us from sending necessary transactional, contractual, service, security or account communications.

We do not sell personal information.

8. Conference Sponsors and Partners

For the National VET Conference, we may provide attendee names and email addresses to sponsors, exhibitors, speakers or event partners only where:

  • the attendee has been clearly informed of the proposed disclosure;
  • the purpose of the disclosure has been explained; and
  • the attendee has provided appropriate consent.

Attendees may choose not to consent without losing access to the core conference service.

Where possible, we provide sponsors and partners with aggregated or de-identified information rather than identifiable personal information.

Sponsors, exhibitors and partners are responsible for their own handling of information received by them.

9. Payments

We accept payments through Stripe and by bank transfer.

Stripe processes payment-card information under its own privacy and security arrangements.

Insources does not ordinarily receive or store complete credit-card or debit-card numbers.

We may receive and retain:

  • payer name;
  • billing details;
  • transaction amount;
  • payment status;
  • transaction reference;
  • limited card information, such as card type and last digits; and
  • records required for accounting, taxation, refunds and dispute management.

10. Cookies and Google Analytics

Our WordPress website uses cookies and similar technologies.

These may be used to:

  • operate website functions;
  • maintain security;
  • remember preferences;
  • understand website traffic;
  • analyse website performance; and
  • improve user experience.

We use Google Analytics to collect information about website use. Google Analytics may use cookies and process technical information such as IP address, device information, approximate location and website activity.

You may control cookies through browser settings and any cookie-preference tools made available on our website.

Disabling certain cookies may affect website functionality.

11. Learning and Business Systems

We use technology providers to operate our services, including:

  • WordPress for our website;
  • Australian-based website hosting;
  • Moodle for learning delivery, with Moodle data stored in Australia;
  • GoHighLevel for customer relationship management;
  • Mailchimp for newsletters and electronic marketing;
  • Stripe for payment processing;
  • Google Analytics for website analytics;
  • cloud communication and document-management providers;
  • transcription services;
  • approved artificial-intelligence tools; and
  • survey and research-analysis tools.

These providers may process personal information on our behalf and may be subject to their own terms and privacy practices.

12. Artificial Intelligence and Automated Tools

We may use approved artificial-intelligence or automated tools, including ChatGPT Enterprise, Google Gemini, transcription tools and automated survey-analysis tools, to support:

  • drafting;
  • summarisation;
  • transcription;
  • analysis;
  • quality assurance;
  • resource development; and
  • internal productivity.

Client Confidential Information and personal information must not be entered into AI tools.

Before using AI-assisted tools, we take reasonable steps to remove or de-identify personal and confidential information.

AI-generated material is subject to appropriate human review and is not used by itself to make final:

  • assessment decisions;
  • audit findings;
  • validation decisions;
  • compliance conclusions;
  • disciplinary decisions; or
  • research findings.

We do not use solely automated systems to make decisions that have a significant legal or similarly significant effect on individuals.

Research use of AI must also comply with the applicable research protocol, ethics approval, participant consent and contract.

13. When We Disclose Information

We may disclose personal information to:

  • employees, contractors and consultants who require access to perform their duties;
  • technology, hosting and cloud-service providers;
  • payment providers;
  • learning-management and webinar providers;
  • email and communication providers;
  • professional advisers;
  • approved research service providers;
  • venues and event-delivery providers;
  • clients where we process information as part of an agreed project;
  • conference sponsors and partners where the individual has been informed and has consented;
  • insurers;
  • regulators, courts, government agencies and law-enforcement bodies where required or authorised; and
  • another party involved in a genuine business sale, restructure or transfer, subject to appropriate safeguards.

We may also disclose information with your consent or as otherwise disclosed when it is collected.

We do not disclose personal information to unrelated organisations for their independent direct marketing without appropriate consent or legal authority.

14. Overseas Processing and Disclosure

Our website and Moodle data are hosted in Australia.

Some other technology and service providers may store, process or permit support access to information outside Australia.

Likely overseas locations include:

  • the United States;
  • European Union countries;
  • New Zealand; and
  • the Philippines.

The country used may vary according to the provider, service configuration, data backup, technical support and subcontractor arrangements.

Where personal information is disclosed or made accessible overseas, we take reasonable steps appropriate to the circumstances to:

  • assess the provider’s privacy and security practices;
  • limit the information provided;
  • use contractual and technical safeguards;
  • control access; and
  • require information to be handled consistently with applicable obligations.

By using our services, you acknowledge that some information may be processed in these locations, subject to the safeguards described in this Policy.

15. Research Privacy

Research information will be collected, used and disclosed in accordance with:

  • the research contract;
  • participant information and consent materials;
  • any applicable ethics approval;
  • the approved research methodology;
  • applicable law; and
  • this Privacy Policy.

Depending on the project:

  • participation may be voluntary;
  • participants may be able to withdraw within stated limits;
  • interviews or focus groups may be recorded;
  • identifiable information may be separated from research data;
  • results may be aggregated or de-identified;
  • findings may be published or presented; and
  • incentives may be provided.

We will not publish information that identifies a research participant unless the participant has provided appropriate consent or publication is otherwise authorised or required.

De-identified research data may be used only in accordance with the applicable consent, ethics approval and research agreement.

16. Data Security

We take reasonable administrative, technical and organisational steps to protect personal information against:

  • misuse;
  • interference;
  • loss;
  • unauthorised access;
  • unauthorised modification; and
  • unauthorised disclosure.

These measures may include:

  • access controls;
  • password and authentication requirements;
  • secure cloud systems;
  • staff and contractor confidentiality requirements;
  • data minimisation;
  • backups;
  • system monitoring;
  • security updates;
  • incident-response procedures; and
  • restricted access to project and research records.

No internet transmission or information-storage system can be guaranteed to be completely secure.

You are responsible for protecting your own account credentials and notifying us promptly if you suspect unauthorised access.

17. Data Breaches

We maintain a data-breach response plan.

If we become aware of a suspected privacy or security incident, we will take reasonable steps to:

  • contain the incident;
  • assess what occurred;
  • identify affected information and individuals;
  • reduce potential harm;
  • investigate the cause;
  • implement corrective measures; and
  • maintain appropriate records.

Where required by applicable law, we will notify affected individuals and the Office of the Australian Information Commissioner.

Suspected privacy or security incidents may be reported to [email protected].

18. Retention and Destruction

We retain personal information only for as long as reasonably required for the purpose for which it was collected and to meet legal, contractual, taxation, insurance, research and professional obligations.

Our usual retention periods are:

We may retain information for longer where:

  • required by law;
  • required under a contract or ethics approval;
  • a complaint, investigation or dispute is continuing;
  • legal proceedings are anticipated or underway; or
  • there is another legitimate and lawful reason.

When information is no longer required, we take reasonable steps to securely destroy or de-identify it.

19. Access, Correction and Deletion Requests

You may request:

  • access to personal information we hold about you;
  • correction of inaccurate, incomplete or outdated information; or
  • deletion of information where it is no longer required and deletion is legally and operationally available.

Requests should be sent to [email protected].

We may ask you to verify your identity before processing a request.

We aim to:

  • acknowledge a request within five Business Days; and
  • provide a substantive response within 30 calendar days.

Correction requests are handled without charge.

Access may be refused or limited where permitted by law, including where access would:

  • unreasonably affect another person’s privacy;
  • disclose commercially sensitive material;
  • reveal confidential evaluative information;
  • prejudice an investigation;
  • breach legal professional privilege; or
  • otherwise be unlawful.

A deletion request may be declined where information must be retained for legal, taxation, contractual, training, research, insurance, dispute or recordkeeping purposes.

Where we refuse a request, we will explain the reason to the extent permitted.

20. Anonymity and Pseudonymity

You may make a general enquiry anonymously or using a pseudonym where practical.

We may require your identity to:

  • process a purchase;
  • create or administer an account;
  • manage a subscription;
  • confirm training attendance;
  • issue a certificate;
  • enter into or perform a contract;
  • verify a research participant;
  • investigate a complaint;
  • protect security; or
  • meet a legal obligation.

21. People Under 18

Insources does not knowingly collect personal information from training participants or research participants under 18 years of age.

Our products and services are intended for adults and organisations.

A person must be at least 18 years old to purchase a product or enter into an agreement in their own name.

If we become aware that personal information about a person under 18 has been collected unintentionally, we will assess the circumstances and take reasonable steps to delete or otherwise appropriately manage the information.

22. Complaints

You may make a privacy complaint by contacting:

Privacy Officer
Insources Group Pty Ltd
Email: [email protected]
Website: www.insources.edu.au

Please include:

  • your name and contact details;
  • a description of the issue;
  • relevant dates and communications; and
  • the outcome you are seeking.

We aim to:

  • acknowledge a complaint within five Business Days; and
  • provide a substantive response within 30 calendar days.

If additional time is reasonably required, we will explain why and provide an expected response date.

Where the Privacy Act applies and you are dissatisfied with our response, you may be able to lodge a complaint with the Office of the Australian Information Commissioner.

23. Changes to this Policy

We may update this Privacy Policy to reflect:

  • changes to our practices;
  • new technologies;
  • new products or services;
  • changes to service providers; or
  • legal and regulatory developments.

The current version will be published on our website with its effective date.

Material changes will be communicated where reasonably appropriate.

24. Contact Us

Questions, access requests, correction requests, deletion requests, complaints and data-breach reports may be directed to:

Insources Group Pty Ltd
ABN 74 625 075 041
Email: [email protected]
Website: www.insources.edu.au