Privacy Policy

Last updated: 17 July 2026

  1. About this policy

Equator Pty. Ltd. trading as Equator Information Technology (Equator ITweus or our) provides the EDMISS student management system and related products, integrations, websites, support and consulting services.

This Privacy Policy explains how we collect, hold, use and disclose Personal Information in connection with:

  • the EDMISS Subscription Service;
  • our websites, forms and communications;
  • customer onboarding, account management, billing, support and consulting;
  • sales, events and marketing;
  • security, service monitoring and product improvement; and
  • our other business activities.

It applies to Customers, Users, website visitors, business contacts, suppliers, contractors and other individuals whose Personal Information we handle.

Personal Information is information or an opinion about an identified individual, or an individual who is reasonably identifiable. Sensitive Information includes certain information about matters such as health, disability, racial or ethnic origin, religious beliefs and sexual orientation.

  1. Our role when colleges use EDMISS

Our customers include colleges, universities, and other education providers (Customers).

In this policy, a User is an individual authorised by a Customer to access EDMISS. An App or Third-Party Product is an application, integration or other third-party service used in connection with EDMISS.

A Customer generally decides what information it collects about its students, prospective students, graduates, education agents, staff and other individuals, why it collects that information and how it uses EDMISS and any connected services. We hold and process that information as necessary to provide EDMISS and related services under our agreement with the Customer.

If your information was entered into EDMISS by a Customer, the Customer will usually be the most appropriate organisation to contact first about:

  • why the information was collected;
  • how it is being used;
  • access to or correction of the information; or
  • a privacy complaint concerning the Customer’s activities.

We will reasonably assist the Customer with privacy requests and complaints relating to Personal Information that we hold on its behalf.

This Privacy Policy does not replace a Customer’s own privacy policy or collection notices.

  1. Personal Information we collect and hold

The Personal Information we collect or hold depends on how an individual interacts with us and how a Customer configures and uses EDMISS. It may include the following categories.

 

3.1 Customer and User information

  • name, business contact details, job title and organisation;
  • EDMISS username, account role, access permissions and authentication information;
  • account, subscription and onboarding information;
  • support requests, correspondence, call notes and training records;
  • billing contacts, invoices and payment records; and
  • preferences and consent records.

 

3.2 Website, technical and usage information

  • IP address, device, browser and operating-system information;
  • login activity, timestamps, audit records and security events;
  • feature usage, performance information and diagnostic logs;
  • website interactions and form submissions; and
  • cookie and similar-technology information.

 

3.3 Sales, marketing and event information

  • business contact information;
  • enquiries, product interests and communications;
  • event attendance and survey responses; and
  • marketing preferences and unsubscribe requests.

 

3.4 Customer Data held through EDMISS

Depending on the Customer’s activities and configuration, Customer Data may include information about students, prospective students, graduates, education agents, staff and other individuals, such as:

  • identity and contact information;
  • date of birth and demographic information;
  • enrolment, course, attendance, assessment and academic information;
  • communications and relationship history;
  • education-agent and commission information;
  • billing, invoicing and payment information;
  • government-related identifiers and immigration or visa-related information;
  • welfare, support, accommodation or guardianship information; and
  • Sensitive Information, where the Customer is permitted to collect and use it.

The Customer determines the particular Customer Data entered into EDMISS. We do not require Customers to provide more Personal Information than is reasonably necessary for the services they choose to use.

We collect Sensitive Information only where it is reasonably necessary for our functions or activities and the individual has consented, or where the collection is otherwise permitted or required by law. A Customer is responsible for ensuring that it is permitted to collect and provide any Sensitive Information it enters into EDMISS.

  1. How we collect Personal Information

We may collect Personal Information:

  • directly from you, including through our websites, forms, emails, telephone calls, meetings, events and support channels;
  •  when you create or use an EDMISS account;
  • from the Customer that employs, engages, enrols or otherwise deals with you;
  • through EDMISS and its security, monitoring and diagnostic systems;
  • from an App, integration or Third-Party Product enabled or directed by a Customer;
  • from our service providers and business partners;
  • from publicly available sources, where lawful and appropriate; and
  • through cookies and similar technologies.

Where a Customer provides Personal Information about a student, education agent, staff member or other individual through EDMISS, the Customer is responsible for giving that individual any privacy notices and obtaining any consents required by law. We do not ordinarily contact those individuals directly. Where we collect Personal Information about an individual from a third party for our own business purposes, we take reasonable steps, where required by law, to notify the individual or otherwise ensure that the individual is aware of the collection.

Where it is lawful and practicable, you may interact with us anonymously or using a pseudonym. We may be unable to provide particular services or respond to a request if we cannot collect the information reasonably required for that purpose.

  1. Why we collect, hold, use and disclose Personal Information

We may handle Personal Information to:

  • provide, operate, administer and support EDMISS and related services;
  • establish and manage Customer relationships, subscriptions and User accounts;
  • perform onboarding, training, consulting and support;
  • authenticate Users and manage permissions;
  • process invoices and payments and maintain business records;
  • communicate with Customers, Users and other contacts;
  • secure, monitor, troubleshoot and maintain our systems and services;
  • detect, prevent and respond to fraud, misuse, cyber threats and data incidents;
  • understand service usage and improve reliability, functionality and customer experience;
  • develop and plan our products and services using properly de-identified information;
  • respond to enquiries, complaints and privacy requests;
  • conduct sales, events and lawful direct marketing;
  • establish, exercise or defend legal claims;
  • comply with legal, regulatory and contractual obligations; and

We may also handle Personal Information for another purpose where you have consented or where the handling is otherwise authorised or required by law.

  1. Artificial intelligence and machine learning

We do not use identifiable Customer Data to train, fine-tune, test, evaluate or improve an artificial-intelligence or machine-learning model. This restriction applies to models operated by us and models operated by our providers.

Where a Customer enables an artificial-intelligence or machine-learning feature that needs to process identifiable Customer Data, that information may be processed only to provide the feature or result requested by the Customer. We do not permit the provider to use that identifiable Customer Data, or related prompts, responses or outputs, to train, fine-tune, test, evaluate or improve a model.

We may use information that has first been properly de-identified for analytics, research, service planning and developing or improving features, including features that use artificial intelligence or machine learning. Before doing so, we take reasonable steps to assess and minimise the risk of re-identification, and we do not attempt to re-identify the information.

  1. When we disclose Personal Information

We do not sell, rent or trade Personal Information. We do not disclose Personal Information to third parties for their own unrelated commercial purposes.

We disclose Personal Information only where reasonably necessary to provide, administer, secure or support our services, where a Customer has enabled or directed the disclosure, where the individual has consented, or where the disclosure is required or authorised by law.

We may disclose Personal Information to:

  • our employees and contractors who need it to perform their duties and are subject to confidentiality obligations;
  • the relevant Customer and its authorised Users;
  • providers that support our hosting, infrastructure, cybersecurity, monitoring, communications, customer support, billing, payment processing, analytics and other business operations;
  • Apps, integrations and Third-Party Products enabled, configured or directed by a Customer;
  • professional advisers, insurers, auditors and financial institutions;
  • law-enforcement bodies, courts, regulators and government agencies where required or authorised by law;
  • any other recipient where you have consented or the disclosure is authorised or required by law.

We require service providers handling Personal Information for us to apply appropriate privacy, confidentiality and security protections.

  1. Overseas access and disclosure

Customer Data hosted and controlled by Equator IT as part of the EDMISS Subscription Service is subject to the protections described in this Privacy Policy.

We do not ordinarily disclose Customer Data to an overseas recipient unless a Customer enables or directs an App, integration or Third-Party Product that involves overseas processing, the disclosure is required or authorised by law, or the Customer otherwise authorises the disclosure.

Some providers used for our website, communications, support, monitoring or other business operations may be located in different countries or may allow authorised personnel in other countries to access Personal Information. The providers and their processing locations may change, and it is not practicable for us to list every country in which an overseas recipient may be located. You may contact our Support team for information that is reasonably available about a particular disclosure.

Before disclosing Personal Information to an overseas recipient, we take reasonable steps required by applicable law to ensure that the recipient handles the information appropriately. These steps may include due diligence, contractual privacy and security requirements, access controls and monitoring.

If a Customer enables, configures or directs an App, integration or Third-Party Product, Personal Information may be transferred to locations selected or used by that Customer or provider. The Customer is responsible for assessing those locations and ensuring that its use of the service complies with applicable privacy and data-protection laws. Our Customer Terms of Service and Developer Terms provide further information about Customer-directed integrations and overseas processing.

  1. Cookies and similar technologies

Our websites and products may use cookies and similar technologies to:

  • operate and secure the website;
  • remember preferences;
  • understand website performance and usage;
  • respond to enquiries and measure engagement; and
  • support marketing, where permitted.

You can control cookies through your browser settings and any cookie controls made available on our website. Blocking some cookies may affect website functionality.

  1. Direct marketing

We may use the name, work contact details, role and organisation of current and former Customer staff members who hold or previously held an EDMISS user account to communicate about EDMISS products, services, events and updates where permitted by law. These communications may continue after the Customer’s subscription ends.

We do not use any other Customer Data for our own direct marketing.

An individual may opt out at any time by using the unsubscribe facility in a marketing message or contacting our Support team. We will process an opt-out request within a reasonable period.

Even if an individual opts out of direct marketing, we may continue to send operational, security, billing and other communications relating to services previously or currently provided by us.

  1. Security

We use administrative, physical and technical safeguards designed to protect Personal Information against misuse, interference, loss and unauthorised access, modification or disclosure. Measures may include access controls, authentication, encryption, logging, monitoring, backups, staff training, incident-response processes and service-provider controls.

No method of electronic transmission or storage is completely secure. If we identify an actual or suspected data incident, we will contain, assess and respond to it in accordance with applicable law and our contractual obligations.

Where we have reasonable grounds to suspect that an eligible data breach may have occurred, we conduct a reasonable and expeditious assessment and take all reasonable steps to complete it within the period required by the Privacy Act. If we have reasonable grounds to believe that an eligible data breach has occurred, we notify the OAIC and affected individuals as soon as practicable, unless an exception applies.

  1. Retention and deletion

Within 30 days after termination or expiration of a Customer’s EDMISS agreement, we securely delete Customer Data in our possession or control, including Customer Data contained in active systems, replicas, archives and backups, except where:

  • the information has been properly de-identified; or
  • we are required by law to retain it, in which case we protect it, restrict its use to the required purpose and securely delete it when retention is no longer required.

For Personal Information other than Customer Data, we retain the information only for as long as reasonably necessary for the purposes for which it is held, including direct marketing as permitted by section 10, or as required or authorised by law. When it is no longer required, we take reasonable steps to destroy it or ensure that it is properly de-identified.

After a Customer’s subscription ends, we may retain the name, work contact details, organisation, business relationship history and marketing preferences of the Customer’s former administrative, operational and business contacts for direct marketing as described in section 10. This information is held separately for our own customer-relationship and marketing purposes and is not Customer Data.

An individual may opt out of direct marketing at any time. After an individual opts out, we may retain a minimal suppression record so that we can continue to honour the opt-out request.

  1. Accessing and correcting Personal Information

You may request access to Personal Information we hold about you or ask us to correct information that is inaccurate, out of date, incomplete, irrelevant or misleading.

Personal Information held by us for our own business purposes may include your account profile, business contact details, support correspondence, marketing preferences and technical or usage information associated with you. Depending on the request and the nature of the information, we may provide a copy or summary, allow the information to be inspected, or provide access in another reasonable and practicable form.

If the requested information is Customer Data entered into EDMISS by a college or other education provider, the Customer will usually be best placed to verify the request and provide access or make a correction. You may contact the Customer directly. If you make the request to us, we will assess it in accordance with applicable law and, where appropriate, coordinate with and reasonably assist the Customer. We will not disclose Personal Information unless we are reasonably satisfied about the identity and authority of the person making the request.

To make a request, contact our Support team using the details below and describe the Personal Information you want to access or correct. We may ask for information reasonably necessary to verify your identity and locate the relevant records. We will respond within a reasonable period, normally within 30 days.

We will not charge you for making an access or correction request, or for correcting Personal Information. Where permitted by law, we may charge reasonable costs for providing access. If we refuse access or correction, or cannot provide access in the requested form, we will provide written reasons where required by law and explain the available complaint options. Where appropriate, we will consider whether access can be provided in another form or whether a statement should be associated with information we decline to correct.

  1. Privacy complaints

If you believe we have mishandled your Personal Information or breached the APPs, contact our Support team and provide details of your concern.

We will acknowledge the complaint promptly, investigate it fairly and aim to provide a written response within 30 days. If we need more time, we will explain why and provide an expected response date.

We keep an appropriate record of the complaint, our investigation and the outcome. We may be unable to fully investigate an anonymous complaint, but we will consider the issues raised and take action where reasonably practicable.

  1. Third-party websites and services

Our websites and services may contain links to or interoperate with third-party websites, Apps and services. Their handling of Personal Information is governed by their own privacy policies and terms. We recommend reviewing those documents before providing Personal Information to them.

  1. Changes to this policy

We may update this Privacy Policy to reflect changes to our practices, services or legal obligations. We will publish the updated policy and its effective date on our website. Where a change is material, we will take reasonable steps to provide additional notice.

Where appropriate, we may also publish a short summary of material changes so individuals can readily understand what has changed.

  1. Contact us

Equator Pty. Ltd. trading as Equator Information Technology
PO Box 7033
Southport QLD 4215
Australia

Email: support@equatorit.com
Telephone: +61 (07) 4800 5086
Website: https://edmiss.com/