GDPR Compliance Statement

Last Updated: August 13, 2026

This statement outlines our commitment to compliance with the General Data Protection Regulation (GDPR) and describes how we protect the personal data of individuals in the European Economic Area who use our services.

Our Role as Data Controller

For the personal data we collect through our website and educational services, we act as the data controller. This means we determine the purposes and means of processing your personal data and are responsible for its protection and lawful processing.

Legal Basis for Processing

We process personal data based on the following legal grounds:

Data We Collect and Process

We collect and process the following categories of personal data:

How We Use Your Data

Personal data is processed for specific, explicit, and legitimate purposes:

Your Rights Under GDPR

You have the following rights regarding your personal data:

Right to Access

You may request confirmation of whether we process your personal data and obtain a copy of that data. We will provide this information in a commonly used electronic format.

Right to Rectification

If your personal data is inaccurate or incomplete, you have the right to request correction or completion of that data.

Right to Erasure

Under certain circumstances, you may request deletion of your personal data. This right is not absolute and may be limited by legal obligations to retain certain records.

Right to Restrict Processing

You may request that we limit how we use your personal data in certain situations, such as when you contest the accuracy of the data or object to processing.

Right to Data Portability

You have the right to receive personal data you provided to us in a structured, commonly used, machine-readable format and to transmit that data to another controller.

Right to Object

You may object to processing of your personal data based on legitimate interests. We will cease such processing unless we demonstrate compelling legitimate grounds that override your interests.

Right to Withdraw Consent

Where processing is based on consent, you may withdraw that consent at any time. Withdrawal does not affect the lawfulness of processing conducted before withdrawal.

Right to Lodge a Complaint

You have the right to lodge a complaint with a supervisory authority if you believe we have processed your personal data in violation of GDPR requirements.

Exercising Your Rights

To exercise any of these rights, please submit a request to [email protected]. Include sufficient information to allow us to verify your identity and locate your data in our systems.

We will respond to verified requests within one month. In complex cases, we may extend this period by two additional months and will inform you of any such extension.

We do not charge a fee for exercising your rights unless requests are manifestly unfounded or excessive, in which case we may charge a reasonable fee or refuse to act on the request.

Data Retention

We retain personal data only for as long as necessary to fulfill the purposes for which it was collected, including legal, accounting, and reporting requirements.

Enrollment and academic records are typically retained for seven years following program completion to comply with educational record-keeping standards. Marketing consent data is retained until consent is withdrawn.

When personal data is no longer required, we securely delete or anonymize it according to our data retention schedule.

International Data Transfers

Personal data collected from individuals in the EEA may be transferred to and processed in Australia. When transferring data outside the EEA, we implement appropriate safeguards to ensure adequate protection.

These safeguards may include standard contractual clauses approved by the European Commission or other legally recognized transfer mechanisms. You may request information about specific safeguards implemented for your data.

Data Security

We implement appropriate technical and organizational measures to protect personal data against unauthorized or unlawful processing, accidental loss, destruction, or damage. These measures include:

Data Breach Notification

In the event of a personal data breach that poses a risk to your rights and freedoms, we will notify you without undue delay. We will also notify relevant supervisory authorities within 72 hours of becoming aware of the breach, where required by law.

Automated Decision-Making

We do not use automated decision-making or profiling that produces legal effects or similarly significantly affects you without human intervention.

Contact Our Data Protection Officer

For questions or concerns about our GDPR compliance or data protection practices, you may contact our Data Protection Officer:

Data Protection Officer
alchecentu
Level 12, Suite 1203
485 La Trobe Street
Melbourne VIC 3000
Australia

Email: [email protected]

Updates to This Statement

We may update this GDPR compliance statement to reflect changes in our practices or legal requirements. Material changes will be communicated through website notice and, where appropriate, direct notification to affected individuals.