Privacy Policy
Last updated 17 August 2026
Â
Commercial INKS Australia Pty Ltd (ACN 679 183 156) as trustee for the Nair and Chand Trust (ABN 15 531 317 588), trading as Commercial INKS Australia (INKS, we, us, our), supplies and supports eCampus Buddy (the System) in Australia. The System is owned by Revolutionary Businesses Solutions LLC (the Owner), a company incorporated in the United Arab Emirates.
​
We are committed to handling personal information openly, transparently and responsibly, in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
​
1. How the Privacy Act applies to us
INKS is a small business operator for the purposes of section 6D of the Privacy Act. We have chosen, under section 6EA of the Privacy Act, to be treated as an organisation. We are therefore bound by the Privacy Act and the APPs, including the Notifiable Data Breaches scheme, in the same way as a larger business. We will maintain that choice.
​
Where we handle personal information on behalf of a Victorian public sector organisation — including a government school, TAFE or university — we act as a contracted service provider and also comply with the Information Privacy Principles under the Privacy and Data Protection Act 2014 (Vic). Where the engaging organisation requires it, we adhere to the Victorian Protective Data Security Standards. We comply with the corresponding legislation of another State or Territory where we supply a public sector organisation of that jurisdiction.
​
Where we handle health information, we also comply with the Health Privacy Principles under the Health Records Act 2001 (Vic) or the corresponding legislation of the relevant jurisdiction.
​
2. Scope of this policy
This policy covers personal information we collect and handle about:
• visitors to our website;
• institutions and individuals who enquire about the System;
• customers and their staff, once an institution contracts with us;
• individuals we meet through referral partners, education events, consultants or industry networks;
• suppliers, contractors and other business contacts; and
• students and staff of an institution, where we access their information while providing support (see section 5).
​
The Owner separately collects and handles information through the System itself. That handling is governed by the Owner’s own privacy terms, which we can provide on request. This policy covers our own handling, including information we access within the System.
​
Where we collect personal information directly from you, we may also give you a short notice at the point of collection. That notice summarises the key details and refers you to this policy.
​
3. Anonymity and pseudonymity
Where it is practicable and lawful, you may deal with us anonymously or under a pseudonym. In most cases we will be unable to respond to an enquiry, supply the System or manage a customer relationship without identifying you, because those interactions require accurate contact and institutional details.
​
4. What information we collect
Depending on how you interact with us, we may collect:
• Contact and identity information: name, job title or role, institution or organisation name, email address and phone number.
• Enquiry and institution details: institution type, approximate student numbers, CRICOS registration status, current systems in use, and the nature of your enquiry.
• Correspondence: records of emails, calls, meetings and other communications.
• Sales and account records: proposals, pilot arrangements, contracts, invoices and billing contact details.
• Website usage information: pages visited, general location, browser or device type and referral source, typically collected using cookies or similar technologies (see section 9).
• Documents you provide: tender documents, brochure requests or supporting materials.
​
We do not seek sensitive information through enquiries or correspondence, and we ask that you do not include it. We may, however, access sensitive information held in the System when providing support to an institution — see section 5.
​
5. Student and staff information in the System
An institution’s records in the System may include information about students and staff, and may include sensitive information such as health information or Aboriginal and Torres Strait Islander status.
​
We do not collect that information from you, and we do not hold a separate copy of it. We may access it only:
• to perform a specific support, configuration or troubleshooting task;
• with the prior approval of the institution;
• for the period required to perform that task; and
• under access that is logged, with the log available to the institution on request.
​
Our personnel do not copy, extract or store that information outside the System. Personnel who may access student information hold a current Working with Children Check and complete child safety training, as set out in our Environmental, Social and Governance Policy.
​
If you are a student, parent or staff member of an institution and have a question about information held in the System, contact your institution in the first instance — the institution controls that record.
​
6. How we collect information
We collect personal information:
• directly from you, when you complete our enquiry form, correspond with us or meet with us;
• through your dealings with us as a customer, including demonstrations, pilots, implementation and account management;
• from referral partners, consultants or industry contacts who introduce you to us;
• automatically through your use of our website (see section 9); and
• from an institution’s records in the System, in the limited circumstances described in section 5.
​
7. Why we collect and use this information
We collect and use personal information to:
• respond to and process enquiries;
• provide the information, products and services you or your institution request;
• assess the System before we offer it, and report our findings to an institution;
• configure, implement and support the System for an institution;
• manage our customer relationships, including contracting, invoicing, collection and support;
• maintain records of our communications;
• share information with the Owner where necessary to activate the System, resolve a product issue or meet our obligations to the Owner;
• operate, maintain and improve our website; and
• comply with our legal and regulatory obligations.
​
We will not use personal information for an unrelated purpose without your consent, unless required or authorised by law.
​
We do not use automated decision-making that produces a legal or similarly significant effect for any individual. If that changes, we will update this policy.
​
8. Disclosure, including overseas disclosure
We may disclose personal information to:
• The Owner. The Owner is incorporated in the United Arab Emirates and its personnel operate from the United Arab Emirates, the United States and India. Information we disclose to the Owner is stored in the United States. We disclose information relating to enquiries, sales, demonstrations, pilots, executed institutional contracts and customer accounts, where necessary for the purposes described in this policy. The Owner requires a copy of each executed institutional contract before the System is activated.
• IT and cloud service providers, including website hosting, email and analytics providers, which may store or process personal information in United Arab Emirates, the United States and India.
• Our personnel, contractors and advisers, on a need-to-know basis, for the purposes described above.
• Referral partners or consultants, only with your consent or where reasonably expected within an existing referral relationship.
• Regulatory or government bodies, where required or authorised by law, including where an institution is investigating an allegation of reportable conduct.
​
Where we disclose personal information to an overseas recipient, we take reasonable steps to ensure the recipient does not breach the APPs in relation to that information, as required by APP 8. For the Owner, this is achieved through contractual arrangements. For IT and cloud service providers, this is achieved through contractual terms and, where relevant, the provider’s published privacy and security standards.
​
We may also use or disclose personal information where APP 6 permits it, including where you have consented, where you would reasonably expect it, or where the use or disclosure is required or authorised by law.
​
9. Cookies and website analytics
Our website may use cookies or similar technologies to understand how visitors use the site and to improve its performance. This may include pages viewed, time on site, and general location or device information. You can manage or disable cookies through your browser settings, which may affect some website functionality.
​
10. Storage and security
We take reasonable steps to protect personal information we hold from misuse, interference and loss, and from unauthorised access, modification or disclosure. This includes secure storage, access restrictions, logging of access to institutional records, and controls over how information is shared with third parties.
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
​
If we become aware of a data breach that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner in accordance with the Notifiable Data Breaches scheme. Where the breach affects an institution, we will notify that institution without delay and provide the information it reasonably requires to meet its own obligations, including to the Office of the Victorian Information Commissioner where applicable.
​
11. Retention
We retain personal information only for as long as reasonably necessary for the purposes described in this policy, or as required by law or by contract with an institution. Where information is no longer needed, we take reasonable steps to destroy it or ensure it is de-identified, in accordance with APP 11.2.
​
12. Access and correction
You may request access to the personal information we hold about you, and ask us to correct it if you believe it is inaccurate, out of date, incomplete, irrelevant or misleading. Contact us using the details below. We will respond within 30 days.
​
If your request concerns information held in the System about a student or staff member of an institution, contact the institution, which controls that record. We will assist the institution to respond.
​
13. Complaints
If you have a concern about how we have handled your personal information, please contact us first using the details below. We will acknowledge your complaint within five business days and aim to resolve it within 30 days.
​
If you are not satisfied with our response, or you would prefer not to raise the matter with us, you may complain to:
• Office of the Australian Information Commissioner — www.oaic.gov.au, 1300 363 992.
• Office of the Victorian Information Commissioner — ovic.vic.gov.au, where the information is held for a Victorian public sector organisation.
​
14. Changes to this policy
We may update this policy from time to time to reflect changes in our practices, our business or our legal obligations. The updated version will be published on our website with a revised date.
​
15. Contact us
For any question about this policy, or to make an access, correction or complaint request contact Commercial INKS Australia Pty Ltd (ACN 679 183 156) as trustee for the Nair and Chand Trust (ABN 15 531 317 588), trading as Commercial INKS Australia.
​
Email: info@commercialinks.com.au
Phone: 1800 888 385